System
System configuration encompasses fundamental device-level settings that control core operational behaviors including hostname identification, IP and IPv6 routing enablement, domain name resolution, login security controls, SSH server parameters, and HTTP/HTTPS server parameters for management access. It provides comprehensive control over essential network services such as multicast routing, source routing, domain lookup, and authentication methods while supporting both local and AAA-based authentication mechanisms for management interfaces. SSH configuration includes bulk-mode optimization for efficient bulk data transfers with configurable window sizes. System configuration is critical for establishing the basic operational foundation of network devices, ensuring proper identification, connectivity, security posture, and management accessibility across the network infrastructure.
Diagram
Section titled “Diagram”Classes
Section titled “Classes”configuration (iosxe.devices)
Section titled “configuration (iosxe.devices)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| system | Class | [system] | No |
system (iosxe.devices.configuration)
Section titled “system (iosxe.devices.configuration)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| hostname | String | Regex: ^[^\s]*$ | No | |
| ip_bgp_community_new_format | Boolean | true, false | No | |
| ip_routing | Boolean | true, false | No | |
| ipv6_unicast_routing | Boolean | true, false | No | |
| mtu | Integer | min: 1500, max: 9198 | No | |
| ip_source_route | Boolean | true, false | No | |
| ip_domain_lookup | Boolean | true, false | No | |
| ip_domain_lookup_nsap | Boolean | true, false | No | |
| ip_domain_lookup_recursive | Boolean | true, false | No | |
| ip_domain_lookup_vrfs | List | [ip_domain_lookup_vrfs] | No | |
| ip_domain_name | String | Regex: ^[^\s]*$ | No | |
| login_delay | Integer | min: 1, max: 10 | No | |
| login_on_failure | Boolean | true, false | No | |
| login_on_failure_log | Boolean | true, false | No | |
| login_on_success | Boolean | true, false | No | |
| login_on_success_log | Boolean | true, false | No | |
| ip_multicast_routing | Boolean | true, false | No | |
| multicast_routing_switch | Boolean | true, false | No | |
| ip_multicast_routing_distributed | Boolean | true, false | No | |
| multicast_routing_vrfs | List | [multicast_routing_vrfs] | No | |
| ipv6_multicast_routing | Boolean | true, false | No | |
| access_session_mac_move_deny | Boolean | true, false | No | |
| archive | Class | [archive] | No | |
| boot_system_bootfiles | List | String | No | |
| boot_system_flash_files | List | String | No | |
| cisp_enable | Boolean | true, false | No | |
| control_plane_service_policy_input | String | No | ||
| diagnostic_bootup_level | Choice | complete, minimal | No | |
| enable_secret | String | No | ||
| enable_secret_level | Integer | min: 0, max: 255 | No | |
| enable_secret_type | Choice | 0, 4, 5, 8, 9 | No | |
| epm_logging | Boolean | true, false | No | |
| ip_domain_lookup_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet | No | |
| ip_domain_lookup_source_interface_id | Any | String or Integer[min: 0] | No | |
| ip_forward_protocol_nd | Boolean | true, false | No | |
| ip_name_servers | List | IP | No | |
| ip_name_servers_vrf | List | [ip_name_servers_vrf] | No | |
| ip_radius_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet | No | |
| ip_radius_source_interface_id | Any | String or Integer[min: 0] | No | |
| ip_radius_source_interface_vrf | String | No | ||
| ip_scp_server_enable | Boolean | true, false | No | |
| ssh | Class | [ssh] | No | |
| ip_tacacs_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet | No | |
| ip_tacacs_source_interface_id | Any | String or Integer[min: 0] | No | |
| ip_sla | Class | [ip_sla] | No | |
| ip_tacacs_source_interface_vrf | String | No | ||
| memory_free_low_watermark_processor | Integer | min: 1, max: 3994575 | No | |
| pnp_profiles | List | [pnp_profiles] | No | |
| redundancy | Boolean | true, false | No | |
| redundancy_mode | Choice | none, rpr, rpr-plus, sso | No | |
| transceiver_type_all_monitoring | Boolean | true, false | No | |
| http | Class | [http] | No | |
| ip_hosts | List | [ip_hosts] | No | |
| subscriber_templating | Boolean | true, false | No | |
| call_home_contact_email | String | No | ||
| call_home_cisco_tac_1_profile_active | Boolean | true, false | No | |
| call_home_cisco_tac_1_destination_transport_method | Choice | email, http | No | |
| ip_ftp_passive | Boolean | true, false | No | |
| tftp_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet | No | |
| tftp_source_interface_id | Any | String or Integer[min: 0] | No | |
| multilink_ppp_bundle_name | String | No | ||
| ip_nbar_classification_dns_classify_by_domain | Boolean | true, false | No | |
| track_objects | List | [track_objects] | No | |
| ip_multicast_route_limit | Integer | min: 1, max: 2147483647 | No | |
| ip_domain_list_names | List | String | No | |
| ip_domain_list_vrf_domain | String | No | ||
| ip_domain_list_vrf | String | No | ||
| ethernet_cfm_alarm_config_delay | Integer | min: 2500, max: 30000 | No | |
| ethernet_cfm_alarm_config_reset | Integer | min: 2500, max: 30000 | No | |
| standby_redirects | Choice | none, enable, disable | No | |
| security_passwords_min_length | Integer | min: 1, max: 16 | No | |
| platform | Class | [platform] | No | |
| cef_ipv4_include_ports_source | Boolean | true, false | No | |
| cef_ipv4_include_ports_destination | Boolean | true, false | No | |
| cef_ipv6_include_ports_source | Boolean | true, false | No | |
| cef_ipv6_include_ports_destination | Boolean | true, false | No | |
| port_channel_load_balance | Choice | dst-ip, dst-mac, dst-mixed-ip-port, dst-port, mpls, src-dst-ip, src-dst-mac, src-dst-mixed-ip-port, src-dst-port, src-ip, src-mac, src-mixed-ip-port, src-port, vlan-dst-ip, vlan-dst-mixed-ip-port, vlan-src-dst-ip, vlan-src-dst-mixed-ip-port, vlan-src-ip, vlan-src-mixed-ip-port | No | |
| authentication_mac_move_permit | Boolean | true, false | No | |
| authentication_mac_move_deny_uncontrolled | Boolean | true, false | No | |
| ip_default_gateway | IP | No | ||
| mac_address_table_aging_time | Any | Integer[min: 0, max: 0] or Integer[min: 10, max: 1000000] or String[Regex: ^.*[\$\%]\{.*$] | No | |
| device_classifier | Boolean | true, false | No | |
| table_maps | List | [table_maps] | No | |
| power_redundancy_mode_combined | Boolean | true, false | No | |
| power_supply_autolc_shutdown | Boolean | true, false | No | |
| power_supply_autolc_priority | List | Integer[min: 1, max: 10] | No | |
| switch_provision | List | [switch_provision] | No |
ip_domain_lookup_vrfs (iosxe.devices.configuration.system)
Section titled “ip_domain_lookup_vrfs (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| vrf | String | Regex: ^[^\s]*$ | Yes | |
| source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet | No | |
| source_interface_id | Any | String or Integer[min: 0] | No |
multicast_routing_vrfs (iosxe.devices.configuration.system)
Section titled “multicast_routing_vrfs (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| vrf | String | Regex: ^[^\s]*$ | Yes | |
| distributed | Boolean | true, false | No |
archive (iosxe.devices.configuration.system)
Section titled “archive (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| log_config_logging_enable | Boolean | true, false | No | |
| log_config_logging_size | Integer | min: 1, max: 1000 | No | |
| maximum | Integer | min: 1, max: 14 | No | |
| path | String | No | ||
| time_period | Integer | min: 1, max: 525600 | No | |
| write_memory | Boolean | true, false | No |
ip_name_servers_vrf (iosxe.devices.configuration.system)
Section titled “ip_name_servers_vrf (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| vrf | String | Yes | ||
| servers | List | IP | No |
ssh (iosxe.devices.configuration.system)
Section titled “ssh (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| authentication_retries | Integer | min: 0, max: 5 | No | |
| source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet | No | |
| source_interface_id | Any | String or Integer[min: 0] | No | |
| time_out | Integer | min: 1, max: 120 | No | |
| version | Choice | 2 | No | |
| bulk_mode | Boolean | true, false | No | |
| bulk_mode_window_size | Integer | min: 131072, max: 1073741824 | No |
ip_sla (iosxe.devices.configuration.system)
Section titled “ip_sla (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| entries | List | [entries] | No | |
| schedules | List | [schedules] | No |
pnp_profiles (iosxe.devices.configuration.system)
Section titled “pnp_profiles (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | Yes | ||
| transport_https_ipv4_ipv4_address | IP | No | ||
| transport_https_ipv4_port | Integer | min: 1, max: 65535 | No |
http (iosxe.devices.configuration.system)
Section titled “http (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| access_class | Integer | min: 1, max: 99 | No | |
| active_session_modules | String | Regex: ^[^\s]*$ | No | |
| secure_active_session_modules | String | Regex: ^[^\s]*$ | No | |
| max_connections | Integer | min: 1, max: 50 | No | |
| authentication_aaa | Boolean | true, false | No | |
| authentication_aaa_exec_authorization | String | Regex: ^[^\s]*$ | No | |
| authentication_aaa_login_authentication | String | Regex: ^[^\s]*$ | No | |
| authentication_aaa_command_authorizations | List | [authentication_aaa_command_authorizations] | No | |
| authentication_local | Boolean | true, false | No | |
| server | Boolean | true, false | No | |
| secure_server | Boolean | true, false | No | |
| secure_trustpoint | String | Regex: ^[^\s]*$ | No | |
| tls_version | Choice | TLSv1.0, TLSv1.1, TLSv1.2, TLSv1.3 | No | |
| client_secure_trustpoint | String | Regex: ^[^\s]*$ | No | |
| client_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, FiftyGigabitEthernet, HundredGigabitEthernet, PortChannel | No | |
| client_source_interface_id | Any | String or Integer[min: 0] | No |
ip_hosts (iosxe.devices.configuration.system)
Section titled “ip_hosts (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | Yes | ||
| ips | List | IP | Yes | |
| vrf | String | No |
track_objects (iosxe.devices.configuration.system)
Section titled “track_objects (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| number | Integer | min: 1, max: 1000 | Yes | |
| ip_sla_number | Integer | min: 1, max: 2147483647 | No | |
| ip_sla_reachability | Boolean | true, false | No |
platform (iosxe.devices.configuration.system)
Section titled “platform (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| punt_keepalive_disable_kernel_core | Boolean | true, false | No | |
| punt_keepalive_settings_fatal_count | Integer | min: 15, max: 60 | No | |
| punt_keepalive_settings_transmit_interval | Integer | min: 2, max: 30 | No | |
| punt_keepalive_settings_warning_count | Integer | min: 10, max: 60 | No |
table_maps (iosxe.devices.configuration.system)
Section titled “table_maps (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | Yes | ||
| default | Any | Choice[copy, ignore] or Integer[min: 0, max: 99] or String[Regex: ^.*[\$\%]\{.*$] | No | |
| mappings | List | [mappings] | No |
switch_provision (iosxe.devices.configuration.system)
Section titled “switch_provision (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| number | Integer | min: 1, max: 16 | Yes | |
| provision | String | Yes |
entries (iosxe.devices.configuration.system.ip_sla)
Section titled “entries (iosxe.devices.configuration.system.ip_sla)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| number | Integer | Yes | ||
| icmp_echo_destination | IP | No | ||
| icmp_echo_source_ip | IP | No |
schedules (iosxe.devices.configuration.system.ip_sla)
Section titled “schedules (iosxe.devices.configuration.system.ip_sla)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| entry_number | Integer | Yes | ||
| life | Integer | No | ||
| start_time_now | Boolean | true, false | No |
authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)
Section titled “authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| level | Integer | min: 0, max: 15 | Yes | |
| name | String | Regex: ^[^\s]*$ | No |
mappings (iosxe.devices.configuration.system.table_maps)
Section titled “mappings (iosxe.devices.configuration.system.table_maps)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| from | Integer | min: 0, max: 63 | Yes | |
| to | Integer | min: 0, max: 63 | Yes |
By configuring system-level parameters, you establish the operational foundation, security, and management accessibility for your network devices.
Guidelines and Limitations
Section titled “Guidelines and Limitations”- The
ip_forward_protocol_ndattribute is supported starting with Cisco IOS-XE 17.15.1 and later. This attribute is not supported on older versions of Cisco IOS-XE, as the underlying YANG models use a deprecatedforward-protocolcontainer that was replaced withforward-protocol-v2in IOS-XE 17.15.1. - The
security_passwords_min_lengthattribute is only supported on Cisco IOS-XE routers (e.g., Catalyst 8000 series) running IOS-XE 17.15.1 or later. This attribute is not supported on Catalyst switches, as the underlying CLI command (security passwords min-length) is not available on switch platforms. Additionally, older versions of IOS-XE do not include this configuration in their YANG models.
System Parameters
Section titled “System Parameters”Key Components:
-
Hostname (
hostname): Sets the device’s hostname for identification. -
IP Routing (
ip_routing), IPv6 Routing (ipv6_unicast_routing): Enables IP and IPv6 routing capabilities. -
Domain Name and Lookup (
ip_domain_name,ip_domain_lookup,ip_domain_lookup_nsap,ip_domain_lookup_recursive,ip_domain_lookup_vrfs): Configures domain name and enables DNS lookup. -
Diagnostic Bootup (
diagnostic_bootup_level): Sets the diagnostic level during device bootup. Valid values arecompleteorminimal. -
Subscriber Templating (
subscriber_templating): Enables subscriber templating functionality for dynamic subscriber configuration. -
Source Routing (
ip_source_route): Enables or disables IP source routing. -
BGP Community Format (
ip_bgp_community_new_format): Enables new-format BGP community strings. -
Login Controls (
login_delay,login_on_failure,login_on_failure_log,login_on_success,login_on_success_log): Configures login security and logging. -
Multicast Routing (
ip_multicast_routing,ip_multicast_routing_distributed,multicast_routing_switch,multicast_routing_vrfs): Enables multicast routing features globally and per-VRF. Themulticast_routing_vrfslist allows configuring VRF-specific multicast routing with distributed mode support. -
MTU (
mtu): Sets the device’s maximum transmission unit (MTU). -
HTTP/HTTPS Server (
http): Configures HTTP/HTTPS server settings, authentication, access control, and security parameters. -
TFTP Source Interface (
tftp_source_interface_type,tftp_source_interface_id): Configures the source interface for TFTP operations. Supports multiple interface types including Loopback, VLAN, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, and HundredGigabitEthernet. -
Platform (
platform): Configures platform-specific settings including punt keepalive functionality for system stability and kernel core management. -
MAC Address-Table Aging Time (
mac_address_table_aging_time): Configures the global MAC address-table aging time in seconds. Valid values are 0 (disable aging) or 10-1000000 seconds. Default is 300 seconds. -
Device Classifier (
device_classifier): Enables the Cisco Device Classifier feature for network device profiling and visibility. -
SSH Configuration (
ssh): Configures SSH server settings including timeout, authentication retries, version, and bulk-mode for optimizing bulk data transfers with configurable window sizes. -
CEF Load Balancing (
cef_ipv4_include_ports_source,cef_ipv4_include_ports_destination,cef_ipv6_include_ports_source,cef_ipv6_include_ports_destination): Configures Cisco Express Forwarding (CEF) load-sharing algorithms to include Layer 4 port information in hash calculations for improved traffic distribution across Equal-Cost Multi-Path (ECMP) routes. -
Port-Channel Load Balancing (
port_channel_load_balance): Configures the load balancing algorithm used to distribute traffic across port-channel member links. -
IP RADIUS Source Interface (
ip_radius_source_interface_type,ip_radius_source_interface_id,ip_radius_source_interface_vrf) - DNA Advantage Required: Configures the source interface for RADIUS authentication requests. Supports multiple interface types. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability. -
PnP Profiles (
pnp_profiles) - DNA Advantage Required: Configures Plug-and-Play profiles for zero-touch provisioning with transport settings for connecting to PnP servers. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability. -
IP SLA (
ip_sla) - DNA Advantage Required: Configures IP Service Level Agreement monitoring entries and schedules for network performance measurement. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability. -
Track Objects (
track_objects) - DNA Advantage Required: Configures object tracking for monitoring IP SLA operations, interfaces, or other tracked objects. Requires Cisco DNA Advantage license for NETCONF/RESTCONF programmability. -
Power Management (
power_redundancy_mode_combined,power_supply_autolc_shutdown,power_supply_autolc_priority) - Chassis Platforms Only: Configures chassis power supply redundancy and automatic linecard shutdown behavior. Thepower_redundancy_mode_combinedenables combined power redundancy mode. Thepower_supply_autolc_shutdownenables automatic linecard shutdown when power budget is exceeded. Thepower_supply_autolc_prioritysets the priority order (1-10) for automatic linecard shutdown. These attributes are only supported on chassis-based platforms (Catalyst 9300/9500/9600 series).
Key Parameters Briefly Explained:
hostname: Device name.ip_routing,ipv6_unicast_routing: Enable routing.ip_domain_name,ip_domain_lookup: Domain name and DNS lookup.diagnostic_bootup_level: Diagnostic level during bootup (completeorminimal).subscriber_templating: Enable subscriber templating functionality.ip_source_route: Source routing.ip_bgp_community_new_format: BGP community format.login_delay,login_on_failure,login_on_failure_log,login_on_success,login_on_success_log: Login controls.ip_multicast_routing,ip_multicast_routing_distributed,multicast_routing_switch,multicast_routing_vrfs: Multicast routing global and per-VRF.mtu: MTU setting.http: HTTP/HTTPS server and authentication.ssh: SSH server settings including bulk-mode for optimized data transfers.tftp_source_interface_type,tftp_source_interface_id: TFTP source interface configuration.platform: Platform-specific settings and punt keepalive configuration.mac_address_table_aging_time: Global MAC address-table aging time in seconds (0 or 10-1000000).cef_ipv4_include_ports_source,cef_ipv4_include_ports_destination,cef_ipv6_include_ports_source,cef_ipv6_include_ports_destination: CEF load-sharing algorithm configuration including Layer 4 port-based hashing for IPv4 and IPv6.port_channel_load_balance: Port-channel load balance algorithm selection.device_classifier: Enable device profiling and classification.ip_radius_source_interface_type,ip_radius_source_interface_id,ip_radius_source_interface_vrf: RADIUS source interface (DNA Advantage required).pnp_profiles: Plug-and-Play provisioning profiles (DNA Advantage required).ip_sla: IP SLA monitoring entries and schedules (DNA Advantage required).track_objects: Object tracking for IP SLA and interfaces (DNA Advantage required).power_redundancy_mode_combined: Enable combined power redundancy mode. Catalyst 9400/9500/9600 series only.power_supply_autolc_shutdown: Enable automatic linecard shutdown when power budget is exceeded. Catalyst 9400/9500/9600 series only.power_supply_autolc_priority: Priority order (1-10) for automatic linecard shutdown, list of up to 8 entries. Catalyst 9400/9500/9600 series only.switch_provision: StackWise member provisioning for stack-capable switches (switch <number> provision <model>).
You can use these system parameters to establish device identity, enable routing, configure management access, and enforce security policies. Adjusting these parameters lets you tailor device behavior and management for your network’s operational needs.
Sample Configuration
Section titled “Sample Configuration”The following configuration describes how to set up system parameters on a Cisco IOS-XE device, including hostname, routing, domain name, login controls, SSH server settings with bulk-mode, multicast routing, and HTTP/HTTPS server settings.
hostname router1-xeip bgp-community new-formatip routingipv6 unicast-routingip source-routeip domain-lookupip domain-name router1_domaindiagnostic bootup level minimalsubscriber templatinglogin delay 2login on-failurelogin on-failure loglogin on-successlogin on-success logip ssh time-out 120ip ssh authentication-retries 3ip ssh bulk-modeip ssh bulk-mode window-size 262144ip multicast-routingip multicast-routing distributedip multicast-routing vrf VRF1 distributeddevice classifierip http access-class 10ip http active-session-modules restconfip http secure-active-session-modules restconfip http max-connections 25ip http authentication localip http serverip http secure-serverip http secure-trustpoint router1_trustpointip http tls-version TLSv1.2ip http client secure-trustpoint router1_trustpointip http client source-interface Loopback0ip cef load-sharing algorithm include-ports source destinationipv6 cef load-sharing algorithm include-ports source destinationport-channel load-balance src-dst-mixed-ip-portip tftp source-interface TenGigabitEthernet1/0/1platform punt-keepalive disable-kernel-coreplatform punt-keepalive settings fatal-count 20platform punt-keepalive settings transmit-interval 10platform punt-keepalive settings warning-count 15ip radius source-interface Loopback10!pnp profile CLOUD_PNP_PROFILE transport https ipv4 192.0.2.50 port 443!ip sla 500 icmp-echo 192.168.1.1ip sla schedule 500 life 3600 start-time now!track 100 ip sla 500 reachability!! Chassis power management (C9400/9500/9600 only)power redundancy-mode combinedpower supply autoLC shutdownpower supply autoLC priority 1 5 3switch 1 provision c9300-24pswitch 2 provision c9300-24pExample YAML Code
Section titled “Example YAML Code”The following YAML code sets up system parameters on IOS-XE devices, showing SSH bulk-mode configuration, local and AAA authentication for HTTP, and switch-specific settings.
iosxe: devices: - name: Router1 configuration: system: hostname: router1-xe ip_bgp_community_new_format: true ip_routing: true ipv6_unicast_routing: true ip_source_route: true ip_domain_lookup: true ip_domain_name: router1_domain diagnostic_bootup_level: minimal subscriber_templating: true login_delay: 2 login_on_failure: true login_on_failure_log: true login_on_success: true login_on_success_log: true ip_multicast_routing: true ip_multicast_routing_distributed: true ip_domain_lookup_vrfs: - vrf: VRF1 source_interface_type: GigabitEthernet source_interface_id: 1/0/5 authentication_mac_move_permit: true authentication_mac_move_deny_uncontrolled: true ssh: authentication_retries: 3 time_out: 120 bulk_mode: true bulk_mode_window_size: 262144 http: access_class: 10 active_session_modules: restconf secure_active_session_modules: restconf max_connections: 25 authentication_local: true server: true secure_server: true secure_trustpoint: router1_trustpoint tls_version: TLSv1.2 client_secure_trustpoint: router1_trustpoint client_source_interface: Loopback0 cef_ipv4_include_ports_source: true cef_ipv4_include_ports_destination: true cef_ipv6_include_ports_source: true cef_ipv6_include_ports_destination: true port_channel_load_balance: src-dst-mixed-ip-port tftp_source_interface_type: TenGigabitEthernet tftp_source_interface_id: 1/0/1 platform: punt_keepalive_disable_kernel_core: true punt_keepalive_settings_fatal_count: 20 punt_keepalive_settings_transmit_interval: 10 punt_keepalive_settings_warning_count: 15
- name: Router2 configuration: system: hostname: router2-xe ip_bgp_community_new_format: true ip_routing: true ipv6_unicast_routing: true ip_source_route: true ip_domain_lookup_nsap: true ip_domain_name: router2_domain login_delay: 2 login_on_failure: true login_on_failure_log: true login_on_success: true login_on_success_log: true ip_multicast_routing: true ip_multicast_routing_distributed: true http: access_class: 20 active_session_modules: restconf secure_active_session_modules: restconf max_connections: 50 authentication_aaa: true authentication_aaa_exec_authorization: test_author_group authentication_aaa_login_authentication: test_authen_group authentication_aaa_command_authorizations: - level: 15 name: test1 server: true secure_server: true secure_trustpoint: router2_trustpoint tls_version: TLSv1.2 client_secure_trustpoint: router2_trustpoint client_source_interface: Loopback1
- name: Switch1 configuration: system: hostname: switch1-xe ip_bgp_community_new_format: true ip_routing: true mtu: 1600 ipv6_unicast_routing: true ip_source_route: true ip_domain_lookup_recursive: true ip_domain_name: switch1_domain login_delay: 2 login_on_failure: true login_on_failure_log: true login_on_success: true login_on_success_log: true multicast_routing_switch: true http: access_class: 30 active_session_modules: restconf secure_active_session_modules: restconf max_connections: 100 authentication_local: true server: true secure_server: true secure_trustpoint: switch1_trustpoint tls_version: TLSv1.2 client_secure_trustpoint: switch1_trustpoint client_source_interface: Loopback2 cef_ipv4_include_ports_source: true cef_ipv4_include_ports_destination: false cef_ipv6_include_ports_source: false cef_ipv6_include_ports_destination: true port_channel_load_balance: src-dst-mac tftp_source_interface_type: Vlan tftp_source_interface_id: 100 mac_address_table_aging_time: 14400
- name: Router3 configuration: system: hostname: router3-xe device_classifier: true multicast_routing_vrfs: - vrf: VRF1 distributed: true ip_radius_source_interface_type: Loopback ip_radius_source_interface_id: "10" track_objects: - number: 100 ip_sla_number: 500 ip_sla_reachability: true pnp_profiles: - name: CLOUD_PNP_PROFILE transport_https_ipv4_ipv4_address: 192.0.2.50 transport_https_ipv4_port: 443 ip_sla: entries: - number: 500 icmp_echo_destination: 192.168.1.1 schedules: - entry_number: 500 start_time_now: true life: 3600 switch_provision: - number: 1 provision: c9300-24p - number: 2 provision: c9300-24p
- name: ChassisSwitch1 configuration: system: hostname: chassis-sw1 power_redundancy_mode_combined: true power_supply_autolc_shutdown: true power_supply_autolc_priority: - 1 - 5 - 3System configuration encompasses fundamental device-level settings that control core operational behaviors including hostname identification, IP and IPv6 routing enablement, domain name resolution, login security controls, SSH server parameters, and HTTP/HTTPS server parameters for management access. It provides comprehensive control over essential network services such as multicast routing, source routing, domain lookup, and authentication methods while supporting both local and AAA-based authentication mechanisms for management interfaces. SSH configuration includes bulk-mode optimization for efficient bulk data transfers with configurable window sizes. System configuration is critical for establishing the basic operational foundation of network devices, ensuring proper identification, connectivity, security posture, and management accessibility across the network infrastructure.
Diagram
Section titled “Diagram”Classes
Section titled “Classes”configuration (iosxe.devices)
Section titled “configuration (iosxe.devices)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| system | Class | [system] | No |
system (iosxe.devices.configuration)
Section titled “system (iosxe.devices.configuration)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| hostname | String | Regex: ^[^\s]*$ | No | |
| ip_bgp_community_new_format | Boolean | true, false | No | |
| ip_routing | Boolean | true, false | No | |
| ipv6_unicast_routing | Boolean | true, false | No | |
| mtu | Integer | min: 1500, max: 9198 | No | |
| ip_source_route | Boolean | true, false | No | |
| ip_domain_lookup | Boolean | true, false | No | |
| ip_domain_lookup_nsap | Boolean | true, false | No | |
| ip_domain_lookup_recursive | Boolean | true, false | No | |
| ip_domain_lookup_vrfs | List | [ip_domain_lookup_vrfs] | No | |
| ip_domain_name | String | Regex: ^[^\s]*$ | No | |
| login_delay | Integer | min: 1, max: 10 | No | |
| login_on_failure | Boolean | true, false | No | |
| login_on_failure_log | Boolean | true, false | No | |
| login_on_success | Boolean | true, false | No | |
| login_on_success_log | Boolean | true, false | No | |
| ip_multicast_routing | Boolean | true, false | No | |
| multicast_routing_switch | Boolean | true, false | No | |
| ip_multicast_routing_distributed | Boolean | true, false | No | |
| multicast_routing_vrfs | List | [multicast_routing_vrfs] | No | |
| ipv6_multicast_routing | Boolean | true, false | No | |
| access_session_mac_move_deny | Boolean | true, false | No | |
| archive | Class | [archive] | No | |
| boot_system_bootfiles | List | String | No | |
| boot_system_flash_files | List | String | No | |
| cisp_enable | Boolean | true, false | No | |
| control_plane_service_policy_input | String | No | ||
| diagnostic_bootup_level | Choice | complete, minimal | No | |
| enable_secret | String | No | ||
| enable_secret_level | Integer | min: 0, max: 255 | No | |
| enable_secret_type | Choice | 0, 4, 5, 8, 9 | No | |
| epm_logging | Boolean | true, false | No | |
| ip_domain_lookup_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet | No | |
| ip_domain_lookup_source_interface_id | Any | String or Integer[min: 0] | No | |
| ip_forward_protocol_nd | Boolean | true, false | No | |
| ip_name_servers | List | String | No | |
| ip_name_servers_vrf | List | [ip_name_servers_vrf] | No | |
| ip_radius_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet | No | |
| ip_radius_source_interface_id | Any | String or Integer[min: 0] | No | |
| ip_radius_source_interface_vrf | String | No | ||
| ip_scp_server_enable | Boolean | true, false | No | |
| ssh | Class | [ssh] | No | |
| ip_tacacs_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet | No | |
| ip_tacacs_source_interface_id | Any | String or Integer[min: 0] | No | |
| ip_sla | Class | [ip_sla] | No | |
| ip_tacacs_source_interface_vrf | String | No | ||
| memory_free_low_watermark_processor | Integer | min: 1, max: 3994575 | No | |
| pnp_profiles | List | [pnp_profiles] | No | |
| redundancy | Boolean | true, false | No | |
| redundancy_mode | Choice | none, rpr, rpr-plus, sso | No | |
| transceiver_type_all_monitoring | Boolean | true, false | No | |
| http | Class | [http] | No | |
| ip_hosts | List | [ip_hosts] | No | |
| subscriber_templating | Boolean | true, false | No | |
| call_home_contact_email | String | No | ||
| call_home_cisco_tac_1_profile_active | Boolean | true, false | No | |
| call_home_cisco_tac_1_destination_transport_method | Choice | email, http | No | |
| ip_ftp_passive | Boolean | true, false | No | |
| tftp_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet | No | |
| tftp_source_interface_id | Any | String or Integer[min: 0] | No | |
| multilink_ppp_bundle_name | String | No | ||
| ip_nbar_classification_dns_classify_by_domain | Boolean | true, false | No | |
| track_objects | List | [track_objects] | No | |
| ip_multicast_route_limit | Integer | min: 1, max: 2147483647 | No | |
| ip_domain_list_names | List | String | No | |
| ip_domain_list_vrf_domain | String | No | ||
| ip_domain_list_vrf | String | No | ||
| ethernet_cfm_alarm_config_delay | Integer | min: 2500, max: 30000 | No | |
| ethernet_cfm_alarm_config_reset | Integer | min: 2500, max: 30000 | No | |
| standby_redirects | Choice | none, enable, disable | No | |
| security_passwords_min_length | Integer | min: 1, max: 16 | No | |
| platform | Class | [platform] | No | |
| authentication_mac_move_permit | Boolean | true, false | No | |
| authentication_mac_move_deny_uncontrolled | Boolean | true, false | No | |
| ip_default_gateway | String | No | ||
| device_classifier | Boolean | true, false | No | |
| table_maps | List | [table_maps] | No |
ip_domain_lookup_vrfs (iosxe.devices.configuration.system)
Section titled “ip_domain_lookup_vrfs (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| vrf | String | Regex: ^[^\s]*$ | Yes | |
| source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet | No | |
| source_interface_id | Any | String or Integer[min: 0] | No |
multicast_routing_vrfs (iosxe.devices.configuration.system)
Section titled “multicast_routing_vrfs (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| vrf | String | Regex: ^[^\s]*$ | Yes | |
| distributed | Boolean | true, false | No |
archive (iosxe.devices.configuration.system)
Section titled “archive (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| log_config_logging_enable | Boolean | true, false | No | |
| log_config_logging_size | Integer | min: 1, max: 1000 | No | |
| maximum | Integer | min: 1, max: 14 | No | |
| path | String | No | ||
| time_period | Integer | min: 1, max: 525600 | No | |
| write_memory | Boolean | true, false | No |
ip_name_servers_vrf (iosxe.devices.configuration.system)
Section titled “ip_name_servers_vrf (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| vrf | String | Yes | ||
| servers | List | String | No |
ssh (iosxe.devices.configuration.system)
Section titled “ssh (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| authentication_retries | Integer | min: 0, max: 5 | No | |
| source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet | No | |
| source_interface_id | Any | String or Integer[min: 0] | No | |
| time_out | Integer | min: 1, max: 120 | No | |
| version | Choice | 2 | No | |
| bulk_mode | Boolean | true, false | No | |
| bulk_mode_window_size | Integer | min: 131072, max: 1073741824 | No |
ip_sla (iosxe.devices.configuration.system)
Section titled “ip_sla (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| entries | List | [entries] | No | |
| schedules | List | [schedules] | No |
pnp_profiles (iosxe.devices.configuration.system)
Section titled “pnp_profiles (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | Yes | ||
| transport_https_ipv4_ipv4_address | String | No | ||
| transport_https_ipv4_port | Integer | min: 1, max: 65535 | No |
http (iosxe.devices.configuration.system)
Section titled “http (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| access_class | Integer | min: 1, max: 99 | No | |
| active_session_modules | String | Regex: ^[^\s]*$ | No | |
| secure_active_session_modules | String | Regex: ^[^\s]*$ | No | |
| max_connections | Integer | min: 1, max: 50 | No | |
| authentication_aaa | Boolean | true, false | No | |
| authentication_aaa_exec_authorization | String | Regex: ^[^\s]*$ | No | |
| authentication_aaa_login_authentication | String | Regex: ^[^\s]*$ | No | |
| authentication_aaa_command_authorizations | List | [authentication_aaa_command_authorizations] | No | |
| authentication_local | Boolean | true, false | No | |
| server | Boolean | true, false | No | |
| secure_server | Boolean | true, false | No | |
| secure_trustpoint | String | Regex: ^[^\s]*$ | No | |
| tls_version | Choice | TLSv1.0, TLSv1.1, TLSv1.2, TLSv1.3 | No | |
| client_secure_trustpoint | String | Regex: ^[^\s]*$ | No | |
| client_source_interface_type | Choice | Loopback, Vlan, GigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, FortyGigabitEthernet, HundredGigabitEthernet, PortChannel | No | |
| client_source_interface_id | Any | String or Integer[min: 0] | No |
ip_hosts (iosxe.devices.configuration.system)
Section titled “ip_hosts (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | Yes | ||
| ips | List | IP | Yes | |
| vrf | String | No |
track_objects (iosxe.devices.configuration.system)
Section titled “track_objects (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| number | Integer | min: 1, max: 1000 | Yes | |
| ip_sla_number | Integer | min: 1, max: 2147483647 | No | |
| ip_sla_reachability | Boolean | true, false | No |
platform (iosxe.devices.configuration.system)
Section titled “platform (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| punt_keepalive_disable_kernel_core | Boolean | true, false | No | |
| punt_keepalive_settings_fatal_count | Integer | min: 15, max: 60 | No | |
| punt_keepalive_settings_transmit_interval | Integer | min: 2, max: 30 | No | |
| punt_keepalive_settings_warning_count | Integer | min: 10, max: 60 | No |
table_maps (iosxe.devices.configuration.system)
Section titled “table_maps (iosxe.devices.configuration.system)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| name | String | Yes | ||
| default | Any | Choice[copy, ignore] or Integer[min: 0, max: 99] or String[Regex: ^.*[\$\%]\{.*$] | No | |
| mappings | List | [mappings] | No |
entries (iosxe.devices.configuration.system.ip_sla)
Section titled “entries (iosxe.devices.configuration.system.ip_sla)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| number | Integer | Yes | ||
| icmp_echo_destination | String | No | ||
| icmp_echo_source_ip | String | No |
schedules (iosxe.devices.configuration.system.ip_sla)
Section titled “schedules (iosxe.devices.configuration.system.ip_sla)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| entry_number | Integer | Yes | ||
| life | Integer | No | ||
| start_time_now | Boolean | true, false | No |
authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)
Section titled “authentication_aaa_command_authorizations (iosxe.devices.configuration.system.http)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| level | Integer | min: 0, max: 15 | Yes | |
| name | String | Regex: ^[^\s]*$ | No |
mappings (iosxe.devices.configuration.system.table_maps)
Section titled “mappings (iosxe.devices.configuration.system.table_maps)”| Name | Type | Constraint | Mandatory | Default Value |
|---|---|---|---|---|
| from | Integer | min: 0, max: 63 | Yes | |
| to | Integer | min: 0, max: 63 | Yes |
By configuring system-level parameters, you establish the operational foundation, security, and management accessibility for your network devices.
System Parameters
Section titled “System Parameters”Key Components:
-
Hostname (
hostname): Sets the device’s hostname for identification. -
IP Routing (
ip_routing), IPv6 Routing (ipv6_unicast_routing): Enables IP and IPv6 routing capabilities. -
Domain Name and Lookup (
ip_domain_name,ip_domain_lookup,ip_domain_lookup_nsap,ip_domain_lookup_recursive,ip_domain_lookup_vrfs): Configures domain name and enables DNS lookup. -
Source Routing (
ip_source_route): Enables or disables IP source routing. -
BGP Community Format (
ip_bgp_community_new_format): Enables new-format BGP community strings. -
Login Controls (
login_delay,login_on_failure,login_on_failure_log,login_on_success,login_on_success_log): Configures login security and logging. -
Multicast Routing (
ip_multicast_routing,ip_multicast_routing_distributed,multicast_routing_switch): Enables multicast routing features. -
MTU (
mtu): Sets the device’s maximum transmission unit (MTU). -
HTTP/HTTPS Server (
http): Configures HTTP/HTTPS server settings, authentication, access control, and security parameters. -
TFTP Source Interface (
tftp_source_interface_type,tftp_source_interface_id): Configures the source interface for TFTP operations. Supports multiple interface types including Loopback, VLAN, GigabitEthernet, TwoGigabitEthernet, FiveGigabitEthernet, TenGigabitEthernet, TwentyFiveGigabitEthernet, FortyGigabitEthernet, and HundredGigabitEthernet. -
Platform (
platform): Configures platform-specific settings including punt keepalive functionality for system stability and kernel core management. -
SSH Configuration (
ssh): Configures SSH server settings including timeout, authentication retries, version, and bulk-mode for optimizing bulk data transfers with configurable window sizes.
Key Parameters Briefly Explained:
hostname: Device name.ip_routing,ipv6_unicast_routing: Enable routing.ip_domain_name,ip_domain_lookup: Domain name and DNS lookup.ip_source_route: Source routing.ip_bgp_community_new_format: BGP community format.login_delay,login_on_failure,login_on_failure_log,login_on_success,login_on_success_log: Login controls.ip_multicast_routing,ip_multicast_routing_distributed,multicast_routing_switch: Multicast routing.mtu: MTU setting.http: HTTP/HTTPS server and authentication.ssh: SSH server settings including bulk-mode for optimized data transfers.tftp_source_interface_type,tftp_source_interface_id: TFTP source interface configuration.platform: Platform-specific settings and punt keepalive configuration.
You can use these system parameters to establish device identity, enable routing, configure management access, and enforce security policies. Adjusting these parameters lets you tailor device behavior and management for your network’s operational needs.
Sample Configuration
Section titled “Sample Configuration”The following configuration describes how to set up system parameters on a Cisco IOS-XE device, including hostname, routing, domain name, login controls, SSH server settings with bulk-mode, multicast routing, and HTTP/HTTPS server settings.
hostname router1-xeip bgp-community new-formatip routingipv6 unicast-routingip source-routeip domain-lookupip domain-name router1_domainlogin delay 2login on-failurelogin on-failure loglogin on-successlogin on-success logip ssh time-out 120ip ssh authentication-retries 3ip ssh bulk-modeip ssh bulk-mode window-size 262144ip multicast-routingip multicast-routing distributedip http access-class 10ip http active-session-modules restconfip http secure-active-session-modules restconfip http max-connections 25ip http authentication localip http serverip http secure-serverip http secure-trustpoint router1_trustpointip http tls-version TLSv1.2ip http client secure-trustpoint router1_trustpointip http client source-interface Loopback0ip tftp source-interface TenGigabitEthernet1/0/1platform punt-keepalive disable-kernel-coreplatform punt-keepalive settings fatal-count 20platform punt-keepalive settings transmit-interval 10platform punt-keepalive settings warning-count 15Example YAML Code
Section titled “Example YAML Code”The following YAML code sets up system parameters on IOS-XE devices, showing SSH bulk-mode configuration, local and AAA authentication for HTTP, and switch-specific settings.
iosxe: devices: - name: Router1 configuration: system: hostname: router1-xe ip_bgp_community_new_format: true ip_routing: true ipv6_unicast_routing: true ip_source_route: true ip_domain_lookup: true ip_domain_name: router1_domain login_delay: 2 login_on_failure: true login_on_failure_log: true login_on_success: true login_on_success_log: true ip_multicast_routing: true ip_multicast_routing_distributed: true ip_domain_lookup_vrfs: - vrf: VRF1 source_interface_type: GigabitEthernet source_interface_id: 1/0/5 authentication_mac_move_permit: true authentication_mac_move_deny_uncontrolled: true ssh: authentication_retries: 3 time_out: 120 bulk_mode: true bulk_mode_window_size: 262144 http: access_class: 10 active_session_modules: restconf secure_active_session_modules: restconf max_connections: 25 authentication_local: true server: true secure_server: true secure_trustpoint: router1_trustpoint tls_version: TLSv1.2 client_secure_trustpoint: router1_trustpoint client_source_interface: Loopback0 tftp_source_interface_type: TenGigabitEthernet tftp_source_interface_id: 1/0/1 platform: punt_keepalive_disable_kernel_core: true punt_keepalive_settings_fatal_count: 20 punt_keepalive_settings_transmit_interval: 10 punt_keepalive_settings_warning_count: 15
- name: Router2 configuration: system: hostname: router2-xe ip_bgp_community_new_format: true ip_routing: true ipv6_unicast_routing: true ip_source_route: true ip_domain_lookup_nsap: true ip_domain_name: router2_domain login_delay: 2 login_on_failure: true login_on_failure_log: true login_on_success: true login_on_success_log: true ip_multicast_routing: true ip_multicast_routing_distributed: true http: access_class: 20 active_session_modules: restconf secure_active_session_modules: restconf max_connections: 50 authentication_aaa: true authentication_aaa_exec_authorization: test_author_group authentication_aaa_login_authentication: test_authen_group authentication_aaa_command_authorizations: - level: 15 name: test1 server: true secure_server: true secure_trustpoint: router2_trustpoint tls_version: TLSv1.2 client_secure_trustpoint: router2_trustpoint client_source_interface: Loopback1
- name: Switch1 configuration: system: hostname: switch1-xe ip_bgp_community_new_format: true ip_routing: true mtu: 1600 ipv6_unicast_routing: true ip_source_route: true ip_domain_lookup_recursive: true ip_domain_name: switch1_domain login_delay: 2 login_on_failure: true login_on_failure_log: true login_on_success: true login_on_success_log: true multicast_routing_switch: true http: access_class: 30 active_session_modules: restconf secure_active_session_modules: restconf max_connections: 100 authentication_local: true server: true secure_server: true secure_trustpoint: switch1_trustpoint tls_version: TLSv1.2 client_secure_trustpoint: switch1_trustpoint client_source_interface: Loopback2 tftp_source_interface_type: Vlan tftp_source_interface_id: 100