subs_id in commands: dhcp show, dhcp reauth, dhcp6 show, dhcp6 reauth, and dhcp disconnect. Descriptionipfix_reserved parameter. Descriptionbind_ipv6_address and bind_ipv6_subnet. If the Framed-IPv6-Prefix has a /128 mask, it is not checked against the bind_ipv6_subnet restriction. Descriptiondev info now includes the name of the LAG that the port belongs to. DescriptionClient-Id now includes tunnel-IP as part of the subscriber ID. For more details, see sections IPv4 Pools Support and IPv6 pools supportipfix_mtu_limit to restrict maximum message size for IPFIX UDP packets. Description: ClickStream export Setup, Configuring Full NetFlow Export in IPFIX Formatvrrp_enable option changel2subs_id + tunnel-IP. For PPPoE sessions, tunnel IP = 0. CLI commands that use subs_id as a key (subs prop show, l2tp show session, l2tp term, etc.) may now return multiple entries with the same l2subs_id. Description hal mempool props
hal mempool stat
DPDK must be built with statistics collection enabled to display mempool stats
Acct-Interim-Interval = 0 is explicitly set in the RADIUS response. For more details, see sections acct-interim-interval, PPPoE Radius Access-Requestdpdk_emit_mempool_size is deprecated and no longer used.vlan group were converted and moved from UDR to SDR, with removal from UDR. Descriptioncombined_io_direction_mode optiontelegram_tlsWECHAT and WECHAT_CALLpcrf connect show — show current status and accumulated statistics for PCRF connections.pcrf connect switch [<pcrf_index>], where <pcrf_indxed> is the index of the connection line in the auth_server parameter. If <pcrf_indxed> is not specified — defaults to 0.ajb_save_dns parameter. DescriptionVASExperts-Service-Type. Radius acct start/interim/stop sends the authorization type in the VASExperts-Service-Type attribute. Descriptionstat flow ip6 command to display IPv6 flow statistics. Descriptionstat flow ip4 command to display IPv4 flow statistics. Analogous to the output in fastdpi_stat.log. Descriptionstat netflow command. Displays general statistics for Netflow/IPFIX (same as in fastdpi_stat.log under the "Statistics on NFLW_export" section). Descriptionstat firewall command. Descriptionajb_save_vlan parameter. Descriptionrouter.subnet6 settings.pending_queue. In some cases (e.g., during state transitions of the pcrf monitor initial → connected), sending commands from the pending_queue was not triggered, which caused commands to "hang" in the queue indefinitely (until reconnection due to a socket error).dpdk_tx_queue_size option. Previously, the tx queue length of the TAP device was always set to 256, which caused errors on the VMware VMXNET3 Ethernet Controller: ETHDEV: Invalid value for nb_tx_desc(=256), should be: <= 4096, >= 512, and a product of 1stat storage ip4 detail outputs statistics on bucket filling in the IPv4 node storagetethering_ttl_allowed = 128:64 [hot] defines the list of allowed TTL values for subscriber traffic that are not considered tethering. Values are separated by ':'. The number of values is up to 256 (0–255). Descriptionbras_disable_l3_auth option — an explicit prohibition of L3 auth in L2 BNG mode for all subscribers. For example, only DHCP authorization will work for subscribers with the AS local meta. Default value: off (L3 auth allowed) bras_disable_l3_auth=off. This option is meaningful only if enable_auth=1. The option is incompatible with the bras_dhcp_auth_mix=0 mode: if bras_dhcp_auth_mix=0 is set, bras_disable_l3_auth is forced to off (L3 auth allowed) and a warning is logged to the alert log.disable_l3_auth=[1:0] has been added to the subs prop set command (1 — disable L3 auth, 0 — enable). By default, L3 auth is enabled.ip_filter_source_as_flags (hot)[hot] — filtering subs traffic by AS. Bit mask of AS (autonomous system) flags for the source IP on the subs side.ip_filter_source_as_flags=0x0ppp show stat commandVasExperts-Policing-Profile attribute with the BR## prefixnoname) user profile for services from parameters passed in the VasExperts-Service-Profile attribute with the BP## prefixrating_group_count — number of rating groups, 0 — RG disabled. Default value: 0rating_group_max_subs — maximum number of subscribers with RG. Default value: 0 (RG disabled)32 * rating_group_count * rating_group_max_subs * num_thread
For example, for 10k subscribers, 256 RGs, and 8 processing threads, 625M of memory is required:
rating_group_count = 256 rating_group_max_subs = 10000 num_thread = 8 memory_required = 32 * 256 * 10000 * 8 = 625M
VasExperts-Acct-Type (id=28, vendor 43823, integer type) is used with the following values:0 — standard Interim Update Accounting1 — RG dataVasExperts-Acct-Rating-Group (new attribute of type short, 16-bit integer) — RG number;VasExperts-Acct-Input-Octets-64VasExperts-Acct-Output-Octets-64VasExperts-Acct-Input-Packets-64VasExperts-Acct-Output-Packets-64acct_swap_dir option (as in Accounting).subs traffic stat CLI command. The command outputs billing statistics and rating group statistics for the specified subscriber, if enabled.VasExperts-Service-Profile :="9:RG"
When service 9 is disabled, RG accumulation is also disabled.
Examples of configuring service 9 and RG:
# service 9 enabled, RG disabled. Standard RADIUS Accounting is sent. VasExperts-Enable-Service :="9:on"
# service 9 enabled, RG enabled. RG data are sent in RADIUS Accounting. VasExperts-Service-Profile :="9:RG"
# service 9 disabled, RG disabled. Standard RADIUS Accounting and RG are not sent. VasExperts-Enable-Service :="9:off"
VasExperts-L2-User=1 flag during L3 authorization).bras_subs_shcv_interval — inactivity interval, seconds; 0 — SHCV disabledbras_subs_shcv_retry_timeout — ARP request response wait time, seconds; default = 3bras_subs_shcv_retry_count — number of ARP requests; default = 3bras_shcv_trace — SHCV tracing; default = offbras_subs_shcv_interval seconds, fastDPI starts pinging the subscriber by sending unicast ARP requests on behalf of the subscriber gateway. The ARP response wait time is bras_subs_shcv_retry_timeout seconds. If no response is received to bras_subs_shcv_retry_count consecutive ARP requests, or the ARP response contains a different MAC address, the subscriber is considered inactive, its authorization status is reset, and the accounting session is stopped.2 and 4 are available for the bras_dhcp_check_secondary_keys option. Full option description:bras_dhcp_check_secondary_keys — control of secondary unique keys (opt82/QinQ) [hot]0 (default) — do not control secondary keys1 — control all secondary keys — QinQ and opt822 — control only opt824 — control only QinQbras_dhcp_server option: keep_siaddr=1 — preserve the DHCP packet siaddr field. Example:bras_dhcp_server=188.227.73.42%eth0;arp_proxy=1;reply_port=67;keep_siaddr=1
By default, the siaddr field may be modified to hide the real DHCP server address.
rx_dispatcher=3 — a method with uniform load balancing across an arbitrary number of threads with support for NAT 1:1 and the requirement to assign specific addressesfdpi_ctrl list status --service 11 --login UserName (--ip IP) command. Additional fields were added to the command output: active_sess_tcp — number of active NAT translations for TCP and active_sess_udp — number of active NAT translations for UDP.nat show <internal_ip> [<lifetime>] command. Displays a list of all NAT translations for the specified gray IP. A translation record looks as follows:<lifetime> (in seconds) is specified, its value is used as the translation lifetime.subs bind show command to view the list of IP addresses bound to the login <login>:subs bind show <login> [memory|udr]
Two modes:
memory (default) displays IP-to-login bindings as currently configured in fastDPIudr — displays IP-to-login bindings from UDRcli framed route ? CLI command groupstat http CLI command. This command outputs internal statistics similar to those in fastdpi_stat.log:list status --service 11 (NAT) and nat show commandsservice_flags — information about the tags assigned to the flow in DPI. Detected tethering is reported via IPFIX in bit 1 of the service_flags field. 63 bits are available for further use.detection_flags — reserved for detection methods.action_flags — reserved for transmitting actions applied to the flow.syslog_level in fdpi_radius.conf — the level of logging messages from the alert log to syslog. 0 — syslog logging disabled (default).