Vyatta documentation

Learn how to install, configure, and operate the Vyatta Network Operating System (Vyatta NOS) and Orchestrator, which help drive our virtual networking and physical platforms portfolio.

Show Page Sections

Configuration commands

This release contains updated configuration commands.

New baseline commands

New baseline configuration commands have been added to this release.

  resources group application-group <group-name> engine user name <name>  
  resources group application-group <group-name> engine user protocol <protocol>  
  resources group application-group <group-name> engine user type <type>  
  security application firewall name <ruleset-name> rule <rule-number> engine user  
  security application firewall name <ruleset-name> rule <rule-number> engine user name <value>  
  security application firewall name <ruleset-name> rule <rule-number> engine user protocol <value>  
  security application firewall name <ruleset-name> rule <rule-number> engine user type <value>

  interfaces switch <name> vif <tagnode> firewall originate <value>

  interfaces switch <name> vif <tagnode> ipv6 address
  interfaces switch <name> vif <tagnode> ipv6 address autoconf
  interfaces switch <name> vif <tagnode> ipv6 address eui64 <value>
  interfaces switch <name> vif <tagnode> ipv6 address link-local <value>
  interfaces switch <name> vif <tagnode> ipv6 disable
  interfaces switch <name> vif <tagnode> ipv6 disable-forwarding
  interfaces switch <name> vif <tagnode> ipv6 dup-addr-detect-transmits <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert
  interfaces switch <name> vif <tagnode> ipv6 router-advert cur-hop-limit <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert default-lifetime <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert default-preference high
  interfaces switch <name> vif <tagnode> ipv6 router-advert default-preference low
  interfaces switch <name> vif <tagnode> ipv6 router-advert default-preference medium
  interfaces switch <name> vif <tagnode> ipv6 router-advert link-mtu <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert managed-flag <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert max-interval <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert min-interval <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert other-config-flag <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert prefix <tagnode>
  interfaces switch <name> vif <tagnode> ipv6 router-advert prefix <tagnode> autonomous-flag <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert prefix <tagnode> on-link-flag <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert prefix <tagnode> preferred-lifetime <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert prefix <tagnode> preferred-lifetime infinity
  interfaces switch <name> vif <tagnode> ipv6 router-advert prefix <tagnode> valid-lifetime <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert prefix <tagnode> valid-lifetime infinity
  interfaces switch <name> vif <tagnode> ipv6 router-advert reachable-time <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert retrans-timer <value>
  interfaces switch <name> vif <tagnode> ipv6 router-advert send-advert <value>

  resources group application-group <group-name> engine ndpi name <name>
  resources group application-group <group-name> engine ndpi protocol <protocol>
  resources group application-group <group-name> engine ndpi type <type>
  security application firewall name <ruleset-name> rule <rule-number> engine ndpi
  security application firewall name <ruleset-name> rule <rule-number> engine ndpi name <application> 
  security application firewall name <ruleset-name> rule <rule-number> engine ndpi protocol <protocol>
  security application firewall name <ruleset-name> rule <rule-number> engine ndpi type <type>

  protocols bgp <tagnode> neighbor <tagnode> fall-over bfd-strict
  protocols bgp <tagnode> neighbor <tagnode> fall-over bfd-strict holdtime <value>

  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> fall-over bfd-strict
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> fall-over bfd-strict holdtime <value>

  protocols bgp <tagnode> address-family ipv4-unicast additional-paths select backup
  protocols bgp <tagnode> address-family ipv4-unicast additional-paths select best-external
  protocols bgp <tagnode> address-family ipv6-unicast additional-paths select backup
  protocols bgp <tagnode> address-family ipv6-unicast additional-paths select best-external
  protocols bgp <tagnode> log additional-paths
  protocols bgp <tagnode> log nexthop-tracking
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map route-map <value>
  protocols bgp <tagnode> neighbor <tagnode> advertise best-external
  protocols bgp <tagnode> neighbor <tagnode> advertise diverse-path backup
  protocols bgp <tagnode> neighbor <tagnode> log additional-paths
  protocols bgp <tagnode> neighbor <tagnode> log nexthop-tracking
  protocols bgp <tagnode> parameters nexthop-tracking delay <value>
  protocols bgp <tagnode> parameters nexthop-tracking disable
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map condition-map match-action advertise
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map condition-map match-action withdraw
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map condition-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map route-map <value>
  protocols bgp <tagnode> peer-group <tagnode> advertise best-external
  protocols bgp <tagnode> peer-group <tagnode> advertise diverse-path backup

  routing routing-instance <instance-name> protocols bgp <tagnode> address-family ipv4-unicast additional-paths select backup
  routing routing-instance <instance-name> protocols bgp <tagnode> address-family ipv4-unicast additional-paths select best-external
  routing routing-instance <instance-name> protocols bgp <tagnode> address-family ipv6-unicast additional-paths select backup
  routing routing-instance <instance-name> protocols bgp <tagnode> address-family ipv6-unicast additional-paths select best-external
  routing routing-instance <instance-name> protocols bgp <tagnode> log additional-paths
  routing routing-instance <instance-name> protocols bgp <tagnode> log nexthop-tracking
  routing routing-instance <instance-name> protocols bgp <tagnode> log rib
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-labeled-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv4-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-labeled-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> address-family ipv6-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> advertise best-external
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> advertise diverse-path backup
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> log additional-paths
  routing routing-instance <instance-name> protocols bgp <tagnode> neighbor <tagnode> log nexthop-tracking
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-labeled-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv4-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-labeled-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map condition-map match-action advertise
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map condition-map match-action withdraw
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map condition-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> address-family ipv6-unicast advertise-map route-map <value>
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> advertise best-external
  routing routing-instance <instance-name> protocols bgp <tagnode> peer-group <tagnode> advertise diverse-path backup

  resources group application-group <group-name>
  resources group application-group <group-name> description <value>

  security application firewall name <ruleset-name> rule <rule-number> group <value>

  interfaces dataplane <tagnode> firewall originate <value>
  interfaces loopback <tagnode> firewall originate <value>

  service path-monitor snmp

  system journal storage size <value>


UfiSpace S9500-30XS

UfiSpace S9500-30XS configuration commands have also been added to this release.

  security ip-packet-filter group <group-name> rule <number> match destination port number <value>
  security ip-packet-filter group <group-name> rule <number> match dscp name af11
  security ip-packet-filter group <group-name> rule <number> match dscp name af12
  security ip-packet-filter group <group-name> rule <number> match dscp name af13
  security ip-packet-filter group <group-name> rule <number> match dscp name af21
  security ip-packet-filter group <group-name> rule <number> match dscp name af22
  security ip-packet-filter group <group-name> rule <number> match dscp name af23
  security ip-packet-filter group <group-name> rule <number> match dscp name af31
  security ip-packet-filter group <group-name> rule <number> match dscp name af32
  security ip-packet-filter group <group-name> rule <number> match dscp name af33
  security ip-packet-filter group <group-name> rule <number> match dscp name af41
  security ip-packet-filter group <group-name> rule <number> match dscp name af42
  security ip-packet-filter group <group-name> rule <number> match dscp name af43
  security ip-packet-filter group <group-name> rule <number> match dscp name cs1
  security ip-packet-filter group <group-name> rule <number> match dscp name cs2
  security ip-packet-filter group <group-name> rule <number> match dscp name cs3
  security ip-packet-filter group <group-name> rule <number> match dscp name cs4
  security ip-packet-filter group <group-name> rule <number> match dscp name cs5
  security ip-packet-filter group <group-name> rule <number> match dscp name cs6
  security ip-packet-filter group <group-name> rule <number> match dscp name cs7
  security ip-packet-filter group <group-name> rule <number> match dscp name default
  security ip-packet-filter group <group-name> rule <number> match dscp name ef
  security ip-packet-filter group <group-name> rule <number> match dscp name va
  security ip-packet-filter group <group-name> rule <number> match dscp value <value>
  security ip-packet-filter group <group-name> rule <number> match icmp name TOS-host-redirect
  security ip-packet-filter group <group-name> rule <number> match icmp name TOS-host-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmp name TOS-network-redirect
  security ip-packet-filter group <group-name> rule <number> match icmp name TOS-network-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmp name address-mask-reply
  security ip-packet-filter group <group-name> rule <number> match icmp name address-mask-request
  security ip-packet-filter group <group-name> rule <number> match icmp name communication-prohibited
  security ip-packet-filter group <group-name> rule <number> match icmp name destination-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmp name echo-reply
  security ip-packet-filter group <group-name> rule <number> match icmp name echo-request
  security ip-packet-filter group <group-name> rule <number> match icmp name fragmentation-needed
  security ip-packet-filter group <group-name> rule <number> match icmp name host-precedence-violation
  security ip-packet-filter group <group-name> rule <number> match icmp name host-prohibited
  security ip-packet-filter group <group-name> rule <number> match icmp name host-redirect
  security ip-packet-filter group <group-name> rule <number> match icmp name host-unknown
  security ip-packet-filter group <group-name> rule <number> match icmp name host-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmp name ip-header-bad
  security ip-packet-filter group <group-name> rule <number> match icmp name network-prohibited
  security ip-packet-filter group <group-name> rule <number> match icmp name network-redirect
  security ip-packet-filter group <group-name> rule <number> match icmp name network-unknown
  security ip-packet-filter group <group-name> rule <number> match icmp name network-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmp name parameter-problem
  security ip-packet-filter group <group-name> rule <number> match icmp name port-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmp name precedence-cutoff
  security ip-packet-filter group <group-name> rule <number> match icmp name protocol-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmp name redirect
  security ip-packet-filter group <group-name> rule <number> match icmp name required-option-missing
  security ip-packet-filter group <group-name> rule <number> match icmp name router-advertisement
  security ip-packet-filter group <group-name> rule <number> match icmp name router-solicitation
  security ip-packet-filter group <group-name> rule <number> match icmp name source-quench
  security ip-packet-filter group <group-name> rule <number> match icmp name source-route-failed
  security ip-packet-filter group <group-name> rule <number> match icmp name time-exceeded
  security ip-packet-filter group <group-name> rule <number> match icmp name timestamp-reply
  security ip-packet-filter group <group-name> rule <number> match icmp name timestamp-request
  security ip-packet-filter group <group-name> rule <number> match icmp name ttl-zero-during-reassembly
  security ip-packet-filter group <group-name> rule <number> match icmp name ttl-zero-during-transit
  security ip-packet-filter group <group-name> rule <number> match icmp type <type-number>
  security ip-packet-filter group <group-name> rule <number> match icmp type <type-number> code <value>
  security ip-packet-filter group <group-name> rule <number> match icmpv6 class error
  security ip-packet-filter group <group-name> rule <number> match icmpv6 class info
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name address-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name bad-header
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name communication-prohibited
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name destination-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name echo-reply
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name echo-request
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name mobile-prefix-advertisement
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name mobile-prefix-solicitation
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name multicast-listener-done
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name multicast-listener-query
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name multicast-listener-report
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name neighbor-advertisement
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name neighbor-solicitation
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name no-route
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name packet-too-big
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name parameter-problem
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name port-unreachable
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name redirect
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name router-advertisement
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name router-solicitation
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name time-exceeded
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name ttl-zero-during-reassembly
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name ttl-zero-during-transit
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name unknown-header-type
  security ip-packet-filter group <group-name> rule <number> match icmpv6 name unknown-option
  security ip-packet-filter group <group-name> rule <number> match icmpv6 type <type-number>
  security ip-packet-filter group <group-name> rule <number> match icmpv6 type <type-number> code <value>
  security ip-packet-filter group <group-name> rule <number> match source port number <value>
  security ip-packet-filter group <group-name> rule <number> match ttl equals <value>
  security ip-packet-filter interface <interface-name> out <value>
 
  interfaces dataplane <tagnode> policy route pbr <value>
  interfaces dataplane <tagnode> vif <tagnode> policy route pbr <value>

  interfaces dataplane <tagnode> policy ingress-map <value>
  interfaces dataplane <tagnode> policy qos <value>
  interfaces dataplane <tagnode> vif <tagnode> policy ingress-map <value>
  interfaces dataplane <tagnode> vif <tagnode> policy qos <value>
  policy qos mark-map <id> designation <designation-type> drop-precedence <colour>
  policy qos mark-map <id> designation <designation-type> drop-precedence <colour> pcp-mark <value>

  interfaces dataplane <tagnode> switch-group port-parameters vlan-parameters mac-limit vlan <vlan-id>
  interfaces dataplane <tagnode> switch-group port-parameters vlan-parameters mac-limit vlan <vlan-id> profile <value>
  security mac-limit profile <profile-name>
  security mac-limit profile <profile-name> limit <value>

  service ptp instance <instance-number> port-ds-list <port-number> additional-path-list <path-number>
  service ptp instance <instance-number> port-ds-list <port-number> additional-path-list <path-number> underlying-interface <value>
  service ptp instance <instance-number> port-ds-list <port-number> additional-path-list <path-number> vlan <value>

UfiSpace S9700-53DX

UfiSpace S9700-53DX configuration commands have also been added to this release.

  interfaces dataplane <tagnode> policy ingress-map <value>
  interfaces dataplane <tagnode> switch-group port-parameters policy ingress-map <value>
  interfaces dataplane <tagnode> switch-group port-parameters vlan-parameters qos-parameters vlan <vlan-id> policy ingress-map <value>
  interfaces dataplane <tagnode> vif <tagnode> policy ingress-map <value>
  policy ingress-map <id>
  policy ingress-map <id> dscp-group <id>
  policy ingress-map <id> dscp-group <id> designation <value>
  policy ingress-map <id> dscp-group <id> drop-precedence green
  policy ingress-map <id> dscp-group <id> drop-precedence red
  policy ingress-map <id> dscp-group <id> drop-precedence yellow
  policy ingress-map <id> pcp <id>
  policy ingress-map <id> pcp <id> designation <value>
  policy ingress-map <id> pcp <id> drop-precedence green
  policy ingress-map <id> pcp <id> drop-precedence red
  policy ingress-map <id> pcp <id> drop-precedence yellow
  policy ingress-map <id> system-default
  policy qos mark-map <id>
  policy qos mark-map <id> description <value>
  policy qos mark-map <id> designation <designation-type>
  policy qos mark-map <id> designation <designation-type> drop-precedence <colour>
  policy qos mark-map <id> designation <designation-type> drop-precedence <colour> pcp-mark <value>
  policy qos name <id> shaper mark-map <value>
  policy qos name <id> shaper profile <id> map designation <id>
  policy qos name <id> shaper profile <id> map designation <id> to <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes drop-precedence <colour>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes drop-precedence <colour> mark-probability <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes drop-precedence <colour> max-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes drop-precedence <colour> min-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes dscp-group <group-name>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes dscp-group <group-name> mark-probability <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes dscp-group <group-name> max-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes dscp-group <group-name> min-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map-bytes filter-weight <value>
  policy qos name <id> shaper traffic-class <id> queue-limit-bytes <value>
  policy qos profile <id> map designation <id>
  policy qos profile <id> map designation <id> to <value>
  policy qos profile <id> queue <id> wred-map-bytes
  policy qos profile <id> queue <id> wred-map-bytes drop-precedence <colour>
  policy qos profile <id> queue <id> wred-map-bytes drop-precedence <colour> mark-probability <value>
  policy qos profile <id> queue <id> wred-map-bytes drop-precedence <colour> max-threshold <value>
  policy qos profile <id> queue <id> wred-map-bytes drop-precedence <colour> min-threshold <value>
  policy qos profile <id> queue <id> wred-map-bytes dscp-group <group-name>
  policy qos profile <id> queue <id> wred-map-bytes dscp-group <group-name> mark-probability <value>
  policy qos profile <id> queue <id> wred-map-bytes dscp-group <group-name> max-threshold <value>
  policy qos profile <id> queue <id> wred-map-bytes dscp-group <group-name> min-threshold <value>
  policy qos profile <id> queue <id> wred-map-bytes filter-weight <value>

Modified commands

No commands have been modified in this release.

Modified defaults

Default values have changed in this release.

UfiSpace S9500-30XS:

urn:vyatta.com:mgmt:vyatta-system-misc
 [system fault-behavior panic-on-io-nmi <value>]
    default changed from true to false
[system fault-behavior panic-on-unrecovered-nmi <value>]
    default changed from true to false
[system fault-behavior reboot-wait-after-panic <value>]
    default changed from 30 to 60
UfiSpace S9700-53XS:
urn:vyatta.com:mgmt:vyatta-policy-qos
 [policy qos name <id> shaper burst <value>]
    default 2093056 added
 [policy qos name <id> shaper profile <id> burst <value>]
    default 2093056 added
 [policy qos profile <id> burst <value>]
    default 2093056 added

Deprecated commands

A range of configuration commands have been marked as deprecated in this release.

  service diamond session-name <name> handler amqp-topic server <value>

  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic server <value>

  service diamond session-name <name> collector netconf get path <value>

  routing routing-instance <instance-name> service diamond session-name <name> collector netconf get path <value>
The following configuration commands have also been marked as deprecated for the platform(s) indicated:

UfiSpace S9500-30XS:

policy qos mark-map <id> designation <designation-type> pcp-mark <value>

Obsoleted commands

A range of configuration commands have been obsoleted in this release.

  service diamond session-name <name> handler amqp-topic
  service diamond session-name <name> handler amqp-topic host <value>
  service diamond session-name <name> handler amqp-topic password <value>
  service diamond session-name <name> handler amqp-topic port <value>
  service diamond session-name <name> handler amqp-topic server <value>
  service diamond session-name <name> handler amqp-topic ssl-certificate-path <value>
  service diamond session-name <name> handler amqp-topic topic-exchange <value>
  service diamond session-name <name> handler amqp-topic user <value>
  service diamond session-name <name> handler amqp-topic vhost <value>

  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic host <value>
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic password <value>
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic port <value>
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic server <value>
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic ssl-certificate-path <value>
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic topic-exchange <value>
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic user <value>
  routing routing-instance <instance-name> service diamond session-name <name> handler amqp-topic vhost <value>

  service diamond session-name <name> collector netconf get path <value>
  service diamond session-name <name> collector netconf get path-map <path>
  service diamond session-name <name> collector netconf get path-map <path> key-field <value>
  service diamond session-name <name> collector netconf get path-map <path> to <value>

  routing routing-instance <instance-name> service diamond session-name <name> collector netconf get path <value>
  routing routing-instance <instance-name> service diamond session-name <name> collector netconf get path-map <path>
  routing routing-instance <instance-name> service diamond session-name <name> collector netconf get path-map <path> key-field <value>
  routing routing-instance <instance-name> service diamond session-name <name> collector netconf get path-map <path> to <value>

  policy route pbr <tagnode> rule <tagnode> application name <name>
  policy route pbr <tagnode> rule <tagnode> application type <value>

  policy qos name <id> shaper class <id> match <id> application name <name>
  policy qos name <id> shaper class <id> match <id> application type <value>

  security application firewall name <ruleset-name> rule <rule-number> name <name>
  security application firewall name <ruleset-name> rule <rule-number> protocol <protocol>
  security application firewall name <ruleset-name> rule <rule-number> type <type>

  security firewall name <ruleset-name> rule <tagnode> session application name <name>
  security firewall name <ruleset-name> rule <tagnode> session application protocol <protocol>
  security firewall name <ruleset-name> rule <tagnode> session application type <value>

  service diamond session-name <name>
  service diamond session-name <name> interval <value>

  routing routing-instance <instance-name> service diamond session-name <name>
  routing routing-instance <instance-name> service diamond session-name <name> interval <value>

The following configuration commands have also been obsoleted in this release for the platform(s) indicated:

UfiSpace S9500-30XS:
  policy qos name <id> shaper class <id> match <id> application name <name>
  policy qos name <id> shaper class <id> match <id> application type <value>
UfiSpace S9700-53DX:
  policy qos name <id> shaper class <id> match <id> application name <name>
  policy qos name <id> shaper class <id> match <id> application type <value>

Removed commands

A range of configuration commands have been removed from this release.

UfiSpace S9500-30XSs:
protocols bfd template <tagnode> auth simple key <value>
UfiSpace S9700-53DX:
urn:vyatta.com:mgmt:vyatta-policy-action
  policy action
  policy action name <id>
  policy action name <id> mark dscp af11
  policy action name <id> mark dscp af12
  policy action name <id> mark dscp af13
  policy action name <id> mark dscp af21
  policy action name <id> mark dscp af22
  policy action name <id> mark dscp af23
  policy action name <id> mark dscp af31
  policy action name <id> mark dscp af32
  policy action name <id> mark dscp af33
  policy action name <id> mark dscp af41
  policy action name <id> mark dscp af42
  policy action name <id> mark dscp af43
  policy action name <id> mark dscp cs1
  policy action name <id> mark dscp cs2
  policy action name <id> mark dscp cs3
  policy action name <id> mark dscp cs4
  policy action name <id> mark dscp cs5
  policy action name <id> mark dscp cs6
  policy action name <id> mark dscp cs7
  policy action name <id> mark dscp default
  policy action name <id> mark dscp ef
  policy action name <id> mark dscp va
  policy action name <id> mark pcp <value>
  policy action name <id> mark pcp-inner
  policy action name <id> police
  policy action name <id> police bandwidth <value>
  policy action name <id> police burst <value>
  policy action name <id> police frame-overhead <value>
  policy action name <id> police ratelimit <value>
  policy action name <id> police tc <value>
  policy action name <id> police then action drop
  policy action name <id> police then mark dscp af11
  policy action name <id> police then mark dscp af12
  policy action name <id> police then mark dscp af13
  policy action name <id> police then mark dscp af21
  policy action name <id> police then mark dscp af22
  policy action name <id> police then mark dscp af23
  policy action name <id> police then mark dscp af31
  policy action name <id> police then mark dscp af32
  policy action name <id> police then mark dscp af33
  policy action name <id> police then mark dscp af41
  policy action name <id> police then mark dscp af42
  policy action name <id> police then mark dscp af43
  policy action name <id> police then mark dscp cs1
  policy action name <id> police then mark dscp cs2
  policy action name <id> police then mark dscp cs3
  policy action name <id> police then mark dscp cs4
  policy action name <id> police then mark dscp cs5
  policy action name <id> police then mark dscp cs6
  policy action name <id> police then mark dscp cs7
  policy action name <id> police then mark dscp default
  policy action name <id> police then mark dscp ef
  policy action name <id> police then mark dscp va
  policy action name <id> police then mark pcp <value>
  policy action name <id> police then mark pcp-inner

  policy qos name <id> shaper class <id>
  policy qos name <id> shaper class <id> description <value>
  policy qos name <id> shaper class <id> match <id>
  policy qos name <id> shaper class <id> match <id> action drop
  policy qos name <id> shaper class <id> match <id> action pass
  policy qos name <id> shaper class <id> match <id> action-group <value>
  policy qos name <id> shaper class <id> match <id> description <value>
  policy qos name <id> shaper class <id> match <id> destination address <value>
  policy qos name <id> shaper class <id> match <id> destination mac-address <value>
  policy qos name <id> shaper class <id> match <id> destination port <value>
  policy qos name <id> shaper class <id> match <id> disable
  policy qos name <id> shaper class <id> match <id> dscp af11
  policy qos name <id> shaper class <id> match <id> dscp af12
  policy qos name <id> shaper class <id> match <id> dscp af13
  policy qos name <id> shaper class <id> match <id> dscp af21
  policy qos name <id> shaper class <id> match <id> dscp af22
  policy qos name <id> shaper class <id> match <id> dscp af23
  policy qos name <id> shaper class <id> match <id> dscp af31
  policy qos name <id> shaper class <id> match <id> dscp af32
  policy qos name <id> shaper class <id> match <id> dscp af33
  policy qos name <id> shaper class <id> match <id> dscp af41
  policy qos name <id> shaper class <id> match <id> dscp af42
  policy qos name <id> shaper class <id> match <id> dscp af43
  policy qos name <id> shaper class <id> match <id> dscp cs1
  policy qos name <id> shaper class <id> match <id> dscp cs2
  policy qos name <id> shaper class <id> match <id> dscp cs3
  policy qos name <id> shaper class <id> match <id> dscp cs4
  policy qos name <id> shaper class <id> match <id> dscp cs5
  policy qos name <id> shaper class <id> match <id> dscp cs6
  policy qos name <id> shaper class <id> match <id> dscp cs7
  policy qos name <id> shaper class <id> match <id> dscp default
  policy qos name <id> shaper class <id> match <id> dscp ef
  policy qos name <id> shaper class <id> match <id> dscp va
  policy qos name <id> shaper class <id> match <id> dscp-group <value>
  policy qos name <id> shaper class <id> match <id> ethertype <value>
  policy qos name <id> shaper class <id> match <id> fragment
  policy qos name <id> shaper class <id> match <id> icmp
  policy qos name <id> shaper class <id> match <id> icmp group <value>
  policy qos name <id> shaper class <id> match <id> icmp name TOS-host-redirect
  policy qos name <id> shaper class <id> match <id> icmp name TOS-host-unreachable
  policy qos name <id> shaper class <id> match <id> icmp name TOS-network-redirect
  policy qos name <id> shaper class <id> match <id> icmp name TOS-network-unreachable
  policy qos name <id> shaper class <id> match <id> icmp name address-mask-reply
  policy qos name <id> shaper class <id> match <id> icmp name address-mask-request
  policy qos name <id> shaper class <id> match <id> icmp name communication-prohibited
  policy qos name <id> shaper class <id> match <id> icmp name destination-unreachable
  policy qos name <id> shaper class <id> match <id> icmp name echo-reply
  policy qos name <id> shaper class <id> match <id> icmp name echo-request
  policy qos name <id> shaper class <id> match <id> icmp name fragmentation-needed
  policy qos name <id> shaper class <id> match <id> icmp name host-precedence-violation
  policy qos name <id> shaper class <id> match <id> icmp name host-prohibited
  policy qos name <id> shaper class <id> match <id> icmp name host-redirect
  policy qos name <id> shaper class <id> match <id> icmp name host-unknown
  policy qos name <id> shaper class <id> match <id> icmp name host-unreachable
  policy qos name <id> shaper class <id> match <id> icmp name ip-header-bad
  policy qos name <id> shaper class <id> match <id> icmp name network-prohibited
  policy qos name <id> shaper class <id> match <id> icmp name network-redirect
  policy qos name <id> shaper class <id> match <id> icmp name network-unknown
  policy qos name <id> shaper class <id> match <id> icmp name network-unreachable
  policy qos name <id> shaper class <id> match <id> icmp name parameter-problem
  policy qos name <id> shaper class <id> match <id> icmp name port-unreachable
  policy qos name <id> shaper class <id> match <id> icmp name precedence-cutoff
  policy qos name <id> shaper class <id> match <id> icmp name protocol-unreachable
  policy qos name <id> shaper class <id> match <id> icmp name redirect
  policy qos name <id> shaper class <id> match <id> icmp name required-option-missing
  policy qos name <id> shaper class <id> match <id> icmp name router-advertisement
  policy qos name <id> shaper class <id> match <id> icmp name router-solicitation
  policy qos name <id> shaper class <id> match <id> icmp name source-quench
  policy qos name <id> shaper class <id> match <id> icmp name source-route-failed
  policy qos name <id> shaper class <id> match <id> icmp name time-exceeded
  policy qos name <id> shaper class <id> match <id> icmp name timestamp-reply
  policy qos name <id> shaper class <id> match <id> icmp name timestamp-request
  policy qos name <id> shaper class <id> match <id> icmp name ttl-zero-during-reassembly
  policy qos name <id> shaper class <id> match <id> icmp name ttl-zero-during-transit
  policy qos name <id> shaper class <id> match <id> icmp type <type-number>
  policy qos name <id> shaper class <id> match <id> icmp type <type-number> code <value>
  policy qos name <id> shaper class <id> match <id> icmpv6
  policy qos name <id> shaper class <id> match <id> icmpv6 group <value>
  policy qos name <id> shaper class <id> match <id> icmpv6 name address-unreachable
  policy qos name <id> shaper class <id> match <id> icmpv6 name bad-header
  policy qos name <id> shaper class <id> match <id> icmpv6 name communication-prohibited
  policy qos name <id> shaper class <id> match <id> icmpv6 name destination-unreachable
  policy qos name <id> shaper class <id> match <id> icmpv6 name echo-reply
  policy qos name <id> shaper class <id> match <id> icmpv6 name echo-request
  policy qos name <id> shaper class <id> match <id> icmpv6 name mobile-prefix-advertisement
  policy qos name <id> shaper class <id> match <id> icmpv6 name mobile-prefix-solicitation
  policy qos name <id> shaper class <id> match <id> icmpv6 name multicast-listener-done
  policy qos name <id> shaper class <id> match <id> icmpv6 name multicast-listener-query
  policy qos name <id> shaper class <id> match <id> icmpv6 name multicast-listener-report
  policy qos name <id> shaper class <id> match <id> icmpv6 name neighbor-advertisement
  policy qos name <id> shaper class <id> match <id> icmpv6 name neighbor-solicitation
  policy qos name <id> shaper class <id> match <id> icmpv6 name no-route
  policy qos name <id> shaper class <id> match <id> icmpv6 name packet-too-big
  policy qos name <id> shaper class <id> match <id> icmpv6 name parameter-problem
  policy qos name <id> shaper class <id> match <id> icmpv6 name port-unreachable
  policy qos name <id> shaper class <id> match <id> icmpv6 name redirect
  policy qos name <id> shaper class <id> match <id> icmpv6 name router-advertisement
  policy qos name <id> shaper class <id> match <id> icmpv6 name router-solicitation
  policy qos name <id> shaper class <id> match <id> icmpv6 name time-exceeded
  policy qos name <id> shaper class <id> match <id> icmpv6 name ttl-zero-during-reassembly
  policy qos name <id> shaper class <id> match <id> icmpv6 name ttl-zero-during-transit
  policy qos name <id> shaper class <id> match <id> icmpv6 name unknown-header-type
  policy qos name <id> shaper class <id> match <id> icmpv6 name unknown-option
  policy qos name <id> shaper class <id> match <id> icmpv6 type <type-number>
  policy qos name <id> shaper class <id> match <id> icmpv6 type <type-number> code <value>
  policy qos name <id> shaper class <id> match <id> ipv6-route
  policy qos name <id> shaper class <id> match <id> ipv6-route type <value>
  policy qos name <id> shaper class <id> match <id> log
  policy qos name <id> shaper class <id> match <id> mark dscp af11
  policy qos name <id> shaper class <id> match <id> mark dscp af12
  policy qos name <id> shaper class <id> match <id> mark dscp af13
  policy qos name <id> shaper class <id> match <id> mark dscp af21
  policy qos name <id> shaper class <id> match <id> mark dscp af22
  policy qos name <id> shaper class <id> match <id> mark dscp af23
  policy qos name <id> shaper class <id> match <id> mark dscp af31
  policy qos name <id> shaper class <id> match <id> mark dscp af32
  policy qos name <id> shaper class <id> match <id> mark dscp af33
  policy qos name <id> shaper class <id> match <id> mark dscp af41
  policy qos name <id> shaper class <id> match <id> mark dscp af42
  policy qos name <id> shaper class <id> match <id> mark dscp af43
  policy qos name <id> shaper class <id> match <id> mark dscp cs1
  policy qos name <id> shaper class <id> match <id> mark dscp cs2
  policy qos name <id> shaper class <id> match <id> mark dscp cs3
  policy qos name <id> shaper class <id> match <id> mark dscp cs4
  policy qos name <id> shaper class <id> match <id> mark dscp cs5
  policy qos name <id> shaper class <id> match <id> mark dscp cs6
  policy qos name <id> shaper class <id> match <id> mark dscp cs7
  policy qos name <id> shaper class <id> match <id> mark dscp default
  policy qos name <id> shaper class <id> match <id> mark dscp ef
  policy qos name <id> shaper class <id> match <id> mark dscp va
  policy qos name <id> shaper class <id> match <id> mark pcp <value>
  policy qos name <id> shaper class <id> match <id> mark pcp-inner
  policy qos name <id> shaper class <id> match <id> pcp <value>
  policy qos name <id> shaper class <id> match <id> police
  policy qos name <id> shaper class <id> match <id> police bandwidth <value>
  policy qos name <id> shaper class <id> match <id> police burst <value>
  policy qos name <id> shaper class <id> match <id> police frame-overhead <value>
  policy qos name <id> shaper class <id> match <id> police ratelimit <value>
  policy qos name <id> shaper class <id> match <id> police tc <value>
  policy qos name <id> shaper class <id> match <id> police then action drop
  policy qos name <id> shaper class <id> match <id> police then mark dscp af11
  policy qos name <id> shaper class <id> match <id> police then mark dscp af12
  policy qos name <id> shaper class <id> match <id> police then mark dscp af13
  policy qos name <id> shaper class <id> match <id> police then mark dscp af21
  policy qos name <id> shaper class <id> match <id> police then mark dscp af22
  policy qos name <id> shaper class <id> match <id> police then mark dscp af23
  policy qos name <id> shaper class <id> match <id> police then mark dscp af31
  policy qos name <id> shaper class <id> match <id> police then mark dscp af32
  policy qos name <id> shaper class <id> match <id> police then mark dscp af33
  policy qos name <id> shaper class <id> match <id> police then mark dscp af41
  policy qos name <id> shaper class <id> match <id> police then mark dscp af42
  policy qos name <id> shaper class <id> match <id> police then mark dscp af43
  policy qos name <id> shaper class <id> match <id> police then mark dscp cs1
  policy qos name <id> shaper class <id> match <id> police then mark dscp cs2
  policy qos name <id> shaper class <id> match <id> police then mark dscp cs3
  policy qos name <id> shaper class <id> match <id> police then mark dscp cs4
  policy qos name <id> shaper class <id> match <id> police then mark dscp cs5
  policy qos name <id> shaper class <id> match <id> police then mark dscp cs6
  policy qos name <id> shaper class <id> match <id> police then mark dscp cs7
  olicy qos name <id> shaper class <id> match <id> police then mark dscp default
  policy qos name <id> shaper class <id> match <id> police then mark dscp ef
  policy qos name <id> shaper class <id> match <id> police then mark dscp va
  policy qos name <id> shaper class <id> match <id> police then mark pcp <value>
  policy qos name <id> shaper class <id> match <id> police then mark pcp-inner
  policy qos name <id> shaper class <id> match <id> protocol <value>
  policy qos name <id> shaper class <id> match <id> protocol-group <value>
  policy qos name <id> shaper class <id> match <id> source address <value>
  policy qos name <id> shaper class <id> match <id> source mac-address <value>
  policy qos name <id> shaper class <id> match <id> source port <value>
  policy qos name <id> shaper class <id> match <id> tcp
  policy qos name <id> shaper class <id> match <id> tcp flags <value>
  policy qos name <id> shaper class <id> profile <value>
  policy qos name <id> shaper profile <id> map dscp <id>
  policy qos name <id> shaper profile <id> map dscp <id> to <value>
  policy qos name <id> shaper profile <id> map pcp <id>
  policy qos name <id> shaper profile <id> map pcp <id> to <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name>
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name> mark-probability <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name> max-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map dscp-group <group-name> min-threshold <value>
  policy qos name <id> shaper profile <id> queue <id> wred-map filter-weight <value>
  policy qos name <id> shaper traffic-class <id> queue-limit <value>
  policy qos name <id> shaper traffic-class <id> random-detect
  policy qos name <id> shaper traffic-class <id> random-detect filter-weight <value>
  policy qos name <id> shaper traffic-class <id> random-detect mark-probability <value>
  policy qos name <id> shaper traffic-class <id> random-detect max-threshold <value>
  policy qos name <id> shaper traffic-class <id> random-detect 
  policy qos profile <id> map dscp <id>
  policy qos profile <id> map dscp <id> to <value>
  policy qos profile <id> map pcp <id>
  policy qos profile <id> map pcp <id> to <value>
  policy qos profile <id> queue <id> wred-map
  policy qos profile <id> queue <id> wred-map dscp-group <group-name>
  policy qos profile <id> queue <id> wred-map dscp-group <group-name> mark-probability <value>
  policy qos profile <id> queue <id> wred-map dscp-group <group-name> max-threshold <value>
  policy qos profile <id> queue <id> wred-map dscp-group <group-name> min-threshold <value>
  policy qos profile <id> queue <id> wred-map filter-weight <value>

  policy qos name <id> shaper class <id> match <id> application
  policy qos name <id> shaper class <id> match <id> application name <name>
  policy qos name <id> shaper class <id> match <id> application type <value>
  policy qos name <id> shaper class <id> match <id> application type aaa
  policy qos name <id> shaper class <id> match <id> application type adult_content
  policy qos name <id> shaper class <id> match <id> application type advertising
  policy qos name <id> shaper class <id> match <id> application type analytics
  policy qos name <id> shaper class <id> match <id> application type anonymizer
  policy qos name <id> shaper class <id> match <id> application type audio_chat
  policy qos name <id> shaper class <id> match <id> application type basic
  policy qos name <id> shaper class <id> match <id> application type blog
  policy qos name <id> shaper class <id> match <id> application type cdn
  policy qos name <id> shaper class <id> match <id> application type chat
  policy qos name <id> shaper class <id> match <id> application type classified_ads
  policy qos name <id> shaper class <id> match <id> application type cloud_services
  policy qos name <id> shaper class <id> match <id> application type db
  policy qos name <id> shaper class <id> match <id> application type email
  policy qos name <id> shaper class <id> match <id> application type enterprise
  policy qos name <id> shaper class <id> match <id> application type file_mngt
  policy qos name <id> shaper class <id> match <id> application type file_transfer
  policy qos name <id> shaper class <id> match <id> application type forum
  policy qos name <id> shaper class <id> match <id> application type gaming
  policy qos name <id> shaper class <id> match <id> application type im_mc
  policy qos name <id> shaper class <id> match <id> application type iot
  policy qos name <id> shaper class <id> match <id> application type mm_streaming
  policy qos name <id> shaper class <id> match <id> application type mobile
  policy qos name <id> shaper class <id> match <id> application type networking
  policy qos name <id> shaper class <id> match <id> application type news_portal
  policy qos name <id> shaper class <id> match <id> application type p2p
  policy qos name <id> shaper class <id> match <id> application type remote_access
  policy qos name <id> shaper class <id> match <id> application type scada
  policy qos name <id> shaper class <id> match <id> application type social_network
  policy qos name <id> shaper class <id> match <id> application type standardized
  policy qos name <id> shaper class <id> match <id> application type update
  policy qos name <id> shaper class <id> match <id> application type video_chat
  policy qos name <id> shaper class <id> match <id> application type voip
  policy qos name <id> shaper class <id> match <id> application type vpn_tun
  policy qos name <id> shaper class <id> match <id> application type web
  policy qos name <id> shaper class <id> match <id> application type web_ecom
  policy qos name <id> shaper class <id> match <id> application type web_search
  policy qos name <id> shaper class <id> match <id> application type web_sites
  policy qos name <id> shaper class <id> match <id> application type webmail