Friday, January 31, 2014

Cisco 3750X Switch: Removable/Replaceable Fans

I like the idea of replaceable fans that help keep the unit cool.  The Cisco 3750X does have this, and I think its a excellent idea.  Ive seen a lot of fans go bad in units, and its a shame to replace the whole unit because of a fan, if you do an RMA.  Now, you can just replace the fan when it goes bad.  I like it.

Thursday, January 30, 2014

Cisco Switch: How To Stack Two 3750 Switches

I was asked recently by a customer to stack two Cisco 3750s and get them ready for re-purposing. So the first thing I did was to look at the IOS versions on both to verify the firmware was the same.  They were not.  This is what they had:
unit 1: "flash:c3750-ipservicesk9-mz.122-55.SE5.bin"
unit 2: "flash:c3750-ipservicesk9-mz.122-55.SE1.bin"

So I tftp'ed the SE5.bin version to my laptop and then put it on unit 2 so that they would match.  You have to have them match if you want them to stack.  Once I had both images the same, I then erased the config on both of them.

switch#wr erase
Erasing the nvram filesystem will remove all configuration files! Continue? [confirm]
[OK]
Erase of nvram: complete
System configuration has been modified. Save? [yes/no]: no
Proceed with reload? [confirm]

Once I wiped the config on both units and reloaded them, I then kept power on unit 1 and powered down unit 2.  I connected the stacking cables as shown in the picture below.  Once connected, I powered unit 2 up and let the stack form.
*Mar  1 00:09:17.951: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 1 Switch 1 has changed to state UP
*Mar  1 00:09:17.951: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 1 has changed to state UP
*Mar  1 00:10:07.612: %STACKMGR-4-SWITCH_ADDED: Switch 2 has been ADDED to the stack
*Mar  1 00:10:14.767: %STACKMGR-5-SWITCH_READY: Switch 2 is READY
*Mar  1 00:10:14.767: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 1 Switch 2 has changed to state UP
*Mar  1 00:10:14.767: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 2 has changed to state UP
*Mar  1 00:10:15.799: %STACKMGR-5-SWITCH_READY: Switch 1 is READY (Switch-2)
*Mar  1 00:10:15.899: %STACKMGR-5-MASTER_READY: Master Switch 1 is READY (Switch-2)
*Mar  1 00:10:15.883: %STACKMGR-5-SWITCH_READY: Switch 2 is READY (Switch-2)
*Mar  1 00:10:19.741: %CFGMGR-4-SLAVE_WRITING_STARTUP_CFG: only master can do that (Switch-2)
*Mar  1 00:10:19.741: %CFGMGR-4-SLAVE_WRITING_STARTUP_CFG: only master can do that (Switch-2)




Wednesday, January 29, 2014

Icy Day In Alabama

Ok, for a lot of you, this is no big deal.  But in Alabama, it is a big deal.  We are not used to snow and ice down here.  We are facing below freezing temperatures for the next upcoming days (not as big of a deal), but this came today (in the pictures below) and has caused all kinds of havoc.  I chose to walk 4 miles to get home today because the traffic was so slow.  And, people in Alabama do not know how to drive in this stuff.  Walking was safer.  The first picture is how I started my trip home.  It took me an hour to get to this point from my office, which is less than a mile from where Im sitting in this picture.

Many people chose to abandon their vehicles and walk.  I did just that.  This is in Pelham, the town where I live.  Im four miles from home at this point.

Still walking, I left the traffic behind.  Literally, I was faster than the traffic.  I made the right decision.

Finally home.  Walking was definitely the way to go.  Great to be outside and what a great walk.

I was very fortunate.  There are a lot of people out tonight that are not as fortunate as I was.  Lets keep them and their families in our prayers.

Tuesday, January 28, 2014

Brocade FCX Switch: How Long Does It Take To Upgrade The POE Firmware?

Have you considered how long it actually takes to upgrade the POE firmware on a Brocade switch?  I have.  In fact, it takes a little longer than what most people think.  I used to think you just TFTP'ed the image up and then did the reboot.  However, if you happen to be consoled into the switch you are upgrading the POE firmware on, it gives you an idea.  Below, I highlight the command for updating the POE firmware in yellow, and it tells you around 6 minutes is how long it takes to do the upgrade.  Notice in orange below.

BrocadeSwitch#inline power install-firmware stack-unit 2 tftp 192.168.0.26 fcx_poeplus_07202h.fw

Flash Memory Write (8192 bytes per dot) ...................
 tftp download successful stackId = 2 file name = poe-fw
Sending PoE Firmware to Stack Unit 2.
Flash Memory Write (8192 bytes per dot) ...................
U2-MSG: PoE Info: FW Download on slot 1...downloading firmware....
U2-MSG: PoE Info: FW Download on slot 1...TPE response received.
U2-MSG: PoE Info: FW Download on slot 1...sending erase command...
U2-MSG: PoE Info: FW Download on slot 1...erase command...accepted.
U2-MSG: PoE Info: FW Download on slot 1...erasing firmware memory...
U2-MSG: PoE Info: FW Download on slot 1...erasing firmware memory...completed
U2-MSG: PoE Info: FW Download on slot 1...sending program command...
U2-MSG: PoE Info: FW Download on slot 1...sending program command...accepted.
U2-MSG: PoE Info: FW Download on slot 1...programming firmware...takes around 6 minutes....
U2-MSG: PoE Info: Firmware Download on slot 1.....10 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....20 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....30 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....40 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....50 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....60 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....70 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....80 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....90 percent completed.
U2-MSG: PoE Info: Firmware Download on slot 1.....100 percent completed.
U2-MSG: PoE Info: FW Download on slot 1...programming firmware...completed.
U2-MSG: PoE Info: FW Download on slot 1...downloading firmware...completed. Module will be reset.
U2-MSG: PoE Info: Resetting module in slot 1....completed.

BrocadeSwitch#
BrocadeSwitch#

Monday, January 27, 2014

Be Prepared For Small Maintenance Windows

When I know I have a small maintenance window, I have to make the best use of my time.  In this case, where I have to upgrade all the switches in the company (16 total), troubleshoot ASAs in HA mode where one is froze up, troubleshoot the IPS modules in each ASA (one in a 'down' state and one not on at all), and physically replace one switch for an RMA.  I have a two hour window to get all this done.
So I have to prepare as much as I can ahead of time.  While I collect my thoughts on what to do for troubleshooting, there isnt much I can do ahead of time since I have no idea what is really going on.  Since its a 24/7 operation, I cant really do much during non-maintenance times.  So, I thought I would write out what I have to do for the upgrades.  That should get this part done quicker.  Below is my template to upgrade both the routing and switching image, along with the boot and poe image (on the switches that have poe).  This should help me on time.  As for the rest, Ill have to pray for success.
=====================================================================
copy tftp flash 192.168.0.244 trz07300.bin boot
copy tftp flash 192.168.0.244 TIS07400c.bin primary
copy tftp flash 192.168.0.244 TIR07400c.bin secondary

Server Room (TurboIrons):
telnet 192.168.0.246
telnet 192.168.0.247
telnet 192.168.0.248
telnet 192.168.0.249
telnet 192.168.0.250
telnet 192.168.0.251
telnet 192.168.0.252

-----------------------------------
copy tftp flash 192.168.0.244 grz07302.bin boot
copy tftp flash 192.168.0.244 FCXS07400c.bin primary
copy tftp flash 192.168.0.244 FCXR07400c.bin secondary
inline power install-firmware stack-unit 1 tftp 192.168.0.244 fcx_poeplus_02.1.0.fw
inline power install-firmware stack-unit 2 tftp 192.168.0.244 fcx_poeplus_02.1.0.fw

Floor:
(FCX)
telnet 192.168.0.237
telnet 192.168.0.240
telnet 192.168.0.239
telnet 192.168.0.238
-----------------------------------------
R&D (ICX)
copy tftp flash 192.168.0.244 kxz07401.bin boot
copy tftp flash 192.168.0.244 ICX64S07400c.bin primary
copy tftp flash 192.168.0.244 ICX64R07400c.bin secondary
inline power install-firmware stack-unit 1 tftp 192.168.0.244 icx64xx_poeplus_02.1.0.fw

telnet 192.168.0.242
=====================================================================

***ADDED THIS NOTE AFTER THE NIGHT I DID THIS***
Well, I didn't get to everything on the list.  I got all of the TurboIron switches upgraded, and then ran into a problem on the first FCX switch when upgrading the POE firmware.  Since I had to take the time to troubleshoot this issue, I didn't get to upgrade the rest of the switches.  I did, while passing by them in the server room, reset the power on the primary ASA that was froze up, which did come back up successfully. I didn't get to the IPS modules.   

Saturday, January 25, 2014

How Much Is Enough?


I found this on the wall at a Jimmie Johns.  I like it.

Friday, January 24, 2014

Cisco ASA LEDs: Green And Amber For HA

These two ASAs are in failover mode.  At least, configured for that way.  Notice the 'Active' LEDs for each of them.  Both are green.  Well, that is not normal for a HA mode.  One of them should be amber.  So, if you see this scenario and you know its an HA config, you probably better take a look at the pair and check on them.  I did a 'show failover' and noticed quickly that one "failed".  When I consoled into it, it was not responsive at all.  I plan on fixing it this weekend.  Keep your eyes open.

Thursday, January 23, 2014

Check Point Gaia: List Of CLI Commands

If you wondered (like I did) what the commands were that you could run on the Gaia OS in CLI, here is the list.  I ran the 'show commands' entry and got this list when trying to figure out an IPS issue I was having.  Its worth a look if you need to use CLI.

CPEnforcementModule1> show commands
add aaa radius-servers priority VALUE host VALUE [ port VALUE ] prompt-secret timeout VALUE
add aaa radius-servers priority VALUE host VALUE [ port VALUE ] secret VALUE timeout VALUE
add aaa tacacs-servers priority VALUE server VALUE key VALUE timeout VALUE
add allowed-client host any-host
add allowed-client host ipv4-address VALUE
add allowed-client host ipv6-address VALUE
add allowed-client network ipv4-address VALUE mask-length VALUE
add allowed-client network ipv6-address VALUE mask-length VALUE
add arp proxy ipv4-address VALUE interface VALUE real-ipv4-address VALUE
add arp proxy ipv4-address VALUE macaddress VALUE real-ipv4-address VALUE
add arp static ipv4-address VALUE macaddress VALUE
add backup ftp ip VALUE username VALUE password plain
add backup local
add backup scp ip VALUE username VALUE password plain
add backup tftp ip VALUE
add backup-scheduled name VALUE ftp ip VALUE username VALUE password plain
add backup-scheduled name VALUE local
add backup-scheduled name VALUE scp ip VALUE username VALUE password plain
add backup-scheduled name VALUE tftp ip VALUE
add bonding group VALUE interface VALUE
add bridging group VALUE fail-open-interfaces VALUE
add bridging group VALUE interface VALUE
add command VALUE path VALUE description VALUE
add cron job VALUE command VALUE recurrence daily time VALUE
add cron job VALUE command VALUE recurrence monthly month VALUE days VALUE time VALUE
add cron job VALUE command VALUE recurrence system-startup
add cron job VALUE command VALUE recurrence weekly days VALUE time VALUE
add dhcp client interface VALUE
add dhcp server subnet VALUE exclude-ip-pool start VALUE end VALUE
add dhcp server subnet VALUE include-ip-pool start VALUE end VALUE
add dhcp server subnet VALUE netmask VALUE
add group VALUE gid VALUE
add group VALUE member VALUE
add host name VALUE ipv4-address VALUE
add host name VALUE ipv6-address VALUE
add installer private_url VALUE
add instance VALUE
add interface VALUE 6in4 VALUE remote VALUE ttl VALUE
add interface VALUE alias VALUE
add interface VALUE loopback VALUE
add interface VALUE vlan VALUE
add mcvr vrid VALUE backup-address VALUE vmac-mode default-vmac
add mcvr vrid VALUE backup-address VALUE vmac-mode extended-vmac
add mcvr vrid VALUE backup-address VALUE vmac-mode interface-vmac
add mcvr vrid VALUE backup-address VALUE vmac-mode static-vmac [ static-mac VALUE ]
add mcvr vrid VALUE priority VALUE priority-delta VALUE [ hello-interval VALUE authtype VALUE password VALUE ]
add neighbor-entry ipv6-address VALUE macaddress VALUE interface VALUE
add netflow collector ip VALUE port VALUE [ srcaddr VALUE export-format VALUE ]
add pppoe client id VALUE interface VALUE user-name VALUE password VALUE use-peer-dns VALUE use-peer-as-default-gateway VALUE
add rba role VALUE domain-type VALUE { all-features }
add rba role VALUE domain-type VALUE { readonly-features VALUE readwrite-features VALUE }
add rba role VALUE virtual-system-access VALUE
add rba user VALUE access-mechanisms VALUE
add rba user VALUE roles VALUE
add snapshot VALUE desc VALUE
add snmp address VALUE
add snmp traps receiver VALUE version v1 community VALUE
add snmp traps receiver VALUE version v2 community VALUE
add snmp traps receiver VALUE version v3
add snmp usm user VALUE security-level authNoPriv auth-pass-phrase VALUE
add snmp usm user VALUE security-level authNoPriv auth-pass-phrase-hashed VALUE
add snmp usm user VALUE security-level authPriv auth-pass-phrase VALUE privacy-pass-phrase VALUE
add snmp usm user VALUE security-level authPriv auth-pass-phrase VALUE privacy-pass-phrase-hashed VALUE
add snmp usm user VALUE security-level authPriv auth-pass-phrase-hashed VALUE privacy-pass-phrase VALUE
add snmp usm user VALUE security-level authPriv auth-pass-phrase-hashed VALUE privacy-pass-phrase-hashed VALUE
add snmp usm user VALUE security-level authPriv privacy-pass-phrase VALUE
add syslog log-remote-address VALUE [ level VALUE ]
add tag name VALUE description VALUE
add upgrade VALUE package file VALUE
add user VALUE uid VALUE homedir VALUE
add virtual-system VALUE
add vpn tunnel VALUE type numbered local VALUE remote VALUE peer VALUE
add vpn tunnel VALUE type unnumbered peer VALUE dev VALUE
commit
delete aaa radius-servers NAS-IP
delete aaa radius-servers priority VALUE
delete aaa tacacs-servers priority VALUE
delete allowed-client host any-host
delete allowed-client host ipv4-address VALUE
delete allowed-client host ipv6-address VALUE
delete allowed-client network ipv4-address VALUE
delete allowed-client network ipv6-address VALUE
delete arp dynamic all
delete arp proxy ipv4-address VALUE
delete arp static ipv4-address VALUE
delete backup VALUE
delete backup-scheduled VALUE
delete bonding group VALUE force
delete bonding group VALUE interface VALUE
delete bridging group VALUE fail-open-interfaces VALUE
delete bridging group VALUE force
delete bridging group VALUE interface VALUE
delete command VALUE
delete cron all
delete cron job VALUE
delete cron mailto
delete dhcp client interface VALUE
delete dhcp server subnet VALUE exclude-ip-pool VALUE
delete dhcp server subnet VALUE include-ip-pool VALUE
delete dns primary
delete dns secondary
delete dns suffix
delete dns tertiary
delete domainname
delete group VALUE member VALUE
delete host name VALUE ipv4
delete host name VALUE ipv6
delete instance VALUE
delete interface VALUE 6in4 VALUE force
delete interface VALUE alias VALUE
delete interface VALUE ipv4-address
delete interface VALUE ipv6-address
delete interface VALUE loopback VALUE
delete interface VALUE vlan VALUE force
delete mcvr old-mc-config
delete neighbor-entry ipv6-address VALUE interface VALUE
delete netflow collector for-ip VALUE for-port VALUE
delete ntp server VALUE
delete pppoe client id VALUE
delete proxy all
delete proxy ip-address
delete proxy port
delete rba role VALUE virtual-system-access VALUE
delete rba role VALUE { readonly-features VALUE readwrite-features VALUE }
delete rba user VALUE access-mechanisms VALUE
delete rba user VALUE roles VALUE
delete snapshot VALUE
delete snmp address VALUE
delete snmp community VALUE
delete snmp contact
delete snmp location
delete snmp traps polling-frequency
delete snmp traps receiver VALUE
delete snmp traps trap-user
delete snmp usm user VALUE
delete syslog log-remote-address VALUE [ level VALUE ]
delete tag name VALUE
delete upgrade VALUE
delete user VALUE
delete virtual-system VALUE
delete vpn tunnel VALUE
exit
expert
halt
help
history
installer download VALUE
installer install VALUE
installer restore_policy
installer start
installer stop
installer uninstall VALUE
load configuration VALUE
lock database override
quit
reboot
revert database date VALUE time VALUE
revert database tag VALUE start
rollback
save clienv
save config
save configuration VALUE
set aaa radius-servers NAS-IP VALUE
set aaa radius-servers priority VALUE host VALUE
set aaa radius-servers priority VALUE new-priority VALUE
set aaa radius-servers priority VALUE port VALUE
set aaa radius-servers priority VALUE prompt-secret
set aaa radius-servers priority VALUE secret VALUE
set aaa radius-servers priority VALUE timeout VALUE
set aaa radius-servers super-user-uid VALUE
set aaa tacacs-servers priority VALUE key VALUE
set aaa tacacs-servers priority VALUE new-priority VALUE
set aaa tacacs-servers priority VALUE server VALUE
set aaa tacacs-servers priority VALUE timeout VALUE
set aaa tacacs-servers state VALUE
set aggregate VALUE aspath-truncate VALUE
set aggregate VALUE contributing-protocol VALUE contributing-route VALUE exact on
set aggregate VALUE contributing-protocol VALUE contributing-route VALUE off
set aggregate VALUE contributing-protocol VALUE contributing-route VALUE on
set aggregate VALUE contributing-protocol VALUE contributing-route VALUE refines on
set aggregate VALUE contributing-protocol VALUE off
set aggregate VALUE off
set aggregate VALUE rank VALUE
set aggregate VALUE weight VALUE
set arp table cache-size VALUE
set arp table validity-timeout VALUE
set as VALUE
set backup restore ftp ip VALUE file VALUE username VALUE password plain
set backup restore local VALUE
set backup restore scp ip VALUE file VALUE username VALUE password plain
set backup restore tftp ip VALUE file VALUE
set backup-scheduled name VALUE recurrence daily time VALUE
set backup-scheduled name VALUE recurrence monthly month VALUE days VALUE time VALUE
set backup-scheduled name VALUE recurrence weekly days VALUE time VALUE
set bgp cluster-id VALUE
set bgp communities VALUE
set bgp confederation aspath-loops-permitted VALUE
set bgp confederation identifier VALUE
set bgp dampening keep-history VALUE
set bgp dampening max-flap VALUE
set bgp dampening off
set bgp dampening on
set bgp dampening reachable-decay VALUE
set bgp dampening reuse-below VALUE
set bgp dampening suppress-above VALUE
set bgp dampening unreachable-decay VALUE
set bgp default-med VALUE
set bgp default-route-gateway VALUE
set bgp external remote-as VALUE description VALUE
set bgp external remote-as VALUE export-routemap VALUE off
set bgp external remote-as VALUE export-routemap VALUE preference VALUE [ family VALUE ] on
set bgp external remote-as VALUE import-routemap VALUE off
set bgp external remote-as VALUE import-routemap VALUE preference VALUE [ family VALUE ] on
set bgp external remote-as VALUE local-address VALUE off
set bgp external remote-as VALUE local-address VALUE on
set bgp external remote-as VALUE off
set bgp external remote-as VALUE on
set bgp external remote-as VALUE outdelay VALUE
set bgp external remote-as VALUE peer VALUE accept-med VALUE
set bgp external remote-as VALUE peer VALUE accept-routes VALUE
set bgp external remote-as VALUE peer VALUE aspath-prepend-count VALUE
set bgp external remote-as VALUE peer VALUE authtype md5 secret VALUE
set bgp external remote-as VALUE peer VALUE authtype none
set bgp external remote-as VALUE peer VALUE capability default
set bgp external remote-as VALUE peer VALUE capability ipv4-unicast VALUE
set bgp external remote-as VALUE peer VALUE capability ipv6-unicast VALUE
set bgp external remote-as VALUE peer VALUE graceful-restart-helper off
set bgp external remote-as VALUE peer VALUE graceful-restart-helper on
set bgp external remote-as VALUE peer VALUE graceful-restart-helper-stalepath-time VALUE
set bgp external remote-as VALUE peer VALUE holdtime VALUE
set bgp external remote-as VALUE peer VALUE ignore-first-ashop VALUE
set bgp external remote-as VALUE peer VALUE keepalive VALUE
set bgp external remote-as VALUE peer VALUE local-address VALUE off
set bgp external remote-as VALUE peer VALUE local-address VALUE on
set bgp external remote-as VALUE peer VALUE log-state-transitions VALUE
set bgp external remote-as VALUE peer VALUE log-warnings VALUE
set bgp external remote-as VALUE peer VALUE med-out VALUE
set bgp external remote-as VALUE peer VALUE multihop VALUE
set bgp external remote-as VALUE peer VALUE no-aggregator-id VALUE
set bgp external remote-as VALUE peer VALUE off
set bgp external remote-as VALUE peer VALUE on
set bgp external remote-as VALUE peer VALUE outgoing-interface VALUE on
set bgp external remote-as VALUE peer VALUE passive-tcp VALUE
set bgp external remote-as VALUE peer VALUE removeprivateas VALUE
set bgp external remote-as VALUE peer VALUE route-refresh off
set bgp external remote-as VALUE peer VALUE route-refresh on
set bgp external remote-as VALUE peer VALUE send-keepalives VALUE
set bgp external remote-as VALUE peer VALUE send-route-refresh request all unicast
set bgp external remote-as VALUE peer VALUE send-route-refresh request ipv4 unicast
set bgp external remote-as VALUE peer VALUE send-route-refresh request ipv6 unicast
set bgp external remote-as VALUE peer VALUE send-route-refresh route-update all unicast
set bgp external remote-as VALUE peer VALUE send-route-refresh route-update ipv4 unicast
set bgp external remote-as VALUE peer VALUE send-route-refresh route-update ipv6 unicast
set bgp external remote-as VALUE peer VALUE suppress-default-originate VALUE
set bgp external remote-as VALUE peer VALUE throttle-count VALUE
set bgp external remote-as VALUE peer VALUE trace VALUE off
set bgp external remote-as VALUE peer VALUE trace VALUE on
set bgp external remote-as VALUE peer VALUE ttl VALUE
set bgp internal description VALUE
set bgp internal export-routemap VALUE off
set bgp internal export-routemap VALUE preference VALUE [ family VALUE ] on
set bgp internal import-routemap VALUE off
set bgp internal import-routemap VALUE preference VALUE [ family VALUE ] on
set bgp internal interface VALUE off
set bgp internal interface VALUE on
set bgp internal local-address VALUE off
set bgp internal local-address VALUE on
set bgp internal med VALUE
set bgp internal nexthop-self VALUE
set bgp internal off
set bgp internal on
set bgp internal outdelay VALUE
set bgp internal peer VALUE [ peer-type VALUE ] on
set bgp internal peer VALUE accept-routes VALUE
set bgp internal peer VALUE authtype md5 secret VALUE
set bgp internal peer VALUE authtype none
set bgp internal peer VALUE capability default
set bgp internal peer VALUE capability ipv4-unicast VALUE
set bgp internal peer VALUE capability ipv6-unicast VALUE
set bgp internal peer VALUE graceful-restart-helper off
set bgp internal peer VALUE graceful-restart-helper on
set bgp internal peer VALUE graceful-restart-helper-stalepath-time VALUE
set bgp internal peer VALUE holdtime VALUE
set bgp internal peer VALUE ignore-first-ashop VALUE
set bgp internal peer VALUE keepalive VALUE
set bgp internal peer VALUE local-address VALUE off
set bgp internal peer VALUE local-address VALUE on
set bgp internal peer VALUE log-state-transitions VALUE
set bgp internal peer VALUE log-warnings VALUE
set bgp internal peer VALUE no-aggregator-id VALUE
set bgp internal peer VALUE off
set bgp internal peer VALUE outgoing-interface VALUE [ peer-type VALUE ] on
set bgp internal peer VALUE passive-tcp VALUE
set bgp internal peer VALUE route-refresh off
set bgp internal peer VALUE route-refresh on
set bgp internal peer VALUE send-keepalives VALUE
set bgp internal peer VALUE send-route-refresh request all unicast
set bgp internal peer VALUE send-route-refresh request ipv4 unicast
set bgp internal peer VALUE send-route-refresh request ipv6 unicast
set bgp internal peer VALUE send-route-refresh route-update all unicast
set bgp internal peer VALUE send-route-refresh route-update ipv4 unicast
set bgp internal peer VALUE send-route-refresh route-update ipv6 unicast
set bgp internal peer VALUE throttle-count VALUE
set bgp internal peer VALUE trace VALUE off
set bgp internal peer VALUE trace VALUE on
set bgp internal peer VALUE weight VALUE
set bgp internal protocol VALUE off
set bgp internal protocol VALUE on
set bgp routing-domain aspath-loops-permitted VALUE
set bgp routing-domain identifier VALUE
set bgp synchronization VALUE
set bonding group VALUE { primary VALUE mii-interval VALUE up-delay VALUE down-delay VALUE mode VALUE lacp-rate VALUE }
set bonding group VALUE { primary VALUE mii-interval VALUE up-delay VALUE down-delay VALUE mode VALUE xmit-hash-policy VALUE }
set bootp interface VALUE maxhopcount VALUE
set bootp interface VALUE off
set bootp interface VALUE on
set bootp interface VALUE primary VALUE wait-time VALUE on
set bootp interface VALUE relay-to VALUE off
set bootp interface VALUE relay-to VALUE on
set clienv config-lock VALUE
set clienv debug VALUE
set clienv echo-cmd VALUE
set clienv on-failure VALUE
set clienv output VALUE
set clienv prompt VALUE
set clienv rows VALUE
set clienv syntax-check VALUE
set config-lock off
set config-lock on [ timeout VALUE override ]
set core-dump disable
set core-dump enable
set core-dump per_process VALUE
set core-dump total VALUE
set cron job VALUE command VALUE
set cron job VALUE recurrence daily time VALUE
set cron job VALUE recurrence monthly month VALUE days VALUE time VALUE
set cron job VALUE recurrence system-startup
set cron job VALUE recurrence weekly days VALUE time VALUE
set cron mailto VALUE
set date VALUE
set dhcp client hostname VALUE
set dhcp client interface VALUE leasetime VALUE
set dhcp client interface VALUE reboot VALUE
set dhcp client interface VALUE retry VALUE
set dhcp client interface VALUE timeout VALUE
set dhcp server disable
set dhcp server enable
set dhcp server subnet VALUE default-gateway VALUE
set dhcp server subnet VALUE default-lease VALUE
set dhcp server subnet VALUE disable
set dhcp server subnet VALUE dns VALUE
set dhcp server subnet VALUE domain VALUE
set dhcp server subnet VALUE enable
set dhcp server subnet VALUE exclude-ip-pool VALUE disable
set dhcp server subnet VALUE exclude-ip-pool VALUE enable
set dhcp server subnet VALUE include-ip-pool VALUE disable
set dhcp server subnet VALUE include-ip-pool VALUE enable
set dhcp server subnet VALUE max-lease VALUE
set dns primary VALUE
set dns secondary VALUE
set dns suffix VALUE
set dns tertiary VALUE
set domainname VALUE
set edition VALUE
set expert-password
set expert-password-hash VALUE
set fcd revert VALUE
set format date dd-mmm-yyyy
set format date dd/mm/yyyy
set format date mm/dd/yyyy
set format date yyyy/mm/dd
set format netmask dotted
set format netmask length
set format time 12-hour
set format time 24-hour
set group VALUE gid VALUE
set host name VALUE ipv4-address VALUE
set host name VALUE ipv6-address VALUE
set hostname VALUE
set igmp interface VALUE last-member-query-interval VALUE
set igmp interface VALUE local-group VALUE off
set igmp interface VALUE local-group VALUE on
set igmp interface VALUE loss-robustness VALUE
set igmp interface VALUE off
set igmp interface VALUE query-interval VALUE
set igmp interface VALUE query-response-interval VALUE
set igmp interface VALUE router-alert VALUE
set igmp interface VALUE static-group VALUE off
set igmp interface VALUE static-group VALUE on
set igmp interface VALUE version VALUE
set inactivity-timeout VALUE
set installer deployment-mail-notification VALUE available_packages false
set installer deployment-mail-notification VALUE available_packages true
set installer deployment-mail-notification VALUE download_status false
set installer deployment-mail-notification VALUE download_status true
set installer deployment-mail-notification VALUE install_status false
set installer deployment-mail-notification VALUE install_status true
set installer download_mode automatic
set installer download_mode manual
set installer download_mode schedule daily VALUE
set installer download_mode schedule monthly VALUE
set installer download_mode schedule singular VALUE
set installer download_mode schedule weekly Friday VALUE
set installer download_mode schedule weekly Monday VALUE
set installer download_mode schedule weekly Saturday VALUE
set installer download_mode schedule weekly Sunday VALUE
set installer download_mode schedule weekly Thursday VALUE
set installer download_mode schedule weekly Tuesday VALUE
set installer download_mode schedule weekly Wednesday VALUE
set installer install_mode automatic
set installer install_mode manual
set installer install_mode schedule daily VALUE
set installer install_mode schedule monthly VALUE
set installer install_mode schedule singular VALUE
set installer install_mode schedule weekly Friday VALUE
set installer install_mode schedule weekly Monday VALUE
set installer install_mode schedule weekly Saturday VALUE
set installer install_mode schedule weekly Sunday VALUE
set installer install_mode schedule weekly Thursday VALUE
set installer install_mode schedule weekly Tuesday VALUE
set installer install_mode schedule weekly Wednesday VALUE
set instance VALUE aggregate VALUE aspath-truncate VALUE
set instance VALUE aggregate VALUE contributing-protocol VALUE contributing-route VALUE exact on
set instance VALUE aggregate VALUE contributing-protocol VALUE contributing-route VALUE off
set instance VALUE aggregate VALUE contributing-protocol VALUE contributing-route VALUE on
set instance VALUE aggregate VALUE contributing-protocol VALUE contributing-route VALUE refines on
set instance VALUE aggregate VALUE contributing-protocol VALUE off
set instance VALUE aggregate VALUE off
set instance VALUE aggregate VALUE rank VALUE
set instance VALUE aggregate VALUE weight VALUE
set instance VALUE ipv6 aggregate VALUE contributing-protocol VALUE contributing-route VALUE off
set instance VALUE ipv6 aggregate VALUE contributing-protocol VALUE contributing-route VALUE on
set instance VALUE ipv6 aggregate VALUE contributing-protocol VALUE off
set instance VALUE ipv6 aggregate VALUE off
set instance VALUE ipv6 ospf3 area VALUE off
set instance VALUE ipv6 ospf3 area VALUE on
set instance VALUE ipv6 ospf3 area VALUE range VALUE off
set instance VALUE ipv6 ospf3 area VALUE range VALUE on
set instance VALUE ipv6 ospf3 area VALUE range VALUE restrict VALUE
set instance VALUE ipv6 ospf3 area VALUE stub default-cost VALUE
set instance VALUE ipv6 ospf3 area VALUE stub off
set instance VALUE ipv6 ospf3 area VALUE stub on
set instance VALUE ipv6 ospf3 area VALUE stub summary off
set instance VALUE ipv6 ospf3 area VALUE stub summary on
set instance VALUE ipv6 ospf3 area VALUE stub-network VALUE off
set instance VALUE ipv6 ospf3 area VALUE stub-network VALUE on
set instance VALUE ipv6 ospf3 area VALUE stub-network VALUE stub-network-cost VALUE
set instance VALUE ipv6 ospf3 default-ase-cost VALUE
set instance VALUE ipv6 ospf3 default-ase-type VALUE
set instance VALUE ipv6 ospf3 export-routemap VALUE off
set instance VALUE ipv6 ospf3 export-routemap VALUE preference VALUE on
set instance VALUE ipv6 ospf3 import-routemap VALUE off
set instance VALUE ipv6 ospf3 import-routemap VALUE preference VALUE on
set instance VALUE ipv6 ospf3 interface VALUE area VALUE off
set instance VALUE ipv6 ospf3 interface VALUE area VALUE on
set instance VALUE ipv6 ospf3 interface VALUE cost VALUE
set instance VALUE ipv6 ospf3 interface VALUE dead-interval VALUE
set instance VALUE ipv6 ospf3 interface VALUE hello-interval VALUE
set instance VALUE ipv6 ospf3 interface VALUE passive VALUE
set instance VALUE ipv6 ospf3 interface VALUE priority VALUE
set instance VALUE ipv6 ospf3 interface VALUE retransmit-interval VALUE
set instance VALUE ipv6 ospf3 spf-delay VALUE
set instance VALUE ipv6 ospf3 spf-holdtime VALUE
set instance VALUE ipv6 rdisc6 interface VALUE address VALUE autonomous VALUE
set instance VALUE ipv6 rdisc6 interface VALUE address VALUE on-link VALUE
set instance VALUE ipv6 rdisc6 interface VALUE address VALUE prefix-pref-lifetime VALUE
set instance VALUE ipv6 rdisc6 interface VALUE address VALUE prefix-valid-lifetime VALUE
set instance VALUE ipv6 rdisc6 interface VALUE hop-limit VALUE
set instance VALUE ipv6 rdisc6 interface VALUE managed-config VALUE
set instance VALUE ipv6 rdisc6 interface VALUE max-adv-interval VALUE
set instance VALUE ipv6 rdisc6 interface VALUE min-adv-interval VALUE
set instance VALUE ipv6 rdisc6 interface VALUE off
set instance VALUE ipv6 rdisc6 interface VALUE on
set instance VALUE ipv6 rdisc6 interface VALUE other-config VALUE
set instance VALUE ipv6 rdisc6 interface VALUE reachable-time VALUE
set instance VALUE ipv6 rdisc6 interface VALUE retransmit-timer VALUE
set instance VALUE ipv6 rdisc6 interface VALUE router-lifetime VALUE
set instance VALUE ipv6 rdisc6 interface VALUE send-mtu VALUE
set instance VALUE ipv6 static-route VALUE comment VALUE
set instance VALUE ipv6 static-route VALUE nexthop blackhole
set instance VALUE ipv6 static-route VALUE nexthop gateway VALUE [ priority VALUE ] on
set instance VALUE ipv6 static-route VALUE nexthop gateway VALUE interface VALUE [ priority VALUE ] on
set instance VALUE ipv6 static-route VALUE nexthop gateway VALUE interface VALUE off
set instance VALUE ipv6 static-route VALUE nexthop gateway VALUE off
set instance VALUE ipv6 static-route VALUE nexthop reject
set instance VALUE ipv6 static-route VALUE off
set instance VALUE kernel-routes VALUE
set instance VALUE max-path-splits VALUE
set instance VALUE ospf area VALUE nssa default-cost VALUE
set instance VALUE ospf area VALUE nssa default-metric-type VALUE
set instance VALUE ospf area VALUE nssa import-summary-routes off
set instance VALUE ospf area VALUE nssa import-summary-routes on
set instance VALUE ospf area VALUE nssa off
set instance VALUE ospf area VALUE nssa on
set instance VALUE ospf area VALUE nssa range VALUE off
set instance VALUE ospf area VALUE nssa range VALUE on
set instance VALUE ospf area VALUE nssa range VALUE restrict VALUE off
set instance VALUE ospf area VALUE nssa range VALUE restrict VALUE on
set instance VALUE ospf area VALUE nssa redistribution off
set instance VALUE ospf area VALUE nssa redistribution on
set instance VALUE ospf area VALUE nssa translator-role VALUE
set instance VALUE ospf area VALUE nssa translator-stability-interval VALUE
set instance VALUE ospf area VALUE off
set instance VALUE ospf area VALUE on
set instance VALUE ospf area VALUE range VALUE off
set instance VALUE ospf area VALUE range VALUE on
set instance VALUE ospf area VALUE range VALUE restrict VALUE off
set instance VALUE ospf area VALUE range VALUE restrict VALUE on
set instance VALUE ospf area VALUE stub default-cost VALUE
set instance VALUE ospf area VALUE stub off
set instance VALUE ospf area VALUE stub on
set instance VALUE ospf area VALUE stub summary off
set instance VALUE ospf area VALUE stub summary on
set instance VALUE ospf area VALUE stub-network VALUE off
set instance VALUE ospf area VALUE stub-network VALUE on
set instance VALUE ospf area VALUE stub-network VALUE stub-network-cost VALUE
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE authtype md5 key VALUE off
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE authtype md5 key VALUE secret VALUE
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE authtype none
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE authtype simple VALUE
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE dead-interval VALUE
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE hello-interval VALUE
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE off
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE on
set instance VALUE ospf area VALUE virtual-link VALUE transit-area VALUE retransmit-interval VALUE
set instance VALUE ospf default-ase-cost VALUE
set instance VALUE ospf default-ase-type VALUE
set instance VALUE ospf export-routemap VALUE off
set instance VALUE ospf export-routemap VALUE preference VALUE on
set instance VALUE ospf graceful-restart-helper off
set instance VALUE ospf graceful-restart-helper on
set instance VALUE ospf import-routemap VALUE off
set instance VALUE ospf import-routemap VALUE preference VALUE on
set instance VALUE ospf interface VALUE area VALUE off
set instance VALUE ospf interface VALUE area VALUE on
set instance VALUE ospf interface VALUE authtype md5 key VALUE off
set instance VALUE ospf interface VALUE authtype md5 key VALUE secret VALUE
set instance VALUE ospf interface VALUE authtype none
set instance VALUE ospf interface VALUE authtype simple VALUE
set instance VALUE ospf interface VALUE cost VALUE
set instance VALUE ospf interface VALUE dead-interval VALUE
set instance VALUE ospf interface VALUE hello-interval VALUE
set instance VALUE ospf interface VALUE passive VALUE off
set instance VALUE ospf interface VALUE passive VALUE on
set instance VALUE ospf interface VALUE priority VALUE
set instance VALUE ospf interface VALUE retransmit-interval VALUE
set instance VALUE ospf interface VALUE virtual-address off
set instance VALUE ospf interface VALUE virtual-address on
set instance VALUE ospf rfc1583-compatibility VALUE off
set instance VALUE ospf rfc1583-compatibility VALUE on
set instance VALUE ospf spf-delay VALUE
set instance VALUE ospf spf-holdtime VALUE
set instance VALUE protocol-rank protocol VALUE rank VALUE
set instance VALUE routemap VALUE id VALUE action aspath-prepend-count VALUE
set instance VALUE routemap VALUE id VALUE action community VALUE as VALUE off
set instance VALUE routemap VALUE id VALUE action community VALUE as VALUE on
set instance VALUE routemap VALUE id VALUE action community VALUE off
set instance VALUE routemap VALUE id VALUE action community VALUE on
set instance VALUE routemap VALUE id VALUE action localpref VALUE
set instance VALUE routemap VALUE id VALUE action metric add VALUE
set instance VALUE routemap VALUE id VALUE action metric igp add VALUE
set instance VALUE routemap VALUE id VALUE action metric igp subtract VALUE
set instance VALUE routemap VALUE id VALUE action metric subtract VALUE
set instance VALUE routemap VALUE id VALUE action metric value VALUE
set instance VALUE routemap VALUE id VALUE action nexthop ip VALUE
set instance VALUE routemap VALUE id VALUE action nexthop ipv6 VALUE
set instance VALUE routemap VALUE id VALUE action ospfautomatictag VALUE
set instance VALUE routemap VALUE id VALUE action ospfmanualtag VALUE
set instance VALUE routemap VALUE id VALUE action precedence VALUE
set instance VALUE routemap VALUE id VALUE action preference VALUE
set instance VALUE routemap VALUE id VALUE action remove aspath-prepend-count
set instance VALUE routemap VALUE id VALUE action remove community
set instance VALUE routemap VALUE id VALUE action remove localpref
set instance VALUE routemap VALUE id VALUE action remove metric
set instance VALUE routemap VALUE id VALUE action remove nexthop ip
set instance VALUE routemap VALUE id VALUE action remove nexthop ipv6
set instance VALUE routemap VALUE id VALUE action remove ospfautomatictag
set instance VALUE routemap VALUE id VALUE action remove ospfmanualtag
set instance VALUE routemap VALUE id VALUE action remove precedence
set instance VALUE routemap VALUE id VALUE action remove preference
set instance VALUE routemap VALUE id VALUE action remove riptag
set instance VALUE routemap VALUE id VALUE action remove route-type
set instance VALUE routemap VALUE id VALUE action riptag VALUE
set instance VALUE routemap VALUE id VALUE action route-type VALUE
set instance VALUE routemap VALUE id VALUE allow
set instance VALUE routemap VALUE id VALUE inactive
set instance VALUE routemap VALUE id VALUE match as VALUE off
set instance VALUE routemap VALUE id VALUE match as VALUE on
set instance VALUE routemap VALUE id VALUE match aspath-regex VALUE origin VALUE
set instance VALUE routemap VALUE id VALUE match community VALUE as VALUE off
set instance VALUE routemap VALUE id VALUE match community VALUE as VALUE on
set instance VALUE routemap VALUE id VALUE match community VALUE off
set instance VALUE routemap VALUE id VALUE match community VALUE on
set instance VALUE routemap VALUE id VALUE match ifaddress VALUE off
set instance VALUE routemap VALUE id VALUE match ifaddress VALUE on
set instance VALUE routemap VALUE id VALUE match interface VALUE off
set instance VALUE routemap VALUE id VALUE match interface VALUE on
set instance VALUE routemap VALUE id VALUE match metric value VALUE
set instance VALUE routemap VALUE id VALUE match neighbor VALUE off
set instance VALUE routemap VALUE id VALUE match neighbor VALUE on
set instance VALUE routemap VALUE id VALUE match network VALUE all [ restrict VALUE ]
set instance VALUE routemap VALUE id VALUE match network VALUE between VALUE and VALUE [ restrict VALUE ]
set instance VALUE routemap VALUE id VALUE match network VALUE exact [ restrict VALUE ]
set instance VALUE routemap VALUE id VALUE match network VALUE off
set instance VALUE routemap VALUE id VALUE match network VALUE refines [ restrict VALUE ]
set instance VALUE routemap VALUE id VALUE match nexthop VALUE off
set instance VALUE routemap VALUE id VALUE match nexthop VALUE on
set instance VALUE routemap VALUE id VALUE match protocol VALUE
set instance VALUE routemap VALUE id VALUE match remove as
set instance VALUE routemap VALUE id VALUE match remove aspath-regex
set instance VALUE routemap VALUE id VALUE match remove community
set instance VALUE routemap VALUE id VALUE match remove ifaddress
set instance VALUE routemap VALUE id VALUE match remove interface
set instance VALUE routemap VALUE id VALUE match remove metric
set instance VALUE routemap VALUE id VALUE match remove neighbor
set instance VALUE routemap VALUE id VALUE match remove network
set instance VALUE routemap VALUE id VALUE match remove nexthop
set instance VALUE routemap VALUE id VALUE match remove protocol
set instance VALUE routemap VALUE id VALUE match remove route-type
set instance VALUE routemap VALUE id VALUE match route-type VALUE off
set instance VALUE routemap VALUE id VALUE match route-type VALUE on
set instance VALUE routemap VALUE id VALUE off
set instance VALUE routemap VALUE id VALUE on
set instance VALUE routemap VALUE id VALUE restrict
set instance VALUE router-id VALUE
set instance VALUE static-route VALUE comment VALUE
set instance VALUE static-route VALUE nexthop blackhole
set instance VALUE static-route VALUE nexthop gateway address VALUE [ priority VALUE ] on
set instance VALUE static-route VALUE nexthop gateway address VALUE off
set instance VALUE static-route VALUE nexthop gateway logical VALUE [ priority VALUE ] on
set instance VALUE static-route VALUE nexthop gateway logical VALUE off
set instance VALUE static-route VALUE nexthop reject
set instance VALUE static-route VALUE off
set instance VALUE static-route VALUE ping off
set instance VALUE static-route VALUE ping on
set instance VALUE static-route VALUE rank VALUE
set instance VALUE static-route VALUE scopelocal off
set instance VALUE static-route VALUE scopelocal on
set instance VALUE trace ospf VALUE off
set instance VALUE trace ospf VALUE on
set instance VALUE trace ospf3 VALUE off
set instance VALUE trace vrrp6 VALUE off
set instance VALUE trace vrrp6 VALUE on
set instance VALUE tracefile maxnum VALUE
set instance VALUE tracefile size VALUE
set interface VALUE ipv4-address VALUE mask-length VALUE
set interface VALUE ipv4-address VALUE subnet-mask VALUE
set interface VALUE ipv6-address VALUE mask-length VALUE
set interface VALUE monitor-mode VALUE
set interface VALUE rx-ringsize VALUE
set interface VALUE tx-ringsize VALUE
set interface VALUE { comments VALUE mac-addr VALUE mtu VALUE state VALUE link-speed VALUE auto-negotiation VALUE }
set interface VALUE { ipv6-autoconfig VALUE }
set iphelper forward-nonlocal off
set iphelper forward-nonlocal on
set iphelper interface VALUE off
set iphelper interface VALUE udp-port VALUE off
set iphelper interface VALUE udp-port VALUE relay-to VALUE off
set iphelper interface VALUE udp-port VALUE relay-to VALUE on
set ipv6-state off
set ipv6-state on
set kernel-routes VALUE
set lcd access none
set lcd access restricted password VALUE
set lcd access unrestricted
set lcd backlight timeout VALUE
set lcd screensaver mode VALUE
set lcd screensaver timeout VALUE
set mail-notification server VALUE
set mail-notification username VALUE
set management interface VALUE
set max-path-splits VALUE
set mcvr vrid VALUE authtype VALUE password VALUE
set mcvr vrid VALUE backup-address VALUE vmac-mode default-vmac
set mcvr vrid VALUE backup-address VALUE vmac-mode extended-vmac
set mcvr vrid VALUE backup-address VALUE vmac-mode interface-vmac
set mcvr vrid VALUE backup-address VALUE vmac-mode static-vmac [ static-mac VALUE ]
set mcvr vrid VALUE hello-interval VALUE
set mcvr vrid VALUE priority VALUE
set message banner VALUE [ line msgvalue VALUE ]
set message banner VALUE [ msgvalue VALUE ]
set message motd VALUE [ line msgvalue VALUE ]
set message motd VALUE [ msgvalue VALUE ]
set neighbor duplicate-detection retry VALUE
set neighbor duplicate-detection state VALUE
set neighbor multicast-limit VALUE
set neighbor queue-limit VALUE
set neighbor unicast-limit VALUE
set net-access telnet VALUE
set netflow collector for-ip VALUE for-port VALUE { ip VALUE port VALUE export-format VALUE srcaddr VALUE }
set netflow collector for-ip VALUE { ip VALUE port VALUE export-format VALUE srcaddr VALUE }
set netflow collector { ip VALUE port VALUE export-format VALUE srcaddr VALUE }
set ntp active VALUE
set ntp server primary VALUE version VALUE
set ntp server secondary VALUE version VALUE
set ospf area VALUE nssa default-cost VALUE
set ospf area VALUE nssa default-metric-type VALUE
set ospf area VALUE nssa import-summary-routes off
set ospf area VALUE nssa import-summary-routes on
set ospf area VALUE nssa off
set ospf area VALUE nssa on
set ospf area VALUE nssa range VALUE off
set ospf area VALUE nssa range VALUE on
set ospf area VALUE nssa range VALUE restrict VALUE off
set ospf area VALUE nssa range VALUE restrict VALUE on
set ospf area VALUE nssa redistribution off
set ospf area VALUE nssa redistribution on
set ospf area VALUE nssa translator-role VALUE
set ospf area VALUE nssa translator-stability-interval VALUE
set ospf area VALUE off
set ospf area VALUE on
set ospf area VALUE range VALUE off
set ospf area VALUE range VALUE on
set ospf area VALUE range VALUE restrict VALUE off
set ospf area VALUE range VALUE restrict VALUE on
set ospf area VALUE stub default-cost VALUE
set ospf area VALUE stub off
set ospf area VALUE stub on
set ospf area VALUE stub summary off
set ospf area VALUE stub summary on
set ospf area VALUE stub-network VALUE off
set ospf area VALUE stub-network VALUE on
set ospf area VALUE stub-network VALUE stub-network-cost VALUE
set ospf area VALUE virtual-link VALUE transit-area VALUE authtype md5 key VALUE off
set ospf area VALUE virtual-link VALUE transit-area VALUE authtype md5 key VALUE secret VALUE
set ospf area VALUE virtual-link VALUE transit-area VALUE authtype none
set ospf area VALUE virtual-link VALUE transit-area VALUE authtype simple VALUE
set ospf area VALUE virtual-link VALUE transit-area VALUE dead-interval VALUE
set ospf area VALUE virtual-link VALUE transit-area VALUE hello-interval VALUE
set ospf area VALUE virtual-link VALUE transit-area VALUE off
set ospf area VALUE virtual-link VALUE transit-area VALUE on
set ospf area VALUE virtual-link VALUE transit-area VALUE retransmit-interval VALUE
set ospf default-ase-cost VALUE
set ospf default-ase-type VALUE
set ospf export-routemap VALUE off
set ospf export-routemap VALUE preference VALUE on
set ospf graceful-restart-helper VALUE off
set ospf graceful-restart-helper VALUE on
set ospf import-routemap VALUE off
set ospf import-routemap VALUE preference VALUE on
set ospf interface VALUE area VALUE off
set ospf interface VALUE area VALUE on
set ospf interface VALUE authtype md5 key VALUE off
set ospf interface VALUE authtype md5 key VALUE secret VALUE
set ospf interface VALUE authtype none
set ospf interface VALUE authtype simple VALUE
set ospf interface VALUE cost VALUE
set ospf interface VALUE dead-interval VALUE
set ospf interface VALUE hello-interval VALUE
set ospf interface VALUE passive VALUE off
set ospf interface VALUE passive VALUE on
set ospf interface VALUE priority VALUE
set ospf interface VALUE retransmit-interval VALUE
set ospf interface VALUE virtual-address VALUE off
set ospf interface VALUE virtual-address VALUE on
set ospf rfc1583-compatibility VALUE off
set ospf rfc1583-compatibility VALUE on
set ospf spf-delay VALUE
set ospf spf-holdtime VALUE
set password-controls complexity VALUE
set password-controls deny-on-fail allow-after VALUE
set password-controls deny-on-fail enable VALUE
set password-controls deny-on-fail failures-allowed VALUE
set password-controls deny-on-nonuse allowed-days VALUE
set password-controls deny-on-nonuse enable VALUE
set password-controls expiration-lockout-days VALUE
set password-controls expiration-warning-days VALUE
set password-controls force-change-when VALUE
set password-controls history-checking VALUE
set password-controls history-length VALUE
set password-controls min-password-length VALUE
set password-controls palindrome-check VALUE
set password-controls password-expiration VALUE
set pbr rule priority VALUE action prohibit
set pbr rule priority VALUE action unreachable
set pbr rule priority VALUE match { from VALUE to VALUE interface VALUE }
set pbr rule priority VALUE off
set pbr table VALUE off
set pbr table VALUE static-route VALUE nexthop blackhole
set pbr table VALUE static-route VALUE nexthop gateway address VALUE off
set pbr table VALUE static-route VALUE nexthop gateway address VALUE on
set pbr table VALUE static-route VALUE nexthop gateway address VALUE priority VALUE
set pbr table VALUE static-route VALUE nexthop gateway logical VALUE off
set pbr table VALUE static-route VALUE nexthop gateway logical VALUE on
set pbr table VALUE static-route VALUE nexthop gateway logical VALUE priority VALUE
set pbr table VALUE static-route VALUE nexthop reject
set pbr table VALUE static-route VALUE off
set pim assert-interval VALUE
set pim assert-limit VALUE
set pim assert-rank protocol VALUE rank VALUE
set pim bootstrap-candidate local-address VALUE
set pim bootstrap-candidate off
set pim bootstrap-candidate on
set pim bootstrap-candidate priority VALUE
set pim candidate-rp advertise-interval VALUE
set pim candidate-rp local-address VALUE
set pim candidate-rp multicast-group VALUE off
set pim candidate-rp multicast-group VALUE on
set pim candidate-rp off
set pim candidate-rp on
set pim candidate-rp priority VALUE
set pim data-interval VALUE
set pim hello-interval VALUE
set pim interface VALUE dr-priority VALUE
set pim interface VALUE local-address VALUE
set pim interface VALUE off
set pim interface VALUE on
set pim interface VALUE virtual-address off
set pim interface VALUE virtual-address on
set pim jp-delay-interval VALUE
set pim jp-interval VALUE
set pim jp-suppress-interval VALUE
set pim mode dense
set pim mode sparse
set pim mode ssm
set pim register-suppress-interval VALUE
set pim spt-threshold multicast VALUE threshold VALUE off
set pim spt-threshold multicast VALUE threshold VALUE on
set pim state-refresh off
set pim state-refresh on
set pim state-refresh-interval VALUE
set pim state-refresh-ttl VALUE
set pim static-rp off
set pim static-rp rp-address VALUE multicast-group VALUE off
set pim static-rp rp-address VALUE multicast-group VALUE on
set pim static-rp rp-address VALUE off
set pim static-rp rp-address VALUE on
set ping count VALUE
set ping interval VALUE
set pppoe client id VALUE interface VALUE
set pppoe client id VALUE password VALUE
set pppoe client id VALUE use-peer-as-default-gateway VALUE
set pppoe client id VALUE use-peer-dns VALUE
set pppoe client id VALUE user-name VALUE
set protocol-rank protocol VALUE rank VALUE
set proxy ip-address VALUE port VALUE
set rdisc interface VALUE adv-lifetime VALUE
set rdisc interface VALUE advertise VALUE off
set rdisc interface VALUE advertise VALUE on
set rdisc interface VALUE advertise VALUE preference VALUE
set rdisc interface VALUE max-adv-interval VALUE
set rdisc interface VALUE min-adv-interval VALUE
set rdisc interface VALUE off
set rdisc interface VALUE on
set rip auto-summary VALUE
set rip expire-interval VALUE
set rip export-routemap VALUE off
set rip export-routemap VALUE preference VALUE on
set rip import-routemap VALUE off
set rip import-routemap VALUE preference VALUE on
set rip interface VALUE [ version VALUE ] on
set rip interface VALUE accept-updates VALUE
set rip interface VALUE authtype md5 secret VALUE [ cisco-compatibility VALUE ]
set rip interface VALUE authtype none
set rip interface VALUE authtype simple VALUE
set rip interface VALUE metric VALUE
set rip interface VALUE off
set rip interface VALUE send-updates VALUE
set rip interface VALUE transport VALUE
set rip interface VALUE virtual-address VALUE
set rip update-interval VALUE
set routemap VALUE id VALUE action aspath-prepend-count VALUE
set routemap VALUE id VALUE action community VALUE as VALUE off
set routemap VALUE id VALUE action community VALUE as VALUE on
set routemap VALUE id VALUE action community VALUE off
set routemap VALUE id VALUE action community VALUE on
set routemap VALUE id VALUE action localpref VALUE
set routemap VALUE id VALUE action metric add VALUE
set routemap VALUE id VALUE action metric igp add VALUE
set routemap VALUE id VALUE action metric igp subtract VALUE
set routemap VALUE id VALUE action metric subtract VALUE
set routemap VALUE id VALUE action metric value VALUE
set routemap VALUE id VALUE action nexthop ip VALUE
set routemap VALUE id VALUE action nexthop ipv6 VALUE
set routemap VALUE id VALUE action ospfautomatictag VALUE
set routemap VALUE id VALUE action ospfmanualtag VALUE
set routemap VALUE id VALUE action precedence VALUE
set routemap VALUE id VALUE action preference VALUE
set routemap VALUE id VALUE action remove aspath-prepend-count
set routemap VALUE id VALUE action remove community
set routemap VALUE id VALUE action remove localpref
set routemap VALUE id VALUE action remove metric
set routemap VALUE id VALUE action remove nexthop ip
set routemap VALUE id VALUE action remove nexthop ipv6
set routemap VALUE id VALUE action remove ospfautomatictag
set routemap VALUE id VALUE action remove ospfmanualtag
set routemap VALUE id VALUE action remove precedence
set routemap VALUE id VALUE action remove preference
set routemap VALUE id VALUE action remove riptag
set routemap VALUE id VALUE action remove route-type
set routemap VALUE id VALUE action riptag VALUE
set routemap VALUE id VALUE action route-type VALUE
set routemap VALUE id VALUE allow
set routemap VALUE id VALUE inactive
set routemap VALUE id VALUE match as VALUE off
set routemap VALUE id VALUE match as VALUE on
set routemap VALUE id VALUE match aspath-regex VALUE origin VALUE
set routemap VALUE id VALUE match community VALUE as VALUE off
set routemap VALUE id VALUE match community VALUE as VALUE on
set routemap VALUE id VALUE match community VALUE off
set routemap VALUE id VALUE match community VALUE on
set routemap VALUE id VALUE match ifaddress VALUE off
set routemap VALUE id VALUE match ifaddress VALUE on
set routemap VALUE id VALUE match interface VALUE off
set routemap VALUE id VALUE match interface VALUE on
set routemap VALUE id VALUE match metric value VALUE
set routemap VALUE id VALUE match neighbor VALUE off
set routemap VALUE id VALUE match neighbor VALUE on
set routemap VALUE id VALUE match network VALUE all [ restrict VALUE ]
set routemap VALUE id VALUE match network VALUE between VALUE and VALUE [ restrict VALUE ]
set routemap VALUE id VALUE match network VALUE exact [ restrict VALUE ]
set routemap VALUE id VALUE match network VALUE off
set routemap VALUE id VALUE match network VALUE refines [ restrict VALUE ]
set routemap VALUE id VALUE match nexthop VALUE off
set routemap VALUE id VALUE match nexthop VALUE on
set routemap VALUE id VALUE match protocol VALUE
set routemap VALUE id VALUE match remove as
set routemap VALUE id VALUE match remove aspath-regex
set routemap VALUE id VALUE match remove community
set routemap VALUE id VALUE match remove ifaddress
set routemap VALUE id VALUE match remove interface
set routemap VALUE id VALUE match remove metric
set routemap VALUE id VALUE match remove neighbor
set routemap VALUE id VALUE match remove network
set routemap VALUE id VALUE match remove nexthop
set routemap VALUE id VALUE match remove protocol
set routemap VALUE id VALUE match remove route-type
set routemap VALUE id VALUE match route-type VALUE off
set routemap VALUE id VALUE match route-type VALUE on
set routemap VALUE id VALUE off
set routemap VALUE id VALUE on
set routemap VALUE id VALUE restrict
set router-id VALUE
set router-options wait-for-clustering VALUE
set selfpasswd
set selfpasswd oldpass VALUE passwd VALUE
set snapshot export VALUE path VALUE name VALUE
set snapshot import VALUE path VALUE name VALUE
set snapshot revert VALUE
set snmp agent VALUE
set snmp agent-version VALUE
set snmp community VALUE read-only
set snmp community VALUE read-write
set snmp contact VALUE
set snmp location VALUE
set snmp mode VALUE
set snmp traps polling-frequency VALUE
set snmp traps receiver VALUE version v1 community VALUE
set snmp traps receiver VALUE version v1 community VALUE
set snmp traps receiver VALUE version v2 community VALUE
set snmp traps receiver VALUE version v2 community VALUE
set snmp traps receiver VALUE version v3
set snmp traps receiver VALUE version v3
set snmp traps trap VALUE disable
set snmp traps trap VALUE enable
set snmp traps trap-user VALUE
set snmp usm user VALUE security-level authNoPriv auth-pass-phrase VALUE
set snmp usm user VALUE security-level authPriv auth-pass-phrase VALUE privacy-pass-phrase VALUE
set snmp usm user VALUE security-level authPriv privacy-pass-phrase VALUE
set snmp usm user VALUE security-level authPriv privacy-pass-phrase VALUE auth-pass-phrase VALUE
set snmp usm user VALUE usm-read-only
set snmp usm user VALUE usm-read-write
set static-route VALUE comment VALUE
set static-route VALUE nexthop blackhole
set static-route VALUE nexthop gateway address VALUE [ priority VALUE ] on
set static-route VALUE nexthop gateway address VALUE off
set static-route VALUE nexthop gateway address VALUE on
set static-route VALUE nexthop gateway logical VALUE [ priority VALUE ] on
set static-route VALUE nexthop gateway logical VALUE off
set static-route VALUE nexthop reject
set static-route VALUE off
set static-route VALUE ping off
set static-route VALUE ping on
set static-route VALUE rank VALUE
set static-route VALUE scopelocal off
set static-route VALUE scopelocal on
set syslog auditlog VALUE
set syslog cplogs off
set syslog cplogs on
set syslog filename VALUE
set syslog log-remote-address VALUE [ level VALUE ]
set time VALUE
set timezone VALUE / VALUE
set trace bgp VALUE off
set trace bgp VALUE on
set trace dvmrp VALUE off
set trace dvmrp VALUE on
set trace global VALUE off
set trace global VALUE on
set trace icmp VALUE off
set trace icmp VALUE on
set trace igmp VALUE off
set trace igmp VALUE on
set trace iphelper VALUE off
set trace iphelper VALUE on
set trace kernel VALUE off
set trace kernel VALUE on
set trace mfc VALUE off
set trace mfc VALUE on
set trace ospf VALUE off
set trace ospf VALUE on
set trace ospf3 VALUE off
set trace ospf3 VALUE on
set trace pim VALUE off
set trace pim VALUE on
set trace rip VALUE off
set trace rip VALUE on
set trace router-discovery VALUE off
set trace router-discovery VALUE on
set trace router-discovery6 VALUE off
set trace router-discovery6 VALUE on
set trace vrrp VALUE off
set trace vrrp VALUE on
set trace vrrp6 VALUE off
set trace vrrp6 VALUE on
set tracefile maxnum VALUE
set tracefile size VALUE
set user VALUE force-password-change VALUE
set user VALUE lock-out off
set user VALUE newpass VALUE
set user VALUE password
set user VALUE password-hash VALUE
set user VALUE { realname VALUE uid VALUE gid VALUE homedir VALUE shell VALUE }
set virtual-system VALUE
set volume VALUE size VALUE
set vrrp accept-connections off
set vrrp accept-connections on
set vrrp coldstart-delay VALUE
set vrrp disable-all-virtual-routers off
set vrrp disable-all-virtual-routers on
set vrrp interface VALUE authtype none
set vrrp interface VALUE authtype simple VALUE
set vrrp interface VALUE monitored-circuit vrid VALUE auto-deactivation VALUE
set vrrp interface VALUE monitored-circuit vrid VALUE backup-address VALUE off
set vrrp interface VALUE monitored-circuit vrid VALUE backup-address VALUE on
set vrrp interface VALUE monitored-circuit vrid VALUE hello-interval VALUE
set vrrp interface VALUE monitored-circuit vrid VALUE monitored-interface VALUE off
set vrrp interface VALUE monitored-circuit vrid VALUE monitored-interface VALUE on
set vrrp interface VALUE monitored-circuit vrid VALUE monitored-interface VALUE priority-delta VALUE
set vrrp interface VALUE monitored-circuit vrid VALUE off
set vrrp interface VALUE monitored-circuit vrid VALUE on
set vrrp interface VALUE monitored-circuit vrid VALUE preempt-mode VALUE
set vrrp interface VALUE monitored-circuit vrid VALUE priority VALUE
set vrrp interface VALUE monitored-circuit vrid VALUE vmac-mode default-vmac
set vrrp interface VALUE monitored-circuit vrid VALUE vmac-mode extended-vmac
set vrrp interface VALUE monitored-circuit vrid VALUE vmac-mode interface-vmac
set vrrp interface VALUE monitored-circuit vrid VALUE vmac-mode static-vmac VALUE
set vrrp interface VALUE off
set vrrp interface VALUE virtual-router backup-vrid VALUE backup-address VALUE off
set vrrp interface VALUE virtual-router backup-vrid VALUE backup-address VALUE on
set vrrp interface VALUE virtual-router backup-vrid VALUE hello-interval VALUE
set vrrp interface VALUE virtual-router backup-vrid VALUE off
set vrrp interface VALUE virtual-router backup-vrid VALUE preempt-mode VALUE
set vrrp interface VALUE virtual-router backup-vrid VALUE priority VALUE
set vrrp interface VALUE virtual-router backup-vrid VALUE vmac-mode default-vmac
set vrrp interface VALUE virtual-router backup-vrid VALUE vmac-mode extended-vmac
set vrrp interface VALUE virtual-router backup-vrid VALUE vmac-mode interface-vmac
set vrrp interface VALUE virtual-router backup-vrid VALUE vmac-mode static-vmac VALUE
set vrrp interface VALUE virtual-router vrid VALUE hello-interval VALUE
set vrrp interface VALUE virtual-router vrid VALUE off
set vrrp interface VALUE virtual-router vrid VALUE on
set vrrp interface VALUE virtual-router vrid VALUE vmac-mode default-vmac
set vrrp interface VALUE virtual-router vrid VALUE vmac-mode extended-vmac
set vrrp interface VALUE virtual-router vrid VALUE vmac-mode interface-vmac
set vrrp interface VALUE virtual-router vrid VALUE vmac-mode static-vmac VALUE
set vrrp monitor-firewall off
set vrrp monitor-firewall on
set vsx off
set vsx on
set web daemon-enable VALUE
set web session-timeout VALUE
set web ssl-certificate cert-file VALUE key-file VALUE passphrase VALUE
set web ssl-certificate cert-file VALUE key-file VALUE prompt-passphrase
set web ssl-port VALUE
show aaa radius-servers NAS-IP
show aaa radius-servers list
show aaa radius-servers priority VALUE host
show aaa radius-servers priority VALUE port
show aaa radius-servers priority VALUE timeout
show aaa radius-servers super-user-uid
show aaa tacacs-servers list
show aaa tacacs-servers priority VALUE server
show aaa tacacs-servers priority VALUE timeout
show aaa tacacs-servers state
show allowed-client all
show arp dynamic all
show arp proxy all
show arp proxy ipv4-address VALUE
show arp static all
show arp table cache-size
show arp table validity-timeout
show as
show asset VALUE
show backup logs
show backup status
show backup-scheduled VALUE
show backups
show bgp
show bgp errors
show bgp groups
show bgp memory
show bgp paths
show bgp peer VALUE advertise
show bgp peer VALUE detailed
show bgp peer VALUE received
show bgp peers
show bgp peers detailed
show bgp peers established
show bgp routemap
show bgp stats
show bgp summary
show bonding group VALUE xmit-hash-policy
show bonding group VALUE { primary mii-interval up-delay down-delay interfaces }
show bonding group VALUE { primary mii-interval up-delay down-delay mode } lacp-rate
show bonding groups
show bootp interface VALUE
show bootp interfaces
show bootp stats
show bootp stats receive
show bootp stats reply
show bootp stats request
show bridging group VALUE fail-open-mode
show bridging group VALUE { interfaces }
show bridging groups
show clienv all
show clienv config-lock
show clienv debug
show clienv echo-cmd
show clienv on-failure
show clienv output
show clienv prompt
show clienv rows
show clienv syntax-check
show clock
show command VALUE
show commands [ op VALUE feature VALUE ]
show config-lock
show config-state
show configuration aaa
show configuration aggregate
show configuration allowed-client
show configuration arp proxy
show configuration as
show configuration bgp
show configuration bonding
show configuration bootp
show configuration bridging
show configuration clienv
show configuration command
show configuration core-dump
show configuration dhcp
show configuration dns
show configuration domainname
show configuration expert-password
show configuration format
show configuration group
show configuration host
show configuration hostname
show configuration igmp
show configuration interface
show configuration iphelper
show configuration ipv6 ospf3
show configuration ipv6 rdisc6
show configuration ipv6 static-route
show configuration ipv6 vrrp6
show configuration ipv6-state
show configuration kernel-routes
show configuration lcd
show configuration mail-notification
show configuration max-path-splits
show configuration mcvr
show configuration message
show configuration neighbor
show configuration net-access
show configuration netflow
show configuration ntp
show configuration ospf
show configuration password-controls
show configuration pbr
show configuration pim
show configuration pppoe
show configuration protocol-rank
show configuration proxy
show configuration rba
show configuration rdisc
show configuration rip
show configuration routemaps
show configuration router-id
show configuration router-options
show configuration snmp
show configuration static-route
show configuration syslog
show configuration timezone
show configuration trace
show configuration tracefile
show configuration user
show configuration vpnt
show configuration vrrp
show configuration web
show core-dump per_process
show core-dump status
show core-dump total
show cron job VALUE command
show cron job VALUE recurrence
show cron jobs
show cron mailto
show date
show dhcp client interface VALUE
show dhcp client interfaces
show dhcp server all
show dhcp server status
show dhcp server subnet VALUE ip-pools
show dhcp server subnets
show dns primary
show dns secondary
show dns suffix
show dns tertiary
show domainname
show extended commands
show fcd VALUE all
show format all
show format date
show format netmask
show format time
show group VALUE
show groups
show host name VALUE ipv4
show host name VALUE ipv6
show host names ipv4
show host names ipv6
show hostname
show igmp
show igmp groups interface VALUE
show igmp groups interface VALUE local
show igmp groups interface VALUE static
show igmp groups local
show igmp groups static
show igmp if-stat VALUE
show igmp if-stats
show igmp interface VALUE
show igmp interfaces
show igmp stats
show igmp stats error
show igmp stats receive
show igmp stats transmit
show igmp summary
show inactivity-timeout
show installer available_local_packages
show installer available_packages
show installer installed_packages
show installer package_status
show interface VALUE 6in4s
show interface VALUE alias VALUE
show interface VALUE aliases
show interface VALUE all
show interface VALUE ipv4-address
show interface VALUE ipv6-address
show interface VALUE ipv6-local-link-address
show interface VALUE loopback VALUE
show interface VALUE loopbacks
show interface VALUE monitor-mode
show interface VALUE protocol-list
show interface VALUE rx-ringsize
show interface VALUE tx-ringsize
show interface VALUE vlans
show interface VALUE { comments mac-addr mtu state speed duplex auto-negotiation type }
show interface VALUE { ipv6-autoconfig }
show interface VALUE { link-state }
show interface VALUE { statistics }
show interfaces all
show iphelper services
show iphelper stats
show ipv6-state
show lcd access
show lcd backlight timeout
show lcd screensaver mode
show lcd screensaver timeout
show mail-notification server
show mail-notification username
show management interface
show mcvr vrid VALUE all
show mcvr vrid VALUE authtype
show mcvr vrid VALUE backup-addresses
show mcvr vrid VALUE hello-interval
show mcvr vrid VALUE password
show mcvr vrid VALUE priority
show mcvr vrid VALUE priority-delta
show mcvr vrids
show message all [ status ]
show message banner [ status ]
show message motd [ status ]
show mfc cache
show mfc interface
show mfc orphans
show mfc stats
show mfc summary
show neighbor dynamic-table
show neighbor interface-table
show neighbor parameters
show neighbor static-table
show neighbor table
show net-access telnet
show netflow all
show netflow collector [ export-format ]
show netflow collector [ ip ]
show netflow collector [ port ]
show netflow collector [ srcaddr ]
show netflow collector for-ip VALUE [ export-format ]
show netflow collector for-ip VALUE [ port ]
show netflow collector for-ip VALUE [ srcaddr ]
show netflow collector for-ip VALUE for-port VALUE [ export-format ]
show netflow collector for-ip VALUE for-port VALUE [ srcaddr ]
show ntp active
show ntp current
show ntp servers
show ospf
show ospf border-routers
show ospf database [ detailed ]
show ospf database area VALUE [ detailed ]
show ospf database areas [ detailed ]
show ospf database asbr-summary-lsa [ detailed ]
show ospf database checksum
show ospf database database-summary
show ospf database external-lsa [ detailed ]
show ospf database network-lsa [ detailed ]
show ospf database nssa-external-lsa [ detailed ]
show ospf database router-lsa [ detailed ]
show ospf database summary-lsa [ detailed ]
show ospf database type VALUE [ detailed ]
show ospf errors
show ospf errors dd
show ospf errors hello
show ospf errors ip
show ospf errors lsack
show ospf errors lsr
show ospf errors lsu
show ospf errors protocol
show ospf events
show ospf interface VALUE [ detailed ]
show ospf interface VALUE stats
show ospf interfaces [ detailed ]
show ospf interfaces stats
show ospf neighbor VALUE [ detailed ]
show ospf neighbors [ detailed ]
show ospf packets
show ospf routemap
show ospf summary
show password-controls all
show password-controls complexity
show password-controls deny-on-fail allow-after
show password-controls deny-on-fail enable
show password-controls deny-on-fail failures-allowed
show password-controls deny-on-nonuse allowed-days
show password-controls deny-on-nonuse enable
show password-controls expiration-lockout-days
show password-controls expiration-warning-days
show password-controls force-change-when
show password-controls history-checking
show password-controls history-length
show password-controls min-password-length
show password-controls palindrome-check
show password-controls password-expiration
show pbr rules
show pbr summary
show pbr tables
show pim
show pim bootstrap
show pim candidate-rp
show pim group-rp-mapping VALUE
show pim interface VALUE
show pim interfaces
show pim joins
show pim memory
show pim neighbor VALUE
show pim neighbors
show pim rps
show pim sparse-mode-stats
show pim stats
show pim summary
show pim timers
show pppoe client id VALUE
show protocol-rank
show proxy ip-address
show proxy port
show rba all
show rba role VALUE
show rba roles
show rba user VALUE
show rba users
show rdisc
show rdisc interface VALUE
show rdisc interfaces
show rdisc stats
show rdisc summary
show rip
show rip errors
show rip interface VALUE
show rip interfaces
show rip neighbors
show rip packets
show rip routemap
show rip summary
show route
show route aggregate
show route all
show route all aggregate
show route all bgp
show route all direct
show route all kernel
show route all ospf
show route all rip
show route all static
show route bgp
show route bgp aspath
show route bgp communities
show route bgp detailed
show route bgp metrics
show route bgp suppressed
show route destination VALUE
show route direct
show route exact VALUE
show route inactive
show route inactive aggregate
show route inactive bgp
show route inactive direct
show route inactive kernel
show route inactive ospf
show route inactive rip
show route inactive static
show route kernel
show route less-specific VALUE
show route more-specific VALUE
show route ospf
show route rip
show route static
show route summary
show routed krt
show routed memory
show routed resources
show routed version
show routemap VALUE all
show routemaps
show router-id
show router-options
show router-options
show snapshot VALUE all
show snapshot VALUE date
show snapshot VALUE desc
show snapshot VALUE size
show snapshots
show snmp addresses
show snmp agent
show snmp agent-version
show snmp community
show snmp contact
show snmp location
show snmp mode
show snmp traps enabled-traps
show snmp traps polling-frequency
show snmp traps receivers
show snmp traps trap-user
show snmp usm user VALUE
show snmp usm users
show sysenv all
show sysenv fans
show sysenv ps
show sysenv temp
show sysenv volt
show syslog all
show syslog auditlog
show syslog cplogs
show syslog filename
show syslog log-remote-addresses
show tacacs_enable
show tag list
show time
show timezone
show upgrade packages
show uptime
show user VALUE
show user VALUE force-password-change
show user VALUE gid
show user VALUE homedir
show user VALUE lock-out
show user VALUE realname
show user VALUE shell
show user VALUE uid
show users
show version all
show version os build
show version os edition
show version os kernel
show version product
show virtual-system all
show volume VALUE
show vpn tunnel VALUE
show vpn tunnels
show vrrp
show vrrp interface VALUE
show vrrp interfaces
show vrrp stats
show vrrp summary
show vsx
show web daemon-enable
show web session-timeout
show web ssl-port
start transaction
tacacs_enable
upgrade cd
upgrade local VALUE
ver
LSMcli
LSMenabler
SnortConvertor
config_system
cp_conf
cpca
cpca_client
cpca_create
cpca_dbutil
cpconfig
cphaprob
cphastart
cphastop
cpinfo
cplic
cpshared_ver
cpstart
cpstat
cpstop
cptop
cpwd_admin
diag
dtps
etmstart
etmstop
fgate
fips
fw
fwaccel
fwm
ifconfig
ips
netstat
patch
ping
ping6
raid_diagnostic
raidconfig
rtm
rtmstart
rtmstop
rtmtopsvc
sim
top
traceroute
vpn
vsx_util
CPEnforcementModule1>

Wednesday, January 22, 2014

Brocade FCX: How To Install And Configure The FCX-2SFPP 2-port 10G Module (2-SFP+) For 10G Fiber Uplinks

I had a hard time finding any kind of configuration documentation for installing the 10G fiber module (the FCX-2SFPP 2-port 10G Module (2-SFP+) in this example).  I had two to install the other night, so I thought I would document how to do this in case anyone else needs to know.  But I have to tell you, I had one problem in particular that really caused me about half of my maintenance window.  Ill describe below.  So, with that said, I had a bigger picture project that included installing and re-configuring several ICX6450s and also connecting them to the core FCX648S via 10G fiber.  Ill focus only on the module install/configuration on this post.  I had a 6 hour window for the whole project, which should have been plenty of time.


So as you can see on the left, this is the FCX-2SFPP 2-port 10G Module (2-SFP+) module that Im installing.  I plan on using it to connect 10 gig uplinks to ICX6450s.  I have two of these to install.  There may be plenty of documentation out there for configuration of these and some release notes, but I couldnt seem to find anything useful.  Hence this post.


Before I put these modules in, below is what I saw when doing a 'show module'.  You can see that I only see module 1, which is the 48 port Ethernet ports/fiber combo.  Also, you see the module in the back of the FCX for the stacking.  Nothing else.




As you can see, this FCX does not have it:

core#sh module
       Module                                         Status Ports Starting MAC
U1:M1  FCX-48GS 48-port Management Module               OK     48   0024.38c3.80x0
U1:M2  FCX-2XGC 2-port 16G Module (2-CX4)               OK     2    0024.38c3.80x1
U2:M1  FCX-48GS 48-port Management Module               OK     48   0024.38c3.80x0
U2:M2  FCX-2XGC 2-port 16G Module (2-CX4)               OK     2    0024.38c2.b4x1
core#

Just FYI, this is where the module goes in.


So its time to put the module in.  You take off the blank and install the module.

Just slide it in and screw in the two screws.  Remember to power off the switches.  I did find documentation that says that you have to do that.  However, you really dont.  During this process, I had to reseat one of the modules when troubleshooting and TAC told me to reseat it with power on.  Obviously its hot swappable.  Anyway, I put the module in and you have to run the following command to configure the FCX module.  I ran the following command in config t.  Remember, I doing this on two stacked FCXs.  Below is for putting the first module in the first FCX:
FCXcore(config)#stack unit 1
FCXcore(config-unit-1)#module 3 ?
  fcx-cx4-2-port-16g-module
  fcx-sfpp-2-port-10g-module
  fcx-xfp-2-port-10g-module
FCXcore(config-unit-1)#module 3 fcx-sfpp-2-port-10g-module
FCXcore(config-unit-1)#exit

Now, the module should show up.  However, in my case it didn't.  This is where my biggest time consumption came.  Trying to figure out why.  When I ran the 'show module' command, I got the same output as above.  I rebooted the switch, same result.  I reseated the module.  Same thing. The FCX just didn't see the module.  So, I called TAC.
So to make a long story short, I got a girl who had no clue as to what she was doing.  I gave her some time to try to work this out, but after 40 minutes, I asked her to escalate the ticket.  On occasion, I have come across TAC engineers that appear to have never taken a call before.  My confidence quickly deteriorates in these cases.  I dont have time for them to learn while Im in a maintenance window.
So after I got another TAC engineer on the phone, he quickly found that there was a bug in my firmware version for detecting that particular module.  I was running code FCXR07202d.  So the answer was to upgrade to FCXR07300e.  I didnt have that readily available, but I did have FCXR07300f.  That works just as well.  So, I tftp'ed the boot image (grz07302.bin) and the new firmware and did the upgrade.  Then rebooted.  Then I did the 'show module' and it comes up just fine.
sp-core#sh mod
       Module                                         Status Ports Starting MAC
U1:M1  FCX-48GS 48-port Management Module               OK     48   0024.38c3.80c0
U1:M2  FCX-2XGC 2-port 16G Module (2-CX4)               OK     2    0024.38c3.80f1
U1:M3  FCX-2XG 2-port 10G Module (2-XFP)                CFG    2    0024.38c3.80f3
U2:M1  FCX-48GS 48-port Management Module               OK     48   0024.38c3.80c0
U2:M2  FCX-2XGC 2-port 16G Module (2-CX4)               OK     2    0024.38c2.b4f1
U2:M3  FCX-2XG 2-port 10G Module (2-XFP)                CFG    2    0024.38c2.b4f3

Notice that is says CFG under status.  I had to go back and tell the FCX what the module was again (see above where I go into each stack unit), then reboot the FCXs again to get it to an 'OK' status.
After the reboot:
sp-core#sh mod
       Module                                         Status Ports Starting MAC
U1:M1  FCX-48GS 48-port Management Module               OK     48   0024.38c3.80c0
U1:M2  FCX-2XGC 2-port 16G Module (2-CX4)               OK     2    0024.38c3.80f1
U1:M3  FCX-2XG 2-port 10G Module (2-XFP)                OK    2    0024.38c3.80f3
U2:M1  FCX-48GS 48-port Management Module               OK     48   0024.38c3.80c0
U2:M2  FCX-2XGC 2-port 16G Module (2-CX4)               OK     2    0024.38c2.b4f1
U2:M3  FCX-2XG 2-port 10G Module (2-XFP)               OK    2    0024.38c2.b4f3

Now that the FCX sees the module, its time to get the 10G gbics in and connect to the uplinks.

Dont forget, the 10Gig gbics are sold separately from the module.
Here are a few other ways to verify your module shows up if you want to check it like one of these:
Do a 'show run':
FCXcore#show run
stack unit 1
  module 1 fcx-48-port-management-module
  module 2 fcx-cx4-2-port-16g-module
  module 3 fcx-sfpp-2-port-10g-module
  priority 128
  stack-port 1/2/1 1/2/2

FCXcore#show int brief
Check for int X/3/1 and X/3/2

FCXcore#show version
...
==========================================================================
UNIT 1: SL 2: FCX-2XGC 2-port 16G Module (2-CX4)
==========================================================================
UNIT 1: SL 3: FCX-2SFPP 2-port 10G Module (2-SFP+)
==========================================================================
UNIT 2: SL 1: FCX-48GS 48-port Management Module
...

Now that things are up and running, it should look this this below.  You should see green activity lights on the side of the module.