| | | | |
| |
client-class-policy - Adds DHCP policy information to a client-class
|
| |
Synopsis |
| |
client-class-policy <client-class-name> delete
client-class-policy <client-class-name>
set <attribute>=<value> [<attribute>=<value> ...]
client-class-policy <client-class-name> get <attribute>
client-class-policy <client-class-name> disable <attribute>
client-class-policy <client-class-name> enable <attribute>
client-class-policy <client-class-name> show
client-class-policy <client-class-name> setLeaseTime <time-val>
client-class-policy <client-class-name> getLeaseTime
client-class-policy <client-class-name> setOption <opt-name | id> <value>
client-class-policy <client-class-name> getOption <opt-name | id>
client-class-policy <client-class-name> unsetOption <opt-name | id>
client-class-policy <client-class-name> listOptions
client-class-policy <client-class-name> setV6Option <opt-name | id> <value>
client-class-policy <client-class-name> getV6Option <opt-name | id>
client-class-policy <client-class-name> unsetV6Option <opt-name | id>
client-class-policy <client-class-name> listV6Options
client-class-policy <client-class-name>
setVendorOption <opt-name | id> <opt-set-name> <value>
client-class-policy <client-class-name>
getVendorOption <opt-name | id> <opt-set-name>
client-class-policy <client-class-name>
unsetVendorOption <opt-name | id> <opt-set-name>
client-class-policy <client-class-name> listVendorOptions
client-class-policy <client-class-name>
setV6VendorOption <opt-name | id> <opt-set-name> <value>
client-class-policy <client-class-name>
getV6VendorOption <opt-name | id> <opt-set-name>
client-class-policy <client-class-name>
unsetV6VendorOption <opt-name | id> <opt-set-name>
client-class-policy <client-class-name> listV6VendorOptions
|
| |
Description |
| |
The client-class-policy command configures embedded policies for
client-classes. Each client-class can contain option data in its
embedded policy and can refer to a named policy with more option
data; for example, a router IP address.
An embedded policy is a collection of DHCP option values and settings
associated with (and named by) a client-class. Network Registrar
implicitly creates and deletes an embedded client-class policy when
you create and delete the corresponding client-class. You manipulate
the client-class policy using the name of the client-class to which
the embedded policy is attached.
client-class-policy <client-class-name> setOption <opt-name | id> <value>
Sets individual option values. When you set an
option value the DHCP server will replace any existing value or
create a new one as needed for the given option name.
client-class-policy <client-class-name> getOption <opt-name | id>
Displays option values.
client-class-policy <client-class-name> unsetOption <opt-name | id>
Unsets option values.
client-class-policy <client-class-name> setLeaseTime <time-val>
Sets the lease time.
client-class-policy <client-class-name> getLeaseTime
Displays the lease time for the specified client-class.
See the attribute descriptions for the policy command for a complete list of
attributesfor client-class-policy. Except where noted in that list,
policy command attributes also apply to client-class policies.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
policy, scope-policy, client-policy
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
client-policy - Adds DHCP policy information to a client object
|
| |
Synopsis |
| |
client-policy <client-name> delete
client-policy <client-name> set <attribute>=<value> [<attribute>=<value> ...]
client-policy <client-name> get <attribute>
client-policy <client-name> disable <attribute>
client-policy <client-name> enable <attribute>
client-policy <client-name> show
client-policy <client-name> setLeaseTime <time-val>
client-policy <client-name> getLeaseTime
client-policy <client-name> setOption <opt-name | id> <value>
client-policy <client-name> getOption <opt-name | id>
client-policy <client-name> unsetOption <opt-name | id>
client-policy <client-name> listOptions
client-policy <client-name> setV6Option <opt-name | id> <value>
client-policy <client-name> getV6Option <opt-name | id>
client-policy <client-name> unsetV6Option <opt-name | id>
client-policy <client-name> listV6Options
client-policy <client-name>
setVendorOption <opt-name | id> <opt-set-name> <value>
client-policy <client-name>
getVendorOption <opt-name | id> <opt-set-name>
client-policy <client-name>
unsetVendorOption <opt-name | id> <opt-set-name>
client-policy <client-name> listVendorOptions
client-policy <client-name>
setV6VendorOption <opt-name | id> <opt-set-name> <value>
client-policy <client-name>
getV6VendorOption <opt-name | id> <opt-set-name>
client-policy <client-name>
unsetV6VendorOption <opt-name | id> <opt-set-name>
client-policy <client-name> listV6VendorOptions
|
| |
Description |
| |
The client-policy command configures embedded policies for clients.
Each client can contain option data in its embedded policy and might
refer to a named policy with more option data—for example, a router
IP address. Network Registrar implicitly creates and deletes an
embedded client policy when you create or delete the corresponding
client. You manipulate the client policy using the name of the client
to which the embedded policy is attached.
client-policy <client-name> setOption <opt-name | id> <value>
Sets individual option values. When you set an
option value the DHCP server replaces any existing value or
creates a new one as needed for the given option name.
client-policy <client-name> unsetOption <opt-name | id>
Unsets option values.
client-policy <client-name> getOption <opt-name | id>
Displays option values for the specified client.
client-policy <client-name> setLeaseTime
Sets lease time values for the specified client.
client-policy <client-name> getLeaseTime
Displays the lease time value.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
policy, scope-policy, client-class-policy
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
cluster - Configures the local and remote clusters
|
| |
Synopsis |
| |
cluster <name> create <address> [<attribute>=<value>]
cluster <name> delete
cluster list
cluster listnames
cluster <name> show
cluster <name> set <attribute>=<value> [<attribute>=<value> ...]
cluster <name> get <attribute>
cluster <name> unset <attribute>
cluster <name> enable <attribute>
cluster <name> disable <attribute>
|
| |
Description |
| |
The cluster command configures the specified local or remote
cluster, primarily providing connection and polling information;
for example, IP address, fully qualified domain name, and HTTP port.
This information provides reference points for objects related to
the cluster.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
|
| |
| |
Attributes |
| |
| |
Sets the administrator identity to use to contact this cluster.
|
| |
if > 0, a process on this cluster is listening for ATUL protocol
queries on this port number.
|
| |
Identifies the local cluster that is the authoritative source
for this object. This attribute is set as part of replica data
propagation.
|
| |
Provides the fully qualified domain name of this server.
This attribute is not used to contact the cluster.
|
| |
Specifies the http-port to use for non-SSL-secured connections
to the web server for this cluster.
|
| |
Controls the https-port to use for SSL-secured connections to
the webserver for this cluster. This port is only used if the
value of the use-https-port attribute is true.
|
| |
Provides the IP address of this server. This attribute,
rather than the fqdn is used to connect to the cluster.
|
| |
Lists the servers associated with this cluster. This transient
attribute makes it easier for clients that want to show a tree
of clusters with their child servers to get all the information
in a single request.
|
| |
Names the cluster.
|
| |
Sets the password that authenticates the identity stored
in the admin attribute. Do not use this clear-text value
except within process memory. Use the corresponding
password-secret instead.
|
| |
Sets the identifier of the secret representing the password that
authenticates the identity stored in the admin attribute.
|
| |
Specifies how often to collect the lease history from the DHCP
server for this cluster. If set to 0, polling does not occur.
|
| |
Provides a fixed time of day for lease history polling.
This time is interpreted as a time of day offset, with 0 being
12 midnight, provided the polling interval is less than 24 hours,
and the offset value is less than the polling interval. If the offset
value is greater than the polling interval, or the interval is
greater than 24 hours, the offset will be ignored.
The scheduler for polling will ensure that the first polling event
occurs at the offset time. For example, if you set the interval to
4 hours and the offset to 2am, the polling would occur at 2am, 6am,
10am, 2pm, 6pm and 10pm.
|
| |
Controls how often to retry if lease history polling fails.
|
| |
Set the automatic replication interval; that is, how often
Network Registrar polls this server for replica data.
|
| |
Sets a fixed time of day for replica polling.
This time is interpreted as a time of day offset, with 0 being
12 midnight, provided that:
the polling interval is less than 24 hours, and
the offset value is less than the polling interval.
If the offset value is greater than the polling interval, or
the interval is greater than 24 hours, the offset is ignored.
The scheduler for polling ensures that the first polling event
occurs at the offset time. For example, if you set the interval
to 4 hours and the offset to 2am, the polling would occur at
2am, 6am, 10am, 2pm, 6pm and 10pm.
|
| |
Specifies how often to collect subnet utilization data from
the DHCP server for this cluster. If set to 0, polling does
not occur.
|
| |
Provides a fixed time of day for subnet utilization polling.
This time is interpreted as a time of day offset, with 0 being
12 midnight, provided the polling interval is less than 24 hours,
and the offset value is less than the polling interval. If the offset
value is greater than the polling interval, or the interval is
greater than 24 hours, the offset will be ignored.
The scheduler for polling will ensure that the first polling event
occurs at the offset time. For example, if you set the interval to
4 hours and the offset to 2am, the polling would occur at 2am, 6am,
10am, 2pm, 6pm and 10pm.
|
| |
Controls how often to retry if subnet utilization polling fails.
|
| |
The product version number of the cluster in major, minor, rev form.
This value is updated when the cluster is resynchronized.
|
| |
Sets the ID on the remote cluster that refers back to the
local cluster. If there are two cluster objects on two servers
that share a secret and refer to each other, then the local ID =
the remote-id, the local remote ID = the remote ID, and the value
of the local shared secret = the value the remote shared secret.
|
| |
Indicates whether data replication has already been initialized
on this cluster.
|
| |
Indicates whether the cluster has been deactivated or is in the
process of being restored from the replica db.
|
| |
Controls the port number used for SCP communications.
|
| |
The time limit for how long we should wait for data when
reading an SCP message from this cluster.
|
| |
Specifies the identifier for the secret shared between the
server storing this object and the cluster it represents.
This shared secret is used to generate single-sign-on
authentication tokens.
|
| |
Controls whether the https-port is used to make single sign-on
connections to the cluster. If the value is false, or the
https-port attribute is not set, then the http-port is used.
|
| |
What security mode should we use when connecting to this cluster.
If optional, and we have a security library installed, we will
try to secure the connection. If required, we will not make
the connection unless we can secure the connection (this requires
the security library to be installed). If none, we will not
try to secure the connection.
|
| | | | |
| |
dhcp - Configures and controls the DHCP server
|
| |
Synopsis |
| |
dhcp disable <attribute>
dhcp enable <attribute>
dhcp get <attribute>
dhcp set <attribute>=<value> [<attribute>=<value> ...]
dhcp unset <attribute>
dhcp show
dhcp getStats [[all | server [,] failover [,] dhcpv6] [total | sample]]
dhcp resetStats
dhcp getScopeCount [FailoverPair <name> | vpn <name> | all]
dhcp getPrefixCount [vpn <name> |all]
dhcp attachExtension <extension-point> <extension-name> [sequence number]
dhcp detachExtension <extension-point> [sequence number]
dhcp listExtensions
dhcp setPartnerDown <partner-server-name> [<date>]
dhcp getRelatedServers [column-separator=<string>]
dhcp updateSms [all]
dhcp serverLogs show
dhcp serverLogs nlogs=<nlogs> logsize=<logsize>
dhcp limitationList <ipaddr> [<limitation-id>] show
|
| |
Description |
| |
The dhcp command lets you configure the DHCP server in a cluster.
dhcp getStats [[all | server [,] failover [,] dhcpv6] [total | sample]]
dhcp resetStats
The getStats command retrieves statistics from a running DHCP
server. You can supply one or more specific categories of
statistics counters, or the keyword all to retrieve all supported
categories. If collection of sample counters is enabled in the
server, you can retrieve the most recent sample counters instead
of the running totals by specifying sample after the categories.
The resetStats command resets the running totals counters.
dhcp attachExtension <extension-point> <extension-name> [sequence number]
dhcp detachExtension <extension-point> [sequence number]
dhcp listExtensions
Use the commands attachExtension, detachExtension,
and listExtensions to configure the extensions points in the
server.
You can associate multiple extensions with each extension
point, and each executes in the order specified by the sequence
number used when the attachment was made. If no sequence number
is used with attachExtension and detachExtension, it defaults
to 1. If multiple extensions are configured for a given point,
listExtensions shows the sequence numbers associated with each.
Sequence numbers must be in the range 1-32.
The available extension points are:
The attachExtension command sets the specified extension point (and
optional sequence position) to call the named extension. If the
extension point is already configured (for a given sequence position)
to call an extension, Network Registrar overwrites it with the new
value.
The detachExtension command removes any extension configuration from
the specified extension point and sequence number.
The listExtensions command shows the current configurations for
each extension point.
You can put the DHCP server into import mode by enabling the
import-mode feature and then restarting the server. You take
the server out of import-mode by disabling the feature and restarting
the server. You can use import mode to exclude all DHCP lease
requests except for the specially tagged ones that come from the
CLI during lease import (see the import command).
dhcp setPartnerDown <partner-server-name> [<date>]
The dhcp setPartnerDown command notifies the DHCP server that one of
its safe failover partner servers is down. The date specified
represents a time equal to or later than the last known time the
partner server could have been operational. If no date is specified,
the current time is used. The time value should be entered using
the local time of the nrcmd process. Formats for the date are:
-<num><value>
where <num> is a decimal number and <value> is one of 's', 'm',
'h', 'd', 'w', in which 's' is seconds, 'm' is minutes, 'h' is
hours, 'd' is days and 'w' is weeks.
<month> <day> <hour>:<minute>[:<second>] <year>
where <month> is the name or first three letters of the name of
the month, <hour> is the hour on a 24- hour clock, and <year> is
the fully-specified year or a two-digit representation in which
98 = 1998, 99 = 1999 and all other two digit values XX = 20XX.
dhcp getRelatedServers [column-separator=<string>]
The dhcp getRelatedServers command displays a table with the following
information for each associated safe failover, DNS or LDAP server:
Type
Main, Backup, DNS or LDAP
Name
DNS host name
Address
IP Address in dotted octet format
Communications
OK or INTERRUPTED
Requests
Number of outstanding requests
<cluster-name> State
Failover state of this server
Partner State
Failover state of partner
dhcp updateSms [all]
The dhcp updateSms command initiates SMS processing. To send all
leases to SMS, use the argument all; otherwise, only the new leases
activated since the last time the command ran successfully are sent.
To run this command, turn on sms-network-discovery and set
sms-library-path. The command returns an error if sms-network-discovery is
not turned on or if it is unable to load SMS library or if the optional
argument string is invalid, otherwise it returns success to indicate SMS
processing started successfully.
dhcp serverLogs show
The serverLogs show command displays the number of log files and the
maximum size for each file.
The serverLogs command allows setting the two server logging parameters,
nlogs and logsize. Either or both may be specified in the command, and
changes will only occur to the one(s) specified. When setting logsize,
the value may be suffixed with K or M to signify units of thousands or
millions. Note that in order for these changes to take effect you must
save the changes and restart the server Agent.
dhcp serverLogs nlogs=6 logsize=500K
dhcp serverLogs logsize=5M
dhcp getScopeCount [FailoverPair <name> | vpn <name> | all]
The getScopeCount command displays the scopes, networks, and VPNs
for the current VPN, all VPNs, a specific VPN, or a failover pair.
The getPrefixCount command displays the prefixes, links, and VPNs
for the current VPN, all VPNs, or a specific VPN.
If the ip-history feature is enabled, you should trim
records from the history database to reclaim disk space.
Each history record has a binding end time. Periodically,
the DHCP server examines the lease history records, and deletes
any records for bindings which ended at least ip-history-max-age
in the past.
dhcp limitationList <ipaddr> [<limitation-id>] show
Lists DHCP clients and leases that are associated by a common
limitation-id for the client (see the client command). Use this
command when a DHCP client is denied service because the number of
existing clients with a common limitation-id equals the allowed
limitation-count, as set for a policy (see the policy command).
It then determines which existing clients with that limitation-id
have active leases.
If you specify both the ipaddr and limitation-id arguments, the ipaddr
determines the network in which to search, and does not have to be an
actual IP address that the DHCP server could allocate. In this case, the
limitation-id must be a blob in nn:nn:nn format (such as 01:02:03) or a
string in string format. If you omit the limitation-id, the ipaddr must
be the IP address of a currently active lease, and the limitation-id used
for the command will be the one associated with that lease.
If you want to determine the existing clients and leases using up
the limitation-count for a particular limitation-id because the following
message appeared in the DHCP server log:
Warning Server 0 05646 Could not add Client MAC:
'1,6,01:02:03:04:0c:03' with limitation-id: 01:02:03
using Lease: 10.0.0.23, already 3 Clients with that id.
No over-limit client class specified! Dropping packet!
Use the lease specified in "... using Lease 10.0.0.23" as
the <ipaddr>, and the limitation-id specified in "... with
limitation-id 01:02:03" as the <limitation-id>:
nrcmd> dhcp limitationList 10.0.0.23 01:02:03 show
The result would be a list of 3 leases with the client's MAC
address, the client last transaction time, and the client's host name.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
server
|
| |
| |
Attributes |
| |
| |
Sets the time that elapses between activity summary log
messages. You must also enable the activity-summary setting
in log-settings.
|
| |
Associates a default selection tag (or list of tags) with incoming
subnet-allocation requests that do not contain any subnet name
data.
|
| |
Controls whether the DHCP server allocates subnets to clients
using address-blocks that the clients have already used.
If you set this attribute to false, the server allocates subnets
from any suitable block (based on other selection data in client
messages.
|
| |
Controls whether DHCP subnet-allocation uses the lan-segment
attribute when it is configured on address-blocks.
|
| |
Controls whether the server compares subnet name data on an
incoming subnet-allocation request with the selection tag of each
address-block. A block is only considered if the two match.
|
| |
If configured, enables the DHCP server to listen for incoming
ATUL queries on this UDP port.
|
| |
Enables DHCP support for the ATUL query protocol. The atul-port
parameter configures the port number to use to listen for
ATUL queries.
|
| |
Specifies the maximum number of clients in the client cache.
The DHCP server allocates the amount at startup and frees
it at shutdown. If you set the value to 0, you disable client
caching and the server must use persistent storage to process a
DHCPREQUEST.
|
| |
Sets the maximum time-to-live in seconds for a client in
cache. The DHCP server discards the entries in memory after
this period.
|
| |
Controls how the DHCP server uses the client and client-class
configuration objects to affect request processing. Default is
false (disabled).
|
| |
Specifies the expression used to determine a client-class solely
on data contained in an incoming DHCP client request.
The expression must return a string with the name of a currently
configured client-class, otherwise it must return the string
''. Any return that is not a string containing the name
of a currently configured client-class or '' is considered
an error.
|
| |
Indicates whether the DHCP server was upgraded from 3.5 to 5.0.
Read-only.
|
| |
Sets the maximum period, in hours, that the DHCP server
maintains address utilization data.
To disable collecting address utilization data, unset
this attribute or give it a value of 0.
Use this attribute, with the collect-addr-util-interval
attribute, to determine the frequency that the server
uses to take snapshots of the data and to set the length of
time the DHCP server maintains the data. Together these attributes
have an impact on memory usage because each snapshot of data is
68 bytes.
For example, if you have 10 scopes and you set
collect-addr-util-duration is set to 24h and
collect-addr-util-interval to 1h, memory used by the DHCP
server to maintain address utilization data is 24 times 68 bytes
for each scope; that is, 10x24x68 or 16KB.
|
| |
Sets the frequency, in minutes or hours, that the DHCP
server uses to take snapshot views of address utilization data.
If collect-addr-util-duration is not configured, or set
to 0, the DHCP server ignores the collect-addr-util-interval.
Use this attribute, with the collect-addr-util-duration
attribute, to determine the frequency that the server uses to
take snapshots of the data and the length of time the DHCP server
maintains the data. Together these attributes affect memory
usage because each snapshot of data is 68 bytes.
For example, if you have 10 scopes and you set
collect-addr-util-duration to 24h and collect-addr-util-interval
to 1h, memory used by the DHCP erver to maintain address
utilization data is 24 times 68 bytesfor each scope; that is,
10x24x68 or 16KB.
|
| |
Controls whether the DHCP server collects statistics for
performance monitoring.
|
| |
Controls whether the DHCP server collects activity statistics
counters independently of the log-settings attribute flag.
If false, this attribute is disabled.
If true, this attribute enables collecting activity
statistics.
Note: These activity statistics counters are also enabled,
if you enable 'activity-summary'
logging is enabled (see 'log-settings').
|
| |
Specifies the default SNMP free-address trap configuration object
for the server. All scopes that are not individually configured
use this default free-address value.
|
| |
Determines whether the DHCP server can defer extending leases
to their full lease expiration time.
If enabled (true), the DHCP server can defer extending the lease
expiration time. Rather than give the client the full configured
lease time, the server instead gives the client the remaining
time on the existing lease, improving server performance and
throughput. The DHCP server typically defers extending the lease
if the client renews early; that is, before the client's lease
renewal time (T1) elapses.
If enabled, the DHCP server can save committing the lease to
disk and updating its failover partner with an extended lease
expiration time.
If disabled, the DHCP server always attempts to extend the
lease expiration time. However, there may be conditions
that prevent the server from extending the lease for the full
configured lease time; for example, failover protocol restrictions.
|
| |
Controls how the DHCP server handles orphaned leases.
Default is false (disabled).
A lease is orphaned if:
--It does not match a range or reservation in a configured scope, or
--If it appears in the lease state database with a VPN ID that does
not match a VPN in the database.
If this is attribute is true, the server deletes orphaned leases
when the server next reloads. This ensures that the lease state
database has no old, unconfigured leases in it, but it also may
cause the total loss of lease state information due to a mistake
in configuration.
If this attribute is false, the server ignores the entries in
the lease state database. If the lease was orphaned due to a
configuration mistake, then when you when you correct the
mistake, the DHCP server can use the lease.
Whether true or false, the server cannot use the lease.
|
| |
Controls how the DHCP server handles information about an
orphaned subnet; that is, whether it keeps the entry in its
database or deletes it. Default is false (disable).
As the DHCP server starts up, it tries to locate the
parent VPN and DHCP address block of each DHCP subnet. If a
subnet refers to a VPN that is no longer configured, or if
the server cannot locate a parent DHCP address block that
contains the subnet, the server uses this attribute
to decide.
|
| |
Controls the number of milliseconds that the DHCP server waits
for a response before retrying dynamic DNS requests.
|
| |
Sets the string value (maximum 255 characters) to substitute
for the %@docsis-vers% variable in the policy command boot-
file attribute. No default.
DOCSIS devices must provide their version id
(for example, "docsis1.0") in the vendor-class-id option.
The server substitutes the DOCSIS version id as the
value of the boot-file option. If the vendor
class-id option is missing, or is not syntactically correct,
the server uses the docsis-version-id-missing attribute
for the boot-file option.
This substitution occurs if the DHCP request packet does not
contain a vendor-class-id option or the option does not contain
a DOCSIS version ID.
|
| |
Sets the time, in seconds, that a packet can age and still be
processed.
The server attempts to read as many packets as possible from
the UDP input queue, and then process them quickly. If the
server is very busy, it can sometimes become flooded with
packets. This could delay processing some packets.
In the DHCP protocol, however, some clients automatically
retry packets that have not been processed in a few seconds
--so allowing the server to process packets that are
older than a small number of seconds. This can increase
congestion without providing any real value for the clients.
The drop-old-packets parameter is the number of seconds that
a packet can age and still be processed by the DHCP server.
If a packet is more than the value of drop-old-packets old
when processed by the DHCP server, the server drops the packet.
|
| |
Causes the server to drop a packet (if possible) when it
encounters an extension failure. Default is true (enable).
|
| |
Enables collection of enhanced statistics counters by the DHCP
server, which are then available with DHCP server statistics.
The enhanced counters provide more detailed information, but
cost the server some performance to maintain. Currently, this
enables collecting milliseconds ACK/Reply latencies (instead
of second based) and scope aggregation data (even if not
explicitly configured).
|
| |
Controls address allocation among scopes in the same network.
This attribute determines how the DHCP server allocates an
address to a new client when multiple scopes have the same
nonzero allocation priority. Default is false (disable).
If disabled, the server uses the scope with the fewest available
addresses to allocate an address to a new client (if not in a
limitation list).
If enabled, the server uses the scope with the most available
addresses to allocate an address to a new client
(if not in a limitation list).
In either case, if a client is in a limitation list,
among those scopes of the same priority, the one that contains
other clients in the same list is always used.
|
| |
Sets the trace level to use when configuring DHCP expressions.
Default is 2 (failure retry).
The range is from 0 through 6, with 0 being the lowest amount
of tracing and 6 the highest:
0 No additional tracing
1 No additional tracing
2 Failure retry
3 Function definitions
4 Function arguments
5 Variable lookups and literal details
6 Everything
Setting a high expression-configuration-trace-level imposes no
performance penalty, since expressions are configured only
when you restart the server.
|
| |
Sets the trace level to use when executing DHCP expressions.
ptional, default 2.
The range is from 0 through 6, with 0 being no tracing and 6 the
highest amount of tracing:
0-No tracing
1-Failures, including those protected by (try ...)
2-Total failure retries (with trace level = 6 for retry)
3-Function calls and returns
4-Function arguments evaluated
5-Print function arguments
6-Datatype conversions (everything)
Setting this attribute to any level other than 0, 1, or 2
imposes a considerable performance penalty.
The setting of 1 only traces when there is a failure in an
expression. The default setting of 2 re-executes
evaluating an expression that fails at the outermost level
with the expression-trace-level=10 for the duration of the
re-execution, to provide maximum debugging assistance.
|
| |
Sets the value of the extension trace level for every
request object. Default is 0.
The range is from 0 through 3, with 0 being very little tracing
and 3 the highest amount of tracing.
|
| |
With failover enabled, controls whether a failover BIND update
(BNDUPD) contains multiple lease state updates. Default true
(enable).
This attribute affects only the lease state updates that a DHCP
client generates.
|
| |
With failover enabled, controls the space of time, in seconds,
that elapses between polls of failover partners to confirm
network connectivity. Default is 15s.
|
| |
With failover enabled, defines the space of time, in seconds,
after which a poll between partners times out. Default is 60s.
This attribute signals that the partners cannot communicate
due to lost network connectivity. The partners then change their
operational states appropriately.
|
| |
With failover enabled, sets the time at which the server
is initialized and goes into RECOVER state. No default.
If failover-recover is non-zero, and the server has no
record of a previous failover state in its stable storage,
then the server assumes that it was previously operational
but lost all of its stable storage.
The time value in the failover-recover parameter represents
a time equal to or later than the last known time the server
could have been operational. The server attempts to refresh
its information from its failover partner by entering RECOVER
state and requesting a complete update of all binding
information.
Time values for this attribute can be in hours (for example,
-2h two hours ago) or month day hour:minute[:second] year.
Use the local time of the nrcmd process.
Formats for the date are:
-
where is a decimal number and is one of 's', 'm',
'h', 'd', 'w', in which 's' is seconds, 'm' is minutes, 'h' is
hours, 'd' is days and 'w' is weeks.
:[:]
where is the name or first three letters of the name of
the month, is the hour on a 24- hour clock, and is
the fully-specified year or a two-digit representation in which
98 = 1998, 99 = 1999 and all other two digit values XX = 20XX.
|
| |
Controls whether the DHCP server retries a DNS update
whenever a client renews its lease, even if it appears
to the server that the update was already completed
successfully. Default is false (disable).
This attribute uses one of the following values:
forward DnsUpdateConfig object (if configured)
reverse DnsUpdateConfig object (if configured)
the default (or where appropriate the server configured
value or default value).
|
| |
Controls whether the DHCP server searches all relevant
policies for a subnet mask option to construct a response
to a client. Default is false (disable).
Normally, the DHCP server retains the subnet mask configured
in the scope containing the base being granted to the DHCP
client.
|
| |
Sets the maximum time period in seconds that the DHCP server
waits for replies from a DNS server before failing over to its
partner. Default is 30s.
To use this attribute, first configure your DHCP server to
perform HA DNS updates.
If DHCP is configured for HA-DNS updates, dns-timeout parameters
are set to fit max-dns-retries within ha-dns-failover-timeout.
For example, with a default ha-dns-failover-timeout value of
30 seconds and and max-dns-retries of 3, dns-timeout is set to
6 seconds, so that after 3 retry attempts and an
ha-dns-failover-timeout, the DHCP server failovers. The DHCP
server uses a minimum limit value for a dns-timeout of 2 seconds
and dns-retries of 1.
|
| |
Controls whether the DHCP server sends unicast rather
than broadcast responses when a client indicates that it can
accept a unicast.
Note: This attribute is only available on these
operating systems: Solaris, Windows 2000, and Windows NT.
|
| |
Skips processing the Cisco-specific DHCP options specified
by name in the comma-separated list. No default.
Allowable option names are vpn-id (185), cisco-vpn-id (221),
and subnet-alloc (220). Use this attribute only if
clients use the options for other purposes.
|
| |
Controls how the DHCP server handles ICMP ECHO (ping-before-
offer) requests. Default is true (enable).
If you enable this attribute and configure the DHCP server to
to send ICMP ECHO requests, the server makes unavailable any
address for which it receives an ECHO reply within its
configured timeout period.
If you disable this attribute, the DHCP server also treats
ICMP DEST_UNREACHABLE and TTL_EXPIRED error messages that it
receives after sending ICMP ECHO requests as grounds for making
an address unavailable.
|
| |
Controls whether to prevent the normal DHCP server
response to client requests for other servers. No
default.
Normally, if the DHCP server detects a client requesting a lease
from another server for an address that this server is
configured to control, it sets the lease to unavailable. Some
clients, however, might send request packets with bad server ID
options--rather than packets actually directed to other
servers--that the server wrongly interprets as an unavailable
address. Enabling this attribute prevents this.
|
| |
Controls whether the DHCP server recognizes only packets
generated from the import leases command, ignoring all
others. Default is false (disable).
Use this attribute to update your DHCP server, preventing
clients from receiving addresses during this period.
|
| |
Controls whether the server uses optimization to recover from
periods of congestion. Default false (disable).
By default, the DHCP server determines that it is heavily loaded
when the number of request packets reaches two-thirds of the
total allocated. The server logs a message and attempts to
recover from the congestion by performing several optimizations.
For example, it relaxes the requirement to keep the client?s
last transaction time updated to the granularity specified by
the last-transaction-time-granularity attribute.
When the number of request packets drops to one-third of the
total allocated, the server logs a message and returns to
normal operation. If you enable the inhibit-busy-optimization
attribute, the server does not use the optimizations or log the
messages when it gets congested.
|
| |
Contains attribute-value pairs that initialize all environment
dictionaries used within the DHCP server. Use these attribute-value
pairs to configure extensions or expressions without having to
re-write the executable code in the extension or expression.
The string must have the format:
"attribute1=value1,attribute2=value2, ... ,attributen=valuen"
|
| |
Enables the lease history database. Default is false (disable).
|
| |
Controls whether to record detailed data for the IP
history database. Default is false (disable).
|
| |
If ip-history is enabled, determines how long IP records are
kept in the database. Default is 4w.
The server accumulates database records over time as lease
bindings change. The ip-history-max-age attribute establishes
a limit on the age of thehistory records kept in the database.
The server periodically examines the lease history records,
establishes an age threshold based on this parameter, and
deletes any records that represent bindings that end before
the threshold. The history records are trimmed by default once
a day, at 3:00 a.m. local time.
|
| |
Sets the time, in seconds, to guarantee that the last
transaction time is accurate. Default is 60s.
Do not set this lower than the default of 60 seconds. For
optimal performance, set it to a value that is greater than half
of your lease interval.
By default the server maintains an accurate record of the time
when it last interacted with a DHCP client concerning a given
lease. This setting provides a control on how accurate that time
is guaranteed to be. A setting of 300 seconds, for instance,
would allow the server to avoid database updates whose sole
purpose is to update a last transaction time that is less than 5
minutes in the past.
|
| |
Determines the preference for using LDAP servers if
multiple LDAP servers are configured. No default.
This attribute has two possible values:
1 round-robin-The DHCP server ignores LDAP server
preferences. It treats all LDAP servers (those configured
to handle client queries and those configured to accept
lease-state updates) equally.
2 failover-The DHCP server uses the active LDAP server with
the lowest preference. If the preferred server loses its
connection or fails, the DHCP server uses the next LDAP
server in preference order. The DHCP server uses servers
with equal preference in round-robin order.
|
| |
Determines which events to log in the log files. Default flags are
default, incoming-packets, and missing-options.
Logging additional detail about events can help analyze a problem.
However, leaving detailed logging enabled for a long period
can fill up the log files.
Possible flags are:
default
The default gives a low level of logging in several parts of
the DHCP server. If you unconfigure the default, even this
logging will not appear.
missing-options
This setting (on by default) will cause a message to be logged
whenever an option requested by a DHCP client has not been
configured in a policy and therefore cannot be supplied by the
DHCP server.
incoming-packets
This setting (on by default) will cause a single line message
to be logged for every incoming packet. This is especially
useful when initially configuring a DHCP server or a BOOTP
relay, in that an immediate positive indication exists that
the DHCP server is receiving packets.
incoming-packet-detail
This setting will cause the contents of every DHCP packet
received by the DHCP server to be interpreted in a human
readable way and printed in the log file. This enables the
built-in DHCP packet sniffer for input packets. The log files
will fill up (and turn over) very rapidly when this setting is
enabled. This setting also causes a significant performance
impact on the DHCP server and should not be left enabled as a
matter of course.
outgoing-packet-detail
This setting will cause the contents of every DHCP packet
transmitted by the DHCP server to be interpreted in a human
readable way and printed in the log file. This enables the
built-in DHCP packet sniffer for output packets. The log files
will fill up (and turn over) very rapidly when this setting is
enabled. This setting also causes a significant performance
impact on the DHCP server and should not be left enabled as a
matter of course.
client-detail
This setting will cause a single line to be logged at the
conclusion of every client-class client lookup operation. This
line will show the composite of the data found for the client
as well as the data that found in the client's client-class.
It is useful when setting up a client-class configuration and
for debugging problems in client-class processing.
client-criteria-processing
This setting will cause a log message to be output whenever a
scope is examined to find an available lease or whenever a
scope is examined to determine if a lease is still acceptable
for a client who already has one. It can be very useful when
configuring or debugging client-class scope criteria
processing. It causes moderate amount of information to be
logged and should not be left enabled as a matter of course.
unknown-criteria
This setting will cause a single line log message to appear
whenever a client entry is found which specifies selection
criteria that is not found in any scope appropriate for that
client's current network location.
dns-update-detail
This setting causes the server to log a message as it sends
each dns update and as it receives replies to update messages.
ldap-query-detail
This setting will cause log messages to appear whenever the
dhcp server initiates a query to LDAP server, receives response
and retrieves result or error messages.
ldap-update-detail
This setting will cause log messages to appear whenever the
dhcp server initiates an update lease state to LDAP server,
receives response and retrieves result or error messages.
ldap-create-detail
This setting will cause log messages to appear whenever the
dhcp server initiates an lease state entry create to LDAP
server, receives response and retrieves result or error
messages.
leasequery
This setting will cause log messages to appear when leasequery
packets are processed without internal errors and result in
an ACK or a NAK.
dropped-waiting-packets
If the value of max-waiting-packets is non-zero packets may
be dropped if the queue length for any IP address exceeds the
value of max-waiting-packets. If dropped-waiting-packets
is set, the server will log a message whenever it drops a
waiting packet from the queue for an IP address.
no-success-messages
This setting will cause the single line message that is
normally logged for every successful outgoing DHCP response
packet to not appear. It affects logging only for successful
outgoing DHCP response packets.
no-dropped-dhcp-packets
This setting will cause a single line message normally logged
for every DHCP packet that is dropped due to DHCP
configuration to not appear. (See no-invalid-packets for
messages associated with packets dropped because they are
invalid.)
no-dropped-bootp-packets
This setting will cause the single line message normally
logged for every BOOTP packet that is dropped to not appear.
no-failover-activity
This setting will cause normal activity and some warning
messages logged for failover to not appear. Serious error
log messages will continue to appear independent of this
log-setting.
activity-summary
This setting will cause a summary message to appear every 5
minutes. It is useful when many of the no-xxx log settings
are enabled, to give some idea of the activity in the server
without imposing the load required for a log message
corresponding to each DHCP message. The time period for
these messages can be configured with the DHCP server
property activity-summary-interval.
no-invalid-packets
This setting will cause a single line message normally logged
for every DHCP packet that is dropped due being invalid to
not appear. (See no-dropped-dhcp-packets for messages
associated with packets dropped due to DHCP server
configuration.)
no-reduce-logging-when-busy
Normally, the DHCP server will reduce logging when it becomes
very busy (i.e., when it has used over 2/3 of the available
receive buffers (itself a configurable value)). It will set
no-success-messages, no-dropped-dhcp-packets,
no-dropped-bootp-packets, no-failover-activity,
no-invalid-packets, and clear everything else except
activity-summary. If no-reduce-logging-activity is set, then
the server will not do this. It will restore the previous
settings when the server becomes unbusy (i.e., when it has
used only 1/3 of the available receive buffers).
no-timeouts
This setting will cause messages associated with timeout
of leases or offers not to appear in the log file.
minimal-config-info
This setting will reduce the number of configuration messages
printed when the server starts or reloads. In particular,
it will not log a message for every scope.
no-failover-conflict
This setting will cause conflicts between failover partners
to not be logged.
atul-detail
This setting causes the server to log messages when ATUL
messages are received and processed.
v6-lease-detail
This setting causes the server to log individual messages
regarding DHCPv6 leasing activity (in addition to or in
place of a single message per client transaction depending
on no-success-messages, or client timeout event depending on
no-timeouts).
|
| |
Controls whether the DHCP server uses the client?s MAC
address as the only client identifier. The standard behavior,
as specified in RFC 2132, is to use the client-id option (if it
is present) as the unique client identifier. Default is false
(disable).
CAUTION: Use this attribute with care. When enabled, it
precludes a MAC address from getting multiple IP addresses per
network. It forces the server to use a Client-Identifier (CID)
created from the MAC address instead of the RFC described
client-id contained in the request. This can preclude newer
devices that take multiple IP addresses. Enabling, or later
disabling, this attribute can also have an operational impact.
Clients that originally obtain addresses through a client-id
cannot renew them once they are assigned attributes based on
a MAC address.
|
| |
Controls how to map the radius attribute, if present,
in the client request relay-agent option:
0 none Ignores the radius class name default
1 map-as-tag Maps the radius class to selection-tags
2 map-as-class Maps the radius class directly to a
client-class name
3 append-to-tags Appends the radius class to the
selection-tags
|
| |
Controls use of the radius framed-pool attribute, if present,
in a client relay-agent option.
0 none Ignores the framed-pool attribute
1 map-as-tag Maps the framed-pool attribute to
selection-tags
2 map-as-class Maps framed-pool attribute directly to a
client-class name
3 append-to-tags Appends the user-class-id to the
selection-tags
|
| |
Controls how the server uses the user-class-id option. Values are:
0 none Ignores the user class-id(default)
1 map-as-tag Maps the user-class-id to selection-tags
2 map-as-class Maps user-class-id directly to a
client-class name
3 append-to-tags Appends the user-class-id to the
selection-tags
|
| |
Sets the maximum number of leases, regardless of state or whether
reserved or not, that the server can associate with a DHCPv6
client. A DHCPv6 lease is always associated with a client; if it
is not, it is deleted.
This setting is to prevent a client from using lots of leases
(such as by issuing many requests with different IAID values). It
is not intended to limit the number of active leases a client may
have.
While 1 can be configured as the minimum for backwards
compatibility, the server uses a minium of 2 to allow for a
client that usually only has a single lease to be renumbered or
moved to a different prefix on the link.
This limit is not applied when existing leases are loaded from
the lease state database during server start-up.
|
| |
Controls the number of buffers that the DHCP server allocates
for receiving client requests.
When you enable failover, allocate at least 150 buffers. Up to
1500 buffers might be reasonable for high capacity
installations.
Caution: Increasing the number of buffers can degrade
performance. Cisco recommends using the default value
in most situations. When buffer size exceeds capacity, a burst
of DHCP activity can clog the server with requests that become
stale before they are processed. This increases the processing
load and might severely degrade performance as clients try to
obtain a new lease. A lower buffer setting throttles requests
and avoids wasted processing on requests that would otherwise be
stale.
When using LDAP client lookups, buffers should not exceed the
LDAP lookup queue size defined by the total number of LDAP
connections and the maximum number of requests allowed for each
connection. Set the LDAP queue size to match the LDAP server?s
capacity to service client lookups.
|
| |
Controls the number of buffers that the DHCP server allocates
for responses to client requests. The server ignores this
value if max-dhcp-requests is higher, or other configuration
options such as failover require that the value be set higher
than configured.
|
| |
Controls the number of times that the DHCP server can attempt
adding a host into DNS, even if the DHCP server detects that the
hostname is already present in DNS. The DHCP server attempts
to modify the hostname in order to resolve a conflict on each
failed update.
|
| |
Controls the number of times that the DHCP server can try to
send dynamic updates to a DNS server.
|
| |
Sets the time to live (TTL) ceiling, in seconds, for DNS records
added through dynamic updates. When the DHCP server adds a DNS
record, it uses a TTL of the minimum of either this ceiling or one
third the lease time.
|
| |
Sets the number of buffers the server allocated for sending and
receiving ICMP ping messages. See the scope 'ping-clients'
command.
|
| |
Sets the maximum number of packets that can wait for a
particular IP address.
The server queues only the most recently received n packets
(of an address) for processing. If an additional packet
associated with that address arrives and n packets are already
queued, the server drops the oldest packet and queues the new
one. It also drops duplicate packets (whose XID, client ID, and
MAC address are the same as one already queued).
A value of 0 indicates that there is no maximum queue length,
and all packets are processed.
Dropped packets are logged if the log setting
dropped-waiting-packets is set. It is off by default.
|
| |
Determines the number of binary large objects (blobs) in a bulk
read. Default 256. Range, 1 to 2500.
Use this attribute to tune DHCP start and reload times.
Generally, a higher value will result in faster server start and
reload time, at the cost of using more memory.
|
| |
Minimum value for time to live (TTL) in seconds, for DNS records
added through dynamic updates. When the DHCP server adds a DNS
record, the TTL value will be min-dns-ttl if one third the lease
time is less than the min-dns-ttl value.
|
| |
Controls the default multicast addresses that are enabled
on interfaces. The address ff02::1:2 is required if any
DHCPv6 clients are directly connected to the link associated
with an interface. The address ff05::1:3 is the default
multicast address that relay agents use to relay DHCPv6
requests.
|
| |
Controls whether the DHCP server releases other leases a client
might have on other LAN segments on this server.
0 disabled
1 last-client-preferred
2 first-client-preferred
Within one LAN segment, the DHCP server never allocates more
than one DHCPv4 address to a single client. Across multiple
independent network LAN segments, however, a single client
might have one address allocated on several networks.
In an enterprise environment this might happen when a laptop
user travels from building to building, causing no particular
problems. In a service provider context, this might happen when
an unapproved user attempts to clone the MAC address of a
legitimate subscriber, causing a theft of service.
The one-lease-per-client feature limits a single client to one
lease over all of the networks configured on the DHCP server.
This limit only affects a client's ability to have concurrent
leases to different IP addresses on more than one network at
a time on the DHCP server.
In the last-client-preferred approach, the client with the most
recent lease is given preference, and any other leases held by
the same client are released.
In the first-client-preferred approach, the first lease that a
particular client receives from the DHCP server is the only
lease that client is allowed. In the event that the client
moves, the first lease must be made available (perhaps by a
force-available command or by letting it expire) before the
client is allowed to lease another IP address on a different
network.
Caution: Use the first-client-preferred approach with great
care, since manual intervention might be required to ensure
proper operation.
Both forms of one-lease-per-client require additional bookkeeping
overhead beyond that normally done in the DHCP server.
|
| |
Controls address allocation among scopes in the same network and
within an individual scope as well.
When enabled, any scope without an explicit setting for
allocation-priority is configured with an allocation-priority
equal to the network number of the scope. Similarly, any scope
without an explicit setting for allocate-first-available
is considered enabled.
Explicit settings for either of these scope attributes override
the priority-address-allocation set for that scope.
This attribute gives the administrator a way to change address
allocation in a server wide manner without having to separately
configure each scope.
|
| |
Controls whether the system returns the client FQDN option
in the outgoing packet to the client if the incoming packet
contains the FQDN option. Default false (disable).
If true (enable), the option flags are always set to 0x3
and the RCODE1 and RCODE2 to 255. Any string contained in the
incoming packet is returned, even if the use-client-fqdn
attribute is disabled and regardless of the actual FQDN.
|
| |
Determines whether to store the vendor=class-id, as
furnished in a dhcp request option 60, as part of the lease
record in either ldap, mcd or both.
|
| |
Determines whether the DHCP server looks up the client entry
in the database to do client-class processing. This value
can be examined as well as changed in a script at the
pre-client-lookup extension point. Default false
(disable).
If true, the server skips the client entry.
|
| |
Sets the amount of time, in milliseconds, that the DHCP server
waits between sending addresses to the System Management Server
(SMS) when executing updateSms command.
|
| |
Overrides the internal default value for the SMS.dll. Default
is an empty string.
If the string is empty, the system defaults to the internal
server default of smsrsgen.dll.
If the string is not empty, its value overrides the internal
SMS library name, smsrsgen.dll. If the system path does not include
the location of the SMS dll, you should provide the absolute path
of the dll.
|
| |
Determines whether the DHCP server generates SMS network
discovery records.
If this attribute is set to 0, you disable SMS network
discovery. If it is set to 1, you enable discovery.
Use this attribute in conjunction with the dhcp updateSMS
command.
|
| |
Specifies the site code name of the SMS server that receives
discovery records when you use the updateSMS keyword.
For proper functioning, make sure that you initialize this
attribute to the appropriate site code.
The default value is an empty string, but this prohibits data
discovery to complete successfully. So, you must provide the
site code.
|
| |
Controls whether the DHCP server automatically generates the
name of the reverse zone (in-addr.arpa or ip6.arpa) that receives
PTR records updates. Default is true (enable).
If true, you are not required to configure an explicit
dns-reverse-zone-name in the DNS update configuration. Instead, the
DHCP server uses the IP address of each lease and the dns-host-bytes
attribute of the scope or the reverse-zone-prefix-length attribute
of the prefix to synthesize the reverse zone name for each update.
The server trims the specified host bytes from the low-order
bytes of the address, and turns the remaining bytes into a zone
name of the form '.b.a.in-addr.arpa.' The host-bytes
low-order bytes of the address are used to form the hostname
within that zone. Similarly, the prefix length is used to
form the 'ip6.arpa' zone name, and the low-order bytes are used
to form the hostname.
|
| |
Determines the traps that this server is configured to send.
1 all
Sends notifications for all server events.
2 server-start
Sends notifications whenever the server is started or
reinitialized.
3 server-stop
Sends notifications whenever the server is stopped.
4 free-address-low
Sends notifications when the number of free IP addresses
becomes less than or equal to the low threshold.
5 free-address-high
Sends notifications when the number of free IP addresses
exceeds the high threshold after having previously
triggered the free-address-low trap.
6 dns-queue-size
Sends notifications when the DHCP server?s DNS queue
fills and the DHCP server stops processing requests.
7 other-server-down
Sends notifications when another server (DHCP, DNS, or
LDAP) stops responding to this DHCP server.
8 other-server-up
Sends notifications when another server (DHCP, DNS, or
LDAP) responds after having been unresponsive.
9 duplicate-address
Sends notifications whenever a duplicate IP address is
detected.
10 address-conflict
Sends notifications when an address conflict with another
DHCP server is detected.
11 failover-config-error
Notifies when a configuration mismatch between DHCP
failover partners occurs.
12 free-address-low
Sends notifications when the number of free IPv6 addresses
becomes less than or equal to the low threshold.
13 free-address-high
Sends notifications when the number of free IPv6 addresses
exceeds the high threshold after having previously
triggered the free-address-low6 trap.
14 duplicate-address6
Sends notifications whenever a duplicate IPv6 address is
detected.
15 duplicate-prefix6
Sends notifications whenever a duplicate prefix is
detected.
No default.
|
| |
Controls whether or not DHCP server trims the hostname string
to the first period (or dot) character (used to update DDNS
records and to return host-name-option to clients). Default,
true (enable).
If true, the hostname is truncated before the period.
If false, the DHCP server retains the period characters in the
hostname.
|
| |
If the server is replying to a BOOTP request, and is offering a
lease from a Scope which is configured to perform DNS updates, it
will check this property before beginning the DNS update. This
feature allows an administrator to prevent DNS updates for BOOTP
clients, while allowing updates for DHCP clients.
|
| |
Controls the time given to a lease in the database that has no
expiration; that is, it became unavailable prior to
installing Network Registrar. The DHCP server uses the
upgrade-unavailable-timeout for the expiration time of the
unavailable lease. Default is 86400 seconds (1 day).
|
| |
Controls whether the server examines the client-FQDN option
for the hostname. Default is true (enable).
If true, the server ignores any characters after the first dot (.)
because the domain is determined from the scope.
If false, the server does not determine the hostname using this.
This is useful if the client is sending unexpected or junk
characters.
|
| |
Controls whether the DHCP server looks at the client-FQDN option
on incoming packets first, before looking at the 'hostname'
option. Default is true (enable).
If true and the client-FQDN option specifies a hostname, the
server uses that hostname.
If the client-FQDN option is not present in the incoming packet,
the server uses the hostname from the 'hostname' option.
If false, the server also uses the hostname from the
'hostname' option.
|
| |
Controls whether the DHCP server adds prerequisites to DNS
update messages. Default true (enable).
If true, the DHCP server includes prerequisites in DNS update
messages to make sure the client is using the domain name,
before it is updated with the current lease (IP
address).
If false, the DHCP server assumes the requesting client is
entitled to the domain name. In this case, it does not include
prerequisites in the DNS update message, and associates the client
lease with that domain name.
Note: The DHCP server always adds prerequisites to the DNS
update message while adding a new domain name record on behalf
of a client acquiring a new lease and removing the domain name
record when a client releases its lease or the lease expires.
|
| |
Specifies whether the server looks at the 'hostname' option
for the hostname. Default is true (enable).
If true, the server obtains the hostname from the 'hostname'
option.
If false, the server does not obtain the hostname from this
option. This is useful if the client is sending unexpected or
junk characters.
|
| |
Controls whether the DHCP server attempts to read client-entry
data using the configuration supplied by the 'ldap'
command. Default is false (disable).
|
| |
Defines the expression used to assign a client-class based
solely on data contained in an incoming DHCPv6 client request.
No default.
The expression must return a string that is the name of a
currently configured client-class; otherwise, the expression
must return the string ''. Any return that is not a string
containing the name of a currently configured client-class or
'' is considered an error.
|
| |
Specifies the default SNMP v6 free-address trap configuration object
for the server. All Prefixes and Links that are not individually
configured use this default free-address value.
|
| |
Controls whether the Network Registrar user interfaces require
that the name of client entries is valid MAC address (or the
literal string 'default'). Default is false (disable).
If true, the user interfaces convert the name to the canonical
MAC address format: 1,6,xx:xx:xx:xx:xx:xx. The DHCP server uses
this as the default client entry lookup key.
If false, the user interfaces allow creating client
entries with arbitrary names, which could match the lookup
keys generated from the client-lookup-id expression.
|
| |
Controls the ability of the DHCP server to communicate with
clients that are on a different VPN from the server. Default
is true (enable).
If true, the server communicates with DHCP clients residing on
a different VPN by using an enhanced DHCP Relay Agent capability.
This enhanced DHCP Relay Agent capability is indicated by the
appearance of the server-id-override sub-option in
the relay agent information option (Option 82).
|
| | | | |
| |
dhcp-address-block-policy - Edits a DHCP policy embedded in an
address-block
|
| |
Synopsis |
| |
dhcp-address-block-policy <name> delete
dhcp-address-block-policy <name> set <attribute>=<value>
[<attribute>=<value> ...]
dhcp-address-block-policy <name> get <attribute>
dhcp-address-block-policy <name> disable <attribute>
dhcp-address-block-policy <name> enable <attribute>
dhcp-address-block-policy <name> show
dhcp-address-block-policy <name> setLeaseTime<time-val>
dhcp-address-block-policy <name> getLeaseTime
dhcp-address-block-policy <name> setOption<opt-name | id> <value>
dhcp-address-block-policy <name> getOption<opt-name | id>
dhcp-address-block-policy <name> unsetOption<opt-name | id>
dhcp-address-block-policy <name> listOptions
dhcp-address-block-policy <name>
setVendorOption <opt-name | id> <opt-set-name> <value>
dhcp-address-block-policy <name>
getVendorOption <opt-name | id> <opt-set-name>
dhcp-address-block-policy <name>
unsetVendorOption <opt-name | id> <opt-set-name>
dhcp-address-block-policy <name> listVendorOptions
|
| |
Description |
| |
The dhcp-address-block-policy command lets you configure a DHCP
policy embedded in a DHCP address block. An embedded policy is a
collection of DHCP option values and settings associated with (and
named by) another object -- in this case an address block. An
dhcp-address-block-policy is created implicitly when you first
reference it, and is deleted when the address block is deleted.
You can set individual option values with the setOption command,
unset option values with the unsetOption command, and view option
values with the getOption and listOptions commands. When you set
an option value the DHCP server will replace any existing value or
create a new one as needed for the given option name.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
policy, client-policy, client-class-policy, scope-policy
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
dns - Configures and controls the DNS server
|
| |
Synopsis |
| |
dns disable <attribute>
dns enable <attribute>
dns get <attribute>
dns set <attribute>=<value> [attribute>=<value ...]
dns unset <attribute>
dns show
dns findRR -name <fqdn>|<addr>
dns findRR [-namePrefix <namePrefix>] [-rrTypes <rrTypeList>]
[-protected | -unprotected] [-zoneType forward | reverse
| primary | secondary | published | unpublished | ALL]
dns addRootHint <name> <addr> [<addr> ...]
dns removeRootHint <name>
dns listRootHints
dns addException <name> <addr> [<addr> ...]
dns removeException <name>
dns listExceptions
dns addForwarder <addr>
dns removeForwarder <addr>
dns listForwarders
dns flushCache
dns rebuildRR-Indexes
dns forceXfer secondary
dns scavenge
dns serverLogs show
dns serverLogs nlogs=<nlogs> logsize=<logsize>
dns getStats [performance | query | errors | security | maxcounters |
ha | ipv6 | all] [total | sample]
dns resetStats
dns getZoneCount [forward | reverse | primary | secondary | published |
unpublished | ALL]
dns getRRCount [zone <name> | forward | reverse | primary | secondary |
published | unpublished | ALL]
dns removecachedRR <name> [<type>] [<data>]
dns setPartnerDown
|
| |
Description |
| |
The dns command lets you configure the DNS server in the cluster.
dns findRR -name <fqdn>|<addr>
dns findRR [-namePrefix <namePrefix>] [-rrTypes <rrTypeList>]
[-protected | -unprotected] [-zoneType forward | reverse
| primary | secondary | published | unpublished | ALL]
Use the findRR commands to display the resource records for a
specific domain name; or to display those matching a name prefix,
a list of resource record types--whether protected or unprotected--and
certain zone types.
dns addRootHint <name> <addr> [<addr> ...]
dns removeRootHint <name>
dns listRootHints
Use the RootHint commands to add or remove the names
and addresses of the root servers. After you specify the
root servers, Network Registrar queries them for their
root name server records. These records are in turn used
to resolve other names. As such, these values need not be
exact, but must be accurate enough for the Network Registrar
DNS server to retrieve the correct information.
The addRootHint command adds the name of a root server and the
addresses (to which it is listening on) to the list that the DNS
server uses to find the roots of the DNS name space.
The removeRootHint command removes a root server from the list.
The listRootHints command lists the root server information.
dns addException <name> <addr> [<addr> ...]
dns removeException <name>
dns listExceptions
Use the exception commands only if you do not want
your DNS server to use the standard name resolution
for querying root name servers for names outside the domain.
The exception command lets you specify the resolution
exception domains and the IP addresses of the associated
servers.
The addException command adds a list of DNS servers to use
to resolve names in a specified domain. This list allows you
to override DNS the publicly configured names server for one
or more domains.
The removeException command removes an entry for exceptional
resolution of addresses within a domain.
The listExceptions command lists the domains that are configured
to have exceptional resolution of their names.
dns addForwarder <addr>
dns removeForwarder <addr>
dns listForwarders
Use the Forwarder commands to specify the addresses of any name
servers that you want your Network Registrar DNS server to use
as forwarders. Network Registrar forwards recursive queries to
these servers before forwarding queries to the Internet at-large.
You can use the exception command to override forwarding for
specific domains.
The addForwarder command adds the address of a forwarder for
this DNS server.
The removeForwarder command removes the address of a forwarder.
The listForwarders command lists the forwarders for this DNS
server.
dns flushCache
The flushCache command flushes the persistently cached
information in the DNS server. To remove cached information, to be removed,
reload the DNS server.
dns rebuildRR-Indexes
The rebuildRR-Indexes command rebuilds the resource record
indexes.
dns forceXfer secondary
The forceXfer command forces full zone transfers for every zone
whose type matches the type (primary or secondary) specified in
the command, regardless of the SOA serial numbers, to synchronize
DNS data store. If a normal zone transfer is already in progress,
the forceXfer command schedules a full zone transfer for that
zone immediately after the normal zone transfer finishes.
Note: The option for primary is not yet available.
dns scavenge
The scavenge command causes scavenging to occur on all primary
zones that have scavenge enabled.
dns serverLogs show
dns serverLogs nlogs=<nlogs> logsize=<logsize>
The serverLogs show command displays the number of log files
and the maximum size for each file.
The serverLogs command allows setting the two server logging
parameters, nlogs and logsize. Either or both may be specified
in the command, and changes will only occur to the one(s)
specified. When setting logsize, a suffix of K or M indicates
units of thousands or millions.
dns serverLogs nlogs=6 logsize=500K
dns serverLogs logsize=5M
Note: For these changes to take effect you must save the changes
and restart the server Agent.
dns getStats [performance | query | errors | security | maxcounters |
ha | ipv6 | all] [total | sample]
dns resetStats
The getStats command displays the requested DNS server
statistics, either since the last reload or for the last sample
period.
The resetStats commands returns the DNS activity counters
(statistics) to zero.
dns getZoneCount [forward | reverse | primary | secondary | published |
unpublished | ALL]
dns getRRCount [zone <name> | forward | reverse | primary | secondary |
published | unpublished | ALL]
The getZoneCount and getRRCount commands display the number of
zones or resource records for the requested zones. By default,
all published zones are reported.
dns removecachedRR <name> [<type>] [<data>]
The removecachedRR comand allows the removal of non-authoritative
RRs from both the (non-authoritative) persistent cache and
the in-memory cache. An RR name-set can be removed by supplying
only 'name'. An RR-set can be completely removed by specifying
both 'name' and 'type'; a specific RR can be purged by supplying
'name', 'type' and 'data'.
dns setPartnerDown
The setParterDown command notifies the DNS server that its High
Availability DNS partner server is down.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
server
|
| |
| |
Attributes |
| |
| |
Sets the period of time that server activity counters use to
collect metrics.
Use this attribute together with the 'collect-sample-counters'
attribute. Make sure the 'collect-sample-counters' is set to
true (enable) to start sampling.
|
| |
Controls what activity counters a DNS server uses for logging.
The possible flags are:
total log the accumulated counters since reset or server
start.
sample log counters for each sampling interval.
performance log performance-related counters.
query log query-related counters.
errors log error-related counters.
security log security-related counters.
maxcounters log maxcounters-related counters.
ha log HA-related counters.
ipv6 log IPv6-related counters.
|
| |
Sets the seconds between DNS activity summary log messages,
if the activity-summary attribute is enabled in the server
log-settings. The default value is 5 minutes.
|
| |
Sets the kilobytes of internal (BTREE) cache that the authzone
database uses.
Note: This value is rounded up to the nearest 4KB boundary. For
example, an 81KB value is rounded up to 84KB.
|
| |
Determines the default multi-record AXFR choice for
foreign (remote) servers not found in remote server list.
Default is true (enable). Only old version Bind 8.x and
Microsoft NT version require this attribute to set false.
|
| |
Sets the kilobytes of internal (BTREE) cache that the cache database
uses.
Note: This value is rounded up to the nearest 4KB boundary. For
example, an 81KB value is rounded up to 84KB.
|
| |
Sets the seconds that elapse between snapshots of zone information.
DNS records this information in the Zone Checkpoint database.
|
| |
Switches counter sampling on and off.
|
| |
Sets the amount of time in seconds that the DNS server caches
negative answers if there is no SOA record in the authority
section of the reply.
The presence of an SOA record in the authority section of a
negative overrides this attribute value.
For more details, see IETF RFC2308.
|
| |
Instructs the DNS server to expect a specified zone to
return only delegations to authoritative nameservers
when queried.
Other than records at the domain name itself, the
specified zone must contain only NS records for each each
nameserver to which the subzone is delegated and the zone's
apex SOA record. For example, 'com.' is a domain that should
contain only delegations.
Use this attribute to filter out wildcard or synthesized data
from authoritative nameservers whose undelegated (in-zone) data
is of no interest.
The server enforces the delegation-only nature of the domains on
this list when it examines responses that are not from a
forwarder or resolution exception server. The server converts
non-conforming answers to no-such-name responses. This cannot
be enforced when the answer comes from a forwarder.
|
| |
Controls the order (forward-first, forward-last or forward-always)
with which the DNS server will forward a query to a configured
resolution exception.
forward-always - DNS will always forward queries to a configured
exception
forward-first - DNS will first forward queries to a configured
exception and if it doesn't get an answer
before the request expires, it will forward to
cached name servers (if any)
forward-last - DNS will first forward queries to cached name
servers (if any) and if it doesn't get an answer
before the request expires, it will forward the
query to a configured exception
|
| |
Controls whether the DNS server rejects queries of fully
qualified domain names that are in IP address form (for
example, an A record like 192.168.40.40), without even trying
to query (or forward to) other servers. Default is true
(enable).
Enabling this feature causes the server to respond to these
queries indicating the name does not exist. Queries of this
type are generally from rogue applications.
|
| |
Sets the retry interval for forwarding a DNS query to a
forwarder or resolution exception server. These queries are
recursive, and may require more time for the forwarder to
resolve.
To ensure the server tries all forwarders, set this value to the
'request-expiration-time' divided by one less than the total
number of configured forwarders).
Note: This attribute has no affect when you enable slave-mode;
the server uses slave-forward-retry-time instead.
|
| |
Sets the period of time that must elapse before the server
determines it cannot communicate with its HA DNS partner.
|
| |
Controls the incremental transfer behavior for zones for
which you have not configured a specific behavior. Required,
true (enable).
|
| |
Specifies the maximum duration between full zone transfers that
the DNS server will request incremental transfer updates for its
secondary zones. After this time interval expires, even if an
incremental transfer would normally be requested, the DNS server
will instead request a full zone transfer. Setting this value
to 0 does not enforce any time limit between full zone transfers.
|
| |
Specifies the UDP and TCP port number that the DNS server
uses to listen for queries.
|
| |
Determines which detailed events the DNS server logs, as set
using a bit mask. Logging these additional details can help
analyze a problem. Leaving detailed logging enable for a long
period, however, can fill the log files and cause the loss of
important information.
The possible flags are:
config
This flag will cause log messages pertaining to server
configuration and server de-initialization (unconfiguration).
ddns
This flag will cause the logging of high-level DDNS messages.
Detailed DDNS logging (e.g. RRs that have been deleted or
added) can be enabled via ddns-details.
xfr-in
This flag will allow the generation of log messages
associated with inbound full and incremental zone transfers.
xfr-out
This flag will allow the generation of log messages
associated with outbound full and incremental zone transfers.
notify
This flag allows log messages associated with the processing
of notify messages.
datastore
This flag allows the generation of log messages associated
with datastores processing. Enabling this flag provides
insight into various events in the server's embedded
databases/datastores.
scavenge
This flag allows the logging of events associated (RR)
scavenging.
scavenge-details
This flag causes more detailed logging, pertaining to
scavenging, to be displayed. Note, this flag is disabled by
default.
server-operations
This flag enables the logging of general high server events
(such as those pertaining to sockets and interfaces).
lame-delegation
This flag allows the logging of lame-delegation events.
Though enabled by default, disabling this flag could prevent
the log from getting filled with frequent lame-delegation
encounters.
root-query
This flag allows the generation of log messages associated
queries (and responses) from root servers.
ddns-refreshes
This flag allows the server to log messages associated with
(W2K) DDNS refreshes.
ddns-refreshes-details
This flag generates log messages that provide details
describing RRs that were refreshed.
ddns-details
This flag enables detailed logging that describes the RR(s)
that have deleted/added due to DDNS updates.
tsig
This flag allows the logging of events associated Transaction
Signature (TSIG) DDNS updates.
tsig-details
This flag causes more detailed logging, pertaining to tsig, to
be displayed. Note, this flag is disabled by default.
query-errors
This flag causes logging of errors encountered while
processing DNS queries.
config-details
This flag generates detailed information during server
configuration (e.g. displaying all configured and assumed
server attributes)
incoming-packets
This flag causes incoming packets to be traced.
outgoing-packets
This flag causes outgoing packets to be traced.
xfr-in-packets
This flag causes incoming zone transfer packets to be traced.
xfr-out-packets
This flag causes outgoing zone transfer packets to be traced.
query-packets
This flag causes query packets to be traced.
notify-packets
This flag causes notify packets to be traced.
ddns-packets
This flag causes DDNS packets to be traced.
performance
This flag logs server level performance statistics.
ha-details
This flag enables detailed logging of HA related information.
|
| |
Sets the maximum amount of time that you want the DNS server
to retain cached information. Default is 604800s (1w).
|
| |
Specifies the maximum number of packets that dns server will
handle concurrently. DNS server will drop inbound packets if this
limit is reached.
|
| |
Sets an upper limit on the number of seconds a DNS server
maintains negative cache entries. Default is 3600s (1h).
A server generates these cache entries after querying another
name server and receiving an authoritative reply stating the
requested records do not exist.
|
| |
Indicates the size, in kilobytes, of the in-memory record cache.
Default is 50000 (50MB).
|
| |
Controls whether the DNS server omits or includes records from
the authority and data sections of query responses when these
records are not required. Enabling this attribute may improve
query performance such as when the DNS server is configured as
a caching server.
|
| |
Indicates how long information learned from other name
servers about non-existent names or data should be cached.
|
| |
Specifies whether you want the DNS server, when composing
a response to a query, to fetch missing glue records.
Glue records are DNS A records, which specify the address of a
domain's authoritative name servers. Normal DNS responses include
NS records and their A records related to the name being queried.
|
| |
Specifies whether you want to disable forwarding client queries
to other name servers when your DNS server is
not authoritative for data in its own cache. If you disable
recursive queries, you make your name server a noncaching server.
|
| |
Controls how the DNS server sends NOTIFY packets for zones
that have changed. Default is true (enable).
You must also set these attributes or accept their defaults:
notify-defer-cnt, notify-min-interval, notify-rcv-internal,
notify-send-stagger, notify-wait.
|
| |
With the notify attribute enabled, sets the maximum number of
changes the DNS server can accumulate during the notify-wait
period. If changes exceed this number, the DNS server sends
notification before the notify-wait period has elapsed.
Default is 100 changes.
|
| |
With the notify attribute enabled, sets the minimum interval
required before sending notification to a particular server of
consecutive changes on the same zone. Default is 2s.
|
| |
With the notify attribute enabled for secondary zones, sets the
minimum amount of time between complete processing of one
notification (serial number testing and/or zone transfer), and
the start of processing of another notification. ,
default 5s.
|
| |
With the notify attribute enabled, sets the interval
to use for staggering notifications to multiple servers
about a zone change. Default is 1s.
|
| |
Specifies the source IP address that the DNS server uses to send
notify requests to other servers. A value of 0.0.0.0 indicates
that operating systen uses the best local address based on the
destination.
|
| |
Specifies the UDP port number that the DNS server uses to send
notify requests to other servers.
A value of zero indicates that the server should choose a random
port. If this attribute is unset, then queries are sent from
the port used to listen for queries (See the local-port-num
attribute).
|
| |
With the notify attribute enabled, and after an initial zone
change, sets the period of time for the DNS server to wait
before it sends change notification to other name servers.
Default is 5s.
This property allows you to accumulate multiple changes,
and thus limit the number of times the serial number advances.
|
| |
Specifies whether the DNS server writes memory chache, or reads
it from the persistent cache database.
If you set this to false, DNS does not use the persistent cache
database.
|
| |
Specifies the source IP address from which the DNS server will
send queries to other servers when resolving names for clients. A
value of 0.0.0.0 indicates that OS will use the best local address
based on the destination.
|
| |
Specifies the UDP port number that the DNS server uses to send
queries to other servers when resolving names for clients. A
value of zero instructs the server to choose a random port. If
you unset this attribute, the server sends queries from the
port it uses to listen for queries (see the local-port-num
attribute).
|
| |
Specifies the UDP and TCP port number the DNS server
uses to send queries to other servers. Default is port 53.
|
| |
Governs the expiration time of DNS queries; for example,
DNS query, zone transfer SOA query, IXFR request and notify
request). A query that is not answered within this time interval
expires.
Note: Cisco recommends that you make sure this value is
considerably larger than 'request-retry-time' to allow multiple
attempts to query multiple servers, using exponential backoff.
|
| |
Dictates the retry time interval (in secs) when querying a name
server. This time interval is used in general queries - in
response to DNS clients queries - (zone transfers) SOA queries,
IXFR requests and notify requests. Understand that this is a
minium retry time. The server applies an exponential backoff on
retries.
|
| |
Specifies an access control list that restricts which
clients are allowed to query for cached non-authoritative
resource records. If unset, restrict-query-acl is used.
Optional.
|
| |
Provides a global access control list (ACL) used to limit device
queries that a DNS server must honor. You can restrict query
clients based on host IP address, network address, TSIG keys,
and access control lists. The default is to allow any client to
perform a query.
Zones inherit this ACL if they are missing their
restrict-query-acl. This ACL also serves as filtering queries for
non-authoritative zones.
|
| |
Defines the global Access Control List (ACL) used to restrict
recursive that the DNS server honors. This list can contain
host, network addresses, TSIG keys and global ACLs that
restrict recursive queries to a certain set of DNS clients.
Default is to allow any client to perform a query. For any client
not passing this ACL andrequesting a recursive query, the server
responds with a referal - as if originally requested with an
iterative query.
|
| |
Overrides the default access control list (designating who can
receive zone transfers).
|
| |
Specifies whether you want round-robin cycling of equivalent
records in responses to queries. Equivalent records are records
of the same name and type. Since clients often only look at the
first record of a set, enabling this features can help balance
loads and keep clients from forever trying to talk to an
out-of-service host.
|
| |
Controls whether to have the server store negative query results.
Default, true (enable).
Disabling this feature prevents persistent caching of negative
query responses.
|
| |
Ensures that the server does not reset the scavenging time with
every server restart. Within this interval, Network Registrar
ignores the time between when a server went down and its restart.
This interval is normally short. The value can range from two
hours to one day. With any time longer than that set,
Network Registrar recalculates the scavenging period
to allow for record updates that cannot take place while the
server is stopped. You can also set this attribute on a zone,
and the value set on the zone overrides the server setting.
Default is 2h.
|
| |
Sets the seconds that DNS waits before removing (scavenging)
out-of-date address (A) records.
|
| |
Sets the number of seconds during which DNS updates cannot increment
the zone timestamp.
|
| |
Sets the number of seconds during which DNS updates can increment
the zone timestamp. After both the no-refresh and refresh intervals
expire, the record is a candidate for scavenging. The value
can range from one hour to 365 days. The zone setting overrides
the server setting of 604800s (1w).
|
| |
Enables compatibility with a Windows 2000 Domain Controller.
When processing a dynamic update packet, which attempts to add
or remove A records from the name of a zone, DNS responds as if
the update succeeded, rather than responding with a refusal, as
would normally occur due to the protected/unprotected name
conflict. No update to the records at the zone name will actually
occur, although the response indicates that it has.
|
| |
Sets the retry interval for forwarding a DNS query in slave-mode.
These queries are recursive, and may require more time for the
forwarder to resolve.
To ensure the server tries all forwarders, set this value to the
'request-expiration-time' divided by one less than the total
number of configured forwarders.
|
| |
Specifies whether you want this server to be a slave server; that
is, a server that relies entirely on forwarders for data that
is not in its cache. Default is false (disable).
This attribute takes effect only if you specify the corresponding
forwarders.
Note: You can override slave-mode for specific domains with the
exception-list property.
|
| |
Controls whether DNS reorders A records when responding to client
queries. Default is false (disable).
As implemented in BIND 4.9.7, the Network Registrar DNS
server confirms the client?s network address before responding to
a query. If the client, server, and target of the query are on the
same subnet, and the target has multiple A records, the server tries
to reorder the A records in its response by putting the target?s
closest address first in the response packet.
Because clients often only look at the first record in a set,
enabling this attribute can help localize network traffic onto
a subnet. This attribute is only applied on answers to queries
from clients located on the same subnet as the DNS server.
|
| |
Defines the retry time for DNS queries over a TCP connection.
Cisco recommends that you set this value to less than
'request-expiration-time'.
|
| |
Specifies the source IP address that the DNS server uses to send
transfer and SOA requests to other servers.
A value of 0.0.0.0 indicates that operating system uses the best
local address based on the destination.
|
| |
Specifies the UDP port number that the DNS server uses to send
transfer and SOA requests to other servers.
A value of 0 (zero) indicates that you should choose a random port.
If this attribute is unset, then queries are sent from the port
used to listen for queries (see local-port-num).
|
| |
Defines the traps that this server is configured to send.
1 all
Sends notifications for all server events.
2 server-start
Sends notifications whenever the server is started or
reinitialized.
3 server-stop
Sends notifications whenever the server is stopped.
4 ha-dns-partner-down
Sends notifications whenever the HA DNS partner
goes down.
5 ha-dns-partner-up
Sends notifications whenever the HA DNS partner becomes
available again after going down.
6 ha-dns-config-error
Sends notifications when a configuration mismatch between
HA DNS partners occurs.
7 masters-not-responding
Sends notifications when master servers stop responding.
8 masters-responding
Sends notifications when master servers start responding
again.
9 secondary-zone-expired
Sends notifications when a secondary server can no longer
claim authority for zone data when responding to queries
during a zone transfer.
10 forwarders-not-responding
Sends notifications when DNS forwarders stop responding.
11 forwarders-responding
Sends notifications when DNS forwarders start responding
again.
|
| |
Provides server-level control of which devices can access and
update the DNS server. If the access control list is set at the
zone level, Network Registrar overrides the server-level setting.
|
| |
Enables DNS updates to specify any zone name in the authoritative
zone rather than the exact zone name; thus, relaxing the RFC 2136
restriction on the zone name record in dynamic updates. This
attribute allows updates to specify a zone name which is any name
within an authoritative zone rather than exactly the name of a zone.
|
| | | | |
| |
failover-pair - configures a DHCP failover relationship
|
| |
Synopsis |
| |
failover-pair <name> create <main-cluster/address>
<backup-cluster/address>
[<attribute>=<value> ...]
[addMatch [<vpn>/]<address/mask>]
failover-pair <name> delete
failover-pair list
failover-pair listnames
failover-pair <name> show
failover-pair <name> get <attribute>
failover-pair <name> set <attribute>=<value> [<attribute>=<value> ...]
failover-pair <name> unset <attribute>
failover-pair <name> addMatch [<vpn>/]<address/mask>
failover-pair <name> removeMatch [<vpn>/]<subnet/mask>
failover-pair <name> listMatches
failover-pair <name> sync <update | complete | exact>
[<main-to-backup | backup-to-main>]
|
| |
Description |
| |
The failover-pair command lets you define and manage the failover
relationship between a main and backup server.
Either the main and backup clusters or the main and backup server
IP addresses can be specified with the create command. If the
main-server and backup-server addresses are set, the cluster addresses
will only be used for synchronization of the server configuration.
The referenced clusters must be configured with appropriate connection
credentials for the sync command to be successful.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
cluster
|
| |
| |
Attributes |
| |
| |
Identifies the cluster that contains the backup server for
a failover pair.
|
| |
Controls the percentage of available addresses that the main
server sends to the backup server. Set this value
on the main server. If it is set on a backup server, it is
ignored (to enable copying of configurations).
Unless you explicitly set this value on a scope and you disable
load balancing, the value set here becomes the default value.
|
| |
Controls the IP address used for the failover protocol on the
backup server. If this value is unset, the address specified
for the backup cluster is used. Cisco recommends setting
this attribute only if the server is configured with
different interfaces for configuration management and clients
requests. Always configure the failover protocol with the
interface used to serve clients.
|
| |
Determines the percentage of available addresses that the
main server sends to the backup server for scopes on which dynamic
BOOTP is enabled. If defined, it must be defined on
the main server. If it is defined in a backup server, it is
ignored (to enable copying of configurations). If it is not
defined at all or the value is 0, the "backup-pct" is
used instead. This parameter is separate from "backup-pct"
because if dynamic BOOTP is enabled on a scope, a server
will never, even in PARTNER-DOWN state, grant leases on
addresses that are available to the other server because
they can never safely be assumed to be available again.
The MCLT has no meaning for dynamic BOOTP leases.
|
| |
Enables failover configuration. If you disable this attribute,
you turn off failover on attached subnets without changing
configuration fundamentals.
|
| |
Determines whether load balancing (RFC 3074) is enabled on a failover
pair. The default is disabled. When enabled, the backup-pct is
ignored and the main and backup server evenly split the client
load and available leases for all scopes in the failover
relationship (that is, as if backup-pct were configured at 50%).
|
| |
Identifies the cluster with the main server for a failover pair.
|
| |
Controls the IP address used for the failover protocol on the
main server. If this value is unset, the address specified
for the main cluster is used. Cisco recommends setting
this attribute only if the server is configured with
different interfaces for configuration management and clients
requests. Always configure the failover protocol with the
interface used to serve clients.
|
| |
Sets the maximum client lead time in seconds. This attribute
controls how far ahead of the backup server that you can make
the client lease expiration. You must define this value on both
the main and backup servers, and make sure the value is
identical on both servers.
|
| |
Names a failover pair.
|
| |
Controls when the main server updates its database. Normally,
the main server updates its database when the backup server
ACKs it with what the backup knows. Disabling this capability
speeds up the main server, but after a restart the main server
is out of sync with what the backup knows, and may offer all
clients one lease period with a renew time of the current time
plus the MCLT.
|
| |
Specifies how often to collect lease history from the DHCP
server for this cluster. If set to 0, no poll occurs.
|
| |
Provides a fixed time of day for lease history polling.
This time is interpreted as a time of day offset, with 0 being
12 midnight, provided the polling interval is less than 24 hours,
and the offset value is less than the polling interval. If the
offset value is greater than the polling interval, or the
interval is greater than 24 hours, the offset will be ignored.
The scheduler for polling will ensure that the first polling
event occurs at the offset time. For example, if you set the
interval to 4 hours and the offset to 2am, the polling would
occur at 2am, 6am, 10am, 2pm, 6pm and 10pm.
|
| |
Specifies how often to retry if the server fails to poll
the data.
|
| |
Specifies which server to poll first:
0 main server
1 backup server
|
| |
Specifies how often to collect the subnet utilization data
from DHCP server for this cluster. If set to 0, no poll
occurs.
|
| |
Provides a fixed time of day for subnet utilization polling.
This time is interpreted as a time of day offset, with 0 being
12 midnight, provided the polling interval is less than 24 hours,
and the offset value is less than the polling interval. If the
offset value is greater than the polling interval, or the
interval is greater than 24 hours, the offset will be ignored.
The scheduler for polling will ensure that the first polling
event occurs at the offset time. For example, if you set the
interval to 4 hours and the offset to 2am, the polling would
occur at 2am, 6am, 10am, 2pm, 6pm and 10pm.
|
| |
Specifies how often to retry if the server fails to poll
the data.
|
| |
Specifies which server to poll first:
0 main server
1 backup server
|
| |
Controls the safe period, in seconds. It does not have to be
the same on both main and backup servers. It only has meaning
if use-safe-period is enabled. Define this attribute on the
main server. If it is defined on a backup server, it is ignored
(to enable copying of configurations).
|
| |
Associates a scope template with a specified failover pair.
|
| |
Controls whether a server can enter PARTNER-DOWN state without
an operator command. If disabled, a server never enters
PARTNER-DOWN without an operator command.
Define this attribute on the main server. If it is defined
on a backup server, it is ignored (to enable copying of
configurations).
|
| | | | |
| |
ldap - Specifies the LDAP remote server's properties
|
| |
Synopsis |
| |
ldap list
ldap listnames
ldap <name> create <hostname> [<attribute>=<value>...]
ldap <name> delete
ldap <name> get <attribute>
ldap <name> set <attribute>=<value> [<attribute>=<value> ...]
ldap <name> unset <attribute>
ldap <name> disable <attribute>
ldap <name> enable <attribute>
ldap <name> show
ldap <name> setEntry <dictionary> <key>=<value>
ldap <name> getEntry <dictionary> <key>
ldap <name> unsetEntry <dictionary> <key>
|
| |
Description |
| |
The ldap command configures the LDAP servers that the DHCP server
should communicate with. The DHCP server can read client configuration
information from or write lease information to an LDAP enabled directory.
Use the setEntry, getEntry, and unsetEntry commands to set, query,
and clear elements of the various dictionary properties in the LDAP server
configuration. These dictionary properties provide a convenient mapping
from strings keys to string values.
The dictionary values for the setEntry command are:
create-dictionary
create-string-dictionary
env-dictionary
query-dictionary
update-dictionary
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
|
| |
| |
Attributes |
| |
| |
Controls whether a particular LDAP server can create new entries
to use to store lease state updates. See the create properties:
create-dictionary, create-string-dictionary, dn-create-format,
create-object-classes.
|
| |
Controls whether a particular LDAP server can be used for client
queries. See the query properties: env-dictionary,
query-dictionary, search-attribute, search-filter, search-path,
and search-scope.
|
| |
Controls whether a particular LDAP server can be used to store
lease state updates. See the update properties: update-dictionary,
update-search-attribute, update-search-filter, update-search-path
update-search-scope.
|
| |
Determines the number of connections that the server can make to an
LDAP object.
Network Registrar creates one thread for each connection configured
in an LDAP object, and each thread can have a maximum of LDAP
requests associated with its request queue.
This is primarily a performance-tuning attribute. In some cases,
having more than one connection can improve overall throughput.
|
| |
Maps LDAP attributes to DHCP lease attributes. If an entry does
not exist and needs to be created, entries in this dictionary
are set to the value of its corresponding DHCP lease attribute.
|
| |
If can-create is enabled, specifies the object classes from
which a new entry inherits.
|
| |
Maps LDAP attributes to user specified strings. If an entry does not
exist and needs to be created, entries in this dictionary are set to
the matching string.
|
| |
Provides a default attribute value (a string) to insert in any LDAP
attribute whose associated lease attribute values are not present in
the lease.
|
| |
Determines how the server constructs the distinguished name (DN)
of the LDAP entry to update or create.
If the server can use one of the lease attributes, it formats the
specified dn-attribute using the dn-format string to construct
the object filter that specifies the LDAP server to modify.
|
| |
Provides the distinguished name (DN) for entry creation. A % is
required at the entry level and is replaced by the value of the
dn-attribute. If you can construct the DN of the LDAP object created
from one of the lease?s attributes, the server formats the specified
dn-attribute using the dn-format string.
|
| |
If the DN of the ldap object that is to be updated can be
constructed from one of the lease's attributes, the specified
dn-attribute will be formatted using the dn-format string to
construct the query filter.
|
| |
Enables or disables this LDAP remote server.
Prevents DHCP from attempting to use an LDAP server that is
known to be unavailable.
|
| |
Specifies the environment dictionary that allows the server to
retrieve additional LDAP attributes along with client-entry
attributes. If any of these are present in a query's results,
their values are made available to scripts through the request's
environment dictionary. The LDA{ value is keyed by the value in
the LDAP query env-dictionary.
|
| |
Sets the hostname of the server to connect to. LDAP servers require
hostnames.
|
| |
Controls whether there should be a limit on the number of
outstanding queries on each LDAP client connection. See the limit
property: max-requests.
|
| |
Limits the number of LDAP referrals the server follows when
querying. A value of zero prohibits following referrals.
|
| |
Controls the number of outstanding queries.
If you have set the 'limit-requests' feature to TRUE, any single
LDAP connection will limit the number of outstanding queries to
'max-requests.' You can improve performance by limiting the
number of outstanding queries.
|
| |
An arbitrary name used to refer to an individual server.
|
| |
Sets the password of a user with access to the parts of the directory
that DHCP uses. Because you can configure LDAP servers to allow
anonymous access, this is optional.
|
| |
Specifies the port on the remote server to connect to.
|
| |
Specifies the preference order in which LDAP servers are used.
A positive integer greater than or equal to one. One (1) is the
highest preference value.
|
| |
Maps LDAP attributes and DHCP attribute names. The server attempts
to retrieve all LDAP attributes specified in the dictionary. When a
query succeeds, the values for any ldap attributes that it returns
are set in the corresponding client-entry attribute.
|
| |
Specifies the number of seconds the DHCP server waits for a response
to individual LDAP Query requests. After a query request times out,
the DHCP server will drop the request and not process it again on
another LDAP connection or LDAP Server. A query-timeout value of 3
seconds is a good value.
Note: The timeout attribute configures the timeout for LDAP
Update and Create requests.
|
| |
Indicates whether an LDAP response is a referral. The referral may
or may not contain the DN for this query. If the DN is present (the
default), the server uses it as the search path, along with a
wildcard search-scope in the query that follows the referral. If not,
the server builds the search path by formatting the data in the
referral attribute with the referral-filter, using the existing
search scope.
|
| |
In the absence of a distinguished name (DN), controls how a
server formats referral-attr data. In such cases, the server formats
the referral attribute's data with this filter expression to build a
search path that uses the existing search-scope for the LDAP server.
|
| |
Specifies the filter to apply in the client-entry query. The server
formats the client's MAC address using the filter to specify the
object that contains the client-entry data.
|
| |
Designates an object in the directory to use as a query
starting-point. Together, the path and the search-scope control the
portion of the directory that the server will search.
|
| |
Controls the comprehensiveness of a search:
If you specify the scope to be SUBTREE, the server searches all
the children of the searchpath.
If you specify the scope to be ONELEVEL, the server searches only
the immediate children of the base object.
If you specify the scope to be BASE, the server searches only the
base object itself.
|
| |
Sets the number of milliseconds that an LDAP client connection
polls for the results of outstanding queries or updates.
|
| |
Controls the number of seconds the DHCP server waits for a response
to an individual LDAP update or create request. If an LDAP request
times out, the DHCP server resubmits it to other LDAP connections.
Further, if the DHCP server receives no response (that is, a result
for an LDAP update or create) from an LDAP connection for the timeout
seconds, DHCP marks this LDAP connection as 'Inactive' and tears down
the connection, then reconnects. A timeout value of 10 seconds is a
good value for LDAP create and update operations.
Note: You can configure a separate timeout for LDAP query operations
using the query-timeout attribute.
|
| |
Maps LDAP attributes to DHCP lease attributes. When an LDAP object
is modified, each LDAP attribute that is present in this dictionary
is set to the value of its corresponding DHCP lease attribute.
|
| |
If the DN of the object to be updated cannot be determined
directly, the DHCP server must issue a query to retrieve the DN.
In that case, the DHCP server uses data in the lease's
'search-attribute,' and formats it using the
'update-search-filter' expression.
|
| |
If the DN of the object to be updated cannot be determined
directly, the DHCP server must issue a query to retrieve the DN.
In that case, the DHCP server uses data in the lease's
'search-attribute,' and formats it using the
'update-search-filter' expression.
|
| |
Determines the starting point for the portion of the directory
containing LDAP objects for the server to update.
|
| |
With update-search-path, controls the portion of the directory
that contains the objects to be updated.
The scope can be SUBTREE (includes all children of the
searchpath), ONELEVEL (includes only the immediate children of the
base object), or BASE (includes only the base object itself).
|
| |
Designates a user with access to the parts of the directory that DHCP
uses. Because you can configure LDAP servers to allow anonymous
access, this is optional.
|
| | | | |
| |
lease - Manage DHCP lease objects
|
| |
Synopsis |
| |
lease list [-vpn=<vpn-name>] [-count-only]
lease list -macaddr <mac-address> [-vpn=<vpn-name>]
lease list -subnet <ip-address> <mask>
lease list -lansegment <ip-address> <mask>
lease [<vpn-name>/]<ip-address> [show]
lease [<vpn-name>/]<ip-address> get <attribute>
lease [<vpn-name>/]<ip-address> activate
lease [<vpn-name>/]<ip-address> deactivate
lease [<vpn-name>/]<ip-address> force-available
lease [<vpn-name>/]<ip-address> macaddr
lease [<vpn-name>/]<ip-address> get-scope-name
lease [<vpn-name>/]<ip-address> send-reservation
lease [<vpn-name>/]<ip-address> delete-reservation
|
| |
Description |
| |
The lease command lets you view and manipulate current DHCP leases
in the cluster.
When you specify the lease on which one of these commands is to
operate, you may optionally specify a <vpn-name> in which the
<ip-address> is to be found. You may specify the name of a
currently defined vpn as the <vpn-name>, or use the reserved vpn
name "global" (without the quotes) to specify the operation on
leases which are not in any explicitly defined vpn. If you do
not specify a <vpn-name>, then the session's current-vpn is used
as a default.
lease list [-vpn=<vpn-name>] [-count-only]
lease list -macaddr <mac-address> [-vpn=<vpn-name>]
lease list -subnet <ip-address> <mask>
lease list -lansegment <ip-address> <mask>
lease [<vpn-name>/]<ip-address> [show]
The list command lists leases in the DHCP server. Only the
leases in the current-vpn or specified vpn-name are listed.
<vpn-name> may be "all" (without the quotes) to request leases
in all vpns. If -count-only is specified, only the count of
the number of leases is returned (no leases are displayed).
The list -subnet command lists all leases in a subnet
(scopes whose address and mask match the query).
The list -lansegment command lists all leases in a LAN
segment, meaning all leases in scopes whose address and mask
match the query, as well as leases in secondary scopes whose
primary scope's address and mask match the query.
The list -macaddr command lists all leases that are associated
with the specified MAC address.
Note: The list -macaddr command for Network Registrar 6.3
and earlier clusters can be extremely slow. In release 7.0
and later, performance is improved. The recommended syntax
is -macaddr=<mac-address>.
lease [<vpn-name>/]<ip-address> activate
lease [<vpn-name>/]<ip-address> deactivate
The activate and deactivate commands tell the DHCP server
to make the specified lease active or inactive. An inactive
lease is not given out, even if it is in the available state.
Making a currently leased lease inactive does not affect its
behavior until it has expired and become available again.
lease [<vpn-name>/]<ip-address> force-available
The force-available command forces the specified lease into the
available state.
lease [<vpn-name>/]<ip-address> macaddr
The macaddr command provides the MAC address associated with
the specified lease.
lease [<vpn-name>/]<ip-address> get-scope-name
The get-scope-name command provides the scope to which the
lease belongs.
lease [<vpn-name>/]<ip-address> send-reservation
The now-deprecated send-reservation command sends an existing
reservation immediately to the DHCP server without requiring a
server reload. You must first run the scope <scope-name>
addReservation command for this reservation.
The recommended sequence is:
nrcmd> scope <scope-name> addReservation <ip-address> <mac-address>
nrcmd> save
nrcmd> lease <ip-address> send-reservation
This sequence ensures that the configuration database contains
the lease and reservation as well as the running server, since
the send-reservation command directly affects only the running
server's in-memory database, and does not itself persist past
the next server reload.
lease [<vpn-name>/]<ip-address> delete-reservation
The now-deprecated delete-reservation command deletes an
existing reservation immediately from the DHCP server without
requiring a server reload. It is important to ensure that
the configuration which the DHCP server uses for the next server
reload also has the reservation removed. The recommended sequence
is:
nrcmd> lease <ip-address> delete-reservation
nrcmd> scope <scope-name> removeReservation <ip-address>
nrcmd> save
Note: The send-reservation and delete-reservation commands are
deprecated. Use synchronous scope-edit-mode instead. These commands
are provided for command-syntax compatibility with prior versions
and only support mac-address based reservations.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
session current-vpn
|
| |
| |
Attributes |
| |
| |
Specifies the IP address of the lease. The address is added at
creation.
|
| |
Within the DHCPlease database, holds the time at which a
lease binding ended.
|
| |
Within the DHCP lease database, shows the time at which a
lease binding began.
|
| |
Displays the binary form of the client's client-identifier, if any.
|
| |
Displays the client DNS name, which the DHCP server attempted
(possibly successfully) to enter into the DNS server for
a specified client.
This attribute is related to the client-host-name, but may not be
identical due to name collisions in the DNS server database.
|
| |
Displays the domain (if any) to which the client's DNS name belongs.
|
| |
Displays any of the following values associated with the client
lease state:
2 client-id-created-from-mac-address
Indicates that the client-id was created for internal use
from the client supplied MAC address. It is never
reported externally if this is true.
3 client-dns-name-up-to-date
Indicates that the client-dns-name (A) is actually current
in the DNS server database.
5 reverse-dns-up-to-date
Indicates that the reverse (PTR) DNS entry is current in
the DNS database.
9 dns-update-pending
Indicates that a DNS operation is pending for this client.
16 in-limitation-list
Indicates that this lease is presently in a limitation list
using the limitation-id shown.
These are for internal use only:
client-valid
client-fqdn-present
client-updates-name
clear-host-name
host-name-has-changed
domain-name-has-changed
use-test-before-update
avoid-dns-retry
dual-zone-dns-update
client-invalid-due-to-macaddress
used-over-limit-client-class
synthesize-dns-name
reservation-uses-client-id
client-id-from-override-id
client-id-from-string
|
| |
Displays the DNS name that the client requested the DHCP server
to place in the DNS server.
|
| |
Displays the time when the client most recently contacted the
DHCP server.
|
| |
Displays the MAC address which the client presented to the DHCP
server.
|
| |
Indicates the operating system of the client. This attribute is used
only by the updateSms keyword and has no other purpose. If you
enable failover, the main server transmits this value to the backup
server. The syntax of this attribute?s value is OS-name major.minor.:
Operating system values are as follows:
Microsoft Windows NT Server
Microsoft Windows NT Advanced Server
Microsoft Windows NT Workstation 4.0
Microsoft Windows NT Workstation 3.51
Microsoft Windows 2000 Professional
Microsoft Windows 95
Microsoft Windows 9x
Microsoft Windows for Workgroups
Microsoft Windows
Dos
Netware
LANMAN Workstation
LANMAN Server
OS/2
MAC OS
|
| |
The value of the override-client-id expression for this
client. If it appears, it is used as the client-id for
this client.
|
| |
The most recently received client vendor class option.
|
| |
The most recently received vendor-specific information
option.
|
| |
Records the original source of the lease data
and the machine from which the data was retrieved.
0 unknown
4 main-main
Indicates the data originated on the main server and
was retrieved from the main server.
5 backup-main
Indicates the data originated on the backup server and
was retrieved from the main server.
6 main-backup
Indicates the data originated on the main server and
was retrieved from the backup server.
7 backup-backup
Indicates the data originated on the backup server and
was retrieved from the backup.
When viewing leases with the UI's, you will see all four
values routinely, especially if load-balancing is enabled.
When looking at lease history records, main-main and
backup-backup are the usual values, but in cases where the
lease history poller has determined that some data may be
missing, then main-backup and backup-main can appear as
well.
|
| |
Displays the date and time the lease will expire.
|
| |
Displays flags that describe this lease:
1 reserved
The lease is reserved for some MAC address. The table
that relates MAC addresses to leases is in the scope.
3 deactivated
The lease is deactivated, which means that it should
not be used. Any client which is using a deactivated
lease will be NAK'ed on their next renewal.
7 dynamic
Last written by server which knew only about the lease
because it was created by a send-reservation command.
8 backup
Indicates that the state for this lease was recorded by
a server whose role was backup with respect to this lease.
For internal use only:
initialized
valid
failover-updated
|
| |
Names the Dns update configuration object used
to perform dynamic DNS update on a forward zone.
|
| |
If present, the contents of the last received non-zero giaddr
field. This represents the relay agent through which the client
and server last communicated.
|
| |
Displays the earliest time the client is expected to issue
a renewal request.
|
| |
Displays the value set for a client-class or client limiting the
number of simultaneous active leases a DHCP server can give out
to devices on customer premises.
|
| |
The contents of the 'authentication' suboption 8 of the relay-agent
information option 82 from this client.
|
| |
Displays the circuit-id sub-option of the DHCP relay-agent
information option 82 from this client.
|
| |
The contents of the 'device-class' suboption 4 of the relay-agent
information option 82 from this client.
|
| |
Displays the contents of the relay-agent information option 82
from the most recent client interaction.
|
| |
Displays the contents, if any, of the RADIUS class attribute
that was contained in the RADIUS Attributes suboption of the DHCP
relay-agent information option 82 from this client.
|
| |
The contents of the 'radius' suboption 7 of the relay-agent
information option 82 from this client.
This suboption has additional structure that is available on
other attributes of this class.
|
| |
Displays the contents, if any, of the RADIUS framed-pool attribute
88 contained in the RADIUS attributes suboption of the DHCP
relay-agent information option 82 from this client.
|
| |
If present, the contents of the RADIUS 'session-timeout' attribute
27 that was contained in the RADIUS Attributes suboption 7 of the
relay-agent information option 82 from this client.
|
| |
Displays the contents, if any, of the RADIUS user attribute
contained in the RADIUS attributes suboption of the DHCP relay-agent
information option 82 from this client.
|
| |
If present, the contents of the RADIUS 'v6-pool-name' attribute 100
that was contained in the RADIUS Attributes suboption 7 of the
relay-agent information option 82 from this client.
|
| |
If present, the contents of the RADIUS 'vendor-specific' attribute
26 that was contained in the RADIUS Attributes suboption 7 of the
relay-agent information option 82 from this client.
|
| |
Displays the remote-id sub-option of the DHCP relay-agent
information option 82 from this client.
|
| |
Displays the IP address in the server-id-override sub-option of the
DHCP relay-agent information option 82 from this client.
This value corresponds to one of two suboption numbers:
If the IANA assigned suboption 182 is present in the packet,
that value is returned; otherwise, if the Cisco suboption 152 is
present, that value is returned.
|
| |
Displays the IP address in the subnet selection sub-option
of the DHCP relay-agent information option 82 from this client.
This value corresponds to one of two suboption numbers:
If the IANA assigned suboption is present in the packet,
that value is returned; otherwise, if Cisco suboption 150 is
present, that value is returned.
|
| |
Displays the contents of the subscriber-id suboption of the
relay-agent information option 82 from this client.
|
| |
The contents of the 'v-i-vendor-class' suboption 9 of the
relay-agent information option 82 from this client.
|
| |
Displays the contents of the vpn-id sub-option of the DHCP
relay-agent information option 82 from this client.
This value corresponds to one of two suboption numbers:
If the IANA assigned suboption 181 is present in the packet,
that value is returned; otherwise, if Cisco suboption 151 is
present, that value is returned.
|
| |
The lookup key with which a reservation for this lease will be
retrieved.
|
| |
Names the Dns update configuration object used
to perform dynamic DNS update on a reverse zone.
|
| |
A reference to the scope that contains this lease.
|
| |
Displays the time the state changed to its current value.
|
| |
Displays the current state of the lease.
1 available
The lease is not currently leased by any client. Any
client information is from the most recent client to
lease or be offered this lease.
2 offered
The lease is offered to the associated client. In many
cases, the database is not written with information
concerning offering a lease to a client since there is
no requirement to update stable storage with this
information.
3 leased
The lease is currently leased to the client whose
information appears in the lease.
4 expired
The client specified has not renewed the lease, and it
expired. Upon expiration the DNS information for this
client was scheduled for removal.
5 unavailable
The lease is unavailable. It was made unavailable because
of some conflict. A ping attempt might have shown that the
another client using the, or the DHCP server might have
detected another DHCP server handing out this IP address,
or a DHCP client might have declined the lease. Use
start-time-of-state to determine when the lease became
unavailable, and look in the log file around that time to
determine exactly why the lease became unavailable.
6 released
The client specified has released the lease, but the
server was configured to apply a 'release-grace-period'.
The lease won't be made available until the
grace-period expires.
7 other-available
Used only when failover is enabled. A lease in the
other-available state is available for allocation by the
other server in the failover pair, but not available for
allocation by this server.
8 pending-available
Used only when failover is enabled. A lease in the
pending-available state will be available as soon as
this server can synchronize its available state with
the other server.
|
| |
This string value is associated with the lease in order to allow
customer applications to relate the lease record to other
databases. It is not used directly by the DHCP server, but may be
read and written by extensions and expressions.
|
| |
Displays the vendor-class-id as offered in a DHCP request option 60.
|
| |
Displays the identifier of the DHCP VPN that contains this lease.
|
| | | | |
| |
link-policy - Edits a DHCP policy embedded in a link.
Note: dhcp-link-policy is a synonym for compatibility with earlier
versions.
|
| |
Synopsis |
| |
link-policy <name> delete
link-policy <name> set <attribute>=<value>
[<attribute>=<value> ...]
link-policy <name> get <attribute>
link-policy <name> disable <attribute>
link-policy <name> enable <attribute>
link-policy <name> show
link-policy <name> setV6Option <opt-name | id> <value>
link-policy <name> getV6Option <opt-name | id>
link-policy <name> unsetV6Option <opt-name | id>
link-policy <name> listV6Options
link-policy <name> setV6VendorOption <opt-name | id>
<opt-set-name> <value>
link-policy <name> getV6VendorOption <opt-name | id>
<opt-set-name>
link-policy<name> unsetV6VendorOption <opt-name | id>
<opt-set-name>
link-policy <name> listV6VendorOptions
|
| |
Description |
| |
The link-policy command lets you configure a DHCP policy embedded
in a DHCP link. An embedded policy is a collection of DHCP option
values and settings that are associated with (and named by) another
object -- in this case a link. You create a link-policy when
you first reference it, and you delete it when you delete the link.
To set individual option values use the setV6Option command; to
unset option values, the unsetV6Option command; and to view option
values, the getV6Option and listV6Options commands. When you set
an option value, the DHCP server replaces any existing value or
creates a new one as needed for the given option name.
See the help file for the policy command for more information.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
policy, client-policy, client-class-policy,
dhcp-address-block-policy, prefix-policy, scope-policy,
scope-template-policy
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
prefix-policy - Edits a DHCP policy embedded in a prefix
Note: dhcp-prefix-policy is a synonym for compatibility with earlier
versions of Network Registrar.
|
| |
Synopsis |
| |
prefix-policy <name> delete
prefix-policy <name> set <attribute>=<value>
[<attribute>=<value> ...]
prefix-policy <name> get <attribute>
prefix-policy <name> disable <feature>
prefix-policy <name> enable <feature>
prefix-policy <name> show
prefix-policy <name> setV6Option <opt-name | id> <value>
prefix-policy <name> getV6Option <opt-name | id>
prefix-policy <name> unsetV6Option <opt-name | id>
prefix-policy <name> listV6Options
prefix-policy <name> setV6VendorOption <opt-name | id>
<opt-set-name> <value>
prefix-policy <name> getV6VendorOption <opt-name | id>
<opt-set-name>
prefix-policy <name> unsetV6VendorOption <opt-name | id>
<opt-set-name>
prefix-policy <name> listV6VendorOptions
|
| |
Description |
| |
The prefix-policy command lets you configure a DHCP policy that
is embedded in a DHCP prefix. An embedded policy is a collection
of DHCP option values and settings associated with (and named by)
another object -- in this case a prefix. A prefix-policy is created
implicitly when you first reference it, and is deleted when the
prefix is deleted.
You can set individual option values with the setV6Option command,
unset option values with the unsetV6Option command, and view option
values with the getV6Option and listV6Options commands. When you set
an option value the DHCP server will replace any existing value or
create a new one as needed for the given option name.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
policy, client-policy, client-class-policy,
dhcp-address-block-policy, link-policy, scope-policy,
scope-template-policy
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
policy - Specifies DHCP policy information
|
| |
Synopsis |
| |
policy <name> create [<attribute>=<value>]
policy <name> create clone=<clone-name>
policy <name> delete
policy list
policy listnames
policy <name> set =<value> [<attribute>=<value> ...]
policy <name> get <attribute>
policy <name> unset <attribute>
policy <name> disable <attribute>
policy <name> enable <attribute>
policy <name> show
policy <name> setLeaseTime <time-val>
policy <name> getLeaseTime
policy <name> setOption <opt-name | id> <value>
policy <name> getOption <opt-name | id>
policy <name> unsetOption <opt-name | id>
policy <name> listOptions
policy <name> setV6Option <opt-name | id> <value>
policy <name> getV6Option <opt-name | id>
policy <name> unsetV6Option <opt-name | id>
policy <name> listV6Options
policy <name> setVendorOption <opt-name | id> <opt-set-name> <value>
policy <name> getVendorOption <opt-name | id> <opt-set-name>
policy <name> unsetVendorOption <opt-name | id> <opt-set-name>
policy <name> listVendorOptions
policy <name> setV6VendorOption <opt-name | id> <opt-set-name> <value>
policy <name> getV6VendorOption <opt-name | id> <opt-set-name>
policy <name> unsetV6VendorOption <opt-name | id> <opt-set-name>
policy <name> listV6VendorOptions
|
| |
Description |
| |
The policy command manages DHCP policy configurations. A policy
is a collection of DHCP option values to associate with a range
of addresses in a scope, or with a specific client or client-class
configuration. Network Registrar considers policy reply options in
a hierarchy of options. For details on these reply options, see
the User Guide for Cisco Network Registrar.
The policy command by itself is for a named policy. You can
also manage the embedded policies for dhcp-address-block,
client, client-class and scope objects through the
dhcp-address-block-policy, client-policy, client-class-policy,
and scope-policy commands, respectively.
For embedded policies, name identifies the object that contains
the embedded policy. For example, an attribute-setting command
for a scope policy would be "scope-policy scope-name set
<attribute>"--using the name of the scope for the name value.
The default policy is a special named policy that includes
default settings. You can manage the default policy just
like all the other named ones.
policy <name> setLeaseTime <time-val>
policy <name> getLeaseTime
Use the setLeaseTime command to set the values of lease
times and the getLeaseTime command to display the value
of a lease time.
policy <name> setV6Option <opt-name | id> <value>
policy <name> getV6Option <opt-name | id>
policy <name> unsetV6Option <opt-name | id>
policy <name> listV6Options
To manage the DHCPv6 options on the policy, use the
commands: setV6Option, getV6Option, unsetV6Option,
listV6Options.
policy <name> setVendorOption <opt-name | id> <opt-set-name> <value>
policy <name> getVendorOption <opt-name | id> <opt-set-name>
policy <name> unsetVendorOption <opt-name | id> <opt-set-name>
policy <name> listVendorOptions
The setVendorOption and getVendorOption commands are used to
set and get vendor-specific option data on the policy. These
commands require an option name and the name of a
vendor-specific option definition set.
The unsetVendorOption command removes the data for the
specific vendor option.
The listVendorOptions command displays all vendor-option
data that is set in the policy. The listing includes the name
of the option-definition set that was used to define the data.
You can manage the DHCPv6 vendor options on the policy
using the commands: setV6VendorOption,
getV6VendorOption, unsetV6VendorOption, listV6VendorOptions.
NOTE: The vendor option commands use a different syntax when
connected to releases prior to 6.2. See the documentation for
the specific release.
|
| |
Examples |
| |
nrcmd> policy default setOption dhcp-lease-time 608400
nrcmd> policy default listOptions
(51)dhcp-lease-time: 604800
nrcmd> policy default set grace-period=3d
|
| |
Status |
| |
|
| |
See Also |
| |
|
option-set, option
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
scope - Specifies the scope's properties
|
| |
Synopsis |
| |
scope list
scope listnames
scope <name> create <address> <mask> [template=<template-name>]
[<attribute>=<value>...]
scope <name> delete
scope <name> set <attribute>=<value> [<attribute>=<value> ...]
scope <name> get <attribute>
scope <name> unset <attribute>
scope <name> disable <attribute>
scope <name> enable <attribute>
scope <name> show
scope <name> listLeases
scope <name> addRange <start> <end>
scope <name> removeRange <start> <end>
scope <name> listRanges
scope <name> addReservation <ipaddr> (<macaddr>|<lookup-key>)
[-mac|-blob|-string]
scope <name> removeReservation (<ipaddr>|<macaddr>|<lookup-key>)
[-mac|-blob|-string]
scope <name> listReservations
scope <name> changeMask <mask>
scope <name> clearUnavailable
scope <name> applyTemplate <template-name>
|
| |
Description |
| |
The scope command lets you manipulate address ranges in the
DHCP server.
When creating a scope using a template, specify - for the
<name> to allow the scope template's scope-name to name
the scope.
scope <name> listLeases
The listLeases command lists the leases associated
with this scope.
scope <name> addRange <start> <end>
scope <name> removeRange <start> <end>
scope <name> listRanges
The addRange command adds a range of available addresses
to the scope. The <start> and <end> values can either be
full IP addresses or host numbers within the scope's
subnet. It is an error if either <start> or <end> is
an IP address outside the scope's subnet or is a host
number that exceeds the bits allocated to host numbers
by the scope's netmask.
The removeRange command removes a range of addresses from the
scope's control.
The listRanges command lists the current ranges of addresses
available for allocation.
scope <name> addReservation <ipaddr> (<macaddr>|<lookup-key>)
[-mac|-blob|-string]
scope <name> removeReservation (<ipaddr>|<macaddr>|<lookup-key>)
[-mac|-blob|-string]
scope <name> listReservations
The addReservation command adds a reservation for a
specific IP address to a specific MAC address or lookup
key.
The removeReservation command removes the reservation for
an IP address, MAC address, or lookup key.
The listReservations command lists the available
reservations.
scope <name> changeMask <mask>
The changeMask command changes the scope's netmask. It
also changes the primary-mask properties of any secondary
scopes. Warnings are issued if the netmask is "narrowed"
and any reservations or ranges fall outside the network
defined by the new mask and existing address.
scope <name> clearUnavailable
The clearUnavailable command moves all unavailable leases
in the specified scope to available.
scope applyTemplate
The applyTemplate command applies the specified
scope-template to the scope. All properties configured
on the scope-template are applied to the scope.
Note: The scope command manages a VPN through a virtual attribute:
vpn [] (AT_STRING, Optional, default: <none>)
Use this attribute to set or get the VPN ID by VPN name
instead of by ID.
|
| |
Examples |
| |
nrcmd> scope scope-example create 192.168.0.0 255.255.255.224
nrcmd> scope scope-example addRange 192.168.0.33 192.168.0.62
nrcmd> scope scope-example addReservation 192.168.0.40 00:d0:ba:d3:bd:3b
nrcmd> scope scope-example changeMask 255.255.255.192
|
| |
Status |
| |
|
| |
See Also |
| |
|
scope-template
|
| |
| |
|
| |
Attributes |
| |
| |
Enables you to force the allocation of new IP addresses
from this scope to be the first available IP address;
otherwise, the default of the 'least recently used' IP address is
used.
If this attribute is not set, or is unset, then the DHCP server
attribute priority-address-allocation controls whether
to allocate the first available IP address.
If priority-address-allocation is set, and allocate-first-available
for the scope is unset, then the scope allocates addresses as if
allocate-first-available was set.
If allocate-first-available is enabled or disabled for a scope, then
for that scope the setting of priority-address-allocation has no
meaning.
|
| |
Assigns an order to scopes for allocating IP addresses. Acceptable
scopes, with the highest allocation priority, grant IP addresses
until the addresses are exhausted.
You can mix scopes with an allocation-priority along with those
without a priority in the same network. In this case, scopes with
allocation priorities are examined for acceptability before those
scopes with no allocation-priority. Lower numeric values have
higher priorities, but an allocation-priority of 0 (the default) has
no priority.
If this attribute is not set, or is unset or 0, then the
DHCP priority-address-allocation attribute controls the priority
of the scope. If the DHCP priority-address-allocation attribute is
set, and allocation-priority for the scope is unset, then the
allocation-priority for the scope is the network number of the
scope.
If you explicitly set allocation-priority, then, for that scope,
the DHCP setting of priority-address-allocation has no meaning.
|
| |
Determines the percentage of available addresses that the main server
sends to the backup server. If you define this value using the
scope command, make sure you define it on the main server. If you
define it on a backup server, it is ignored.
Used with the scope command, the backup-pct attribute overrides
the defined values on the failover pair for backup-pct and
dynamic-bootp-backup-pct. The attribute value defined with the scope
command becomes the value used for this scope, whether or not this
scope supports dynamic-bootp.
If you set the value to zero (0), the backup server receives no
addresses. Since 0 is a significant value, once you set this value,
you must unset it for the scope to use the failover pair's values for
backup-pct or dynamic-bootp-backup-pct.
Note: If the failover pair is configured to use load balancing, the
backup-pct is ignored and 50% is used.
|
| |
Controls whether the server accepts BOOTP requests. If you want
clients to always receive the same addresses, you must reserve
IP addresses for all your BOOTP clients.
|
| |
Controls whether a scope extends leases to any clients. A deactivated
scope does not extend leases to any clients. It treats all addresses
in its ranges as if they were individually deactivated.
|
| |
Describes the scope.
|
| |
Controls whether the DHCP server accepts DHCP requests for this
scope. Disable DHCP if you want a scope to use BOOTP exclusively
or you want to deactivate the scope temporarily.
|
| |
Tells DHCP how many bytes in a lease IP address to use when forming
in-addr.arpa names. The server forms names in the in-addr zone by
prepending dns-host-bytes of IP address (in reverse order) to the
reverse zone name. If unset, the server synthesizes an appropriate
value based on the scope's subnet size.
|
| |
Controls whether the server will accept dynamic BOOTP
requests for this scope. Dynamic BOOTP requests are BOOTP requests
that do not match a reservation, but could be satisfied from the
available lease pool. To use this feature you must also enable
bootp.
|
| |
Displays the embedded policy for a scope.
|
| |
Sets the IP address allocation boundary for a backup server in a
failover relationship.
If the allocate-first-available attribute is set, the backup
server allocates IP addresses in descending order from this
boundary.
If the allocate-first available attribute is unset or set to 0,
the boundary used for allocating addresses is half the
distance between the first and last IP address configured in the
ranges for this scope. If no IP addresses are available
below this boundary, the first IP address available above this
boundary is used.
|
| |
Identifies which trap captures unexpected free address events
on this scope.
|
| |
Determines whether the server reacts to server DHCPDECLINE
messages that refer to one of the scope's IP addresses.
If enabled (true), the DHCP server ignores all declines that
refer to an IP address in this scope. If disabled, the DHCP server
sets to UNAVAILABLE every IP address referred to in this scope.
Default is false (disabled).
|
| |
Controls whether the server should attempt to ping an address
before offering a lease. If enabled (true), this attribute also
indicates a ping timeout.
|
| |
Sets the number of milliseconds the DHCP server waits for ping
responses. If you make this value too large, you slow down
the lease offering processes. If you make this value too small,
you reduce the effectiveness of pinging addresses before
offering them. Three hundred milliseconds (the default value) is
often the best choice.
|
| |
Identifies the name of the policy associated with this scope. Default
is the default policy. This means that the scope uses all the
properties set in the default policy (including the lease time),
unless you specifically reset a property.
|
| |
Determines the subnet address and mask of the primary scope.
Use this attribute when multiple logical IP subnets are present
on the same physical network.
|
| |
Controls whether to allow existing clients to reacquire their
leases, but not offer any leases to new clients. Note that a
renew-only scope does not change the client associated with any
of its leases (other than to allow a client, currently using what
the server believes is an available IP address, to continue using
the address).
|
| |
Associates a comma-separated list of selection tags with a
scope. The scope compares a client's selection criteria to this
list in order to determine whether the client can obtain a lease
from the scope.
|
| |
The network address of the IP subnet that this scope represents.
|
| |
Displays the identifier of the DHCP VPN that contains the addresses
in this scope. Define this value with the vpn vpn-name create id
command. Once set, you cannot change this value.
|
| | | | |
| |
scope-policy - Adds DHCP policy information to a scope
|
| |
Synopsis |
| |
scope-policy <scope-name> delete
scope-policy <scope-name> set <attribute>=<value> [<attribute>=<value> ...]
scope-policy <scope-name> get <attribute>
scope-policy <scope-name> unset <attribute>
scope-policy <scope-name> disable <attribute>
scope-policy <scope-name> enable <attribute>
scope-policy <scope-name> show
scope-policy <scope-name> setLeaseTime <time-val>
scope-policy <scope-name> getLeaseTime
scope-policy <scope-name> setOption <opt-name | id> <value>
scope-policy <scope-name> getOption <opt-name | id>
scope-policy <scope-name> unsetOption <opt-name | id>
scope-policy <scope-name> listOptions
scope-policy <scope-name>
setVendorOption <opt-name | id> <opt-set-name> <value>
scope-policy <scope-name>
getVendorOption <opt-name | id> <opt-set-name>
scope-policy <scope-name>
unsetVendorOption <opt-name | id> <opt-set-name>
scope-policy <scope-name> listVendorOptions
|
| |
Description |
| |
The scope-policy command lets you configure embedded DHCP policy
information for a DHCP scope. An embedded policy is a collection of
DHCP option values and settings associated with (and named by)
another object -- in this case a scope. A scope policy is created
implicitly when you first reference it, and is deleted when the
scope is deleted.
You can set individual option values with the setOption command,
unset option values with the unsetOption command, and view option
values with the getOption and listOptions commands. When you set an
option value the DHCP server replaces any existing value or
creates a new one as needed for the given option name.
You can use the setLeaseTime command to set the values of lease
times and the getLeaseTime command to display the value of a lease
time.
|
| |
Examples |
| |
nrcmd> scope-policy scope-example set backup-pct=30
nrcmd> scope-policy scope-example enable allocate-first-available
|
| |
Status |
| |
|
| |
See Also |
| |
|
policy, client-policy, client-class-policy
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
scope-template - Configures a scope template
|
| |
Synopsis |
| |
scope-template <name> create [<attribute>=<value> ...]
scope-template <name> delete
scope-template <name> set <attribute>=<value> [<attribute>=<value> ...]
scope-template <name> get <attribute>
scope-template <name> unset <attribute>
scope-template <name> disable <attribute>
scope-template <name> enable <attribute>
scope-template <name> show
scope-template <name> create clone=<clone-name>
scope-template <name> apply-to <all | <scope1>[,...]>
|
| |
Description |
| |
The scope-template command lets you configure a template to use
when creating scopes.
|
| |
Examples |
| |
nrcmd> scope-template scope-example createscope-template scope-example set backup-pct=30scope-template scope-example enable allocate-first-available
|
| |
Status |
| |
|
| |
See Also |
| |
|
scope
|
| |
| |
Attributes |
| |
| |
This boolean attribute forces all allocation of new IP addresses from
this scope to be made from the first available IP address, rather than
the default of the "least recently used" IP address.
If this attribute is not set (unset), then the decision on whether to
allocate the first available IP address in the scope will be
controlled by the DHCP server attribute priority-address-allocation.
If priority-address-allocation is set (and allocate-first-available
for the scope is not set (unset)), then the scope will allocate
addresses as if allocate-first-available was set. If
allocate-first-available has been explicitly configured (either
enabled or disabled) for a scope, then for that scope the setting of
priority-address-allocation has no meaning.
|
| |
You can use the allocation-priority to assign an ordering to scopes,
such that allocation of IP addresses will take place from acceptable
scopes with a higher priority until the IP addresses in all those
scopes are exhausted. An allocation-priority of 0 is treated as not
having an allocation-proiority. You can mix scopes with an
allocation-priority along with those without an allocation-priority
(or with an allocation-priority of 0, which is the same thing) in the
same network. In this case, the scopes with an allocation priority
will be examined for acceptability prior to those scopes with no
allocation-priority (or an allocation-priority of 0).
If this attribute is not set (unset), then the allocation-priority of
the scope will be controlled by the DHCP server attribute
priority-address-allocation. If priority-address-allocation is set
(and allocation-priority for the scope is not set (unset)), then the
allocation-priority for the scope will be the network number of the
scope. If allocation-priority has been explicitly configured for a
scope, then for that scope the setting of priority-address-allocation
has no meaning.
|
| |
The percentage of available addresses that the main server
should send to the backup server. If defined for a scope, it
must be defined for the scope in the main server. If it is
defined in a backup server, it is ignored (to enable copying
of configurations). If it is defined, the defined value will
override the failover pair's defined values for backup-pct
and dynamic-bootp-backup-pct, and the value defined here is
the value that will be used for this scope, whether or not
this scope supports dynamic-bootp. If it is set to zero (0),
no addresses will be sent to the backup server. Since zero
is a significant value, once set, this parameter must be
unset in order for this scope to utilize the failover pair's
values for backup-pct or dynamic-bootp-backup-pct.
Note: If the failover pair is configured to use load balancing,
the percentage is ignored and 50% is used.
|
| |
Controls whether the server will accept BOOTP requests
for this scope. If you want clients to always receive the
same addresses, you need to reserve IP addresses for all your
BOOTP clients.
|
| |
A deactivated scope will not extend leases to any clients. It treats
all of the addresses in its ranges as if they were individually
deactivated.
|
| |
Describes the scope template.
|
| |
Controls whether the server will accept DHCP requests
for this scope. Typically, this is only disabled when
bootp is enabled for that scope, to allow only a scope
to be used exclusively for BOOTP.
|
| |
This value tells DHCP how many of the bytes in a lease's IP address to
use when forming in-addr.arpa names. The server forms names in the
in-addr zone by prepending dns-host-bytes of IP address (in reverse
order) to the reverse zone name.
If this is unset, the server will synthesize an appropriate value
based on the scope's subnet size.
|
| |
Controls whether the server will accept dynamic BOOTP
requests for this scope. Dynamic BOOTP requests are BOOTP requests
that do not match a reservation, but could be satisfied from the
available lease pool. To use this feature you must also enable bootp.
|
| |
The embedded policy object for this scope.
|
| |
The free-address trap configuration to use for this individual scope.
|
| |
The length of time between the expiration of a lease and the time it
is made available for re-assignment.
|
| |
This attribute controls whether the DHCP server will process a
DHCPDECLINE request referencing an IP address in this scope. If
this attribute is enabled, then the DHCP server will ignore all
declines which reference an IP address in this scope. If this
attribute is not set, the DHCP server will set to UNAVAILABLE
every IP address which is referenced in a DHCPDECLINE message.
The default value is false, so that DHCPDECLINE messages are
processed normally, and the IP addresses referenced in these
DHCPDECLINE messages are set to UNAVAILABLE.
|
| |
The name of this scope template.
|
| |
If the server offers a lease to a client, but the offer is not
accepted, the server will wait the specified number of seconds before
making the lease 'available' again.
|
| |
An expression to define the list of embedded policy options
to be created for a scope object.
|
| |
Controls whether the server should attempt to ping
addresses before offering leases.
|
| |
The number of milliseconds the DHCP server should wait for ping
responses. If you make this value too large, you will slow down the
lease offering processes. If you make this value too small, you will
reduce the effectiveness of pinging addresses before offering them.
|
| |
The name of the policy associated with this scope.
|
| |
An expression to define the list of scope ranges to be created
for a scope object.
|
| |
Controls whether to allow existing clients to reacquire their leases,
but not offer any leases to new clients. Note that a 'renew-only'
scope will not change the client associated with any of its leases
(other than to allow a client currently using what the server believes
is an available IP address to continue using it).
|
| |
This is use to create the ip address from the subnet to put it on the
router interface because router interface does not take network id.
It takes ipaddress and mask
|
| |
Defines an AT_STRING expression to apply to the description
on the scope object created when using the template.
|
| |
An expression to define the name of the scope object created
when using the scope template.
|
| |
The list of selection tags to associate with a scope.
|
| |
If the server is replying to a BOOTP request, and is offering a lease
from a Scope which is configured to perform DNS updates, it will check
this property before beginning the DNS update. This feature allows
an administrator to prevent DNS updates for BOOTP clients, while
allowing updates for DHCP clients.
'Update-dns-for-bootp' can be controlled globally with the 'server'
command; that global command can be overridden by individual Scopes
as necessary.
|
| |
The id of the dhcp vpn that contains this scope. The
vpn-id of a scope must be initialized when the scope
is created, and cannot be edited once it is set.
|
| | | | |
| |
scope-template-policy - Edits a DHCP policy embedded in a scope-
template
|
| |
Synopsis |
| |
scope-template-policy <name> delete
scope-template-policy <name> set
<attribute>=<value>
[<attribute>=<value> ...]
scope-template-policy <name> get <attribute>
scope-template-policy <name> disable <attribute>
scope-template-policy <name> enable <attribute>
scope-template-policy <name> show
scope-template-policy <name> setLeaseTime <time-val>
scope-template-policy <name> getLeaseTime
scope-template-policy <name> setOption <opt-name | id> <value>
scope-template-policy <name> getOption <opt-name | id>
scope-template-policy <name> unsetOption <opt-name | id>
scope-template-policy <name> listOptions
scope-template-policy <name>
setVendorOption <opt-name | id> <opt-set-name> <value>
scope-template-policy <name>
getVendorOption <opt-name | id> <opt-set-name>
scope-template-policy <name>
unsetVendorOption <opt-name | id> <opt-set-name>
scope-template-policy <name> listVendorOptions
|
| |
Description |
| |
The scope-template-policy command lets you configure a DHCP
policy embedded in a DHCP scope template. An embedded policy is a
collection of DHCP option values and settings associated with (and
named by) another object -- in this case a scope template. A
scope-template-policy is created implicitly when you first
reference it, and is deleted when the scope-template is deleted.
You can set individual option values with the setOption command,
unset option values with the unsetOption command, and view option
values with the getOption and listOptions commands. When you set
an option value the DHCP server will replace any existing value or
create a new one as needed for the given option name.
|
| |
Examples |
| |
nrcmd> scope-template-policy exampleScope set default-prefix-
length=32
nrcmd> scope-template-policy exampleScope enable allow-rapid-
commit
|
| |
Status |
| |
|
| |
See Also |
| |
|
policy, client-policy, client-class-policy,
dhcp-address-block-policy, link-policy, prefix-policy,
scope-policy
|
| |
| |
Attributes |
| |
| |
Associates a lease in the AVAILABLE state with the client that
last held the lease. If the client requests a lease during the
affinity period, it is granted the same lease; that is, unless
renewals are prohibited, then it is explicitly not given the lease.
Because of the vast IPv6 address space and depending on the address
generation technique, it could be millions of years before an
address ever needs reassignment to a different client, and there
is no reason to hold on to this information for that long.
To prohibit renewals enable either the inhibit-all-renews attribute
or the inhibit-renews-at-reboot attribute.
|
| |
Determines if a client is allowed to update A records.
If the client sets the flags in the FQDN option to indicate that
it wants to do the A record update in the request, and if this
value is TRUE, the server allows the client to do the A record
update; otherwise, based on other server configurations, the server
does the A record update.
|
| |
Enables DHCP clients to perform DNS updates into two DNS zones.
To support these clients, you can configure the DHCP server to
allow the client to perform an update, but also to perform a DNS
update on the client's behalf.
|
| |
Gives the server control over the lease period. Although a client
can request a specific lease time, the server need not honor the
request if this attribute is set to false (the default).
Even if set to true, clients can request only lease times that are
shorter than those configured for the server.
|
| |
Determines whether DHCPv6 clients can request non-temporary
(IA_NA) addresses.
The default is to allow clients to request non-temporary addresses.
|
| |
Determines whether DHCPv6 clients can use a Solicit with the
Rapid Commit option to obtain configuration information with
fewer messages. To permit this, make sure that a single DHCP
server is servicing clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked:
- If any of the prefix policies has this attribute set to
FALSE, Rapid Commit is not allowed.
- If at least one has it set to TRUE, Rapid Commit is allowed.
- Otherwise, the remaining policies in the hierarchy are
checked.
The default is not to allow clients to use Rapid Commit.
|
| |
Determines whether DHCPv6 clients can request temporary (IA_TA)
addresses.
The default is to allow clients to request temporary addresses.
|
| |
For delegation, specifies the default length of the delegated prefix,
if a router (client) does not explicitly request it.
The default length must always be less than or equal to the prefix
length of the prefix range.
|
| |
Specifies the name of the update configuration that determines
which forward zones to include in updates.
|
| |
Designates an optional forward zone for DNS updates.
|
| |
Enables the DHCP server to set the server-id option on a DHCPOFFER
and a DHCPACK to the giaddr of the incoming packet, instead of the
IP address of the server (the default action).
This causes all unicast renews to be sent to the relay agent instead
of directly to the DHCP server, and so renews arrive at the DHCP
server with option-82 information appended to the packet.
Some relay agents may not support this capability and, in some
complex configurations, the giaddr might not actually be an address
to which the DHCP client can send A unicast packet. In these cases,
the DHCP client cannot renew a lease, and must always perform a
rebind operation (where the DHCP client broadcasts a request instead
of sending a unicast to what it believes is the DHCP server).
|
| |
Defines the length of time between the expiration of a lease
and the time it is made available for reassignment.
|
| |
Causes the server to reject all renewal requests, forcing the client
to obtain a different address any time it contacts the DHCP server.
|
| |
Permits clients to renew their leases, but the server forces
them to obtain new addresses each time they reboot.
|
| |
Specifies the maximum number of clients with the same limitation-id
that are allowed to have currently active and valid leases.
|
| |
Instructs the server to wait a specified amount of time when it
has offered a lease to a client, but the offer is not yet accepted.
At the end of the specified time interval, the server makes the
lease available again.
|
| |
Identifies the boot-file to use in the boot process of a client.
The server returns this file name in the 'file' field of its replies.
The packet-file-name cannot be longer than 128 characters.
|
| |
Identifies the host-name of the server to use in a client's boot
process. The server returns this file name in the 'sname' field
of its replies. The packet-server-name field cannot be longer
than 64 characters.
|
| |
Identifies the IP address of the next server in the client boot
process. For example, this might be the address of a TFTP server
used by BOOTP clients. The server returns this address in the
'siaddr' field of its replies.
|
| |
Indicates whether leases using this policy are permanently granted
to requesting clients. If leases are permanently granted, the server
ignores the configured dhcp-lease-time option value and uses the
maximum lease time.
|
| |
Assigns the default and maximum preferred lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative to
the time the server sent the packet, this attribute sets the
length of time that the address is preferred; that is, its use is
unrestricted. When the preferred lifetime expires, the address
becomes deprecated and its use is restricted.
|
| |
Controls DHCPv6 client reconfiguration support:
1 allow Allows clients to request reconfiguration
support and the server will honor the
request (default).
2 disallow Allows clients to request reconfiguration
support but the server will not honor
the clients' request.
3 require Requires clients to request reconfiguration
support and the server drops client
Solicit and Request messages that do not
include a Reconfigure-Accept option.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked
as follows:
- If any of the prefix policies has this attribute set to
disallow or require, that setting is used.
- Otherwise, if at least one has it set to allow, Reconfigure
is allowed.
- If no prefix policies have this attribute set, the remaining
policies in the hierarchy are checked.
|
| |
Controls whether the server should prefer unicasting or
relaying DHCPv6 Reconfigure messages.
If false (the default), the server prefers to unicast
Reconfigure messages if the client has one or more valid
statefully assigned addresses.
If true, the server prefers to send Reconfigure messages
via the relay agent unless no relay agent information is
available.
Note: When you use this attribute, consider that:
- In networks where the DCHPv6 server cannot communicate
directly with its client devices?for example, where
firewalls are in place?set this value to true.
- The DHCPv6 server does not use embedded and named
policies configured on a client when it evaluates
this attribute.
- The relay agent cannot be used if the Relay-Forw message
came from a link-local address.
|
| |
Specifies the name of the update configuration that determines
which reverse zones to include in a DNS update.
|
| |
Tells the server how long a lease is valid. For more frequent
communication with a client, you might have the server consider
leases as leased for a longer period than the client considers them.
This also provides more lease-time stability. This value is not used
unless it is longer than the lease time in the dhcp-lease-time option
found through the normal traversal of policies.
|
| |
Specifies a value that the DHCP server might use internally to
affect lease times.
If enabled, the DHCP server still offers clients lease times that
reflect the configured lease-time option from the appropriate
policy; but the server bases its decisions regarding expiration
on the 'server-lease-time' value.
|
| |
Permits the server to make a lease unavailable for the time specified
and then to return the lease to available state. If there is no value
configured in the system_default_policy, then the default is
86400 seconds (or 24 hours).
|
| |
Controls how the server database checks for reserved IP
addresses.
By default, the server uses the MAC address of the DHCP client as the
key for its database lookup. If this attribute is set to true
(enabled), then the server does the check for reserved
addresses using the DHCP client-id, which the client usually sends.
In cases where the DHCP client does not supply the client-id, the
server synthesizes it, and uses that value.
|
| |
Lists the options the server returns to all BOOTP clients.
|
| |
Lists the options the server returns to all DHCPv4 clients, whether
or not the client specifically asks for the option data.
|
| |
Lists the options that should be returned in any
replies to DHCPv6 clients.
This attribute has special handling during the policy hierarchy
processing when checking the Prefix policies (embedded or named)
for the Prefixes on a Link. The Prefixes for the Link are
processed in alphabetic (case blind) order. For each Prefix, the
embedded and then named policy are checked. Only Prefixes to which
the client has access (based on selection tags, etc.) are checked.
|
| |
Assigns the default and maximum valid lifetime for leases to
DHCPv6 client interfaces. Expressed in seconds and relative
to the time the server sent the packet, this attribute sets
the length of time that an address remains valid. When this
period of time expires, the address becomes invalid and
unusable. The valid lifetime must be greater than or equal
to the preferred lifetime.
|
| | | | |
| |
zone - configures a DNS zone
|
| |
Synopsis |
| |
zone <name> create primary file=<hostfile> [template=<template-name>]
zone <name> create primary <name server> <person>
[template=<template-name] [<attribute>=<value>...]
zone <name> create secondary <address> [<attribute>=<value>...]
zone <name> delete
zone list
zone listnames
zone <name> set =<value> [<attribute>=<value> ...]
zone <name> get <attribute>
zone <name> unset <attribute>
zone <name> disable <attribute>
zone <name> enable <attribute>
zone <name> show
zone <name> addHost <host name> <address> [<alias> ...]
zone <name> removeHost <host name>
zone <name> listHosts
zone <name> addRR [-staged|-sync] <name> [<ttl>] [<class>] <type> <data>
zone <name> addDNSRR <name> [<ttl>] <type> <data>
zone <name> removeRR <name> [<type> [<data>]]
zone <name> removeDNSRR <name> [<type>] [<data>]
zone <name> listRR [all|ccm|dns]
zone <name> findRR [-namePrefix <namePrefix>]
[-rrTypes <rrTypeList>] [-protected | -unprotected]
zone <name> < protect-name|unprotect-name > <name>
zone <name> forceXfer secondary
zone <name> syncToDns
zone <secondary-zone-name> promote-to-primary
zone <name> chkpt
zone <name> dumpchkpt
zone <name> scavenge
zone <name> getScavengeStartTime
zone <name> applyTemplate <template-name>
|
| |
Description |
| |
The zone command lets you create and edit DNS zones.
The name of the zone may be an IPv4 subnet (<address>/<length>),
IPv6 prefix (<address>/<length>), prefix name (the prefix
address is used), or DNS name.
zone <name> addHost <host name> <address> [<alias> ...]
zone <name> removeHost <host name>
zone <name> listHosts
The addHost command adds a host with a given name, address
and optional aliases to the zone.
The removeHost command removes a host from the zone.
The listHosts command lists the hosts in the zone.
zone <name> addRR [-staged|-sync] <name> [<ttl>] [<class>] <type> <data>
zone <name> addDNSRR <name> [<ttl>] <type> <data>
zone <name> removeRR <name> [<type> [<data>]]
zone <name> removeDNSRR <name> [<type>] [<data>]
zone <name> listRR [all|ccm|dns]
zone <name> findRR [-namePrefix <namePrefix>]
[-rrTypes <rrTypeList>] [-protected | -unprotected]
The addRR command adds a protected resource record to a zone.
The arguments to addRR are in the same format as BIND files.
An attempt to add a protected record to an unprotected name
will fail.
The removeRR command removes all specified protected resource
records. Resource records may be specified by name, by name
and type, or by name, type, and data (the data is specified in
BIND-style format.)
The addDNSRR command adds an unprotected resource record. The
name, type, and data must be specified. An attempt to add an
unprotected record to a protected name will fail.
The removeDNSRR command removes all specified unprotected
resource records. Resource records may be specified by name,
by name+type, or name+type+data. The changes take effect
immediately; no serverreload is necessary. If the DNS server
is not running, the command will fail.
The listRR command lists the resource records in the zone.
CCM records are the records being managed by the CCM server,
and stored in its database. DNS records are the records that
the running DNS server is serving to clients.
The findRR command displays the resource records matching a
name prefix, a list of resource record types, and whether
protected or not (or either).
The cleanRR command removes obsolete resource records. It is
particularly useful for removing records remaining from zone
deletion followed by recreation of the same zone. This command
is valid only for pre-6.2 clusters.
zone <name> protect-name|unprotect-name> <name>
The protect-name/unprotect-name command sets the protection
status of the resource records for the name. Protected names
cannot be updated using DNS update requests.
zone <name> forceXfer secondary
The forceXfer command forces a full zone transfer of a
secondary zone, regardless of the zone serial number, to
synchronize DNS data store. If a normal zone transfer is
already in progress, the forceXfer command is scheduled
immediately after the normal zone transfer finishes. An
option for primary zones has not been implemented yet.
zone <name> chkpt
zone <name> dumpchkpt
The chkpt command forces the specified zone name to be the next
one checkpointed. If none are currently being checkpointed
it is done immediately. Otherwise, it is done upon completion
of the current checkpoint.
The dumpchkpt command interprets an existing checkpoint file
and writes its contents to a file in human-readable format.
zone <name> scavenge
zone <name> getScavengeStartTime
The scavenge command schedules zone scavenging immediately
for the given zone regardless of the scavenging interval.
The getScavengeStartTime command returns the date and time
of the next check for stale records, when records might
be scavenged.
zone <secondary-zone-name> promote-to-primary
The promote-to-primary command can be used to promote a
secondary zone to a primary zone (for example, if the primary
DNS server has had a hardware failure).
zone <name> applyTemplate <template-name>
The applyTemplate command applies the specified zone template
to the zone. All properties configured on the zone template
are applied to the zone.
|
| |
Examples |
| |
nrcmd> zone example.com. create primary file=host.local
nrcmd> zone example.com. create primary ns ns-server
|
| |
Status |
| |
|
| |
See Also |
| |
|
zone-template
|
| |
| |
Attributes |
| |
| |
Sets the number of seconds that elapse between saves of zone data.
When the interval expires, Network Registrar takes a snapshot of
the zone data and records it in the zone checkpoint database.
|
| |
Specifies the minimum amount of time required (in seconds)
between the time the first checkpoint occurs and the second
checkpoint starts. This attribute applies only to zones with
dynamic resource records.
|
| |
Controls the default TTL value used for resource records in this
zone that do not specify a TTL.
|
| |
Identifies the zone distribution map associated with the
specified zone. The zone distribution map describes which
primary and secondary DNS servers should provide DNS service
for this zone.
|
| |
Enables RFC 2136 dynamic updates to the zone. The most typical source
of these updates is a DHCP server.
|
| |
Sets the number of seconds that a secondary server can continue
providing zone data without confirming that the data remains current.
The expire interval must be greater than the refresh interval.
|
| |
Sets the minimum TTL value displayed in resource records for this
zone. Records with TTL values lower than the minttl are published
with this value.
|
| |
Lists the nameservers for this zone.
|
| |
Enables notification of other authoritative servers when this
zone changes. When set, to either true or false, it overrides the
global "notify" value for this zone.
|
| |
Lists additional servers to notify of changes to this zone. All
servers listed in NS records for the zone, with the exception of
the server described by the "ns" property of the zone (the mname
field of the SOA record), receive notifications.
Servers listed in "notify-list" are also notified.
|
| |
Displays the fully-qualified domain name of the primary name server
for this zone. This host is the original, or primary source, of data
for this zone.
|
| |
Displays the ttl value applied to the NS resource records of
the zone.
|
| |
Displays the fully-qualified name of the zone's root. The zone name.
|
| |
Names the owner of this zone. Use the owner field to group
similarly owned zones and to limit administrative access.
|
| |
Displays a domain name specifying the mailbox of the person
responsible for this zone. The first label is a user or mail
alias, the rest of the labels are a mail destination. A mailbox
of hostmaster@test.com would be represented as hostmaster.test.com.
|
| |
Sets the number of seconds that a secondary server waits before
polling for zone changes and refreshing its zone data.
|
| |
Associates a region with the specified object. Use
the region field to group similarly located zones and
to limit administrative access.
|
| |
Specifies the zone access control list (ACL) used to restrict
the queries that the DNS server for this zone accepts. This list
can contain host IPs, network addresses, TSIG keys, and (global)
ACLs. Only queries from clients defined in the ACL are accepted.
If unset, the zone inherits the value of the server's
restrict-query-acl attribute.
|
| |
Limits sending zone transfers to a specific set of hosts. If
you restrict zone transfers, use the restrict-xfer-acl attribute
to specify the access control list that defines which servers
can perform zone transfers.
|
| |
Identifies the access control list designating who can receive
zone transfers from this zone.
|
| |
Sets the number of seconds that a secondary server waits before
it retries polling for changes to zone data or it retries a zone
transfer that has encountered errors. The retry interval must be
less than (expire - refresh).
|
| |
Enables dynamic resource-record scavenging for the zone. This
attribute removes stale records when clients are
configured to perform DNS updates but do not delete their
entries when they're no longer valid. If the DHCP server is used
to perform updates, it will also delete records when client
leases expire. Scavenging should not be enabled on these zones.
|
| |
Ensures that the server does not reset the scavenging time
whenever a server restarts. With this attribute set,
Network Registrar ignores the time between when a server went
down and the time it restarts. This interval is normally short.
The value can range from two hours to one day.
With any time longer than the set time, Network Registrar
recalculates the scavenging period to allow for record updates
that cannot take place while the server is stopped. You can also
set this attribute on a zone, and the value set on the zone
overrides the server setting. Default is 2h.
|
| |
Sets the period of time that must elapse before a DNS server
can remove an out-of-date address (A) record. An A record becomes
out-of-date once it ages past its initial creation date plus its
scvg-refresh-interval and scvg-no-refresh-interval. Default is 1w.
|
| |
Sets the maximum number of records to remove from a zone during
its scavenging interval.
|
| |
Sets the maximum number of records to search for out-of-date
A records. These records are candidates for scavenging.
|
| |
With scavenging enabled, sets the interval during which DNS
updates cannot increment an A record timestamp. After both
the no-refresh and refresh intervals expire, the record becomes a
candidate for scavenging. The value can range from one hour to
365 days. You can also set this attribute on a zone, and the
value set on the zone overrides the server setting. Default is 1w.
|
| |
Sets the number of seconds the server waits after scavenging
one set of records before going to the next set.
|
| |
With scavenging enabled, sets the interval during which DNS
updates can increment the A record timestamp. After both the
no-refresh and refresh intervals expire, the record is a
candidate for scavenging. The value can range from one hour
to 365 days. You can also set this attribute on a zone, and
the value set on the zone overrides the server setting.
Default is 1w.
|
| |
Displays an administratively specified serial number. The serial
number value must always increase; therefore, this serial number is
only applied to the zone if it is greater than the actual (dynamic)
serial number.
|
| |
Displays the time-to-live (ttl) value applied to the SOA
resource record of the zone.
|
| |
Specifies whether subzones use forwarders or not. When no-forward is
set, any query for the zone is not sent to the forwarder. This
is an extended resolution exception.
|
| |
Specifies the access control list for DNS updates to the zone,
given as an address match element list. The access control list
is not applied to administrative edits managed through the CCM server.
|
| |
Lists the DNS update policies used to authorize or deny DNS
updates. This attribute is ignored if the update-acl attribute
is also set.
|
| | | | |
| |
zone-template - Configures a zone template
|
| |
Synopsis |
| |
zone-template <name> create [<attribute>=<value> ...]
zone-template <name> delete
zone-template <name> set <attribute>=<value> [<attribute>=<value> ...]
zone-template <name> get <attribute>
zone-template <name> unset <attribute>
zone-template <name> disable <attribute>
zone-template <name> enable <attribute>
zone-template <name> show
zone-template <name> create clone=<clone-name>
zone-template <name> apply-to [all | <zone1>[,...]
|
| |
Description |
| |
The zone-template command lets you configure templates to use
when creating zones.
|
| |
Examples |
| |
|
| |
Status |
| |
|
| |
See Also |
| |
|
zone
|
| |
| |
Attributes |
| |
| |
Sets the number of seconds that elapse between saves of zone data.
When the interval expires, Network Registrar takes a snapshot of
the zone data and records it in the zone checkpoint database.
|
| |
Controls the minimum time required (in seconds) between the
time the first zone checkpoint occurs and the second zone
checkpoint starts. This attribute applies only to zones with
dynamic rrs.
|
| |
Controls the default TTL value used for resource records in a
zone that do not specify a TTL.
|
| |
Associates a zone distribution map with a zone. The map
describes the primary and secondary DNS servers that provide
DNS service for this zone.
|
| |
Enables RFC 2136 dynamic updates to the zone. The most typical source
of these updates is a DHCP server.
|
| |
Sets the number of seconds that a secondary server can continue
providing zone data without confirming that the data remains
current. The expire interval must be greater than the refresh
interval.
|
| |
Sets the minimum TTL value displayed in resource records for a
zone. Records with TTL values lower than the minttl are published
with this value.
|
| |
Names this zone template.
|
| |
Lists the nameservers for a zone.
|
| |
Enables notification of other authoritative servers when this
zone changes. When set, to either true or false, it overrides
the global "notify" value for a zone.
|
| |
Lists additional servers to notify of changes to a zone. All
servers listed in NS records for the zone, with the exception of
the server described by the "ns" property of the zone (the mname
field of the SOA record), receive notifications.
Servers listed in "notify-list" are also notified.
|
| |
Specifies the fully-qualified domain name (FQDN) of the
primary name server for the zone. This host is the original
or primary source of data for this zone.
Note: Network Registrar treats the value set here as a string
rather than a dnsname to enable encoding relative or absolute
names in this attribute.
|
| |
Controls the ttl value applied to the zone's NS resource records.
|
| |
Identifies the owner of this zone. Use the owner field to group
similarly owned zones and to limit administrative access.
|
| |
Specifies the mailbox for the hostmaster (person) in domain name
form. The first label is a user or mail alias, the rest of the
labels are a mail destination. A mailbox of hostmaster@test.com
would be represented as:
hostmaster.test.com.
Note: Network Registrar treats the value set here as a string
rather than a dnsname to enable encoding relative or absolute
names in this attribute.
|
| |
Sets the interval at which a secondary server contacts its
master server for changes to zone data. The interval is
defined in the server?s SOA record and is also known as the
secondary refresh time.
|
| |
The region associated with this object. This region field is used
to group similarly located zones and can be
used to limit administrative access.
|
| |
Zone Address Control List (ACL) used to restrict queries to be
honored by the DNS server on this zone. This list can contain host
IPs, network addresses, TSIG keys and/or (global) ACLs. Those
clients defined in this ACL list shall be honored; others shall be
refused. If unset, the zone inherits the value of the server's
restrict-query-acl attribute.
|
| |
Restricts sending zone transfers to a specific set of hosts. If you
restrict zone transfers, you need to use the restrict-xfer-acl
property to specify the access control list of who is allowed to
perform zone transfers.
|
| |
The access control list that designates who is allowed to receive
zone transfers from this zone.
|
| |
Sets the amount of time that a secondary server waits before
it retries polling for changes to zone data or it retries a zone
transfer that has encountered errors. The retry interval must be
less than the expire and refresh intervals. A good value is
between one-third and one-tenth of the refresh time.
|
| |
Enables dynamic resource-record scavenging for the zone. Use
this feature to remove stale records that arise when clients are
configured to perform DNS updates, but do not delete their
entries when they are no longer valid. If the DHCP server
performs updates, it also delete records when client leases
expire. Scavenging should not be enabled on these zones.
|
| |
Ensures that the server does not reset the scavenging time
whenever a server restarts. Within this attribute set,
Network Registrar ignores the time between when a server went
down and the time it restarts. This interval is normally short.
The value can range from two hours to one day.
With any time longer than the set time, Network Registrar
recalculates the scavenging period to allow for record updates
that cannot take place while the server is stopped. You can also
set this attribute on a zone, and the value set on the zone
overrides the server setting.
|
| |
Sets the seconds that DNS waits before removing (scavenging)
out-of-date resource records.
|
| |
Controls the maximum number of records to search at one time for
candidates to be scavenged.
|
| |
Sets the maximum number of records to be scavenged from the zone
during a scavenging interval.
|
| |
Sets the number of seconds during which DNS updates cannot increment
the zone timestamp.
|
| |
Controls the interval (in seconds) that scavenging will wait
after scavenging a set of records, before going onto the next
set.
|
| |
Sets the number of seconds during which DNS updates can increment
the zone timestamp. After both the no-refresh and refresh intervals
expire, the record is a candidate for scavenging. The value
can range from one hour to 365 days. The zone setting overrides
the server setting of 604800s (1w).
|
| |
Sets the starting serial number of the zone. A DNS server uses
a serial number to indicate database changes. Increments to this
number trigger zone transfers to a secondary server.
|
| |
Controls the ttl value applied to a zone's SOA resource record.
|
| |
Specifies whether subzones use forwarders or not. When no-forward is
set, any query for the zone will not be sent to the forwarder. This
is an extended resolution exception.
|
| |
Specifies the access control list for DNS updates to a zone,
defined as an address match element list. The access control
list is not applied to dynamic updates coming from the UIs. Updates
from them UIs are always allowed as long as the zone attribute
dynamic is enabled. The access control list is not applied
to administrative edits managed through the CCM server.
|
| |
An ordered list of DNS update policies that can be used to authorize
or deny DNS updates. This attribute will be ignored if update-acl
is also set.
|