Configuration rules

36

TABLE 95

Predefined conditions (Continued)

 

 

 

 

 

 

 

 

 

 

 

Name

 

Description

Use

Matches/

Configuration

Lines in

 

 

 

regular

Not Matches

exact

 

 

 

expression

 

 

order

 

 

 

 

 

 

IronWare OS Interface shutdown

Checks whether the IronWare device

No

Matches

disable

No

check

 

port is in shutdown state. (This is not

 

 

 

 

 

 

applicable for Ethernet router

 

 

 

 

 

 

products.) This condition should be

 

 

 

 

 

 

used within an interface block.

 

 

 

 

 

 

 

 

 

 

IronWare OS Interface sflow check

Checks whether sFlow is configured

No

Matches

sflow-forwarding

Yes

 

 

on the IronWare device port. This

 

 

sflow sample 32768

 

 

 

condition should be used within an

 

 

 

 

 

 

interface block.

 

 

 

 

 

 

 

 

 

 

IronWare OS SNMP community

Checks whether SNMP community

Yes

Matches

snmp-server

No

Strings configured check

strings are configured.

 

 

community .*

 

 

 

 

 

 

 

Network OS SNMP community strings

Checks whether SNMP community

Yes

Matches

snmp-server

No

configured check

strings are configured.

 

 

community private rw

 

 

 

 

 

 

snmp-server

 

 

 

 

 

 

community public

 

 

 

 

 

 

 

IronWare OS Interface name check

Checks whether the port is named or

Yes

Matches

port-name.*

No

 

 

not.

 

 

 

 

 

 

 

 

 

 

IronWare OS VLAN name check

Checks whether the VLAN is named or

Yes

Matches

vlan(.)+name(.)+$

No

 

 

not.

 

 

 

 

 

 

 

 

 

 

IronWare OS Super User password

Checks whether the super user

Yes

Matches

^enable

No

enabled check

password is enabled on the device or

 

 

super-user-password

 

 

 

not.

 

 

 

 

IronWare OS Password min length enabled check

Checks whether the password

Yes

Matches

^enable

No

minimum length is enabled or not.

 

 

password-min-length

 

The range allowed is from 8 through

 

 

([8-9][1-9][0-9]1[0-

 

255 characters.

 

 

9][0-9]2[0-4][0-9]2

 

 

 

 

5[0-5])$

 

IronWare OS AAA Console Enabled

Checks whether the AAA console is

Yes

Matches

^enable aaa

No

check

enabled or not

 

 

console$

 

 

 

 

 

 

 

IronWare OS SSH timeout check

Checks whether the IP SSH timeout

Yes

Matches

'^ip ssh +timeout

No

 

value has been configured for the

 

 

(0*([1-9][0-9]?1[01]

 

 

device in the range [1 - 120].

 

 

[0-9]120))$'

 

 

 

 

 

 

 

IronWare OS SSH idle-time check

Checks whether the IP SSH

Yes

Matches

^ip ssh +idle-time

No

 

idle-timeout is less than or equal to

 

 

([0-9]10)$

 

 

10 minutes.

 

 

 

 

 

 

 

 

 

 

IronWare OS SSH Client Allowed

Checks to see if the SSH client is

Yes

Matches

ip ssh +client.*

No

check

allowed or not.

 

 

 

 

 

 

 

 

 

 

RFS with Configuration Auto Install

Checks whether auto-installation of

No

Matches

no autoinstall

No

Disabled

the configuration is disabled in a

 

 

configuration

 

 

user-specified profile. This condition

 

 

 

 

 

should be used inside the profile

 

 

 

 

 

block. If the profile name is not

 

 

 

 

 

specified in the configuration or if the

 

 

 

 

 

user selects all the profiles (profile.*),

 

 

 

 

 

then it will match against the first

 

 

 

 

 

available profile.

 

 

 

 

Brocade Network Advisor IP User Manual

1129

53-1003056-01

 

Page 1181
Image 1181
Brocade Communications Systems IP250 user manual Configuration rules Predefined conditions