Skip to content

System

System configuration encompasses fundamental device-level settings that control core operational behaviors including hostname identification, IP and IPv6 routing enablement, domain name resolution, login security controls, SSH server parameters, and HTTP/HTTPS server parameters for management access. It provides comprehensive control over essential network services such as multicast routing, source routing, domain lookup, and authentication methods while supporting both local and AAA-based authentication mechanisms for management interfaces. SSH configuration includes bulk-mode optimization for efficient bulk data transfers with configurable window sizes. System configuration is critical for establishing the basic operational foundation of network devices, ensuring proper identification, connectivity, security posture, and management accessibility across the network infrastructure.

Diagram
NameTypeConstraintMandatoryDefault Value
systemClass[system]No

NameTypeConstraintMandatoryDefault Value
hostnameStringRegex: ^[^\s]*$No
ip_bgp_community_new_formatBooleantrue, falseNo
ip_routingBooleantrue, falseNo
ipv6_unicast_routingBooleantrue, falseNo
mtuIntegermin: 1500, max: 9198No
ip_source_routeBooleantrue, falseNo
ip_domain_lookupBooleantrue, falseNo
ip_domain_lookup_nsapBooleantrue, falseNo
ip_domain_lookup_recursiveBooleantrue, falseNo
ip_domain_lookup_vrfsList[ip_domain_lookup_vrfs]No
ip_domain_nameStringRegex: ^[^\s]*$No
login_delayIntegermin: 1, max: 10No
login_on_failureBooleantrue, falseNo
login_on_failure_logBooleantrue, falseNo
login_on_successBooleantrue, falseNo
login_on_success_logBooleantrue, falseNo
ip_multicast_routingBooleantrue, falseNo
multicast_routing_switchBooleantrue, falseNo
ip_multicast_routing_distributedBooleantrue, falseNo
multicast_routing_vrfsList[multicast_routing_vrfs]No
ipv6_multicast_routingBooleantrue, falseNo
access_session_mac_move_denyBooleantrue, falseNo
archiveClass[archive]No
boot_system_bootfilesListStringNo
boot_system_flash_filesListStringNo
cisp_enableBooleantrue, falseNo
control_plane_service_policy_inputStringNo
diagnostic_bootup_levelChoicecomplete, minimalNo
enable_secretStringNo
enable_secret_levelIntegermin: 0, max: 255No
enable_secret_typeChoice0, 4, 5, 8, 9No
epm_loggingBooleantrue, falseNo
ip_domain_lookup_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernetNo
ip_domain_lookup_source_interface_idAnyString or Integer[min: 0]No
ip_forward_protocol_ndBooleantrue, falseNo
ip_name_serversListIPNo
ip_name_servers_vrfList[ip_name_servers_vrf]No
ip_radius_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernetNo
ip_radius_source_interface_idAnyString or Integer[min: 0]No
ip_radius_source_interface_vrfStringNo
ip_scp_server_enableBooleantrue, falseNo
sshClass[ssh]No
ip_tacacs_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernetNo
ip_tacacs_source_interface_idAnyString or Integer[min: 0]No
ip_slaClass[ip_sla]No
ip_tacacs_source_interface_vrfStringNo
memory_free_low_watermark_processorIntegermin: 1, max: 3994575No
pnp_profilesList[pnp_profiles]No
redundancyBooleantrue, falseNo
redundancy_modeChoicenone, rpr, rpr-plus, ssoNo
transceiver_type_all_monitoringBooleantrue, falseNo
httpClass[http]No
ip_hostsList[ip_hosts]No
subscriber_templatingBooleantrue, falseNo
call_home_contact_emailStringNo
call_home_cisco_tac_1_profile_activeBooleantrue, falseNo
call_home_cisco_tac_1_destination_transport_methodChoiceemail, httpNo
ip_ftp_passiveBooleantrue, falseNo
tftp_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernetNo
tftp_source_interface_idAnyString or Integer[min: 0]No
multilink_ppp_bundle_nameStringNo
ip_nbar_classification_dns_classify_by_domainBooleantrue, falseNo
track_objectsList[track_objects]No
ip_multicast_route_limitIntegermin: 1, max: 2147483647No
ip_domain_list_namesListStringNo
ip_domain_list_vrf_domainStringNo
ip_domain_list_vrfStringNo
ethernet_cfm_alarm_config_delayIntegermin: 2500, max: 30000No
ethernet_cfm_alarm_config_resetIntegermin: 2500, max: 30000No
standby_redirectsChoicenone, enable, disableNo
security_passwords_min_lengthIntegermin: 1, max: 16No
platformClass[platform]No
cef_ipv4_include_ports_sourceBooleantrue, falseNo
cef_ipv4_include_ports_destinationBooleantrue, falseNo
cef_ipv6_include_ports_sourceBooleantrue, falseNo
cef_ipv6_include_ports_destinationBooleantrue, falseNo
port_channel_load_balanceChoicedst-ip, dst-mac, dst-mixed-ip-port, dst-port, mpls, src-dst-ip, src-dst-mac, src-dst-mixed-ip-port, src-dst-port, src-ip, src-mac, src-mixed-ip-port, src-port, vlan-dst-ip, vlan-dst-mixed-ip-port, vlan-src-dst-ip, vlan-src-dst-mixed-ip-port, vlan-src-ip, vlan-src-mixed-ip-portNo
authentication_mac_move_permitBooleantrue, falseNo
authentication_mac_move_deny_uncontrolledBooleantrue, falseNo
ip_default_gatewayIPNo
mac_address_table_aging_timeAnyInteger[min: 0, max: 0] or Integer[min: 10, max: 1000000] or String[Regex: ^.*[\$\%]\{.*$]No
device_classifierBooleantrue, falseNo
table_mapsList[table_maps]No
power_redundancy_mode_combinedBooleantrue, falseNo
power_supply_autolc_shutdownBooleantrue, falseNo
power_supply_autolc_priorityListInteger[min: 1, max: 10]No
switch_provisionList[switch_provision]No

ip_domain_lookup_vrfs (iosxe.devices.configuration.system)

Section titled “ip_domain_lookup_vrfs (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
vrfStringRegex: ^[^\s]*$Yes
source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernetNo
source_interface_idAnyString or Integer[min: 0]No

multicast_routing_vrfs (iosxe.devices.configuration.system)

Section titled “multicast_routing_vrfs (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
vrfStringRegex: ^[^\s]*$Yes
distributedBooleantrue, falseNo

archive (iosxe.devices.configuration.system)

Section titled “archive (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
log_config_logging_enableBooleantrue, falseNo
log_config_logging_sizeIntegermin: 1, max: 1000No
maximumIntegermin: 1, max: 14No
pathStringNo
time_periodIntegermin: 1, max: 525600No
write_memoryBooleantrue, falseNo

ip_name_servers_vrf (iosxe.devices.configuration.system)

Section titled “ip_name_servers_vrf (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
vrfStringYes
serversListIPNo

NameTypeConstraintMandatoryDefault Value
authentication_retriesIntegermin: 0, max: 5No
source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernetNo
source_interface_idAnyString or Integer[min: 0]No
time_outIntegermin: 1, max: 120No
versionChoice2No
bulk_modeBooleantrue, falseNo
bulk_mode_window_sizeIntegermin: 131072, max: 1073741824No

ip_sla (iosxe.devices.configuration.system)

Section titled “ip_sla (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
entriesList[entries]No
schedulesList[schedules]No

pnp_profiles (iosxe.devices.configuration.system)

Section titled “pnp_profiles (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
transport_https_ipv4_ipv4_addressIPNo
transport_https_ipv4_portIntegermin: 1, max: 65535No

NameTypeConstraintMandatoryDefault Value
access_classIntegermin: 1, max: 99No
active_session_modulesStringRegex: ^[^\s]*$No
secure_active_session_modulesStringRegex: ^[^\s]*$No
max_connectionsIntegermin: 1, max: 50No
authentication_aaaBooleantrue, falseNo
authentication_aaa_exec_authorizationStringRegex: ^[^\s]*$No
authentication_aaa_login_authenticationStringRegex: ^[^\s]*$No
authentication_aaa_command_authorizationsList[authentication_aaa_command_authorizations]No
authentication_localBooleantrue, falseNo
serverBooleantrue, falseNo
secure_serverBooleantrue, falseNo
secure_trustpointStringRegex: ^[^\s]*$No
tls_versionChoiceTLSv1.0, TLSv1.1, TLSv1.2, TLSv1.3No
client_secure_trustpointStringRegex: ^[^\s]*$No
client_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
client_source_interface_idAnyString or Integer[min: 0]No

ip_hosts (iosxe.devices.configuration.system)

Section titled “ip_hosts (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
ipsListIPYes
vrfStringNo

track_objects (iosxe.devices.configuration.system)

Section titled “track_objects (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
numberIntegermin: 1, max: 1000Yes
ip_sla_numberIntegermin: 1, max: 2147483647No
ip_sla_reachabilityBooleantrue, falseNo

platform (iosxe.devices.configuration.system)

Section titled “platform (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
punt_keepalive_disable_kernel_coreBooleantrue, falseNo
punt_keepalive_settings_fatal_countIntegermin: 15, max: 60No
punt_keepalive_settings_transmit_intervalIntegermin: 2, max: 30No
punt_keepalive_settings_warning_countIntegermin: 10, max: 60No

table_maps (iosxe.devices.configuration.system)

Section titled “table_maps (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
defaultAnyChoice[copy, ignore] or Integer[min: 0, max: 99] or String[Regex: ^.*[\$\%]\{.*$]No
mappingsList[mappings]No

switch_provision (iosxe.devices.configuration.system)

Section titled “switch_provision (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
numberIntegermin: 1, max: 16Yes
provisionStringYes

entries (iosxe.devices.configuration.system.ip_sla)

Section titled “entries (iosxe.devices.configuration.system.ip_sla)”
NameTypeConstraintMandatoryDefault Value
numberIntegerYes
icmp_echo_destinationIPNo
icmp_echo_source_ipIPNo

schedules (iosxe.devices.configuration.system.ip_sla)

Section titled “schedules (iosxe.devices.configuration.system.ip_sla)”
NameTypeConstraintMandatoryDefault Value
entry_numberIntegerYes
lifeIntegerNo
start_time_nowBooleantrue, falseNo

authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)

Section titled “authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)”
NameTypeConstraintMandatoryDefault Value
levelIntegermin: 0, max: 15Yes
nameStringRegex: ^[^\s]*$No

mappings (iosxe.devices.configuration.system.table_maps)

Section titled “mappings (iosxe.devices.configuration.system.table_maps)”
NameTypeConstraintMandatoryDefault Value
fromIntegermin: 0, max: 63Yes
toIntegermin: 0, max: 63Yes

By configuring system-level parameters, you establish the operational foundation, security, and management accessibility for your network devices.

  • The ip_forward_protocol_nd attribute is supported starting with Cisco IOS-XE 17.15.1 and later. This attribute is not supported on older versions of Cisco IOS-XE, as the underlying YANG models use a deprecated forward-protocol container that was replaced with forward-protocol-v2 in IOS-XE 17.15.1.
  • The security_passwords_min_length attribute is only supported on Cisco IOS-XE routers (e.g., Catalyst 8000 series) running IOS-XE 17.15.1 or later. This attribute is not supported on Catalyst switches, as the underlying CLI command (security passwords min-length) is not available on switch platforms. Additionally, older versions of IOS-XE do not include this configuration in their YANG models.

Key Components:

  • Hostname (hostname): Sets the device’s hostname for identification.

  • IP Routing (ip_routing), IPv6 Routing (ipv6_unicast_routing): Enables IP and IPv6 routing capabilities.

  • Domain Name and Lookup (ip_domain_name, ip_domain_lookup, ip_domain_lookup_nsap, ip_domain_lookup_recursive, ip_domain_lookup_vrfs): Configures domain name and enables DNS lookup.

  • Diagnostic Bootup (diagnostic_bootup_level): Sets the diagnostic level during device bootup. Valid values are complete or minimal.

  • Subscriber Templating (subscriber_templating): Enables subscriber templating functionality for dynamic subscriber configuration.

  • Source Routing (ip_source_route): Enables or disables IP source routing.

  • BGP Community Format (ip_bgp_community_new_format): Enables new-format BGP community strings.

  • Login Controls (login_delay, login_on_failure, login_on_failure_log, login_on_success, login_on_success_log): Configures login security and logging.

  • Multicast Routing (ip_multicast_routing, ip_multicast_routing_distributed, multicast_routing_switch, multicast_routing_vrfs): Enables multicast routing features globally and per-VRF. The multicast_routing_vrfs list allows configuring VRF-specific multicast routing with distributed mode support.

  • MTU (mtu): Sets the device’s maximum transmission unit (MTU).

  • HTTP/HTTPS Server (http): Configures HTTP/HTTPS server settings, authentication, access control, and security parameters.

  • TFTP Source Interface (tftp_source_interface_type, tftp_source_interface_id): Configures the source interface for TFTP operations. Supports multiple interface types including Loopback, VLAN, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, and HundredGigabitEthernet.

  • Platform (platform): Configures platform-specific settings including punt keepalive functionality for system stability and kernel core management.

  • MAC Address-Table Aging Time (mac_address_table_aging_time): Configures the global MAC address-table aging time in seconds. Valid values are 0 (disable aging) or 10-1000000 seconds. Default is 300 seconds.

  • Device Classifier (device_classifier): Enables the Cisco Device Classifier feature for network device profiling and visibility.

  • SSH Configuration (ssh): Configures SSH server settings including timeout, authentication retries, version, and bulk-mode for optimizing bulk data transfers with configurable window sizes.

  • CEF Load Balancing (cef_ipv4_include_ports_source, cef_ipv4_include_ports_destination, cef_ipv6_include_ports_source, cef_ipv6_include_ports_destination): Configures Cisco Express Forwarding (CEF) load-sharing algorithms to include Layer 4 port information in hash calculations for improved traffic distribution across Equal-Cost Multi-Path (ECMP) routes.

  • Port-Channel Load Balancing (port_channel_load_balance): Configures the load balancing algorithm used to distribute traffic across port-channel member links.

  • IP RADIUS Source Interface (ip_radius_source_interface_type, ip_radius_source_interface_id, ip_radius_source_interface_vrf) - DNA Advantage Required: Configures the source interface for RADIUS authentication requests. Supports multiple interface types. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability.

  • PnP Profiles (pnp_profiles) - DNA Advantage Required: Configures Plug-and-Play profiles for zero-touch provisioning with transport settings for connecting to PnP servers. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability.

  • IP SLA (ip_sla) - DNA Advantage Required: Configures IP Service Level Agreement monitoring entries and schedules for network performance measurement. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability.

  • Track Objects (track_objects) - DNA Advantage Required: Configures object tracking for monitoring IP SLA operations, interfaces, or other tracked objects. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability.

  • Power Management (power_redundancy_mode_combined, power_supply_autolc_shutdown, power_supply_autolc_priority) - Chassis Platforms Only: Configures chassis power supply redundancy and automatic linecard shutdown behavior. The power_redundancy_mode_combined enables combined power redundancy mode. The power_supply_autolc_shutdown enables automatic linecard shutdown when power budget is exceeded. The power_supply_autolc_priority sets the priority order (1-10) for automatic linecard shutdown. These attributes are only supported on chassis-based platforms (Catalyst 9300/9500/9600 series).

Key Parameters Briefly Explained:

  • hostname: Device name.
  • ip_routing, ipv6_unicast_routing: Enable routing.
  • ip_domain_name, ip_domain_lookup: Domain name and DNS lookup.
  • diagnostic_bootup_level: Diagnostic level during bootup (complete or minimal).
  • subscriber_templating: Enable subscriber templating functionality.
  • ip_source_route: Source routing.
  • ip_bgp_community_new_format: BGP community format.
  • login_delay, login_on_failure, login_on_failure_log, login_on_success, login_on_success_log: Login controls.
  • ip_multicast_routing, ip_multicast_routing_distributed, multicast_routing_switch, multicast_routing_vrfs: Multicast routing global and per-VRF.
  • mtu: MTU setting.
  • http: HTTP/HTTPS server and authentication.
  • ssh: SSH server settings including bulk-mode for optimized data transfers.
  • tftp_source_interface_type, tftp_source_interface_id: TFTP source interface configuration.
  • platform: Platform-specific settings and punt keepalive configuration.
  • mac_address_table_aging_time: Global MAC address-table aging time in seconds (0 or 10-1000000).
  • cef_ipv4_include_ports_source, cef_ipv4_include_ports_destination, cef_ipv6_include_ports_source, cef_ipv6_include_ports_destination: CEF load-sharing algorithm configuration including Layer 4 port-based hashing for IPv4 and IPv6.
  • port_channel_load_balance: Port-channel load balance algorithm selection.
  • device_classifier: Enable device profiling and classification.
  • ip_radius_source_interface_type, ip_radius_source_interface_id, ip_radius_source_interface_vrf: RADIUS source interface (DNA Advantage required).
  • pnp_profiles: Plug-and-Play provisioning profiles (DNA Advantage required).
  • ip_sla: IP SLA monitoring entries and schedules (DNA Advantage required).
  • track_objects: Object tracking for IP SLA and interfaces (DNA Advantage required).
  • power_redundancy_mode_combined: Enable combined power redundancy mode. Catalyst 9400/9500/9600 series only.
  • power_supply_autolc_shutdown: Enable automatic linecard shutdown when power budget is exceeded. Catalyst 9400/9500/9600 series only.
  • power_supply_autolc_priority: Priority order (1-10) for automatic linecard shutdown, list of up to 8 entries. Catalyst 9400/9500/9600 series only.
  • switch_provision: StackWise member provisioning for stack-capable switches (switch <number> provision <model>).

You can use these system parameters to establish device identity, enable routing, configure management access, and enforce security policies. Adjusting these parameters lets you tailor device behavior and management for your network’s operational needs.

The following configuration describes how to set up system parameters on a Cisco IOS-XE device, including hostname, routing, domain name, login controls, SSH server settings with bulk-mode, multicast routing, and HTTP/HTTPS server settings.

hostname router1-xe
ip bgp-community new-format
ip routing
ipv6 unicast-routing
ip source-route
ip domain-lookup
ip domain-name router1_domain
diagnostic bootup level minimal
subscriber templating
login delay 2
login on-failure
login on-failure log
login on-success
login on-success log
ip ssh time-out 120
ip ssh authentication-retries 3
ip ssh bulk-mode
ip ssh bulk-mode window-size 262144
ip multicast-routing
ip multicast-routing distributed
ip multicast-routing vrf VRF1 distributed
device classifier
ip http access-class 10
ip http active-session-modules restconf
ip http secure-active-session-modules restconf
ip http max-connections 25
ip http authentication local
ip http server
ip http secure-server
ip http secure-trustpoint router1_trustpoint
ip http tls-version TLSv1.2
ip http client secure-trustpoint router1_trustpoint
ip http client source-interface Loopback0
ip cef load-sharing algorithm include-ports source destination
ipv6 cef load-sharing algorithm include-ports source destination
port-channel load-balance src-dst-mixed-ip-port
ip tftp source-interface TenGigabitEthernet1/0/1
platform punt-keepalive disable-kernel-core
platform punt-keepalive settings fatal-count 20
platform punt-keepalive settings transmit-interval 10
platform punt-keepalive settings warning-count 15
ip radius source-interface Loopback10
!
pnp profile CLOUD_PNP_PROFILE
transport https ipv4 192.0.2.50 port 443
!
ip sla 500
icmp-echo 192.168.1.1
ip sla schedule 500 life 3600 start-time now
!
track 100 ip sla 500 reachability
!
! Chassis power management (C9400/9500/9600 only)
power redundancy-mode combined
power supply autoLC shutdown
power supply autoLC priority 1 5 3
switch 1 provision c9300-24p
switch 2 provision c9300-24p

The following YAML code sets up system parameters on IOS-XE devices, showing SSH bulk-mode configuration, local and AAA authentication for HTTP, and switch-specific settings.

iosxe:
devices:
- name: Router1
configuration:
system:
hostname: router1-xe
ip_bgp_community_new_format: true
ip_routing: true
ipv6_unicast_routing: true
ip_source_route: true
ip_domain_lookup: true
ip_domain_name: router1_domain
diagnostic_bootup_level: minimal
subscriber_templating: true
login_delay: 2
login_on_failure: true
login_on_failure_log: true
login_on_success: true
login_on_success_log: true
ip_multicast_routing: true
ip_multicast_routing_distributed: true
ip_domain_lookup_vrfs:
- vrf: VRF1
source_interface_type: GigabitEthernet
source_interface_id: 1/0/5
authentication_mac_move_permit: true
authentication_mac_move_deny_uncontrolled: true
ssh:
authentication_retries: 3
time_out: 120
bulk_mode: true
bulk_mode_window_size: 262144
http:
access_class: 10
active_session_modules: restconf
secure_active_session_modules: restconf
max_connections: 25
authentication_local: true
server: true
secure_server: true
secure_trustpoint: router1_trustpoint
tls_version: TLSv1.2
client_secure_trustpoint: router1_trustpoint
client_source_interface: Loopback0
cef_ipv4_include_ports_source: true
cef_ipv4_include_ports_destination: true
cef_ipv6_include_ports_source: true
cef_ipv6_include_ports_destination: true
port_channel_load_balance: src-dst-mixed-ip-port
tftp_source_interface_type: TenGigabitEthernet
tftp_source_interface_id: 1/0/1
platform:
punt_keepalive_disable_kernel_core: true
punt_keepalive_settings_fatal_count: 20
punt_keepalive_settings_transmit_interval: 10
punt_keepalive_settings_warning_count: 15
- name: Router2
configuration:
system:
hostname: router2-xe
ip_bgp_community_new_format: true
ip_routing: true
ipv6_unicast_routing: true
ip_source_route: true
ip_domain_lookup_nsap: true
ip_domain_name: router2_domain
login_delay: 2
login_on_failure: true
login_on_failure_log: true
login_on_success: true
login_on_success_log: true
ip_multicast_routing: true
ip_multicast_routing_distributed: true
http:
access_class: 20
active_session_modules: restconf
secure_active_session_modules: restconf
max_connections: 50
authentication_aaa: true
authentication_aaa_exec_authorization: test_author_group
authentication_aaa_login_authentication: test_authen_group
authentication_aaa_command_authorizations:
- level: 15
name: test1
server: true
secure_server: true
secure_trustpoint: router2_trustpoint
tls_version: TLSv1.2
client_secure_trustpoint: router2_trustpoint
client_source_interface: Loopback1
- name: Switch1
configuration:
system:
hostname: switch1-xe
ip_bgp_community_new_format: true
ip_routing: true
mtu: 1600
ipv6_unicast_routing: true
ip_source_route: true
ip_domain_lookup_recursive: true
ip_domain_name: switch1_domain
login_delay: 2
login_on_failure: true
login_on_failure_log: true
login_on_success: true
login_on_success_log: true
multicast_routing_switch: true
http:
access_class: 30
active_session_modules: restconf
secure_active_session_modules: restconf
max_connections: 100
authentication_local: true
server: true
secure_server: true
secure_trustpoint: switch1_trustpoint
tls_version: TLSv1.2
client_secure_trustpoint: switch1_trustpoint
client_source_interface: Loopback2
cef_ipv4_include_ports_source: true
cef_ipv4_include_ports_destination: false
cef_ipv6_include_ports_source: false
cef_ipv6_include_ports_destination: true
port_channel_load_balance: src-dst-mac
tftp_source_interface_type: Vlan
tftp_source_interface_id: 100
mac_address_table_aging_time: 14400
- name: Router3
configuration:
system:
hostname: router3-xe
device_classifier: true
multicast_routing_vrfs:
- vrf: VRF1
distributed: true
ip_radius_source_interface_type: Loopback
ip_radius_source_interface_id: "10"
track_objects:
- number: 100
ip_sla_number: 500
ip_sla_reachability: true
pnp_profiles:
- name: CLOUD_PNP_PROFILE
transport_https_ipv4_ipv4_address: 192.0.2.50
transport_https_ipv4_port: 443
ip_sla:
entries:
- number: 500
icmp_echo_destination: 192.168.1.1
schedules:
- entry_number: 500
start_time_now: true
life: 3600
switch_provision:
- number: 1
provision: c9300-24p
- number: 2
provision: c9300-24p
- name: ChassisSwitch1
configuration:
system:
hostname: chassis-sw1
power_redundancy_mode_combined: true
power_supply_autolc_shutdown: true
power_supply_autolc_priority:
- 1
- 5
- 3

System configuration encompasses fundamental device-level settings that control core operational behaviors including hostname identification, IP and IPv6 routing enablement, domain name resolution, login security controls, SSH server parameters, and HTTP/HTTPS server parameters for management access. It provides comprehensive control over essential network services such as multicast routing, source routing, domain lookup, and authentication methods while supporting both local and AAA-based authentication mechanisms for management interfaces. SSH configuration includes bulk-mode optimization for efficient bulk data transfers with configurable window sizes. System configuration is critical for establishing the basic operational foundation of network devices, ensuring proper identification, connectivity, security posture, and management accessibility across the network infrastructure.

Diagram
NameTypeConstraintMandatoryDefault Value
systemClass[system]No

NameTypeConstraintMandatoryDefault Value
hostnameStringRegex: ^[^\s]*$No
ip_bgp_community_new_formatBooleantrue, falseNo
ip_routingBooleantrue, falseNo
ipv6_unicast_routingBooleantrue, falseNo
mtuIntegermin: 1500, max: 9198No
ip_source_routeBooleantrue, falseNo
ip_domain_lookupBooleantrue, falseNo
ip_domain_lookup_nsapBooleantrue, falseNo
ip_domain_lookup_recursiveBooleantrue, falseNo
ip_domain_lookup_vrfsList[ip_domain_lookup_vrfs]No
ip_domain_nameStringRegex: ^[^\s]*$No
login_delayIntegermin: 1, max: 10No
login_on_failureBooleantrue, falseNo
login_on_failure_logBooleantrue, falseNo
login_on_successBooleantrue, falseNo
login_on_success_logBooleantrue, falseNo
ip_multicast_routingBooleantrue, falseNo
multicast_routing_switchBooleantrue, falseNo
ip_multicast_routing_distributedBooleantrue, falseNo
multicast_routing_vrfsList[multicast_routing_vrfs]No
ipv6_multicast_routingBooleantrue, falseNo
access_session_mac_move_denyBooleantrue, falseNo
archiveClass[archive]No
boot_system_bootfilesListStringNo
boot_system_flash_filesListStringNo
cisp_enableBooleantrue, falseNo
control_plane_service_policy_inputStringNo
diagnostic_bootup_levelChoicecomplete, minimalNo
enable_secretStringNo
enable_secret_levelIntegermin: 0, max: 255No
enable_secret_typeChoice0, 4, 5, 8, 9No
epm_loggingBooleantrue, falseNo
ip_domain_lookup_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernetNo
ip_domain_lookup_source_interface_idAnyString or Integer[min: 0]No
ip_forward_protocol_ndBooleantrue, falseNo
ip_name_serversListStringNo
ip_name_servers_vrfList[ip_name_servers_vrf]No
ip_radius_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernetNo
ip_radius_source_interface_idAnyString or Integer[min: 0]No
ip_radius_source_interface_vrfStringNo
ip_scp_server_enableBooleantrue, falseNo
sshClass[ssh]No
ip_tacacs_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernetNo
ip_tacacs_source_interface_idAnyString or Integer[min: 0]No
ip_slaClass[ip_sla]No
ip_tacacs_source_interface_vrfStringNo
memory_free_low_watermark_processorIntegermin: 1, max: 3994575No
pnp_profilesList[pnp_profiles]No
redundancyBooleantrue, falseNo
redundancy_modeChoicenone, rpr, rpr-plus, ssoNo
transceiver_type_all_monitoringBooleantrue, falseNo
httpClass[http]No
ip_hostsList[ip_hosts]No
subscriber_templatingBooleantrue, falseNo
call_home_contact_emailStringNo
call_home_cisco_tac_1_profile_activeBooleantrue, falseNo
call_home_cisco_tac_1_destination_transport_methodChoiceemail, httpNo
ip_ftp_passiveBooleantrue, falseNo
tftp_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernetNo
tftp_source_interface_idAnyString or Integer[min: 0]No
multilink_ppp_bundle_nameStringNo
ip_nbar_classification_dns_classify_by_domainBooleantrue, falseNo
track_objectsList[track_objects]No
ip_multicast_route_limitIntegermin: 1, max: 2147483647No
ip_domain_list_namesListStringNo
ip_domain_list_vrf_domainStringNo
ip_domain_list_vrfStringNo
ethernet_cfm_alarm_config_delayIntegermin: 2500, max: 30000No
ethernet_cfm_alarm_config_resetIntegermin: 2500, max: 30000No
standby_redirectsChoicenone, enable, disableNo
security_passwords_min_lengthIntegermin: 1, max: 16No
platformClass[platform]No
authentication_mac_move_permitBooleantrue, falseNo
authentication_mac_move_deny_uncontrolledBooleantrue, falseNo
ip_default_gatewayStringNo
device_classifierBooleantrue, falseNo
table_mapsList[table_maps]No

ip_domain_lookup_vrfs (iosxe.devices.configuration.system)

Section titled “ip_domain_lookup_vrfs (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
vrfStringRegex: ^[^\s]*$Yes
source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernetNo
source_interface_idAnyString or Integer[min: 0]No

multicast_routing_vrfs (iosxe.devices.configuration.system)

Section titled “multicast_routing_vrfs (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
vrfStringRegex: ^[^\s]*$Yes
distributedBooleantrue, falseNo

archive (iosxe.devices.configuration.system)

Section titled “archive (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
log_config_logging_enableBooleantrue, falseNo
log_config_logging_sizeIntegermin: 1, max: 1000No
maximumIntegermin: 1, max: 14No
pathStringNo
time_periodIntegermin: 1, max: 525600No
write_memoryBooleantrue, falseNo

ip_name_servers_vrf (iosxe.devices.configuration.system)

Section titled “ip_name_servers_vrf (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
vrfStringYes
serversListStringNo

NameTypeConstraintMandatoryDefault Value
authentication_retriesIntegermin: 0, max: 5No
source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernetNo
source_interface_idAnyString or Integer[min: 0]No
time_outIntegermin: 1, max: 120No
versionChoice2No
bulk_modeBooleantrue, falseNo
bulk_mode_window_sizeIntegermin: 131072, max: 1073741824No

ip_sla (iosxe.devices.configuration.system)

Section titled “ip_sla (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
entriesList[entries]No
schedulesList[schedules]No

pnp_profiles (iosxe.devices.configuration.system)

Section titled “pnp_profiles (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
transport_https_ipv4_ipv4_addressStringNo
transport_https_ipv4_portIntegermin: 1, max: 65535No

NameTypeConstraintMandatoryDefault Value
access_classIntegermin: 1, max: 99No
active_session_modulesStringRegex: ^[^\s]*$No
secure_active_session_modulesStringRegex: ^[^\s]*$No
max_connectionsIntegermin: 1, max: 50No
authentication_aaaBooleantrue, falseNo
authentication_aaa_exec_authorizationStringRegex: ^[^\s]*$No
authentication_aaa_login_authenticationStringRegex: ^[^\s]*$No
authentication_aaa_command_authorizationsList[authentication_aaa_command_authorizations]No
authentication_localBooleantrue, falseNo
serverBooleantrue, falseNo
secure_serverBooleantrue, falseNo
secure_trustpointStringRegex: ^[^\s]*$No
tls_versionChoiceTLSv1.0, TLSv1.1, TLSv1.2, TLSv1.3No
client_secure_trustpointStringRegex: ^[^\s]*$No
client_source_interface_typeChoiceLoopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannelNo
client_source_interface_idAnyString or Integer[min: 0]No

ip_hosts (iosxe.devices.configuration.system)

Section titled “ip_hosts (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
ipsListIPYes
vrfStringNo

track_objects (iosxe.devices.configuration.system)

Section titled “track_objects (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
numberIntegermin: 1, max: 1000Yes
ip_sla_numberIntegermin: 1, max: 2147483647No
ip_sla_reachabilityBooleantrue, falseNo

platform (iosxe.devices.configuration.system)

Section titled “platform (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
punt_keepalive_disable_kernel_coreBooleantrue, falseNo
punt_keepalive_settings_fatal_countIntegermin: 15, max: 60No
punt_keepalive_settings_transmit_intervalIntegermin: 2, max: 30No
punt_keepalive_settings_warning_countIntegermin: 10, max: 60No

table_maps (iosxe.devices.configuration.system)

Section titled “table_maps (iosxe.devices.configuration.system)”
NameTypeConstraintMandatoryDefault Value
nameStringYes
defaultAnyChoice[copy, ignore] or Integer[min: 0, max: 99] or String[Regex: ^.*[\$\%]\{.*$]No
mappingsList[mappings]No

entries (iosxe.devices.configuration.system.ip_sla)

Section titled “entries (iosxe.devices.configuration.system.ip_sla)”
NameTypeConstraintMandatoryDefault Value
numberIntegerYes
icmp_echo_destinationStringNo
icmp_echo_source_ipStringNo

schedules (iosxe.devices.configuration.system.ip_sla)

Section titled “schedules (iosxe.devices.configuration.system.ip_sla)”
NameTypeConstraintMandatoryDefault Value
entry_numberIntegerYes
lifeIntegerNo
start_time_nowBooleantrue, falseNo

authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)

Section titled “authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)”
NameTypeConstraintMandatoryDefault Value
levelIntegermin: 0, max: 15Yes
nameStringRegex: ^[^\s]*$No

mappings (iosxe.devices.configuration.system.table_maps)

Section titled “mappings (iosxe.devices.configuration.system.table_maps)”
NameTypeConstraintMandatoryDefault Value
fromIntegermin: 0, max: 63Yes
toIntegermin: 0, max: 63Yes

By configuring system-level parameters, you establish the operational foundation, security, and management accessibility for your network devices.

Key Components:

  • Hostname (hostname): Sets the device’s hostname for identification.

  • IP Routing (ip_routing), IPv6 Routing (ipv6_unicast_routing): Enables IP and IPv6 routing capabilities.

  • Domain Name and Lookup (ip_domain_name, ip_domain_lookup, ip_domain_lookup_nsap, ip_domain_lookup_recursive, ip_domain_lookup_vrfs): Configures domain name and enables DNS lookup.

  • Source Routing (ip_source_route): Enables or disables IP source routing.

  • BGP Community Format (ip_bgp_community_new_format): Enables new-format BGP community strings.

  • Login Controls (login_delay, login_on_failure, login_on_failure_log, login_on_success, login_on_success_log): Configures login security and logging.

  • Multicast Routing (ip_multicast_routing, ip_multicast_routing_distributed, multicast_routing_switch): Enables multicast routing features.

  • MTU (mtu): Sets the device’s maximum transmission unit (MTU).

  • HTTP/HTTPS Server (http): Configures HTTP/HTTPS server settings, authentication, access control, and security parameters.

  • TFTP Source Interface (tftp_source_interface_type, tftp_source_interface_id): Configures the source interface for TFTP operations. Supports multiple interface types including Loopback, VLAN, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, and HundredGigabitEthernet.

  • Platform (platform): Configures platform-specific settings including punt keepalive functionality for system stability and kernel core management.

  • SSH Configuration (ssh): Configures SSH server settings including timeout, authentication retries, version, and bulk-mode for optimizing bulk data transfers with configurable window sizes.

Key Parameters Briefly Explained:

  • hostname: Device name.
  • ip_routing, ipv6_unicast_routing: Enable routing.
  • ip_domain_name, ip_domain_lookup: Domain name and DNS lookup.
  • ip_source_route: Source routing.
  • ip_bgp_community_new_format: BGP community format.
  • login_delay, login_on_failure, login_on_failure_log, login_on_success, login_on_success_log: Login controls.
  • ip_multicast_routing, ip_multicast_routing_distributed, multicast_routing_switch: Multicast routing.
  • mtu: MTU setting.
  • http: HTTP/HTTPS server and authentication.
  • ssh: SSH server settings including bulk-mode for optimized data transfers.
  • tftp_source_interface_type, tftp_source_interface_id: TFTP source interface configuration.
  • platform: Platform-specific settings and punt keepalive configuration.

You can use these system parameters to establish device identity, enable routing, configure management access, and enforce security policies. Adjusting these parameters lets you tailor device behavior and management for your network’s operational needs.

The following configuration describes how to set up system parameters on a Cisco IOS-XE device, including hostname, routing, domain name, login controls, SSH server settings with bulk-mode, multicast routing, and HTTP/HTTPS server settings.

hostname router1-xe
ip bgp-community new-format
ip routing
ipv6 unicast-routing
ip source-route
ip domain-lookup
ip domain-name router1_domain
login delay 2
login on-failure
login on-failure log
login on-success
login on-success log
ip ssh time-out 120
ip ssh authentication-retries 3
ip ssh bulk-mode
ip ssh bulk-mode window-size 262144
ip multicast-routing
ip multicast-routing distributed
ip http access-class 10
ip http active-session-modules restconf
ip http secure-active-session-modules restconf
ip http max-connections 25
ip http authentication local
ip http server
ip http secure-server
ip http secure-trustpoint router1_trustpoint
ip http tls-version TLSv1.2
ip http client secure-trustpoint router1_trustpoint
ip http client source-interface Loopback0
ip tftp source-interface TenGigabitEthernet1/0/1
platform punt-keepalive disable-kernel-core
platform punt-keepalive settings fatal-count 20
platform punt-keepalive settings transmit-interval 10
platform punt-keepalive settings warning-count 15

The following YAML code sets up system parameters on IOS-XE devices, showing SSH bulk-mode configuration, local and AAA authentication for HTTP, and switch-specific settings.

iosxe:
devices:
- name: Router1
configuration:
system:
hostname: router1-xe
ip_bgp_community_new_format: true
ip_routing: true
ipv6_unicast_routing: true
ip_source_route: true
ip_domain_lookup: true
ip_domain_name: router1_domain
login_delay: 2
login_on_failure: true
login_on_failure_log: true
login_on_success: true
login_on_success_log: true
ip_multicast_routing: true
ip_multicast_routing_distributed: true
ip_domain_lookup_vrfs:
- vrf: VRF1
source_interface_type: GigabitEthernet
source_interface_id: 1/0/5
authentication_mac_move_permit: true
authentication_mac_move_deny_uncontrolled: true
ssh:
authentication_retries: 3
time_out: 120
bulk_mode: true
bulk_mode_window_size: 262144
http:
access_class: 10
active_session_modules: restconf
secure_active_session_modules: restconf
max_connections: 25
authentication_local: true
server: true
secure_server: true
secure_trustpoint: router1_trustpoint
tls_version: TLSv1.2
client_secure_trustpoint: router1_trustpoint
client_source_interface: Loopback0
tftp_source_interface_type: TenGigabitEthernet
tftp_source_interface_id: 1/0/1
platform:
punt_keepalive_disable_kernel_core: true
punt_keepalive_settings_fatal_count: 20
punt_keepalive_settings_transmit_interval: 10
punt_keepalive_settings_warning_count: 15
- name: Router2
configuration:
system:
hostname: router2-xe
ip_bgp_community_new_format: true
ip_routing: true
ipv6_unicast_routing: true
ip_source_route: true
ip_domain_lookup_nsap: true
ip_domain_name: router2_domain
login_delay: 2
login_on_failure: true
login_on_failure_log: true
login_on_success: true
login_on_success_log: true
ip_multicast_routing: true
ip_multicast_routing_distributed: true
http:
access_class: 20
active_session_modules: restconf
secure_active_session_modules: restconf
max_connections: 50
authentication_aaa: true
authentication_aaa_exec_authorization: test_author_group
authentication_aaa_login_authentication: test_authen_group
authentication_aaa_command_authorizations:
- level: 15
name: test1
server: true
secure_server: true
secure_trustpoint: router2_trustpoint
tls_version: TLSv1.2
client_secure_trustpoint: router2_trustpoint
client_source_interface: Loopback1
- name: Switch1
configuration:
system:
hostname: switch1-xe
ip_bgp_community_new_format: true
ip_routing: true
mtu: 1600
ipv6_unicast_routing: true
ip_source_route: true
ip_domain_lookup_recursive: true
ip_domain_name: switch1_domain
login_delay: 2
login_on_failure: true
login_on_failure_log: true
login_on_success: true
login_on_success_log: true
multicast_routing_switch: true
http:
access_class: 30
active_session_modules: restconf
secure_active_session_modules: restconf
max_connections: 100
authentication_local: true
server: true
secure_server: true
secure_trustpoint: switch1_trustpoint
tls_version: TLSv1.2
client_secure_trustpoint: switch1_trustpoint
client_source_interface: Loopback2
tftp_source_interface_type: Vlan
tftp_source_interface_id: 100