Virtual Private Routed Network Services
7210 SAS M Services Guide Page 619
Interface SAP Commands
sap
Syntax sap sap-id [create]
no sap sap-id
Context config>service>vprn>if
Description This command creates a Service Access Point (SAP) within a service. A SAP is a combination of port 
and encapsulation parameters which identifies the service access point on the interface and within the 
7210 SAS. Each SAP must be unique. 
All SAPs must be explicitly created. If no SAPs are created within a service or on an IP interface, a 
SAP will not exist on that object. 
Enter an existing SAP without the create keyword to edit SAP parameters. The SAP is owned by the 
service in which it was created. 
A SAP can only be associated with a single service. A SAP can only be defined on a port that has 
been configured as an access port using the config interface port-type port-id mode access 
command. Channelized TDM ports are always access ports.
If a port is shutdown, all SAPs on that port become operationally down. When a service is shutdown, 
SAPs for the service are not displayed as operationally down although all traffic traversing the service 
will be discarded. The operational state of a SAP is relative to the operational state of the port on 
which the SAP is defined. 
The no form of this command deletes the SAP with the specified port. When a SAP is deleted, all 
configuration parameters for the SAP will also be deleted. 
Default No SAPs are defined. 
Special Cases VPRN — A VPRN SAP must be defined on an Ethernet interface. 
sap ipsec-id.private | public:tag — This parameter associates an IPSec group SAP with this 
interface. This is the public side for an IPSec tunnel. Tunnels referencing this IPSec group in the 
private side may be created if their local IP is in the subnet of the interface subnet and the routing 
context specified matches with the one of the interface. 
This context will provide a SAP to the tunnel. The operator may associate an ingress and egress QoS 
policies as well as filters and virtual scheduling contexts. Internally this creates an Ethernet SAP that 
will be used to send and receive encrypted traffic to and from the MDA. Multiple tunnels can be 
associated with this SAP. The “tag” will be a dot1q value. The operator may see it as an identifier. The 
range is limited to 1 — 4094.
Parameters sap-id — Specifies the physical port identifier portion of the SAP definition. See Common CLI 
Command Descriptions on page 939 for command syntax.
port-id — Specifies the physical port ID in the slot/mda/port format.
If the card in the slot has Media Dependent Adapters (MDAs) installed, the port-id must be in the 
slot_number/MDA_number/port_number format.  For example 2/3 specifies port 3 on  MDA 2 
in slot .