For feedback and comments:
documentation.feedback@alcatel-lucent.com

Table of Contents Previous Next PDF


IP Tunnel Command Reference
Configuration Commands
 
Hardware Commands
 
config
card slot-number
mda mda-slot
mda-type isa-tunnel
 
ISA Commands
config
tunnel-group tunnel-group-id [create]
no tunnel-group tunnel-group-id
backup mda-id
description description-string
mda mda-id
[no] mda
primary mda-id
reassembly [wait-msecs]
IPSec Commands
config
cert-profile profile-name [create]
no cert-profile profile-name
entry entry-id [create]
no entry entry-id
cert cert-filename
key key-filename
trust-anchor-profile name [create]
trust-anchor ca-profile-name
ts-list list-name [create]
no ts-list list-name
entry entry-id [create]
no entry entry-id
address prefix ip-prefix/ip-prefix-len
address from begin-ip-address to end-ip-address
config
ike-policy ike-policy-id [create]
no ike-policy ike-policy-id
auth-algorithm auth-algorithm
auth-method {psk|plain-psk-xauth|cert-auth|psk-radius|cert-radius|eap|auto-eap-radius}
auto-eap-method {psk|cert|psk-or-cert}
description description-string
dh-group {1 2 | 5 | 14 | 15}
dpd [interval interval] [max-retries max-retries] [reply-only]
encryption-algorithm {des | 3des | aes128 | aes192 | aes256}
ike-mode {main | aggressive}
ipsec-lifetime ipsec-lifetime
isakmp-lifetime isakmp-lifetime
nat-traversal [force] [keep-alive-interval keep-alive-interval] [force-keep-alive]
own-auth-method {psk | cert | eap-only}
pfs [dh-group {1 | 2 | 5 | 14 | 15}]
config
ipsec-transform transform-id [create]
no ipsec-transform transform-id
esp-auth-algorithm {null | md5 | sha1| sha256 | sha384 | sha512| aes-xcbc}
esp-encryption-algorithm {null | des | 3des | aes128 | aes192 | aes256}
 
config
[no] static-sa sa-name
authentication auth-algorithm ascii-key ascii-string
authentication auth-algorithm hex-key hex-string [hash|hash2]
description description-string
direction ipsec-direction
protocol ipsec-protocol
spi spi
 
config
tunnel-template ipsec template identifier [create]
no tunnel-templateipsec template identifier
description description-string
packet-too-big number [10..1000] seconds [1..60]
ip-mtu octets
replay-window {32 | 64 | 128 | 256 | 512}
transform transform-id [transform-id...(up to 4 max)]
 
config
radius-server-policy radius-server-policy-name
update-interval minutes [jitter seconds]
password password [hash|hash2]
radius-server-policy radius-server-policy-name
 
Service Configuration Commands
 
IES Commands
config
ies service-id [customer customer-id] [vpn vpn-id]
[no] interface ip-int-name [tunnel]
[no] sap sap-id [create]
ip-tunnel ip-tunnel-name [create]
backup-remote-ip ip-address
delivery-service {service-id | svc-name}
description description-string
dscp dscp-name
[no] dest-ip ip-address
gre-header send-key send-key receive-key receive-key
ip-mtu octets
reassembly [wait-msecs]
remote-ip ip-address
source ip-address
cert filename
cert-profile profile
key filename
default-result {revoked|good}
primary {ocsp|crl}
secondary {ocsp|crl}
trust-anchor ca-profile-name
trust-anchor ca-profile-name
default-secure-service service-id ipsec-interface ip-int-name
default-tunnel-template ipsec template identifier
[no] dhcp
gi-address ip-address
server ip-address [ip-address...(upto 8 max)] router router-instance
server ip-address [ip-address...(upto 8 max)] service-name service-name
ike-policy ike-policy-id
address-source router router-instance dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
address-source service-name service-name dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
address-source router router-instance dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
address-source service-name service-name dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
local-id {ipv4 | fqnd| ipv6} [value [255 chars max]]
ts-negotiation ts-list list-name
VPRN Commands
config
vprn service-id [customer customer-id]
no vprn service-id
security-policy security-policy-id [create]
no security-policy security-policy-id
entry entry-id [create]
no entry entry-id
local-ip {ip-prefix/prefix-length | ip-prefix netmask | any}
local-v6-ip ipv6-prefix/prefix-length
remote-ip {ip-prefix/prefix-length | ip-prefix netmask | any}
remote-v6-ip ipv6-prefix/prefix-length
[no] interface ip-int-name
address ipv6-address/prefix-length [eui-64] [preferred] [track-srrp srrp-instance]
no address ipv6-address/prefix-length
link-local-address ipv6-address [preferred]
config
vprn service-id [customer customer-id]
no vprn service-id
[no] interface ip-int-name [create] [tunnel]
[no] sap sap-id [create]
ip-tunnel ip-tunnel-name [create]
backup-remote-ip ip-address
delivery-service {service-id | svc-name}
description description-string
dscp dscp-name
[no] dest-ip ip-address
ip-mtu octets
reassembly [wait-msecs]
remote-ip ip-address
source ip-address
cert filename
cert-profile profile
key filename
default-result {revoked|good}
primary {ocsp|crl}
secondary {ocsp|crl}
trust-anchor ca-profile-name
default-secure-service service-id ipsec-interface ip-int-name
default-tunnel-template ipsec template identifier
[no] dhcp
gi-address ip-address
server ip-address [ip-address...(upto 8 max)] router router-instance
server ip-address [ip-address...(upto 8 max)] service-name service-name
ike-policy ike-policy-id
address-source router router-instance dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
address-source service-name service-name dhcp-server local-dhcp4-svr-name pool dhcp4-server-pool
address-source router router-instance dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
address-source service-name service-name dhcp-server local-dhcp6-svr-name pool dhcp6-server-pool
local-id {ipv4 | fqdn |ipv6} [value [255 chars max]]
ts-negotiation ts-list list-name
ipsec-tunnel ipsec-tunnel-name [create]
no ipsec-tunnel ipsec-tunnel-name
bfd-enable service service-id interface interface-name dst-ip ip-address
description description-string
[no] dest-ip ip-address
cert filename
cert-profile profile
key filename
default-result {revoked|good}
primary {ocsp|crl}
secondary {ocsp|crl}
trust-anchor ca-profile-name
ike-policy ike-policy-id
local-id {ipv4 | fqdn |ipv6} [value [255 chars max]]
transform transform-id [transform-id...(up to 4 max)]
packet-too-big number [10..1000] seconds [1..60]
ip-mtu octets
local-gateway-address ip-address peer ip-address delivery-service service-id
local-id type type [value <[255 chars max]>
security-association security-entry-id authentication-key authentication-key encryption-key encryption-key spi spi transform transform-id direction {inbound|outbound}
no security-association security-entry-id direction {inbound|outbound}
replay-window replay-window-size
security-policy security-policy-id
IPSec Mastership Election Commands
configure
peer ip-address [create]
no peer ip-address
discovery-interval interval-secs [boot interval-secs]
tunnel-group tunnel-group-id [create]
no tunnel-group tunnel-group-id
peer-group tunnel-group-id
priority priority
 
Related Commands
config
protocol protocol [all | instance instance]
state state
config
[no] ipsec
tunnel-group tunnel-group-id sync-tag tag-name [create]
no tunnel-group tunnel-group-id
 
CMPv2 Commands
config
ca-profile name [create]
http-version [1.0|1.1]
key password [hash|hash2] reference reference-number
no key reference reference-number
url url-string [service-id service-id]
revocation-check {crl | crl-optional}
 
admin
cert-request ca ca-profile-name current-key key-filename current-cert cert-filename [hash-alg hash-algorithm] newkey key-filename subject-dn subject-dn [domain-name <[255 chars max]> [ip-addr <ip-address|ipv6-address>] save-as save-path-of-result-cert
clear-request ca ca-profile-name
initial-registration ca ca-profile-name key-to-certify key-filename protection-alg {password password reference ref-number | signature [cert cert-file-name [send-chain [with-ca ca-profile-name]]] [protection-key key-file-name] [hash-alg {md5 | sha1 | sha224 | sha256 | sha384 | sha512}]} subject-dn dn [domain-name <[255 chars max]> [ip-addr <ip-address|ipv6-address>] save-as save-path-of-result-cert
key-update ca ca-profile-name newkey key-filename oldkey key-filename oldcert cert-filename [hash-alg hash-algorithm] save-as save-path-of-result-cert
poll ca ca-profile-name
show-request [ca ca-profile-name]
 
 
 
 
 
 
Auto-Update Commands
config
ipv6-source-address ipv6-address
retry count
router router-instance
timeout seconds
 
config
ca-profile name [create]
url-entry entry-id [create]
no url-entry entry-id
url url
periodic-update-interval [days days] [hrs hours] [min minutes] [sec seconds]
pre-update-time [days days] [hrs hours] [min minutes] [sec seconds]
pre-update-time schedule-type
schedule-type schedult-type
 
admin
crl-update ca ca-profile-name
 
Show Commands
show
cert-profile name association
cert-profile name entry [1..8]
certificate filename association
gateway name name
gateway [service service-id]
gateway tunnel [ip-address:port]
gateway name name tunnel ip-address:port
gateway name name tunnel
gateway [name name] tunnel state state
gateway [name name] tunnel idi-value idi-prefix
gateway tunnel count
ike-policy ike-policy-id
security-policy service-id [security-policy-id]
static-sa name sa-name
static-sa spi spi
transform [transform-id]
trust-anchor-profile trust-anchor-profile association
trust-anchor-profile [trust-anchor-profile ]
ts-list [list-name]
ts-list list-name association
ts-list list-name entry [1..32]
tunnel ipsec-tunnel-name
tunnel-template [ipsec template identifier]
mc-ipsec peer ip-address tunnel-group tunnel-group-id
mc-ipsec peer ip-address
 
 
Debug Commands
debug
[no] gateway name name tunnel ip-address[:port] [nat-ip nat-ip[:port]] [detail]
tunnel ipsec-tunnel-name [detail]
no tunnel ipsec-tunnel-name
[no] certificate filename
[no] ca-profile profile-name
 
 
 
Tools Commands
tools
force-switchover tunnel-group local-group-id [now][to {master|standby}]