client-class (nrcmd)					client-class (nrcmd)


NAME
    client-class - Creates client-classes

SYNOPSIS
    client-class <name> create [<attribute>=<value>] 
    client-class <name> delete 
    client-class list
    client-class listnames
    client-class <name> show 
    client-class <name> set <attribute>=<value> [<attribute>=<value> ...]
    client-class <name> get <attribute>
    client-class <name> unset <attribute>

DESCRIPTION
    The client-class command applies a set of attributes to a group or
    class of DHCP client configurations. Unlike most client configurations, 
    the DHCP server reads the client-class configurations at server startup 
    time. Therefore, you must reload the server for changes to take effect.

    You must enable client-class processing for the server for 
    Network Registrar to recognize client-classes, as the examples show.

EXAMPLES
	 nrcmd> dhcp enable client-class
       nrcmd> client-class internal create 
       nrcmd> dhcp reload

STATUS

SEE ALSO

PROPERTIES
  Attributes:

    action[5] (AT_FLAGSINT(), Optional, default: <none>)
        Specifies what action to take with this client-class.  You can
        specify exclude, causing the server to ignore all communication
        from this client.
        If you specify the exclude action in the default client entry,
        then any client not specifically registered through the client
        command cannot communicate with the server.
        The one-shot and use-release-grace-period actions are now
        deprecated and ignored; these are available through the policy
        inhibit-all-renews and release-grace-period attributes.

    add-to-environment-dictionary[28] (AT_STRING, Optional, default: <none>)
        This string contains attribute-value pairs that are added to the
        environment dictionary whenever this client-class is associated
        with an incoming DHCP request.  You can use these attribute-value
        pairs to configure extensions or expressions without having to
        re-write the executable code in the extension or expression.  The
        string must have the format:
        "attribute1=value1,attribute2=value2, ... ,attributen=valuen"

    client-lookup-id[21] (AT_EXPR, Optional, default: <none>)
        Specifies the key value used to lookup the specified client in the
        client database, using an expression that evaluates to a string
        or a blob that is a valid string.  The lookup can be local or through
        LDAP.

    default-vpn[24] (AT_NAMEREF(VPN), Optional, default: <none>)
        Determines the VPN to which a client is assigned if the client does
        not supply a VPN-ID (or vrf-name) value.

    domain-name[3] (AT_STRING, Optional, default: <none>)
        Sets the domain name, which must be a zone, for performing DNS
        updates. Places the client's A record in this DNS domain.
        This feature is maintained for compatibility with prior versions.
        Additional options to specify the forward zone are provided on
        the client-class's policy (or embedded policy) and its
        referenced DNSUpdateConfig objects.

    embedded-policy[18] (AT_OBJ, Optional, default: <none>)
        Specifies the embedded policy object for this client-class.

    host-name[2] (AT_STRING, Optional, default: <none>)
        Specifies the hostname for clients in this client-class.
        Network Registrar uses this form of hostname value to signal the
        following special handling:
            @host-name-option
               Causes the server to use whatever hostname option the
               client sent. This is the default behavior if there is no
               entry for host-name in either the client or client-class.
            @no-host-name-option
               Causes the server to drop the hostname option that the
               client sent, and not replace it. If you have disabled
               DNS name synthesis, then the client will have no name
               placed into DNS.
            @use-macaddress
               Causes the server to synthesize a host-name for the
               client that is derived from its MAC address, and is thus
               unique. This token is used to ensure that a client has a
               valid name in DNS.
        This feature is maintained for compatibility with prior versions.
        Additional options for host-name synthesis are provided on the
        DNSUpdateConfig object referenced by the policy hierarchy.

    limitation-id[20] (AT_EXPR, Optional, default: <none>)
        Specifies an expression that evaluates to a binary large object
        (blob), or a string that can be used as a blob. The resulting
        value groups leases that have a maximum limit on the number of
        simultaneous active leases allowed. To configure the limit, use
        limitation-count attribute of the policy command. See also
        the over-limit-client-class attribute.

    over-limit-client-class-name[19] (AT_STRING, Optional, default: <none>)
        Designates the client-class used if this client is over the limit
        allowed for the specified limitation-id.

    override-client-id[27] (AT_EXPR, Optional, default: <none>)
        Specifies the client-identity value for the specified client, using
        an expression that evaluates to a binary large object (blob).  The
        value that is derived from the expression evaluation replaces any
        client-id option value in the incoming packet (though in actual
        practice, both values are retained in the lease-state database).

    override-vpn[25] (AT_NAMEREF(VPN), Optional, default: <none>)
        Determines the VPN to which a client is assigned regardless
        of what the client provides for a VPN-ID (or vrf-name) value.

    policy-name[4] (AT_STRING, Optional, default: <none>)
        Names the policy that should be used for this client-class.

    selection-criteria[14] (AT_ARRAY(AT_STRING), Optional, default: <none>)
        Lists the selection tags for this client-class. All the criteria
        in this list must appear in the scope/prefix selection tags for a
        scope/prefix to be considered acceptable to this client-class.

    unauthenticated-client-class-name[11] (AT_STRING, Optional, default: <none>)
        Names the client-class used if this client is no longer
        authenticated.

    user-defined[12] (AT_STRING, Optional, default: <none>)
        Provides an opaque user-defined string that can be set
        and queried. This property has no effect on the operation
        of the DHCP server.

    v6-client-lookup-id[26] (AT_EXPR, Optional, default: <none>)
        Specifies the key value used to lookup the DHCPv6 client in the
        client database, using an expression that evaluates to a string
        or a blob that is a valid string.  The lookup can be local or through
        LDAP.

    v6-override-client-id[29] (AT_EXPR, Optional, default: <none>)
        An expression which evaluates to a blob which is used for the
        client-identity value for the current DHCPv6 client.  Conceptually
        this value derived from the expression evaluation will replace any
        client-id option value in the incoming packet (though in actual
        practice, both values are retained in the lease-state database).

