background image

DES-3526 Layer 2 Fast Ethernet Switch  

 

DES-3526:4# 

 

config 802.1x auth_protocol 

Purpose 

Used to configure the 802.1x authentication protocol on the Switch. 

Syntax 

config 802.1x auth_protocol [radius_eap | radius_pap] 

Description 

The config 802.1x auth_protocol command enables you to configure 
the authentication protocol. 

Parameters 

radius_eap | radius_pap

 – Specify the type of authentication protocol 

desired. 

Restrictions Only 

administrator-level users can issue this command. 

Example usage: 

To configure the authentication protocol on the Switch: 

DES-3526:4# config 802.1x auth_protocol radius_pap 

Command: config 802.1x auth_protocol local radius_pap 

 

Success. 

 

DES-3526:4# 

 

config 802.1x init 

Purpose 

Used to initialize the 802.1x function on a range of ports. 

Syntax 

config 802.1x init {port_based ports [<portlist> | all] | 
mac_based [ports] [<portlist> | all] {mac_address <macaddr>}] 

Description 

The 

config 802.1x init 

command is used to immediately initialize the 

802.1x functions on a specified range of ports or for specified MAC 
addresses operating from a specified range of ports. 

Parameters 

port_based 

– This instructs the Switch to initialize 802.1x functions 

based only on the port number. Ports approved for initialization can 
then be specified. 

mac_based  

 This instructs the Switch to initialize 802.1x functions 

based only on the MAC address. MAC addresses approved for 
initialization can then be specified. 

ports <portlist>

 

 Specifies a port or range of ports to be configured.  

all 

 Specifies all of the ports on the Switch. 

mac_address <macaddr>

 - Enter the MAC address to be initialized. 

 

142

Summary of Contents for DES-3526 - Switch - Stackable

Page 1: ...DES 3526 Layer 2 Switch Command Line Interface Reference Manual Release 2 Second Edition June 2004 651ES3526025 Printed In Taiwan RECYCLABLE...

Page 2: ...n e Das Ger t ist gefallen und oder das Geh use ist besch digt f Wenn das Ger t deutliche Anzeichen eines Defektes aufweist 16 Bei Reparaturen d rfen nur Orginalersatzteile bzw den Orginalteilen entsp...

Page 3: ...ackage returned to D Link without an RMA number will be rejected and shipped back to Purchaser at Purchaser s expense and D Link reserves the right in such a case to levy a reasonable handling charge...

Page 4: ...or defective media with software that substantially conforms to D Link s functional specifications for the Software or to refund at D Link s sole discretion Except as otherwise agreed by D Link in wri...

Page 5: ...OR DATA CONTAINED IN STORED ON OR INTEGRATED WITH ANY PRODUCT RETURNED TO D LINK FOR WARRANTY SERVICE RESULTING FROM THE USE OF THE PRODUCT RELATING TO WARRANTY SERVICE OR ARISING OUT OF ANY BREACH OF...

Page 6: ...This is a Class A product In a domestic environment this product may cause radio interference in which case the user may be required to take adequate measures vi...

Page 7: ...ing Database Commands 86 Broadcast Storm Control Commands 94 QoS Commands 96 Port Mirroring Commands 104 VLAN Commands 108 Asymmetric VLAN Commands 115 Link Aggregation Commands 117 Basic IP Commands...

Page 8: ...D Link Single IP Management Commands 220 Command History List 232 Technical Specifications 236...

Page 9: ...ting a VT 100 terminal and a serial port configured as above is then connected to the Switch s serial port via an RS 232 DB 9 cable With the serial port properly connected to a management computer the...

Page 10: ...known The IP address may be set using the Command Line Interface CLI over the console serial port as follows 1 Starting at the command line prompt enter the commands config ipif System ipaddress xxx...

Page 11: ...an IP address of 10 53 13 144 with a subnet mask of 255 0 0 0 The system message Success indicates that the command was executed successfully The Switch can now be configured and managed via Telnet SN...

Page 12: ...RAM and reloaded when the Switch is rebooted If the Switch is rebooted without using the save command the last configuration saved to NV RAM will be loaded Connecting to the Switch The console interf...

Page 13: ...mand prompt DES 3526 4 There are a number of helpful features included in the CLI Entering the command will display a list of all of the top level commands Figure 2 2 The Command When you enter a comm...

Page 14: ...next possible sub commands in sequential order by repeatedly pressing the Tab key To re enter the previous command at the command prompt press the up arrow cursor key The previous command will appear...

Page 15: ...recognized by the CLI the top level commands will be displayed under the Available commands prompt Figure 2 5 The Next Available Commands Prompt The top level commands consist of commands such as show...

Page 16: ...mple all of the possible next parameters for the show command are displayed At the next command prompt the up arrow was used to re enter the show command followed by the account parameter The CLI then...

Page 17: ...n_name 32 space and the network address in the network_address space Do not type the angle brackets Example Command create ipif Engineering vlan Design ipaddress 10 24 22 5 255 0 0 0 square brackets P...

Page 18: ...e right Left Arrow Moves the cursor to the left Right Arrow Moves the cursor to the right Up Arrow Repeats the previously entered command Each time the up arrow is pressed the command previous to that...

Page 19: ...DES 3526 Layer 2 Fast Ethernet Switch a Displays the remaining pages without pausing between pages Enter Displays the next line or table entry 11...

Page 20: ...0_minutes 15_minutes enable clipaging disable clipaging enable telnet tcp_port_number 1 65535 disable telnet enable web tcp_port_number 1 65535 disable web save reboot reset config system login logout...

Page 21: ...Purpose Used to configure user accounts Syntax config account username Description The config account command configures a user account that has been created using the create account command Parameter...

Page 22: ...created DES 3526 4 show account Command show account Current Accounts Username Access Level dlink Admin Total Entries 1 DES 3526 4 delete account Purpose Used to delete an existing user account Syntax...

Page 23: ...S 3526 4 show session Command show session ID Login Time Live Time From Level Name 8 00000 days 00 00 37 03 36 27 Serial Port 4 Anonymous show switch Purpose Used to display general information about...

Page 24: ...nt System Name DES 3526 System Location 7th_flr_east_cabinet System Contact Julius_Erving_212 555 6666 Spanning Tree Disabled GVRP Disabled IGMP Snooping Disabled TELNET Enabled TCP 23 WEB Enabled TCP...

Page 25: ...115200 The serial bit rate that will be used to communicate with the management host There are four options 9600 19200 38400 115200 never No time limit on the length of time the console can be open wi...

Page 26: ...eters None Restrictions Only administrator level users can issue this command Example usage To enable pausing of the screen display when the show command output reaches the end of the page DES 3526 4...

Page 27: ...l use to listen for Telnet requests Parameters tcp_port_number 1 65535 The TCP port number TCP ports are numbered between 1 and 65535 The well known TCP port for the Telnet protocol is 23 Restrictions...

Page 28: ..._number 1 65535 The TCP port number TCP ports are numbered between 1 and 65535 The well known port for the Web based management software is 80 Restrictions Only administrator level users can issue thi...

Page 29: ...onfiguration will be loaded into the Switch s memory each time the Switch is restarted Parameters None Restrictions Only administrator level users can issue this command Example usage To save the Swit...

Page 30: ...ings are restored on the Switch The Switch will save and reboot after the settings are changed to default Rebooting will clear all entries in the Forwarding Data Base If no parameter is specified the...

Page 31: ...mmand login UserName logout Purpose Used to log out a user from the Switch s console Syntax logout Description This command terminates the current user s session on the Switch s console Parameters Non...

Page 32: ...ed Parameters all Configure all ports on the Switch portlist Specifies a port or range of ports to be configured speed Allows the user to adjust the speed for a port or range of ports The user has a c...

Page 33: ...he configuration of all ports on a standalone switch DES 3526 4 show ports Command show ports Port Port Settings Connection Address State Speed Duplex FlowCtrl Speed Duplex FlowCtrl Learning 1 Enabled...

Page 34: ...State Speed Duplex FlowCtrl Speed Duplex FlowCtrl Learning 1 Enabled Auto Disabled Link Down Enabled Description dads1 2 Enabled Auto Disabled Link Down Enabled Description 3 Enabled Auto Disabled Lin...

Page 35: ...k_no 0 10 lock_address_mode Permanent DeleteOnTimeout DeleteOnReset Description This command allows for the configuration of the port security feature Only the ports listed in the portlist are affecte...

Page 36: ...ty entry by port VLAN name and MAC address Parameters vlan name vlan_name 32 Enter the corresponding vlan name of the port which the user wishes to delete mac_address macaddr Enter the corresponding M...

Page 37: ...t_security Purpose Used to display the current port security configuration Syntax show port_security ports portlist Description This command is used to display port security information of the Switch...

Page 38: ...ty String is used for authentication NoAuthNoPriv v3 Username Username is used for authentication NoAuthNoPriv v3 MD5 or SHA Authentication is based on the HMAC MD5 or HMAC SHA algorithms AuthNoPriv v...

Page 39: ...r show trusted_host ipaddr enable snmp traps enable snmp authenticate_traps show snmp traps disable snmp traps disable snmp authenticate_traps config snmp system contact sw_contact config snmp system...

Page 40: ...y specifying the auth_password below This method is recommended by_key Requires the SNMP user to enter a encryption key for authentication and privacy The key is defined by specifying the key in hex f...

Page 41: ...e Adding this parameter will add no encryption Restrictions Only administrator level users can issue this command Example usage To create an SNMP user on the Switch DES 3526 4 create snmp user dlink d...

Page 42: ...configured on the Switch DES 3526 4 show snmp user Command show snmp user Username Group Name SNMP Version Auth Protocol PrivProtocol initial initial V3 None None Total Entries 1 DES 3526 4 create sn...

Page 43: ...iew 1 3 6 view_type included Success DES 3526 4 delete snmp view Purpose Used to remove an SNMP view entry previously created on the Switch Syntax delete snmp view view_name 32 all oid Description The...

Page 44: ...Command show snmp view Vacm View Table Settings View Name Subtree View Type ReadView 1 Included WriteView 1 Included NotifyView 1 3 6 Included restricted 1 3 6 1 2 1 1 Included restricted 1 3 6 1 2 1...

Page 45: ...a password to give remote SNMP managers access to MIB objects in the Switch s SNMP agent view_name 32 An alphanumeric string of up to 32 characters that is used to identify the group of MIB objects t...

Page 46: ...he SNMP community string dlink DES 3526 4 delete snmp community dlink Command delete snmp community dlink Success DES 3526 4 show snmp community Purpose Used to display SNMP community strings configur...

Page 47: ...gineID command configures a name for the SNMP engine on the Switch Parameters snmp_engineID An alphanumeric string that will be used to identify the SNMP engine on the Switch Restrictions Only adminis...

Page 48: ...n alphanumeric name of up to 32 characters that will identify the SNMP group the new SNMP user will be associated with v1 Specifies that SNMP version 1 will be used The Simple Network Management Proto...

Page 49: ...Specifies that the SNMP group being created has write privileges notify_view Specifies that the SNMP group being created can receive SNMP trap messages generated by the Switch s SNMP agent view_name 3...

Page 50: ...model level and status of each group are also displayed Syntax show snmp groups Description The show snmp groups command displays the group names of SNMP groups currently configured on the Switch The...

Page 51: ...restricted WriteView Name Notify View Name restricted Security Model SNMPv3 Security Level NoAuthNoPriv Group Name ReadGroup ReadView Name CommunityView WriteView Name Notify View Name CommunityView...

Page 52: ...SMI and adds some security features v3 Specifies that the SNMP version 3 will be used SNMP v3 provides secure access to devices through a combination of authentication and encrypting packets over the...

Page 53: ...ll receive SNMP traps generated by the Switch s SNMP agent Restrictions Only administrator level users can issue this command Example usage To delete an SNMP host entry DES 3526 4 delete snmp host 10...

Page 54: ...trusted_host ipaddr Description The create trusted_host command creates the trusted host The Switch allows you to specify up to four IP addresses that are allowed to manage the Switch via in band SNMP...

Page 55: ...the create trusted_host command above Parameters ipaddr The IP address of the trusted host Restrictions None Example Usage To display the list of trust hosts DES 3526 4 show trusted_host Command show...

Page 56: ...ntax enable snmp traps Description The enable snmp traps command is used to enable SNMP trap support on the Switch Parameters None Restrictions Only administrator level users can issue this command Ex...

Page 57: ...ntax show snmp traps Description This command is used to view the SNMP trap support status currently configured on the Switch Parameters None Restrictions Only administrator level users can issue this...

Page 58: ...uthentication support on the Switch Parameters None Restrictions Only administrator level users can issue this command Example Usage To disable the SNMP authentication trap support DES 3526 4 disable...

Page 59: ...on of the location of the Switch Syntax config snmp system_location sw_location Description The config snmp system_location command is used to enter a description of the location of the Switch A maxim...

Page 60: ...Switch DES 3526 4 config snmp system_name DES 3526 Switch Command config snmp system_name DES 3526 Switch Success DES 3526 4 enable rmon Purpose Used to enable RMON on the Switch Syntax enable rmon De...

Page 61: ...is used in conjunction with the enable rmon command above to enable and disable remote monitoring RMON on the Switch Parameters None Restrictions Only administrator level users can issue this command...

Page 62: ...nt Description This command is used to download a new firmware or a Switch configuration file from a TFTP server Parameters firmware Download and install new firmware on the Switch from a TFTP server...

Page 63: ...oot up section Parameters image_id Specifies the working section The Switch can hold two firmware versions for the user to select from which are specified by image ID delete Entering this parameter wi...

Page 64: ...nt switch settings or the switch history log to a TFTP Syntax upload configuration log ipaddr path_filename 64 Description This command is used to upload either the Switch s current settings or the Sw...

Page 65: ...between the Switch and the remote device Parameters ipaddr Specifies the IP address of the host times value 1 255 The number of individual ICMP echo messages to be sent A value of 0 will send an infi...

Page 66: ...state enable disable config syslog host all index 1 4 severity informational warning all facility local0 local1 local2 local3 local4 local5 local6 local7 udp_port udp_port_number ipaddress ipaddr sta...

Page 67: ...the error statistics for a range of ports Syntax show error ports portlist Description This command will display all of the packet error statistics collected and logged by the Switch for a given port...

Page 68: ...will display the current cpu utilization of the Switch ports Entering this parameter will display the current port utilization of the Switch portlist Specifies a port or range of ports to be displayed...

Page 69: ...Five minutes 14 DES 3526 4 clear counters Purpose Used to clear the Switch s statistics counters Syntax clear counters ports portlist Description This command will clear the counters used by the Swit...

Page 70: ...This command will display the contents of the Switch s history log Parameters index value This command will display the history log beginning at 1 and ending at the value specified by the user in the...

Page 71: ...e Restrictions Only administrator level users can issue this command Example usage To the syslog function on the Switch DES 3526 4 enable syslog Command enable syslog Success DES 3526 4 disable syslog...

Page 72: ...abled DES 3526 4 create syslog host Purpose Used to create a new syslog host Syntax create syslog host index 1 4 ipaddress ipaddr severity informational warning all facility local0 local1 local2 local...

Page 73: ...o the remote host This corresponds to number 4 from the list above all Specifies that all of the currently supported syslog messages that are generated by the Switch will be sent to the remote host fa...

Page 74: ...ssages will be sent to the remote host This corresponds to number 18 from the list above local3 Specifies that local use 3 messages will be sent to the remote host This corresponds to number 19 from t...

Page 75: ...rning all facility local0 local1 local2 local3 local4 local5 local6 local7 udp_port udp_port_number ipaddress ipaddr state enable disable Description The config syslog host command is used to configur...

Page 76: ...ll be sent to the remote host facility Some of the operating system daemons and processes have been assigned Facility values Processes and daemons that have not been explicitly assigned a Facility may...

Page 77: ...om the list above local4 Specifies that local use 4 messages will be sent to the remote host This corresponds to number 20 from the list above local5 Specifies that local use 5 messages will be sent t...

Page 78: ...a syslog host that has been previously configured from the Switch Syntax delete syslog host index 1 4 all Description The delete syslog host command is used to remove a syslog host that has been prev...

Page 79: ...ch Parameters index 1 4 Specifies that the command will be applied to an index of hosts There are four available indexes numbered 1 through 4 Restrictions None Example usage To show Syslog host inform...

Page 80: ...ple and full processing of frames regardless of administrative errors in defining VLANs and their respective spanning trees Each switch utilizing the MSTP on a network will have a single MSTP configur...

Page 81: ...nable STP on the Switch Syntax enable stp Description This command allows the Spanning Tree Protocol to be globally enabled on the Switch Parameters None Restrictions Only administrator level users ca...

Page 82: ...STP globally on the Switch stp Selecting this parameter will set the Spanning Tree Protocol STP globally on the Switch Restrictions Only administrator level users can issue this command Example usage...

Page 83: ...then discard the BDPU packet and the information held for the port will age out The user may set a hop count from 1 to 20 The default is 20 hellotime value 1 10 The user may set the time interval betw...

Page 84: ...is still functioning The user may choose a time between 1 and 10 seconds The default is 2 seconds migrate yes no Setting this parameter as yes will set the ports to send out BDPU packets to other brid...

Page 85: ...path cost 19 hellotime set to 5 seconds migration enable and state enable for ports 1 5 of module 1 DES 3526 4 config stp ports 1 5 externalCost 19 hellotime 5 migrate yes state enable Command config...

Page 86: ...ion_level number and the same name Parameters value 1 4 Enter a number between 1 and 4 to define the instance_id The switch supports 5 STP regions with one unchangeable default instance ID set as 0 ad...

Page 87: ...p priority value 0 61440 instance_id value 0 4 Description This command is used to update the STP instance configuration settings on the Switch The MSTP will utilize the priority in selecting the root...

Page 88: ...e same revision_level and name will be considered as part of the same MSTP region Parameters revision_level int 0 65535 Enter a number between 0 and 65535 to identify the MSTP region This value along...

Page 89: ...e CIST Common and Internal Spanning Tree internalCost This parameter is set to represent the relative cost of forwarding packets to specified ports when an interface is selected within a STP instance...

Page 90: ...on the Switch Status 1 STP enabled with STP compatible version DES 3526 4 show stp Command show stp STP Status Enabled STP Version STP Compatible Max Age 20 Hello Time 2 Forward Delay 15 Max Age 20 TX...

Page 91: ...nce Operational Status currently implemented on the Switch Parameters portlist Specifies a port or range of ports to be viewed Restrictions None Example usage To show stp ports 1 through 9 DES 3526 4...

Page 92: ...ictions None Example usage To display the STP instance configuration for instance 0 the internal CIST on the Switch DES 3526 4 show stp instance 0 Command show stp instance 0 STP Instance Settings Ins...

Page 93: ...s the Switch s current MSTP configuration identification Parameters None Restrictions None Example usage To show the MSTP configuration identification currently set on the Switch DES 3526 4 show stp m...

Page 94: ...e portlist all forward_all_groups forward_unregistered_groups filter_unregistered_groups show multicast port_filtering_mode portlist Each command is listed in detail in the following sections create f...

Page 95: ...s macaddr The MAC address that will be added to the forwarding table Restrictions Only administrator level users can issue this command Example usage To create multicast MAC forwarding DES 3526 4 crea...

Page 96: ...of the source MAC addresses and their associated port numbers are deleted from the table if they are not accessed within the aging time The aging time can be from 10 to 1000000 seconds with a default...

Page 97: ...LAN on which the MAC address resides macaddr The MAC address that will be added to the forwarding table Restrictions Only administrator level users can issue this command Example usage To delete a per...

Page 98: ...ding database Restrictions Only administrator level users can issue this command Example usage To clear all FDB dynamic entries DES 3526 4 clear fdb all Command clear fdb all Success DES 3526 4 show m...

Page 99: ...ents of the Switch s forwarding database Parameters port port The port number corresponding to the MAC destination address The Switch will always forward traffic to the specified device through this p...

Page 100: ...SC q Quit SPACE n Next Page ENTER Next Entry a All config multicast port_filtering_mode Purpose Used to configure the multicast packet filtering mode on a port per port basis Syntax config multicast p...

Page 101: ...multicast port_filtering_mode Port Multicast Filter Mode 1 forward_unregistered_groups 2 forward_unregistered_groups 3 forward_unregistered_groups 4 forward_unregistered_groups 5 forward_unregistered_...

Page 102: ...to configure broadcast storm control Parameters storm_grouplist Used to specify a broadcast storm control group This is specified by entering the syntax unit_id all Specifies all broadcast storm cont...

Page 103: ...broadcast storm control group This is specified by entering the syntax unit_id Restrictions None Example usage To display traffic control setting DES 3526 4 show traffic control Command show traffic c...

Page 104: ...will transmit all of the packets in its buffer before permitting the next lower priority to transmit its packets When the lowest hardware priority queue has finished transmitting all of its packets th...

Page 105: ...pecifies that there will be no limit on the rate of packets received by the above specified ports value 1 1000 Specifies the packet limit in Mbps that the above ports will be allowed to receive The tr...

Page 106: ...fy the rotation by which these four hardware priority queues are emptied The Switch s default if the config scheduling command is not used or if the config scheduling command is entered with both max_...

Page 107: ...This specifies which of the four hardware priority queues the config scheduling command will apply to The four hardware priority queues are identified by number from 0 to 3 with the 0 queue being the...

Page 108: ...Latency Class 0 100 150 Class 1 99 100 Class 2 91 101 Class 3 21 201 DES 3526 4 config 802 1p user_priority Purpose Used to map the 802 1p user priority of an incoming packet to one of the four hardw...

Page 109: ...our hardware priority queues available They are numbered between 0 the lowest priority and 3 the highest priority Restrictions Only administrator level users can issue this command Example usage To co...

Page 110: ...Syntax config 802 1p default_priority portlist all priority 0 7 Description This command allows you to specify default priority handling of untagged packets received by the Switch The priority value...

Page 111: ...plays the currently configured 802 1p priority value that will be assigned to an incoming untagged packet before being forwarded to its destination Parameters portlist Specifies a port or range of por...

Page 112: ...rk sniffer or other device can monitor the network traffic In addition you can specify that only traffic received by or sent by one or both is mirrored to the Target port Parameters port This specifie...

Page 113: ...rroring ports DES 3526 4 config mirror port 1 delete source port 2 4 Command config mirror 1 delete source 2 4 Success DES 3526 4 enable mirror Purpose Used to enable a previously entered port mirrori...

Page 114: ...off without having to modify the port mirroring configuration Parameters None Restrictions Only administrator level users can issue this command Example usage To disable mirroring configurations DES 3...

Page 115: ...DES 3526 Layer 2 Fast Ethernet Switch DES 3526 4 show mirror Command show mirror Current Settings Mirror Status Enabled Target Port 1 Mirrored Port RX TX 5 7 DES 3526 4 107...

Page 116: ...ommand is listed in detail in the following sections create vlan Purpose Used to create a VLAN on the Switch Syntax create vlan vlan_name 32 tag vlanid 1 4094 advertisement Description This command al...

Page 117: ...ports to a previously configured VLAN Syntax config vlan vlan_name 32 add tagged untagged forbidden delete portlist advertisement enable disable Description This command allows you to add ports to the...

Page 118: ...cess DES 3526 4 config gvrp Purpose Used to configure GVRP on the Switch Syntax config gvrp portlist all state enable disable ingress_checking enable disable acceptable_frame tagged_only admit_all pvi...

Page 119: ...atus the sending and receiving GVRP information DES 3526 4 config gvrp 1 4 state enable ingress_checking enable acceptable_frame tagged_only pvid 2 Command config gvrp 1 4 state enable ingress_checkin...

Page 120: ...ess DES 3526 4 show vlan Purpose Used to display the current VLAN configuration on the Switch Syntax show vlan vlan_name 32 Description This command displays summary information about each VLAN includ...

Page 121: ...on the Switch Parameters portlist Specifies a port or range of ports for which the GVRP status is to be displayed Restrictions None Example usage To display GVRP port status DES 3526 4 show gvrp Comm...

Page 122: ...mes 17 1 Disabled Enabled All Frames 18 1 Disabled Enabled All Frames 19 1 Disabled Enabled All Frames 20 1 Disabled Enabled All Frames 21 1 Disabled Enabled All Frames 22 1 Disabled Enabled All Frame...

Page 123: ...the Switch Syntax enable asymmetric_vlan Description This command enables the asymmetric VLAN function on the Switch Parameters None Restrictions Only administrator level users can issue this command...

Page 124: ...symmetric VLAN state on the Switch Syntax show asymmetric_vlan Description This command displays the asymmetric VLAN state on the Switch Parameters None Restrictions Only administrator level users can...

Page 125: ...tion This command will create a link aggregation group with a unique identifier Parameters value Specifies the group ID The Switch allows up to 6 link aggregation groups to be configured The group num...

Page 126: ...sue this command Example usage To delete link aggregation group DES 3526 4 delete link_aggregation group_id 6 Command delete link_aggregation group_id 6 Success DES 3526 4 config link_aggregation Purp...

Page 127: ...er_port 1 ports 5 7 9 Success DES 3526 4 config link_aggregation algorithm Purpose Used to configure the link aggregation algorithm Syntax config link_aggregation algorithm mac_source mac_destination...

Page 128: ...nk_aggregation group_id value 1 6 algorithm Description This command will display the current link aggregation configuration of the Switch Parameters value 1 6 Specifies the group ID The Switch allows...

Page 129: ...ggregated port group that is to add or subtract ports from the group at least one of the participating devices must designate LACP ports as active Both devices must support LACP passive LACP ports tha...

Page 130: ...ACP status for all ports Restrictions Only administrator level users can issue this command Example usage To display LACP port mode settings DES 3526 4 show lacp_port 1 10 Command show lacp_port 1 10...

Page 131: ...Switch Parameters ipif_name 12 Enter an alphanumeric string of up to 12 characters to identify this IP interface ipaddress network_address IP address and netmask of the IP interface to be created You...

Page 132: ...12 Description This command will display the configuration of an IP interface on the Switch Parameters ipif_name 12 The name created for the IP interface Restrictions None Example usage To display IP...

Page 133: ...vlan vlan_name 32 static dynamic forbidden show igmp_snooping forwarding vlan vlan_name 32 show igmp_snooping group vlan vlan_name 32 Each command is listed in detail in the following sections config...

Page 134: ...Syntax config igmp_snooping querier vlan_name 32 all query_interval sec 1 65535 max_response_time sec 1 25 robustness_variable value 1 255 last_member_query_interval sec 1 25 state enable disable Des...

Page 135: ...ct a subnet to be lossy Although 1 is specified as a valid entry the roubustness variable should not be one or problems may arise last_member_query_interval sec 1 25 The maximum amount of time between...

Page 136: ...ing Purpose Used to enable IGMP snooping on the Switch Syntax enable igmp_snooping forward_mcrouter_only Description This command allows you to enable IGMP snooping on the Switch If forward_mcrouter_o...

Page 137: ...Entering this command without the parameter will disable igmp snooping on the Switch Restrictions Only administrator level users can issue this command Example usage To disable IGMP snooping on the Sw...

Page 138: ...led VLAN Name vlan2 Query Interval 125 Max Response Time 10 Robustness Value 2 Last Member Query Interval 1 Host Timeout 260 Route Timeout 260 Leave Timer 2 Querier State Disabled Querier Router Behav...

Page 139: ...Name default Multicast group 234 5 6 7 MAC address 01 00 5E 05 06 07 Reports 1 Port Member 4 10 VLAN Name default Multicast group 236 54 63 75 MAC address 01 00 5E 36 3F 4B Reports 1 Port Member 18 22...

Page 140: ...and show router_ports VLAN Name default Static router port 1 2 10 Dynamic router port Total Entries 1 DES 3526 4 show igmp_snooping forwarding Purpose Used to display the IGMP snooping forwarding tabl...

Page 141: ...y the current IGMP setup currently configured on the Switch Parameters vlan_name 32 The name of the VLAN for which to view IGMP snooping group information Restrictions None Example usage To view the c...

Page 142: ...group 236 54 63 75 MAC address 01 00 5E 36 3F 4B Reports 1 Port Member 14 16 VLAN Name default Multicast group 239 255 255 250 MAC address 01 00 5E 7F FF FA Reports 2 Port Member 18 20 VLAN Name defau...

Page 143: ...max_req value 1 10 reauth_period sec 1 65535 enable_reauth enable disable config 802 1x auth_protocol radius eap radius pap config 802 1x init port_based ports portlist all mac_based ports portlist al...

Page 144: ...1x Port based Network Access control server application on the Switch Parameters None Restrictions Only administrator level users can issue this command Example usage To disable 802 1x on the Switch...

Page 145: ...lDir Both In Shows whether a controlled Port that is unauthorized will exert control over communication in both receiving and transmitting directions or just the receiving direction Port Control Force...

Page 146: ...try a All show 802 1x auth_state Purpose Used to display the current authentication state of the 802 1x server on the Switch Syntax show 802 1x auth_state ports portlist Description The show 802 1x au...

Page 147: ...State Port Status 2 ForceAuth Success Authorized 5 ForceAuth Success Authorized 8 ForceAuth Success Authorized Command show 802 1x auth_state 1 ForceAuth Success Authorized 3 ForceAuth Success Authori...

Page 148: ...802 1x capability ports 1 10 authenticator Command config 802 1x capability ports 1 10 authenticator Success DES 3526 4 config 802 1x auth_parameter Purpose Used to configure the 802 1x Authentication...

Page 149: ...figures the number of times to retry sending packets to a supplicant user reauth_period sec 1 65535 Configures the time interval between successive re authentications enable_reauth enable disable Dete...

Page 150: ...Purpose Used to initialize the 802 1x function on a range of ports Syntax config 802 1x init port_based ports portlist all mac_based ports portlist all mac_address macaddr Description The config 802...

Page 151: ...port based or MAC based 802 1x authentication feature on the Switch Parameters port_based mac_based The Switch allows you to authenticate 802 1x by either port or MAC address Only administrator level...

Page 152: ...ts 1 18 Command config 802 1x reauth port_based ports 1 18 Success DES 3526 4 config radius add Purpose Used to configure the settings the Switch will use to communicate with a RADIUS server Syntax co...

Page 153: ...ccess DES 3526 4 config radius delete Purpose Used to delete a previously entered RADIUS server configuration Syntax config radius delete server_index 1 3 Description The config radius delete command...

Page 154: ...port udp_port_number 1 65535 The UDP port number for authentication requests The default is 1812 acct_port udp_port_number 1 65535 The UDP port number for accounting requests The default is 1813 Restr...

Page 155: ...ings on the Switch DES 3526 4 show radius Command show radius Index IP Address Auth Port Acct Port Status Key Number Number 1 10 1 1 1 1812 1813 Active switch 2 20 1 1 1 1800 1813 Active des3226 3 30...

Page 156: ...ernet vlan vlan_name 32 source_mac macaddr destination_mac macaddr 802 1p value 0 7 ethernet_type hex 0x0 0xffff ip vlan vlan_name 32 source_ip ipaddr destination_ip ipaddr dscp value 0 63 icmp type v...

Page 157: ...s profile the rule with the highest priority lowest access_id will take precedence The ip parameter instructs the Switch that this new rule will be applied to the IP addresses contained within each fr...

Page 158: ...he Switch will examine the IP address in each frame s header source_ip_mask netmask Specifies an IP address mask for the source IP address icmp Specifies that the Switch will examine the Internet Cont...

Page 159: ...port mask for the source port dst_port_mask hex 0x0 0xffff Specifies a UDP port mask for the destination port protocol_id Specifies that the Switch will examine each frame s Protocol ID field user_def...

Page 160: ...access profile when it is created with the create access_profile command Restrictions Only administrator level users can issue this command Example usage To delete the access profile with a profile I...

Page 161: ...cal AND operation with masks entered with the create access_profile command above Parameters profile_id value 1 255 Enter an integer between 1 and 8 that is used to identify the access profile that wi...

Page 162: ...Message Protocol ICMP field within each packet type value 0 65535 Specifies that the access profile will apply to this ICMP type value code value 0 255 Specifies that the access profile will apply to...

Page 163: ...the frame header using a logical AND operation offset_0 15 Enter a value in hex form to mask the packet from the beginning of the packet to the 15th byte permit Specifies that packets that match the a...

Page 164: ...frames that have IP addresses in the range between 10 42 73 0 to 10 42 73 255 DES 3526 4 config access_profile profile_id 2 add access_id 1 ip source_ip 10 42 73 1 deny Command config access_profile...

Page 165: ...47 Type Ethernet Frame Filter Ports All Masks 802 1p ID Mode Access Profile ID 249 Type Packet Content Filter Ports All Masks Offset 0 15 0x00000000 00000000 00000000 00000000 Offset 16 31 0x00000000...

Page 166: ...egmentation command is used to configure traffic segmentation on the Switch Parameters portlist Specifies a port or range of ports that will be configured for traffic segmentation forward_list Specifi...

Page 167: ...hich the current traffic segmentation configuration on the Switch will be displayed Restrictions The port lists for segmentation and the forward list must be on the same Switch Example usage To displa...

Page 168: ...e end_date 1 31 e_mth end_mth 1 12 e_time end_time hh mm offset 30 60 90 120 show time Each command is listed in detail in the following sections config sntp Purpose Used to setup SNTP service Syntax...

Page 169: ...ay the SNTP information Syntax show sntp Description This command will display SNTP settings information including the source IP address time and poll interval Restrictions Only administrator level us...

Page 170: ...sntp Example usage To enable the SNTP function DES 3526 4 enable sntp Command enable sntp Success DES 3526 4 disable sntp Purpose To disable SNTP server support Syntax disable sntp Description This w...

Page 171: ...rical characters for the year For example 03aug2003 Example usage To manually set system time and date settings DES 3526 4 config time 30jun2003 16 30 30 Command config time 30jun2003 16 30 30 Success...

Page 172: ...isable the DST seasonal time adjustment for the Switch repeating Using repeating mode will enable DST seasonal time adjustment Repeating mode requires that the DST beginning and ending date be specifi...

Page 173: ...minutes to add or to subtract during the summertime The possible offset times are 30 60 90 120 The default value is 60 end_day sun sat The day of the week in which DST ends expressed using a three ch...

Page 174: ...how time Description This will display system time and date configuration as well as display current system time Parameters None Restrictions Only administrator level users can issue this command Exam...

Page 175: ...he ARP table Syntax create arpentry ipaddr macaddr Description This command is used to enter an IP address and the corresponding MAC address into the Switch s ARP table Parameters ipaddr The IP addres...

Page 176: ...rpentry 10 48 74 12 00 50 BA 00 07 36 Command config arpentry 10 48 74 12 00 50 BA 00 07 36 Success DES 3526 4 delete arpentry Purpose Used to delete a static entry into the ARP table Syntax delete ar...

Page 177: ...command Parameters Restrictions Example Usage To configure ARP aging time DES 3526 4 config arp_aging time 30 Command config arp_aging time 30 Success DES 3526 4 show arpentry Purpose Used to display...

Page 178: ...50 BA 38 7D 5E Dynamic System 10 21 32 203 00 80 C8 40 C1 06 Dynamic System 10 40 44 60 00 50 BA 6B 2A 1E Dynamic System 10 42 73 221 00 01 02 03 04 00 Dynamic System 10 44 67 1 00 50 BA DA 02 51 Dyna...

Page 179: ...itch s IP routing table Parameters ipaddr The gateway IP address for the next hop router metric 1 65535 Allows the entry of a routing protocol metric entry representing the number of routers between t...

Page 180: ...ess DES 3526 4 show iproute Used to display the Switch s current IP routing table show iproute Description This command will display the Switch s current IP routing table Parameters None Purpose Synta...

Page 181: ...command is listed in detail in the following sections enable mac_notification Purpose Used to enable global MAC address table notification on the Switch enable mac_notification Description This comman...

Page 182: ...notification interval int 1 2147483647 historysize int 1 500 Description MAC address notificiation is used to monitor MAC addresses learned and entered into the FDB Parameters interval sec 1 214748364...

Page 183: ...ess table notification on the Switch Restrictions Only administrator level users can issue this command Example usage To enable port 7 for MAC address table notification DES 3526 4 config mac_notifica...

Page 184: ...ed to display the Switch s MAC address table notification status settings Parameters portlist Specify a port or group of ports to be viewed Entering this command without the parameter will display the...

Page 185: ...er 2 Fast Ethernet Switch 11 Disabled 12 Disabled 13 Disabled 14 Disabled 15 Disabled 16 Disabled 17 Disabled 18 Disabled 19 Disabled 20 Disabled CTRL C ESC q Quit SPACE n Next Page p Previous Page r...

Page 186: ...other than the Switch called a server host and it must include usernames and passwords for authentication When the user is prompted by the Switch to enter usernames and passwords for authentication t...

Page 187: ...n_login method_list_name string 15 show authen_login default method_list_name string 15 all create authen_enable method_list_name string 15 config authen_enable default method_list_name string 15 meth...

Page 188: ...etail in the following sections enable authen_policy Purpose Used to enable system access authentication policy Syntax enable authen_policy Description This command will enable an administrator define...

Page 189: ...leges Parameters None Restrictions Only administrator level users can issue this command Example usage To disable the system access authentication policy DES 3526 4 disable authen_policy Command disab...

Page 190: ...xtacacs tacacs radius server_group string 15 local none Description This command will configure a user defined or default method list of authentication methods for users logging on to the Switch The s...

Page 191: ...the TACACS server group list radius Adding this parameter will require the user to be authenticated using the RADIUS protocol from the remote RADIUS server hosts of the RADIUS server group list server...

Page 192: ...s local Command config authen_login method_list_name Trinity method tacacs xtacacs local Success DES 3526 4 Example usage To configure the default method list with authentication methods xtacacs tacac...

Page 193: ...ameter will display all the authentication login methods currewntly configured on the Switch The window will display the following parameters Restrictions Only administrator level users can issue this...

Page 194: ...sed to promote users with normal level privileges to Administrator level privileges using authentication methods on the Switch Once a user acquires normal user level privileges on the Switch he or she...

Page 195: ...the Switch will restart the same sequence with the following protocol listed xtacacs If no authentication takes place using the xtacacs list the local_enable password set in the Switch is used to auth...

Page 196: ...a remote TACACS server radius Adding this parameter will require the user to be authenticated using the RADIUS protocol from a remote RADIUS server server_group string 15 Adding this parameter will r...

Page 197: ...er an alphanumeric string of up to 15 characters to define the given enable method list the user wishes to delete Restrictions Only administrator level users can issue this command Example usage To de...

Page 198: ...r method list name Comment Defines the type of Method User defined Group refers to server groups defined by the user Built in Group refers to the TACACS XTACACS TACACS and RADIUS security protocols wh...

Page 199: ...r user authentication using the default method list method_list_name string 15 Use this parameter to configure an application for user authentication using a prevoisly configured method list Enter a a...

Page 200: ...6 4 create authen server_host Purpose Used to create an authentication server host Syntax create authen server_host ipaddr protocol tacacs xtacacs tacacs radius port int 1 65535 key key_string 254 non...

Page 201: ...reply to an authentication request The default value is 5 seconds retransmit int 1 255 Enter the value in the retransmit field to change how many times the device will resend an authentication reques...

Page 202: ...server host the user wishes to alter protocol The protocol used by the server host The user may choose one of the following port int 1 65535 Enter a number between 1 and 65535 to define the virtual po...

Page 203: ...ommand is used to delete a user defined authentication server host previously created on the Switch Parameters server_host ipaddr The IP address of the remote server host to be deleted protocol The pr...

Page 204: ...or the server host to reply to an authentication request Port The virtual port number on the server host The default value is 49 Retransmit The value in the retransmit field denotes how many times the...

Page 205: ...authen server_group Purpose Used to configure a user defined authentication server group Syntax config authen server_group tacacs xtacacs tacacs radius string 15 add delete server_host ipaddr protocol...

Page 206: ...ver group server_host ipaddr Enter the IP address of the previously configured server host to add or delete protocol Enter the protocol utilized by the server host There are three options Restrictions...

Page 207: ...sed to view authentication server groups on the Switch Syntax show authen server_group string 15 Description This command will display authentication server groups currently configured on the Switch T...

Page 208: ...set the time the Switch will wait for a response of authentication from the user Parameters response_timeout int 1 255 Set the time in seconds the Switch will wait for a response of authentication fr...

Page 209: ...maximum number of authentication attempts at 5 DES 3526 4 config authen parameter attempt 5 Command config authen parameter attempt 5 Success DES 3526 4 show authen parameter Purpose Used to display t...

Page 210: ...oups local enable local account on the Switch or no authentication none Because XTACACS and TACACS do not support the enable function the user must create a special account on the server host which ha...

Page 211: ...alphanumeric string of no more than 15 characters and finally prompted to enter the new password again for confirmation See the example below Restrictions Only administrator level users can issue this...

Page 212: ...and decrypt messages sent between the SSH Client and the SSH Server Finally enable SSH on the Switch using the enable ssh command After following the above steps you can configure an SSH Client on the...

Page 213: ...SSH on the Switch Parameters None Restrictions Only administrator level users can issue this command Purpose Syntax Description Usage Example To disable SSH DES 3526 4 disable ssh Command disable ssh...

Page 214: ...rating system with a SSH program previously installed enable disable This allows you to enable or disable SSH authentication on the Switch Restrictions Only administrator level users can issue this co...

Page 215: ...0 Allows the administrator to set the maximum number of attempts that a user may try to logon utilizing SSH authentication After the maximum number of attempts is exceeded the Switch will be disconnec...

Page 216: ...username of no more than 15 characters to identify the SSH user authmode Specifies the authentication mode of the SSH user wishing to log on to the Switch The administrator may choose between hostbas...

Page 217: ...er DES 3526 4 config ssh user Trinity authmode Password Command config ssh user Trinity authmode Password Enter a case sensitive new password Enter the new password again for conformation Success DES...

Page 218: ...ryption Standard AES192 encryption algorithm AES256 This parameter will enable or disable the Advanced Encryption Standard AES256 encryption algorithm arcfour This parameter will enable or disable the...

Page 219: ...to display the SSH algorithm setting Syntax show ssh algorithm Description This command will display the current SSH algorithm setting status Parameters None Restrictions None Usage Example To display...

Page 220: ...DES 3526 Layer 2 Fast Ethernet Switch MD5 Enabled Public Key Algorithm SHA1 Enabled RSA Enabled DSA Enabled DES 3526 4 212...

Page 221: ...e server and the host The user may implement any one or combination of the ciphersuites available yet different ciphersuites will affect the security level and the performance of the secured connectio...

Page 222: ...ession The user may choose any combination of the following The ciphersuites are enabled by default on the Switch yet the SSL status is disabled by default Enabling SSL with a cipersuite will not enab...

Page 223: ...tion of listed ciphersuites on the Switch Parameters ciphersuite A security string that determines the exact cryptographic parameters specific encryption algorithms and key sizes to be used for an aut...

Page 224: ...session is established every time the clent and host go through a key exchange Specifying a longer timeout will allow the SSL session to reuse the master key on future connections with that particula...

Page 225: ...out Command show ssl cachetimeout DES 3526 4 Cache timeout is 600 second s show ssl Purpose Used to view the SSL status and the certificate file status on the Switch Syntax show ssl Description This c...

Page 226: ...iption This command is used to download a certificate file for the SSL function on the Switch from a TFTP server The certificate file is a data record used for authenticating devices on the network It...

Page 227: ...4 DES 3526 4 download certificate_fromTFTP 10 53 13 94 certfilename c cert der keyfilename c pkey der Command download certificate_fromTFTP 10 53 13 94 certfilename c cert der keyfilename c pkey der...

Page 228: ...of a SIM group cannot cross a router A SIM group accepts up to 32 switches numbered 0 31 including the Commander Switch numbered 0 If multiple VLANs are configured the SIM group will only utilize the...

Page 229: ...the CS may receive a response packet from the MS which it will encode and send back to the administrator When a CS becomes a MS it automatically becomes a member of the first SNMP community include re...

Page 230: ...ers None Restrictions Only administrator level users can issue this command Purpose Example usage To disable SIM on the Switch DES 3526 4 disable sim Command disable sim Success DES 3526 4 show sim Pu...

Page 231: ...1 32 Entering this parameter will display information concerning candidates of the SIM group To view a specific candidate include that candidate s ID number listed from 1 to 32 members member_id 1 32...

Page 232: ...specified DES 3526 4 show sim candidates Command show sim candidates ID MAC Address Platform Hold Firmware Device Name Capability Time Version 1 00 01 02 03 04 00 DES 3526 L2 Switch 40 2 00 B02 The M...

Page 233: ...mware Device Name Capability Time Version 1 00 01 02 03 04 00 DES 3526 L2 Switch 40 2 00 B02 Trinity 2 00 55 55 00 55 00 DES 3526 L2 Switch 140 2 00 B02 default master SIM Group Name SIM2 Capability T...

Page 234: ...with member id 2 through the CS using the command line interface DES 3526 4 reconfig member_id 2 Command reconfig member_id 2 DES 3526 4 Login config sim_group Purpose Used to add candidates and dele...

Page 235: ...e parameters of switches of the SIM Parameters commander Use this parameter to configure the commander switch CS for the following parameters group_name groupname 64 Used to update the name of the gro...

Page 236: ...onds the Switch will hold information sent to it from other switches utilizing the discovery interval protocol The user may set the hold time from 100 to 300 seconds Only administrator level users can...

Page 237: ...pecify this parameter if the user wishes to download a switch configuration to members of a SIM group ipaddr Enter the IP address of the TFTP server path_filename Enter the path and the filename of th...

Page 238: ...firmware 10 53 13 94 c des3526 txt members all This device is updating configuation Please wait Download Status ID MAC Address Result 1 00 01 02 03 04 00 Success 2 00 07 06 05 04 03 Success 3 00 07 06...

Page 239: ...y the member the user prefers to upload a switch configuation file to The user may specify a member or members by adding the ID number of the specified member Restrictions Only administrator level use...

Page 240: ...ions Purpose Used to display all commands in the Command Line Interface CLI Syntax Description This command will display all of the commands available through the Command Line Interface CLI Parameters...

Page 241: ...in the Command Line Interface CLI Syntax dir Description This command will display all of the commands available through the Command Line Interface CLI Parameters None Restrictions None Example usage...

Page 242: ...figure the command history Parameters value 1 40 The number of previously executed commands maintained in the buffer Up to 40 of the latest executed commands may be viewed Restrictions Description Non...

Page 243: ...DES 3526 Layer 2 Fast Ethernet Switch DES 3526 4 show command_history Command show command_history show show vlan show command history DES 3526 4 235...

Page 244: ...fails Power Consumption 90 watts maximum DC fans 2 built in 40 x 40 x10 mm fans Operating Temperature 0 to 40 degrees Celsius 32 to 104 degrees Fahrenheit Storage Temperature 40 to 70 degrees Celsius...

Page 245: ...CD Data Transfer Rates Ethernet Fast Ethernet Gigabit Ethernet Fiber Optic Half duplex Full duplex 10 Mbps 20Mbps 100Mbps 200Mbps n a 2000Mbps SFP Mini GBIC Support IEEE 802 3z 1000BASE LX DEM 310GT...

Page 246: ...t Ethernet Performance Transmission Method Store and forward RAM Buffer 16 MB per device Filtering Address Table 8K MAC address per device Packet Filtering Forwarding Rate Full wire speed for all conn...

Reviews: