background image

 

92

D-Link DES-3226L Command Line Reference

show authentication

This command displays the ordered authentication methods for all authentication login lists.

Format. 

show authentication

Mode  

Privileged EXEC

Authentication Login List  

This displays the authentication login listname.

Method 1  

This displays the first method in the specified authentication login list, if any.

Method 2  

This displays the second method in the specified authentication login list, if 
any.

Method 3  

This displays the third method in the specified authentication login list, if any.

show authentication users

This command displays information about the users assigned to the specified authentication login list. If 
the login is assigned to non-configured users, the user “default” will appear in the user column.

Format  

show authentication users

 

<listname>

Mode  

Privileged EXEC

User  

This field displays the user assigned to the specified authentication login list.

Component  

This field displays the component (User or 802.1x) for which the authentica-
tion login list is assigned.

show dot1x

This command is used to show a summary of the global dot1x configuration, summary information of 
the dot1x configuration for a specified port or all ports, the detailed dot1x configuration for a specified 
port and the dot1x statistics for a specified port - depending on the tokens used.

Format  

show dot1x

 

[{summary {<

slot/port

> | all} | {detail <

slot/port

>} | 

{statistics <

slot/port

>}]

Mode  

Privileged EXEC

If  none of the optional parameters are used, the global dot1x configuration summary is displayed.

Administrative mode  

Indicates whether authentication control on the switch is enabled or 

disabled.

If the optional parameter 'summary {<slot/port> | all}' is used, the dot1x configuration for the specified 
port or all ports are displayed.

Port  

The interface whose configuration is displayed.

Control Mode  

The configured control mode for this port. Possible values are force-unau-

thorized | force-authorized | auto.

Operating Control Mode  

The control mode under which this port is operating. Possible 

values are authorized | unauthorized.

Reauthentication Enabled  

Indicates whether re-authentication is enabled on this port.

Summary of Contents for DES-3226L

Page 1: ...CLI Command Reference Layer 2 Switch 24 Port 10 100 Managed Switch Plus 2 Combo Gigabit Copper SFP Ports DES 3226L Release 2 Business Class Networking...

Page 2: ......

Page 3: ...CLI Line Editing Conventions 22 Using the No Form of a Command 22 Using CLI Help 23 Accessing the CLI 23 Command Line Interface Modes 25 Mode based Topology 26 Mode based Command Hierarchy 26 Command...

Page 4: ...36 auto negotiate 36 no auto negotiate 36 auto negotiate all 36 no auto negotiate all 36 deleteport Interface Config 36 deleteport Global Config 36 monitor session 37 no monitor session 37 no monitor...

Page 5: ...server enable traps multiusers 45 snmp server enable traps stpmode 46 no snmp server enable traps stpmode 46 snmptrap 46 no snmptrap 46 snmptrap snmpversion 46 snmptrap ipaddr 47 snmptrap mode 47 no s...

Page 6: ...ode 59 port lacpmode all 59 no port lacpmode all 59 port channel adminmode 59 no port channel adminmode 59 port channel linktrap 59 no port channel linktrap 60 port channel name 60 show port channel b...

Page 7: ...ng tree hello time 69 spanning tree max age 69 no spanning tree max age 69 spanning tree max hops 69 no spanning tree max hops 70 spanning tree mst 70 no spanning tree mst 70 spanning tree mst instanc...

Page 8: ...ode 84 no users snmpv3 accessmode 84 users snmpv3 authentication 84 no users snmpv3 authentication 85 users snmpv3 encryption 85 no users snmpv3 encryption 85 show loginsession 85 show users 86 discon...

Page 9: ...th 96 radius server primary 96 radius server retransmit 97 no radius server retransmit 97 radius server timeout 97 no radius server timeout 97 show radius 97 show radius accounting 98 show radius stat...

Page 10: ...g persistent 115 logging host 115 logging host remove 115 logging syslog 115 no logging syslog 115 show logging 115 show logging persistent 116 show logging hosts 116 show logging traplogs 116 System...

Page 11: ...List of Figures 11 List of Figures Figure 1 Mode based CLI 26 Figure 2 Syntax Error Message 28...

Page 12: ...12 D Link DES 3226L Command Line Reference...

Page 13: ...es Table 1 Parameter Conventions 20 Table 2 Parameter Descriptions 20 Table 3 Type of Slots 21 Table 4 Type of Ports 21 Table 5 CLI Editing Conventions 22 Table 6 CLI Command Modes 25 Table 7 Broadcas...

Page 14: ...14 D Link DES 3226L Command Line Reference...

Page 15: ...describes the commands you use to configure management access and basic port settings z Switching Commands on page 51 describes the commands you use to configure and view switch properties such as VLA...

Page 16: ...16 D Link DES 3226L Command Line Reference...

Page 17: ...ntinues to evolve from high end backbone applications to desktop switching applications The price of the technology continues to decline while performance and feature sets continue to improve The D Li...

Page 18: ...18 D Link DES 3226L Command Line Reference...

Page 19: ...parameters The following example describes the network parms command syntax Format network parms ipaddr netmask gateway z network parms is the command name z ipaddr and netmask are parameters and repr...

Page 20: ...xt inside them square brackets value Indicates an optional parameter that you can enter in place of the brackets and text inside them curly braces choice1 choice2 Indicates that you must select a para...

Page 21: ...le quotation marks to identify character strings for example System Name with Spaces An empty string is not valid Table 3 Type of Slots Slot Type Description Physical slot numbers Physical slot number...

Page 22: ...enable a disabled feature or to enable a feature that is disabled by default Only the configuration commands are available in the no form Table 5 CLI Editing Conventions Key Sequence Description DEL...

Page 23: ...addr Enter the IP Address If there are no additional command keywords or parameters or if additional parameters are optional the following message appears in the output cr Press Enter to execute the c...

Page 24: ...24 D Link DES 3226L Command Line Reference...

Page 25: ...From the User EXEC mode enter enable Switch To exit to the User EXEC mode enter exit or press Ctrl Z VLAN Mode From the Privileged EXEC mode enter vlan database Switch Vlan To exit to the Privi leged...

Page 26: ...ne mode are not available until you switch to that particular mode with the exception of the User EXEC mode commands You can execute the User EXEC mode commands in the Privileged EXEC mode The command...

Page 27: ...ifications to the run ning configuration From the Global Configuration mode you can enter the System Configura tion mode the Physical Port Configuration mode the Interface Configuration mode or the Pr...

Page 28: ...dditional parameters you enter are treated as optional parameters If any of the parameters are not recognized a syntax error message is displayed 2 After the command is successfully parsed and validat...

Page 29: ...To manage the device by using SNMP see SNMP Community Commands on page 42 To manage the device by using SSH see Secure Shell SSH Commands on page 100 To manage the device by using telnet the switch m...

Page 30: ...e until the session is ended or an abnormal network error ends the session Default enabled Format transport input telnet Mode Line Config no transport input telnet This command disables telnet session...

Page 31: ...IVL system the fdbid all parameter is required The seconds parameter must be within the range of 10 to 1 000 000 seconds Fdbid Forwarding database ID indicates which forwarding database s aging timeo...

Page 32: ...group address b 1 z The second character of the twelve character macaddr must be 2 6 A or E A locally administered address must have bit 6 On b 1 and bit 7 Off b 0 Format network mac address macaddr M...

Page 33: ...rompt This command changes the name of the prompt The length of name may be up to 64 alphanumeric characters Format set prompt prompt_string Mode Privileged EXEC show forwardingdb agetime This command...

Page 34: ...olon between each byte Bit 1 of byte 0 must be set to a 1 and bit 0 to a 0 i e byte 0 should have the following mask xxxx xx10 The MAC address used by this bridge when it must be referred to in a uniq...

Page 35: ...eout Baud Rate bps The default baud rate at which the serial port will try to connect The available values are 1200 2400 4800 9600 19200 38400 57600 and 115200 baud The factory Default is 9600 baud Ch...

Page 36: ...otiate all This command enables automatic negotiation on all ports The default value is enable Format auto negotiate all Mode Global Config no auto negotiate all This command disables automatic negoti...

Page 37: ...d the port to any desired VLANs Note This command sets the monitor session port monitoring mode to disable Format no monitor session session id Mode Global Config no monitor This command removes all t...

Page 38: ...on id The possible values are Enabled and Disabled Probe Port It is the probe port destination port for the session identified with session id If probe port is not set this field is blank List of Sour...

Page 39: ...x 10h 10BASE T half duplex 10f 10BASE T full duplex storm control broadcast This command enables broadcast storm recovery mode If the mode is enabled broadcast storm recovery with high and low thresho...

Page 40: ...disables 802 3x flow control for the switch Note This command only applies to full duplex mode ports Format no storm control flowcontrol Mode Global Config show mac address table multicast This comman...

Page 41: ...Multicast Forwarding Database table This value is also known as the MFDB high water mark Current Entries Displays the current number of entries in the MFDB show monitor session This command displays...

Page 42: ...r or not to send a trap when link status changes The factory default is enabled LACP Mode Displays whether LACP is enabled or disabled on this port show storm control This command displays switch conf...

Page 43: ...Mode Global Config snmp server community ipaddr This command sets a client IP address for an SNMP community The address is the associated community SNMP packet sending address and is used along with...

Page 44: ...no SNMP requests using this community are accepted In this case the SNMP manager associated with this community cannot manage the switch until the Status is changed back to Enable Default The default...

Page 45: ...on page 47 Default enabled Format snmp server enable traps linkmode Mode Global Config no snmp server enable traps linkmode This command disables Link Up Down traps for the entire switch Format no sn...

Page 46: ...ed to be unique however the name and ipaddr pair must be unique Multiple entries can exist with the same name as long as they are associated with a different ipaddr The reverse scenario is also accept...

Page 47: ...ptrap mode name ipaddr Mode Global Config no snmptrap mode This command deactivates an SNMP trap Format no snmptrap mode name ipaddr Mode Global Config snmp trap link status This command enables link...

Page 48: ...community The requesting entity s IP address is ANDed with the Subnet Mask before being compared to the IP Address Note If the Subnet Mask is set to 0 0 0 0 an IP Address of 0 0 0 0 matches all IP ad...

Page 49: ...lt is enabled Indicates whether spanning tree traps will be sent show snmptrap This command displays SNMP trap receivers Trap messages are sent across a network to an SNMP Network Manager These messag...

Page 50: ...50 D Link DES 3226L Command Line Reference...

Page 51: ...ds VLANs allow users located on different physical networks to be on the same logical network This section describes the commands you use to view and configure VLAN settings vlan This command creates...

Page 52: ...blank string Format vlan name 2 4094 name Mode VLAN database no vlan name This command sets the name of a VLAN to a blank string The VLAN ID is a valid VLAN identification number ID range is 2 4094 Fo...

Page 53: ...VLAN tagged frames are forwarded in accordance with the IEEE 802 1Q VLAN Specification Default admit all Format vlan port acceptframe all vlanonly all Mode Global Config no vlan port acceptframe all...

Page 54: ...Mode Global Config vlan pvid This command changes the VLAN ID per interface Default 1 Format vlan pvid 1 4094 Mode Interface Config no vlan pvid This command sets the VLAN ID per interface to 1 Format...

Page 55: ...n this VLAN The permis sible values are Include This port is always a member of this VLAN This is equivalent to registration fixed in the IEEE 802 1Q standard Exclude This port is never a member of th...

Page 56: ...gged frames or priority tagged frames received on this port are accepted and assigned the value of the Port VLAN ID for this port With either option VLAN tagged frames are forwarded in accordance to t...

Page 57: ...el 802 3AD Commands This section describes the commands you use to configure link aggregation groups LAG which are also called port channels Link aggregation allows you to combine multiple full duplex...

Page 58: ...no port channel logical slot port all Mode Global Config clear port channel Use this command to clear all configured port channels Format clear port channel Mode Privileged EXEC port channel staticca...

Page 59: ...The option all sets every configured port channel with the same administrative mode setting Format port channel adminmode all Mode Global Config no port channel adminmode This command disables a port...

Page 60: ...ce as well as a summary of individual port channels Format show port channel brief Mode Privileged EXEC User EXEC Static Capability This field displays whether or not the device has static capability...

Page 61: ...Group Management Protocol IGMP Snooping on the D Link DES 3226L switch The IGMP Snooping feature can help conserve bandwidth because it allows the switch to forward IP multicast traffic only to conne...

Page 62: ...nd enables or disables IGMP Snooping fast leave admin mode on a selected interface or VLAN Enabling fast leave allows the switch to immediately remove the layer 2 LAN interface from its forwarding tab...

Page 63: ...cular interface or VLAN The Maximum Response time is the amount of time in seconds that a switch will wait after sending a query on an interface because it did not receive a report for a particular gr...

Page 64: ...at set igmp mrouter vlanId Mode Interface Config no set igmp mrouter This command disables multicast router mode for a particular VLAN ID vlanId Format no set igmp mrouter vlanId Mode Interface Config...

Page 65: ...ther Fast Leave mode is enabled Group Membership Interval Displays the amount of time in seconds that the device waits for a report from a particular group on a particular interface before deleting th...

Page 66: ...e table as a result of a learning process or protocol Description The text description of this multicast table entry Interfaces The list of interfaces that are designated for forwarding Fwd and filter...

Page 67: ...slot port all Mode Global Config spanning tree configuration name This command sets the Configuration Identifier Name for use in identifying the configuration that this switch is currently using The...

Page 68: ...parameter to a new value The Force Protocol Version can be one of the following z 802 1d ST BPDUs are transmitted rather than MST BPDUs IEEE 802 1d functionality supported z 802 1w RST BPDUs are tran...

Page 69: ...internal spanning tree to two Format no spanning tree hello time Mode Interface Config spanning tree max age This command sets the Bridge Max Age parameter to a new value for the common and internal...

Page 70: ...fic multiple spanning tree instance or the common and internal spanning tree instance depending on the mstid parameter The port priority value is a number in the range of 0 to 240 in increments of 16...

Page 71: ...of 0 to 61440 in increments of 4096 If you specify 0 defined as the default CIST ID as the mstid this command sets the Bridge Priority parameter to a new value for the common and internal spanning tr...

Page 72: ...isting VLAN ID Format no spanning tree mst vlan mstid vlanid Mode Global Config spanning tree port mode This command sets the Administrative Switch Port State for this port to enabled Default disabled...

Page 73: ...bridge It is made up from the bridge pri ority and the base MAC address of the bridge Root Path Cost Value of the Root Path Cost parameter for the common and internal span ning tree Root Port Identif...

Page 74: ...IEEE 802 1d based upon the Force Protocol Version parameter Configuration Name Identifier used to identify the configuration currently being used Configuration Revision Level Identifier used to ident...

Page 75: ...ted MST instance It is made up from the port priority and the interface number of the port Port Priority The priority for a particular port within the selected MST instance The port priority is displa...

Page 76: ...ng if a topology change is in progress for this port Hello Time The hello time in use for this port Edge Port The configured value indicating if this port is an edge port Edge Port Status The derived...

Page 77: ...instance show spanning tree vlan This command displays the association between a VLAN and a multiple spanning tree instance The vlanid corresponds to an existing VLAN ID Format show spanning tree vla...

Page 78: ...Current attributes are a VLAN or multicast group There is an instance of this timer on a per Port per GARP participant basis Permissible values are 10 to 100 centiseconds 0 1 to 1 0 seconds The facto...

Page 79: ...service dot1p mapping This command maps an 802 1p priority to an internal traffic class The userpriority parameter is the 802 1p priority level The value ranges from 0 7 The trafficclass parameter spe...

Page 80: ...0 value is the percentage of bandwidth to limit For example a value of 20 means that the port speed for ingress traffic is at 20 of the maximum rate The rate 0 10000000 value is the absolute bandwidth...

Page 81: ...t port Mode Privileged EXEC show interfaces cos queue This command displays the class of service queue configuration for the specified interface The slot port parameter is optional and is only valid o...

Page 82: ...82 D Link DES 3226L Command Line Reference...

Page 83: ...s The D Link DES 3226L switch has two default users admin and guest The admin user can view and configure system settings and the guest user can view settings This section describes the commands you u...

Page 84: ...e for the admin user and readonly for all other users Default admin readwrite other readonly Format users snmpv3 accessmode username readonly readwrite Mode Global Config no users snmpv3 accessmode Th...

Page 85: ...sword so it must be a minimum of eight characters If you select none you do not need to provide a key The username value is the login user name associated with the specified encryption Default no encr...

Page 86: ...entication protocol to be used for the specified login user SNMPv3 Encryption This field displays the encryption protocol to be used for the speci fied login user disconnect This command closes a teln...

Page 87: ...st name is invalid or does not match an existing authentication login list z The specified authentication login list is assigned to any user or to the non configured user for any component z The login...

Page 88: ...iming out the supplicant The count value must be in the range 1 10 Default 2 Format dot1x max req count Mode Interface Config no dot1x max req This command sets the maximum number of times the authent...

Page 89: ...Default auto Format dot1x port control all force unauthorized force authorized auto Mode Global Config no dot1x port control All This command sets the authentication mode to be used on all ports to au...

Page 90: ...must be a value in the range 1 65535 quiet period Sets the value in seconds of the timer used by the authenticator state machine on this port to define periods of time in which it will not attempt to...

Page 91: ...tlogin This command assigns the authentication login list to use for non configured users when attempting to log in to the system This setting is overridden by the authentication login list assigned t...

Page 92: ...ent User or 802 1x for which the authentica tion login list is assigned show dot1x This command is used to show a summary of the global dot1x configuration summary information of the dot1x configurati...

Page 93: ...t Period The timer used by the authenticator state machine on the specified port to determine when to send an EAPOL EAP Request Identity frame to the suppli cant The value is expressed in seconds and...

Page 94: ...or EAP Response Frames Received The number of valid EAP response frames other than resp id frames that have been received by this authenticator EAP Request Id Frames Transmitted The number of EAP requ...

Page 95: ...ures the IP address to use to connect to a RADIUS authentication server You can configure up to 3 servers per RADIUS client If the maximum number of configured servers is reached the command fails unt...

Page 96: ...secret is configured for the RADIUS authentication or RADIUS accounting server The IP address provided must match a previously configured server When this command is executed the secret is prompted N...

Page 97: ...value Format no radius server retransmit Mode Global Config radius server timeout This command sets the timeout value in seconds after which a request must be retransmitted to the RADIUS server if no...

Page 98: ...d EXEC If the optional token statistics ipaddr is not included then only the accounting mode and the RADIUS accounting server details are displayed Mode Enabled or disabled IP Address The configured I...

Page 99: ...P Address specified must match that of a previously configured RADIUS server On execution the following fields are displayed Format show radius statistics ipaddr Mode Privileged EXEC If the IP address...

Page 100: ...server Unknown Types The number of RADIUS packets of unknown types which were received from this server on the authentication port Packets Dropped The number of RADIUS packets received from this serv...

Page 101: ...ut value for active sessions does not become effective until the session is re accessed Also any keystroke activates the new timeout duration Default 5 Format sshcon timeout 1 160 Mode Privileged EXEC...

Page 102: ...The protocol level can be set to TLS1 SSL3 or to both TLS1 and SSL3 Default SSL3 and TLS1 Format ip http secure protocol SSL3 TLS1 Mode Privileged EXEC ip http secure server This command is used to en...

Page 103: ...rivileged EXEC show ip http This command displays the http settings for the switch Format show ip http Mode Privileged EXEC Secure Server Administrative Mode This field indicates whether the administr...

Page 104: ...104 D Link DES 3226L Command Line Reference...

Page 105: ...r commands clear some or all of the settings to factory defaults System Information and Statistics Commands This section describes the commands you use to view information about system features compon...

Page 106: ...are Version The release version revision number of the code currently running on the switch Operating System The operating system currently running on the switch Network Processing Device The type of...

Page 107: ...equested to be transmitted to the Broadcast address including those that were discarded or not sent Transmit Packet Errors The number of outbound packets that could not be transmitted because of error...

Page 108: ...ts Received 1024 1518 Octets The total number of packets including bad packets received that were between 1024 and 1518 octets in length inclu sive excluding framing bits but including FCS octets Pack...

Page 109: ...orwarding process Local Traffic Frames The total number of frames dropped in the forward ing process because the destination address was located off of this port 802 3x Pause Frames Received A count o...

Page 110: ...number of octets Oversized The total number of frames that exceeded the max permitted frame size This counter has a max increment rate of 815 counts per sec at 10 Mb s Underrun Errors The total number...

Page 111: ...ames of any type that have been received by this authenticator EAPOL Frames Transmitted The number of EAPOL frames of any type that have been transmitted by this authenticator Time Since Counters Last...

Page 112: ...nt their being deliverable to a higher layer protocol A possible reason for dis carding a packet could be to free up buffer space Most Address Entries Ever Used The highest number of Forwarding Data b...

Page 113: ...how mac addr table macaddr all Mode Privileged EXEC Mac Address A unicast MAC address for which the switch has forwarding and or filtering information The format is 6 or 8 two digit hexadecimal number...

Page 114: ...System Name Name used to identify the switch System Location Text used to identify the location of the switch May be up to 31 alpha numeric characters The factory default is blank System Contact Text...

Page 115: ...514 Level Critical Format logging host ipaddress port severitylevel Mode Global Config logging host remove This command disables logging to host See show logging hosts on page 116 for a list of host...

Page 116: ...g Messages with an equal or lower numerical severity are logged Persistent Log Count The number of messages received by the log process This includes messages that are dropped or ignored show logging...

Page 117: ...rameter is the UDP port used as the destination of packets sent as part of the traceroute This port should be an unused port on the destination system Format traceroute ipaddr port Mode Privileged EXE...

Page 118: ...at clear traplog Mode Privileged EXEC clear vlan This command resets VLAN configuration parameters to the factory defaults Format clear vlan Mode Privileged EXEC logout This command closes the current...

Page 119: ...respectively During the download of a configuration script the copy command validates the script In case of any error the command lists all the lines at the end of the validation process and prompts y...

Page 120: ...ult configuration however you are not prevented from applying scripts on systems with non default configurations Note Scripts must conform to the following rules The file extension must be scr A maxim...

Page 121: ...f the script Size Size of the script script show This command displays the contents of a script file The parameter scriptname is the name of the script file Format script show scriptname Mode Privileg...

Page 122: ...122 D Link DES 3226L Command Line Reference...

Page 123: ...that dynamically maps Internet addresses to physical hardware addresses on a LAN Aging When an entry for a node is added to the lookup table of a switch it is given a timestamp Each time a packet is...

Page 124: ...n and correction FCS is used in X 25 HDLC Frame Relay and other data link layer protocols G GE See Gigabit Ethernet on page 124 Gigabit Ethernet A high speed Ethernet connection H hop count The number...

Page 125: ...ed based on a MAC Address in conjunction with a VLAN ID L LAN See Local Area Network on page 125 Learning The bridge examines the Layer 2 source addresses of every frame on the attached networks calle...

Page 126: ...the administrator to keep close track of switch performance and alter it if necessary Port mirroring can be managed locally or remotely An administrator configures port mirroring by assigning a port...

Page 127: ...2u and SNMPv2 and updated after much review The documents defing this protocol will soon be published as RFCs SNMP See Simple Network Management Protocol on page 127 SODIMM Small Outline Dual Inline M...

Page 128: ...al area networks LANs X XModem One of the most popular file transfer protocols FTPs Xmodem is fairly effective at detecting errors It sends blocks of data together with a checksum and then waits for a...

Reviews: