ocsp (PKI)Sets the HTTP method for the Online Certificate Status Protocol (OCSP) request.
ocsp-url (PKI)Defines the URL to be used for Online Certificate Status Protocol (OCSP) requests.
-
opaque-capability (OSPFv2)Enables the opaque link-state advertisement (LSA) capability.
openflow controllerConnects devices to openflow controller
connections.
openflow default
send-to-controllerConfigures a device-level option to
forward the packets to the controller.
openflow enable
Enables or disables the OpenFlow hybrid port-mode on the port.
openflow hello-reply
disableEnables the second hello message sent from
the switch to the controller.
openflow log timeoutEnables or disables the syslog message
that is generated when a flow is deleted as a result of idling or hard timeout.
openflow
protected-vlans Enables or disables the protected VLANs
on an OpenFlow hybrid port mode interface.
openflow purge-timeConfigures the maximum amount of time (in seconds) before stale flows are purged from
the OpenFlow flow table after a switchover, failover, or OS upgrade.
optical-monitorConfigures the device to monitor optical transceivers in the system.
optionSpecifies Dynamic Host Configuration Protocol (DHCP) options to be exchanged between
the server and the client.
originator-idConfigures MSDP to use the specified interface IP address as the IP address of the
rendezvous point (RP) in a source-active (SA) message.
other-protoConfigures the other protocol VLAN and enters the other protocol VLAN configuration
mode.
overlay-gatewayConfigures a VXLAN overlay-gateway name
and enters gateway configuration mode.
ownerDesignates a virtual router as the Virtual Router Redundancy Protocol (VRRP) owner
and configures priority and track values.
packet-inerror-detectEnables the monitoring of a port for inError packets and defines the maximum number
of inError packets allowed for the port during the configured sampling interval.
pass-throughEnables pass-through which allows certain protocol packets to pass through ports that
are enabled for Flexible authentication.
-
password Specifies the password to be used for the key in encrypted form for the cryptographic
algorithm.
pdu-rate (EFM-OAM) Configures the number of Protocol Data Units (PDUs) to be transmitted per second
by the Data Terminal Equipment (DTE).
pe-idAssigns and reserves an ID for an SPX port extender (PE) unit.
pe-nameAssigns a name to the PE unit.
peerConfigures the software clock to synchronize a peer or to be synchronized by a peer.
peer disable-fast-failoverDisables the MCT fast-failover mode.
peer timersConfigures the keep-alive and hold-time timers for peer devices.
peer-infoConfigures the peer system ID and system key for a single dynamic Link Aggregation
Group (LAG).
permit (Extended IPv4 ACLs and
IPv6 ACLs)Inserts filtering rules to permit
packets in IPv4 extended named or numbered ACLs or IPv6 ACLs.
permit (Standard IPv4
ACLs)Inserts filtering rules in IPv4 standard
named or numbered ACLs that will permit packets.
phy cable-diagnostics
tdrRuns a Virtual Cable Test (VCT) Time
Domain Reflectometry (TDR) cable diagnostic test for a specified port.
phy-fifo-depthConfigures the depth of the transmit and receive FIFOs.
pingVerifies whether a device can reach another device through the network.
pki authenticateAuthenticates the certificate authority (CA) to the router by obtaining the self-signed
certificate of the CA.
pki cert-validateDetermines if a trustpoint has been successfully authenticated.
pki enrollRequests certificates from the certificate authority (CA) for each key pair of the
router.
pki-entityConfigures a PKI entity and enters a configuration sub-mode where you can define PKI
end-user parameters.
pki profile-enrollmentEnters PKI enrollment configuration submode, where you can onfigure PKI enrollment
parameters.
pki trustpointEnters PKI trustpoint configuration mode, where PKI CA parameters can be configured.
poison-local-routesConfigures the device to avoid routing loops by advertising local RIP or RIPng routes
with a cost of 16 (infinite or unreachable) when these routes go down.
poison-reverseEnables poison reverse loop prevention, either globally or on an individual interface,
by assigning an "unreachable" cost to a route before advertising it on the interface
where the route was learned. The global command can be used for RIP or RIPng routes.
pool (DHCPv6)Configures a DHCPv6 server pool.
port securityEnters port security configuration mode.
port-down-authenticated-mac-cleanupEnables forced reauthentication of the hosts if all the ports on the device go down.
port-nameConfigures the names of individual ports or a group of ports.
port-name (LAG)Assigns a port name to an individual port in a LAG.
- port-profile
Configures a port profile on the
device.
port-statistics-reset-timestamp enable Enables the display of the elapsed timestamp information in the output of the
show statistics
command.
portsAdds ports in a LAG.
preferred-lifetime (DHCPv6)Specifies the length of time that the DHCPv6 server keeps the IPv6 prefix active.
prefix6 (DHCPv6)Assigns a range of IPv6 prefixes to a subnet.
-
prefix-list Associates an IPv6 prefix list with a Router Advertisement (RA) guard policy.
prefix-list (RIP)Applies a pre-configured prefix list to permit or deny RIP routes globally.
preforwarding-timeConfigures the preforwarding time interval, the time a port will remain in the preforwarding
state before changing to the forwarding state.
pre-shared-key Configures the pre-shared MACsec key on the interface.
prf Configures a pseudorandom function (PRF) for an Internet Key Exchange version 2 (IKEv2)
proposal.
priorityConfigures a priority value for the device. This value is used along with other factors
to determine controller election if a stack failover or merge occurs.
priority-flow-controlEnables priority flow control (PFC) on a priority group.
priority-flow-control enableEnables priority flow control (PFC) globally or on an individual port.
privilegeConfigures the management privilege access level of a command.
profile-configConfigures the port buffer, queue buffer, port descriptor, and queue descriptor for
a port.
proposal
(IKEv2)Configures an Internet Key Exchange version 2 (IKEv2) proposal for an IKEv2 policy.
proposal
(IPsec)Configures an IP security (IPsec) proposal for an IPsec profile.
protectedConfigures VRF traffic protection for an Internet Key Exchange version 2 (IKEv2) profile.
protected-portConfigures a port as protected, restricting communication among such ports at the
system level, providing isolation to end hosts.
prune-timerConfigures the time a PIM device maintains a prune state for a forwarding entry.
prune-waitConfigures the time a PIM device waits before stopping traffic to neighbor devices
that do not want the traffic.
pstatStarts or stops the collecting of CPU packet statistics.
pstat field-addSpecifies the fields for which statistics on the number of packets sent to the CPU
will be collected.
pstat field-deleteRemoves the specified fields from the collection of CPU packet statistics.
pstat maxConfigures the maximum number of fields that will be used in the collection CPU packet
statistics.
pstat saveWrites the CPU packet statistics counter entries to flash memory as a text file (pstat.txt),
so the file can be transferred to a server for analysis.
- ptp-clock transparent
Enables transparent clock (TC) mode for
precision time protocol (PTP).
pvlan mappingCreates a Private VLAN domain with Primary-Secondary pair. Maps promiscuous and host
ports to VLAN based forwarding in PVLAN domain.
pvlan pvlan-trunkCreates a Private VLAN domain with Primary-Secondary pair. Maps ISL and host ports
to VLAN based forwarding in PVLAN domain.
pvlan typeConfigures the PVLAN as a primary, isolated, or community PVLAN.
pvst-modeEnables Per-VLAN Spanning Tree Plus (PVST+) support on a port immediately.
pvstplus-protectPrevents flooding and resulting port blocking on an interface when a Per-VLAN Spanning
Tree Plus (PVST+) packet is received on a port configured for Multiple Spanning Tree
Protocol (MSTP), blocking the PVST+ Bridge Protocol Data Unit (BPDU) and marking the
port as ERR-DISABLED.
qd-bufferConfigures the port buffers.
qd-descriptorConfigures the allowable port descriptors.
qos egress-buffer-profile port-share-level Configures an egress buffer profile for the share port level.
qos egress-buffer-profile queue-share-level Configures an egress buffer profile for the share queue level.
qos egress-shape-ifg-bytesConfigures egress shaper IFG bytes.
qos ingress-buffer-profile Configures an ingress buffer profile.
- qos guaranteed-rate
Configure the minimum percentage of a port
outbound bandwidth guaranteed to the queues.
qos mechanismConfigures the Quality of Service (QoS) queuing method.
qos
monitor-queue-drop-countersConfigures the port that the
RUCKUS ICX 7150 device monitors for the incrementing of the egress queue drop counters.
qos nameRenames the queue.
qos priority-to-pgConfigures priority-to-priority-group (PG) mapping for priority flow control (PFC).
qos profileChanges the minimum bandwidth percentages of the eight Weighted Round Robin (WRR)
queues.
qos scheduler-profile Configures a user-defined Quality of Service (QoS) scheduler profile.
- qos sflow-set-cpu-rate-limit
Sets the CPU rate limit for sFlow.
qos tagged-priorityChanges the VLAN priority of 802.1p to hardware forwarding queue mappings.
qos-internal-trunk-queue
Modifies the dynamic buffer-share level of inter-packet-processor (inter-pp) HiGig
links egress queues on ICX 7450 devices.
qos-tos map dscp-priorityChanges the ifferentiated Services Code Point (DSCP)-to-internal-forwarding-priority
mappings.
radius-client coa hostConfigures the key to be used between the Change of Authorization (CoA) client and
FastIron device.
radius-client coa port
Changes the default CoA (Change of Authorization) port number.
radius-server accounting
Configures to send interim updates of accounting messages to the RADIUS server at
regular intervals..
radius-server dead-timeConfigures the interval at which the test user message is sent to the server to check
the status of non-responding servers that are marked as dead.
radius-server enable Configures the device to allow RADIUS server management access only to clients connected
to ports within the port-based VLAN.
radius-server hostConfigures the Remote Authentication Dial-In User Service (RADIUS) server.
radius-server keyConfigures the value that the device sends to the RADIUS server when trying to authenticate
user access.
radius-server retransmitConfigures the maximum number of retransmission attempts for a request when a RADIUS
authentication request times out.
radius-server test Sets the user name to be used in the RADIUS request packets for RADIUS dead server
detection.
radius-server timeoutConfigures the number of seconds the device waits for a response from a RADIUS server
before either retrying the authentication request, or determining that the RADIUS
servers are unavailable and moving on to the next authentication method in the authentication
method list.
-
raguard Configures the current interface as a trusted, untrusted, or host Router Advertisement
(RA) guard port.
range6 (DHCPv6)Specifies a range of IPv6 prefixes for a subnet for a DHCPv6 server.
rapid-commit (DHCPv6)Configures the DHCPv6 Rapid Commit option (DHCPv6 option 14) for the DHCPv6 server for faster IPv6 prefix delegation.
rarpAssigns a static IP RARP entry for static routes.
rate-limit-arpLimits the number of ARP packets the
RUCKUS device accepts during each second.
rate-limit inputConfigures a port-based rate-limiting policy.
rate-limit outputConfigures the maximum rate at which outbound traffic is sent on a port priority queue
or on a LAG port.
- rate-limit-log
Configures the global level BUM suppression logging interval.
rconsoleEstablishes a remote console session with
a stack unit.
rconsole (SPX)Establishes a remote connection to a control bridge or port extender unit.
rdDistinguishes a route for Virtual Routing and Forwarding (VRF) instances.
re-authentication (Flexible Authentication)Periodically re-authenticates clients connected to MAC authentication-enabled interfaces
and 802.1X-enabled interfaces.
rear-moduleDefines the operating mode of ports on the rear module.
reauth-periodConfigure the interval at which clients connected to MAC authentication-enabled ports
and 802.1X authentication-enabled ports are periodically reauthenticated.
reauth-timeConfigures the number of seconds an authenticated user remains authenticated.
rebind-time (DHCPv6)Specifies the time interval after which a client transitions to the rebinding state
after receiving an IPv6 address.
-
redistribute
Configures the device to redistribute IPv4 and IPv6 routes from one routing domain
to another.
-
redistribute
(BGP)Configures the device to redistribute RIP routes, directly connected routes, or static
routes into BGP4 and BGP4+.
redistribute (RIP)Configures the device to redistribute connected routes, learned static routes, OSPF
routes, or BGP4 routes through RIP. The RIP router can then advertise these routes
to RIP neighbors.
redistribute (RIPng)Configures RIPng to advertise routes from the specified protocol or connections.
refresh-time (DHCPv6)Sets the refresh time for a DHCPv6 Server.
regenerate-seq-num
Changes the sequence numbers of the rules within a specified access control list (ACL)
to provide flexibility in inserting new rules between existing rules.
register-probe-timeConfigures the time the PIM router waits for a register-stop from a rendezvous point
(RP) before it generates another NULL register to the PIM RP
register-rate-limitConfigures the register message rate limit
for Protocol Independent Multicast (PIM) and IPv6 Protocol Independent Multicast
(PIMv6).
register-suppress-timeConfigures the interval at which the PIM router triggers the NULL register message.
relative-utilizationConfigures uplink utilization lists that display the percentage of a given uplink
port's bandwidth that is used by a specific list of downlink ports.
reloadReloads a stand-alone device, a stack, or specified stack units other than the active
controller.
remarkAdds a comment to describe entries in an IPv4 or IPv6 ACL.
remote-identifierConfigures a remote identifier for an Internet Key Exchange version 2 (IKEv2) profile.
remote-loopback Starts or stops the remote loopback procedure on a remote device.
remove-tagged-portsRemoves all tagged member ports from a VLAN or from multiple VLANs.
remove-untagged-portsRemoves all untagged member ports from a VLAN or from multiple VLANs.
remove-vlan (VLAN Group) Removes individual VLANs or a range of VLANs from a VLAN group.
renewal-time (DHCPv6)Specifies the time interval after which the client transitions to the renewing state
upon receipt of an IPv6 address.
replay-protectionUsed with extended sequence numbering in IPsec to prevent replay attacks by assigning
each encrypted packet an increasing sequence number that is tracked at the IPsec endpoint.
reserved-vlan-mapAssigns a different VLAN ID to the reserved VLAN.
responder-onlyConfigures responder-only mode for an IKEv2 profile.
restart-portsConfigures a VSRP-configured device to shut down its ports when a failover occurs
and restart after a period of time.
restart-vsrp-portConfigures a single port on a VSRP-configured device to shut down when a failover
occurs and restart after a period of time.
- restconf config-sync
Forces configuration synchronization from
the FI system to the RESTConf running configuration database.
- restconf config-sync-interval
Configures the sync periodic interval when
periodic config sync is enabled. Whenever a configuration change is detected on the
system,
a complete configuration sync to the RESTCONF DB is performed.
- restconf enable
Enables RESTCONF management
interface.
- restconf enable-config-sync
Synchronizes restconf database after a
conf-sync-interval time is performed.
restricted-vlanConfigures a specific VLAN as the restricted VLAN for all ports on the device to place
the client port when the authentication fails.
reverse-manifest-enableEnables the system backup to USB operation to be carried on the system.
reverse-path-check Enables uRPF for all Layer 3 routes.
revocation-check (PKI)Specifies the method to be used for certificate revocation checks.
-
rfc1583-compatibility
(OSPF)Configures compatibility with RFC 1583.
ring-interfacesConfigures the primary and secondary interfaces for the ring to control outward traffic
flow.
rmon alarmConfigures an Remote Monitoring (RMON) alarm.
rmon eventDefines the action to be taken when an alarm is reported and collects and stores reported
events for retrieval by an Remote Monitoring (RMON) application.
rmon historyConfigures an RMON history control.
route-mapCreates a route map and enters route-map
configuration mode.
route-onlyDisables support for Layer 2 switching on
a
RUCKUS Layer
3 switch.
route-precedenceConfigures a table that defines the order (precedence) in which multicast routes are
selected from the multicast routing table (mRTM) and unicast routing (uRTM) table.
route-precedence admin-distanceConfigures route precedence so that multicast routes are selected from the best route
in the multicast routing table (mRTM) and unicast routing (uRTM) table.
router bgpEnables BGP routing.
router msdpEnables multicast source discovery protocol (MSDP) on a router.
-
router ospf Enables and configures the Open Shortest Path First version 2 (OSPFv2) routing protocol.
router pimConfigures basic global Protocol
Independent Multicast (PIM) Sparse parameters on a device within the PIM Sparse
domain and
enters PIM-router configuration mode.
router ripEnables Routing Information Protocol (RIP) globally on the device. Does not enable
RIP at the interface level.
router vrrpGlobally enables Virtual Router Redundancy Protocol (VRRP).
router vrrp-extendedGlobally enables Virtual Router Redundancy Protocol Extended (VRRP-E) and enters VRRP-E
router configuration mode.
router vsrpEnables the Virtual Switch Redundancy Protocol (VSRP) on Layer 2 or Layer 3 switches.
rp-addressConfigures a device interface as a rendezvous point (RP).
rp-adv-intervalConfigures the interval at which the candidate rendezvous point (RP) configured on
the device sends candidate-RP advertisement messages to the bootstrap router (BSR).
rp-candidateConfigures a device as a candidate rendezvous point (RP) for all multicast groups
with the prefix 224.0.0.0/4, by default, and explicitly adds or deletes groups with
other prefixes.
rp-embeddedConfigures embedded-rendezvous point (RP) support on PIM devices.
rpf-modeEnables strict or loose unicast Reverse Path Forwarding (uRPF) mode on FastIron ICX
devices.
rsakeypair (PKI)Specifies which RSA keypair to use during enrollment.
rspan destinationConfigures a Remote Switched Port Analyzer (RSPAN) destination port for port mirroring.
rspan sourceConfigures a Remote Switched Port Analyzer (RSPAN) source port and properties for
port mirroring.
rspan-vlanConfigures the VLAN to support Remote Switched Port Analyzer (RSPAN) traffic analysis.
sa-filterConfigures filters for incoming and outgoing Source-Active (SA) messages from and
to multicast source discovery protocol (MSDP) neighbors.
save-current-valuesConfigures a backup to save the VSRP timer values received from the master instead
of the timer values configured on the backup.
scale-timerChanges the timer scale, the value used by the software to calculate all VSRP timers.
-
scale-timer vrrp-extended Configures a scale time factor that increases the timing sensitivity across all configured
and default Virtual Router Redundancy Protocol Extended (VRRP-E) timers.
scheduler-profile Attaches a scheduler profile to one or more ports.
scp (License)Copies a license file from an SCP-enabled client to the license database of a
RUCKUS ICX device.
securewipeSecurely erases the flash memory contents
permanently according to DoD 5220.22-M standards, and afterwards reinstalls the
ICX device.
secure-loginConfigures Web Authentication to use secure (HTTPS) or non-secure (HTTP) login and
logout pages.
secure-mac-addressConfigures secure MAC addresses on tagged and untagged interfaces.
-
send-lifetime Configures the time period during which the key on a keychain becomes active and is
valid to be sent.
sequence (permit | deny in
Extended IPv4 ACLs)Inserts filtering rules in IPv4 extended named or numbered ACLs.
sequence (permit | deny in IPv6
ACLs)Inserts filtering rules in IPv6 access control lists (ACLs).
sequence (permit | deny in
Standard IPv4 ACLs)Inserts filtering rules in IPv4 standard named or numbered ACLs. Standard ACLs permit
or deny traffic according to source address only.
server (NTP)Configures the device in client mode and
specifies the Network Time Protocol (NTP) servers to synchronize the system clock.
service local-user-protectionPrevents unauthorized deletion or modification of a user account.
service password-encryption Configures the password encryption service to encrypt the passwords using different
encryption methods.
set interface null0Drops traffic when the null0 statement becomes the active setting as determined by
the route-hop selection process.
set ip next-hopConfigures the next-hop IP address for the traffic that matches a match statement
in the route map.
set next-hop-ip-tunnel Configures an IPsec or GRE tunnel interface as the next hop of a PBR route map.
sflow agent-ipConfigures an arbitrary IPv4 or IPv6 address as the sFlow agent IP address.
sflow destinationConfigures an sFlow collector for the destination address.
sflow enableEnables sFlow forwarding globally.
sflow exportConfigures exporting, to the sFlow collector, the CPU usage and memory usage information
or exporting CPU-directed data.
sflow forwardingEnables sFlow forwarding on individual interfaces.
sflow forwarding (LAG)Enables sFlow forwarding on an individual port in a deployed LAG.
sflow management-vrf-disableDisables the management Vitual Routing and Forwarding (VRF) in sFlow.
sflow max-packet-size Configures the maximum flow sample size sent to the sFlow collector.
sflow polling-intervalConfigures the sflow polling interval.
sflow sampleChanges the default sampling rate.
sflow sourceConfigures the sFlow source interface (IPv4 or IPv6) from which the IP source address
is selected for the sFlow datagram.
sflow source-portConfigures the source sFlow UDP port.
sflow versionConfigures the version used for exporting sFlow data.
short-path-forwardingEnables short-path forwarding on a Virtual Router Redundancy Protocol (VRRP) router.