Raguard-Netconf
此内容尚不支持你的语言。
Raguard
Section titled “Raguard”Resources Summary
Section titled “Resources Summary”| YANG Path | get/get-config | edit-config | rpc |
|---|---|---|---|
| /raguard | Y | merge, replace, create, delete | — |
| /raguard/interfaces/{name} | Y | merge, replace, create, delete | — |
| /raguard/policies/{if-name} | Y | merge, replace, create, delete | — |
Examples
Section titled “Examples”This chapter provides examples on how to use Netconf to manage RAGuard configurations on AsterNOS devices.
Get Current RAGuard Configurations
Section titled “Get Current RAGuard Configurations”Request example to get all RAGuard configurations via get-config with subtree filter.
<filter type="subtree"> <top> <raguard/> </top></filter>Response example
<data xmlns="urn:ietf:params:xml:ns:netconf:base:1.0"> <top> <raguard xmlns="http://asterfusion.com/ns/yang/asternos-raguard"> <interfaces> <interface> <name>Ethernet2</name> <role>hybrid</role> </interface> <interface> <name>Ethernet3</name> <role>router</role> </interface> </interfaces> <policies> <policy> <if-name>Vlan100</if-name> <hop-limit-high>200</hop-limit-high> <hop-limit-low>10</hop-limit-low> <managed-flag>true</managed-flag> <other-flag>true</other-flag> <prefix>2001:db8:1::/64</prefix> <prefix>2001:db8:2::/64</prefix> <router-pref-max>high</router-pref-max> <src-ip>2001:db8:1::1</src-ip> <src-ip>2001:db8:1::2</src-ip> <src-mac>00:11:22:33:44:55</src-mac> <src-mac>00:11:22:33:44:56</src-mac> </policy> </policies> </raguard> </top></data>Set RAGuard Configurations
Section titled “Set RAGuard Configurations”Request example to set RAGuard role of interface via edit-config.
<config> <top> <raguard> <interfaces> <interface> <name>Ethernet3</name> <role>router</role> </interface> </interfaces> </raguard> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:78473a87-95cc-4903-ad01-4a1cc83e651d"> <ok/></rpc-reply>Request example to set RAGuard policy of vlan via edit-config.
<config> <top> <raguard> <interfaces> <interface> <name>Ethernet2</name> <role>hybrid</role> </interface> </interfaces> <policies> <policy> <if-name>Vlan100</if-name> <hop-limit-high>200</hop-limit-high> <hop-limit-low>10</hop-limit-low> <managed-flag>true</managed-flag> <other-flag>true</other-flag> <prefix>2001:db8:1::/64</prefix> <prefix>2001:db8:2::/64</prefix> <router-pref-max>high</router-pref-max> <src-ip>2001:db8:1::1</src-ip> <src-ip>2001:db8:1::2</src-ip> <src-mac>00:11:22:33:44:55</src-mac> <src-mac>00:11:22:33:44:56</src-mac> </policy> </policies> </raguard> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:068c16a1-f9db-427c-b71f-99ef7f146123"> <ok/></rpc-reply>Delete RAGuard Configurations
Section titled “Delete RAGuard Configurations”Request example to delete RAGuard role of interface via edit-config.
<config> <top> <raguard> <interfaces> <interface operation="delete"> <name>Ethernet3</name> </interface> </interfaces> </raguard> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:ecbca071-bfae-4004-af7d-b9c21fc3ce49"> <ok/></rpc-reply>Request example to delete RAGuard policy of interface via edit-config.
<config> <top> <raguard> <policies operation="delete"> <policy> <if-name>Vlan100</if-name> </policy> </policies> </raguard> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:fabbb617-2230-43a4-ad41-cd85490f5db2"> <ok/></rpc-reply>Properties Descriptions
Section titled “Properties Descriptions”raguard configuration
Section titled “raguard configuration”Tree Diagram
module: asternos-raguard +--rw raguard +--rw interfaces | +--rw interface* [name] | +--rw name cmn:ethernet-port-name | +--rw role? identityref +--rw policies +--rw policy* [if-name] +--rw if-name cmn:vlan-name +--rw hop-limit-high? uint8 +--rw hop-limit-low? uint8 +--rw managed-flag? boolean +--rw other-flag? boolean +--rw prefix* inet:ipv6-prefix +--rw router-pref-max? identityref +--rw src-ip* inet:ipv6-address-no-zone +--rw src-mac* yang:mac-addressTable of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| raguard | M | Path-only node, has no configurable value. raguard configuration. | |
| interfaces | M | Path-only node, has no configurable value. raguard interface configuration. | |
| interface | M | Path-only node, has no configurable value. raguard interface. | |
| name | O | cmn:ethernet-port-name | interface name. |
| role | O | ”none" "router" "hybrid" "user” | RA guard interface role. |
| policies | M | Path-only node, has no configurable value. RA guard policy configuration. | |
| policy | M | Path-only node, has no configurable value. RA guard policy. | |
| if-name | O | cmn:vlan-name | Interface name for configuring RA Guard policy, the interfaces within this VLAN must be set to hybrid role to take effect. |
| hop-limit-high | O | 0..255 | The maximum value of the hop limit in RA packet. |
| hop-limit-low | O | 0..255 | The minimum value of the hop limit in RA packet. |
| managed-flag | O | ”true" "false” | Managed flag of RA packet. |
| other-flag | O | ”true" "false” | Other flag of RA packet. |
| prefix | O | inet:ipv6-prefix | Prefix of RA packet. |
| router-pref-max | O | ”low" "high" "medium” | The router preference priority of RA packet. Effective when the Prf value is not greater than the set value. |
| src-ip | O | inet:ipv6-address-no-zone | Source IP of RA packet. |
| src-mac | O | yang:mac-address | Source MAC of RA packet. |
raguard interface configuration
Section titled “raguard interface configuration”Tree Diagram
module: asternos-raguard +--rw raguard +--rw interfaces +--rw interface* [name] +--rw name cmn:ethernet-port-name +--rw role? identityrefTable of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| interfaces | M | Path-only node, has no configurable value. raguard interface configuration. | |
| interface | M | Path-only node, has no configurable value. raguard interface. | |
| name | O | cmn:ethernet-port-name | interface name. |
| role | O | ”none" "router" "hybrid" "user” | RA guard interface role. |
RA guard policy configuration
Section titled “RA guard policy configuration”Tree Diagram
module: asternos-raguard +--rw raguard +--rw policies +--rw policy* [if-name] +--rw if-name cmn:vlan-name +--rw hop-limit-high? uint8 +--rw hop-limit-low? uint8 +--rw managed-flag? boolean +--rw other-flag? boolean +--rw prefix* inet:ipv6-prefix +--rw router-pref-max? identityref +--rw src-ip* inet:ipv6-address-no-zone +--rw src-mac* yang:mac-addressTable of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| policies | M | Path-only node, has no configurable value. RA guard policy configuration. | |
| policy | M | Path-only node, has no configurable value. RA guard policy. | |
| if-name | O | cmn:vlan-name | Interface name for configuring RA Guard policy, the interfaces within this VLAN must be set to hybrid role to take effect. |
| hop-limit-high | O | 0..255 | The maximum value of the hop limit in RA packet. |
| hop-limit-low | O | 0..255 | The minimum value of the hop limit in RA packet. |
| managed-flag | O | ”true" "false” | Managed flag of RA packet. |
| other-flag | O | ”true" "false” | Other flag of RA packet. |
| prefix | O | inet:ipv6-prefix | Prefix of RA packet. |
| router-pref-max | O | ”low" "high" "medium” | The router preference priority of RA packet. Effective when the Prf value is not greater than the set value. |
| src-ip | O | inet:ipv6-address-no-zone | Source IP of RA packet. |
| src-mac | O | yang:mac-address | Source MAC of RA packet. |