Skip to content
Ask AI

IPSG-Netconf

YANG Pathget/get-configedit-configrpc
/ipsgYmerge, replace, create, delete—
/ipsg/interfaces/{name}/{ip-type}Ymerge, replace, create, delete—

This chapter provides examples on how to use Netconf to manage IPSG configurations on AsterNOS devices.

Request example to get all IPSG configurations via get-config with subtree filter.

<filter type="subtree">
<top>
<ipsg/>
</top>
</filter>

Response example

<data xmlns="urn:ietf:params:xml:ns:netconf:base:1.0">
<top>
<ipsg xmlns="http://asterfusion.com/ns/yang/asternos-ipsg">
<interfaces>
<interface>
<name>Ethernet1</name>
<ip-type>v6</ip-type>
<enable>true</enable>
</interface>
<interface>
<name>Vlan100</name>
<ip-type>v6</ip-type>
<enable>true</enable>
<trusted-interfaces>Ethernet2</trusted-interfaces>
<trusted-interfaces>Ethernet3</trusted-interfaces>
</interface>
<interface>
<name>Ethernet1</name>
<ip-type>v4</ip-type>
<enable>true</enable>
</interface>
<interface>
<name>Vlan100</name>
<ip-type>v4</ip-type>
<enable>true</enable>
<trusted-interfaces>Ethernet3</trusted-interfaces>
<trusted-interfaces>Ethernet2</trusted-interfaces>
</interface>
</interfaces>
</ipsg>
</top>
</data>

‘enable’ and ‘trust-enable’ cannot be configured as true at the same time

IPSG configuration of interface must specify IP type.

Request example to set IPSG configuration of interface to enabled via edit-config.

<config>
<top>
<ipsg>
<interfaces>
<interface>
<name>Ethernet1</name>
<ip-type>v4</ip-type>
<enable>true</enable>
</interface>
<interface>
<name>Vlan100</name>
<ip-type>v4</ip-type>
<enable>true</enable>
<trusted-interfaces>Ethernet2</trusted-interfaces>
<trusted-interfaces>Ethernet3</trusted-interfaces>
</interface>
<interface>
<name>Ethernet1</name>
<ip-type>v6</ip-type>
<enable>true</enable>
</interface>
<interface>
<name>Vlan100</name>
<ip-type>v6</ip-type>
<enable>true</enable>
<trusted-interfaces>Ethernet2</trusted-interfaces>
<trusted-interfaces>Ethernet3</trusted-interfaces>
</interface>
</interfaces>
</ipsg>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:b40b1881-532f-44e9-9db5-27ad280454b2">
<ok/>
</rpc-reply>

Request example to set IPSG configuration of interface to trust-enabled via edit-config.

<config>
<top>
<ipsg>
<interfaces>
<interface>
<name>Ethernet1</name>
<ip-type>v6</ip-type>
<trust-enable>true</trust-enable>
</interface>
<interface>
<name>Ethernet1</name>
<ip-type>v4</ip-type>
<trust-enable>true</trust-enable>
</interface>
</interfaces>
</ipsg>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:98421788-dd19-4dfa-a6cd-651a5a14fe6c">
<ok/>
</rpc-reply>

Request example to delete IPSG configuration of interface via edit-config.

<config>
<top>
<ipsg>
<interfaces>
<interface operation="delete">
<name>Ethernet1</name>
<ip-type>v4</ip-type>
</interface>
<interface operation="delete">
<name>Ethernet1</name>
<ip-type>v6</ip-type>
</interface>
</interfaces>
</ipsg>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:d76fc07a-6f40-442c-8748-543754dac541">
<ok/>
</rpc-reply>

Tree Diagram

module: asternos-ipsg
+--rw ipsg
+--rw interfaces
+--rw interface* [name ip-type]
+--rw name union
+--rw ip-type enumeration
+--rw enable? boolean
+--rw trust-enable? boolean
+--rw trusted-interfaces* cmn:ethernet-port-name

Table of Properties

NameRequiredType/RangeDescription
ipsgMPath-only node, has no configurable value.
Container for IPSG configurations.
interfacesMPath-only node, has no configurable value.
interfaceMPath-only node, has no configurable value.
Configure IPSG interfaces based on VLAN or PORT.

Note: ‘enable’ and ‘trust-enable’ cannot be configured as true at the same time
nameOEthernet nameName of the interface.
ip-typeO”v4"
"v6”
enableO”true"
"false”
Enable or disable the configuration for interface.
trust-enableO”true"
"false”
Enable or disable the trust for ethernet interface.

Only valid for ethernet interface, not VLAN interface.

Suitable for configuration scenarios with multiple VLANs on the interface.

When configured as true, trust any VLAN on the interface
trusted-interfacesOcmn:ethernet-port-nameList of trusted ethernet port or sub-ethernet interfaces for VLAN.

Only valid for VLAN interface.

Tree Diagram

module: asternos-ipsg
+--rw ipsg
+--rw interfaces
+--rw interface* [name ip-type]
+--rw name union
+--rw ip-type enumeration
+--rw enable? boolean
+--rw trust-enable? boolean
+--rw trusted-interfaces* cmn:ethernet-port-name

Table of Properties

NameRequiredType/RangeDescription
interfacesMPath-only node, has no configurable value.
interfaceMPath-only node, has no configurable value.
Configure IPSG interfaces based on VLAN or PORT.

Note: ‘enable’ and ‘trust-enable’ cannot be configured as true at the same time
nameOEthernet nameName of the interface.
ip-typeO”v4"
"v6”
enableO”true"
"false”
Enable or disable the configuration for interface.
trust-enableO”true"
"false”
Enable or disable the trust for ethernet interface.

Only valid for ethernet interface, not VLAN interface.

Suitable for configuration scenarios with multiple VLANs on the interface.

When configured as true, trust any VLAN on the interface
trusted-interfacesOcmn:ethernet-port-nameList of trusted ethernet port or sub-ethernet interfaces for VLAN.

Only valid for VLAN interface.