Command Reference

Configuration Commands

comment <config node> "comment text"

commit

compare <saved | N> <M>

delete

delete protocols static route 0.0.0.0/0

exit [discard]

loadkey <username> <location>

rollback <N>

run

save

set firewall all-ping [enable | disable]

set firewall broadcast-ping [enable | disable]

set firewall group address-group <name> address [address | address range]

set firewall group address-group <name> description <text>

set firewall group ipv6-address-group <name> address <address>

set firewall group ipv6-address-group <name> description <text>

set firewall group ipv6-network-group <name> description <text>

set firewall group ipv6-network-group <name> network <CIDR>

set firewall group network-group <name> description <text>

set firewall group network-group <name> network <CIDR>

set firewall group port-group <name> description <text>

set firewall group port-group <name> port [portname | portnumber | startport-endport]

set firewall ip-src-route [enable | disable]

set firewall ipv6-name <name> default-action [drop | reject | accept]

set firewall ipv6-name <name> description <text>

set firewall ipv6-name <name> enable-default-log

set firewall ipv6-name <name> rule <1-9999> action [drop | reject | accept]

set firewall ipv6-name <name> rule <1-9999> description <text>

set firewall ipv6-name <name> rule <1-9999> destination address [address | addressrange | CIDR]

set firewall ipv6-name <name> rule <1-9999> destination group address-group <name>

set firewall ipv6-name <name> rule <1-9999> destination group network-group <name>

set firewall ipv6-name <name> rule <1-9999> destination group port-group <name>

set firewall ipv6-name <name> rule <1-9999> destination port [1-65535 | portname | start-end]

set firewall ipv6-name <name> rule <1-9999> disable

set firewall ipv6-name <name> rule <1-9999> log [disable | enable]

set firewall ipv6-name <name> rule <1-9999> protocol [<text> | <0-255> | all | tcp_udp]

set firewall ipv6-name <name> rule <1-9999> source address [address | addressrange | CIDR]

set firewall ipv6-name <name> rule <1-9999> source group address-group <name>

set firewall ipv6-name <name> rule <1-9999> source group network-group <name>

set firewall ipv6-name <name> rule <1-9999> source group port-group <name>

set firewall ipv6-name <name> rule <1-9999> source mac-address <mac-address>

set firewall ipv6-name <name> rule <1-9999> source port [1-65535 | portname | start-end]

set firewall ipv6-name <name> rule <1-9999> state [established | invalid | new | related] [enable | disable ]

set firewall ipv6-name <name> rule <1-9999> tcp flags <text>

set firewall ipv6-receive-redirects [enable | disable]

set firewall ipv6-src-route [enable | disable]

set firewall log-martians [enable | disable]

set firewall name <name> default-action [drop | reject | accept]

set firewall name <name> description <text>

set firewall name <name> enable-default-log

set firewall name <name> rule <1-9999> action [drop | reject | accept]

set firewall name <name> rule <1-9999> description <text>

set firewall name <name> rule <1-9999> destination address [address | addressrange | CIDR]

set firewall name <name> rule <1-9999> destination group address-group <name>

set firewall name <name> rule <1-9999> destination group network-group <name>

set firewall name <name> rule <1-9999> destination group port-group <name>

set firewall name <name> rule <1-9999> destination port [1-65535 | portname | start-end]

set firewall name <name> rule <1-9999> disable

set firewall name <name> rule <1-9999> log [disable | enable]

set firewall name <name> rule <1-9999> protocol [<text> | <0-255> | all | tcp_udp]

set firewall name <name> rule <1-9999> source address [address | addressrange | CIDR]

set firewall name <name> rule <1-9999> source group address-group <name>

set firewall name <name> rule <1-9999> source group network-group <name>

set firewall name <name> rule <1-9999> source group port-group <name>

set firewall name <name> rule <1-9999> source mac-address <mac-address>

set firewall name <name> rule <1-9999> source port [1-65535 | portname | start-end]

set firewall name <name> rule <1-9999> state [established | invalid | new | related] [enable | disable ]

set firewall name <name> rule <1-9999> tcp flags <text>

set firewall receive-redirects [enable | disable]

set firewall send-redirects [enable | disable]

set firewall source-validation [strict | loose | disable]

set firewall state-policy established action [accept | drop | reject]

set firewall state-policy established log enable

set firewall state-policy invalid action [accept | drop | reject]

set firewall state-policy invalid log enable

set firewall state-policy related action [accept | drop | reject]

set firewall state-policy related log enable

set firewall syn-cookies [enable | disable]

set firewall twa-hazards-protection [enable | disable]

set interface ethernet <ethN> firewall [in | out | local] [name | ipv6-name] <rule-set>

set interfaces <dummy | ethernet | bonding | bridge | pppoe> <interface> vrf <name>

set interfaces bonding <interface> address <address | dhcp | dhcpv6>

set interfaces bonding <interface> arp-monitor interval <time>

set interfaces bonding <interface> arp-monitor target <address>

set interfaces bonding <interface> description <description>

set interfaces bonding <interface> disable

set interfaces bonding <interface> hash-policy <policy>

set interfaces bonding <interface> ipv6 address autoconf

set interfaces bonding <interface> ipv6 address eui64 <prefix>

set interfaces bonding <interface> mac <mac-address>

set interfaces bonding <interface> member interface <member>

set interfaces bonding <interface> mode <mode>

set interfaces bonding <interface> primary <interface>

set interfaces bridge <interface> address <address | dhcp | dhcpv6>

set interfaces bridge <interface> aging <time>

set interfaces bridge <interface> description <description>

set interfaces bridge <interface> disable

set interfaces bridge <interface> disable-flow-control

set interfaces bridge <interface> forwarding-delay <delay>

set interfaces bridge <interface> hello-time <interval>

set interfaces bridge <interface> igmp querier

set interfaces bridge <interface> ipv6 address autoconf

set interfaces bridge <interface> ipv6 address eui64 <prefix>

set interfaces bridge <interface> mac <mac-address>

set interfaces bridge <interface> max-age <time>

set interfaces bridge <interface> member interface <member>

set interfaces bridge <interface> member interface <member> cost <cost>

set interfaces bridge <interface> member interface <member> priority <priority>

set interfaces bridge <interface> stp

set interfaces dummy <interface> address <address | dhcp | dhcpv6>

set interfaces dummy <interface> description <description>

set interfaces dummy <interface> disable

set interfaces ethernet <ethN> ip ospf bfd

set interfaces ethernet <ethN> ipv6 ospfv3 bfd

set interfaces ethernet <interface> address <address | dhcp | dhcpv6>

set interfaces ethernet <interface> description <description>

set interfaces ethernet <interface> disable

set interfaces ethernet <interface> disable-flow-control

set interfaces ethernet <interface> duplex <auto | full | half>

set interfaces ethernet <interface> ipv6 address autoconf

set interfaces ethernet <interface> ipv6 address eui64 <prefix>

set interfaces ethernet <interface> mac <mac-address>

set interfaces ethernet <interface> mtu <mtu>

set interfaces ethernet <interface> speed <auto | 10 | 100 | 1000 | 2500 | 5000 | 10000 | 25000 | 40000 | 50000 | 100000>

set interfaces geneve gnv0 address <address>

set interfaces geneve gnv0 mtu <mtu>

set interfaces geneve gnv0 remote <address>

set interfaces geneve gnv0 vni <vni>

set interfaces loopback lo address <address>

set interfaces loopback lo description <description>

set interfaces macsec <interface> security cipher [gcm-aes-128]

set interfaces macsec <interface> security encrypt

set interfaces macsec <interface> security mka cak <key>

set interfaces macsec <interface> security mka ckn <key>

set interfaces macsec <interface> security mka priority <priority>

set interfaces macsec <interface> security replay-window <window>

set interfaces macsec <interface> source-interface <physical-source>

set interfaces openvpn vtun10 openvpn-option 'persistent-key'

set interfaces openvpn vtun10 openvpn-option 'push &quot;keepalive 1 10&quot;'

set interfaces pppoe <interface> access-concentrator <name>

set interfaces pppoe <interface> authentication password <password>

set interfaces pppoe <interface> authentication user <username>

set interfaces pppoe <interface> connect-on-demand

set interfaces pppoe <interface> default-route

set interfaces pppoe <interface> description

set interfaces pppoe <interface> dhcpv6-option prefix-delegation interface <prefix-interface> address <local-addr>

set interfaces pppoe <interface> dhcpv6-option prefix-delegation interface <prefix-interface> sla-id <id>

set interfaces pppoe <interface> dhcpv6-option prefix-delegation interface <prefix-interface> sla-len <len>

set interfaces pppoe <interface> dhcpv6-option prefix-delegation length <length>

set interfaces pppoe <interface> disable

set interfaces pppoe <interface> idle-timeout <time>

set interfaces pppoe <interface> ipv6 address autoconf

set interfaces pppoe <interface> ipv6 enable

set interfaces pppoe <interface> local-address <address>

set interfaces pppoe <interface> mtu <mtu>

set interfaces pppoe <interface> no-peer-dns

set interfaces pppoe <interface> remote-address <address>

set interfaces pppoe <interface> service-name <name>

set interfaces pppoe <interface> source-interface <source-interface>

set interfaces pseudo-ethernet <interface> address <address | dhcp | dhcpv6>

set interfaces pseudo-ethernet <interface> description <description>

set interfaces pseudo-ethernet <interface> disable

set interfaces pseudo-ethernet <interface> ipv6 address autoconf

set interfaces pseudo-ethernet <interface> mac <mac-address>

set interfaces pseudo-ethernet <interface> source-interface <ethX>

set interfaces vxlan <interface> address <address>

set interfaces vxlan <interface> description <description>

set interfaces vxlan <interface> disable

set interfaces vxlan <interface> group <address>

set interfaces vxlan <interface> ipv6 address autoconf

set interfaces vxlan <interface> ipv6 address eui64 <prefix>

set interfaces vxlan <interface> mtu <mtu>

set interfaces vxlan <interface> port <port>

set interfaces vxlan <interface> remote <address>

set interfaces vxlan <interface> source-address <interface>

set interfaces vxlan <interface> source-interface <interface>

set interfaces vxlan <interface> vni <number>

set interfaces wirelessmodem <interface> apn <apn>

set interfaces wirelessmodem <interface> backup distance <metric>

set interfaces wirelessmodem <interface> description <description>

set interfaces wirelessmodem <interface> device <tty>

set interfaces wirelessmodem <interface> disable

set interfaces wirelessmodem <interface> mtu <mtu>

set interfaces wirelessmodem <interface> no-peer-dns

set interfaces wirelessmodem <interface> ondemand

set protocols bfd peer <address>

set protocols bfd peer <address> echo-mode

set protocols bfd peer <address> interval [receive | transmit] <10-60000>

set protocols bfd peer <address> interval echo-interval <10-60000>

set protocols bfd peer <address> interval multiplier <2-255>

set protocols bfd peer <address> multihop

set protocols bfd peer <address> shutdown

set protocols bfd peer <address> source [address <address> | interface <interface>]

set protocols bgp <asn>

set protocols bgp <asn> neighbor <address> bfd

set protocols bgp <asn> parameters bestpath as-path confed

set protocols bgp <asn> parameters bestpath as-path ignore

set protocols bgp <asn> parameters bestpath as-path multipath-relax

set protocols bgp <asn> parameters router-id

set protocols bgp <asn> peer-group <group> bfd

set protocols igmp interface <interface query-interval <seconds>

set protocols igmp interface <interface query-max-response-time <deciseconds>

set protocols igmp interface <interface> join <multicast-address> source <IP-address>

set protocols igmp interface <interface> version <version-number>

set protocols igmp interface eth1

set protocols igmp-proxy disable

set protocols igmp-proxy disable-quickleave

set protocols igmp-proxy interface <interface> alt-subnet <network>

set protocols igmp-proxy interface <interface> role <upstream | downstream>

set protocols pim int <interface> hello <seconds>

set protocols pim interface <interface-name>

set protocols pim interface <interface> dr-priority <value>

set protocols pim rp address <address> group <multicast-address/mask-bits>

set protocols pim rp keep-alive-timer <seconds>

set protocols static arp <address> hwaddr <mac>

set protocols static interface-route <subnet> next-hop-interface <interface>

set protocols static interface-route <subnet> next-hop-interface <interface> disable

set protocols static interface-route <subnet> next-hop-interface <interface> distance <distance>

set protocols static interface-route6 <subnet> next-hop-interface <interface>

set protocols static interface-route6 <subnet> next-hop-interface <interface> disable

set protocols static interface-route6 <subnet> next-hop-interface <interface> distance <distance>

set protocols static route 0.0.0.0/0 next-hop <address>

set protocols static route <subnet> blackhole

set protocols static route <subnet> blackhole distance <distance>

set protocols static route <subnet> next-hop <address>

set protocols static route <subnet> next-hop <address> disable

set protocols static route <subnet> next-hop <address> distance <distance>

set protocols static route6 <subnet> blackhole

set protocols static route6 <subnet> blackhole distance <distance>

set protocols static route6 <subnet> next-hop <address>

set protocols static route6 <subnet> next-hop <address> disable

set protocols static route6 <subnet> next-hop <address> distance <distance>

set protocols vrf <name> static interface-route <subnet> next-hop-interface <interface>

set protocols vrf <name> static interface-route <subnet> next-hop-interface <interface> disable

set protocols vrf <name> static interface-route <subnet> next-hop-interface <interface> distance <distance>

set protocols vrf <name> static interface-route6 <subnet> next-hop-interface <interface>

set protocols vrf <name> static interface-route6 <subnet> next-hop-interface <interface> disable

set protocols vrf <name> static interface-route6 <subnet> next-hop-interface <interface> distance <distance>

set protocols vrf <name> static route <subnet> blackhole

set protocols vrf <name> static route <subnet> blackhole distance <distance>

set protocols vrf <name> static route <subnet> next-hop <address>

set protocols vrf <name> static route <subnet> next-hop <address> disable

set protocols vrf <name> static route <subnet> next-hop <address> distance <distance>

set protocols vrf <name> static route <subnet> next-hop <address> next-hop-vrf <default | vrf-name>

set protocols vrf <name> static route6 <subnet> blackhole

set protocols vrf <name> static route6 <subnet> blackhole distance <distance>

set protocols vrf <name> static route6 <subnet> next-hop <address>

set protocols vrf <name> static route6 <subnet> next-hop <address> disable

set protocols vrf <name> static route6 <subnet> next-hop <address> distance <distance>

set protocols vrf <name> static route6 <subnet> next-hop <address> next-hop-vrf <default | vrf-name>

set service broadcast-relay disable

set service broadcast-relay id <n> description <description>

set service broadcast-relay id <n> disable

set service broadcast-relay id <n> interface <interface>

set service broadcast-relay id <n> port <port>

set service console-server <device> data-bits [7 | 8]

set service console-server <device> description <string>

set service console-server <device> parity [even | odd | none]

set service console-server <device> speed [ 300 | 1200 | 2400 | 4800 | 9600 | 19200 | 38400 | 57600 | 115200 ]

set service console-server <device> ssh port <port>

set service console-server <device> stop-bits [1 | 2]

set service dhcp-relay interface <interface>

set service dhcp-relay relay-options hop-count <count>

set service dhcp-relay relay-options max-size <size>

set service dhcp-relay relay-options relay-agents-packet <append | discard | forward | replace>

set service dhcp-relay relay-options relay-agents-packets discard

set service dhcp-relay server <server>

set service dhcp-server shared-network-name <name> authoritative

set service dhcp-server shared-network-name <name> subnet <subnet> default-router <address>

set service dhcp-server shared-network-name <name> subnet <subnet> dns-server <address>

set service dhcp-server shared-network-name <name> subnet <subnet> domain-name <domain-name>

set service dhcp-server shared-network-name <name> subnet <subnet> domain-search <domain-name>

set service dhcp-server shared-network-name <name> subnet <subnet> exclude <address>

set service dhcp-server shared-network-name <name> subnet <subnet> failover local-address <address>

set service dhcp-server shared-network-name <name> subnet <subnet> failover name <name>

set service dhcp-server shared-network-name <name> subnet <subnet> failover peer-address <address>

set service dhcp-server shared-network-name <name> subnet <subnet> failover status <primary | secondary>

set service dhcp-server shared-network-name <name> subnet <subnet> lease <time>

set service dhcp-server shared-network-name <name> subnet <subnet> range <n> start <address>

set service dhcp-server shared-network-name <name> subnet <subnet> range <n> stop <address>

set service dhcp-server shared-network-name <name> subnet <subnet> static-mapping <description> ip-address <address>

set service dhcp-server shared-network-name <name> subnet <subnet> static-mapping <description> mac-address <address>

set service dhcpv6-relay listen-interface <interface>

set service dhcpv6-relay max-hop-count 'count'

set service dhcpv6-relay upstream-interface <interface> address <server>

set service dhcpv6-relay use-interface-id-option

set service dhcpv6-server preference <preference value>

set service dhcpv6-server shared-network-name <name> subnet <prefix> lease-time {default | maximum | minimum}

set service dhcpv6-server shared-network-name <name> subnet <prefix> nis-domain <domain-name>

set service dhcpv6-server shared-network-name <name> subnet <prefix> nis-server <address>

set service dhcpv6-server shared-network-name <name> subnet <prefix> nisplus-domain <domain-name>

set service dhcpv6-server shared-network-name <name> subnet <prefix> nisplus-server <address>

set service dhcpv6-server shared-network-name <name> subnet <prefix> prefix-delegation start <address> prefix-length <length>

set service dhcpv6-server shared-network-name <name> subnet <prefix> prefix-delegation start <address> stop <address>

set service dhcpv6-server shared-network-name <name> subnet <prefix> sip-server <address | fqdn>

set service dhcpv6-server shared-network-name <name> subnet <prefix> sntp-server-address <address>

set service dns dynamic interface <interface> rfc2136 <service-name>

set service dns dynamic interface <interface> rfc2136 <service-name> key <keyfile>

set service dns dynamic interface <interface> rfc2136 <service-name> record <record>

set service dns dynamic interface <interface> rfc2136 <service-name> server <server>

set service dns dynamic interface <interface> rfc2136 <service-name> ttl <ttl>

set service dns dynamic interface <interface> rfc2136 <service-name> zone <zone>

set service dns dynamic interface <interface> service <service> host-name <hostname>

set service dns dynamic interface <interface> service <service> login <username>

set service dns dynamic interface <interface> service <service> password <password>

set service dns dynamic interface <interface> service <service> protocol <protocol>

set service dns dynamic interface <interface> service <service> server <server>

set service dns dynamic interface <interface> use-web skip <pattern>

set service dns dynamic interface <interface> use-web url <url>

set service dns forwarding allow-from <network>

set service dns forwarding dnssec <off | process-no-validate | process | log-fail | validate>

set service dns forwarding domain <domain-name> server <address>

set service dns forwarding ignore-hosts-file

set service dns forwarding listen-address

set service dns forwarding max-cache-entries

set service dns forwarding name-server <address>

set service dns forwarding negative-ttl

set service dns forwarding system

set service lldp

set service lldp interface <interface>

set service lldp interface <interface> disable

set service lldp legacy-protocols <cdp|edp|fdp|sonmp>

set service lldp management-address <address>

set service lldp snmp enable

set service mdns repeater disable

set service mdns repeater interface <interface>

set service pppoe-server access-concentrator <name>

set service pppoe-server authentication local-users username <name> password <password>

set service pppoe-server authentication local-users username <name> rate-limit <download | upload>

set service pppoe-server authentication mode <local | radius>

set service pppoe-server authentication radius dynamic-author <key | port | server>

set service pppoe-server authentication radius rate-limit enable

set service pppoe-server authentication radius server <address> key <secret>

set service pppoe-server client-ip-pool start <address>

set service pppoe-server client-ip-pool stop <address>

set service pppoe-server client-ip-pool subnet <address>

set service pppoe-server client-ipv6-pool delegate <address> delegation-prefix <number-of-bits>

set service pppoe-server client-ipv6-pool prefix <address> mask <number-of-bits>

set service pppoe-server interface <interface>

set service pppoe-server interface <interface> <vlan-id | vlan range> <text>

set service pppoe-server local-ip <address>

set service pppoe-server name-server <address>

set service pppoe-server pado-delay <number-of-ms> sessions <number-of-sessions>

set service router-advert interface <interface> ....

set service router-advert interface <interface> no-send-advert

set service router-advert interface <interface> prefix 2001:DB8::/32

set service ssh ciphers <cipher>

set service ssh disable-password-authentication

set service ssh listen-address <address>

set service ssh macs <mac>

set service ssh port <port>

set service tftp-server allow-upload

set service tftp-server directory <directory>

set service tftp-server listen-address <address>

set system config-management commit-archive location <URI>

set system config-management commit-revisions <N>

set system console device <device>

set system console device <device> speed <speed>

set system domain-name <domain>

set system flow-accounting buffer-size <buffer size>

set system flow-accounting disable-imt

set system flow-accounting interface <interface>

set system flow-accounting netflow engine-id <id>

set system flow-accounting netflow max-flows <n>

set system flow-accounting netflow sampling-rate <rate>

set system flow-accounting netflow server <address>

set system flow-accounting netflow source-ip <address>

set system flow-accounting netflow timeout expiry-interval <interval>

set system flow-accounting netflow version <version>

set system flow-accounting sflow agent-address <address>

set system flow-accounting sflow sampling-rate <rate>

set system flow-accounting sflow server <address>

set system flow-accounting syslog-facility <facility>

set system host-name <hostname>

set system login banner post-login <message>

set system login banner pre-login <message>

set system login radius server <address> disable

set system login radius server <address> port <port>

set system login radius server <address> secret <secret>

set system login radius server <address> timeout <timeout>

set system login radius source-address <address>

set system login user <name> authentication encrypted-password <password>

set system login user <name> authentication plaintext-password <password>

set system login user <name> full-name "<string>"

set system login user <username> authentication public-keys <identifier> key <key>

set system login user <username> authentication public-keys <identifier> type <type>

set system ntp allow-clients address <address>

set system ntp listen-address <address>

set system ntp server <address>

set system proxy password <password>

set system proxy port <port>

set system proxy url <url>

set system proxy username <username>

set system static-host-mapping host-name <hostname> alias <alias>

set system static-host-mapping host-name <hostname> inet <address>

set system syslog console facility <keyword> level <keyword>

set system syslog file <filename> archive file <number>

set system syslog file <filename> archive size <size>

set system syslog file <filename> facility <keyword> level <keyword>

set system syslog host <address> facility <keyword> level <keyword>

set system syslog host <address> facility <keyword> protocol <udp|tcp>

set system syslog user <username> facility <keyword> level <keyword>

set system task-scheduler task <task> crontab-spec <spec>

set system task-scheduler task <task> executable arguments <args>

set system task-scheduler task <task> executable path <path>

set system task-scheduler task <task> interval <interval>

set system time-zone <timezone>

set system wifi-regulatory-domain DE

set traffic-policy drop-tail <policy-name> queue-limit <number-of-packets>

set traffic-policy fair-queue <policy-name>

set traffic-policy fair-queue <policy-name> hash-interval <seconds>`

set traffic-policy fair-queue <policy-name> queue-limit <limit>

set traffic-policy fq-codel <policy name> codel-quantum <bytes>

set traffic-policy fq-codel <policy name> flows <number-of-flows>

set traffic-policy fq-codel <policy name> interval <miliseconds>

set traffic-policy fq-codel <policy-name> queue-limit <number-of-packets>`

set traffic-policy fq-codel <policy-name> target <miliseconds>`

set traffic-policy limiter <policy-name> class <class ID> match <match-name> description <description>

set traffic-policy limiter <policy-name> class <class ID> priority <value>

set traffic-policy limiter <policy-name> class <class-ID> bandwidth <rate>

set traffic-policy limiter <policy-name> class <class-ID> burst <burst-size>

set traffic-policy limiter <policy-name> default bandwidth <rate>

set traffic-policy limiter <policy-name> default burst <burst-size>

set traffic-policy network-emulator <policy-name> bandwidth <rate>

set traffic-policy network-emulator <policy-name> burst <burst-size>

set traffic-policy network-emulator <policy-name> network-delay <delay>

set traffic-policy network-emulator <policy-name> packet-corruption <percent>

set traffic-policy network-emulator <policy-name> packet-loss <percent>`

set traffic-policy network-emulator <policy-name> packet-reordering <percent>`

set traffic-policy network-emulator <policy-name> queue-limit <limit>

set traffic-policy priority-queue <policy-name> class <class-ID> queue-limit <limit>`

set traffic-policy random-detect <policy-name> bandwidth <bandwidth>

set traffic-policy random-detect <policy-name> precedence <IP-precedence-value> average-packet <bytes>

set traffic-policy random-detect <policy-name> precedence <IP-precedence-value> mark-probability <value>

set traffic-policy random-detect <policy-name> precedence <IP-precedence-value> maximum-threshold <packets>

set traffic-policy random-detect <policy-name> precedence <IP-precedence-value> minimum-threshold <packets>

set traffic-policy random-detect <policy-name> precedence <IP-precedence-value> queue-limit <packets>

set traffic-policy rate-control <policy-name> bandwidth <rate>

set traffic-policy rate-control <policy-name> burst <burst-size>

set traffic-policy rate-control <policy-name> latency

set traffic-policy round-robin <policy name> class <class ID> queue-limit <packets>

set traffic-policy round-robin <policy name> class <class-ID> quantum <packets>

set traffic-policy shaper <policy-name> bandwidth <rate>

set traffic-policy shaper <policy-name> class <class-ID> bandwidth <rate>

set traffic-policy shaper <policy-name> class <class-ID> burst <bytes>

set traffic-policy shaper <policy-name> class <class-ID> ceiling <bandwidth>

set traffic-policy shaper <policy-name> class <class-ID> priority <0-7>

set vpn sstp authentication local-users username <user> disable

set vpn sstp authentication local-users username <user> password <pass>

set vpn sstp authentication local-users username <user> rate-limit download <bandwidth>

set vpn sstp authentication local-users username <user> rate-limit upload <bandwidth>

set vpn sstp authentication local-users username <user> static-ip <address>

set vpn sstp authentication mode <local | radius>

set vpn sstp authentication protocols <pap | chap | mschap | mschap-v2>

set vpn sstp authentication radius acct-timeout <timeout>

set vpn sstp authentication radius dynamic-author key <secret>

set vpn sstp authentication radius dynamic-author port <port>

set vpn sstp authentication radius dynamic-author server <address>

set vpn sstp authentication radius max-try <number>

set vpn sstp authentication radius nas-identifier <identifier>

set vpn sstp authentication radius nas-ip-address <address>

set vpn sstp authentication radius rate-limit attribute <attribute>

set vpn sstp authentication radius rate-limit enable

set vpn sstp authentication radius rate-limit vendor

set vpn sstp authentication radius server <server> disable

set vpn sstp authentication radius server <server> fail-time <time>

set vpn sstp authentication radius server <server> key <secret>

set vpn sstp authentication radius server <server> port <port>

set vpn sstp authentication radius source-address <address>

set vpn sstp authentication radius timeout <timeout>

set vpn sstp network-settings client-ip-settings gateway-address <gateway>

set vpn sstp network-settings client-ip-settings subnet <subnet>

set vpn sstp network-settings client-ipv6-pool delegate <address> delegation-prefix <number-of-bits>

set vpn sstp network-settings client-ipv6-pool prefix <address> mask <number-of-bits>

set vpn sstp network-settings name-server <address>

set vpn sstp ppp-settings lcp-echo-failure <number>

set vpn sstp ppp-settings lcp-echo-interval <interval>

set vpn sstp ppp-settings lcp-echo-timeout

set vpn sstp ppp-settings mppe <require | prefer | deny>

set vpn sstp ssl ca-cert-file <file>

set vpn sstp ssl cert-file <file>

set vpn sstp ssl key-file <file>

set vrf bind-to-all

set vrf name <name>

set vrf name <name> table <id>

set zone-policy zone <name> default-action [drop | reject]

set zone-policy zone <name> description

set zone-policy zone <name> from <name> firewall ipv6-name <rule-set>

set zone-policy zone <name> from <name> firewall name <rule-set>

set zone-policy zone <name> interface <interfacenames>

set zone-policy zone <name> local-zone

show

Operational Commands

add system image <url | path>

connect console-server <device>

connect interface <interface>

delete system image [image-name]

disconnect interface <interface>

generate wireguard default-keypair

ping <host> vrf <name>

reset dns forwarding <all | domain>

restart dhcp relay-agent

restart dhcp server

restart dhcpv6 relay-agent

restart dhcpv6 server

restart dns forwarding

restart igmp-proxy

run generate macsec mka-cak

run generate macsec mka-ckn

set pppoe-server maintenance-mode <enable | disable>

set system image default-boot

show bridge

show bridge <name> spanning-tree

show configuration

show configuration commands

show console-server ports

show console-server user

show dhcp server leases

show dhcp server leases pool <pool>

show dhcp server leases sort <key>

show dhcp server leases state <state>

show dhcp server statistics

show dhcp server statistics pool <pool>

show dhcpv6 relay-agent status

show dhcpv6 server leases

show dhcpv6 server leases pool <pool>

show dhcpv6 server leases sort <key>

show dhcpv6 server leases state <state>

show dhcpv6 server status

show firewall

show firewall [name | ipv6name] <name>

show firewall [name | ipv6name] <name> rule <1-9999>

show firewall [name | ipv6name] <name> rule <1-9999>

show firewall [name | ipv6name] <name> statistics

show firewall group <name>

show firewall statistics

show firewall summary

show flow-accounting interface <interface>

show flow-accounting interface <interface> host <address>

show interfaces dummy

show interfaces dummy <interface>

show interfaces ethernet

show interfaces ethernet <interface>

show interfaces ethernet <interface> physical

show interfaces ethernet <interface> physical offload

show interfaces ethernet <interface> transceiver

show interfaces loopback

show interfaces loopback lo

show interfaces macsec

show interfaces macsec <interface>

show interfaces pppoe <interface>

show interfaces pppoe <interface> queue

show interfaces wireless <wlanX>

show interfaces wireless <wlanX> brief

show interfaces wireless <wlanX> queue

show interfaces wireless <wlanX> scan

show interfaces wireless detail

show interfaces wireless info

show interfaces wirelessmodem <interface>

show interfaces wirelessmodem <interface> log

show interfaces wirelessmodem <interface> statistics

show ip route 0.0.0.0

show ip route vrf <name>

show ipv6 route vrf <name>

show lldp neighbors

show lldp neighbors detail

show lldp neighbors interface <interface>

show log [all | authorization | cluster | conntrack-sync | ...]

show log firewall [name | ipv6name] <name>

show log image <name> [all | authorization | directory | file <file name> | tail <lines>]

show log lldp

show pppoe-server sessions

show protocols bfd peer

show protocols static arp

show protocols static arp interface eth1

show queueing <interface-type> <interface-name>

show system commit

show system image

show system usb

show system usb

show version

show vrf

show vrf <name>

show wireguard keypairs pubkey default

show zone-policy zone <name>

traceroute vrf <name> [ipv4 | ipv6] <host>