M.3. Data types

M.3.1. user-level: User login level

User login level - commands available are restricted according to assigned level.

Table M.119. user-level: User login level

ValueDescription
NOBODYUnknown or not logged in user
GUESTGuest user
USERNormal unprivileged user
ADMINSystem administrator
DEBUGSystem debugger

M.3.2. ppp-dump: PPP dump format

Table M.120. ppp-dump: PPP dump format

ValueDescription
defaultMixed hex/decode
decodedDecoded only
decoded+rawDecoded + raw
rawRaw hex

M.3.3. autoloadtype: Type of s/w auto load

Table M.121. autoloadtype: Type of s/w auto load

ValueDescription
falseDo no auto load
factoryLoad factory releases
betaLoad beta test releases
alphaLoad test releases

M.3.4. lacp-hot-standby: LACP hot standby mode

Table M.122. lacp-hot-standby: LACP hot standby mode

ValueDescription
enabledNormal hot standby
nosyncDon't set SYNC (helps with some switches)
disabledDon't do hot standby

M.3.5. config-access: Type of access user has to config

Table M.123. config-access: Type of access user has to config

ValueDescription
noneNo access unless explicitly listed
viewView only access (no passwords)
readRead only access (with passwords)
demoFull view and edit access but can only test config, not save
testFull view and edit access but must test save config first
fullFull view and edit access

M.3.6. eap-subsystem: Subsystem with EAP access control

Table M.124. eap-subsystem: Subsystem with EAP access control

ValueDescription
IPsecIPsec/IKEv2 VPN

M.3.7. eap-method: EAP access method

Table M.125. eap-method: EAP access method

ValueDescription
MD5MD5 Challenge
MSChapV2MS Challenge

M.3.8. syslog-severity: Syslog severity

Log severity - different loggable events log at different levels.

Table M.126. syslog-severity: Syslog severity

ValueDescription
EMERGSystem is unstable
ALERTAction must be taken immediately
CRIT Critical conditions
ERRError conditions
WARNINGWarning conditions
NOTICENormal but significant events
INFOInformational
DEBUGDebug level messages
NO-LOGGINGNo logging

M.3.9. syslog-facility: Syslog facility

Syslog facility, usually used to control which log file the syslog is written to.

Table M.127. syslog-facility: Syslog facility

ValueDescription
KERNKernel messages
USERUser level messges
MAILMail system
DAEMONSystem Daemons
AUTHSecurity/auth
SYSLOGInternal to syslogd
LPRPrinter
NEWSNews
UUCPUUCP
CRONCron deamon
AUTHPRIVprivate security/auth
FTPFile transfer
12Unused
13Unused
14Unused
15Unused
LOCAL0Local 0
LOCAL1Local 1
LOCAL2Local 2
LOCAL3Local 3
LOCAL4Local 4
LOCAL5Local 5
LOCAL6Local 6
LOCAL7Local 7

M.3.10. http-mode: HTTP/HTTPS security mode

Table M.128. http-mode: HTTP/HTTPS security mode

ValueDescription
http-onlyNo HTTPS access
http+httpsBoth HTTP and HTTPS access
https-onlyNo HTTP access
redirect-to-httpsHTTP accesses are redirected to use HTTPS
redirect-to-https-if-acmeHTTP accesses are redirected to use HTTPS if ACME set up for hostname
redirect-to-https-except-trustedHTTP accesses are redirected to use HTTPS (except trusted IPs)

M.3.11. radiuspriority: Options for controlling platform RADIUS response priority tagging

Table M.129. radiuspriority: Options for controlling platform RADIUS response priority tagging

ValueDescription
equalAll the same priority
strictIn order specified
randomRandom order
callingHashed on calling station id
calledHashed on called station id
usernameHashed on full username
userHashed on username before @
realmHashed on username after @
prefixHashed on username initial letters and numbers only

M.3.12. radiustype: Type of RADIUS server

Table M.130. radiustype: Type of RADIUS server

ValueDescription
authenticationAuthentication server
accountingAccounting server
controlAllowed to send control (CoA/DM)

M.3.13. mqtt-brokers: Select MQTT brokers

Table M.131. mqtt-brokers: Select MQTT brokers

ValueDescription
noneNo broker/internal
mqttMQTT only
mqttsMQTTS only
mqtt+mqttsMQTT and MQTTS
externalExternal only
external+mqttExternal ant MQTT
external+mqttsExternal ant MQTTS
allAll brokers

M.3.14. month: Month name (3 letter)

Table M.132. month: Month name (3 letter)

ValueDescription
JanJanuary
FebFebruary
MarMarch
AprApril
MayMay
JunJune
JulJuly
AugAugust
SepSeptember
OctOctober
NovNovember
DecDecember

M.3.15. day: Day name (3 letter)

Table M.133. day: Day name (3 letter)

ValueDescription
SunSunday
MonMonday
TueTuesday
WedWednesday
ThuThursday
FriFriday
SatSaturday

M.3.16. port: Physical port

Table M.134. port: Physical port

ValueDescription
0 Port 0 (not valid) (deprecated)
1Port 1
2Port 2
3Port 3
4Port 4

M.3.17. Crossover: Crossover configuration

Physical port crossover configuration.

Table M.135. Crossover: Crossover configuration

ValueDescription
autoCrossover is determined automatically
MDIForce no crossover

M.3.18. LinkSpeed: Physical port speed

Table M.136. LinkSpeed: Physical port speed

ValueDescription
10M10Mbit/sec
100M100Mbit/sec
1G1Gbit/sec
autoSpeed determined by autonegotiation

M.3.19. LinkDuplex: Physical port duplex setting

Table M.137. LinkDuplex: Physical port duplex setting

ValueDescription
halfHalf-duplex
fullFull-duplex
autoDuplex determined by autonegotiation

M.3.20. LinkFlow: Physical port flow control setting

Table M.138. LinkFlow: Physical port flow control setting

ValueDescription
noneNo flow control
symmetricCan support two-way flow control
send-pausesCan send pauses but does not support pause reception
anyCan receive pauses and may send pauses if required

M.3.21. LinkClock: Physical port Gigabit clock master/slave setting

Table M.139. LinkClock: Physical port Gigabit clock master/slave setting

ValueDescription
prefer-masterMaster status negotiated; preference for master
prefer-slaveMaster status negotiated; preference for slave
force-masterMaster status forced
force-slaveSlave status forced

M.3.22. LinkLED: LED settings

Table M.140. LinkLED: LED settings

ValueDescription
Link/ActivityOn when link up; blink when Tx or Rx activity
Link1000/ActivityOn when link up at 1G; blink when Tx or Rx activity
Link100/ActivityOn when link up at 100M; blink when Tx or Rx activity
Link10/ActivityOn when link up at 10M; blink when Tx or Rx activity
Link100-1000/ActivityOn when link up at 100M or 1G; blink when Tx or Rx activity
Link10-1000/ActivityOn when link up at 10M or 1G; blink when Tx or Rx activity
Link10-100/ActivityOn when link up at 10M or 100M; blink when Tx or Rx activity
Duplex/CollisionOn when full-duplex; blink when half-duplex and collisions detected
CollisionBlink when collisions detected
TxBlink when Tx activity
RxBlink when Rx activity
OffPermanently off
OnPermanently on
LinkOn when link up
Link1000On when link up at 1G
Link100On when link up at 100M
Link10On when link up at 10M
Link100-1000On when link up at 100M or 1G
Link10-1000On when link up at 10M or 1G
Link10-100On when link up at 10M or 100M
DuplexOn when full-duplex

M.3.23. LinkPower: PHY power saving options

Table M.141. LinkPower: PHY power saving options

ValueDescription
noneNo power saving
link-downPower save only when link is down
link-upPower save only when link is up
fullFull power saving

M.3.24. LinkFault: Link fault type to send

Table M.142. LinkFault: Link fault type to send

ValueDescription
falseNo fault
trueSend fault
off-lineSend offline fault (1G)
aneSend ANE fault (1G)

M.3.25. sampling-protocol: Sampling protocol

Table M.143. sampling-protocol: Sampling protocol

ValueDescription
sflowUse sFlow protocol
ipfix-psampUse IPFIX/PSAMP protocol
ipfix-legacyUse legacy (Cisco-style) IPFIX

M.3.26. trunk-mode: Trunk port mode

Table M.144. trunk-mode: Trunk port mode

ValueDescription
falseNot trunking
randomRandom trunking
l2-hashL2 hashed trunking
l23-hashL2 and L3 hashed trunking
l3-hashL3 hashed trunking

M.3.27. ramode: IPv6 route announce level

IPv6 route announcement mode and level

Table M.145. ramode: IPv6 route announce level

ValueDescription
falseDo not announce
lowAnnounce as low priority
mediumAnnounce as medium priority
highAnnounce as high priority
trueAnnounce as default (medium) priority
dhcp6triggeredWhen triggered by DHCPv6

M.3.28. bgpmode: BGP announcement mode

BGP mode defines the default advertisement mode for prefixes, based on well-known community tags

Table M.146. bgpmode: BGP announcement mode

ValueDescription
falseNot included in BGP at all
no-advertiseNot included in BGP, not advertised at all
no-exportNot normally exported from local AS/confederation
local-asNot exported from local AS
no-peerExported with no-peer community tag
trueExported as normal with no special tags added

M.3.29. sampling-mode: Sampling mode

Table M.147. sampling-mode: Sampling mode

ValueDescription
offDon't perform sampling
ingressSample incoming traffic
egressSample outgoing traffic
bothSample incoming and outgoing traffic

M.3.30. sfoption: Source filter option

Table M.148. sfoption: Source filter option

ValueDescription
falseNo source filter checks
blackholeCheck replies blackholed
nowhereCheck replies valid
selfCheck replies valid and not self
trueCheck replies down same port/vlan

M.3.31. pppoe-mode: Type of PPPoE connection

Table M.149. pppoe-mode: Type of PPPoE connection

ValueDescription
clientNormal PPPoE client connects to access controller
bras-l2tpPPPoE server mode linked to L2TP operation

M.3.32. pppoe-calling: Additional prefix on PPPoE calling ID

Table M.150. pppoe-calling: Additional prefix on PPPoE calling ID

ValueDescription
noneNone
macMAC
vlanInner VLAN
mac-vlanMAC and inner VLAN
vlanvlanOuter and inner VLANs padded to 4 digits

M.3.33. pppoe-calling-suffix: Main calling ID

Table M.151. pppoe-calling-suffix: Main calling ID

ValueDescription
noneNo suffix
macMAC address suffix

M.3.34. pdp-context-type: Type of IP connection

Table M.152. pdp-context-type: Type of IP connection

ValueDescription
ipIPv4 only
ip6IPv6 only
ip4ip6IPv4/IPv6 dual stack
pppEnd to end PPP

M.3.35. ipsec-type: IPsec encapsulation type

Table M.153. ipsec-type: IPsec encapsulation type

ValueDescription
AHAuthentication Header
ESPEncapsulating Security Payload

M.3.36. ipsec-auth-algorithm: IPsec authentication algorithm

Table M.154. ipsec-auth-algorithm: IPsec authentication algorithm

ValueDescription
nullNo authentication
HMAC-MD5HMAC-MD5-96 (RFC 2403)
HMAC-SHA1HMAC-SHA1-96 (RFC 2404)
AES-XCBCAES-XCBC-MAC-96 (RFC 3566)
HMAC-SHA256HMAC-SHA-256-128 (RFC 4868)

M.3.37. ipsec-crypt-algorithm: IPsec encryption algorithm

Table M.155. ipsec-crypt-algorithm: IPsec encryption algorithm

ValueDescription
nullNo encryption (RFC 2410)
3DES-CBC3DES-CBC (RFC 2451)
blowfishBlowfish CBC (RFC 2451) with 16-byte key
blowfish-192Blowfish CBC (RFC 2451) with 24-byte key
blowfish-256Blowfish CBC (RFC 2451) with 32-byte key
AES-CBCAES-CBC (Rijndael) (RFC 3602) with 16-byte key
AES-192-CBCAES-CBC (Rijndael) (RFC 3602) with 24-byte key
AES-256-CBCAES-CBC (Rijndael) (RFC 3602) with 32-byte key

M.3.38. peertype: BGP peer type

Peer type controls many of the defaults for a peer setting. It allows typical settings to be defined with one attribute that reflects the type of peer.

Table M.156. peertype: BGP peer type

ValueDescription
normalNormal BGP operation
transitEBGP Mark received as no-export
peerEBGP Mark received as no-export, only accept peer AS
customerEBGP Allow export as if confederate, only accept peer AS
internalIBGP allowing own AS
reflectorIBGP allowing own AS and working in route reflector mode
confederateEBGP confederate
ixpInternet exchange point peer on route server, soft routes EBGP only

M.3.39. radius-nas: NAS IP to report

Table M.157. radius-nas: NAS IP to report

ValueDescription
false Local LNS IP (deprecated)
lnsLocal LNS IP
bothSend NAS IP twice (LAC then LNS)
lacRemote LAC IP
true Remote LAC IP (deprecated)

M.3.40. ike-authmethod: authentication method

Table M.158. ike-authmethod: authentication method

ValueDescription
SecretShared Secret
CertificateX.509 certificate
EAPUse EAP for authentication

M.3.41. ike-mode: connection setup mode

Table M.159. ike-mode: connection setup mode

ValueDescription
WaitWait for peer to initiate the connection
On-demandBring up when needed for traffic
ImmediateAlways attempt to bring up connection

M.3.42. ike-PRF: IKE Pseudo-Random Function

Table M.160. ike-PRF: IKE Pseudo-Random Function

ValueDescription
HMAC-MD5HMAC-MD5
HMAC-SHA1HMAC-SHA1
AES-XCBC-128AES-XCBC with 128-bit key
HMAC-SHA256PRF-HMAC-SHA-256 (rfc4868)

M.3.43. ike-DH: IKE Diffie-Hellman group

Table M.161. ike-DH: IKE Diffie-Hellman group

ValueDescription
noneNo D-H negotiation (only used with AH/ESP)
MODP-10241024-bit Sophie Germain Prime MODP Group
MODP-20482048-bit Sophie Germain Prime MODP Group

M.3.44. ike-ESN: IKE Sequence Number support

Table M.162. ike-ESN: IKE Sequence Number support

ValueDescription
ALLOW-ESNAllow Extended Sequence Numbers (64 bits)
ALLOW-SHORT-SNAllow short sequence numbers (32 bits)

M.3.45. ipsec-encapsulation: Manually keyed IPsec encapsulation mode

Table M.163. ipsec-encapsulation: Manually keyed IPsec encapsulation mode

ValueDescription
tunnelIPsec tunnel
transportIPsec transport

M.3.46. switch: Profile manual setting

Manual setting control for profile

Table M.164. switch: Profile manual setting

ValueDescription
falseProfile set to OFF
trueProfile set to ON
control-switchProfile set based on control switch on home page

M.3.47. chksum-action: Handling of TCP/UDP packet checksum

Table M.165. chksum-action: Handling of TCP/UDP packet checksum

ValueDescription
leaveDon't correct checksum
udp-removeRemove checksum for UDP packets
recalcRecalculate new checksum
check-recalcCheck old value and recalculate new

M.3.48. dynamic-graph: Type of dynamic graph

Table M.166. dynamic-graph: Type of dynamic graph

ValueDescription
falseNo dynamic graph
ipUse source IP address
macUse source MAC address

M.3.49. firewall-action: Firewall action

Table M.167. firewall-action: Firewall action

ValueDescription
continueContinue rule-set checking
acceptAllow but no more rule-set checking
rejectEnd all rule checking now and set to send ICMP reject
dropEnd all rule checking now and set to drop
ignoreEnd all rule checking and ignore (drop) just this packet, not making a session

M.3.50. privacy-type: Privacy tag to use for withheld

Table M.168. privacy-type: Privacy tag to use for withheld

ValueDescription
falseDo not send Privacy header
idSend Privacy:id to mark withheld
userSend Privacy:user to mark withheld
user-idSend Privacy:user;id to mark withheld

M.3.51. voip-format: Number presentation format

Table M.169. voip-format: Number presentation format

ValueDescription
transparentUnchanged
internationalFull international number
int-no-plusInternational without leading plus
nationalWith nat/int prefix
localLocal number/extension
blockDo not use for calls

M.3.52. uknumberformat: Number formatting option

Table M.170. uknumberformat: Number formatting option

ValueDescription
falseDon't format numbers for display
trueFormat numbers for display with spacing
replace-zeroFormat numbers for display with spacing and replacing zeros - may look clearer on some CLI devices

M.3.53. recordoption: Recording option

Table M.171. recordoption: Recording option

ValueDescription
falseDon't automatically record calls
in-onlyAutomatically record incoming calls
out-onlyAutomatically record outgoing calls
trueAutomatically record all calls

M.3.54. voip-screen: Call screen setting

Table M.172. voip-screen: Call screen setting

ValueDescription
false Non ACR (deprecated)
no-callsReject all calls
acceptedOnly directory screen accept calls
foundOnly directory screen found calls
non-rejectedAll non rejected calls
acrAll non withhled calls
true ACR (deprecated)

M.3.55. ring-group-order: Order of ring

Table M.173. ring-group-order: Order of ring

ValueDescription
strictOrder in config
randomRandom order
cyclicCycling from last call
oldestOldest used phone first

M.3.56. ring-group-type: Type of ring when one call in queue

Table M.174. ring-group-type: Type of ring when one call in queue

ValueDescription
allAll phones
cascadeIncreasing number of phones
sequenceOne phone at a time

M.3.57. voip-screen-set: Directory screen setting

Table M.175. voip-screen-set: Directory screen setting

ValueDescription
rejectReject call
acceptAccept call

M.3.58. record-beep-option: Record beep option

Table M.176. record-beep-option: Record beep option

ValueDescription
falseNo beep
buttonBeep on record button press
trueBeep on start of record