Security
68
"FD 100/320Gbps NT and FX NT IHub System
Basics, Management and OAM Guide"
3HH-11982-AAAA-TQZZA Issue: 10
4.4.2.35 shutdown
Table 71 shutdown command
4.4.2.36 renum
Table 72 renum command
Context configure>system>security>cpu-filter>ipv6-filter>entry>match
Description This command configures matching on the SYN bit being set or reset in the control bits of the
TCP header of an IP packet as an CPU filter match criterion.
The SYN bit is normally set when the source of the packet wants to initiate a TCP session with
the specified destination IP address.
The no form of the command removes the criterion from the match entry.
Parameters true — Specifies matching on IP packets that have the SYN bit set in the control bits of the
TCP header of an IP packet.
false — Specifies matching on IP packets that do not have the SYN bit set in the control bits
of the TCP header of the IP packet.
Item Description
(2 of 2)
Item Description
Syntax [no] shutdown
Context configure>system>security>cpu-filter>ipv6-filter
Description The shutdown command administratively disables the entity.
The no form of the command puts an entity into the administratively enabled state.
Shutdown/no shutdown will reset counters on all ipv6-filter entries.
Item Description
Syntax renum old-entry-id new-entry-id
Context configure>system>security>cpu-filter>ip-filter
Description This command renumbers existing CPU filter entries to properly sequence filter entries.
This may be required in some cases since the OS exits when the first match is found and
executes the actions according to the accompanying action command. This requires that
entries be sequenced correctly from most to least explicit.
(1 of 2)