client-class-policy (nrcmd)			client-class-policy (nrcmd)

NAME
    client-class-policy - Adds DHCP policy information to a client-class

SYNOPSIS
    client-class-policy <client-class-name> delete
    client-class-policy <client-class-name> 
        set <attribute>=<value> [<attribute>=<value> ...]

    client-class-policy <client-class-name> get <attribute>
    
    client-class-policy <client-class-name> disable <attribute>
    client-class-policy <client-class-name> enable <attribute>
    client-class-policy <client-class-name> show
    
    client-class-policy <client-class-name> setLeaseTime <time-val>
    client-class-policy <client-class-name> getLeaseTime
    
    client-class-policy <client-class-name> setOption <opt-name | id> <value>
    client-class-policy <client-class-name> getOption <opt-name | id>
    client-class-policy <client-class-name> unsetOption <opt-name | id> 
    client-class-policy <client-class-name> listOptions

    client-class-policy <client-class-name> setV6Option <opt-name | id> <value>
    client-class-policy <client-class-name> getV6Option <opt-name | id>
    client-class-policy <client-class-name> unsetV6Option <opt-name | id> 
    client-class-policy <client-class-name> listV6Options

    client-class-policy <client-class-name> 
        setVendorOption <opt-name | id> <opt-set-name> <value>

    client-class-policy <client-class-name> 
        getVendorOption <opt-name | id> <opt-set-name>

    client-class-policy <client-class-name> 
        unsetVendorOption <opt-name | id> <opt-set-name>

    client-class-policy <client-class-name> listVendorOptions

    client-class-policy <client-class-name> 
        setV6VendorOption <opt-name | id> <opt-set-name> <value>

    client-class-policy <client-class-name> 
        getV6VendorOption <opt-name | id> <opt-set-name>

    client-class-policy <client-class-name> 
        unsetV6VendorOption <opt-name | id> <opt-set-name>

    client-class-policy <client-class-name> listV6VendorOptions

DESCRIPTION
    The client-class-policy command configures embedded policies for 
    client-classes. Each client-class can contain option data in its 
    embedded policy and can refer to a named policy with more option
    data; for example, a router IP address.

    An embedded policy is a collection of DHCP option values and settings
    associated with (and named by) a client-class. Network Registrar 
    implicitly creates and deletes an embedded client-class policy when
    you create and delete the corresponding client-class. You manipulate
    the client-class policy using the name of the client-class to which 
    the embedded policy is attached.
    
    client-class-policy <client-class-name> setOption <opt-name | id> <value>
       Sets individual option values. When you set an
       option value the DHCP server will replace any existing value or
       create a new one as needed for the given option name.

    client-class-policy <client-class-name> getOption <opt-name | id>
       Displays option values.

    client-class-policy <client-class-name> unsetOption <opt-name | id> 
       Unsets option values.

    client-class-policy <client-class-name> setLeaseTime <time-val>
        Sets the lease time.
    
    client-class-policy <client-class-name> getLeaseTime    
        Displays the lease time for the specified client-class.
   
    See the attribute descriptions for the policy command for a complete list of
    attributesfor client-class-policy. Except where noted in that list, 
    policy command attributes also apply to client-class policies.
EXAMPLES

STATUS

SEE ALSO
    policy, scope-policy, client-policy

PROPERTIES
  Attributes:

    affinity-period[46] (AT_TIME, Optional, default: <none>)
        Associates a lease in the AVAILABLE state with the client that
        last held the lease. If the client requests a lease during the
        affinity period, it is granted the same lease; that is, unless
        renewals are prohibited, then it is explicitly not given the lease.
        Because of the vast IPv6 address space and depending on the address
        generation technique, it could be millions of years before an
        address ever needs reassignment to a different client, and there
        is no reason to hold on to this information for that long.
        To prohibit renewals enable either the inhibit-all-renews attribute
        or the inhibit-renews-at-reboot attribute.

    allow-client-a-record-update[24] (AT_BOOL, Optional, default: disabled)
        Determines if a client is allowed to update A records.
        If the client sets the flags in the FQDN option to indicate that
        it wants to do the A record update in the request, and if this
        value is TRUE, the server allows the client to do the A record
        update; otherwise, based on other server configurations, the server
        does the A record update.

    allow-dual-zone-dns-update[28] (AT_BOOL, Optional, default: disabled)
        Enables DHCP clients to perform DNS updates into two DNS zones.
        To support these clients, you can configure the DHCP server to
        allow the client to perform an update, but also to perform a DNS
        update on the client's behalf.

    allow-lease-time-override[7] (AT_BOOL, Optional, default: disabled)
        Gives the server control over the lease period.  Although a client
        can request a specific lease time, the server need not honor the
        request if this attribute is set to false (the default).
        Even if set to true, clients can request only lease times that are
        shorter than those configured for the server.

    allow-non-temporary-addresses[38] (AT_BOOL, Optional, default: true)
        Determines whether DHCPv6 clients can request non-temporary
        (IA_NA) addresses.
        The default is to allow clients to request non-temporary addresses.

    allow-rapid-commit[47] (AT_BOOL, Optional, default: false)
        Determines whether DHCPv6 clients can use a Solicit with the
        Rapid Commit option to obtain configuration information with
        fewer messages. To permit this, make sure that a single DHCP
        server is servicing clients.
        This attribute has special handling during the policy hierarchy
        processing when checking the Prefix policies (embedded or named)
        for the Prefixes on a Link. The Prefixes for the Link are
        processed in alphabetic (case blind) order. For each Prefix, the
        embedded and then named policy are checked. Only Prefixes to which
        the client has access (based on selection tags, etc.) are checked:
          - If any of the prefix policies has this attribute set to
            FALSE, Rapid Commit is not allowed.
          - If at least one has it set to TRUE, Rapid Commit is allowed.
          - Otherwise, the remaining policies in the hierarchy are
            checked.
        The default is not to allow clients to use Rapid Commit.

    allow-temporary-addresses[39] (AT_BOOL, Optional, default: true)
        Determines whether DHCPv6 clients can request temporary (IA_TA)
        addresses.
        The default is to allow clients to request temporary addresses.

    default-prefix-length[49] (AT_RANGEINT(0-128), Optional, default: 64)
        For delegation, specifies the default length of the delegated prefix,
        if a router (client) does not explicitly request it.
        The default length must always be less than or equal to the prefix
        length of the prefix range.

    forward-dnsupdate[53] (AT_NAMEREF(DnsUpdateConfig), Optional, default: <none>)
        Specifies the name of the update configuration that determines
        which forward zones to include in updates.

    forward-zone-name[54] (AT_DNSNAME, Optional, default: <none>)
        Designates an optional forward zone for DNS updates.

    giaddr-as-server-id[34] (AT_BOOL, Optional, default: false)
        Enables the DHCP server to set the server-id option on a DHCPOFFER
        and a DHCPACK to the giaddr of the incoming packet, instead of the
        IP address of the server (the default action).
        This causes all unicast renews to be sent to the relay agent instead
        of directly to the DHCP server, and so renews arrive at the DHCP
        server with option-82 information appended to the packet.
        Some relay agents may not support this capability and, in some
        complex configurations, the giaddr might not actually be an address
        to which the DHCP client can send A unicast packet. In these cases,
        the DHCP client cannot renew a lease, and must always perform a
        rebind operation (where the DHCP client broadcasts a request instead
        of sending a unicast to what it believes is the DHCP server).

    grace-period[3] (AT_TIME, Optional, default: 5m)
        Defines the length of time between the expiration of a lease
        and the time it is made available for reassignment.

    inhibit-all-renews[31] (AT_BOOL, Optional, default: false)
        Causes the server to reject all renewal requests, forcing the client
        to obtain a different address any time it contacts the DHCP server.

    inhibit-renews-at-reboot[32] (AT_BOOL, Optional, default: false)
        Permits clients to renew their leases, but the server forces
        them to obtain new addresses each time they reboot.

    limitation-count[30] (AT_INT, Optional, default: <none>)
        Specifies the maximum number of clients with the same limitation-id
        that are allowed to have currently active and valid leases.

    offer-timeout[2] (AT_TIME, Optional, default: 2m)
        Instructs the server to wait a specified amount of time when it
        has offered a lease to a client, but the offer is not yet accepted.
        At the end of the specified time interval, the server makes the
        lease available again.

    packet-file-name[14] (AT_STRING, Optional, default: <none>)
        Identifies the boot-file to use in the boot process of a client.
        The server returns this file name in the 'file' field of its replies.
        The packet-file-name cannot be longer than 128 characters.

    packet-server-name[15] (AT_STRING, Optional, default: <none>)
        Identifies the host-name of the server to use in a client's boot
        process. The server returns this file name in the 'sname' field
        of its replies. The packet-server-name field cannot be longer
        than 64 characters.

    packet-siaddr[13] (AT_IPADDR, Optional, default: <none>)
        Identifies the IP address of the next server in the client boot
        process. For example, this might be the address of a TFTP server
        used by BOOTP clients. The server returns this address in the
        'siaddr' field of its replies.

    permanent-leases[6] (AT_BOOL, Optional, default: disabled)
        Indicates whether leases using this policy are permanently granted
        to requesting clients. If leases are permanently granted, the server
        ignores the configured dhcp-lease-time option value and uses the
        maximum lease time.

    preferred-lifetime[41] (AT_TIME, Optional, default: 1w)
        Assigns the default and maximum preferred lifetime for leases to
        DHCPv6 client interfaces. Expressed in seconds and relative to
        the time the server sent the packet, this attribute sets the
        length of time that the address is preferred; that is, its use is
        unrestricted. When the preferred lifetime expires, the address
        becomes deprecated and its use is restricted.

    reconfigure[60] (AT_ENUMINT(), Optional, default: allow)
        Controls DHCPv6 client reconfiguration support:
           1  allow        Allows clients to request reconfiguration
                           support and the server will honor the
                           request (default).
           2  disallow     Allows clients to request reconfiguration
                           support but the server will not honor
                           the clients' request.
           3  require      Requires clients to request reconfiguration
                           support and the server drops client
                           Solicit and Request messages that do not
                           include a Reconfigure-Accept option.
        This attribute has special handling during the policy hierarchy
        processing when checking the Prefix policies (embedded or named)
        for the Prefixes on a Link. The Prefixes for the Link are
        processed in alphabetic (case blind) order. For each Prefix, the
        embedded and then named policy are checked. Only Prefixes to which
        the client has access (based on selection tags, etc.) are checked
        as follows:
           - If any of the prefix policies has this attribute set to
           disallow or require, that setting is used.
           - Otherwise, if at least one has it set to allow, Reconfigure
           is allowed.
           - If no prefix policies have this attribute set, the remaining
           policies in the hierarchy are checked.

    reconfigure-via-relay[59] (AT_BOOL, Optional, default: false)
        Controls whether the server should prefer unicasting or
        relaying DHCPv6 Reconfigure messages.
        If false (the default), the server prefers to unicast
        Reconfigure messages if the client has one or more valid
        statefully assigned addresses.
        If true, the server prefers to send Reconfigure messages
        via the relay agent unless no relay agent information is
        available.
        Note: When you use this attribute, consider that:
            -  In networks where the DCHPv6 server cannot communicate
               directly with its client devicesfor example, where
               firewalls are in placeset this value to true.
            -  The DHCPv6 server does not use embedded and named
               policies configured on a client when it evaluates
               this attribute.
            -  The relay agent cannot be used if the Relay-Forw message
               came from a link-local address.

    reverse-dnsupdate[55] (AT_NAMEREF(DnsUpdateConfig), Optional, default: <none>)
        Specifies the name of the update configuration that determines
        which reverse zones to include in a DNS update.

    server-lease-time[4] (AT_TIME, Optional, default: <none>)
        Tells the server how long a lease is valid.  For more frequent
        communication with a client, you might have the server consider
        leases as leased for a longer period than the client considers them.
        This also provides more lease-time stability. This value is not used
        unless it is longer than the lease time in the dhcp-lease-time option
        found through the normal traversal of policies.

    split-lease-times[5] (AT_BOOL, Optional, default: disabled)
        Specifies a value that the DHCP server might use internally to
        affect lease times.
        If enabled, the DHCP server still offers clients lease times that
        reflect the configured lease-time option from the appropriate
        policy; but the server bases its decisions regarding expiration
        on the 'server-lease-time' value.

    unavailable-timeout[33] (AT_TIME, Optional, default: 24h)
        Permits the server to make a lease unavailable for the time specified
        and then to return the lease to available state. If there is no value
        configured in the system_default_policy, then the default is
        86400 seconds (or 24 hours).

    use-client-id-for-reservations[56] (AT_BOOL, Optional, default: off)
        Controls how the server database checks for reserved IP
        addresses.
        By default, the server uses the MAC address of the DHCP client as the
        key for its database lookup.  If this attribute is set to true
        (enabled), then the server does the check for reserved
        addresses using the DHCP client-id, which the client usually sends.
        In cases where the DHCP client does not supply the client-id, the
        server synthesizes it, and uses that value.

    v4-bootp-reply-options[58] (AT_NLIST(AT_OPTIONID4), Optional, default: <none>)
        Lists the options the server returns to all BOOTP clients.

    v4-reply-options[57] (AT_NLIST(AT_OPTIONID4), Optional, default: <none>)
        Lists the options the server returns to all DHCPv4 clients, whether
        or not the client specifically asks for the option data.

    v6-reply-options[48] (AT_NLIST(AT_OPTIONID6), Optional, default: <none>)
        Lists the options that should be returned in any
        replies to DHCPv6 clients.
        This attribute has special handling during the policy hierarchy
        processing when checking the Prefix policies (embedded or named)
        for the Prefixes on a Link. The Prefixes for the Link are
        processed in alphabetic (case blind) order. For each Prefix, the
        embedded and then named policy are checked. Only Prefixes to which
        the client has access (based on selection tags, etc.) are checked.

    valid-lifetime[43] (AT_TIME, Optional, default: 2w)
        Assigns the default and maximum valid lifetime for leases to
        DHCPv6 client interfaces. Expressed in seconds and relative
        to the time the server sent the packet, this attribute sets
        the length of time that an address remains valid.  When this
        period of time expires, the address becomes invalid and
        unusable. The valid lifetime must be greater than or equal
        to the preferred lifetime.

