The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Description: Configure console methods
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa authentication login console
Description: Configure default methods
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa authentication login default
Description: Configure domain methods
Syntax:
WORD |
Login domain name |
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa authentication login domain <WORD>
Description: CLI informational banner to be displayed before user login (wrap with single quotes)
Syntax:
LINE |
CLI informational banner to be displayed before user login (wrap with single quotes) (Max Size None) |
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa banner <LINE>
Description: LDAP server group name.
Syntax:
WORD |
LDAP server group name |
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa group server ldap <WORD>
Description: RADIUS server group name.
Syntax:
WORD |
RADIUS server group name |
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa group server radius <WORD>
Description: TACACS+ server group name.
Syntax:
WORD |
TACACS+ server group name |
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa group server tacacsplus <WORD>
Description: AAACertRule
Syntax:
WORD |
Certificate name |
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa scvmm-certificate <WORD>
Description: Default role assigned by aaa-admin for remote authentication
Syntax:
<default-role-policy> |
<default-role-policy> |
Command Mode: configure : Configuration Mode
Command Path:
# configure [['terminal', 't']] (config)# aaa user default-role <default-role-policy>
Description: Absolute window configuration mode
Syntax:
window |
Configure scheduler window |
WORD |
Window name (Max size 31) |
Command Mode: scheduler : Scheduler configuration mode
Command Path:
# configure [['terminal', 't']] (config)# scheduler fabric|controller schedule <WORD> (config-scheduler)# absolute window <WORD>
Description: Apply an access-list on this subject
Syntax:
WORD |
Name of the access-list to apply (Max Size 64) |
WORD |
Directions |
Command Mode: subject : Configuration a subject on the contract
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# contract <WORD> [type <type>] (config-tenant-contract)# subject <WORD> (config-tenant-contract-subj)# access-group <WORD> <WORD>
Description: Create access-list
Syntax:
WORD |
Access-list Name (Max Size 64) |
Command Mode: tenant : tenant configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# access-list <WORD>
Description: Set The status of the locally-authenticated user account.
Syntax:
WORD |
status of the locally-authenticated user account |
Command Mode: username : Create a locally-authenticated user account
Command Path:
# configure [['terminal', 't']] (config)# username <WORD> (config-username)# account-status <WORD>
Description: Snapshot import action merge|replace
Syntax:
merge |
Merge with existing configuration |
replace |
Replace existing configuration |
Command Mode: snapshot import : Configuration import setup mode
Command Path:
# configure [['terminal', 't']] (config)# snapshot import <WORD> (config-import)# action merge|replace
Description: EIGRP Policy Address Family
Syntax:
ipv4 |
Address Family IPv4 |
ipv6 |
Address Family IPv6 |
unicast |
Unicast |
Command Mode: vrf : Configure VRF information
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router eigrp default (config-eigrp)# vrf member tenant <WORD> vrf <WORD> (config-eigrp-vrf)# address-family ipv4|ipv6 unicast
Description: Configure an address-family for peer
Syntax:
ipv4 |
Configure IPv4 address-family |
ipv6 |
Configure IPv6 address-family |
unicast |
Configure Unicast sub-address-family |
Command Mode: neighbor : Configure a BGP neighbor
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router bgp <fabric-ASN> (config-bgp)# vrf member tenant <WORD> vrf <WORD> (config-leaf-bgp-vrf)# neighbor A.B.C.D|A.B.C.D/LEN|A:B::C:D|A:B::C:D/LEN [l3out <WORD>] (config-leaf-bgp-vrf-neighbor)# address-family ipv4|ipv6 unicast
Description: Configure an address-family
Syntax:
ipv4 |
Configure IPv4 address-family |
ipv6 |
Configure IPv6 address-family |
unicast |
Configure unicast address-family |
Command Mode: vrf : Virtual Router Context
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router bgp <fabric-ASN> (config-bgp)# vrf member tenant <WORD> vrf <WORD> (config-leaf-bgp-vrf)# address-family ipv4|ipv6 unicast
Description: Configure the ip address for dns servers
Syntax:
A.B.C.D |
IP address in format i.i.i.i |
preferred |
(Optional) Configure the address to be preferred |
Command Mode: dns : Configure default dns policy
Command Path:
# configure [['terminal', 't']] (config)# dns (config-dns)# address <A.B.C.D> [preferred]
Description: Enable the state of the SSH communication service
Command Mode: ssh-service : SSH communication policy group
Command Path:
# configure [['terminal', 't']] (config)# comm-policy <WORD> (config-comm-policy)# ssh-service (config-ssh-service)# admin-state-enable
Description: Enable the state of the TELNET communication service
Command Mode: telnet : TELNET communication policy group
Command Path:
# configure [['terminal', 't']] (config)# comm-policy <WORD> (config-comm-policy)# telnet (config-telnet)# admin-state-enable
Description: Enable the state of the shellinabox communication service
Command Mode: shellinabox : SHELLINABOX communication policy group
Command Path:
# configure [['terminal', 't']] (config)# comm-policy <WORD> (config-comm-policy)# shellinabox (config-shellinabox)# admin-state-enable
Description: Enable the state of the HTTP communication service
Command Mode: http : HTTP communication policy group
Command Path:
# configure [['terminal', 't']] (config)# comm-policy <WORD> (config-comm-policy)# http (config-http)# admin-state-enable
Description: Enable the state of the HTTPS communication service
Command Mode: https : HTTPS communication policy group
Command Path:
# configure [['terminal', 't']] (config)# comm-policy <WORD> (config-comm-policy)# https (config-https)# admin-state-enable
Description: Set admin state of syslog group
Syntax:
enable |
Enable |
Command Mode: logging : Logging server group configuration mode
Command Path:
# configure [['terminal', 't']] (config)# logging server-group <WORD> (config-logging)# admin enable
Description: Set OSPF Interface Policy Controls
Command Mode: template ospf interface-policy : Configure OSPF Interface Policy Templates
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# template ospf interface-policy <WORD> tenant <WORD> (config-interface-policy)# advertise-subnet
Description: Route summarization
Syntax:
IP-PREFIX/LEN |
Aggregate IPv4 address and mask length |
as-set |
(Optional) Autonomous system set path information and community information |
Command Mode: vrf : Virtual Router Context
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router bgp <fabric-ASN> (config-bgp)# vrf member tenant <WORD> vrf <WORD> (config-leaf-bgp-vrf)# aggregate-address <IP-PREFIX/LEN> [as-set]
Description: The URL to return in the Access-Control-Allow-Origin HTTP header
Syntax:
WORD |
The URL to return in the Access-Control-Allow-Origin HTTP header (Max Size 256) |
Command Mode: http : HTTP communication policy group
Command Path:
# configure [['terminal', 't']] (config)# comm-policy <WORD> (config-comm-policy)# http (config-http)# allow-origin <WORD>
Description: Accept as-path with my AS present in it
Command Mode: neighbor : Configure a BGP neighbor
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router bgp <fabric-ASN> (config-bgp)# vrf member tenant <WORD> vrf <WORD> (config-leaf-bgp-vrf)# neighbor A.B.C.D|A.B.C.D/LEN|A:B::C:D|A:B::C:D/LEN [l3out <WORD>] (config-leaf-bgp-vrf-neighbor)# allow-self-as
Description: Allow writes for the RBAC rule
Command Mode: rbac rule : Create RBAC rule, security domain users can read subtree starting at specific object
Command Path:
# configure [['terminal', 't']] (config)# rbac rule <DN> <WORD> (config-rule)# allow-writes
Description: The number of occurrences of a local access service network
Syntax:
<1-10> |
Number of occurrences of AS number, default is 3. Number range from=1 to=10 |
Command Mode: neighbor : Configure a BGP neighbor
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router bgp <fabric-ASN> (config-bgp)# vrf member tenant <WORD> vrf <WORD> (config-leaf-bgp-vrf)# neighbor A.B.C.D|A.B.C.D/LEN|A:B::C:D|A:B::C:D/LEN [l3out <WORD>] (config-leaf-bgp-vrf-neighbor)# allowed-self-as-count <NUMBER>
Description: application configuration mode
Syntax:
WORD |
Application name (Max Size 64) |
Command Mode: tenant : tenant configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD>
Description: Set OSPF default area cost
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
<0-16777215> |
Cost value |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> default-cost <0-16777215>
Description: Enable OSPF in the l3Out
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
<l3out name> |
Configure ASN on an API configured L3Out |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> l3out <l3out name>
Description: Configure OSPF on Loopback
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
<Loopback Ip Address> |
Loopback Ip |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> loopback <Loopback Ip Address>
Description: Configure area as nssa
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> nssa
Description: Originate a default route
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
no-redistribute |
(Optional) No Redistribute area option |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> nssa default-information-originate [no-redistribute]
Description: Configure area as no-redistribute
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
default-information-originate |
(Optional) Originate a default route |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> nssa no-redistribute [default-information-originate]
Description: Translate LSAs
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
type7 |
From Type 7 to Type 5 |
suppress-fa |
Suppress forwarding address in translated LSAs |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> nssa translate type7 suppress-fa
Description: range
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
IP-PREFIX/LENGTH |
Summarized IP |
cost |
(Optional) Route cost |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> range <IP-PREFIX/LENGTH> [cost <cost>]
Description: Set Route Map
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
WORD |
Route Map Name (Max Size 63) |
out |
Apply policy to outgoing routes |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> route-map <WORD> out
Description: Configure area as a stub
Syntax:
<A.B.C.D|NUMBER> |
OSPF area ID |
Command Mode: vrf : Associate Router OSPF Policy with Tenant/VRF
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router ospf default (config-leaf-ospf)# vrf member tenant <WORD> vrf <WORD> (config-leaf-ospf-vrf)# area <A.B.C.D|NUMBER> stub
Description: Enable ARP flooding
Command Mode: bridge-domain : Configuration for bridge-domain
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# bridge-domain <WORD> (config-tenant-bd)# arp flooding
Description: Configure BGP Autonomous System number
Syntax:
<1-4294967295> |
Number that uniquely identifies an autonomous system. Number range from=1 to=4294967295 |
Command Mode: bgp : Border Gateway Protocol (BGP)
Command Path:
# configure [['terminal', 't']] (config)# pod 1 (config-pod)# bgp fabric (config-pod-bgp)# asn <NUMBER>
Description: An LDAP endpoint attribute to be used as the CiscoAVPair
Syntax:
<WORD> |
LDAP endpoint attribute (Max Size 63) |
Command Mode: ldap-server host : LDAP server DNS name or IP address
Command Path:
# configure [['terminal', 't']] (config)# ldap-server host <A.B.C.D|A:B::C:D|WORD> (config-host)# attribute <WORD>
Description: Configure a Custom attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
WORD |
custom label name |
arg |
|
WORD |
string to be matched |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match custom <WORD> <> <WORD>
Description: Configure a Datacenter name attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
arg |
|
WORD |
Value |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match datacenter <> <WORD>
Description: Configure a Domain name attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
arg |
|
WORD |
Value |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match domain <> <WORD>
Description: Configure a Guest-OS attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
arg |
|
WORD |
Value |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match guest-os <> <WORD>
Description: Configure a Hypervisor ID attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
arg |
|
WORD |
Value |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match hypervisor-id <> <WORD>
Description: Configure a IP address attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
<ip-addr/mask> |
Full IP Address and mask |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match ip <ip-addr/mask>
Description: Configure a MAC address attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
E.E.E |
MAC address (Option 1) |
EE-EE-EE-EE-EE-EE |
MAC address (Option 2) |
EE:EE:EE:EE:EE:EE |
MAC address (Option 3) |
EEEE.EEEE.EEEE |
MAC address (Option 4) |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match mac E.E.E|EE-EE-EE-EE-EE-EE|EE:EE:EE:EE:EE:EE|EEEE.EEEE.EEEE
Description: Configure a VM identifier attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
arg |
|
WORD |
Value |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match vm-id <> <WORD>
Description: Configure a VM name attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
arg |
|
WORD |
Value |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match vm-name <> <WORD>
Description: Configure a Vnic name attribute
Syntax:
WORD |
uSeg attribute name |
match |
Match criteria |
arg |
|
WORD |
Value |
Command Mode: epg : AEPg configuration mode
Command Path:
# configure [['terminal', 't']] (config)# tenant <WORD> (config-tenant)# application <WORD> (config-tenant-app)# epg <WORD> [type <WORD>] (config-tenant-app-epg)# attribute <WORD> match vnic <> <WORD>
Description: Configure authentication for the default ntp policy
Command Mode: ntp : Configure the default ntp policy
Command Path:
# configure [['terminal', 't']] (config)# pod 1 (config-pod)# ntp (config-ntp)# authenticate
Description: Configure ntp authentication keys for the default ntp policy
Syntax:
id |
Id for the authentication key. Number range from=1 to=65535 |
md5 |
(Optional) Configure the authentication key (Max Size 510) |
Command Mode: ntp : Configure the default ntp policy
Command Path:
# configure [['terminal', 't']] (config)# pod 1 (config-pod)# ntp (config-ntp)# authentication-key <id> [md5 <md5>]
Description: Set OSPF Policy Bandwidth Reference
Syntax:
reference-bandwidth |
OSPF Policy Bandwidth Reference |
<1-4000000> |
Bandwidth Reference Value in Mbps. Number range from=1 to=4000000 |
Command Mode: template ospf vrf-policy : Configure Router OSPF Timer Policy Templates
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# template ospf vrf-policy <WORD> tenant <WORD> (config-vrf-policy)# auto-cost reference-bandwidth <NUMBER>
Description: Autonomous System Configuration for EIGRP
Syntax:
<1-65535> |
The autonomous system number. Number range from=1 to=65535 |
l3out |
(Optional) Configure ASN on an API configured L3Out |
Command Mode: vrf : Configure VRF information
Command Path:
# configure [['terminal', 't']] (config)# leaf <101-4000> (config-leaf)# router eigrp default (config-eigrp)# vrf member tenant <WORD> vrf <WORD> (config-eigrp-vrf)# autonomous-system <NUMBER> [l3out <l3out>]