client (nrcmd)							client (nrcmd)


NAME
    client - Creates clients and assigns them to client-classes

SYNOPSIS
    client <name> create [<attribute>=<value>]
    client <name> delete
    client list  
    client listnames
    client <name> show 
    client <name> get <attribute>
    client <name> set <attribute>=<value>
    client <name> unset <attribute>

DESCRIPTION
    The client command assigns attributes to a specific client entry. 
    These attributes determine what type of IP address, policy, or 
    both that Network Registrar assigns to the requesting host. 
    Network Registrar always stores the client identifier (MAC 
    address or default) in lowercase characters.

    Because the DHCP server reads the client-specific configuration
    information each time a request comes in, you do not have to 
    reload the server after modifying it. However, you must reload
    the server if you modify the default client configuration.
     
    The attributes you can assign include such things as
    a class of client, a policy, an action, and the inclusion or
    exclusion of scope selection tags. The DHCP server looks up these
    properties to determine how it should process a host request for
    an IP address.
    
    If you have common client attributes to configure, such as selection 
    criteria, use the client-class so that multiple client
    configurations can reference the attributes.
          
    You can specify the client by using the MAC address or some
    other unique client identifier related to the client-lookup-id
    that is specified in the client's associated client-class.

    A sample Ethernet MAC address might be 1,6,00:a0:24:2e:9c:20


    client name create [attribute=value]
    client default create [attribute=value]
       Creates the client identifier as a MAC address or the word default 
       (and optionally defines its attributes). The default client configuration
       applies to all clients that do not have an explicit configuration. If an 
       entry for the client already exists, the command overwrites it.

       If using a MAC address, it should be in the form hardware, length, 
       address (without spaces and including the commas):

          hardware
          Usually 1 (Ethernet) or 6 (Token Ring), but can be any number from 1 through 255.

          length
          Octets in the MAC address (usually 6, but can be any number from 1 through 16).

          address
          MAC address itself, with octets separated by colons, and each octet having a 
          two-character hex value from 00 through FF (not case-sensitive).

               
    
EXAMPLES
    nrcmd> client 1,6,00:d0:ba:d3:bd:3b create client-class-name=external

STATUS

SEE ALSO
    client-class

PROPERTIES
  Attributes:

    action[5] (AT_FLAGSINT(), Optional, default: <none>)
        Describes the action the DHCP server takes for this client.
            1  exclude - causes the server to ignore all
               communication from this client.
            2  deprecated-one-shot - now deprecated.
            3  deprecated-use-release-grace-period - now deprecated.
            32 none
        If you specify the exclude action in the default client
        entry, then any client not specifically registered through
        the client command cannot communicate with the server.
        Note: The deprecated flags (2,3) are now available through
        the policy command attributes inhibit-all-renews and
        release-grace-period.

    add-to-environment-dictionary[26] (AT_STRING, Optional, default: <none>)
        Lists attribute-value pairs that are added to the environment
        dictionary whenever this client-class is associated with an
        incoming DHCP request.  You can use these attribute-value pairs
        to configure extensions or expressions without having to rewrite
        the executable code in the extension or expression.
        The string must have the format:
        "attribute1=value1,attribute2=value2, ... ,attributen=valuen"

    authenticate-until[9] (AT_DATE, Optional, default: <none>)
        Sets an authentication expiration date, using date format or the
        forever keyword. Dates can be in the 2h (two hours ago, for
        example) or month day hour:minute[:second] year format.
        Formats for the date are:
         +<num><unit>
            Time in the future, where num is a decimal number and unit
            is s, m, h, d, or w for seconds, minutes, hours, days or
            weeks, respectively.
         <month> <day> <hour>:<minute>[:<second>] <year>
            Month, day, 24-hour time, and 2-or-4-digit-year.
            For example:Jun 30 20:00:00 2007. Enter the time that is
            local to the nrcmd process.
         forever
            Does not expire the authentication for this client.

    client-class-name[1] (AT_STRING, Optional, default: <none>)
        Identifies the client-class to which a client belongs. If the client
        is not a member of a client-class, then the DHCP server uses the
        default client-class properties.

    default-vpn[24] (AT_NAMEREF(VPN), Optional, default: <none>)
        Names the VPN to assign to clients that do not already have a
        vpn-id or vrf-name value.

    domain-name[3] (AT_STRING, Optional, default: <none>)
        Gives the domain name (which must be a zone) to use when performing
        DNS updates. Places the client's A record in this DNS domain.
        This feature is maintained for compatibility with prior versions.
        Additional options to specify the forward zone are provided on
        the client policy (or embedded policy) and its referenced
        DNSUpdateConfig objects.

    embedded-policy[18] (AT_OBJ, Optional, default: <none>)
        Specifies the embedded policy object for this client.

    host-name[2] (AT_STRING, Optional, default: <none>)
        Specifies the hostname. Use this string to replace any hostname
        DHCP option that the DHCP client sends. The two forms for
        specifying the hostname are:
        1.  A string that does not start with an at (@) sign. This form
            of host-name value is used to override the DHCP client
            request host name. When you enter a valid name, you cause
            the DHCP server to ignore any host-name specified by this
            client, and, instead, use this client-entry attribute. The
            actual value of the hostname option in the client's DHCP
            packet is ignored. You can use any valid DNS name. You
            cannot use underscores (_)in the hostname.
        2.  A string that starts with an at (@) sign. Network Registrar
            uses this form of hostname value to signal the following
            special handling:
            @host-name-option
               Causes the server to use whatever hostname option the
               client sent. This is the default behavior if there is no
               entry for hostname in either the client or client-class.
            @no-host-name-option
               Causes the server to drop the hostname option that the
               client sent, and not replace it. If you have disabled DNS
               name synthesis, then the client will have no name placed
               into DNS.
            @use-macaddress
               Causes the server to synthesize a hostname for the
               client that is derived from its MAC address, and is
               thus unique. This token is used to ensure that a
               client has a valid name in DNS.
        This feature is maintained for compatibility with earlier versions.
        Additional options for hostname synthesis are provided on the
        DNSUpdateConfig object referenced by the policy hierarchy.

    over-limit-client-class-name[19] (AT_STRING, Optional, default: <none>)
        Identifies which client-class to use if this client is over the
        limit allowed for the number of simultaneous active leases with
        a common limitation-id.

    override-vpn[25] (AT_NAMEREF(VPN), Optional, default: <none>)
        Names the VPN to assign to clients, no matter what values
        clients present as VPN-IDs or vrf-names.

    policy-name[4] (AT_STRING, Optional, default: <none>)
        Identifies the policy to add to Network Registrar's DHCP policy
        search list for this client.

    selection-criteria[14] (AT_ARRAY(AT_STRING), Optional, default: <none>)
        Lists selection tags for this client. All the criteria in this
        list must appear in the scope/prefix selection tags for a
        scope/prefix to be considered acceptable to this client.

    unauthenticated-client-class-name[11] (AT_STRING, Optional, default: <none>)
        Identifies the client-class to use if this client is no longer
        authenticated.

    user-defined[12] (AT_STRING, Optional, default: <none>)
        Contains an opaque user-defined string that can be set and
        queried. This attribute has no effect on the operation of the
        DHCP server.

