: Set Commands Introduced in PAN-OS 11.0
Focus
Focus

Set Commands Introduced in PAN-OS 11.0

Table of Contents
End-of-Life (EoL)

Set Commands Introduced in PAN-OS 11.0

Command line interface 'set' commands that are new in PAN-OS 11.
The following commands are new in the 11 release:
There are 23 new set deviceconfig commands
set deviceconfig system tls-mode<tlsv1.3-only|mixed-mode|exclude-tlsv1.3> set deviceconfig system certificate <value> set deviceconfig system panorama cloud-service set deviceconfig setting global-protect tasks <10-100000> set deviceconfig setting global-protect auth-requests <1024-8192> set deviceconfig setting wildfire real-time-hold <yes|no> set deviceconfig setting wildfire real-time-hold-timeout <1-5000> set deviceconfig setting wildfire real-time-hold-timeout-action <allow|reset-both> set deviceconfig setting inline-url-setting max-latency <1-240000> set deviceconfig setting inline-spyware-setting max-latency <1-240000> set deviceconfig setting session dhcp-bcast-session-on <yes|no> set deviceconfig setting dns-over-https set deviceconfig setting dns-over-https enable <yes|no> set deviceconfig setting net-inspection <yes|no> set deviceconfig setting dhcp-syslog-server set deviceconfig setting dhcp-syslog-server <name> set deviceconfig setting dhcp-syslog-server <name> description <value> set deviceconfig setting dhcp-syslog-server <name> enabled <yes|no> set deviceconfig setting dhcp-syslog-server <name> ip-address <ip/netmask> set deviceconfig setting dhcp-syslog-server <name> protocol <SSL|TCP|UDP> set deviceconfig setting cloud-userid set deviceconfig setting cloud-userid disabled <yes|no> set deviceconfig setting cloud-userid address <ip/netmask>|<value>
There are 1393 new set network commands
set network profiles zone-protection-profile <name> net-inspection set network profiles zone-protection-profile <name> net-inspection rule set network profiles zone-protection-profile <name> net-inspection rule <name> set network profiles zone-protection-profile <name> net-inspection rule <name> threat-id <41000-6900000> set network profiles zone-protection-profile <name> net-inspection rule <name> enable <yes|no> set network profiles zone-protection-profile <name> net-inspection rule <name> signature set network profiles zone-protection-profile <name> net-inspection rule <name> signature comment <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-version value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-header-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-header-length value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-tos set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-tos value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-total-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-total-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-id value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-fragment-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-fragment-offset value <0-8191> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-ttl set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-ttl value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-protocol set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-protocol value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-header-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-header-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-number value <0-31> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-length value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-option-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-user-defined offset <0-60> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-version value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-traffic-class set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-traffic-class value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-flow-label set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-flow-label value <0-1048575> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-payload-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-payload-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-next-header set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-next-header value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-hop-limit set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-hop-limit value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context ip6-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-code value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-id value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-sequence set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-sequence value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-code value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-user-defined offset <0-4> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context icmp6-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-source-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-destination-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-sequence-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-sequence-number value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-acknowledge-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-acknowledge-number value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-data-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-data-offset value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-reserved set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-reserved value <0-7> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-window-size set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-window-size value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-urgent-pointer set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-urgent-pointer value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-user-defined offset <0-24> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-kind set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-kind value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-length value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context tcp-option-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-source-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-destination-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator greater-than context udp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-version value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-header-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-header-length value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-tos set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-tos value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-total-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-total-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-id value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-fragment-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-fragment-offset value <0-8191> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-ttl set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-ttl value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-protocol set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-protocol value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-header-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-header-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-number value <0-31> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-length value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-option-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-user-defined offset <0-60> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-version value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-traffic-class set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-traffic-class value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-flow-label set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-flow-label value <0-1048575> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-payload-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-payload-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-next-header set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-next-header value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-hop-limit set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-hop-limit value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context ip6-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-code value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-id value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-sequence set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-sequence value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-code value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-user-defined offset <0-4> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context icmp6-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-source-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-destination-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-sequence-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-sequence-number value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-acknowledge-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-acknowledge-number value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-data-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-data-offset value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-reserved set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-reserved value <0-7> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-window-size set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-window-size value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-urgent-pointer set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-urgent-pointer value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-user-defined offset <0-24> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-kind set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-kind value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-length value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context tcp-option-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-source-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-destination-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator less-than context udp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-source-address set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-source-address value <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-source-address mask <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-source-address prefix <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-destination-address set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-destination-address value <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-destination-address mask <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-destination-address prefix <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-source-address set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-source-address value <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-source-address mask <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-source-address prefix <1-128> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-destination-address set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-destination-address value <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-destination-address mask <ip/netmask> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-destination-address prefix <1-128> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-version value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-version mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-header-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-header-length value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-header-length mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-tos set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-tos value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-tos mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-total-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-total-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-total-length mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-id value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-id mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-fragment-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-fragment-offset value <0-8191> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-fragment-offset mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-ttl set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-ttl value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-ttl mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-protocol set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-protocol value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-protocol mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-header-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-header-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-header-checksum mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-type mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-number value <0-31> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-number mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-length value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-length mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-option-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-flag-reserved set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-flag-reserved value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-flag-df set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-flag-df value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-flag-mf set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-flag-mf value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-user-defined offset <0-60> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-version value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-version mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-traffic-class set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-traffic-class value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-traffic-class mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-flow-label set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-flow-label value <0-1048575> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-flow-label mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-payload-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-payload-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-payload-length mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-next-header set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-next-header value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-next-header mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-hop-limit set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-hop-limit value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-hop-limit mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context ip6-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-type mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-code value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-code mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-checksum mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-id value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-id mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-sequence set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-sequence value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-sequence mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-type value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-type mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-code value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-code mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-checksum mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-user-defined offset <0-4> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context icmp6-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-source-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-source-port mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-destination-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-destination-port mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-sequence-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-sequence-number value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-sequence-number mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-acknowledge-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-acknowledge-number value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-acknowledge-number mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-data-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-data-offset value <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-data-offset mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-reserved set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-reserved value <0-7> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-reserved mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-ece set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-ece value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-cwr set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-cwr value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-urg set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-urg value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-ack set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-ack value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-psh set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-psh value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-rst set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-rst value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-syn set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-syn value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-fin set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-flag-fin value <0-1> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-window-size set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-window-size value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-window-size mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-checksum mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-urgent-pointer set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-urgent-pointer value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-urgent-pointer mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-user-defined offset <0-24> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-kind set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-kind value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-kind mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-length value <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-length mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context tcp-option-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-source-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-source-port mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-destination-port value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-destination-port mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-length value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-length mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-checksum value <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-checksum mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-user-defined value <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to context udp-user-defined mask <value> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator equal-to negate <yes|no> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-version low <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-version high <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-header-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-header-length low <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-header-length high <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-tos set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-tos low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-tos high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-total-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-total-length low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-total-length high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-id low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-id high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-fragment-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-fragment-offset low <0-8191> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-fragment-offset high <0-8191> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-ttl set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-ttl low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-ttl high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-protocol set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-protocol low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-protocol high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-header-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-header-checksum low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-header-checksum high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-type low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-type high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-number low <0-31> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-number high <0-31> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-length low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-length high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-option-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-user-defined offset <0-60> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-version set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-version low <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-version high <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-traffic-class set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-traffic-class low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-traffic-class high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-flow-label set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-flow-label low <0-1048575> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-flow-label high <0-1048575> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-payload-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-payload-length low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-payload-length high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-next-header set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-next-header low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-next-header high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-hop-limit set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-hop-limit low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-hop-limit high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context ip6-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-type low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-type high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-code low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-code high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-checksum low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-checksum high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-id set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-id low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-id high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-sequence set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-sequence low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-sequence high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-type set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-type low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-type high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-code set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-code low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-code high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-checksum low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-checksum high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-user-defined offset <0-4> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context icmp6-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-source-port low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-source-port high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-destination-port low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-destination-port high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-sequence-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-sequence-number low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-sequence-number high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-acknowledge-number set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-acknowledge-number low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-acknowledge-number high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-data-offset set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-data-offset low <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-data-offset high <0-15> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-reserved set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-reserved low <0-7> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-reserved high <0-7> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-window-size set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-window-size low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-window-size high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-checksum low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-checksum high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-urgent-pointer set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-urgent-pointer low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-urgent-pointer high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-user-defined offset <0-24> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-kind set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-kind low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-kind high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-length low <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-length high <0-255> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-user-defined offset <0-40> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context tcp-option-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-source-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-source-port low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-source-port high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-destination-port set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-destination-port low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-destination-port high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-length set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-length low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-length high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-checksum set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-checksum low <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-checksum high <0-65535> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-user-defined set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-user-defined offset <0-8> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-user-defined width <1-32> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-user-defined low <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator range context udp-user-defined high <0-4294967295> set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-same-address set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip6-same-address set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-eool set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-nop set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-sec set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-lsr set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-ts set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-esec set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-cipso set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-rr set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-sid set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-ssr set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-zsu set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-mtup set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-mtur set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-finn set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-visa set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-encode set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-imitd set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-eip set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-tr set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-addext set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-rtralt set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-sdb set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-dps set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-ump set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context ip-option-qs set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-eool set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-nop set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-mss set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-ws set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-sack-permit set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-sack set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-echo set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-echo-reply set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-ts set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-partial-permit set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-partial-profile set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-cc set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-cc-new set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-cc-echo set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-alt-rst set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-alt-dat set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-skeeter set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-bubba set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-trailer set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-md5 set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-scps set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-snak set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-rec-bd set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-corrupt set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-snap set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-compress set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-qs-res set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-user-timeout set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-tcp-ao set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-mptcp set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-fast set network profiles zone-protection-profile <name> net-inspection rule <name> signature or-condition <name> and-condition <name> operator event context tcp-option-eno set network profiles zone-protection-profile <name> net-inspection rule <name> icmp-unreachable <yes|no> set network profiles zone-protection-profile <name> net-inspection rule <name> action <allow|alert|drop|reset-client|reset-server|reset-both> set network profiles zone-protection-profile <name> net-inspection rule <name> log-severity <value> set network profiles zone-protection-profile <name> net-inspection rule <name> log-interval <15-3600> set network profiles zone-protection-profile <name> net-inspection rule <name> cve [ <cve1> <cve2>... ] set network profiles zone-protection-profile <name> net-inspection rule <name> bugtraq [ <bugtraq1> <bugtraq2>... ] set network profiles zone-protection-profile <name> net-inspection rule <name> vendor [ <vendor1> <vendor2>... ] set network profiles zone-protection-profile <name> net-inspection rule <name> reference [ <reference1> <reference2>... ] set network profiles zone-protection-profile <name> net-inspection rule <name> packet-capture <disable|single-packet|extended-capture> set network profiles zone-protection-profile <name> net-inspection rule <name> exempt-ip set network profiles zone-protection-profile <name> net-inspection rule <name> exempt-ip <name> set network interface ethernet <name> layer3 cluster-interconnect <yes|no> set network interface ethernet <name> layer3 traffic-interconnect <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client set network interface ethernet <name> layer3 ipv6 dhcp-client enable <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client accept-ra-route <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client default-route-metric <1-65535> set network interface ethernet <name> layer3 ipv6 dhcp-client preference <low|medium|high> set network interface ethernet <name> layer3 ipv6 dhcp-client v6-options set network interface ethernet <name> layer3 ipv6 dhcp-client v6-options enable set network interface ethernet <name> layer3 ipv6 dhcp-client v6-options enable no set network interface ethernet <name> layer3 ipv6 dhcp-client v6-options enable yes set network interface ethernet <name> layer3 ipv6 dhcp-client v6-options enable yes non-temp-addr <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client v6-options enable yes temp-addr <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client v6-options rapid-commit <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client prefix-delegation set network interface ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable set network interface ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable no set network interface ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes set network interface ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes prefix-len-hint <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes prefix-len <0-128> set network interface ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes pfx-pool-name <value> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery enable-ndp-monitor <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery enable-dad <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dad-attempts <1-10> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery ns-interval <1-3600> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery reachable-time <10-36000> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server enable <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source dhcpv6 set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual server set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix enable <yes|no> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source dhcpv6 set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery neighbor set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery neighbor <name> set network interface ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery neighbor <name> hw-address <value> set network interface ethernet <name> layer3 ipv6 inherited set network interface ethernet <name> layer3 ipv6 inherited enable <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua enable-on-interface <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua prefix-pool <value> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type dynamic set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type dynamic-id set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type dynamic-id identifier <0-4095> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise enable <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise onlink-flag <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise auto-config-flag <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula enable-on-interface <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula address <ip/netmask> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula prefix <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula anycast <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise enable <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise valid-lifetime <0-4294967294>|<infinity> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise preferred-lifetime <0-4294967294>|<infinity> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise onlink-flag <yes|no> set network interface ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise auto-config-flag <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery enable-ndp-monitor <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery enable-dad <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dad-attempts <1-10> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery ns-interval <1-3600> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery reachable-time <10-36000> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement enable <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement max-interval <4-1800> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement min-interval <3-1350> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement link-mtu <1280-9216>|<unspecified> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement reachable-time <0-3600000>|<unspecified> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement retransmission-timer <0-4294967295>|<unspecified> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement hop-limit <1-255>|<unspecified> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement lifetime <0-9000> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement router-preference <High|Medium|Low> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement managed-flag <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement other-flag <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement enable-consistency-check <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server enable <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source dhcpv6 set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source dhcpv6 prefix-pool <value> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual server set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual server <name> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix enable <yes|no> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 prefix-pool <value> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual suffix set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery neighbor set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery neighbor <name> set network interface ethernet <name> layer3 ipv6 inherited neighbor-discovery neighbor <name> hw-address <value> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client accept-ra-route <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client default-route-metric <1-65535> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client preference <low|medium|high> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable no set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable yes set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable yes non-temp-addr <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable yes temp-addr <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options rapid-commit <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable no set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes prefix-len-hint <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes prefix-len <0-128> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes pfx-pool-name <value> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery enable-ndp-monitor <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery enable-dad <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dad-attempts <1-10> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery ns-interval <1-3600> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery reachable-time <10-36000> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source dhcpv6 set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source dhcpv6 set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery neighbor set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery neighbor <name> set network interface ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery neighbor <name> hw-address <value> set network interface ethernet <name> layer3 units <name> ipv6 inherited set network interface ethernet <name> layer3 units <name> ipv6 inherited enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua enable-on-interface <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua prefix-pool <value> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic-id set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic-id identifier <0-4095> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise onlink-flag <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise auto-config-flag <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula enable-on-interface <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula address <ip/netmask> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula prefix <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula anycast <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise valid-lifetime <0-4294967294>|<infinity> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise preferred-lifetime <0-4294967294>|<infinity> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise onlink-flag <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise auto-config-flag <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery enable-ndp-monitor <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery enable-dad <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dad-attempts <1-10> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery ns-interval <1-3600> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery reachable-time <10-36000> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement max-interval <4-1800> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement min-interval <3-1350> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement link-mtu <1280-9216>|<unspecified> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement reachable-time <0-3600000>|<unspecified> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement retransmission-timer <0-4294967295>|<unspecified> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement hop-limit <1-255>|<unspecified> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement lifetime <0-9000> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement router-preference <High|Medium|Low> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement managed-flag <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement other-flag <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement enable-consistency-check <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source dhcpv6 set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source dhcpv6 prefix-pool <value> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual server set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual server <name> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix enable <yes|no> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 prefix-pool <value> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery neighbor set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery neighbor <name> set network interface ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery neighbor <name> hw-address <value> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client accept-ra-route <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client default-route-metric <1-65535> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client preference <low|medium|high> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client v6-options set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client v6-options enable set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client v6-options enable no set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client v6-options enable yes set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client v6-options enable yes non-temp-addr <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client v6-options enable yes temp-addr <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client v6-options rapid-commit <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client prefix-delegation set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable no set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes prefix-len-hint <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes prefix-len <0-128> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client prefix-delegation enable yes pfx-pool-name <value> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery enable-ndp-monitor <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery enable-dad <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dad-attempts <1-10> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery ns-interval <1-3600> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery reachable-time <10-36000> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source dhcpv6 set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual server set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source dhcpv6 set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery neighbor set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery neighbor <name> set network interface aggregate-ethernet <name> layer3 ipv6 dhcp-client neighbor-discovery neighbor <name> hw-address <value> set network interface aggregate-ethernet <name> layer3 ipv6 inherited set network interface aggregate-ethernet <name> layer3 ipv6 inherited enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua enable-on-interface <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua prefix-pool <value> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type dynamic set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type dynamic-id set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua pool-type dynamic-id identifier <0-4095> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise onlink-flag <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type gua advertise auto-config-flag <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula enable-on-interface <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula address <ip/netmask> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula prefix <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula anycast <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise valid-lifetime <0-4294967294>|<infinity> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise preferred-lifetime <0-4294967294>|<infinity> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise onlink-flag <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited assign-addr <name> type ula advertise auto-config-flag <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery enable-ndp-monitor <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery enable-dad <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dad-attempts <1-10> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery ns-interval <1-3600> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery reachable-time <10-36000> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement max-interval <4-1800> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement min-interval <3-1350> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement link-mtu <1280-9216>|<unspecified> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement reachable-time <0-3600000>|<unspecified> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement retransmission-timer <0-4294967295>|<unspecified> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement hop-limit <1-255>|<unspecified> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement lifetime <0-9000> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement router-preference <High|Medium|Low> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement managed-flag <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement other-flag <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery router-advertisement enable-consistency-check <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source dhcpv6 set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source dhcpv6 prefix-pool <value> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual server set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual server <name> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix enable <yes|no> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 prefix-pool <value> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual suffix set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery neighbor set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery neighbor <name> set network interface aggregate-ethernet <name> layer3 ipv6 inherited neighbor-discovery neighbor <name> hw-address <value> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client accept-ra-route <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client default-route-metric <1-65535> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client preference <low|medium|high> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable no set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable yes set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable yes non-temp-addr <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options enable yes temp-addr <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client v6-options rapid-commit <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable no set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes prefix-len-hint <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes prefix-len <0-128> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client prefix-delegation enable yes pfx-pool-name <value> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery enable-ndp-monitor <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery enable-dad <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dad-attempts <1-10> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery ns-interval <1-3600> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery reachable-time <10-36000> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source dhcpv6 set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source dhcpv6 set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery neighbor set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery neighbor <name> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 dhcp-client neighbor-discovery neighbor <name> hw-address <value> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua enable-on-interface <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua prefix-pool <value> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic-id set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic-id identifier <0-4095> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise onlink-flag <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type gua advertise auto-config-flag <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula enable-on-interface <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula address <ip/netmask> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula prefix <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula anycast <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise valid-lifetime <0-4294967294>|<infinity> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise preferred-lifetime <0-4294967294>|<infinity> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise onlink-flag <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited assign-addr <name> type ula advertise auto-config-flag <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery enable-ndp-monitor <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery enable-dad <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dad-attempts <1-10> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery ns-interval <1-3600> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery reachable-time <10-36000> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement max-interval <4-1800> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement min-interval <3-1350> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement link-mtu <1280-9216>|<unspecified> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement reachable-time <0-3600000>|<unspecified> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement retransmission-timer <0-4294967295>|<unspecified> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement hop-limit <1-255>|<unspecified> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement lifetime <0-9000> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement router-preference <High|Medium|Low> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement managed-flag <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement other-flag <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery router-advertisement enable-consistency-check <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source dhcpv6 set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source dhcpv6 prefix-pool <value> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual server set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual server <name> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix enable <yes|no> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 prefix-pool <value> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery neighbor set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery neighbor <name> set network interface aggregate-ethernet <name> layer3 units <name> ipv6 inherited neighbor-discovery neighbor <name> hw-address <value> set network interface vlan ipv6 dhcp-client set network interface vlan ipv6 dhcp-client enable <yes|no> set network interface vlan ipv6 dhcp-client accept-ra-route <yes|no> set network interface vlan ipv6 dhcp-client default-route-metric <1-65535> set network interface vlan ipv6 dhcp-client preference <low|medium|high> set network interface vlan ipv6 dhcp-client v6-options set network interface vlan ipv6 dhcp-client v6-options enable set network interface vlan ipv6 dhcp-client v6-options enable no set network interface vlan ipv6 dhcp-client v6-options enable yes set network interface vlan ipv6 dhcp-client v6-options enable yes non-temp-addr <yes|no> set network interface vlan ipv6 dhcp-client v6-options enable yes temp-addr <yes|no> set network interface vlan ipv6 dhcp-client v6-options rapid-commit <yes|no> set network interface vlan ipv6 dhcp-client prefix-delegation set network interface vlan ipv6 dhcp-client prefix-delegation enable set network interface vlan ipv6 dhcp-client prefix-delegation enable no set network interface vlan ipv6 dhcp-client prefix-delegation enable yes set network interface vlan ipv6 dhcp-client prefix-delegation enable yes prefix-len-hint <yes|no> set network interface vlan ipv6 dhcp-client prefix-delegation enable yes prefix-len <0-128> set network interface vlan ipv6 dhcp-client prefix-delegation enable yes pfx-pool-name <value> set network interface vlan ipv6 dhcp-client neighbor-discovery set network interface vlan ipv6 dhcp-client neighbor-discovery enable-ndp-monitor <yes|no> set network interface vlan ipv6 dhcp-client neighbor-discovery enable-dad <yes|no> set network interface vlan ipv6 dhcp-client neighbor-discovery dad-attempts <1-10> set network interface vlan ipv6 dhcp-client neighbor-discovery ns-interval <1-3600> set network interface vlan ipv6 dhcp-client neighbor-discovery reachable-time <10-36000> set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server enable <yes|no> set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server source set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server source dhcpv6 set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server source manual set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server source manual server set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> set network interface vlan ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix enable <yes|no> set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix source set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix source dhcpv6 set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix source manual set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> set network interface vlan ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface vlan ipv6 dhcp-client neighbor-discovery neighbor set network interface vlan ipv6 dhcp-client neighbor-discovery neighbor <name> set network interface vlan ipv6 dhcp-client neighbor-discovery neighbor <name> hw-address <value> set network interface vlan ipv6 inherited set network interface vlan ipv6 inherited enable <yes|no> set network interface vlan ipv6 inherited assign-addr set network interface vlan ipv6 inherited assign-addr <name> set network interface vlan ipv6 inherited assign-addr <name> type set network interface vlan ipv6 inherited assign-addr <name> type gua set network interface vlan ipv6 inherited assign-addr <name> type gua enable-on-interface <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type gua prefix-pool <value> set network interface vlan ipv6 inherited assign-addr <name> type gua pool-type set network interface vlan ipv6 inherited assign-addr <name> type gua pool-type dynamic set network interface vlan ipv6 inherited assign-addr <name> type gua pool-type dynamic-id set network interface vlan ipv6 inherited assign-addr <name> type gua pool-type dynamic-id identifier <0-4095> set network interface vlan ipv6 inherited assign-addr <name> type gua advertise set network interface vlan ipv6 inherited assign-addr <name> type gua advertise enable <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type gua advertise onlink-flag <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type gua advertise auto-config-flag <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type ula set network interface vlan ipv6 inherited assign-addr <name> type ula enable-on-interface <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type ula address <ip/netmask> set network interface vlan ipv6 inherited assign-addr <name> type ula prefix <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type ula anycast <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type ula advertise set network interface vlan ipv6 inherited assign-addr <name> type ula advertise enable <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type ula advertise valid-lifetime <0-4294967294>|<infinity> set network interface vlan ipv6 inherited assign-addr <name> type ula advertise preferred-lifetime <0-4294967294>|<infinity> set network interface vlan ipv6 inherited assign-addr <name> type ula advertise onlink-flag <yes|no> set network interface vlan ipv6 inherited assign-addr <name> type ula advertise auto-config-flag <yes|no> set network interface vlan ipv6 inherited neighbor-discovery set network interface vlan ipv6 inherited neighbor-discovery enable-ndp-monitor <yes|no> set network interface vlan ipv6 inherited neighbor-discovery enable-dad <yes|no> set network interface vlan ipv6 inherited neighbor-discovery dad-attempts <1-10> set network interface vlan ipv6 inherited neighbor-discovery ns-interval <1-3600> set network interface vlan ipv6 inherited neighbor-discovery reachable-time <10-36000> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement set network interface vlan ipv6 inherited neighbor-discovery router-advertisement enable <yes|no> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement max-interval <4-1800> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement min-interval <3-1350> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement link-mtu <1280-9216>|<unspecified> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement reachable-time <0-3600000>|<unspecified> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement retransmission-timer <0-4294967295>|<unspecified> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement hop-limit <1-255>|<unspecified> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement lifetime <0-9000> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement router-preference <High|Medium|Low> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement managed-flag <yes|no> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement other-flag <yes|no> set network interface vlan ipv6 inherited neighbor-discovery router-advertisement enable-consistency-check <yes|no> set network interface vlan ipv6 inherited neighbor-discovery dns-server set network interface vlan ipv6 inherited neighbor-discovery dns-server enable <yes|no> set network interface vlan ipv6 inherited neighbor-discovery dns-server source set network interface vlan ipv6 inherited neighbor-discovery dns-server source dhcpv6 set network interface vlan ipv6 inherited neighbor-discovery dns-server source dhcpv6 prefix-pool <value> set network interface vlan ipv6 inherited neighbor-discovery dns-server source manual set network interface vlan ipv6 inherited neighbor-discovery dns-server source manual server set network interface vlan ipv6 inherited neighbor-discovery dns-server source manual server <name> set network interface vlan ipv6 inherited neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface vlan ipv6 inherited neighbor-discovery dns-suffix set network interface vlan ipv6 inherited neighbor-discovery dns-suffix enable <yes|no> set network interface vlan ipv6 inherited neighbor-discovery dns-suffix source set network interface vlan ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 set network interface vlan ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 prefix-pool <value> set network interface vlan ipv6 inherited neighbor-discovery dns-suffix source manual set network interface vlan ipv6 inherited neighbor-discovery dns-suffix source manual suffix set network interface vlan ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> set network interface vlan ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface vlan ipv6 inherited neighbor-discovery neighbor set network interface vlan ipv6 inherited neighbor-discovery neighbor <name> set network interface vlan ipv6 inherited neighbor-discovery neighbor <name> hw-address <value> set network interface vlan units <name> ipv6 dhcp-client set network interface vlan units <name> ipv6 dhcp-client enable <yes|no> set network interface vlan units <name> ipv6 dhcp-client accept-ra-route <yes|no> set network interface vlan units <name> ipv6 dhcp-client default-route-metric <1-65535> set network interface vlan units <name> ipv6 dhcp-client preference <low|medium|high> set network interface vlan units <name> ipv6 dhcp-client v6-options set network interface vlan units <name> ipv6 dhcp-client v6-options enable set network interface vlan units <name> ipv6 dhcp-client v6-options enable no set network interface vlan units <name> ipv6 dhcp-client v6-options enable yes set network interface vlan units <name> ipv6 dhcp-client v6-options enable yes non-temp-addr <yes|no> set network interface vlan units <name> ipv6 dhcp-client v6-options enable yes temp-addr <yes|no> set network interface vlan units <name> ipv6 dhcp-client v6-options rapid-commit <yes|no> set network interface vlan units <name> ipv6 dhcp-client prefix-delegation set network interface vlan units <name> ipv6 dhcp-client prefix-delegation enable set network interface vlan units <name> ipv6 dhcp-client prefix-delegation enable no set network interface vlan units <name> ipv6 dhcp-client prefix-delegation enable yes set network interface vlan units <name> ipv6 dhcp-client prefix-delegation enable yes prefix-len-hint <yes|no> set network interface vlan units <name> ipv6 dhcp-client prefix-delegation enable yes prefix-len <0-128> set network interface vlan units <name> ipv6 dhcp-client prefix-delegation enable yes pfx-pool-name <value> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery enable-ndp-monitor <yes|no> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery enable-dad <yes|no> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dad-attempts <1-10> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery ns-interval <1-3600> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery reachable-time <10-36000> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server enable <yes|no> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server source set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server source dhcpv6 set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix enable <yes|no> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source dhcpv6 set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery neighbor set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery neighbor <name> set network interface vlan units <name> ipv6 dhcp-client neighbor-discovery neighbor <name> hw-address <value> set network interface vlan units <name> ipv6 inherited set network interface vlan units <name> ipv6 inherited enable <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr set network interface vlan units <name> ipv6 inherited assign-addr <name> set network interface vlan units <name> ipv6 inherited assign-addr <name> type set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua enable-on-interface <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua prefix-pool <value> set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua pool-type set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic-id set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua pool-type dynamic-id identifier <0-4095> set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua advertise set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua advertise enable <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua advertise onlink-flag <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type gua advertise auto-config-flag <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula enable-on-interface <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula address <ip/netmask> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula prefix <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula anycast <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula advertise set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula advertise enable <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula advertise valid-lifetime <0-4294967294>|<infinity> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula advertise preferred-lifetime <0-4294967294>|<infinity> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula advertise onlink-flag <yes|no> set network interface vlan units <name> ipv6 inherited assign-addr <name> type ula advertise auto-config-flag <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery set network interface vlan units <name> ipv6 inherited neighbor-discovery enable-ndp-monitor <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery enable-dad <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery dad-attempts <1-10> set network interface vlan units <name> ipv6 inherited neighbor-discovery ns-interval <1-3600> set network interface vlan units <name> ipv6 inherited neighbor-discovery reachable-time <10-36000> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement enable <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement max-interval <4-1800> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement min-interval <3-1350> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement link-mtu <1280-9216>|<unspecified> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement reachable-time <0-3600000>|<unspecified> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement retransmission-timer <0-4294967295>|<unspecified> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement hop-limit <1-255>|<unspecified> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement lifetime <0-9000> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement router-preference <High|Medium|Low> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement managed-flag <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement other-flag <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery router-advertisement enable-consistency-check <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server enable <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server source set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server source dhcpv6 set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server source dhcpv6 prefix-pool <value> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server source manual set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server source manual server set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server source manual server <name> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-server source manual server <name> lifetime <4-3600> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix enable <yes|no> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix source set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix source dhcpv6 prefix-pool <value> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix source manual set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> set network interface vlan units <name> ipv6 inherited neighbor-discovery dns-suffix source manual suffix <name> lifetime <4-3600> set network interface vlan units <name> ipv6 inherited neighbor-discovery neighbor set network interface vlan units <name> ipv6 inherited neighbor-discovery neighbor <name> set network interface vlan units <name> ipv6 inherited neighbor-discovery neighbor <name> hw-address <value> set network tunnel ipsec <name> ipsec-mode <tunnel|transport> set network logical-router <name> vrf <name> ospf area <name> type stub default-route-metric <1-16777215> set network logical-router <name> vrf <name> ospf area <name> type nssa default-information-originate metric <1-16777215> set network logical-router <name> vrf <name> ospfv3 area <name> type stub default-route-metric <1-16777215> set network logical-router <name> vrf <name> ospfv3 area <name> type nssa default-information-originate metric <1-16777215> set network logical-router <name> vrf <name> multicast pim interface <name> dr-priority <1-4294967295> set network logical-router <name> vrf <name> multicast msdp set network logical-router <name> vrf <name> multicast msdp enable <yes|no> set network logical-router <name> vrf <name> multicast msdp global-timer <value> set network logical-router <name> vrf <name> multicast msdp global-authentication <value> set network logical-router <name> vrf <name> multicast msdp originator-id set network logical-router <name> vrf <name> multicast msdp originator-id interface <value> set network logical-router <name> vrf <name> multicast msdp originator-id ip <value> set network logical-router <name> vrf <name> multicast msdp peer set network logical-router <name> vrf <name> multicast msdp peer <name> set network logical-router <name> vrf <name> multicast msdp peer <name> enable <yes|no> set network logical-router <name> vrf <name> multicast msdp peer <name> local-address set network logical-router <name> vrf <name> multicast msdp peer <name> local-address interface <value> set network logical-router <name> vrf <name> multicast msdp peer <name> local-address ip <value> set network logical-router <name> vrf <name> multicast msdp peer <name> peer-as <1-4294967295>|<value> set network logical-router <name> vrf <name> multicast msdp peer <name> peer-address set network logical-router <name> vrf <name> multicast msdp peer <name> peer-address ip <value>|<ip/netmask>|<validate> set network logical-router <name> vrf <name> multicast msdp peer <name> peer-address fqdn <value> set network logical-router <name> vrf <name> multicast msdp peer <name> authentication <value>|<inherit|none> set network logical-router <name> vrf <name> multicast msdp peer <name> max-sa <0-1024> set network logical-router <name> vrf <name> multicast msdp peer <name> inbound-sa-filter <value> set network logical-router <name> vrf <name> multicast msdp peer <name> outbound-sa-filter <value> set network routing-profile multicast pim-interface-timer-profile <name> assert-interval <1-65534> set network routing-profile multicast msdp-auth-profile set network routing-profile multicast msdp-auth-profile <name> set network routing-profile multicast msdp-auth-profile <name> secret <value> set network routing-profile multicast msdp-timer-profile set network routing-profile multicast msdp-timer-profile <name> set network routing-profile multicast msdp-timer-profile <name> keep-alive-interval <1-60> set network routing-profile multicast msdp-timer-profile <name> message-timeout <1-75> set network routing-profile multicast msdp-timer-profile <name> connection-retry-interval <1-60> set network routing-profile rip redistribution-profile <name> static metric <1-16> set network routing-profile rip redistribution-profile <name> connected metric <1-16> set network routing-profile rip redistribution-profile <name> bgp metric <0-16> set network routing-profile rip redistribution-profile <name> ospf metric <0-16>
There are 18 new set shared commands
set shared reports<name> type decryption group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|tls_version|tls_keyxchg|tls_enc|tls_auth|ec_curve|err_index|root_status|proxy_type|policy_name|cn|issuer_cn|root_cn|sni|error|cluster_name|src_dag|dst_dag|src_edl|dst_edl|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set shared reports <name> type desum group-by <serial|time_generated|vsys_name|device_name|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|app|src|dst|srcuser|dstuser|vsys|tls_version|tls_keyxchg|tls_enc|tls_auth|sni|error|err_index|src_edl|dst_edl|cluster_name|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set shared reports <name> type threat group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|threatid|category|severity|direction|http_method|nssai_sst|filedigest|filetype|http2_connection|xff_ip|threat_name|src_edl|dst_edl|dynusergroup_name|hostid|partial_hash|cloud_reportid|cluster_name|flow_type|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|misc|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|flag-nat|flag-pcap|subtype|transaction|captive-portal|flag-proxy|non-std-dport|tunnelid|monitortag|users|category-of-threatid|threat-type> set shared reports <name> type thsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|rule|threatid|srcuser|dstuser|srcloc|dstloc|xff_ip|vsys|from|to|dev_serial|dport|action|severity|inbound_if|outbound_if|category|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|tunnel|direction|assoc_id|ppid|http2_connection|rule_uuid|threat_name|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype|tunnelid|monitortag|category-of-threatid|threat-type> set shared reports <name> type traffic group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|category|session_end_reason|action_source|nssai_sst|nssai_sd|http2_connection|xff_ip|dynusergroup_name|src_edl|dst_edl|hostid|session_owner|policy_id|offloaded|flow_type|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|decrypt-mirror|threat-type|flag-nat|flag-pcap|captive-portal|flag-proxy|non-std-dport|transaction|sym-return|sessionid|flag-decrypt-fwd|tunnelid|monitortag> set shared reports <name> type urlsum group-by <serial|time_generated|vsys_name|device_name|app|category|src|dst|rule|srcuser|dstuser|srcloc|dstloc|vsys|from|to|dev_serial|inbound_if|outbound_if|dport|action|tunnel|url_domain|user_agent|http_method|http2_connection|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|rule_uuid|xff_ip|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|url_category_list|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|monitortag> set shared reports <name> type trsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|xff_ip|rule|srcuser|dstuser|srcloc|dstloc|category|vsys|from|to|dev_serial|dport|action|tunnel|inbound_if|outbound_if|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|assoc_id|http2_connection|rule_uuid|src_edl|dst_edl|dynusergroup_name|s_decrypted|s_encrypted|hostid|nssai_sst|cluster_name|flow_type|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|monitortag|standard-ports-of-app> set shared reports <name> type userid group-by <serial|time_generated|vsys_name|device_name|vsys|ip|user|datasourcename|beginport|endport|datasource|datasourcetype|factortype|factorcompletiontime|factorno|tag_name|origindatasource|direction|cluster_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype> set shared reports <name> type auth group-by <serial|time_generated|vsys_name|device_name|vsys|ip|user|normalize_user|object|authpolicy|authid|vendor|clienttype|event|factorno|authproto|rule_uuid|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|serverprofile|desc|subtype> set shared reports <name> type iptag group-by <serial|time_generated|vsys_name|device_name|vsys|ip|tag_name|event_id|datasourcename|datasource_type|datasource_subtype|cluster_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set shared reports <name> type hipmatch group-by <serial|time_generated|vsys_name|device_name|srcuser|vsys|machinename|src|matchname|os|matchtype|srcipv6|hostid|mac|cluster_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set shared authentication-sequence <name> exit-sequence-on-failure <yes|no> set shared authentication-sequence <name> use-userid-domain <yes|no> set shared admin-role <name> role device webui monitor custom-reports decryption-log <enable|disable> set shared admin-role <name> role device webui monitor custom-reports decryption-summary <enable|disable> set shared admin-role <name> role device webui device dhcp-syslog-server <enable|read-only|disable> set shared admin-role <name> role device webui save object-level-changes <enable|disable> set shared admin-role <name> role device webui commit object-level-changes <enable|disable>
There are 1 new set zone commands
set zone<name> network net-inspection <yes|no>
There are 1 new set x-authenticated-user commands
set x-authenticated-user overwrite-xau<yes|no>
There are 6 new set global-protect commands
set global-protect global-protect-gateway<name> roles <name> lifetime-notify-prior <0-60> set global-protect global-protect-gateway <name> roles <name> lifetime-notify-message <value> set global-protect global-protect-gateway <name> roles <name> inactivity-notify-prior <0-60> set global-protect global-protect-gateway <name> roles <name> inactivity-notify-message <value> set global-protect global-protect-gateway <name> roles <name> admin-logout-notify <yes|no> set global-protect global-protect-gateway <name> roles <name> admin-logout-notify-message <value>
There are 12 new set profiles commands
set profiles virus<name> wfrt-hold-mode <yes|no> set profiles spyware <name> botnet-domains rtype-action set profiles spyware <name> botnet-domains rtype-action svcb <allow|block> set profiles spyware <name> botnet-domains rtype-action https <allow|block> set profiles spyware <name> botnet-domains rtype-action any <allow|block> set profiles vulnerability <name> cloud-inline-analysis <yes|no> set profiles vulnerability <name> mica-engine-vulnerability-enabled set profiles vulnerability <name> mica-engine-vulnerability-enabled <name> set profiles vulnerability <name> mica-engine-vulnerability-enabled <name> inline-policy-action <alert|allow|reset-both|reset-client|reset-server> set profiles vulnerability <name> inline-exception-edl-url [ <inline-exception-edl-url1> <inline-exception-edl-url2>... ] set profiles vulnerability <name> inline-exception-ip-address [ <inline-exception-ip-address1> <inline-exception-ip-address2>... ] set profiles decryption <name> ssl-forward-proxy block-if-sni-mismatch <yes|no>
There are 11 new set reports commands
set reports<name> type decryption group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|tls_version|tls_keyxchg|tls_enc|tls_auth|ec_curve|err_index|root_status|proxy_type|policy_name|cn|issuer_cn|root_cn|sni|error|cluster_name|src_dag|dst_dag|src_edl|dst_edl|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set reports <name> type desum group-by <serial|time_generated|vsys_name|device_name|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|app|src|dst|srcuser|dstuser|vsys|tls_version|tls_keyxchg|tls_enc|tls_auth|sni|error|err_index|src_edl|dst_edl|cluster_name|container_id|pod_namespace|pod_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set reports <name> type threat group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|threatid|category|severity|direction|http_method|nssai_sst|filedigest|filetype|http2_connection|xff_ip|threat_name|src_edl|dst_edl|dynusergroup_name|hostid|partial_hash|cloud_reportid|cluster_name|flow_type|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|misc|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|flag-nat|flag-pcap|subtype|transaction|captive-portal|flag-proxy|non-std-dport|tunnelid|monitortag|users|category-of-threatid|threat-type> set reports <name> type thsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|rule|threatid|srcuser|dstuser|srcloc|dstloc|xff_ip|vsys|from|to|dev_serial|dport|action|severity|inbound_if|outbound_if|category|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|tunnel|direction|assoc_id|ppid|http2_connection|rule_uuid|threat_name|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype|tunnelid|monitortag|category-of-threatid|threat-type> set reports <name> type traffic group-by <serial|time_generated|src|dst|natsrc|natdst|rule|srcuser|dstuser|srcloc|dstloc|app|vsys|from|to|inbound_if|outbound_if|sport|dport|natsport|natdport|proto|action|tunnel|rule_uuid|s_encrypted|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|vsys_name|device_name|parent_session_id|parent_start_time|category|session_end_reason|action_source|nssai_sst|nssai_sd|http2_connection|xff_ip|dynusergroup_name|src_edl|dst_edl|hostid|session_owner|policy_id|offloaded|flow_type|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|pbf-s2c|pbf-c2s|decrypt-mirror|threat-type|flag-nat|flag-pcap|captive-portal|flag-proxy|non-std-dport|transaction|sym-return|sessionid|flag-decrypt-fwd|tunnelid|monitortag> set reports <name> type urlsum group-by <serial|time_generated|vsys_name|device_name|app|category|src|dst|rule|srcuser|dstuser|srcloc|dstloc|vsys|from|to|dev_serial|inbound_if|outbound_if|dport|action|tunnel|url_domain|user_agent|http_method|http2_connection|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|rule_uuid|xff_ip|src_edl|dst_edl|hostid|dynusergroup_name|nssai_sst|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|url_category_list|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|monitortag> set reports <name> type trsum group-by <serial|time_generated|vsys_name|device_name|app|src|dst|xff_ip|rule|srcuser|dstuser|srcloc|dstloc|category|vsys|from|to|dev_serial|dport|action|tunnel|inbound_if|outbound_if|category-of-app|subcategory-of-app|technology-of-app|container-of-app|risk-of-app|parent_session_id|parent_start_time|assoc_id|http2_connection|rule_uuid|src_edl|dst_edl|dynusergroup_name|s_decrypted|s_encrypted|hostid|nssai_sst|cluster_name|flow_type|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|dst_category|dst_profile|dst_model|dst_vendor|dst_osfamily|dst_osversion|dst_host|dst_mac|container_id|pod_namespace|pod_name|src_dag|dst_dag|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|tunnelid|monitortag|standard-ports-of-app> set reports <name> type userid group-by <serial|time_generated|vsys_name|device_name|vsys|ip|user|datasourcename|beginport|endport|datasource|datasourcetype|factortype|factorcompletiontime|factorno|tag_name|origindatasource|direction|cluster_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|subtype> set reports <name> type auth group-by <serial|time_generated|vsys_name|device_name|vsys|ip|user|normalize_user|object|authpolicy|authid|vendor|clienttype|event|factorno|authproto|rule_uuid|cluster_name|src_category|src_profile|src_model|src_vendor|src_osfamily|src_osversion|src_host|src_mac|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time|serverprofile|desc|subtype> set reports <name> type iptag group-by <serial|time_generated|vsys_name|device_name|vsys|ip|tag_name|event_id|datasourcename|datasource_type|datasource_subtype|cluster_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time> set reports <name> type hipmatch group-by <serial|time_generated|vsys_name|device_name|srcuser|vsys|machinename|src|matchname|os|matchtype|srcipv6|hostid|mac|cluster_name|day-of-receive_time|hour-of-receive_time|quarter-hour-of-receive_time>