Table M.105. ppp-dump: PPP dump format
| Value | Description | 
| default | Mixed hex/decode | 
| decoded | Decoded only | 
| decoded+raw | Decoded + raw | 
| raw | Raw hex | 
Table M.106. autoloadtype: Type of s/w auto load
| Value | Description | 
| false | Do no auto load | 
| factory | Load factory releases | 
| beta | Load beta test releases | 
| alpha | Load test releases | 
Table M.107. config-access: Type of access user has to config
| Value | Description | 
| none | No access unless explicitly listed | 
| view | View only access (no passwords) | 
| read | Read only access (with passwords) | 
| demo | Full view and edit access but can only test config, not save | 
| test | Full view and edit access but must test save config first | 
| full | Full view and edit access | 
User login level - commands available are restricted according to assigned level.
Table M.108. user-level: User login level
| Value | Description | 
| NOBODY | Unknown or not logged in user | 
| GUEST | Guest user | 
| USER | Normal unprivileged user | 
| ADMIN | System administrator | 
| DEBUG | System debugger | 
Log severity - different loggable events log at different levels.
Table M.111. syslog-severity: Syslog severity
| Value | Description | 
| EMERG | System is unstable | 
| ALERT | Action must be taken immediately | 
| CRIT | Critical conditions | 
| ERR | Error conditions | 
| WARNING | Warning conditions | 
| NOTICE | Normal but significant events | 
| INFO | Informational | 
| DEBUG | Debug level messages | 
| NO-LOGGING | No logging | 
Syslog facility, usually used to control which log file the syslog is written to.
Table M.112. syslog-facility: Syslog facility
| Value | Description | 
| KERN | Kernel messages | 
| USER | User level messges | 
| Mail system | |
| DAEMON | System Daemons | 
| AUTH | Security/auth | 
| SYSLOG | Internal to syslogd | 
| LPR | Printer | 
| NEWS | News | 
| UUCP | UUCP | 
| CRON | Cron deamon | 
| AUTHPRIV | private security/auth | 
| FTP | File transfer | 
| 12 | Unused | 
| 13 | Unused | 
| 14 | Unused | 
| 15 | Unused | 
| LOCAL0 | Local 0 | 
| LOCAL1 | Local 1 | 
| LOCAL2 | Local 2 | 
| LOCAL3 | Local 3 | 
| LOCAL4 | Local 4 | 
| LOCAL5 | Local 5 | 
| LOCAL6 | Local 6 | 
| LOCAL7 | Local 7 | 
Table M.113. http-mode: HTTP/HTTPS security mode
| Value | Description | 
| http-only | No HTTPS access | 
| http+https | Both HTTP and HTTPS access | 
| https-only | No HTTP access | 
| redirect-to-https | HTTP accesses are redirected to use HTTPS | 
| redirect-to-https-if-acme | HTTP accesses are redirected to use HTTPS if ACME set up for hostname | 
| redirect-to-https-except-trusted | HTTP accesses are redirected to use HTTPS (except trusted IPs) | 
Table M.114. radiuspriority: Options for controlling platform RADIUS response priority tagging
| Value | Description | 
| equal | All the same priority | 
| strict | In order specified | 
| random | Random order | 
| calling | Hashed on calling station id | 
| called | Hashed on called station id | 
| username | Hashed on full username | 
| user | Hashed on username before @ | 
| realm | Hashed on username after @ | 
| prefix | Hashed on username initial letters and numbers only | 
Table M.115. radiustype: Type of RADIUS server
| Value | Description | 
| authentication | Authentication server | 
| accounting | Accounting server | 
| control | Allowed to send control (CoA/DM) | 
Table M.116. month: Month name (3 letter)
| Value | Description | 
| Jan | January | 
| Feb | February | 
| Mar | March | 
| Apr | April | 
| May | May | 
| Jun | June | 
| Jul | July | 
| Aug | August | 
| Sep | September | 
| Oct | October | 
| Nov | November | 
| Dec | December | 
Table M.117. day: Day name (3 letter)
| Value | Description | 
| Sun | Sunday | 
| Mon | Monday | 
| Tue | Tuesday | 
| Wed | Wednesday | 
| Thu | Thursday | 
| Fri | Friday | 
| Sat | Saturday | 
Table M.118. port: Physical port
| Value | Description | 
| 0 | Port 0 (not valid) (deprecated) | 
| 1 | Port 1 | 
| 2 | Port 2 | 
| 3 | Port 3 | 
| 4 | Port 4 | 
Physical port crossover configuration.
Table M.119. Crossover: Crossover configuration
| Value | Description | 
| auto | Crossover is determined automatically | 
| MDI | Force no crossover | 
Table M.120. LinkSpeed: Physical port speed
| Value | Description | 
| 10M | 10Mbit/sec | 
| 100M | 100Mbit/sec | 
| 1G | 1Gbit/sec | 
| auto | Speed determined by autonegotiation | 
Table M.121. LinkDuplex: Physical port duplex setting
| Value | Description | 
| half | Half-duplex | 
| full | Full-duplex | 
| auto | Duplex determined by autonegotiation | 
Table M.122. LinkFlow: Physical port flow control setting
| Value | Description | 
| none | No flow control | 
| symmetric | Can support two-way flow control | 
| send-pauses | Can send pauses but does not support pause reception | 
| any | Can receive pauses and may send pauses if required | 
Table M.123. LinkClock: Physical port Gigabit clock master/slave setting
| Value | Description | 
| prefer-master | Master status negotiated; preference for master | 
| prefer-slave | Master status negotiated; preference for slave | 
| force-master | Master status forced | 
| force-slave | Slave status forced | 
Table M.124. LinkLED: LED settings
| Value | Description | 
| Link/Activity | On when link up; blink when Tx or Rx activity | 
| Link1000/Activity | On when link up at 1G; blink when Tx or Rx activity | 
| Link100/Activity | On when link up at 100M; blink when Tx or Rx activity | 
| Link10/Activity | On when link up at 10M; blink when Tx or Rx activity | 
| Link100-1000/Activity | On when link up at 100M or 1G; blink when Tx or Rx activity | 
| Link10-1000/Activity | On when link up at 10M or 1G; blink when Tx or Rx activity | 
| Link10-100/Activity | On when link up at 10M or 100M; blink when Tx or Rx activity | 
| Duplex/Collision | On when full-duplex; blink when half-duplex and collisions detected | 
| Collision | Blink when collisions detected | 
| Tx | Blink when Tx activity | 
| Rx | Blink when Rx activity | 
| Off | Permanently off | 
| On | Permanently on | 
| Link | On when link up | 
| Link1000 | On when link up at 1G | 
| Link100 | On when link up at 100M | 
| Link10 | On when link up at 10M | 
| Link100-1000 | On when link up at 100M or 1G | 
| Link10-1000 | On when link up at 10M or 1G | 
| Link10-100 | On when link up at 10M or 100M | 
| Duplex | On when full-duplex | 
Table M.125. LinkPower: PHY power saving options
| Value | Description | 
| none | No power saving | 
| link-down | Power save only when link is down | 
| link-up | Power save only when link is up | 
| full | Full power saving | 
Table M.126. LinkFault: Link fault type to send
| Value | Description | 
| false | No fault | 
| true | Send fault | 
| off-line | Send offline fault (1G) | 
| ane | Send ANE fault (1G) | 
Table M.127. sampling-protocol: Sampling protocol
| Value | Description | 
| sflow | Use sFlow protocol | 
| ipfix-psamp | Use IPFIX/PSAMP protocol | 
| ipfix-legacy | Use legacy (Cisco-style) IPFIX | 
Table M.128. trunk-mode: Trunk port mode
| Value | Description | 
| false | Not trunking | 
| random | Random trunking | 
| l2-hash | L2 hashed trunking | 
| l23-hash | L2 and L3 hashed trunking | 
| l3-hash | L3 hashed trunking | 
IPv6 route announcement mode and level
Table M.129. ramode: IPv6 route announce level
| Value | Description | 
| false | Do not announce | 
| low | Announce as low priority | 
| medium | Announce as medium priority | 
| high | Announce as high priority | 
| true | Announce as default (medium) priority | 
Table M.130. dhcpv6control: Control for RA and DHCPv6 bits
| Value | Description | 
| false | Don't set bit or answer on DHCPv6 | 
| true | Set bit but do not answer on DHCPv6 | 
| dhcpv6 | Set bit and do answer on DHCPv6 | 
BGP mode defines the default advertisement mode for prefixes, based on well-known community tags
Table M.131. bgpmode: BGP announcement mode
| Value | Description | 
| false | Not included in BGP at all | 
| no-advertise | Not included in BGP, not advertised at all | 
| no-export | Not normally exported from local AS/confederation | 
| local-as | Not exported from local AS | 
| no-peer | Exported with no-peer community tag | 
| true | Exported as normal with no special tags added | 
Table M.132. sampling-mode: Sampling mode
| Value | Description | 
| off | Don't perform sampling | 
| ingress | Sample incoming traffic | 
| egress | Sample outgoing traffic | 
| both | Sample incoming and outgoing traffic | 
Table M.133. sfoption: Source filter option
| Value | Description | 
| false | No source filter checks | 
| blackhole | Check replies have any valid route | 
| true | Check replies down same port/vlan | 
Table M.134. pppoe-mode: Type of PPPoE connection
| Value | Description | 
| client | Normal PPPoE client connects to access controller | 
| bras-l2tp | PPPoE server mode linked to L2TP operation | 
Table M.135. pppoe-calling: Additional prefix on PPPoE calling ID
| Value | Description | 
| none | None | 
| mac | MAC | 
| vlan | VLAN | 
| mac-vlan | MAC and VLAN | 
Table M.136. ipsec-type: IPsec encapsulation type
| Value | Description | 
| AH | Authentication Header | 
| ESP | Encapsulating Security Payload | 
Table M.137. ipsec-auth-algorithm: IPsec authentication algorithm
| Value | Description | 
| null | No authentication | 
| HMAC-MD5 | HMAC-MD5-96 (RFC 2403) | 
| HMAC-SHA1 | HMAC-SHA1-96 (RFC 2404) | 
| AES-XCBC | AES-XCBC-MAC-96 (RFC 3566) | 
| HMAC-SHA256 | HMAC-SHA-256-128 (RFC 4868) | 
Table M.138. ipsec-crypt-algorithm: IPsec encryption algorithm
| Value | Description | 
| null | No encryption (RFC 2410) | 
| 3DES-CBC | 3DES-CBC (RFC 2451) | 
| blowfish | Blowfish CBC (RFC 2451) with 16-byte key | 
| blowfish-192 | Blowfish CBC (RFC 2451) with 24-byte key | 
| blowfish-256 | Blowfish CBC (RFC 2451) with 32-byte key | 
| AES-CBC | AES-CBC (Rijndael) (RFC 3602) with 16-byte key | 
| AES-192-CBC | AES-CBC (Rijndael) (RFC 3602) with 24-byte key | 
| AES-256-CBC | AES-CBC (Rijndael) (RFC 3602) with 32-byte key | 
Peer type controls many of the defaults for a peer setting. It allows typical settings to be defined with one attribute that reflects the type of peer.
Table M.139. peertype: BGP peer type
| Value | Description | 
| normal | Normal BGP operation | 
| transit | EBGP Mark received as no-export | 
| peer | EBGP Mark received as no-export, only accept peer AS | 
| customer | EBGP Allow export as if confederate, only accept peer AS | 
| internal | IBGP allowing own AS | 
| reflector | IBGP allowing own AS and working in route reflector mode | 
| confederate | EBGP confederate | 
| ixp | Internet exchange point peer on route server, soft routes EBGP only | 
Table M.140. radius-nas: NAS IP to report
| Value | Description | 
| false | Local LNS IP (deprecated) | 
| lns | Local LNS IP | 
| both | Send NAS IP twice (LAC then LNS) | 
| lac | Remote LAC IP | 
| true | Remote LAC IP (deprecated) | 
Table M.141. ike-authmethod: authentication method
| Value | Description | 
| Secret | Shared Secret | 
| Certificate | X.509 certificate | 
| EAP | Use EAP for authentication | 
Table M.142. ike-mode: connection setup mode
| Value | Description | 
| Wait | Wait for peer to initiate the connection | 
| On-demand | Bring up when needed for traffic | 
| Immediate | Always attempt to bring up connection | 
Table M.143. ike-PRF: IKE Pseudo-Random Function
| Value | Description | 
| HMAC-MD5 | HMAC-MD5 | 
| HMAC-SHA1 | HMAC-SHA1 | 
| AES-XCBC-128 | AES-XCBC with 128-bit key | 
| HMAC-SHA256 | PRF-HMAC-SHA-256 (rfc4868) | 
Table M.144. ike-DH: IKE Diffie-Hellman group
| Value | Description | 
| none | No D-H negotiation (only used with AH/ESP) | 
| MODP-1024 | 1024-bit Sophie Germain Prime MODP Group | 
| MODP-2048 | 2048-bit Sophie Germain Prime MODP Group | 
Table M.145. ike-ESN: IKE Sequence Number support
| Value | Description | 
| ALLOW-ESN | Allow Extended Sequence Numbers (64 bits) | 
| ALLOW-SHORT-SN | Allow short sequence numbers (32 bits) | 
Table M.146. ipsec-encapsulation: Manually keyed IPsec encapsulation mode
| Value | Description | 
| tunnel | IPsec tunnel | 
| transport | IPsec transport | 
Manual setting control for profile
Table M.147. switch: Profile manual setting
| Value | Description | 
| false | Profile set to OFF | 
| true | Profile set to ON | 
| control-switch | Profile set based on control switch on home page | 
Table M.148. dynamic-graph: Type of dynamic graph
| Value | Description | 
| false | No dynamic graph | 
| ip | Use source IP address | 
| mac | Use source MAC address | 
Table M.149. firewall-action: Firewall action
| Value | Description | 
| continue | Continue rule-set checking | 
| accept | Allow but no more rule-set checking | 
| reject | End all rule checking now and set to send ICMP reject | 
| drop | End all rule checking now and set to drop | 
| ignore | End all rule checking and ignore (drop) just this packet, not making a session | 
Table M.150. voip-format: Number presentation format
| Value | Description | 
| international | Full international number | 
| int-no-plus | International without leading plus | 
| national | With nat/int prefix | 
| local | Local number/extension | 
| transparent | Unchanged | 
| block | Do not use for calls | 
Table M.151. uknumberformat: Number formatting option
| Value | Description | 
| false | Don't format numbers for display | 
| true | Format numbers for display with spacing | 
| replace-zero | Format numbers for display with spacing and replacing zeros - may look clearer on some CLI devices | 
Table M.152. recordoption: Recording option
| Value | Description | 
| false | Don't automatically record calls | 
| in-only | Automatically record incoming calls | 
| out-only | Automatically record outgoing calls | 
| true | Automatically record all calls | 
Table M.153. ring-group-order: Order of ring
| Value | Description | 
| strict | Order in config | 
| random | Random order | 
| cyclic | Cycling from last call | 
| oldest | Oldest used phone first |