跳转到内容
Ask AI

Raguard-Netconf

此内容尚不支持你的语言。

YANG Pathget/get-configedit-configrpc
/raguardYmerge, replace, create, delete—
/raguard/interfaces/{name}Ymerge, replace, create, delete—
/raguard/policies/{if-name}Ymerge, replace, create, delete—

This chapter provides examples on how to use Netconf to manage RAGuard configurations on AsterNOS devices.

Request example to get all RAGuard configurations via get-config with subtree filter.

<filter type="subtree">
<top>
<raguard/>
</top>
</filter>

Response example

<data xmlns="urn:ietf:params:xml:ns:netconf:base:1.0">
<top>
<raguard xmlns="http://asterfusion.com/ns/yang/asternos-raguard">
<interfaces>
<interface>
<name>Ethernet2</name>
<role>hybrid</role>
</interface>
<interface>
<name>Ethernet3</name>
<role>router</role>
</interface>
</interfaces>
<policies>
<policy>
<if-name>Vlan100</if-name>
<hop-limit-high>200</hop-limit-high>
<hop-limit-low>10</hop-limit-low>
<managed-flag>true</managed-flag>
<other-flag>true</other-flag>
<prefix>2001:db8:1::/64</prefix>
<prefix>2001:db8:2::/64</prefix>
<router-pref-max>high</router-pref-max>
<src-ip>2001:db8:1::1</src-ip>
<src-ip>2001:db8:1::2</src-ip>
<src-mac>00:11:22:33:44:55</src-mac>
<src-mac>00:11:22:33:44:56</src-mac>
</policy>
</policies>
</raguard>
</top>
</data>

Request example to set RAGuard role of interface via edit-config.

<config>
<top>
<raguard>
<interfaces>
<interface>
<name>Ethernet3</name>
<role>router</role>
</interface>
</interfaces>
</raguard>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:78473a87-95cc-4903-ad01-4a1cc83e651d">
<ok/>
</rpc-reply>

Request example to set RAGuard policy of vlan via edit-config.

<config>
<top>
<raguard>
<interfaces>
<interface>
<name>Ethernet2</name>
<role>hybrid</role>
</interface>
</interfaces>
<policies>
<policy>
<if-name>Vlan100</if-name>
<hop-limit-high>200</hop-limit-high>
<hop-limit-low>10</hop-limit-low>
<managed-flag>true</managed-flag>
<other-flag>true</other-flag>
<prefix>2001:db8:1::/64</prefix>
<prefix>2001:db8:2::/64</prefix>
<router-pref-max>high</router-pref-max>
<src-ip>2001:db8:1::1</src-ip>
<src-ip>2001:db8:1::2</src-ip>
<src-mac>00:11:22:33:44:55</src-mac>
<src-mac>00:11:22:33:44:56</src-mac>
</policy>
</policies>
</raguard>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:068c16a1-f9db-427c-b71f-99ef7f146123">
<ok/>
</rpc-reply>

Request example to delete RAGuard role of interface via edit-config.

<config>
<top>
<raguard>
<interfaces>
<interface operation="delete">
<name>Ethernet3</name>
</interface>
</interfaces>
</raguard>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:ecbca071-bfae-4004-af7d-b9c21fc3ce49">
<ok/>
</rpc-reply>

Request example to delete RAGuard policy of interface via edit-config.

<config>
<top>
<raguard>
<policies operation="delete">
<policy>
<if-name>Vlan100</if-name>
</policy>
</policies>
</raguard>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:fabbb617-2230-43a4-ad41-cd85490f5db2">
<ok/>
</rpc-reply>

Tree Diagram

module: asternos-raguard
+--rw raguard
+--rw interfaces
| +--rw interface* [name]
| +--rw name cmn:ethernet-port-name
| +--rw role? identityref
+--rw policies
+--rw policy* [if-name]
+--rw if-name cmn:vlan-name
+--rw hop-limit-high? uint8
+--rw hop-limit-low? uint8
+--rw managed-flag? boolean
+--rw other-flag? boolean
+--rw prefix* inet:ipv6-prefix
+--rw router-pref-max? identityref
+--rw src-ip* inet:ipv6-address-no-zone
+--rw src-mac* yang:mac-address

Table of Properties

NameRequiredType/RangeDescription
raguardMPath-only node, has no configurable value.
raguard configuration.
interfacesMPath-only node, has no configurable value.
raguard interface configuration.
interfaceMPath-only node, has no configurable value.
raguard interface.
nameOcmn:ethernet-port-nameinterface name.
roleO”none"
"router"
"hybrid"
"user”
RA guard interface role.
policiesMPath-only node, has no configurable value.
RA guard policy configuration.
policyMPath-only node, has no configurable value.
RA guard policy.
if-nameOcmn:vlan-nameInterface name for configuring RA Guard policy, the interfaces within this VLAN must be set to hybrid role to take effect.
hop-limit-highO0..255The maximum value of the hop limit in RA packet.
hop-limit-lowO0..255The minimum value of the hop limit in RA packet.
managed-flagO”true"
"false”
Managed flag of RA packet.
other-flagO”true"
"false”
Other flag of RA packet.
prefixOinet:ipv6-prefixPrefix of RA packet.
router-pref-maxO”low"
"high"
"medium”
The router preference priority of RA packet. Effective when the Prf value is not greater than the set value.
src-ipOinet:ipv6-address-no-zoneSource IP of RA packet.
src-macOyang:mac-addressSource MAC of RA packet.

Tree Diagram

module: asternos-raguard
+--rw raguard
+--rw interfaces
+--rw interface* [name]
+--rw name cmn:ethernet-port-name
+--rw role? identityref

Table of Properties

NameRequiredType/RangeDescription
interfacesMPath-only node, has no configurable value.
raguard interface configuration.
interfaceMPath-only node, has no configurable value.
raguard interface.
nameOcmn:ethernet-port-nameinterface name.
roleO”none"
"router"
"hybrid"
"user”
RA guard interface role.

Tree Diagram

module: asternos-raguard
+--rw raguard
+--rw policies
+--rw policy* [if-name]
+--rw if-name cmn:vlan-name
+--rw hop-limit-high? uint8
+--rw hop-limit-low? uint8
+--rw managed-flag? boolean
+--rw other-flag? boolean
+--rw prefix* inet:ipv6-prefix
+--rw router-pref-max? identityref
+--rw src-ip* inet:ipv6-address-no-zone
+--rw src-mac* yang:mac-address

Table of Properties

NameRequiredType/RangeDescription
policiesMPath-only node, has no configurable value.
RA guard policy configuration.
policyMPath-only node, has no configurable value.
RA guard policy.
if-nameOcmn:vlan-nameInterface name for configuring RA Guard policy, the interfaces within this VLAN must be set to hybrid role to take effect.
hop-limit-highO0..255The maximum value of the hop limit in RA packet.
hop-limit-lowO0..255The minimum value of the hop limit in RA packet.
managed-flagO”true"
"false”
Managed flag of RA packet.
other-flagO”true"
"false”
Other flag of RA packet.
prefixOinet:ipv6-prefixPrefix of RA packet.
router-pref-maxO”low"
"high"
"medium”
The router preference priority of RA packet. Effective when the Prf value is not greater than the set value.
src-ipOinet:ipv6-address-no-zoneSource IP of RA packet.
src-macOyang:mac-addressSource MAC of RA packet.