This section lists the CLIs that are qualified for the CLI add-on feature templates in Cisco IOS XE Release Amsterdam 17.2.1v.
ACL Commands
ip access-list extended acl_1
11 permit object-group employee_1 any any
!
AppNav Commands
service-insertion appnav-controller-group scg
appnav-controller 192.3.3.1 vrf 2
appnav-controller 192.3.3.2 vrf 2
!
service-insertion service-node-group acg1
service-node 192.3.3.3
!
service-insertion service-context waas/1
appnav-controller-group scg
service-node-group acg1
service-policy p1
enable
!
service-insertion waas interface Tunnel2
service-insertion waas interface Tunnel3
!
AppQoE Commands
appqoe
no tcpopt enable
BFD Commands
bfd color mpls
hello-interval 300000
no pmtu-discovery
multiplier 60
!
bfd color lte
hello-interval 300000
pmtu-discovery
multiplier 60
!
bfd color 3g
hello-interval 300000
no pmtu-discovery
multiplier 60
!
bfd app-route multiplier 6
bfd app-route poll-interval 4294967295
Cisco BGP Commands
router bgp
address-family no-vrf ipv4
address-family no-vrf ipv6
address-family with-vrf ipv4
address-family with-vrf ipv6
bgp always-compare-med
bgp bestpath as-path multipath-relax
bgp bestpath med missing-as-worst
bgp deterministic-med
bgp graceful-restart
bgp bestpath compare-routerid
bgp log-neighbor-changes
bgp router-id
distance bgp extern-as
distance bgp internal-as
distance bgp local
maximum-paths eibgp
timers bgp holdtime
timers bgp keepalive-interval
neighbor dns-address1 remote-as 999999999
neighbor dns-address1 ebgp-multihop 255
neighbor dns-address1 password 7 00141215174C04140B1E1E
neighbor dns-address1 shutdown
neighbor dns-address1 timers 65534 65535
neighbor dns-address2 remote-as 999999
neighbor dns-address2description test_neighbor_1
neighbor dns-address2ebgp-multihop 255
neighbor dns-address2 password 7 13151601181B0B382F1B7A
neighbor dns-address2 shutdown
neighbor dns-address2 timers 65534 65535
neighbor 10.228.0.129 remote-as 999999999
neighbor 10.228.0.129 advertise-map ADVERTISE non-exist-map NON-EXIST
neighbor 10.228.0.129 ha-mode graceful-restart disable
propagate-aspath
address-family ipv4 unicast vrf 1
redistribute connected
redistribute omp
redistribute static
exit-address-family
!
address-family ipv6 unicast vrf 1
redistribute connected
redistribute omp
redistribute static
exit-address-family
propagate-aspath
!
address-family ipv4 unicast
aggregate-address 192.168.51.0 255.255.255.0 as-set summary-only
aggregate-address 192.168.52.0 255.255.255.0 as-set summary-only
neighbor 10.0.0.1 advertise-map ADVERTISE non-exist-map NON-EXIST
neighbor dns-address1 remote-as 999999999
neighbor dns-address1 activate
neighbor dns-address1 advertisement-interval 600
neighbor dns-address1 maximum-prefix 2147483647 100
neighbor dns-address1 maximum-prefix 769434 100 restart 65535
neighbor dns-address1 next-hop-self
neighbor dns-address1 send-community both
neighbor dns-address2 remote-as 999999
neighbor dns-address2 activate
neighbor dns-address2 advertisement-interval 600
neighbor dns-address2 maximum-prefix 98765 100 restart 65535
neighbor dns-address2 next-hop-self
neighbor dns-address2 route-map <route_map_name>
neighbor dns-address2 send-community both
neighbor dns-address2 timers 3 9
network dns-address2 mask 255.255.255.0
network 192.168.51.0 mask 255.255.255.0
network 192.168.52.0 mask 255.255.255.0
exit-address-family
!
timers bgp 60 180
!
Class Map Commands
class-map match-any BestEffort
match qos-group 3
!
class-map match-any Bulk
match qos-group 4
!
class-map match-any Critical
match qos-group 1
!
class-map match-any Critical-Low
match qos-group 2
!
class-map match-any BULK
match qos-group 2
!
class-map match-any CONTROL-SIGNALING
match qos-group 4
!
class-map match-any CRITICAL-DATA
match qos-group 1
!
class-map match-any Default
match qos-group 5
!
class-map match-any INTERACTIVE-VIDEO
match qos-group 3
!
class-map match-any LLQ
match qos-group 0
!
class-map match-any Queue0
match qos-group 0
!
class-map match-any Queue1
match qos-group 1
!
class-map match-any Queue2
match qos-group 2
!
class-map match-any Queue3
match qos-group 3
!
class-map match-any Queue4
match qos-group 4
!
class-map match-any Queue5
match qos-group 5
!
class-map type inspect match-all cmap
match access-group name cmap
!
pass
!
class-map match-any Queue4
match qos-group 0
!
Crypto Commands
crypto ikev2 authorization policy li_policy
exit
no crypto ikev2 diagnose error
crypto ikev2 keyring if-ipsec256-ikev2-keyring
peer if-ipsec256-ikev2-keyring-peer
address 172.16.93.1
pre-shared-key cisco123
!
!
crypto ikev2 policy policy1-global
proposal p1-global
!
crypto ikev2 profile if-ipsec256-ikev2-profile
aaa authorization group psk list default li_policy
authentication local pre-share
authentication remote pre-share
no config-exchange request
keyring local if-ipsec256-ikev2-keyring
lifetime 86400
match identity remote address 172.16.93.2
!
crypto ikev2 proposal p1-global
encryption aes-cbc-128 aes-cbc-256
group 14 15 16 2
integrity sha1 sha256 sha384 sha512
!
!
crypto ipsec transform-set if-ipsec256-ikev2-transform esp-gcm 256
mode tunnel
!
crypto ipsec profile if-ipsec256-ipsec-profile
set ikev2-profile if-ipsec256-ikev2-profile
set pfs group16
set transform-set if-ipsec256-ikev2-transform
set security-association lifetime kilobytes disable
set security-association lifetime seconds 3600
set security-association replay window-size 512
!
no crypto isakmp diagnose error
crypto isakmp aggressive-mode disable
parameter-map type inspect-global
multi-tenancy
vpn zone security
!
no crypto ikev2 diagnose error
no crypto isakmp diagnose error
EIGRP Commands
router eigrp eigrp-name
address-family ipv4 vrf {{SVPN}} autonomous-system {{SVPN}}
af-interface {{LAN_EIGRP_INT1_name}}
no dampening-change
no dampening-interval
hello-interval 5
hold-time 15
split-horizon
exit-af-interface
!
af-interface {{LAN_EIGRP_INT2_name}}
no dampening-change
no dampening-interval
hello-interval 5
hold-time 15
split-horizon
exit-af-interface
!
{{LAN_EIGRP_neighbor1_tf}} neighbor {{LAN_EIGRP_neighbor1_ip_addr}} {{LAN_EIGRP_neighbor1_src_int}}
{{LAN_EIGRP_neighbor2_tf}} neighbor {{LAN_EIGRP_neighbor2_ip_addr}} {{LAN_EIGRP_neighbor2_src_int}}
{{LAN_EIGRP_neighbor3_tf}} neighbor {{LAN_EIGRP_neighbor3_ip_addr}} {{LAN_EIGRP_neighbor3_src_int}}
{{LAN_EIGRP_neighbor4_tf}} neighbor {{LAN_EIGRP_neighbor4_ip_addr}} {{LAN_EIGRP_neighbor4_src_int}}
{{LAN_EIGRP_neighbor5_tf}} neighbor {{LAN_EIGRP_neighbor5_ip_addr}} {{LAN_EIGRP_neighbor5_src_int}}
network {{LAN_EIGRP_INT1_linknet}}
network {{LAN_EIGRP_INT2_linknet}}
topology base
redistribute omp metric 1000000 255 1 1500
redistribute static
exit-af-topology
!
exit-address-family
!
!
Global Configuration Commands
memory free low-watermark processor 70694
platform punt-keepalive disable-kernel-core
no service pad
no service tcp-small-servers
no service udp-small-servers
platform console virtual
platform qfp utilization monitor load 80
platform punt-keepalive disable-kernel-core
hostname myorg
username admin privilege 15 secret
username
username employee1 privilege
username employee1 secret encryption
username employee1 secret secret
clock timezone UTC
logging monitor
logging persistent
logging persistent size 104857600 filesize 10485760
logging buffered
logging console
logging trap errors
logging rate-limit
logging host 10.90.9.6 vrf 4
logging source-interface loopback111 vrf 4
login on-success log
no crypto ikev2 diagnose error
no crypto isakmp diagnose error
crypto pki trustpoint TP-self-signed-3865005142
enrollment selfsigned
revocation-check none
subject-name cn=IOS-Self-Signed-Certificate-3865005142
line con 0
login authentication default
speed 9600
stopbits 1
!
login authentication default
speed 19200
stopbits 1
line vty 0 4
transport input ssh
line vty 5 80
transport input ssh
!mac address-table aging-time <timeout>
lldp run
Interface GigabitEthernet Commands
no shutdown
arp timeout
ip address 192.10.6.5
vrf forwarding vrf10
ip address dhcp client-id GigabitEthernet1
no ip redirects
ip mtu
mtu
ip nat outside
ip ospf 65535 area 1
ip ospf authentication message-digest
ip ospf network broadcast
ip ospf cost
ip ospf dead-interval
ip ospf hello-interval
ip ospf message-digest-key 255 md5 7 00051105005E0D01072846
ip ospf priority
ip ospf retransmit-interval
negotiation auto
service-policy output policy_1
ip tcp adjust-mss 1100
cdp enable
ip nat outside
bandwidth 100000
vrrp 64 address-family ipv4
vrrpv2
track 2 shutdown
address 10.50.4.3 primary
priority 11
timers advertise 1000
interface GigabitEthernet1.101
no shutdown
encapsulation dot1Q 101
vrf forwarding 2
ip address 192.168.66.1
no ip redirects
ip directed-broadcast
ip mtu 1496
ipv6 address 2001:DB8::1
ipv6 enable
ip nbar protocol-discovery
ip policy route-map policy_1
ip helper-address 10.8.4.5
ip helper-address 10.50.4.6
tunnel-interface
encapsulation gre weight 1
encapsulation ipsec weight 1
no border
color lte
no last-resort-circuit
no low-bandwidth-link
max-control-connections 1
exclude-controller-group-list 1
no vbond-as-stun-server
vmanage-connection-preference 5
port-hop
carrier default
nat-refresh-interval 5
hello-interval 1000
hello-tolerance 12
no allow-service all
no allow-service bgp
allow-service dhcp
allow-service dns
allow-service icmp
no allow-service sshd
no allow-service netconf
no allow-service ntp
no allow-service ospf
no allow-service stun
allow-service https
no allow-service snmp
bandwidth-downstream 300000000
interface GigabitEthernet4.302
tloc-extension GigabitEthernet
access-list 4451-Marking-Spoke in
interface Dialer1
no shutdown
encapsulation ppp
ip address negotiated
ip nat outside
dialer pool 1
ppp chap hostname ntt
ppp chap password ntt
ppp authentication chap calling
interface Loopback100
interface VirtualPortGroup0
interface Vlan1
pppoe enable group global
pppoe-client dial-pool-number
interface Tunnel
ip unnumbered GigabitEthernet0/2.101
no ip redirects
ipv6 unnumbered GigabitEthernet0/2.101
no ipv6 redirects
tunnel source GigabitEthernet0/2.101
tunnel mode sdwan
interface atm 0/3/0
description site1
ip mtu 1496
no shutdown
interface atm 0/3/0.1 point-to-point
description site1
ip mtu 1496
[no] ip address 10.0.0.0 255.255.255.252
no shutdown
load-interval 30
pvc 0/100
[no] shutdown
bridge-dot1q encap 1
encapsulation aal5snap
dialer pool-member 1
protocol ppp dialer
interface GigabitEthernet1
description branch1
no ip address
no shutdown
ip mtu 1500
interface GigabitEthernet4.302
description branch1
encapsulation dot1Q 101
pppoe enable group global
pppoe-client dial-pool-number
no shutdown
[no] ip address 192.10.6.5
ip mtu 1496
interface Dialer1
ip address negotiated
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap callin
ppp chap hostname ntt
ppp chap password ntt
ppp pap sent-username ntt password ntt
ppp sent-password ntt password 0 ntt
no shutdown
controller VDSL 0/3/0
description branch1
operating mode auto
[no] firmware filename bootflash:firmware
[no] modem auto
[no] sra
no shutdown
training log filename flash:4431.log
[no] bitswap
line-mode single-wire line 0
sync mode none
no diagnostics DELT
IP Commands
ip dhcp use hardware-address client-id
no ip dhcp use class
ip host <vbond ip_address1 ip_address2>
ip ssh version 2
ip dhcp use vrf remote
ip multicast route-limit
ip route
ip name-server 10.70.1.2
ip name-server vrf
ip prefix-list prfx1 permit 172.16.55.1
ip bootp server
no ip source-route
no ip http server
ip route vrf Mgmt-intf 172.16.55.10
ipv6 route vrf Mgmt-intf 2001:DB8:101::1
ip tcp mss 1200
no ip http secure-server
no ip igmp ssm-map query dns
ip nat settings central-policy
ip nat inside source list nat-dia-vpn-hop-access-list interface GigabitEthernet5 overload
ip nat translation tcp-timeout
ip nat translation udp-timeout
cdp run
object-group service cdp-service-1
ip
ip access-list extended access_list_1
permit object-group group1 any any
ip arp proxy disable
no ip rcmd rcp-enable
no ip rcmd rsh-enable
no ip domain lookup
ip dhcp use class
ip dhcp pool vrf-1-GigabitEthernet5
option 150 ip ip-list
vrf
lease 365 0 0
default-router 10.1.19.15
dns-server 172.16.79.1
domain-name dns1
network 255.255.255.0
ip http authentication local
no ip finger
ip http server
ip http secure-server
no ip igmp ssm-map query dns
ip nat pool natpool-GigabitEthernet0/0/0-0 10.4.1.11 10.4.1.250 prefix-length 24
ip nat inside source list global-list pool natpool-GigabitEthernet0/0/0-0 overload egress-interface GigabitEthernet4
ip nat inside source list nat-dia-vpn-hop-access-list interface GigabitEthernet4.101 overload
ip nat inside source list nat-dia-vpn-hop-access-list interface GigabitEthernet4.102 overload
ip nat inside source list nat-dia-vpn-hop-access-list interface GigabitEthernet4.103 overload
ip nat inside source list nat-dia-vpn-hop-access-list interface GigabitEthernet4.104 overload
ip nat inside source list nat-dia-vpn-hop-access-list interface GigabitEthernet4.105 overload
ip nat translation tcp-timeout 10
ip nat translation udp-timeout 40
ip nat route vrf 65529 0.0.0.0 0.0.0.0 global
ip nat route vrf 2 172.16.200.0 255.255.255.0 global
ipv6 route vrf 1 2001:DB8:EF::1
vlan internal allocation policy ascending
ip redirects
route-map trigger permit
match ip address prefix
line vty 0 4
access-class
ipv6 access-class
Logging Commands
logging trap informational syslog-format rfc5424
logging tls-profile profile1 tls-version TLSv1.1
logging tls-profile profile1 ciphersuite aes-256-cbc-sha
NAT Commands
nat64 translation timeout tcp 60
nat64 translation timeout udp 1
NTP Commands
ntp authentication-key 65535 md5 test
ntp server 10.0.1.1 source GigabitEthernet8 key 65535 prefer version 4
ntp source GigabitEthernet8
ntp trusted-key
ntp access-group peer 25
Object Group Commands
object-group network Auth-Servers
host 10.16.137.22
!
object-group service ZBF-DIA-External
tcp 80
udp
tcp range 1024 65535
tcp source 23
ip
icmp
!
OMP Commands
omp
no shutdown
overlay-as 4294967295
send-path-limit 16
ecmp-limit 16
graceful-restart
no as-dot-notation
timers
holdtime 65535
advertisement-interval 65535
graceful-restart-timer 43200
eor-timer 3600
exit
address-family ipv4
advertise bgp
advertise ospf external
advertise connected
advertise static
advertise eigrp
advertise lisp
advertise isis
!
address-family ipv6
advertise bgp
advertise connected
advertise static
advertise eigrp
advertise lisp
advertise isis
OSPF Commands
router ospf 1 10
auto-cost reference-bandwidth 100
timers throttle spf 200 1000 10000
router-id 10.68.202.1
compatible rfc1583
default-information originate
default-information originate metric-type 1
distance ospf external 110
distance ospf inter-area 110
distance ospf intra-area 110
redistribute connected subnets
redistribute nat-route dia
!
max-metric router-lsa on-startup 86400
area 4294967295 nssa no-summary
area 4294967295 range 10.1.1.0 255.255.255.0 not-advertise
area 4294967295 range 192.168.1.0 255.255.255.0 cost 16777214
area 4294967295 range 172.16.5.0 255.255.255.0 advertise
default-information originate always metric 16777214 metric-type 1
redistribute static
Policy Commands
route-map rmap1 deny 10
match ip address prefix-list prfx1
!
route-map rmap1 permit 10
match as-path 120
match ip address prefix-list prfx1 !
route-map clear-df permit 10
!
parameter-map type inspect-global
alert on
log dropped-packets
multi-tenancy
vpn zone security
!
policy
app-visibility
flow-visibility
implicit-acl-logging
log-frequency 1000
policer pol1
rate 500000000
burst 15000
exceed drop
lists
data-prefix-list Email-Server
ip-prefix prfx1
class-map
class LLQ queue 0
class Queue0 queue 0
class VOICE queue 0
class CRITICAL-DATA queue 1
class Queue1 queue 1
class BULK queue 2
class Queue2 queue 2
class INTERACTIVE-VIDEO queue 3
class Queue3 queue 3
class CONTROL-SIGNALING queue 4
class Queue4 queue 4
class Default queue 5
class Queue5 queue 5
!
rewrite-rule Branch-QoS-Rewrite-Template
class BULK low dscp 10
class BULK high dscp 10
class CRITICAL-DATA low dscp 28
class CRITICAL-DATA high dscp 28
class INTERACTIVE-VIDEO low dscp 34
class INTERACTIVE-VIDEO high dscp 34
!
access-list acl1
sequence 10
match
destination-ip 172.16.5.10
!
action drop
default-action accept
action drop
count 192-167-199-DROP-CNT
access-list 4451-Marking-Spoke
sequence 1
match
destination-ip 172.16.10.5
!
action accept
count SSL
class LLQ
count EXCHANGE
class CONTROL-SIGNALING
action accept
count RTP
class LLQ
action accept
count HTTP_10K_60K
class BULK
action accept
count HTTP_BROWSING
class BULK
count Oracle
class CRITICAL-DATA
count Citrix
class INTERACTIVE-VIDEO
count SSL
class BULK
count EXCHANGE
class CONTROL-SIGNALING
count Video
class INTERACTIVE-VIDEO
"access-list Marking-HQ
sequence 1
match
source-ip 10.74.201.203/32"
"!
sequence 21
match
source-ip 10.74.201.202/32
!
action accept
set
dscp 18"
"policy-map type inspect security-zbfw
class security-zbfw-seq-1
inspect"
"sequence 181
match
destination-data-prefix-list QOS-QUALYS-SCANNERS"
"sequence 11
match
destination-ip 10.53.128.23/32
destination-port 443"
Policy Map Commands
policy-map type inspect pmap1
class cos-map-generic inspect
bandwidth remaining percent 5
policy-map Branch-QoS-Policy
class Queue0
priority level 1
police rate percent 30
!
!
class Queue1
bandwidth remaining ratio 20
random-detect precedence-based
!
class class-default
bandwidth remaining ratio 10
random-detect precedence-based
!
class Queue3
bandwidth remaining ratio 20
random-detect precedence-based
!
class Queue4
bandwidth remaining ratio 10
random-detect precedence-based
!
class Queue5
bandwidth remaining ratio 10
random-detect precedence-based
!
!
policy-map shape_GigabitEthernet0/0/1
class class-default
service-policy Branch-QoS-Policy
shape average 1000000000
!
class class-default
drop
!
!
QOS Policy commands
policy-map QOS-POLICY-MAP
class Queue0
priority percent 30
class Queue1
bandwidth percent 20
class Queue3
bandwidth percent 20
class class-default
bandwidth percent 30
policy-map QOS-POLICY-MAP
class Queue0
priority percent 30
class Queue1
bandwidth percent 20
random-detect
class Queue3
bandwidth percent 20
class class-default
bandwidth percent 30
random-detect
policy-map QOS-POLICY-MAP
class Queue0
priority percent 30
class Queue1
bandwidth percent 20
random-detect
class Queue3
bandwidth percent 20
class class-default
bandwidth percent 30
random-detect
policy-map QOS-POLICY-MAP
class Queue0
priority level 1
police rate percent 30
class Queue1
bandwidth percent 20
random-detect
class Queue3
bandwidth percent 20
class class-default
bandwidth percent 30
random-detect
policy-map QOS-POLICY-MAP
class Queue0
priority level 1
police rate percent 30
class Queue1
bandwidth remaining ratio 20
random-detect
class Queue3
bandwidth remaining ratio 20
class class-default
bandwidth remaining ratio 30
random-detect
RADIUS Commands
radius-server dead-criteria time 10 tries 3
radius-server deadtime 15
Security Commands
security
ipsec
rekey 1209600
replay-window 4096
authentication-type sha1-hmac ah-sha1-hmac ah-no-id
pairwise-keying
SNMP Commands
snmp-server community Log view Logging RO
snmp-server community Trap view Interface RO
snmp-server contact
snmp-server enable traps
snmp-server engineID local
snmp-server group test_group_v3 v3 noauth read view_test_v3
snmp-server host 10.100.51.1 vrf 1 version 2c Log udp-port 7081
snmp-server host 10.1.15.15 version 3 noauth test_user_v3 udp-port 161
snmp-server community xxxxx view yyyyy RO acl-name1
snmp-server ifindex persist
snmp-server location
snmp-server trap timeout
snmp-server trap-source Loopback
snmp-server user test_user_v3 test_group_v3 v3 encrypted
snmp-server view Interface 1.3.1 included
snmp-server view Logging 1.4.1 included
snmp-server view view_test_v3 1.3.6.1 included
SSL Proxy Commands
sslproxy
no enable
rsa-key-modulus 2048
certificate-lifetime 730
eckey-type P256
ca-tp-label
settings expired-certificate drop
settings untrusted-certificate drop
settings unknown-status drop
settings certificate-revocation-check none
settings unsupported-protocol-versions drop
settings unsupported-cipher-suites drop
settings failure-mode close
settings minimum-tls-ver TLSv1
no tcpproxy enable
System Commands
gps-location latitude 37.368140
gps-location longitude -121.913658
system-ip
overlay-id
site-id
port-offset
control-session-pps
controller-group-list 1 2
device-groups a
admin-tech-on-failure
sp-organization-name
organization-name
max-omp-sessions 8
port-hop
track-transport
track-default-gateway
upgrade-confirm
console-baud-rate
vbond 192.168.5.4 port 12346
logging
enable
UTD Commands
utd multi-tenancy
utd engine standard multi-tenancy
utd global
file-reputation
cloud-server cloud-isr-asn.amp.cisco.com
est-server cloud-isr-est.amp.cisco.com
query-interval 300
!
file-analysis
cloud-server panacea.threatgrid.com
!
!
file-analysis profile FILE-ANA-PROFILE1
file-types
pdf
ms-exe
new-office
rtf
mdb
mscab
msole2
wri
xlw
flv
swf
!
alert level critical
!
file-reputation profile FILE-REP-PROFILE1
alert level critical
!
file-inspection profile FILE-INS-PROFILE1
analysis profile FILE-ANA-PROFILE1
reputation profile FILE-REP-PROFILE1
!
Voice Commands
sip-ua
!
voice class codec 1000
codec preference 1 g729r8
codec preference 2 g711ulaw bytes 160
codec preference 3 g711alaw bytes 160
codec preference 4 g722-64 bytes 160
!
voice service voip
allow-connections sip to sip
no supplementary-service sip handle-replaces
no supplementary-service sip moved-temporarily
no supplementary-service sip refer
sip
registrar server expires max 300 min 200
!
!
voice register global
max-dn 200
max-pool 100
system message "SRST mode"
!
voice register pool 100
id network 10.0.0.0 mask 255.0.0.0
!
dial-peer voice 1000 voip
description Branch 1
destination-pattern 1T
no shutdown
voice-class codec 1000
session transport udp
session protocol sipv2
session target ipv4:10.1.101.8
dtmf-relay rtp-nte digit-drop sip-kpml sip-notify
!
dial-peer voice 2000 voip
description Branch 1
destination-pattern 2T
no shutdown
voice-class codec 1000
session transport udp
session protocol sipv2
session target ipv4:10.1.101.8
dtmf-relay rtp-nte digit-drop sip-kpml sip-notify
!
dial-peer voice 8000 voip
description Branch 7
destination-pattern 8T
no shutdown
voice-class codec 1000
session transport udp
session protocol sipv2
session target ipv4:10.1.101.8
dtmf-relay rtp-nte digit-drop sip-kpml sip-notify
!
dial-peer voice 9000 voip
description CallManager for Dial 9
destination-pattern 9T
no shutdown
voice-class codec 1000
session transport udp
session protocol sipv2
session target ipv4:10.1.101.8
dtmf-relay rtp-nte digit-drop sip-kpml sip-notify
!
VRF Commands
vrf definition
address-family ipv4
address-family ipv6
description
rd
route-target export
route-target import
service tcp-keepalives-in
service tcp-keepalives-out
service tcp-small-servers
service udp-small-servers
Zone Based Firewall commands
zone security LAN
vpn 2
!
zone security WAN
vpn 0
!
zone-pair security ZP_LAN_WAN_test-policy source LAN destination WAN
service-policy type inspect test-policy
!
zone-pair security ZP_WAN_LAN_test-policy source WAN destination LAN
service-policy type inspect test-policy