设为首页 收藏本站
查看: 1789|回复: 0

[经验分享] Juniper [edit system] Hierarchy Level

[复制链接]

尚未签到

发表于 2015-11-5 14:08:15 | 显示全部楼层 |阅读模式
[edit system] Hierarchy Level
system {accounting {destination {radius {server {server-address {accounting-port port-number;max-outstanding-requestsport port-number;retry number;secret password;source-address address;timeout seconds;}}}tacplus {server {server-address {port port-number;secret password;single-connection;source-address address;timeout seconds;}}}}events  [ change-loginteractive-commands login ];}allow-6pe-traceroute;allow-v4mapped-packets;archival {configuration {archive-sites {ftp://<username>:<password>@<host>:<port>/<url-path>;scp://<username>:<password>@<host>:<port>/<url-path>;}transfer-interval interval;transfer-on-commit;}}arp {aging-timer minutes;gratuitous-arp-delay;gratuitous-arp-on-ifup;interfaces {logical-interface-name {aging-timer minutes;}}passive-learning;purging;}authentication-order [ authentication-methods ];auto-configuration{traceoptions {file<filename> <files number> <match regular-expression> <size size> <world-readable |no-world-readable>;flag <all | auth | configuration |;interfaces | io | rtsock | ui>level level;no-remote-trace;}}backup-router address <destination [ destination-addresses ]>;commit{fast-synchronize;synchronize;server{commit-interval number;days-to-keep-error-logs number;maximum-aggregate-pool number;maximum-entries number;traceoptions{file <filename> <files number> <match regular-expression><size size> <world-readable | no-world-readable>;flag <all | auth | configuration |;interfaces | io | rtsock | ui>level level;no-remote-trace;}}}(compress-configuration-files |no-compress-configuration-files);ddos-protection {global {disable-fpc;disable-logging;disable-routing-engine;flow-detection;flow-report-rate;violation-report-rate;}protocols protocol-group (aggregate| packet-type) {bandwidth packets-per-second;burst size;disable-fpc;disable-logging;disable-routing-engine;fpc {bandwidth-scale percentage;burst-scale percentage;disable-fpc;}priority level;recover-time seconds;flow-detection {flow-detect-time detect-period;no-flow-logging;timeout-active-flows enable-period;flow-level-bandwidth;flow-level-control (all| keep-all | police);flow-detection-mode (always-on|automatic |disabled);physical-interface;flow-recover-time recover-period;flow-timeout-time timeout-period;subscriber;}}traceoptions{file filename <files number><match regular-expression > <size maximum-file-size> <world-readable | no-world-readable>;flag flag;level(all | error | info | notice | verbose | warning);no-remote-trace;}}default-address-selection;diag-port-authentication (encrypted-password&quot;password&quot; | plain-text-password);dynamic-profile-options {versioning;}domain-name domain-name;domain-search [ domain-list ];donot-disable-ip6op-ondad;extensions{providers {provider-id {license-type license deployment-scope[ deployments ];}}resource-limits {package package-name {resources {cpu{priority number;time seconds;}file{core-size bytes;open number;size bytes;}memory{data-size bytes;locked-in bytes;resident-set-size bytes;socket-buffers bytes;stack-size bytes;}}}process process-ui-name {resources {cpu{priority number;time seconds;}file{core-size bytes;open number;size bytes;}memory{data-size bytes;locked-in bytes;resident-set-size bytes;socket-buffers bytes;stack-size bytes;}}}}}fips{level level;}host-name hostname;inet6-backup-router ipv6-address <destination address>;internet-options {(gre-path-mtu-discovery |no-gre-path-mtu-discovery);icmpv4-rate-limit bucket-size number packet-rate rate;icmpv6-rate-limit bucket-size number packet-rate rate;(ipip-path-mtu-discovery |no-ipip-path-mtu-discovery);(ipv6-path-mtu-discovery |noipv6-path-mtu-discovery);ipv6-path-mtu-discovery-timeout;no-tcp-rfc1323-paws;no-tcp-rfc1323;(path-mtu-discovery |no-path-mtu-discovery);source-port upper-limit port-number;(source-quench |no-source-quench);tcp-drop-synfin-set;}kernel-replication;license{autoupdate {url URL;password password;}renewbefore-expiration number;interval numbertraceoptions {file<filename> <files number> <size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}}location {altitude feet;building name;country-code code;floor number;hcoord horizontal-coordinate;lata service-area;latitude degrees;longitude degrees;npa-nxx number;postal-code postal-code;rack number;vcoord vertical-coordinate;}login {announcement &quot;text&quot;;class class-name {access-end &quot;hh<:mm:<ss>>&quot;;access-start &quot;hh<:mm:<ss>>&quot;;allow-commands &quot;regular-expression&quot;;( allow-configuration | allow-configuration-regexps)“regular expression 1” “regular expression 2”;allowed-days [ sundaymonday tuesday wednesday thursday friday saturday ];configuration-breadcrumbs;deny-commands &quot;regular-expression&quot;;( deny-configuration | deny-configuration-regexps ) “regular expression 1” “regular expression 2 ”;idle-timeout minutes;logical-system logical-system-name;login-alarms;login-script filename;login-tip;permissions [ permissions ];security-role[security-role ] ;}deny-sources(address address | apply-groups | apply-groups-except) ;message &quot;text&quot;;password {change-type (character-sets |set-transitions);format (des |md5 | sha1);maximum-length length;minimum-changes number;minimum-length length;minimum-lower-cases number;minimum-numerics number;minimum-punctuations number;minimum-upper-cases number;}retry-options {backoff-factor number;backoff-threshold number;maximum-time number;minimum-time number;tries-before-disconnect number;}user username {authentication {(encrypted-password&quot;password&quot; | plain-text-password);load-key-file filename;ssh-dsa&quot;public-key&quot; <from hostname>;ssh-ecdsa &quot;public-key&quot;<from hostname>;ssh-rsa &quot;public-key&quot; <from hostname>;}class class-name;full-name &quot;complete-name&quot;;uid uid-value;}}max-configurations-on-flash number;mirror-flash-on-disk;name-server {address;}nd-maxmcast-solicitnd-retransmit-timerno-multicast-echo;no-neighbor-learn;;no-ping-record-route;no-ping-time-stamp;no-redirects;no-redirects-ipv6;ntp {authentication-key key-number typemd5 value password;boot-server address;broadcast <address><key key-number> <ttl value> <version value>;broadcast-client;multicast-client <address>;peer address <key key-number><prefer> <version value>;server address <key key-number><prefer> <version value>;source-address source-address;trusted-key [ key-numbers ];}pic-console-authentication {(encrypted-password&quot;encrypted-password&quot; | plain-text-password);}ports {auxiliary {disable;insecure;type(ansi | small-xterm | vt100 | xterm);port-type (mini-usb| rj45) ;}}console {disable;insecure;log-out-on-disconnect;type(ansi | small-xterm | vt100 | xterm);}}processes {process-name (enable |disable) failover (alternate-media | other-routing-engine);command path;timeout seconds;}proxy{password password;port port-number;server(hostname | ip-address);username username;}radius-options {attributes{nas-ip-address address;}password-protocolmschap-v2;}radius-server {server-address {accounting-port port-number;max-outstanding-requests number;port port-number;retry number;secret password;source-address source-address;timeout seconds;}}root-authentication {(encrypted-password&quot;password&quot; | plain-text-password);load-key-file filename;ssh-dsa&quot;public-key&quot; <from hostname>;ssh-ecdsa &quot;public-key&quot;<from hostname>;ssh-rsa &quot;public-key&quot; <from hostname>;}(saved-core-context |no-saved-core-context);saved-core-files number;scripts {load-scripts-from-flash;commit {allow-transients;direct-access;file filename.xsl{checksum (md5 |sha-256 | sha1) hash;optional;refresh;refresh-from url;source url;}max-datasizerefresh;refresh-from url;traceoptions {file<filename> <files number> <size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}}op {file filename.xsl{arguments {argument-name {description descriptive-text;}}checksum (md5| sha-256 | sha1) hash;command filename-alias;description descriptive-text;refresh;refresh-from url;source url;}max-datasizeno-allow-urlrefresh;refresh-from url;traceoptions {file<filename> <files number> <size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}}}static-host-mapping {hostname {alias [ aliases ];inet [ addresses ];inet6 [ addresses ];sysid system-identifier;}}syslog {allow-duplicates;archive <binary-data| no-binary-data> <files number> <size size> <world-readable | no-world-readable>;console {any| authorization | change-log | conflict-log | daemon | dfc | external | firewall | ftp | interactive-commands | kernel | ntp | pfe | security | user) (alert | any | critical | emergency | error | info | none | notice | warning);}file filename {facility severity;allow-duplicates;any(alert | any | critical | emergency | error | info | none | notice | warning);archive <archive-sites {ftp-url <password password>}><files number> <size size> <start-time &quot;YYYY-MM-DD.hh:mm&quot;><transfer-interval minutes> <world-readable | no-world-readable>;authorization (alert | any| critical | emergency | error | info | none | notice | warning);change-log (alert | any | critical | emergency | error | info | none |notice | warning);conflict-log (alert | any | critical | emergency | error | info | none | notice | warning);daemon(alert | any | critical | emergency | error | info | none | notice | warning);dfc (alert | any | critical | emergency | error | info |none | notice | warning);explicit-priority;external(alert | any | critical | emergency | error | info | none | notice | warning);firewall (alert | any | critical | emergency | error | info| none | notice | warning);ftp (alert | any | critical | emergency | error | info | none | notice | warning);interactive-commands(alert | any | critical | emergency | error | info | none | notice | warning);kernel (alert | any | critical | emergency | error | info| none | notice | warning);match &quot;regular-expression&quot;;ntp(alert | any | critical | emergency | error | info | none | notice | warning);pfe (alert | any | critical | emergency | error | info |none | notice | warning);security (alert | any | critical | emergency | error | info | none | notice | warning);structured-data {brief}host (hostname |other-routing-engine | scc-master) {facility severity;authorization(alert | any | critical | emergency | error | info | none | notice | warning);change-log (alert | any | critical | emergency | error |info | none | notice | warning);conflict-log (alert | any | critical | emergency | error | info | none | notice | warning);daemon(alert | any | critical | emergency | error | info | none | notice | warning);dfc (alert | any | critical | emergency | error | info |none | notice | warning);explicit-priority;external(alert | any | critical | emergency | error | info | none | notice | warning);facility-override facility;firewall(alert | any | critical | emergency | error | info | none | notice | warning);ftp (alert | any | critical | emergency | error | info |none | notice | warning);interactive-commands (alert | any | critical | emergency | error | info | none | notice | warning);kernel(alert | any | critical | emergency | error | info | none | notice | warning);log-prefix string;match &quot;regular-expression&quot;;ntp(alert | any | critical | emergency | error | info | none | notice | warning);pfe (alert | any | critical | emergency | error | info |none | notice | warning);security (alert | any | critical | emergency | error | info | none | notice | warning);source-address source-address;structured-data {briefuser (username |*) {}log-rotate-frequency minutes;server;source-address address;time-format (year |millisecond | year millisecond);user (username |*) {facility severity;match &quot;regular-expression&quot;;}}tacplus-options {(exclude-cmd-attribute |no-cmd-attribute-value);service-name service-name;}tacplus-server {server-address {port port-number;secret password;single-connection;source-address source-address;timeout seconds;}}time-zone (GMT |GMT&#43;hour-offset | GMT-hour-offset | zone-name);tracing destination-overridesyslog host address;use-imported-time-zones;}}system {services{database-replication {traceoptions {file<filename> <files number> <match regular-expression> <size maximum-file-size><world-readable | no-world-readable>;flag flag;no-remote-trace;}}dhcp-local-server {authentication{password password;username-include {circuit-type;delimiter delimiter-character;domain-name domain-name;logical-system-name;mac-address;option-60;option-82 <circuit-id><remote-id>;routing-instance-name;user-prefix user-prefix;}}duplicate-clients-on-interface;dynamic-profile (profile-name |junos-default-profile) <aggregate-clients <merge | replace> | use-primary primary-profile-name>;forward-snooped-clients (all-interfaces |configured-interfaces | non-configured-interfaces);group group-name {dynamic-profile (profile-name |junos-default-profile) <aggregate-clients <merge | replace> | use-primary primary-profile-name>;interface interface-name {exclude;overrides {... samestatements as at the [edit system services dhcp-local-server overrides] hierarchy level ...}trace;upto upto-interface-name;}}overrides {client-discover-match <option60-and-option82>;interface-client-limit number;no-arp;process-inform {pool pool-name;}}pool-match-order {external-authority;ip-address-first;option-82;}reconfigure{attempts attempt-count;clear-on-abort;strict;timeout timeout-value;token token-value;trigger {radius-disconnect;}}traceoptions {file<filename> <files number> <match regular-expression> <size maximum-file-size><world-readable | no-world-readable>;flag flag;no-remote-trace;}}dhcpv4-profiles profile-name {bind-interface interface-name;dead-server-retry-interval interval-in-seconds;dead-server-successive-retry-attempt number-of-attempts;dhcp-server-selection-algorithm (highest-priority-server| round-robin);lease-time time-in-seconds;pool-name pool-name;retransmission-attempt number-of-attempts;retransmission-interval interval-in-seconds;servers ip-address {priority value;}}dhcpv6-profiles profile-name {bind-interface interface-name;lease-time time-in-seconds;pool-name pool-name;retransmission-attempt number-of-attempts;retransmission-interval interval-in-seconds;}traceoptions {file<filename> <files number> <match regular-expression> <size maximum-file-size><world-readable | no-world-readable>;flag flag;no-remote-trace;}}finger {connection-limit limit;rate-limit limit;}flow-tap-dtcp {ssh{connection-limit limit;rate-limit limit;}}ftp {connection-limit limit;rate-limit limit;}local-policy-decision-function{statistics {aacl-statistics-profile profile-name {aacl-fields{address;all-fields;application;application-group;input-bytes;input-interface;input-packets;ipv6-addressipv6-prefix-lengthmask;output-bytes;output-packets;subscriber-name;timestamp;vrf-name;}file filename;record-type(delta | interim);}file filename {archive-sites{url;}files number;size bytes;transfer-interval minutes;}record-type(data | interim);}traceoptions{file <filename> <files number> <match regular-expression><size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}}netconf {ssh {connection-limit limit;port port;rate-limit limit;}traceoptions {file<filename> <files number> <match regular-expression> <size size> <world-readable |no-world-readable>;flag flag;no-remote-trace;on-demand;}}outbound-ssh {client client-id {address {port port-number;retry number;timeout seconds;}device-id device-id;keep-alive{retry number;timeout seconds;}reconnect-strategy(in-order | sticky);secret secret;servicesnetconf;}traceoptions{file <filename> <files number> <match regular-expression><size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}}resource-monitor{resource-category jtree {resource-typefree-dwords {low-watermark number;high-watermark number;}resource-typefree-pages {low-watermark number;high-watermark number;}}no-throttle;no-logging;high-threshold number;traceoptions{file filename <files number> <match regular-expression><size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}}service-deployment {local-certificate certificate-name;servers {server-address {port port-number;security-options{(ssl3 | tls);}user username;}}source-address source-address;traceoptions{flag flag;}}ssh {ciphers [ cipher-1cipher-2 cipher-3 ...]client-alive-count-max seconds;client-alive-interval seconds;connection-limit limit;hostkey-algorithm limit;key-exchange limit;macs limit;max-sessions-per-connection number;no-tcp-forwarding;protocol-version [v1v2];rate-limit limit;root-login (allow| deny | deny-password);}subscriber-management {enforce-strict-scale-limit-license;gres-route-flush-delay;maintain-subscriber {interface-delete;}traceoptions {file filename <files number><match regular-expression > <size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}}traceoptions {file filename <files number><match regular-expression > <size maximum-file-size> <world-readable | no-world-readable>;flag flag;no-remote-trace;}telnet {connection-limit limit;rate-limit limit;}tftp-server{connection-limit limit;rate-limit limit;}xnm-clear-text {connection-limit limit;rate-limit limit;}xnm-ssl {connection-limit limit;local-certificate certificate-name;rate-limit limit;}}

运维网声明 1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com

所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其承担任何法律责任,如涉及侵犯版权等问题,请您及时通知我们,我们将立即处理,联系人Email:kefu@iyunv.com,QQ:1061981298 本贴地址:https://www.yunweiku.com/thread-135493-1-1.html 上篇帖子: Unbuntu 安装 juniper 下篇帖子: 使用juniper禁止访问部分网站
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

扫码加入运维网微信交流群X

扫码加入运维网微信交流群

扫描二维码加入运维网微信交流群,最新一手资源尽在官方微信交流群!快快加入我们吧...

扫描微信二维码查看详情

客服E-mail:kefu@iyunv.com 客服QQ:1061981298


QQ群⑦:运维网交流群⑦ QQ群⑧:运维网交流群⑧ k8s群:运维网kubernetes交流群


提醒:禁止发布任何违反国家法律、法规的言论与图片等内容;本站内容均来自个人观点与网络等信息,非本站认同之观点.


本站大部分资源是网友从网上搜集分享而来,其版权均归原作者及其网站所有,我们尊重他人的合法权益,如有内容侵犯您的合法权益,请及时与我们联系进行核实删除!



合作伙伴: 青云cloud

快速回复 返回顶部 返回列表