Appendix K. Configuration Objects

Table of Contents

K.1. Top level
K.1.1. config: Top level config
K.2. Objects
K.2.1. system: System settings
K.2.2. link: Web links
K.2.3. user: Admin users
K.2.4. eap: User access controlled by EAP
K.2.5. log: Log target controls
K.2.6. log-syslog: Syslog logger settings
K.2.7. log-email: Email logger settings
K.2.8. services: System services
K.2.9. http-service: Web service settings
K.2.10. dns-service: DNS service settings
K.2.11. dns-host: Fixed local DNS host settings
K.2.12. dns-block: Fixed local DNS blocks
K.2.13. radius-service: RADIUS service definition
K.2.14. radius-service-match: Matching rules for RADIUS service
K.2.15. radius-server: RADIUS server settings
K.2.16. telnet-service: Telnet service settings
K.2.17. snmp-service: SNMP service settings
K.2.18. time-service: System time server settings
K.2.19. ethernet: Physical port controls
K.2.20. portdef: Port grouping and naming
K.2.21. interface: Port-group/VLAN interface settings
K.2.22. subnet: Subnet settings
K.2.23. vrrp: VRRP settings
K.2.24. dhcps: DHCP server settings
K.2.25. dhcp-attr-hex: DHCP server attributes (hex)
K.2.26. dhcp-attr-string: DHCP server attributes (string)
K.2.27. dhcp-attr-number: DHCP server attributes (numeric)
K.2.28. dhcp-attr-ip: DHCP server attributes (IP)
K.2.29. pppoe: PPPoE settings
K.2.30. ppp-route: PPP routes
K.2.31. route: Static routes
K.2.32. network: Locally originated networks
K.2.33. blackhole: Dead end networks
K.2.34. loopback: Locally originated networks
K.2.35. namedbgpmap: Mapping and filtering rules of BGP prefixes
K.2.36. bgprule: Individual mapping/filtering rule
K.2.37. bgp: Overall BGP settings
K.2.38. bgppeer: BGP peer definitions
K.2.39. bgpmap: Mapping and filtering rules of BGP prefixes
K.2.40. cqm: Constant Quality Monitoring settings
K.2.41. l2tp: L2TP settings
K.2.42. l2tp-incoming: L2TP settings for incoming L2TP connections
K.2.43. l2tp-relay: Relay and local authentication rules for L2TP
K.2.44. profile: Control profile
K.2.45. profile-date: Test passes if within any of the time ranges specified
K.2.46. profile-time: Test passes if within any of the date/time ranges specified
K.2.47. profile-ping: Test passes if any addresses are pingable
K.2.48. shaper: Traffic shaper
K.2.49. shaper-override: Traffic shaper override based on profile
K.2.50. ip-group: IP Group
K.2.51. dhcp-relay: DHCP server settings for remote / relayed requests
K.3. Data types
K.3.1. ppp-dump: PPP dump format
K.3.2. autoloadtype: Type of s/w auto load
K.3.3. config-access: Type of access user has to config
K.3.4. user-level: User login level
K.3.5. eap-subsystem: Subsystem with EAP access control
K.3.6. eap-method: EAP access method
K.3.7. syslog-severity: Syslog severity
K.3.8. syslog-facility: Syslog facility
K.3.9. http-mode: HTTP/HTTPS security mode
K.3.10. radiuspriority: Options for controlling platform RADIUS response priority tagging
K.3.11. radiustype: Type of RADIUS server
K.3.12. month: Month name (3 letter)
K.3.13. day: Day name (3 letter)
K.3.14. port: Physical port
K.3.15. Crossover: Crossover configuration
K.3.16. LinkSpeed: Physical port speed
K.3.17. LinkDuplex: Physical port duplex setting
K.3.18. LinkFlow: Physical port flow control setting
K.3.19. LinkClock: Physical port Gigabit clock master/slave setting
K.3.20. LinkLED-g: Green LED setting
K.3.21. LinkLED-y: Yellow LED setting
K.3.22. LinkPower: PHY power saving options
K.3.23. LinkFault: Link fault type to send
K.3.24. trunk-mode: Trunk port mode
K.3.25. ramode: IPv6 route announce level
K.3.26. dhcpv6control: Control for RA and DHCPv6 bits
K.3.27. bgpmode: BGP announcement mode
K.3.28. sfoption: Source filter option
K.3.29. pppoe-mode: Type of PPPoE connection
K.3.30. pppoe-calling: Additional prefix on PPPoE calling ID
K.3.31. peertype: BGP peer type
K.3.32. radius-nas: NAS IP to report
K.3.33. switch: Profile manual setting
K.4. Basic types

This appendix defines the object definitions used in the FireBrick FB6202 L2TP configuration. Copyright © 2008-16 FireBrick Ltd.

K.1. Top level

K.1.1. config: Top level config

The top level config element contains all of the FireBrick configuration data.

Table K.1. config: Attributes

AttributeTypeDefaultDescription
ip IPAddr -Config store IP address
patch integer -Internal use, for s/w updates that change config syntax
serial string -Serial number
timestamp dateTime -Config store time, set automatically when config is saved
version string -Code version
who string -Config store username

Table K.2. config: Elements

ElementTypeInstancesDescription
bgp bgp Optional, up to 100BGP config
bgp-filter namedbgpmap Optional, unlimitedMapping and filtering rules for use with BGP peers
blackhole blackhole Optional, unlimitedBlack hole (dropped packets) networks
cqm cqm OptionalConstant Quality Monitoring config
dhcp-relay dhcp-relay Optional, unlimitedDHCP server settings for remote / relayed requests
eap eap Optional, unlimitedUser access control via EAP
ethernet ethernet Optional, unlimitedEthernet port settings
interface interface Optional, up to 8192Ethernet interface (port-group/vlan) and subnets
ip-group ip-group Optional, unlimitedNamed IP groups
l2tp l2tp OptionalL2TP settings
log log Optional, up to 50Log target controls
loopback loopback Optional, unlimitedExtra local addresses
network network Optional, unlimitedLocally originated networks
nowhere blackhole Optional, unlimitedDead end (icmp error) networks
port portdef Optional, up to 2Port grouping and naming
ppp pppoe Optional, up to 10PPPoE settings
profile profile Optional, unlimitedControl profiles
route route Optional, unlimitedStatic routes
services services OptionalGeneral system services
shaper shaper Optional, unlimitedNamed traffic shapers
system system OptionalSystem settings
user user Optional, unlimitedAdmin users