Important: In this release only one active charging service can be configured in a system.
Important: The commands or keywords/variables that are available are dependent on platform type, product version, and installed license(s).
Important: This command is available only in StarOS 8.1 and in StarOS 9.0 and later releases, and must be used to configure the Policy-based Stateful Firewall and NAT features.
access_ruledef_name must be an alpha and/or numeric string of 1 through 63 characters in length, and can contain punctuation characters.
Important: An access ruledef can be referenced by multiple firewall rulebases.
Important: Access ruledefs are different from ACS ruledefs.
Also see the Firewall-and-NAT Access Ruledef Configuration Mode Commands chapter.
The following command creates an access ruledef named ruledef1, and enters the Firewall-and-NAT Access Ruledef Configuration Mode:
policy_name and must be an alpha and/or numeric string of 1 through 63 characters in length.
Also see the ACS Bandwidth Policy Configuration Mode Commands chapter.
The following command creates a bandwidth policy named test73, and enters the ACS Bandwidth Policy Configuration Mode:
number must be an integer from 1 through 255.
number must be an integer from 1 through 255.
Important: A maximum of 2048 charging actions can be configured in the active charging service.
charging_action_name must be an alpha and/or numeric string of 1 through 63 characters in length, and can contain punctuation characters.
Also see the ACS Charging Action Configuration Mode Commands chapter.
The following command creates a charging action named action123 and changes to the ACS Charging Action Configuration Mode:
Important: A maximum of 64 Content Filtering Category Policies can be configured in the active charging service.
cf_policy_id must be an integer from 1 through 4,294,967,295.
description [ description_string ]
description_string must be an alpha and/or numeric string of 1 through 31 characters in length.
Note that both description and
description_string are optional.
“description description_string” saves
description_string as the new description.
“description” removes the previously specified description.
This description is displayed in the output of the “show content-filtering category policy-id id id” and “
show active-charging service name service_name” commands.
Also see the Content Filtering Policy Configuration Mode Commands chapter.
Important: The
group keyword is only available in StarOS 8.1 and later releases.
group_name must be an alpha and/or numeric string of 1 through 63 characters in length.
Also see the Credit Control Configuration Mode Commands chapter.
Description This command has been obsoleted, and is replaced by the
credit-control command.
edr_format_name must be a string of 1 through 63 characters in length.
Also see the EDR Format Configuration Mode Commands chapter.
queue_size must be an integer from 1 through 2500.
deactivate_margin is a percentage value, and must be an integer from 1 through 100.
max_flows must be an integer from 1 through 1000.
memory-share memory_share
memory_share is a percentage value, and must be an integer from 1 through 100.
usage_threshold is a percentage value, and must be an integer from 1 through 100.
|
•
|
downlink: Enables flow recovery for packets from downlink direction.
|
|
•
|
uplink: Enables flow recovery for packets from uplink direction.
|
timeout must be an integer from 1 through 86400.
Important: NAT flows will not be recovered.
|
•
|
all: Enables/disables all of the following NAT ALGs.
|
|
•
|
ftp: Enables/disables File Transfer Protocol (FTP) NAT ALG.
|
|
•
|
h323: Enables/disables H323 NAT ALG.
|
|
•
|
pptp: Enables/disables Point-to-Point Tunneling Protocol (PPTP) NAT ALG.
|
|
•
|
rtsp: Enables/disables Real Time Streaming Protocol (RTSP) ALG.
|
|
•
|
sip: Enables/disables Session Initiation Protocol (SIP) NAT ALG.
|
|
•
|
non-scanner: Specifies the connection attempt success percentage for a non-scanner.
|
percentage must be an integer from 60 through 99.
|
•
|
scanner: Specifies the connection attempt success percentage for a scanner.
|
percentage must be an integer from 1 through 40.
inactivity-timeout inactivity_timeout
inactivity_timeout must be an integer from 60 through 1800.
|
•
|
tcp: Specifies response timeout for TCP.
|
response_timeout must be an integer from 3 through 30.
|
•
|
udp: Specifies response timeout for UDP.
|
response_timeout must be an integer from 3 through 60.
|
•
|
block inactivity-timeout inactivity_timeout: Specifies blocking any subsequent traffic from the scanner. If the scanner is found to be inactive for the inactivity-timeout period, then the scanner is no longer blocked, and traffic is allowed.
|
inactivity_timeout specifies the scanner inactivity timeout period, in seconds, and must be an integer from 1 through 4294967295.
|
•
|
log-only: Specifies logging scanner information without blocking scanner traffic.
|
Important: This command is available only in StarOS 8.1. This command must be used to configure the Rulebase-based Stateful Firewall and NAT features.
firewall_ruledef_name must be a string of 1 through 63 characters in length, and can contain punctuation characters.
Important: A firewall ruledef can be referenced by multiple firewall rulebases.
Important: The firewall ruledefs are different from the ACS ruledefs.
Also see the Firewall-and-NAT Access Ruledef Configuration Mode Commands chapter.
The following command creates a firewall ruledef named fw_ruledef1, and enters the Firewall Ruledef Configuration Mode:
Important: This command variant is available only in StarOS 8.3 and later releases.
no_of_servers specifies the number of servers to track, and must be an integer from 1 through 100.
Important: This command is available only in 11.0 and later releases. This command must be used to configure the Stateful Firewall and NAT Action features.
action_name must be an alpha and/or numeric string of 1 through 63 characters in length.
[context_name]
hostname(config-fw-and-nat-action)#
Also see the Firewall-and-NAT Action Configuration Mode Commands chapter.
The following command creates a Firewall-and-NAT action named test1, and changes to the Firewall-and-NAT Action Configuration Mode:
Important: This command is available only in StarOS 8.1 and in StarOS 9.0 and later releases. This command must be used to configure the Policy-based Stateful Firewall and NAT features.
Important: When a Firewall-and-NAT policy is deleted, for all subscribers using the policy, Stateful Firewall and NAT processing is disabled, also ACS sessions for the subscribers are dropped. In case of session recovery, the calls are recovered but with Stateful Firewall and NAT disabled.
policy_name must be an alpha and/or numeric string of 1 through 63 characters in length.
[context_name]
hostname(config-fw-and-nat-policy)#
Also see the Firewall-and-NAT Policy Configuration Mode Commands chapter.
The following command creates a Firewall-and-NAT policy named test321, and changes to the Firewall-and-NAT Policy Configuration Mode:
Important: This command is available only in StarOS 10.2 and later releases.
Important: A maximum of 16 object groups can be configured in the active charging service. And a maximum of 128 objects can be configured within each object group.
group_name must be an alpha and/or numeric string of 1 through 63 characters in length.
Important: “string” is the only data type supported in this release.
Also see the ACS Group-of-Objects Configuration Mode Commands chapter.
The following command creates a group-of-objects named test4 with the data type string, and enters the ACS Group-of-Objects Configuration Mode:
Important: This command is customer specific. For more information contact your local sales representative.
Important: A maximum of 64 group-of-prefixed-URL groups can be configured in the active charging service.
group_name must be an alpha and/or numeric string of 1 through 63 characters in length.
Also see the ACS Group-of-Prefixed-URLs Configuration Mode Commands chapter.
The following command creates group-of-prefixed-urls named test5, and enters the ACS Group-of-Prefixed-URLs Configuration Mode:
Important: A maximum of 64 groups-of-ruledefs can be configured in the active charging service.
ruledefs_group_name must be unique within the active charging service, and must be a string of 1 through 63 characters in length. Up 64 groups may be configured.
Also see the ACS Group-of-Ruledefs Configuration Mode Commands chapter.
The following command creates a group-of-ruledefs named group1, and enters the ACS Group-of-Ruledefs Configuration Mode:
timeout must be an integer from 1 through 2147483647.
h323 timeout { admission adm_timeout | discovery disc_timeout | location loc_timeout | registration reg_timeout | unregistration unreg_timeout }
adm_timeout must be an integer from 1 through 20.
disc_timeout must be an integer from 1 through 20.
loc_timeout must be an integer from 1 through 20.
reg_timeout must be an integer from 1 through 20.
unregistration unreg_timeout
unreg_timeout must be an integer from 1 through 20.
max_tpkt_size must be an integer from 4 through 4096.
version_number must be an integer from 1 through 7.
host_pool_name must be a string of 1 through 63 characters in length, and can contain punctuation characters.
Important: Host pools configured in other ruledefs cannot be deleted.
Also see the ACS Host Pool Configuration Mode Commands chapter.
The following command creates a host pool named hostpool1, and enters the ACS Host Pool Configuration Mode:
Default: alg-media: 120 seconds;
flow-mapping: 300 seconds for TCP and 0 seconds for UDP;
icmp,
tcp,
udp: 300 seconds
For alg-media specifies the media inactivity timeout. The
idle_timeout value gets applied on RTP and RTCP media flows that are created for SIP/H.323 calls. The timeout is applied only on those flows that actually match the RTP and RTCP media pinholes that are created by the SIP/H.323 ALG.
imsi_pool_name must be a string of 1 through 63 characters in length, and can contain punctuation characters.
Important: IMSI pools configured in other ruledefs cannot be deleted.
Also see the ACS IMSI Pool Configuration Mode Commands chapter.
The following command creates an IMSI pool named imsipool1, and enters the ACS IMSI Pool Configuration Mode:
max_fragments must be an integer from 1 through 300.
content_id must be an integer from 0 through 4,294,967,295.
string must be an alpha and/or numeric string of 1 through 64 characters in length.
Important: This command is available only in StarOS 8.3 and later releases.
Important: This command is available only in StarOS 8.3 and later releases.
|
•
|
buffer: Specifies to buffer packets.
|
|
•
|
drop: Specifies to drop packets.
|
Important: This command is available only in StarOS 8.3 and later releases.
timeout must be an integer from 30 through 240.
Configures the system to detect all supported P2P protocols. Specifying all is the same as individually configuring each of the following protocols.
Important: The
facetime protocol option is available only in 9.0 and in 11.0 and later releases.
Important: The
gamekit protocol option is available only in 9.0 and in 11.0 and later releases.
packet_filter_name must be a string of 1 through 63 characters in length.
Also see the ACS Packet Filter Configuration Mode Commands chapter.
The following command creates a packet filter named filter3, and enters the ACS Packet Filter Configuration Mode:
duration must be an integer from 1 through 20.
bytes must be an integer from 1 through 4000000000.
Default: active-charging-group-of-ruledefs
When the ignore-when-removed option is configured, PCRF request for removal of Charging-Rule-Base-Name is ignored and no action is taken.
port_map_name must be an alpha and/or numeric string of 1 through 63 characters in length, and can contain punctuation characters.
Important: Port maps in use in other ruledefs cannot be deleted.
Also see the ACS Port Map Configuration Mode Commands chapter.
The following command creates a port map named portmap1, and enters the ACS Port Map Configuration Mode:
user_agent_name must be an alpha and/or numeric string of 1 through 32 characters in length.
The following command specifies the redirect user agent user_rule1 for conditional redirection of traffic flow:
Important: A maximum of 512 rulebases can be configured in the active charging service.
rulebase_name must be an alpha and/or numeric string of 1 through 63 characters in length, and can contain punctuation characters.
Also see the ACS Rulebase Configuration Mode Commands chapter.
The following command creates a rulebase named test1, and enters the ACS Rulebase Configuration Mode:
Important: A maximum of 2048 ruledefs can be configured in the active charging service.
ruledef ruledef_name [ -noconfirm ]
ruledef_name must be an alpha and/or numeric string of 1 through 63 characters in length, and can contain punctuation characters.
ruledef_name must be unique with in the service. Host pool, port map, IMSI pool, and firewall, routing, and charging ruledefs must have unique names.
Also see the ACS Ruledef Configuration Mode Commands chapter.
The following command creates an ACS ruledef named test1, and enters the ACS Ruledef Configuration Mode:
Important: This command is customer specific. For more information contact your local sales representative.
Default: no system-limit l4-flows
Important: This command is available only in StarOS 8.1 and in StarOS 9.0 and later releases.
Important: A maximum of 10 timedefs can be configured in the active charging service.
timedef timedef_name [ -noconfirm ]
timedef_name must be an alpha and/or numeric string of 1 through 63 characters in length.
Also see the ACS Timedef Configuration Mode Commands chapter.
The following command creates a timedef named test1, and enters the ACS Timedef Configuration Mode:
tpo_policy_name must be an alpha and/or numeric string of 1 through 63 characters in length.
Important: A maximum of 2048 TPO policies can be created in the system.
Also see the ACS TPO Policy Configuration Mode Commands chapter.
The following command creates a TPO policy named tpo_policy_1, and enters the ACS TPO Policy Configuration Mode:
tpo_profile_name must be an alpha and/or numeric string of 1 through 63 characters in length.
Important: A maximum of 2048 TPO profiles can be created in the system.
Also see the ACS TPO Profile Configuration Mode Commands chapter.
The following command creates a TPO profile named tpo_profile_1, and enters the ACS TPO Profile Configuration Mode:
udr_format_name must be an alpha and/or numeric string of 1 through 63 characters in length.
Also see the UDR Format Configuration Mode Commands chapter.
xheader_format_name must be an alpha and/or numeric string of 1 through 63 characters in length.
An x-header may be specified in a charging action to be inserted into HTTP GET and POST request packets. See xheader-insert CLI command in the
ACS Charging Action Configuration Mode Commands chapter. Also see the
ACS X-header Format Configuration Mode Commands chapter.
The following command creates an x-header format named test, and enters the ACS X-header Format Configuration Mode: