5RXWHUDPLO\
 Efficient Networks
 Software License and Limited Warranty
 Limitations
 Release
Revision History
001 12 Feb
 Contents
 File System Commands
 Contents
 Contents
 Remote Commands
Eth ip directbcast
 Contents
 Contents
 WAN Interface Commands
 Dhcp Commands
 L2TP Commands
 Remote setpppoeservice -1 pppoe close -2 pppoe list
L2tp set window -16 remote setl2tpclient -17 remote setlns
 Contents
 Voice Commands
 User Commands
 Stateful Firewall Commands
 QoS Commands
Ssh set rekey -8 ssh set status -8 system sshport
 This page intentionally left blank
 Introduction
How This Manual is Organized
 Password
Command Conventions
Accessing the Command Line
Username
 Command line is now available for use
Re-enter the new password at the prompt
Password change will be confirmed
Terminal Sessions
 Terminal Session under Windows HyperTerminal
 Data bits Parity None Stop bits Flow control Hardware
 Terminal Session for Macintosh or Unix
 Telnet Session for Remote Access
Telnet
 Command Line via the Web Management Interface
 Mode is learning, listening, or forwarding
Lists the top-level commands and keywords and a
Resolution Protocol ARP table
Lists the contents of the bridge table
 Initiates a reboot of the system
Lists the current services in the IPX SAPs table
Changes the current user password
Enables Sntp requests
 Parameters
? or help
Input Format
Response
 Mgmt Class
Arp delete
Arp list
Example
 Voice R
Input Format Parameters
Arp list
Arp list
 Bi list
Bi list
Bi list
 Call remotename
Call
Voice R/W
Remotenamea Name of the target router
 Date
Display when date is entered with no parameters
Display when date is entered with parameters
All R/W
 Erase
Admin R/W
When entered with no parameters, same as erase all
 All R
Exit
Ifs
Voice R, Network R
 An example of additional interfaces that may be displayed
Ipifs
Typical response is shown below
Ipifs
 Iproutes
Iproutes
Ipxroutes
Ipxroutes
 Ipxroutes
Ipxsaps
Ipxsaps
Ipxsaps
 Logout
Logout
 Mem
Mem
System R, Debug R
Mem
 Mlp summary
Mlp summary
 Admin101@console- password 1675309 lobster
Password
Password old password new password
 Ping
 Ping -I 192.168.1.2
Ping -c 2 -i 7 -s 34
Ping -I 192.168.254.254
 TID Name Bottom Current Size 1IDLE
 Reboot
Reboot option
 Save
User is prompted to verify the command
Save
 Sntp disable
Sntp disable
Disables Sntp requests
Sntp active
 Sntp offset
Sntp enable
When no parameter is entered, current offset is displayed
Itive number is east a negative number is west
 Sntp prefserver number
When entered with no number parameter
Sntp prefserver
Number of a server within the Sntp server list
 When entered and no sntp preferred server is defined
When entered with a number parameter
When entered while sntp function is currently disabled
When entered and an sntp preferred server has been defined
 When entered with the default parameter
Sntp server ipaddress default number
Requests the default server list
Sntp server
 Typical response
Tcp stats
Tcp stats
Tcp stats
 Time
 Dress as the source address
Traceroute
Network R/W, Debug R
Hop is listed in the output message
 Traceroute -n
172.17.20.1
Traceroute
 Vers
Vers
 Copies a file from the source to the destination
This command loads batch files of configuration
Commands into the router
Deletes the specified file from the flash filesystem
 Copy srcfile dstfile
Copy
Examples
Copy tftp@128.1.210.66kernelnw kernel.f2k
 Refer to examples for typical responses
Admin R/W, System R/W
Delete
Delete filename
 Dir
Dir
Dir
 Execute
Execute filename
 System R/W, Debug R/W
Following is an example of the format disk command
Format disk
Format disk
 Msfs
Msfs
Msfs fix
 Sync
Following is an example rename command
Rename
Commits the changes made to the file system to Flash memory
 Remaps a range of local-LAN IP addresses to a
Adds an address to the BootP server list
Lists the supported keywords
Range of public IP addresses on a system-wide ba
 Changes the Dial Backup retry period
Disables the Dial Backup option in the router
Enables the Dial Backup option in the router
Changes the Dial Backup stability period
 Manages the system Http port access
Lists the default modem settings
Removes an address from the BootP server list
Lists the system settings for the target router
 Manages SSH port access
Enables and disables the secure mode function
Manages Snmp port access
Manages Syslog port access
 System ?
System addbootpserver
System addbootpserver ipaddr
System ?
 System addbootpserver
IP address of the server
 System addhostmapping
 System addhttpfilter first ip addr last ip addr lan
System addhttpfilter
Security R/W
Local Ethernet LAN
 System addiproutingtable
 System addiproutingtable 192.168.1.5 192.168.1.12 Rosa
System addserver
Response Example
 Selects the host with this IP address as server
Action One of the following command actions
Rlogin port
Discards the incoming server request
 System addsnmpfilter
System addsnmpfilter first ip addr last ip addr lan
 System addsyslogfilter
System addsyslogfilter firstipaddr last ipaddr lan
 System addsyslogserver ipaddr
System addsyslogserver
System R/W
IP address to be added to the Syslog server address list
 System addtelnetfilter
System addtelnetfilter first ip addr last ip addr lan
 First port in the UDP port range to be created
System addudprelay
Warded
Incorporates all the available UDP ports in the new range
 Cally
System authen
System authen none pap chap
Chap is performed
 IP address to be added to the list
System backup add
System backup add ipaddr gw dns group
Address
 Following command deletes all addresses from group
System backup delete
Following command deletes the gateway address from group
IP address to be deleted from the list
 System backup disable
System backup disable
Following command clears all addresses from the list
System backup delete all all
 System backup enable
System backup enable
 Number of seconds in the ping interval for the group
System backup pinginterval
System backup pinginterval seconds group
Optional, number of a group
 System backup pingsamples
System backup pingsamples
System backup pingsamples samples group
System backup pingsamples 0
 Following command changes the retry period to 60 minutes
System backup retry
System backup retry minutes
Following command changes the retry period to
 System backup stability minutes
System backup stability
System backup successrate
Following command changes the stability period to 5 minutes
 System backup successrate
System blocknetbiosdefault
System backup successrate percentage group
System backup successrate 0
 System community
System blocknetbiosdefault yes no
Sets the default to block all NetBIOS and NetBUI requests
System community snmp community name
 System defaultmodem
System default modem
System delbootpserver
System delbootpserver ipaddr all
 System delbootpserver all
Removes all addresses from the BootP server list
System delbootpserver
System delhostmapping
 System delhttpfilter first ip addr last ip addr lan
System delhttpfilter
System deliproutingtable
First IP address of the range
 System delserver
Following command deletes the virtual routing table Rosa
Deletes an entry created by the system addserver command
System deliproutingtable 192.168.1.5 192.168.1.6 Rosa
 Action One of the following command actions
 First IP address of the client range
System delsnmpfilter
System delsnmpfilter first ip addr last ip addr lan
 System delsyslogfilter firstipaddr last ipaddr lan
System delsyslogfilter
System delsyslogserver
System delsyslogserver ipaddr
 System deltelnetfilter
System deltelnetfilter first ipaddr last ipaddr lan
 Deletes all existing UDP ports
System deludprelay
System history
Last port in the UDP port range to be deleted
 Following is a typical response
System history
 System httpport
System httpport default disabled port
This command sets the Http port to the default value
Cess
 Following is an example of a typical response
System list
System list
System list
 Initiates monitoring activity
System log
System log start stop status
Ture
 System modem
Following command changes the string for the init setting
Following command selects pulse dialing
Enter one of the following options
 System moveiproutingtable
First ipaddra First IP address of the range to be moved
 System msg message
System msg Configured on10/21/98
System msg
Message a,b
 Router name
System name
System name name
Name a,b
 Tions
System onewandialup
System onewandialup on off
 Timer value for RIP information exchange
System riptimer
Passworda,bAuthentication password of the target router
System passwd
 System securemode set
System securemode set enable disable
System securemode list
Security R
 System securemode set cli
Disable Disables secure mode
Typical response indicating the curent mode is displayed
System securemode set cli value
 System securemode set wan
Mode is enabled
System securemode set lan
System securemode set lan trusted untrusted
 System securemode set wan trusted untrusted
System securitytimer
System securitytimer minutes
 Will be applied
System selnat addpolicy
Specifies the destination IP address to which the policy
Policy will be applied
 System selnat delpolicy policy number
System selnat delpolicy
System selnat list
Number of the policy to be deleted
 System snmpport default disabled port
System snmpport
 This command remaps the Snmp port to port
This command sets the Snmp port to the default value
This command disables the existing Snmp port
 System sshport
System supporttrace
 System supporttrace
Debug R/W
System supporttrace
 === Processes === TID Name FL P Bottom Current Size 1IDLE
 DSP
 ATZ
 QA-LABPC
 === Interfaces ===
 NW PRM
 Efficient Networks
 === END of Tech Support Data
 System syslogport default disabled port
System syslogport
 This command remaps the syslog port to port
This command sets the Syslog port to the default value
This command disables the existing Syslog port
System telnetport default disabled port
 This command sets the Telnet port to the default value
Disables the existing Telnet port
Mote access
This command disables the existing telnet port
 Link
System wan2wanforwarding
System wan2wanforwarding on
 Subnets
That the router can provide service to multiple IP
Adds a logical interface onto an Ethernet port so
Deletes a logical interface from an Ethernet port
 Enables IP routing across the Ethernet LAN
Removes a route from the default routing table
Disables IP routing across the Ethernet LAN
Enables and disables Ethernet Firewall Filtering
 Clears the password in a Vrrp attribute record for Vrid
Disables IPX routing across the Ethernet LAN
Enables IPX routing across the Ethernet LAN
Sets the IPX network number for the Ethernet LAN Connection
 Eth ?
Eth ?
 Eth add
Eth add
Eth add port#logical#
 Ethernet interface from which logical port will be deleted
Eth delete
Eth delete port#logical#
Logical interface number to be deleted
 Eth ip addhostmapping
Typical usage
 Ethernet LAN IP address
Eth ip addr
Eth ip addr ipaddr ipnetmask interface
IP network mask
 IP address of the IP gateway
Eth ip addroute
Eth ip addroute ipaddr ipnetmask gateway hops interface
Ethernet interface through which the packet is sent
 Eth ip addserver
 Eth ip bindroute
 Ethernet LAN IP address
 Eth ip defgateway
Eth ip defgateway ipaddr interface
 Eth ip delhostmapping
 Eth ip delroute 10.9.2.0
Eth ip delroute
Eth ip addroute ipaddr ipnetmask interface
Eth ip delroute 10.1.3.0 255.255.255.0
 Eth ip delserver
 MP port
Protocolid a Numerical protocol ID
Hypettext Transfer Protocol Http port
 Disables the forwarding of packets broadcast to a subnet
Eth ip disable
Enables the forwarding of packets broadcast to a subnet
Eth ip directbcast
 Eth ip enable
Eth ip enable
Eth ip disable
 Eth ip filter append
Eth ip filter command type action parameters interface
Eth ip filter
Eth ip filter insert
 Eth ip filter clear
Eth ip filter delete
Eth ip filter flush
Eth ip filter delete type action parameters interface
 Eth ip filter watch
Eth ip filter check
Eth ip filter list
 Protocol TCP UDP Icmp
 Dp Icmp type first dest portlast dest port
 Eth ip filter flush input
 Eth ip firewall on off list
Disables the firewall filtering feature
Eth ip firewall
To be performed
 Eth ip mgmt ipaddr ipnetmask interface
Eth ip mgmt
Ping -I 192.168.1.2
 Eth ip options option on off interface
Eth ip mgmt 10.0.0.1 255.255.255.0 Save Reboot
Eth ip options
 Eth ip ripmulticast ipaddr
Eth ip ripmulticast
OptionMust be one of the following
 Eth ip translate on
Eth ip translate
Eth ip translate on off interface
Eth ip translate off
 Eth ip unbindroute
Eth ip unbindroute ipaddr tablename interface
 Eth ip vrid
Eth ip vrid vrid interface
 Eth ipx addr ipxnet port#
Eth ipx disable
Eth ipx addr
Eth ip vrid 7
 Eth ipx disable port#
Eth ipx enable
This command requires a reboot
Eth ipx enable port#
 Eth list
Eth ipx enable type
Eth ipx frame
Eth list interface
 Global BRIDGING/ROUTING Settings
Eth list
 Eth mtu size interface
Eth mtu
Eth restart
 Interfacea,b Logical Ethernet interface
Eth start
Eth restart interface
Eth start interface
 Eth stop
Interfacea,b Logical Ethernet interface
 Eth vrrp add
Eth vrrp add
Eth vrrp add vrid port#
Eth vrrp add 2
 Eth clear password
Eth vrrp clear password
Eth vrrp clear password vrid port#
 Eth vrrp delete
Eth vrrp delete
Eth vrrp delete vrid port#
 Eth vrrp list port#
Eth vrrp list
Eth vrrp set multicast
 Eth vrrp multicast
Eth vrrp set option
Eth vrrp set multicast ipaddr
 Preempt immediately
Eth vrrp set password
Tribute record was created by the command eth vrrp add
Do not preempt a router with lower priority
 Attribute record was created by the command eth vrrp add
Eth vrrp set password password vrid port#
Password
Eth vrrp set password AbCdEfGh
 Eth vrrp set priority
Eth vrrp set priority priority vrid port#
 Eth vrrp set priority 50 7
Eth vrrp set timeinterval
Eth vrrp set priority 255
 Virtual router ID of the Vrrp attribute record
Eth vrrp set timeinterval seconds vrid port#
Time interval value in seconds
Eth vrrp set timeinterval 2
 Adds the source routing option
Eth ip remsrcrouteopt enable disable
Removes the source routing option. Default value
 Remote Commands
 Remote bindipvirtualroute
 Remote disbridge
 Remote setcompression
 Remote setppppretrytimer
 Adds a remote router entry into the remote router database
Remote ?
Remote add
Remotenamea Name of the tunnel. b
 All MAC addresses
Remote addbridge
Remote addbridge * macaddr remotename
MAC address
 Remote addhostmapping
 Remote addiproute
 Examples
 IPX network number
Remote addipxroute
Remote addIpxRoute ipxne# metric ticks remotename
Network/station
 IPX node address
Name of service
Remote addipxsap
Ers
 Remote addserver
 T120
Smtp
Sntp
Telnet
 Route
Enter a gateway only if you are configuring a MER interface
Remote bindipvirtualroute
Address of a router on the remote LAN
 Disables NetBIOS filtering
Remote blocknetbios
Enables NetBIOS filtering
Remote del
 ATM forum encoding
Remote delatmsnap
Remote delbridge
ITU E164 encoding
 Remote delencryption remotename
Remote delencryption
Deletes encryption files associated with a remote router
 Remote deliproute ipaddr remotename
Remote delhostmapping
Remote deliproute
 Remote delipxroute
Remote delIpxRoute ipxnet remotename
 Remote delipxSap servicename remotename
Remote delipxsap
 Remote delourpasswd remotename
Remote delourpasswd
Remote deloursysname
Remote deloursysname remotename
 Remote delphone
Remote delserver
 Action One of the following command actions
 Remote disauthen
Remote disable
Remote disable remotename
Remote disauthen remotename
 Remote disbridge
Remote disbridge remotename
 Remote enaauthen
Remote enable
Remote enable remotename
Remote enaAuthen remotename
 Remote enablebridge remotename
Remote enabridge
 Remote ipfilter append
Remote ipfilter command type action parameters remotename
Remote ipfilter
Remote ipfilter insert
 Remote ipfilter clear
Remote ipfilter delete
Remote ipfilter flush
Remote ipfilter check
 Remote ipfilter list
For example, the command
Management Protocol error message
Remote ipfilter watch
 Protocol TCP UDP Icmp
 Tcp syn ack noflag rst
 Remote ipfilter flush receive internet
Remote list
Remote list remotename
Remote ipfilter list input internet
 If entered with no parameters, all remote router entries
Are listed
 Remote listbridge
If entered with no parameters, bridge settings for all re
Typical response when entered with no remotename parameter
Mote routers entries are listed
 Dest
Remote listiproutes
Remote listiproutes remotename
Private Yes
 Remote listipxroutes remotename
Remote listipxroutes
Remote listipxsaps
Remote listipxsaps remotename
 Rem listipxsaps hq
Remote listphones
Remote listphones remotename
Rem listphones hq
 Remote restart remotename
Remote restart
Remote setatmnsap
 Nsap
Remote setauthen
Remote setatmnasp atmf e164 partial full nsap remotename
Remote setauthen protocol remotename
 Remote setbod
Remote setBOD in out both remotename
 Remote setbroptions
Default is on
Any traffic, including PPPoE traffic. The default is off
Remote setBrOptions option on off remotename
 Remote setBWthresh threshold remotename
Default is 0, in which case, whenever data transmission
Remote setbwthresh
Occurs, the maximum number of links is allocated
 Remote setencryption
Disables compression negotiation. The default is off
Remote setcompression
They both share a common compression protocol
 Remote setEncryption DESE1KEYDESE2KEY filename remoteName
 Remote setipoptions
Remote setipoptions option on off remotename
 Use periodic echo
Slave mode setting. The default is no
Remote setipslaveppp
Remote setipslaveppp yes no remotename
 Remote setipxaddr
Enables or disables NAT
Remote setiptranslate
Remote setiptranslate on off remotename
 Remote setipxoptions
Remote setIpxOptions ripsap on off remotename
 Remote setmgmtipaddr
Default is
Remote setmaxline
Remote setMaxLine 1 2 remotename
 IP sub-network mask
Remote setmgmtipaddr ipaddr mask remotename
IP address
 Remote setminline
Is allocated for the connection only when needed.
Remote setMinLine 0 PPPoEuser Remote settimer 600 PPPoEuser
Remote setminline minlines remotename
 Remote setmtu 1400 HQ
Remote setmtu
Remote setmtu size remotename
 Remote setoursysname
Remote setourpasswd password remotename
Remote setourpasswd
Remote router
 Remote setpasswd
Remote setpasswd password remotename
Authentication password of the remote router
Remote setphone
 Remote setPhone async isdn 1 2 phone# remotename
Remote setspeed 115200 async 2 backup
Remote setphone async 1 5552000&5554000 backup
 Remote setpppoptions option on off remotename
Desired setting for the option
Remote setpppoptions
Use IPX RIP/SAP protocols
 Value to
Remote setppppretrytimer
Remote setpppretrytimer timervalue remotename
 Bers and bit rates in the remote profile
Remote setprefer
Remote setprefer async fr hsd remotename
Frame Relay
 Remote setPrefer async backup Remote list backup
 Remote setprotocol
 Virtual Path ID number that identifies the link formed by
Remote setpvc
Remote setpvc vpi number*vci number remotename
Virtual path
 IP address of the remote router
Remote setrmtipaddr
Remote setrmtipaddr ipaddr mask remotename
IP network mask of the remote router
 Bit rate to be used for the phone number
Use the default speed
Remote setspeed
Primary phone number
 Target IP address of the WAN connection to the remote rout
Remote setsrcipaddr
Remote setsrcipaddr ipaddr mask remotename
 Number of seconds in the timeout period
Remote settimer
Remote settimer seconds remotename
 Remote start
Remote start remotename
 Total connect time +011148 Total bytes out 15896
Remote stats
Remote stats remotename
 Remote stop
Remote stop remotename
 IP virtual routing table to which the route is removed
Remote unbindipvirtualroute
Remote unbindipvirtualroute ipaddr tablename remotename
Remote unbindIPVirtualRoute 10.1.2.0 Francisco HQ
 This page intentionally left blank
 WAN Interface Commands
 Adsl Commands
Adsl ?
 Adsl restart
Adsl restart
Adsl speed
Adsl speed
 Statistical information displayed
Adsl stats
Adsl stats clear
Adsl speed
 Atm ?
ATM Commands
Atm ?
 Atm pcr
Following command requests the current speed
Typical response when entered with no parameter
Atm pcr cells/second
 Atm speed
Saves the ATM configuration settings
Atm save
Atm save
 Remote setATMTraffic scr mbs remoteName
Remote setatmtraffic
Upstream speed requested in kilobits/second
Atm speed
 Remote setATMtraffic 47 31 HQ
Sustained Cell Rate cells per second
Remote setATMTraffic 0 0 HQ
Remote setATMtraffic 47 1 HQ
 Dmt ?
DMT Commands
Dmt ?
 Dmt link
 Ansi notrellisansi Selects the DMT mode used
Dmt mode
Dmt mode ansi notrellisansi uawg
 Dual-Ethernet Router ETH Commands
 Eth br enable
Eth br enable
Eth br disable
Eth br disable
 Ethernet port number
Eth br options
Eth br options option on off port#
 Eth br options stp off
Eth br options pppoeonly on
 Frame ?
Frame Commands
Frame ?
 Frame cmpplay
Selects bridging mode
Selects bridging mode, default value
Frame lmi
 Frame stats
Frame stats
Displays frame relay statistics
Frame stats
 Frame voice
Frame voice
Displays the voice Dlci for voice routers
 Gti speed
GTI Commands
Gti ?
 Gti stats
Gti stats
Gti speed
Gti speed
 Gti version
Gti version
GTI Adsl Version information is displayed
 Hdsl ?
Hdsl Commands
Hdsl ?
 Hdsl speed
Saves the HDSL-related changes across restarts and reboots
Hdsl save
Hdsl save
 Command example displaying current mode
Sets the terminal operation mode to CPE
Sets the terminal operation mode to CO
Hdsl terminal
 Idsl list
Idsl Commands
Idsl list
Typical response
 Idsl save
Idsl save
Idsl set speed
Idsl set speed 64 128
 Link speed of 64 Kbps
Idsl set switch
Remote setdlci
Link speed of 128 Kbps
 Remote setProtocol ppp fr mer remotename
Remote setprotocol
Frame Relay number identifying the data-link connection
PPP protocol with no encapsulation
 Sdsl ?
Sdsl Commands
Sdsl ?
 Sdsl preact on off
Disables pre-activation
Sdsl preact
CPE end. a
 Sdsl save
Sdsl save
Sdsl speed
Sdsl speed speed noauto
 Sdsl speed
This command example requests a line speed of 1152 Kb/s
See examples above
 Terminal operation is displayed
Sdsl terminal
Sdsl terminal cpe co
Sdsl terminal
 Shdsl Commands
 Shdsl annex
Enables the selected annex
Shdsl ?
Lists the supported Shdsl keywords
 Shdsl list
Lists the current configuration of the G.shdsl interface
Shdsl list
Shdsl list
 Shdsl ratemode
Selects adaptive or fixed rate mode
Shdsl margin
Noise margin in decibels
 Shdsl restart
Selects adaptive mode
Selects fixed mode
Current ratemode is displayed
 Shdsl save
Shdsl save
Shdsl speed
 Speed in Kbps
This command usage requests a line speed of 1096 Kb/s
Shdsl speed speed auto
Selects auto-speed detection
 Shdsl stats
Shdsl stats
Shdsl stats clear
Shdsl stats clear
 Shdsl terminal
Shdsl terminal
 Shdsl ver
Shdsl ver
Displays the G.shdsl version level of the modem firmware
Shdsl ver
 This page intentionally left blank
 Specifies the boot file name kernel and the sub
Allows a BootP request to be processed for a par
Denies processing of a BootP request for a partic
Lists the supported Dhcp keywords
 Enables a subnetwork or a client lease
Specifies the Tftp server boot server
Disables a subnetwork or a client lease
Clears the values from a pool of addresses
 To define a subnetwork
Dhcp ?
Dhcp add
To define a client lease
 Dhcp add
Command usage defining a subnetwork
Command usage defining a client lease
Dhcp add 128 1 4 ipAddress
 Dhcp addrelay ipaddr
Command usage defining, then listing a Dhcp relay server
Dhcp addrelay
Dhcp addrelay
 IP address of the subnetwork lease
Dhcp bootp allow
Dhcp bootp disallow
IP address of the client lease
 Name of the file to boot from
Dhcp bootp file
Dhcp bootp file net ipaddr name
 Dhcp clear addresses
Dhcp bootp tftpserver
Dhcp bootp tftpserver net ipaddr tftpserver ipaddr
IP address of the Tftp server
 Dhcp clear expire
Word records cannot be abbreviated in the command
Dhcp clear all records
Dhcp clear all records
 Dhcp clear valueoption net ipaddr code
Dhcp clear valueoption
Ipaddra IP address of the subnetwork lease
User defined code c
 Example command deleting the user-defined option with code
Example command to delete the defined subnetwork
Example command usage deleting a client lease
Dhcp del
 Dhcp delrelay
Dhcp disable
Dhcp disable all net ipaddr
Dhcp delrelay ipaddr all
 Enables all subnets
Dhcp enable
Disables all subnets
IIP address of the subnetwork lease
 Lists global, subnetwork, and client lease information
Following example command lists global information
Dhcp list
Dhcp list net ipaddr
 Following example command lists information for client
Gateway
 Predefined or user-defined number or keyword
Dhcp list definedoptions
Dhcp list definedoptions code string
Character string
 Efficient Networks
 Dhcp list definedoptions ga
Dhcp list lease
Dhcp list lease
 Dhcp set addresses
Default lease duration is displayed
Dhcp set expire ipaddr hours default infinite
Dhcp set expire
 Dhcp set lease
 Dhcp set mask
Example command sets client lease time to the default value
Example command sets lease time to infinite for this subnet
Dhcp set mask net mask
 Dhcp set otherserver
Dhcp set otherserver net continue stop
 Subnetwork lease
Dhcp set valueoption
Lease
Code specifying the option to be set
 This page intentionally left blank
 Nels, except for the authentication password/se
Configures the router to forward all incoming calls
Display of the current configuration settings for tun
Lists the supported L2TP keywords
 Creates the host name of the remote tunnel
Creates a Chap secret
Creates local router’s host name
Defines the type of L2TP support for the tunnel
 L2tp add
Example command adding the tunnel named PacingAtWork
L2tp ?
Tunnelnamea Name of the tunnel. b
 L2tp call tunnelname
L2tp call
L2tp close
L2tp call PacingAtWork
 L2tp del
 No incoming calls are allowed to be forwarded through
L2tp forward
Forward all incoming calls through the tunnel to an LNS
Tunnel to an LNS
 Tunnelname a Name of the tunnel. b
L2tp list
L2tp list tunnelname
L2tp list
 IP address of the remote LAC or LNS
L2tp set address
L2tp set address ipaddr tunnelname
 L2tp set authen
Enables authentication
Disables authentication
L2tp set chapsecret
 L2tp set hiddenavp
Chap secret used to authenticate the creation of the tunnel
L2tp set dialout
L2tp set dialout yes no tunnelname
 L2tp set ouraddress
Allows the router hide AVPs. Default value
Disables hidden AVPs
Source IP address used for this tunnel
 Lenged by another router
L2tp set ourpassword
L2tp set oursysname
Name of the tunnel
 Name of the local router
L2tp set ourtunnelname
L2tp set remotename
Tunnelnamea,b Name of the tunnel
 L2tp set type
 Lishing the L2TP tunnel
L2tp set wanif
L2tp set wanif remote tunnelname
 L2tp set window
 Name of the remote entry
Remote setl2tpclient
Remote setl2tpclient tunnelnameremotename
 Remote setlns
Remote setLNS tunnelname remotename
 Filter br ?
Lists the supported Bridge Filtering keywords
 Hexadecimal number up to 6 bytes
Filter br add
Byte offset within a packet
Allows forwarding of the packets
 Filter br del 12 8035 deny
Filter br del
Filter br del pos data allow deny
 Filter br list
Filter br list
Lists the bridging filters in the filtering database
Filter br list
 Filter br use
 This page intentionally left blank
 Remote setpppoeservice
 Ifsnumber Session to be closed.a
Pppoe close
Pppoe close ifsnumber
 Pppoe list
Pppoe list
Lists information about the currently active PPPoE sessions
Pppoe list
 This page intentionally left blank
 IKE/IPSEC Commands
 Defines a proposal filtering parameter value for
Defines a peer filtering parameter value for the pol Icy
Defines the pfs filtering parameter value for Policy
Defines a protocol filtering parameter value for
 Lists the defined IKE peers
Message authentication done
Disables a defined IPSec security association SA Entry
Sets the local ID for the IKE peer connection
 Specifies the identifier Spid for the IPSec tunnel
Enables a defined IPSec security association en Try
Clears all IPSec definitions
 Ike ipsec ?
 Ike flush
Commit bit is not set. Default value
Ike commit
Displays help message
 Ike ipsec policies add policyname
Ike ipsec policies add
Ike ipsec policies delete
Policynamea New name for an IPsec policy.b
 Name of an existing IPsec policy. b
Ike ipsec policies disable
Ike ipsec policies disable policyname
Policynamea Name of an existing IPsec policy.b
 Ike ipsec policies enable mypolicy
Ike ipsec policies enable
Ike ipsec policies enable policyname
 Ike ipsec policies list
Ike ipsec policies list IKE IPSec policies mypolicy enabled
Ike ipsec policies list
 IP address allowed to be the destination of the data
Ike ipsec policies set dest
Ike ipsec policies set destport
Name of the IPsec policy to which the destination parameter
 Portnumber Telnet Http Snmp Tftp Policynamea
 Ike ipsec policies set interface
Ike ipsec policies set interface interface all policyname
 Ike ipsec policies set interface backup corporate
Ike ipsec policies set mode
Ike ipsec policies set mode tunnel transport policyname
Ike ipsec policies set interface all mypolicy
 Parameter value is added. a
Name of the IPsec policy to which the encapsulation mode
Ike ipsec policies set peer
Ike ipsec policies set peer peerpame policyname
 Negotiation
Ike ipsec policies set pfs
Ike ipsec policies set pfs 1 2 none policyname
Ike ipsec policies set pfs 2 mypolicy
 Ike ipsec policies set proposal myproposal mypolicy
Ike ipsec policies set proposal
Ike ipsec policies set proposal proposalname policyname
 Ike ipsec policies set protocol
Ue is added. b
 IP address allowed to be the source of the data
Ike ipsec policies set source
Ike ipsec policies set source ipaddress ipmask policyname
Is added. c
 Ike ipsec policies set sourceport
 Ike ipsec policies set translate
Ike ipsec policies set translate on off policyname
 Ike ipsec proposals add
Ike ipsec proposals add proposalname
 Name of an existing IPsec proposal. b
Ike ipsec proposals delete
Ike ipsec proposals delete proposalname
Ike ipsec proposals add myproposal
 Ike ipsec proposals list
Ike ipsec proposals list
Ike ipsec proposals list
 Ike ipsec proposals set ahauth md5 sha1 none proposalname
Use AH encapsulation and authenticate using hash algorithm
Ike ipsec proposals set ahauth
Secure Hash Algorithm-1
 Auth command
Use ESP encapsulation and authenticate using hash algorithm
No ESP encapsulation and no ESP message authentication. If
Ike ipsec proposals set espauth
 Use ESP encapsulation and 168-bit encryption if 3DES is en
Ike ipsec proposals set espenc
Use ESP encapsulation and 56-bit encryption
Abled in the router
 Ike ipsec proposals set lifedata
Compress using the LZS algorithm
Ike ipsec proposals set ipcomp
Ike ipsec proposals set ipcomp none lzs proposalname
 Means unlimited
Ike ipsec proposals set lifetime
Ike ipsec proposals set lifedata kbytes proposalname
Ike ipsec proposals set lifetime seconds proposalname
 Ike peers add peername
Ike peers add
Unlimited
Peernamea New name for an IKE peer.b
 Ike peers delete peername
Ike peers delete
Ike peers list
Peernamea Name of the IKE peer to delete.b
 Ike peers list IKE Peers
Ike peers set address
Ike peers set address ipaddress peername
 Ike peers set address 0.0.0.0 myaggressivepeer
Ike peers set localid
Ike peers set localid aggressivemodeid peername
 Name of the IKE peer whose local ID is specified. c
Ike peers set localidtype
Example Response
Ike peers set localidtype ipaddr domainname email peername
 Ike peers set localidtype domainname myaggressivepeer
 Selects aggressive mode one end can change
Ike peers set mode
Select main mode both ends constant
Name of the IKE peer whose mode is specified. b
 Ike peers set peerid aggressivemodeid peername
Ike peers set peerid
Ike peers set peeridtype
Name of the IKE peer whose peer ID is specified. c
 Ike peers set secret secret peername
Ike peers set secret
Ike peers set peeridtype ipaddr domainname email peername
Ike peers set peeridtype domainname myaggressivepeer
 Ike proposals add ProposalName
Ike proposals add
Ike proposals delete
Proposalnamea New name for an IKE proposal.b
 Ike proposals list
Ike proposals list
Proposalnamea Name of the IKE proposal to delete.b
Ike proposals delete myikeproposal
 No DH group is used
Ike proposals set dhgroup
Ike proposals set dhgroup none 1 2 proposalname
Use DH group
 Ike proposals set lifetime
Use 3DES 168-bit encryption if 3DES encryption is enabled
Ike proposals set encryption
Use DES 56-bit encryption
 Ike proposals set messageauth none md5 sha1 proposalName
Ike proposals set messageauth
Maximum number of seconds before renegotiation
Ike proposals set lifetime 86400 myikeproposal
 Ike proposals set sessionauth
 Ipsec add saname
IPSec Commands
Ipsec add
Sanamea Name for the new IPSec SA.b
 Sanamea Name of the IPSec SA to be disabled.b
Ipsec disable
Disables a defined IPSec security association entry
Ipsec delete
 Sanamea Name of the IPSec SA to be enabled.b
Ipsec enable
Ipsec enable saname
Ipsec disable showrx
 Ipsec flush
Ipsec flush
Ipsec list
Ipsec list saname
 Ipsec list
 Specifies the authentication key for the IPSec SA
Ipsec set authentication
Ipsec set authentication md5 sha1 saname
Ipsec set authkey
 Defines the direction of the IPSec SA
Hexadecimal authentication key
Ipsec set direction
Ipsec set direction inbound outbound saname
 Ipsec set compression none lzs saname
Ipsec set compression
Ipsec set enckey
Specifies the encryption key for the IPSec SA
 Ipsec set encryption
 Defines the IP address of the IP gateway of the IPSec SA
Ipsec set gateway
Ipsec set ident
Ipaddressa IP address of the IP gateway
 Spid for the IPSec tunnel
Ipsec set mode
Ipsec set mode tunnel transport saname
Name of the IPSec SA. b
 AH authentication
Ipsec set service
Ipsec set service esp ah both saname
Use Both ESP encryption and authentication
 Displays the current voice rate and encoding type
Lists the top-level voice or dsp commands
Keywords and a brief description of their function
Clears the L2 control channel statistics
 Dsp ? / voice ?
Dsp voice ?
 Selects the voice encoding method for all voice ports
Typical response when entered with no parameters
Dsp ecode
Sets encoding method to alaw
 Is displayed
Dsp jitter
Dsp jitter milliseconds
Optional, Length of jitter buffer in milliseconds
 Dsp provision
 Dsp vr
Voice port to configure
Dsp save
Dsp save
 Voice profile profile
Voice l2clear
Voice l2stats
Voice l2stats
 Voice l2stats
Example response confirming the configuration change
Voice profile
Voice profile
 Mode
Voice refreshcas
Voice refreshcas active always
An idle state
 This page intentionally left blank
 Attempting the next radius server, if configured
Lists the supported radius commands and key
Deletes a configured radius server entry
Words
 Rad ?
Rad ?
Rad deleteserver
Rad deleteserver integer
 Rad list secret
Rad list secret
Rad list secret
 Rad list server
Rad list server
Rad list server
 Rad set retries
Radius set server
 Radius set secret
Radius set timeout
Authentication secret for the specified radius server
Number of seconds between retry attempts
 Deletes an access path from the specified user ac
Adds an access privilege to for the specified user
Configures the managements class with read-only
Disables an existing user account
 Admin R
Displays the contents of the user account data Base
Lists the characteristics of the pre-defined user Templates
User ?
 Adds user access through the WAN connection
User add access
Adds user access through a LAN connection
Adds user access through the console serial port
 User add class
 User add user username password template enable disable
User add user
 Removes user access through a LAN connection
User delete access
User delete access lan wan console username
Removes user access through the WAN connection
 User delete class mgtclass read write username
Enabled for read-only
User delete class
Must be one of the following
 User delete user
User delete class admin write Admin1
User delete class voice read Admin1
User delete user username1 username2 usernameN
 User delete user Admin1 staff001
User disable
User disable username
User disable VoiceAdmin
 User enable Admin1
User enable
User enable username
User list
 User list
 User list lookup
User list lookup
User list template
Displays the pre-defined user template information
 Efficient Networks
 User set lookup
 User setpassword username newpassword
User set password
Changes the password of an existing user account
Newpassworda New password for the user account
 This page intentionally left blank
 Deletes a feature key from the key-enabled feature
Lists the supported key commands
Validates and adds a key to the key-enabled fea
Ture database
 Unrevokes a revoked feature key
Disables a key-enabled feature
Revokes a key-enabled feature key
Updates the expiration date of an expired feature Key
 Key add keystring
Example response when adding a key for L2TP
Key add
 Example response when deleting the key for Radius
Key delete featurename
Featurenamea Name of the feature to be deleted.b
Key delete
 Featurename Name of the feature to be disabled.a
Key disable
Key disable featurename
Key disable l2tp
 Featurenamea Name of the feature to be enabled.b
Key enable
Key enable featurename
Key list
 Installed
Typical response with the -lparameter is shown below
 Key revoke
Key revoke feature
Featurenamea Name of the feature key to be revoked
Key unrevoke
 Keystringa Key string for the feature
Key update
Key update keystring
Key unrevoke keystring
 This page intentionally left blank
 Enables or disables transmission of unsolicited
Disables Snmp access from the specified inter
Enables Snmp access from the specified inter
Sets an authentication password for an Snmp
 Snmp ?
Snmp ?
Snmp addsnmpfilter
 Snmp addstrapdest ip addr
Snmp addtrapdest
Snmp addsnmpfilter first ip addr last ip addr lan
IP address of the trap manager
 Snmp community name
Snmp community
Snmp community snmp community name
Following example sets the Snmp community name to iads
 Snmp delsnmpfilter
Snmp delsnmpfilter first ip addr last ip addr lan
 Snmp deltrapdest
Snmp disablesnmpif
Snmp disablesnmpif wanlan
Snmp deltrapdest ip addr
 Snmp enablesnmpif wanlan
Snmp enablesnmpif
Wan lan Interface from which Snmp access will be disabled
Wan lan Interface from which Snmp access will be enabled
 Snmp list
Snmp settrapenable
Snmp settrapenable on off
Snmp list
 Snmp Manager authentication password
Enables trap event message transmission
Current password
Example response when a password parameter is entered
 Snmp snmpport default disabled port
Snmp snmpport
 Enables or disables the stateful firewall function
Displays the current stateful firewall settings
Configured rules
Due to firewall rules that when exceeded, will log
 Sets the threshold value for the number of SYN
Firewall ?
Sets the threshold value for the number of Icmp
Sets the threshold value for the number of UDP
 Firewall allow protocol application parameters
Packets must match the assigned application characteristics
Firewall allow
Packet must have the specified protocol
 Examples
 Firewall allow -a FTP -sa 192.168.1.34 -d out
Firewall -a netmeeting -sa 192.168.1.23 -d out
 Indicates the specified rule is in the deny rules list
Firewall clearcounter
Indicates the specified rule is in the allow rules list
Firewall clearcounter 13 allow
 Firewall clearcounter all
Firewall clearcounter all
Firewall delete
 Firewall delete all allow deny
Example command deletes rule 3 from the deny rules list
Firewall delete all
Will delete all rules from the allow rules list
 Firewall delete all allow
Firewall deny
Firewall deny protocol application parameters
 Both
 Firewall list allow deny
Command entered with no parameters
Firewall list
Optional parameter will display only allow rules list
 Firewall modify allow deny number parameter
Command entered with the optional allow parameter
Firewall modify
Following identifies the firewall rule to be modified
 Modifies the source IP address or specified address range
Specifies the protocol a packet must have
Modifies the firewall rule type
Modifies the specified source ip mask
 Firewall set
Enables the firewall as currently configured
Disables the firewall
Firewall setdroppktthreshold
 Threshold value in packets per seconds
Firewall seticmpfloodthreshold
Firewall seticmpfloodthreshold number
Firewall setdroppkthreshold
 Firewall setsynfloodthreshold
Firewall setsynfloodthreshold number
 Firewall setudpfloodthreshold number
Firewall setudpfloodthreshold
Firewall viewdroppkts
Firewall viewdroppkts number
 Typical response using the optional number parameter
Firewall viewdroppkts
 No messages are printed to the console or Syslog server
Firewall watch
Firewall watch on off
 This page intentionally left blank
 Configured SSH port
List the supported SSH sub-commands
Displays the current SSH configuration with the ex
Sets the idle timeout period for SSH connections
 Ssh ?
Ssh ?
Ssh keygen
Generates the Private-Public key-pair for the local server
 Ssh list
Ssh list
Ssh load privatekey
Ssh load publickey tftp@server-addrpriv-key-file
 Key file to load
Ssh load publickey
Ssh load publickey TFTP@server-addrpub-key-file
Ssh load privatekey tftp@192.168.13.174mykey
 Sets the types of encryption the SSH connections will use
Multiple types are allowed on the command line
Ssh set encryption
DES 56-bit encryption
 Idle timeout period in seconds
Ssh set idletimeout
Ssh set idletimeout seconds
Ssh set keepalive enable disable
 Keepalive messages are sent
Ssh set keepalive enable
Ssh set mac
Ssh set mac md5 sha1
 Ssh set rekey
Enables and disables SSH server connections
Ssh set status enable disable
Ssh set status
 Ssh set status enable
Allows SSH connections
 This page intentionally left blank
 Services field
List the supported QoS commands and a brief de
Enables and disables marking of the differentiated
Scription of their functions
 Qos append
Saves the current QoS configuration and QoS pol Icies
Qos ?
Defines a proposal filtering parameter value for Policy
 Policy namea Specifies the QoS policy name to be added
Specifies that all disabled QoS policies will be deleted
Qos del
Specifies the QoS policy to be deleted
 Qos diffserv
Qos disable
Example command that deletes all disabled QoS policies
QOS will mark Diffserv field in IP header
 Qos enable policy name
Qos enable
Policy namea Specifies the QoS policy to be disabled
Specifies the QoS policy to be enabled
 Qos del policy name insert before this policy
Qos insert
Qos list
Qos list policy name
 Qos list mypolicy3
LOW
 Qos move policy name move to before this policy
Qos move
Qos movetoend
Specifies the QoS policy to be moved
 Qos off
Qos off
 Qos save
Saves the current QoS feature and policy configurations
Qos on
Qos on
 Qos set parameter policy name
Specifies the priority, with normal the default value
Qos set
 Specifies the incoming code point
Specifies the outgoing code point
 Queue
Qos setweight
Qos setweight highmeduimnormallow weight
 This page intentionally left blank
 Disables the specified Ethernet port
Lists the supported Switch sub-commands
Specifies the aging time of the switch
Configures port traffic mirroring
 Switch ? help
Switch ?
Switch agetime
Switch agetime seconds
 Ethernet port to be disabled
Switch block
Switch block port
Switch block
 Switch mirror capture 6 switch mirror map Switch mirror map
Switch mirror
Switch mirror on off capture port map port unmap port
 Switch status
Switch status
Displays the current port states for the Ethernet switch
Switch mirror capture
 Ethernet port to be enabled
Switch unblock
Switch unblock port
Switch status