background image

Spanning-Tree Commands

239

Spanning-Tree Commands

 

NOTE: 

Some of the commands included in this group may have implications on internal ports.

spanning-tree

The 

spanning-tree 

Global Configuration mode command enables spanning-tree functionality. To 

disable spanning-tree functionality, use the 

no 

form of this command.

Syntax

spanning-tree
no spanning-tree

Default Configuration

Spanning-tree is enabled.

Command Modes 

Global Configuration mode

User Guidelines

There are no user guidelines for this command.

Example

The following example enables spanning-tree functionality.

spanning-tree mode

The 

spanning-tree mode 

Global Configuration mode command configures the spanning-tree 

protocol. To return to the default configuration, use the 

no 

form of this command.

Syntax

spanning-tree mode 

{

stp 

rstp

mstp

}

no spanning-tree mode

stp 

— STP is the Spanning Tree operative mode.

rstp 

— RSTP is the Spanning Tree operative mode.

• mstp 

— MSTP is enabled

Default Configuration

STP

console(config)# 

spanning-tree

22

Summary of Contents for PowerConnect 5316M

Page 1: ...w w w d e l l c o m s u p p o r t d e l l c o m Dell PowerConnect 5316M CLI Reference Guide ...

Page 2: ...rmation in this document is subject to change without notice 2006 Dell Inc All rights reserved Reproduction in any manner whatsoever without the written permission of Dell Inc is strictly forbidden Trademarks used in this text Dell the DELL logo and PowerConnect are trademarks of Dell Inc Other trademarks and trade names may be used in this document to refer to either the entities claiming the mar...

Page 3: ...ernet Configuration Commands 6 GVRP Commands 7 IGMP Snooping Commands 8 IP Addressing 8 LACP Commands 9 Line Commands 9 LLDP Commands 10 Management ACL Commands 11 PHY Diagnostics Commands 11 Port Channel Commands 12 Port Monitor Commands 12 QoS Commands 12 Radius Commands 13 RMON Commands 14 SNMP Commands 14 Spanning Tree Commands 15 SSH Commands 17 Syslog Commands 18 ...

Page 4: ...agement Access level Mode 31 PE Privileged EXEC Mode 31 SP SSH Public Key Mode 33 UE User EXEC Mode 33 VC VLAN Configuration Mode 34 3 Using the CLI CLI Command Modes 37 Introduction 37 User EXEC Mode 38 Privileged EXEC Mode 38 Global Configuration Mode 39 Interface Configuration Mode and Specific Configuration Modes 40 Starting the CLI 40 Editing Features 42 Terminal Command Buffer 43 Negating th...

Page 5: ...entication methods 52 password 53 enable password 54 username 55 show users accounts 55 5 Address Table Commands bridge address 57 bridge multicast filtering 58 bridge multicast address 58 bridge multicast forbidden address 60 bridge multicast forward all 61 bridge multicast forbidden forward all 61 bridge aging time 62 clear bridge 63 port security 63 port security routed secure address 64 show b...

Page 6: ...clock timezone 74 clock summer time 75 sntp authentication key 76 sntp authenticate 77 sntp trusted key 78 sntp client poll timer 78 sntp broadcast client enable 79 sntp anycast client enable 80 sntp client enable interface 80 sntp unicast client enable 81 sntp unicast client poll 82 sntp server 82 show clock 83 show sntp configuration 85 show sntp status 86 7 Configuration and Image Files delete ...

Page 7: ...e range ethernet 99 shutdown 100 description 101 speed 101 duplex 102 negotiation 103 flowcontrol 103 mdix 104 back pressure 105 port jumbo frame 106 clear counters 106 set interface active 107 show interfaces configuration 107 show interfaces status 109 show interfaces description 111 show interfaces counters 112 show ports jumbo frame 115 port storm control include multicast 116 ...

Page 8: ... gvrp registration forbid 124 clear gvrp statistics 124 show gvrp configuration 125 show gvrp statistics 126 show gvrp error statistics 127 10 IGMP Snooping Commands ip igmp snooping Global 129 ip igmp snooping 129 ip igmp snooping mrouter learn pim dvmrp 130 ip igmp snooping host time out 130 ip igmp snooping mrouter time out 131 ip igmp snooping leave time out 132 show ip igmp snooping mrouter 1...

Page 9: ...40 arp 141 arp timeout 142 clear arp cache 143 show arp 143 ip domain lookup 144 ip domain name 144 ip name server 145 ip host 146 clear host 146 show hosts 147 12 LACP Commands lacp system priority 149 lacp port priority 149 lacp timeout 150 show lacp ethernet 151 show lacp port channel 153 13 Line Commands line 155 exec timeout 155 ...

Page 10: ...l tlv 163 lldp management address 164 clear lldp rx 164 show lldp configuration 165 show lldp local 166 show lldp neighbors 166 15 Management ACL management access list 169 permit management 170 deny management 171 management access class 172 show management access list 173 show management access class 173 16 PHY Diagnostics Commands test copper port tdr 175 show copper ports tdr 175 ...

Page 11: ...nnel load balance 181 show interfaces port channel 181 18 Port Monitor Commands port monitor 183 show ports monitor 184 19 QoS Commands qos 187 show qos 187 wrr queue cos map 188 wrr queue bandwidth 189 priority queue out num of queues 190 show qos interface 190 qos map dscp queue 192 qos trust Global 192 qos trust Interface 193 qos cos 194 show qos map 194 ...

Page 12: ...w radius servers 201 21 RMON Commands show rmon statistics 203 rmon collection history 205 show rmon collection history 206 show rmon history 207 rmon alarm 210 show rmon alarm table 211 show rmon alarm 212 rmon event 214 show rmon events 215 show rmon log 216 rmon table size 217 22 SNMP Commands snmp server community 219 snmp server view 220 snmp server filter 221 snmp server contact 222 ...

Page 13: ...ngineID local 230 show snmp engineid 232 show snmp 232 show snmp views 233 show snmp groups 234 show snmp filters 235 show snmp users 236 23 Spanning Tree Commands spanning tree 239 spanning tree mode 239 spanning tree forward time 240 spanning tree hello time 241 spanning tree max age 241 spanning tree priority 242 spanning tree disable 242 spanning tree cost 243 spanning tree port priority 244 s...

Page 14: ...55 spanning tree mst port priority 256 spanning tree mst cost 257 spanning tree mst configuration 257 instance mst 258 name mst 259 revision mst 259 show mst 260 exit mst 261 abort mst 261 spanning tree mst mstp rstp 262 spanning tree guard root 263 24 SSH Commands ip ssh server 265 ip ssh port 265 crypto key generate dsa 266 crypto key generate rsa 266 ip ssh pubkey auth 267 crypto key pubkey cha...

Page 15: ...ing on 275 logging 275 logging console 276 logging buffered 277 logging buffered size 277 clear logging 278 logging file 279 clear logging file 279 show logging 280 show logging file 281 show syslog servers 282 26 System Management ping 285 traceroute 286 telnet 289 resume 292 reload 293 hostname 293 show users 294 show sessions 294 ...

Page 16: ...erver key 300 tacacs server timeout 300 tacacs server source ip 301 show tacacs 302 28 User Interface enable 303 disable 303 login 304 configure 304 exit configuration 305 exit EXEC 306 end 306 help 307 history 307 history size 308 debug mode 308 show history 309 show privilege 310 terminal history 310 terminal history size 311 ...

Page 17: ... 319 switchport general allowed vlan 319 switchport general pvid 320 switchport general ingress filtering disable 321 switchport general acceptable frame type tagged only 321 switchport forbidden vlan 322 map protocol protocols group 323 switchport general map protocols group vlan 324 show vlan 324 show vlan protocols groups 325 show interfaces switchport 326 30 Web Server ip http server 329 ip ht...

Page 18: ...1x 341 dot1x system auth control 342 dot1x port control 342 dot1x re authentication 343 dot1x timeout re authperiod 344 dot1x re authenticate 344 dot1x timeout quiet period 345 dot1x timeout tx period 346 dot1x max req 347 dot1x timeout supp timeout 347 dot1x timeout server timeout 348 show dot1x 349 show dot1x users 351 show dot1x statistics 352 ADVANCED FEATURES 354 dot1x auth not req 354 dot1x ...

Page 19: ...Contents 19 show dot1x advanced 356 ...

Page 20: ...20 Contents ...

Page 21: ...uide also provides information for configuring the PowerConnect Ethernet Switch Module details the procedures and provides configuration examples Basic installation configuration is described in the User s Guide and must be completed before using this document Command Groups The system commands can be broken down into the functional groups shown below Command Group Description AAA Configures conne...

Page 22: ...SNMP Configures SNMP communities traps and displays SNMP information Spanning Tree Configures and reports on Spanning Tree protocol SSH Configures SSH authentication Syslog Commands Manages and displays syslog messages System Management Configures the Ethernet Switch Module clock name and authorized users TACACS Configures TACACS commands User Interface Describes user commands used for entering CL...

Page 23: ...thentication methods Privileged EXEC password Specifies a password on a line Line Configuration enable password Sets a local password to control access to normal and privilege levels Global Configuration username Establishes a username based authentication system Global Configuration show users accounts Displays information about the local user database Privileged EXEC Command Group Description Ac...

Page 24: ... Displays the number of addresses present in all VLANs or at a specific VLAN Privileged EXEC show bridge multicast address table Displays all entries in the bridge forwarding database Privileged EXEC show bridge multicast filtering Displays the multicast filtering configuration Privileged EXEC show ports security Displays the port lock status Privileged EXEC Command Group Description Access Mode c...

Page 25: ...etwork Time Protocol SNTP predefined unicast clients Global Configuration sntp server Configures the Ethernet Switch Module to use the Simple Network Time Protocol SNTP to request and accept Network Time Protocol NTP traffic from a server Global Configuration show clock Displays the time and date from the system clock User EXEC show sntp configuration Shows the configuration of the Simple Network ...

Page 26: ...onfiguration speed Configures the speed of a given Ethernet interface when not using auto negotiation Interface Configuration negotiation Enables auto negotiation operation for the speed and duplex parameters of a given interface Interface Configuration flowcontrol Configures the Flow Control on a given interface Interface Configuration mdix Enables automatic crossover on a given interface Interfa...

Page 27: ...plays the storm control configuration Privileged User EXEC Command Group Description Mode gvrp enable global Enables GVRP globally Global Configuration gvrp enable interface Enables GVRP on an interface Interface Configuration garp timer Adjusts the GARP application join leave and leaveall GARP timer values Interface Configuration gvrp vlan creation forbid Enables or disables dynamic VLAN creation...

Page 28: ...nfigures the leave time out Interface VLAN show ip igmp snooping mrouter Displays information on dynamically learned multicast router interfaces User EXEC show ip igmp snooping interface Displays IGMP snooping configuration User EXEC show ip igmp snooping groups Displays multicast groups learned by IGMP snooping User EXEC Command Group Description Access Mode ip address Sets an IP address Interfac...

Page 29: ...ys the default domain name a list of name server hosts the static and cached list of host names and addresses Privileged EXEC Command Group Description Access Mode lacp system priority Configures the system LACP priority Global Configuration lacp port priority Configures the priority value for physical ports Interface Configuration lacp timeout Assigns an administrative LACP timeout Interface Conf...

Page 30: ...x delay Specifies the delay between successive LLDP frame transmissions initiated by value status changes in the LLDP local systems MIB Global Configuration lldp optional tlv Specifies which optional TLVs from the basic set should be transmitted Interface Configuration Ethernet lldp management address Specifies the management address that would be advertised from an interface Interface Configurati...

Page 31: ...is used Global Configuration show management access list Displays management access lists Privileged EXEC show management access class Displays the active management access list Privileged EXEC Command Group Description Access Mode test copper port tdr Diagnoses with TDR Time Domain Reflectometry technology the quality and characteristics of a copper cable attached to a port Privileged EXEC show c...

Page 32: ... User EXEC Command Group Description Access Mode port monitor Starts a port monitoring session Interface Configuration show ports monitor Displays the port monitoring status User EXEC Command Group Description Access Mode qos Enables quality of service QoS on the Ethernet Switch Module and enters QoS basic mode Global Configuration show qos Displays the QoS status User EXEC wrr queue cos map Maps ...

Page 33: ...d encryption key for all RADIUS communications between the Ethernet Switch Module and the RADIUS daemon Global Configuration radius server retransmit Specifies the number of times the software searches the list of RADIUS server hosts Global Configuration radius server source ip Specifies the source IP address used for communication with RADIUS servers Global Configuration radius server timeout Set...

Page 34: ...nt table User EXEC show rmon log Displays the RMON logging table User EXEC rmon table size Configures the maximum RMON tables sizes Global Configuration Command Group Description Access Mode snmp server community Sets up the community access string to permit access to SNMP protocol Global Configuration snmp server view Sets up a system contact Global Configuration snmp server filter Creates or upd...

Page 35: ...D of the local Simple Network Management Protocol SNMP engine Privileged User EXEC show snmp Displays the SNMP status Privileged EXEC show snmp views Displays the configuration of views Privileged User EXEC show snmp groups Displays the configuration of groups Privileged User EXEC show snmp filters Displays the configuration of filters Privileged User EXEC show snmp users Displays the configuratio...

Page 36: ... Restarts the protocol migration process on all interfaces or on the specified interface Privileged EXEC show spanning tree Displays spanning tree configuration Privileged EXEC spanning tree mst priority Configures the device priority for the specified spanning tree instance Global Configuration spanning tree mst max hops Configures the number of hops in an MST region before the BDPU is discarded ...

Page 37: ...onfiguration Command Group Description Access Mode ip ssh port Specifies the port to be used by the SSH server Global Configuration ip ssh server Enables the Ethernet Switch Module to be configured from a SSH server Global Configuration crypto key generate dsa Generates DSA key pairs Global Configuration crypto key generate rsa Generates RSA key pairs Global Configuration ip ssh pubkey auth Enable...

Page 38: ...ssages displayed from an internal buffer based on severity Global Configuration logging buffered size Changes the number of syslog messages stored in the internal buffer Global Configuration clear logging Clears messages from the internal logging buffer Privileged EXEC logging file Limits syslog messages sent to the logging file based on severity Global Configuration clear logging file Clears mess...

Page 39: ...n Telnet sessions User EXEC show system Displays system information User EXEC show version Displays the system version information User EXEC asset tag Specifies the Ethernet Switch Module asset tag Global Configuration show system id Displays the service ID information User EXEC Command Group Description Mode tacacs server host Specifies a TACACS host Global Configuration tacacs server key Sets th...

Page 40: ...rns to the Privileged EXEC mode AfterPrivileged EXEC help Displays a brief description of the help system All history Enables the command history function Line Configuration history size Changes the command history buffer size for a particular line Line Configuration debug mode Switches the mode to debug Privileged EXEC show history Lists the commands entered in the current session Privileged EXEC...

Page 41: ...ID Interface Configuration switchport general allowed vlan Adds or removes VLANs from a general port Interface Configuration switchport general pvid Configures the PVID when the interface is in general mode Interface Configuration switchport general ingress filtering disable Disables port ingress filtering Interface Configuration switchport general acceptable frame type tagged only Discards untagg...

Page 42: ...displays certificate requests for HTTPS Privileged EXEC crypto certificate import Imports a certificate signed by Certification Authority for HTTPS Global Configuration ip https certificate Configures the active certificate for HTTPS Global Configuration show ip http Displays the HTTP server configuration Privileged EXEC show ip https Displays the HTTPS server configuration Privileged EXEC show cr...

Page 43: ...1x timeout supp timeout Sets the time for the retransmission of an Extensible Authentication Protocol EAP request frame to the client Interface Configuration dot1x timeout server timeout Sets the time for the retransmission of packets to the authentication server Interface Configuration show dot1x Allows multiple hosts on an 802 1X authorized port that has the dot1x port control interface configur...

Page 44: ...24 Command Groups ...

Page 45: ...one for display purposes clock summer time Configures the system to automatically switch to summer time daylight saving time crypto certificate generate Generates a HTTPS certificate crypto certificate import Imports a certificate signed by Certification Authority for HTTPS crypto key generate dsa Generates DSA key pairs crypto key generate rsa Generates RSA key pairs crypto key pubkey chain ssh E...

Page 46: ...les the Ethernet Switch Module to be configured from a browser ip https authentication Specifies authentication methods for HTTPS ip https certificate Configures the active certificate for HTTPS Use the no form of this command to return to default ip https server Enables the Ethernet Switch Module to be configured from a secured browser ip https port Configures a TCP port for use by a secure web b...

Page 47: ...bal Configure the system to trust state radius server deadtime Improves RADIUS response times when servers are unavailable port storm control broadcast rate Configures the maximum broadcast rate qos map dscp queue Defines the wrr queue mechanism on an egress queue wrr queue bandwidth Assigns Weighted Round Robin WRR weights to egress queues radius server host Specifies a RADIUS server host radius ...

Page 48: ...unctionality spanning tree bpdu Defines BPDU handling when spanning tree is disabled on an interface spanning tree forward time Configures the spanning tree bridge forward time spanning tree hello time Configures the spanning tree bridge Hello Time spanning tree max age Configures the spanning tree bridge maximum age spanning tree mode Configures the spanning tree protocol spanning tree pathcost m...

Page 49: ...e authperiod Sets the number of seconds between re authentication attempts dot1x timeout server timeout Sets the time for the retransmission of packets to the authentication server dot1x timeout supp timeout Sets the time for the retransmission of an EAP request frame to the client dot1x timeout tx period Sets the number of seconds that the Ethernet Switch Module waits for a response to an Extensi...

Page 50: ... interfaces sntp client enable interface Enables the Simple Network Time Protocol SNTP client on an interface spanning tree cost Configures the spanning tree path cost for a port spanning tree disable Disables spanning tree on a specific port spanning tree link type Overrides the default link type setting spanning tree portfast Enables PortFast mode spanning tree port priority Configures port prio...

Page 51: ...ration Protocol DHCP clear logging Clears messages from the internal logging buffer clear logging file Clears messages from the logging file clear spanning tree detected protocols Restarts the protocol migration process on all interfaces or on the specified interface clock set Manually sets the system clock configure Enters the global configuration mode copy Copies files from a source to a destina...

Page 52: ...itch Module show crypto certificate mycertificate Displays the SSL certificates of the Ethernet Switch Module show dot1x Displays 802 1X status for the Ethernet Switch Module or for the specified interface show dot1x advanced Displays 802 1X enhanced features for the Ethernet Switch Module or for the specified interface show dot1x users Displays 802 1X users for the Ethernet Switch Module show dot...

Page 53: ...ers accounts Displays information about the local user database test copper port tdr Diagnoses with TDR Time Domain Reflectometry technology the quality and characteristics of a copper cable attached to a port Command Description key string Manually specifies a SSH public key user key Specifies which SSH public key is manually configured and enters the SSH public key string configuration command C...

Page 54: ...n dynamically learned multicast router interfaces show line Displays line parameters show ports jumbo frame Displays the jumbo frames configuration show ports monitor Displays the port monitoring status show privilege Displays the current privilege level show qos Displays the QoS status show qos interface Assigns CoS values to select one of the egress queues show qos map Displays all the maps for ...

Page 55: ...les forwarding of all multicast frames on a port ip igmp snooping Enables Internet Group Management Protocol IGMP snooping on a specific VLAN ip igmp snooping host time out Configures the host time out ip igmp snooping leave time out Configures the leave time out ip igmp snooping mrouter time out Configures the mrouter time out ip igmp snooping mrouter learn pim dvmrp The ip igmp snooping mrouter ...

Page 56: ...36 Command Modes ...

Page 57: ...ommand modes Each command mode has its own set of specific commands Entering a question mark at the system prompt console prompt displays a list of commands available for that particular command mode From each mode a specific command is used to navigate from one command mode to another The standard order to access the modes is as follows User EXEC mode Privileged EXEC mode Global Configuration mod...

Page 58: ...asic tests and list system information The user level prompt consists of the Ethernet Switch Module host name followed by the angle bracket The default host name is Console unless it has been changed using the hostname command in the Global Configuration mode Privileged EXEC Mode Privileged access is password protected to prevent unauthorized use because many of the privileged commands set operati...

Page 59: ...ommand configure is used to enter the Global Configuration mode To enter the Global Configuration mode perform the following steps 1 At the Privileged EXEC mode prompt enter the command configure and press Enter The Global Configuration mode prompt is displayed The Global Configuration mode prompt consists of the Ethernet Switch Module host name followed by the word config and To return from the G...

Page 60: ...he member ports as a single entity The Global Configuration mode command interface port channel is used to enter the Port Channel Interface Configuration mode SSH Public Key chain Contains commands to manually specify other Ethernet Switch Module SSH public keys The Global Configuration mode command crypto key pubkey chain ssh is used to enter the SSH Public Key chain Configuration mode QoS Contai...

Page 61: ...g in onto the DRAC MC using the default username root and password calvin The DRAC MC CLI command prompt DRAC MC is displayed For more information see Dell Modular Server System User s Guide 4 If Dell Modular Server Chassis is off then power it on using the following DRAC MC CLI command racadm chassisaction m chassis powerup NOTE The Ethernet Switch Module inserted into the Chassis I O bay is powe...

Page 62: ... the Ethernet Switch Module is operating properly 8 If an error is displayed or the green system LED is flashing stop the installation process and contact Dell technical support 9 Enter the following commands to begin the configuration procedure console enable console configure console config 10 Configure the Ethernet Switch Module and enter the necessary commands to complete the required tasks 11...

Page 63: ... time a command is entered in the CLI it is recorded on an internally managed Command History buffer Commands stored in the buffer are maintained on a First In First Out FIFO basis These commands can be recalled reviewed modified and reissued This buffer is not preserved across Ethernet Switch Module resets By default the history buffer system is enabled but it can be disabled at any time For info...

Page 64: ...re are certain command entry standards that apply to all commands The following table describes the command conventions Keyboard Key Description Up arrow key Recalls commands from the history buffer beginning with the most recent command Repeat the key sequence to recall successively older commands Down arrow key Returns the most recent commands from the history buffer after recalling commands wit...

Page 65: ...rompts appearing on the console all When a parameter is required to define a range of ports or parameters and all is an option the default for the command is all when no parameters are defined For example the command interface range port channel has the option of either entering a range of channels or selecting all When the command is entered without a parameter it automatically defaults to all ...

Page 66: ...46 Using the CLI ...

Page 67: ...e from the following table Default Configuration The local user database is checked This has the same effect as the command aaa authentication login list name local NOTE On the console login succeeds without any authentication check if the authentication method is not defined Command Mode Global Configuration mode User Guidelines The default and optional list names created with the aaa authenticat...

Page 68: ... To return to the default configuration use the no form of this command Syntax aaa authentication enable default list name method1 method2 no aaa authentication enable default default Uses the listed authentication methods that follow this argument as the default list of methods when using higher privilege levels list name Character string up to 12 characters used to name the list of authenticatio...

Page 69: ...equence The additional methods of authentication are used only if the previous method returns an error not if it fails To ensure that the authentication succeeds even if all methods return an error specify none as the final method in the command line All aaa authentication enable default requests sent by the Ethernet Switch Module to a RADIUS or TACACS server include the username enab15 Example Th...

Page 70: ...sole To return to the default specified by the enable authentication command use the no form of this command Syntax enable authentication default list name no enable authentication default Uses the default list created with the authentication enable command list name Uses the indicated list created with the authentication enable command Default Configuration Uses the default set with the command a...

Page 71: ...ethod returns an error not if it fails To ensure that the authentication succeeds even if all methods return an error specify none as the final method in the command line Example The following example configures the http authentication ip https authentication The ip https authentication Global Configuration mode command specifies authentication methods for https servers To return to the default us...

Page 72: ...methods return an error specify none as the final method in the command line Example The following example configures https authentication show authentication methods The authentication methods Privileged EXEC mode command displays information about the authentication methods Syntax show authentication methods Default Configuration This command has no default configuration Command Mode Privileged ...

Page 73: ...this command Syntax password password encrypted no password password Password for this level from 1 to 159 characters in length console show authentication methods Login Authentication Method Lists Console_Default None Network_Default Local Enable Authentication Method Lists Console_Default Enable None Network_Default Enable Line Login Method List Enable Method List Console Default Default Telnet ...

Page 74: ...rol access to user and privilege levels To remove the password requirement use the no form of this command Syntax enable password level level password encrypted no enable password level level password Password for this level from 1 to 159 characters in length level Level for which the password applies If not specified the level is 15 Range 1 15 encrypted Encrypted password entered copied from anot...

Page 75: ...n password for the user Range 1 159 characters level The user level Range 1 15 encrypted Encrypted password entered copied from another Ethernet Switch Module configuration Default Configuration No user is defined Command Mode Global Configuration mode User Guidelines User account can be created without a password Example The following example configures user bob with the password lee and user lev...

Page 76: ...has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays the local users configured with access to the system console show users accounts Username Privilege Bob 15 Robert 15 ...

Page 77: ... valid MAC address in the format of xx xx xx xx xx xx interface A valid Ethernet port port channel number A valid port channel number permanent The address can only be deleted by the no bridge address command delete on reset The address is deleted after reset delete on timeout The address is deleted after age out time has expired secure The address is deleted after the port changes mode to unlock ...

Page 78: ...o drop on the multicast router ports If multicast routers exist on the VLAN and IGMP snooping is not enabled the bridge multicast forward all command should be used to enable forwarding all multicast packets to the multicast routers Example In this example bridge multicast filtering is enabled bridge multicast address The bridge multicast address Interface Configuration VLAN mode command registers...

Page 79: ...te a range of ports port channel number list Separate non consecutive port channels with a comma and no spaces a hyphen is used to designate a range of ports Default Configuration No multicast addresses are defined Command Mode Interface configuration VLAN mode User Guidelines If the command is executed without add or remove the command only registers the group in the bridge database Static multic...

Page 80: ... xx ip multicast address IP multicast address in the format of xxx xxx xxx xxx interface list Separate non consecutive valid Ethernet ports with a comma and no spaces hyphen is used to designate a range of ports port channel number list Separate non consecutive valid port channels with a comma and no spaces a hyphen is used to designate a range of port channels Default Configuration No forbidden a...

Page 81: ...o designate a range of ports port channel number list Separate non consecutive valid port channels with a comma and no spaces a hyphen is used to designate a range of port channels Default Configuration Forward all is not defined on any interface Command Mode Interface Configuration VLAN mode User Guidelines There are no user guidelines for this command Example In this example all multicast packet...

Page 82: ...etting is disabled forwarding to the port is not forbidden Command Mode Interface Configuration VLAN mode User Guidelines IGMP snooping dynamically discovers multicast router ports When a multicast router port is discovered all the multicast packets are forwarded to it unconditionally This command prevents a port to be a multicast router port Example In this example forwarding all multicast packet...

Page 83: ...no keywords or arguments Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example In this example the bridge tables are cleared port security The port security Interface Configuration Ethernet port channel mode command locks the port By locking the port unknown traffic can be blocked and ...

Page 84: ...ernet port channel mode User Guidelines Multiple hosts must be enabled see dot1x multiple hosts Example In this example the port g12 is locked for learning but continues to forward all packets received with traps being sent every 100 seconds if a packet with an unkown source address is received port security routed secure address The port security routed secure address Interface Configuration Ethe...

Page 85: ...o port g13 show bridge address table The show bridge address table Privileged EXEC mode command displays all entries in the bridge forwarding database Syntax show bridge address table vlan vlan ethernet interface port channel port channel number vlan Specific valid VLAN such as VLAN 1 interface A valid Ethernet port port channel number A valid port channel number Default Configuration This command...

Page 86: ...umber vlan Specific valid VLAN such as VLAN 1 interface A valid Ethernet port port channel number A valid port channel number Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example In this example all static entries in the bridge forwarding database are displayed console show bridge add...

Page 87: ...rt channel number A valid port channel number Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines This command displays the count of addresses for one of the VLANs for all VLANs or for a specific port Example In this example the number of addresses present in all VLANs are displayed console show bridge address table static Aging time is...

Page 88: ... multicast address An IP multicast address in the format of xxx xxx xxx xxx format Multicast address format Can be ip or mac If format is unspecified the default is mac Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines A MAC address can be displayed in IP format only if it is in the range of 0100 5e00 0000 0100 5e7f ffff Example In th...

Page 89: ...9 01 00 5e 02 02 08 dynamic g15 16 Forbidden ports for multicast addresses Vlan MAC Address Ports 1 01 00 5e 02 02 03 g11 19 01 00 5e 02 02 08 g12 console show bridge multicast address table format ip Vlan IP Address Type Ports 1 224 239 130 2 2 3 static g11 g12 19 224 239 130 2 2 8 static g13 14 19 224 239 130 2 2 8 dynamic g15 16 Forbidden ports for multicast addresses Vlan IP Address Ports 1 22...

Page 90: ...e User Guidelines There are no user guidelines for this command Example In this example the multicast configuration for VLAN 1 is displayed show ports security The show ports security Privileged EXEC mode command displays the port lock status Syntax show ports security ethernet interface port channel port channel number interface A valid Ethernet port port channel number A valid port channel numbe...

Page 91: ...extra columns in the displayed port lock status are as follows Frequency Minimum time in seconds between consecutive traps Counter Number of actions since last trap Example In this example all classes of entries in the port lock status are displayed console show ports security Port Status Action Trap Frequency Counter g11 Locked Discard Enable 100 88 g12 Unlocked g13 Locked Discard Shutdown Disabl...

Page 92: ...72 Address Table Commands ...

Page 93: ...c year Current year 2000 2097 Default Configuration The default time set is 0 0 0 Jan 1 2000 or xxxxx Month Day Year Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example sets the system time to 13 32 00 on the 7th March 2002 clock source The clock source Global Configuration mode command configures an external time source for...

Page 94: ...and Syntax clock timezone hours offset minutes minutes offset zone acronym no clock timezone hours offset Hours difference from UTC Range 12 13 minutes offset Minutes difference from UTC Range 0 59 acronym The acronym of the time zone Range Up to 4 characters Default Configuration Clock set to UTC Command Mode Global Configuration mode User Guidelines The system internally keeps time in UTC so thi...

Page 95: ...uld start on the first specific date listed in the command and end on the second specific date in the command usa The summer time rules are the United States rules eu The summer time rules are the European Union rules week Week of the month Range 1 5 first last day Day of the week Range first three letters by name like sun date Date of the month Range 1 31 month Month Range first three letters by ...

Page 96: ...g time Start Last Sunday in March End Last Sunday in October Time 1 am 01 00 The following steps must be completed before setting the summer clock a Configure the summer time b Define the timezone c Set the clock For example console config clock summer time recurring usa console config clock timezone 2 zone TMZ2 console config clock set 10 00 00 apr 15 2004 Examples The following example sets summ...

Page 97: ...e following example defines the authentication key for SNTP sntp authenticate The sntp authenticate Global Configuration mode command grants authentication for received Network Time Protocol NTP traffic from servers To disable the feature use the no form of this command Syntax sntp authenticate no sntp authenticate Default Configuration No authentication Command Mode Global Configuration mode User...

Page 98: ...5 Default Configuration No keys are trusted Command Mode Global Configuration mode User Guidelines The command is relevant for both received unicast and broadcast If there is at least 1 trusted key then unauthenticated messages will be ignored Examples The following example authenticates key 8 sntp client poll timer The sntp client poll timer Global Configuration mode command sets the polling time...

Page 99: ...tp broadcast client enable The sntp broadcast client enable Global Configuration mode command enables the Simple Network Time Protocol SNTP broadcast clients To disable the SNTP broadcast clients use the no form of this command Syntax sntp broadcast client enable no sntp broadcast client enable Default Configuration Client is disabled Command Mode Global Configuration mode User Guidelines Use the ...

Page 100: ...iguration mode command Use the sntp client enable Interface Configuration mode command to enable the SNTP client on a specific interface The port must have an IP interface already configured Examples The following example enables anycast clients sntp client enable interface The sntp client enable Interface Configuration Ethernet port channel VLAN mode command enables the Simple Network Time Protoc...

Page 101: ...ables the Ethernet Switch Module to use the Simple Network Time Protocol SNTP to request and accept Network Time Protocol NTP traffic from servers To disable requesting and accepting Network Time Protocol NTP traffic from servers use the no form of this command Syntax sntp unicast client enable no sntp unicast client enable Default Configuration Client is disabled Command Mode Global Configuration...

Page 102: ...ollowing example enables polling for the Simple Network Time Protocol SNTP predefined unicast clients sntp server The sntp server Global Configuration mode command configures the Ethernet Switch Module to use the Simple Network Time Protocol SNTP to request and accept Network Time Protocol NTP traffic from a specified server To remove a server from the list of NTP servers use the no form of this c...

Page 103: ...obal Configuration mode command If multiple servers are added then the updates applied are determined by the following Unicast Server updates take precedence followed by Anycast and then Broadcast Examples The following example configures the Ethernet Switch Module to accept Network Time Protocol NTP traffic from the server on 192 1 1 1 show clock The show clock User EXEC mode command displays the...

Page 104: ...tive blank Time is authoritative Time is authoritative but SNTP is not synchronized console show clock 15 29 03 PDT UTC 7 Jun 17 2002 Time source is SNTP console show clock detail 15 29 03 PDT UTC 7 Jun 17 2002 Time source is SNTP Time zone Acronym is PST Offset is UTC 8 Summertime Acronym is PDT Recurring every year Begins at first Sunday of April at 2 00 Ends at last Sunday of October at 2 00 Of...

Page 105: ...leged EXEC mode User Guidelines There are no user guidelines for this command Examples The following example displays Ethernet Switch Module current SNTP configuration console show sntp configuration Polling interval 1024 seconds No MD5 Authentication keys Authentication is not required for synchronization No Trusted Keys Unicast Clients Polling Disabled Server Polling Encryption Key 176 1 1 8 Ena...

Page 106: ...nes There are no user guidelines for this command Examples The following example shows the status of the SNTP console show sntp status Clock is synchronized stratum 4 reference is 176 1 1 8 Reference time is AFE2525E 70597B34 00 10 22 438 PDT Jul 5 1993 Unicast servers Server Status Last response Offset mSec Delay mSec 176 1 1 8 Up 19 58 22 289 PDT Feb 19 2002 7 33 117 79 176 1 8 179 Unknown 12 17...

Page 107: ...Clock 87 176 1 11 8 VLAN 118 Up 9 53 21 789 PDT Feb 19 2002 7 19 119 89 Broadcast Interface Interface Last response 176 1 1 8 VLAN 119 19 17 59 792 PDT Feb 19 2002 ...

Page 108: ...88 Clock ...

Page 109: ...leged EXEC mode User Guidelines There are no user guidelines for this command Examples The following example deletes the startup config file copy The copy Privileged EXEC mode command copies files from a source to a destination Syntax copy source url destination url source url The source file location URL or reserved keyword being copied destination url The destination file URL or reserved keyword...

Page 110: ...s period dot b At the command prompt of the DRAC MC issue the following command racadm config g cfgSerial o cfgSerialConsoleIdleTimeout 0x3000 Keyword Description flash Source or destination URL for Flash memory It s the default in case a URL is specified without a prefix The syntax is flash startup config flash image running config Represents the current running configuration file startup config ...

Page 111: ...tination exist Specifically the following cannot be copied If the source file and destination file are the same file xmodem cannot be a destination Can only be copied to image boot and null tftp cannot be the source and destination on the same copy Active Image is the image the system currently boots from see show bootvar command or set to boot next from Non active image is the spare image locatio...

Page 112: ... replace the startup configuration file with the copied configuration file Storing the Running or Startup Configuration on a Server Use the copy running config destination url command to copy the current configuration file to a network server using TFTP Use the copy startup config destination url command to copy the startup configuration file to a network server The configuration file copy can ser...

Page 113: ...Specifies image 1 as the system startup image image 2 Specifies image 2 as the system startup image Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines Use the show bootvar command to find out which image is the active image Examples The following example loads system image 1 for the next Ethernet Switch Module startup console copy tftp...

Page 114: ...le Syntax show running config Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines show running config does not show all the port configurations under the port Although the Ethernet Switch Module is already configured with some default parameters show running config on an empty Ethernet Switch Module is empty ...

Page 115: ...file contents Syntax show startup config Default Configuration This command has no default configuration console show running config no spanning tree vlan database vlan 2 exit interface range ethernet g 1 2 switchport access vlan 2 exit interface vlan 2 bridge address 00 00 00 00 00 01 ethernet g1 exit interface ethernet g1 gvrp enable exit gvrp enable interface ethernet g14 ip address dhcp exit i...

Page 116: ...onfig The show backup config Privileged EXEC mode command displays the backup configuration file contents console show startup config no spanning tree vlan database vlan 2 exit interface range ethernet g 1 2 switchport access vlan 2 exit interface vlan 2 bridge address 00 00 00 00 00 01 ethernet g1 exit interface ethernet g1 gvrp enable exit gvrp enable interface ethernet g14 ip address dhcp exit ...

Page 117: ...onfiguration file contents show bootvar The show bootvar Privileged EXEC mode command displays the active system image file that the Ethernet Switch Module loads at startup Syntax show bootvar Default Configuration This command has no default configuration console show backup config hostname device interface ethernet g1 ip address 176 242 100 100 255 255 255 0 duplex full speed 1000 interface ethe...

Page 118: ...s There are no user guidelines for this command Examples The following example displays the active system image file that the Ethernet Switch Module loads at startup console show bootvar Images currently available on the FLASH image 1 active selected for next boot image 2 not active ...

Page 119: ...es There are no user guidelines for this command Example The following example enables ports g16 for configuration interface range ethernet The interface range ethernet Global Configuration mode command enters the interface configuration mode to configure multiple Ethernet type interfaces Syntax interface range ethernet port range all port range List of valid ports to add Where more than one port ...

Page 120: ...to g14 are grouped to receive the same command shutdown The shutdown Interface Configuration Ethernet port channel mode command disables interfaces To restart a disabled interface use the no form of this command Syntax shutdown no shutdown Default Configuration The interface is enabled Command Mode Interface Configuration Ethernet port channel mode User Guidelines There are no user guidelines for ...

Page 121: ...e a description Command Mode Interface Configuration Ethernet port channel mode User Guidelines There are no user guidelines for this command Example The following example adds a description to port g15 speed The speed Interface Configuration Ethernet port channel mode command configures the speed of a given Ethernet interface when not using auto negotiation To restore the default use the no form ...

Page 122: ... duplex The duplex Interface Configuration Ethernetl mode command configures the full half duplex operation of a given Ethernet interface when not using auto negotiation To restore the default use the no form of this command Syntax duplex half full no duplex half Configure half duplex operation full Configure full duplex operation Default Configuration The interface is set to full duplex Command M...

Page 123: ...Mode Interface Configuration Ethernet port channel mode User Guidelines Turning off auto negotiation on an aggregate link may under some circumstances make it nonoperational If the other side has auto negotiation turned on it may re synchronize all members of the aggregated link to half duplex operation and may as per the standards set them all inactive Example The following example enables autone...

Page 124: ... set to HALF When Flow Control is ON the head of line blocking mechanism of this port is disabled If a link is set to NOT use auto negotiation the other side of the link must also be configured to not use auto negotiation Example In the following example Flow Control is enabled on port g15 mdix The mdix Interface Configuration Ethernet port channel mode command enables automatic crossover on a giv...

Page 125: ...ting you can only use either an ethernet standard cross over cable to connect to a PC or an ethernet standard cable to connect to another Ethernet Switch Module Example In the following example automatic crossover is enabled on port g15 back pressure The back pressure Interface Configuration Ethernet port channel mode command enables Back Pressure on a given interface To disable Back Pressure use ...

Page 126: ...are not enabled Command Mode Global Configuration mode User Guidelines The command would be effective only after reset Example In the following example Jumbo Frames are enabled on the Ethernet Switch Module clear counters The clear counters User EXEC mode command clears statistics on an interface Syntax clear counters ethernet interface port channel port channel number interface Valid Ethernet por...

Page 127: ...face Valid Ethernet port port channel number Valid port channel index Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines This command is used to activate interfaces that were configured to be active but were shutdown for some reason for example port security Example The following example activates interface g15 which is disabled show i...

Page 128: ...User Guidelines There are no user guidelines for this command Example The following example displays the configuration for all configured interfaces console show interfaces configuration Port Type Duplex Speed Neg Flow Control Admin State Back Pressure Mdix Mode g1 1G Fiber Full 1000 Disabled On Up Enable Auto g2 1G Fiber Full 1000 Disabled Off Up Disable Off g3 1G Fiber Full 1000 Disabled Off Up ...

Page 129: ...rol status Admin State Displays whether the port is enabled or disabled Back Pressure Displays the Back Pressure status MDIX Mode Displays the Auto crossover status show interfaces status The show interfaces status User EXEC mode command displays the status for all interfaces Syntax show interfaces status ethernet interface port channel port channel number interface A valid Ethernet port port chan...

Page 130: ...terfaces status Port Type Duplex Speed Neg Flow Control Back Pressure MDIX Mode Link State g11 1G Copper Full 100 Enabled On Enable On Up g12 1G Copper Full 100 Enabled Off Disable Off Down Ch Type Duplex Speed Neg Flow Control Back Pressure Link State Ch1 1000 Full 1000 Off Off Disable Up The interface was suspended by the system ...

Page 131: ...tus Link State Displays the Link Aggregation status Back Pressure Displays the Back Pressure status MDIX Mode Displays the MDIX status show interfaces description The show interfaces description User EXEC mode command displays the description for all configured interfaces Syntax show interfaces description ethernet interface port channel port channel number interface Valid Ethernet port port chann...

Page 132: ...ce A valid Ethernet port port channel number A valid port channel index Default Configuration This command has no default configuration Command Modes User EXEC mode User Guidelines There are no user guidelines for this command Examples The following example displays traffic seen by the physical interface console show interfaces description ethernet g11 Port Description g11 Management_port console ...

Page 133: ...isplays counters for port g11 Port OutOctets OutUcastPkts OutMcastPkts OutBcastPkts g14 9188 9 8 0 g15 0 0 0 0 g16 8789 27 8 0 Ch InOctets InUcastPkts InMcastPkts InBcastPkts 1 27889 928 0 78 Ch OutOctets OutUcastPkts OutMcastPkts OutBcastPkts 1 23739 882 0 122 ...

Page 134: ...le Collision Frames 0 Multiple Collision Frames 0 SQE Test Errors 0 Deferred Transmissions 0 Late Collisions 0 Excessive Collisions 0 Internal MAC Tx Errors 0 Carrier Sense Errors 0 Oversize Packets 0 Internal MAC Rx Errors 0 Received Pause Frames 0 Transmitted Pause Frames 0 Field Description InOctets Counted received octets InUcastPkts Counted received unicast packets InMcastPkts Counted receive...

Page 135: ...etection mechanism in the PLS Carrier Sense Function as described in IEEE Std 802 3 2000 Edition section 7 2 4 6 Deferred Transmissions A count of frames for which the first transmission attempt is delayed because the medium is busy Late Collisions Counted times that a collision is detected later than one slotTime into the transmission of a packet Excessive Collisions Counted frames for which tran...

Page 136: ...ast packets use the no form of this command Syntax port storm control include multicast no port storm control include multicast There are no arguments or keywords for this command Default Configuration Multicast packets are not counted Command Modes Global Configuration mode User Guidelines To control multicasts storms use the commands port storm control broadcast enable and port storm control bro...

Page 137: ...rt of the storm frames if the port storm control include multicast Global Configuration mode command is enabled Example The following example enables broadcast storm control on port g15 port storm control broadcast rate The port storm control broadcast rate Global Configuration mode command configures the maximum broadcast rate Use the no form of this command to return to the default value port st...

Page 138: ...isplays the storm control configuration Syntax show ports storm control ethernet interface interface A valid Ethernet port Default Configuration This command has no default configuration Command Modes Privileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays the storm control configuration console config port storm control broadcast r...

Page 139: ...ser Guidelines There are no user guidelines for this command Example The following example enables NIC redundancy feature show nic redundancy Use the show nic redundancy command to display the NIC redundancy status Syntax show nic redundancy Default Configuration Disabled Command Modes Global configuration User Guidelines There are no user guidelines for this command Example The following example ...

Page 140: ...120 Ethernet Configuration Commands ...

Page 141: ...RP globally on the Ethernet Switch Module use the no form of this command Syntax gvrp enable no gvrp enable Default Configuration GVRP is globally disabled Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example globally enables GVRP on the Ethernet Switch Module gvrp enable interface The gvrp enable Interface Configuration...

Page 142: ... the no form of this command Syntax garp timer join leave leaveall timer_value no garp timer join Indicates the time in milliseconds that PDUs are transmitted Range 10 2147483640 leave Indicates the amount of time in milliseconds that the Ethernet Switch Module waits before leaving its GARP state The Leave Time is activated by a Leave All Time message sent received and cancelled by the Join messag...

Page 143: ...g16 to 900 milliseconds gvrp vlan creation forbid The gvrp vlan creation forbid Interface Configuration Ethernet port channel mode command enables or disables dynamic VLAN creation To disable dynamic VLAN creation use the no form of this command Syntax gvrp vlan creation forbid no gvrp vlan creation forbid Default Configuration By default dynamic VLAN creation is enabled Command Mode Interface Con...

Page 144: ...rt is allowed Command Mode Interface Configuration Ethernet port channel mode User Guidelines There are no user guidelines for this command Example The following example shows how default dynamic registering and deregistering is forbidden for each VLAN on port g16 clear gvrp statistics The clear gvrp statistics Privileged EXEC mode command clears all the GVRP statistics information Syntax clear gv...

Page 145: ...C mode command displays GVRP configuration information including timer values whether GVRP and dynamic VLAN creation is enabled and which ports are running GVRP Syntax show gvrp configuration ethernet interface port channel port channel number interface A valid Ethernet interface port channel number A valid port channel index Default Configuration This command has no default configuration Command ...

Page 146: ...valid Ethernet interface port channel number A valid index Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command console show gvrp configuration GVRP Feature is currently enabled on the device Maximum VLANs 256 Port s GVRP Status Registration Dynamic VLAN Creation Timers milliseconds Join Leave Leav...

Page 147: ...eived rJIn Join In Received rEmp Empty Received rLIn Leave In Received rLE Leave Empty Received rLA Leave All Received sJE Join Empty Sent sJIn Join In Sent sEmp Empty Sent sLIn Leave In Sent sLE Leave Empty Sent sLA Leave All Sent Port rJE rJIn rEmp rLIn rLE rLA sJE sJIn sEmp sLIn sLE sLA g11 0 0 0 0 0 0 0 0 0 0 0 0 g12 0 0 0 0 0 0 0 0 0 0 0 0 g13 0 0 0 0 0 0 0 0 0 0 0 0 g14 0 0 0 0 0 0 0 0 0 0 0...

Page 148: ... mode User Guidelines There are no user guidelines for this command Example The following example displays GVRP statistics information console show gvrp error statistics GVRP error statistics Legend INVPROT Invalid Protocol Id INVATYP Invalid Attribute Type INVALEN Invalid Attribute Length INVAVAL Invalid Attribute Value INVEVENT Invalid Event Port INVPROT INVATYP INVAVAL INVALEN INVEVENT g11 0 0 ...

Page 149: ...ration mode User Guidelines There are no user guidelines for this command Example The following example enables IGMP snooping ip igmp snooping The ip igmp snooping Interface Configuration VLAN mode command enables Internet Group Management Protocol IGMP snooping on a specific VLAN To disable IGMP snooping on a VLAN interface use the no form of this command Syntax ip igmp snooping no ip igmp snoopi...

Page 150: ...c learning of multicast router ports is enabled Command Mode Interface Configuration VLAN mode User Guidelines There are no user guidelines for this command Example The following example enables automatic learning of multicast router ports on VLAN 2 ip igmp snooping host time out The ip igmp snooping host time out Interface Configuration VLAN mode command configures the host time out If an IGMP re...

Page 151: ...ping mrouter time out Interface Configuration VLAN mode command configures the mrouter time out The ip igmp snooping mrouter time out command is used for setting the aging out time after multicast router ports are automatically learned To configure the default mrouter time out use the no form of this command Syntax ip igmp snooping mrouter time out time out no ip igmp snooping mrouter time out tim...

Page 152: ...oping leave time out time out leave time out in seconds Range 0 2147483647 immediate leave Specifies that the port should be immediately removed from the members list after receiving IGMP Leave Default Configuration The default leave time out configuration is 10 seconds Command Mode Interface Configuration VLAN mode User Guidelines The leave timeout should be set greater than the maximum time that...

Page 153: ...uration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Example The following example shows IGMP snooping multicast router information show ip igmp snooping interface The show ip igmp snooping interface User EXEC mode command displays IGMP snooping configuration Syntax show ip igmp snooping interface vlan id vlan id VLAN ID value Default Configuration This...

Page 154: ...IP multicast address Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines To see the full multicast address table including static addresses use the show bridge multicast address table Privileged EXEC command Example The example shows IGMP snooping information console show ip igmp snooping interface 1 IGMP Snooping is globaly disabled IGMP Sno...

Page 155: ...IGMP Snooping Commands 135 console show ip igmp snooping groups Vlan IP Address Querier Ports 1 224 239 130 2 2 3 Yes g11 g12 19 224 239 130 2 2 8 Yes g13 14 ...

Page 156: ...136 IGMP Snooping Commands ...

Page 157: ...d Mode Privileged EXEC mode User Guidelines This command would delete the host name to address mapping temporarily until the next renew of the IP address Examples The following example deletes all entries from the host name to address mapping ip address The ip address Interface Configuration Ethernet VLAN port channel mode command sets an IP address To remove an IP address use the no form of this ...

Page 158: ...Interface Configuration Ethernet VLAN port channel mode command acquires an IP address on an interface from the Dynamic Host Configuration Protocol DHCP server To deconfigure any acquired address use the no form of this command The no ip address dhcp command deconfigures any IP address that was acquired thus sending a DHCPRELEASE message Syntax ip address dhcp hostname host name no ip address dhcp...

Page 159: ...fied DHCP host name is the Ethernet Switch Module globally configured host name However you can use the ip address dhcp hostname host name command to place a different name in the DHCP option 12 field than the globally configured host name of the Ethernet Switch Module The no ip address dhcp command deconfigures any IP address that was acquired thus sending a DHCPRELEASE message Example The follow...

Page 160: ... show ip interface ethernet interface number vlan vlan id port channel port channel number interface number Ethernet port number vlan id VLAN number port channel number Port channel number Default Configuration This command has no default configuration Command Mode Pivileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example the displays the confi...

Page 161: ... this command Syntax arp ip_addr hw_addr ethernet interface number vlan vlan id port channel port channel number no arp ip_addr ethernet interface number vlan vlan id port channel port channel number ip_addr IP address or IP alias to map to the specified MAC address hw_addr MAC address to map to the specified IP address or IP alias interface number Ethernet port number vlan id VLAN number port cha...

Page 162: ...eout Global Configuration mode command configures how long an entry remains in the ARP cache To restore the default value use the no form of this command Syntax arp timeout seconds no arp timeout seconds Time in seconds that an entry remains in the ARP cache Range 1 40000000 Default Configuration The default timeout is 60000 seconds Command Mode Global Configuration mode User Guidelines It is reco...

Page 163: ...ivileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example deletes all dynamic entries from the ARP cache show arp The show arp Privileged EXEC mode command displays entries in the ARP table Syntax show arp Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guideline...

Page 164: ...lines There are no user guidelines for this command Examples The following example enables the IP Domain Naming System DNS based host name to address translation ip domain name The ip domain name Global Configuration mode command defines a default domain name that the software uses to complete unqualified host names names without a dotted decimal domain name To disable use of the Domain Name Syste...

Page 165: ...of www dell com ip name server The ip name server Global Configuration mode command sets the available name servers To remove a name server use the no form of this command Syntax ip name server server address server address2 server address8 no ip name server server address1 server address8 server address IP addresses of the name server Up to 8 servers can be defined in one command or by using mult...

Page 166: ...ress Associated IP address Default Configuration No host is defined Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Examples The following example defines a static host name to address mapping in the host cache clear host The clear host Privileged EXEC mode command deletes entries from the host name to address cache Syntax clear host name name P...

Page 167: ...how hosts The show hosts Privileged EXEC mode command displays the default domain name a list of name server hosts the static and the cached list of host names and addresses Syntax show hosts name name Name of the host Range 1 158 characters Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this comman...

Page 168: ...domain is GM COM Name address lookup is enabled Name servers 176 16 1 18 176 16 1 19 Static host name to address mapping Host Addresses www dell com 176 16 8 8 176 16 8 9 Cache TTL Hours Host Total Elapsed Type Addresses www dell com 72 3 IP 171 64 14 203 ...

Page 169: ...em priority value is 1 Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example configures the system priority to 120 lacp port priority The lacp port priority Interface Configuration Ethernet mode command configures the priority value for physical ports To reset to default priority value use the no form of this command Synt...

Page 170: ...ut use the no form of this command Syntax lacp timeout long short no lacp timeout long Specifies a long timeout value short Specifies a short timeout value Default Configuration The default port timeout value is long Command Mode Interface Configuration Ethernet mode User Guidelines There are no user guidelines for this command Example The following example assigns an administrative LACP timeout f...

Page 171: ...statistics protocol state Interface Ethernet interface parameters Link aggregation parameter information statistics Link aggregation statistics information protocol state Link aggregation protocol state information Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example ...

Page 172: ...ort Oper key 30 port Oper number 21 port Admin priority 1 port Oper priority 1 port Admin timeout LONG port Oper timeout LONG LACP Activity ACTIVE Aggregation AGGREGATABLE synchronization FALSE collecting FALSE distributing FALSE expired FALSE Partner system priority 0 system mac addr 00 00 00 00 00 00 port Admin key 0 port Oper key 0 port Oper number 0 port Admin priority 0 collecting FALSE distr...

Page 173: ...s LACP PDUs sent 2 LACP PDUs received 2 Port g11 LACP Protocol State LACP State Machines Receive FSM Port Disabled State Mux FSM Detached State Periodic Tx FSM No Periodic State Control Variables BEGIN FALSE LACP_Enabled TRUE Ready_N FALSE Selected UNSELECTED Port_moved FALSE NNT FALSE Port_enabled FALSE Timer counters periodic tx timer 0 current while timer 0 wait while timer 0 ...

Page 174: ...ode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example shows how to display LACP port channel information console show lacp port channel 1 Port Channel 1 Port Type 1000 Ethernet Actor System Priority 1 MAC Address 00 02 85 0E 1C 00 Admin Key 29 Oper Key 29 Partner System Priority 0 MAC Address 00 00 00 00 00 00 Oper Key 14 ...

Page 175: ...e Global Configuration mode User Guidelines There are no user guidelines for this command Examples The following example configures the Ethernet Switch Module as a virtual terminal for remote console access exec timeout The exec timeout Line Configuration mode command sets the interval that the system waits until user input is detected To restore the default setting use the no form of this command...

Page 176: ...o 20 minutes show line The show line User EXEC mode command displays line parameters Syntax show line console telnet ssh console Console terminal line telnet Virtual terminal for remote console access Telnet ssh Virtual terminal for secured remote console access SSH Default Configuration If line is not specified the default value is console Command Mode User EXEC mode User Guidelines There are no ...

Page 177: ...Line Commands 157 Examples The following example displays the line configuration console show line console Interactive timeout 10 minutes History 10 ...

Page 178: ...158 Line Commands ...

Page 179: ...re no guidelines for this command Example The following example enables Link Layer Discovery Protocol LLDP lldp enable interface To enable Link Layer Discovery Protocol LLDP on an interface use the lldp enable command in interface configuration mode To disable LLDP on an interface use the no form of this command Syntax lldp enable rx tx both no lldp enable rx Receive only LLDP packets tx Transmit ...

Page 180: ...Examples The following example enables Link Layer Discovery Protocol LLDP on an interface g5 lldp timer To specify how often the software sends Link Layer Discovery Protocol LLDP updates use the lldp timer command in global configuration mode To revert to the default setting use the no form of this command Syntax lldp timer seconds no lldp timer seconds Specifies in seconds how often the software ...

Page 181: ...pecifies the hold time to be sent in the LLDP update packets as a multiple of the timer value Range 2 10 Default Configuraiton The default configuration is 4 Command Modes Global configuration User Guidelines The actual time to live value used in LLDP frames can be expressed by the following formula TTL min 65535 LLDP Timer LLDP HoldMultiplier For example if the value of LLDP timer is 30 and the v...

Page 182: ...ser Guidelines There are no user guidelines for this command Examples The following example pecifies the minimum time an LLDP port will wait before reinitializing LLDP transmission lldp tx delay To specify the delay between successive LLDP frame transmissions initiated by value status changes in the LLDP local systems MIB use the lldp tx delay command in global configuration mode To revert to the ...

Page 183: ... tlv command in interface configuration mode To revert to the default setting use the no form of this command Syntax lldp optional tlv tlv1 tlv2 tlv5 no lldp optional tlv tlv Specifies TLV that should be included Available optional TLVs are port desc sys name sys desc and sys cap Range 1 8192 seconds Default Configuration No optional TLV is transmitted Command Modes Interface configuration Etherne...

Page 184: ...nfiguration No IP address is advertised Command Modes Interface configuration Ethernet User Guidelines Each port can advertise one IP address Only static IP addresses can be advertised Example The following example specifies management address that would be advertised from an interface clear lldp rx To restart the LLDP RX state machine and clearing the neighbors table use the clear lldp rx command...

Page 185: ...ivileged EXEC mode Syntax show lldp configuration ethernet interface Interface Ethernet port Command Modes Privileged EXEC User Guidelines There are no user guidelines for this command Example The following example displays the Link Layer Discovery Protocol LLDP configuration console config clear lldp rx Switch show lldp configuration Timer 30 Seconds Hold multiplier 4 Reinit delay 2 Seconds Tx de...

Page 186: ...ing example displays the Link Layer Discovery Protocol LLDP information that is advertised from a specific port show lldp neighbors To display information about neighboring devices discovered using Link Layer Discovery Protocol LLDP use the show lldp neighbors command in privileged EXEC mode Syntax show lldp neighbors ethernet interface Interface Ethernet port Command Modes Privileged EXEC Switch ...

Page 187: ...ch show lldp neighbors Switch show lldp neighbors ethernet g1 Device ID 0060 704C 73FE Port ID 1 Hold Time 117 Capabilities B System Name ts 7800 2 System description Port description Management address 172 16 1 1 Port Device ID Port ID Hold Time Capabilities System Name g1 0060 704C 73FE 1 117 B ts 7800 2 g1 0060 704C 73FD 1 93 B ts 7800 2 g2 0060 704C 73F C 9 1 B R ts 7900 1 g3 0060 704C 73FB 1 ...

Page 188: ...168 LLDP Commands ...

Page 189: ...al Configuration mode User Guidelines This command enters the access list configuration mode where the denied or permitted access conditions with the deny and permit commands must be defined If no match criteria are defined the default is deny If reentering to an access list context the new rules are entered at the end of the access list Use the management access class command to select the active...

Page 190: ...ermit ip source ip address mask mask prefix length ethernet interface number vlan vlan id port channel port channel number service service interface number A valid Ethernet port number vlan id A valid VLAN number port channel number A valid port channel number ip address Source IP address Range Valid IP Address mask Specifies the network mask of the source IP address Range Valid subnet mask consol...

Page 191: ...itted in the access list called mlist deny management The deny Management Access List Configuration mode command defines a deny rule Syntax deny ethernet interface number vlan vlan id port channel port channel number service service deny ip source ip address mask mask prefix length ethernet interface number vlan vlan id port channel port channel number service service interface number A valid Ethe...

Page 192: ...cess list called mlist management access class The management access class Global Configuration mode command defines which management access list is used To disable restriction use the no form of this command Syntax management access class console only name no management access class name Name of the access list If unspecified defaults to an empty access list Range 1 32 characters console only The...

Page 193: ...t Range 1 32 characters Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays the active management access list show management access class The show management access class Privileged EXEC mode command displays the active management access list console c...

Page 194: ... no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays the management access list information console show management access class Management access class is enabled using access list mlist ...

Page 195: ...ion This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command NOTE The maximum distance VCT can function is 120 meters Examples The following example results in a report on the cable attached to port g13 show copper ports tdr The show copper ports tdr Privileged EXEC mode command displays the last TDR Time Domain Refle...

Page 196: ...ileged EXEC mode command displays the estimated copper cable length attached to a port Syntax show copper ports cable length interface interface A valid Ethernet port Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines The port must be active and working in 1000M mode console show copper ports tdr Port Result Length meters Date g11 OK g...

Page 197: ...ics Commands 177 Example The following example displays the estimated copper cable length attached to all ports console show copper ports cable length Port Length meters g11 50 g12 Giga link not active g13 110 140 ...

Page 198: ...178 PHY Diagnostics Commands ...

Page 199: ...ed with up to 6 member ports per port channel The aggregated links valid ID s are 1 8 Turning off auto negotiation of an aggregate link may under some circumstances make it nonoperational If the other side has auto negotiation turned on it may re synchronize all members of the aggregated link to half duplex operation and may as per the standards set them all to inactive Example The following examp...

Page 200: ...Example The following example shows how port channels 1 2 and 6 are grouped to receive the same command channel group The channel group Interface Configuration mode command associates a port with a port channel To remove a port from a port channel use the no form of this command Syntax channel group port channel number mode on auto no channel group port channel_number Specifies the number of the v...

Page 201: ... 2 3 Port channel load balancing is based on layer 2 and layer 3 parameters layer 2 3 4 Port channel load balancing is based on layer 2 layer 3 and layer 4 parameters Default Configuration Layer 2 Command Modes Global Configuration User Guidelines In L2 L3 L4 load balancing policy fragmented packets might be reordered Example The following example configures the load balancing policy of the port c...

Page 202: ...ault Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Example The following example shows how all port channel information is displayed console config show interfaces port channel Channel Ports ch1 Active g11 ch2 Active g12 g13 Inactive g14 ch3 Active g15 g16 ...

Page 203: ...on mode User Guidelines This command enables traffic on one port to be copied to another port or between the source port src interface and a destination port the port being configured Only a single target port can be defined per system The port being monitored cannot be set faster than the monitoring port The following restrictions apply to ports configured to be destination ports The port cannot ...

Page 204: ...x and receive Rx directions of more than one port are monitored the capacity may exceed the bandwidth of the target port In this case the division of the monitored packets may not be equal The user is advised to use caution in assigning port monitoring Example The following example shows how traffic on port g16 source port is copied to port g11 destination port show ports monitor The show ports mo...

Page 205: ... Monitor Commands 185 Example The following example shows how the port copy status is displayed console show ports monitor Source Port Destination Port Type Status g11 g16 RX TX Active g12 g16 RX TX Active ...

Page 206: ...186 Port Monitor Commands ...

Page 207: ...Ethernet Switch Module Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example shows how QoS is enabled on the Ethernet Switch Module in basic mode show qos The show qos User EXEC mode command displays the quality of service QoS mode for the entire Ethernet Switch Module Syntax show qos Default Configuration This command ha...

Page 208: ... queue cos map queue id queue id The queue number to which the following CoS values are mapped cos values Map to specific queues up to eight CoS values from 0 to 7 Separate values by space Default Configuration The map default values for 4 queues CoS value 1 select queue 1 CoS value 2 select queue 1 CoS value 0 select queue 2 CoS value 3 select queue 2 CoS value 4 select queue 3 CoS value 5 select...

Page 209: ... WRR weight is 1 Command Mode Global Configuration mode User Guidelines The ratio for each queue is defined by the queue weight divided by the sum of all queue weights that is the normalized weight This actually sets the bandwidth allocation of each queue A weight of 0 means no bandwidth is allocated for the same queue and the share bandwidth is divided among the remaining queues All 4 queues part...

Page 210: ...0 4 Default Configuration All queues are SP queues Command Mode Global Configuration mode User Guidelines When configuring the priority queue out num of queues command the weighted round robin WRR weight ratios are deleted Queue 4 is taken as the highest index queue Queue 3 is taken as the next highest queue If two priority queues are selected then queue 4 and 3 will be used leaving queue 2 and 1 ...

Page 211: ...oS to queue map and the TBD EF priority Default Configuration There is no default configuration for this command Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Examples The following example displays output from the show qos interface command console show qos interface ethernet g11 queuing Ethernet g11 wrr bandwidth weights and EF priority qid weights Ef ...

Page 212: ...P values separate each DSCP with a space Range 0 63 queue id Enter the queue number to which the DSCP value corresponds Default Configuration The following table describes the default map Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example maps DSCP values 33 40 and 41 to queue 1 1 1 2 1 3 2 4 3 5 3 6 4 7 4 DSCP value 0...

Page 213: ...ues Default Configuration CoS is the default trust mode Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example configures the system to DSCP trust state qos trust Interface The qos trust Interface Configuration mode command enables each port trust state To disable the trust state on each port use the no form of this comman...

Page 214: ... cos Specifies the default CoS value being assigned to the port If the port is trusted and the packet is untagged the CoS value will get the default CoS from the port Range 0 7 Default Configuration Port CoS is 0 Command Mode Interface Configuration Ethernet port channel command User Guidelines This command has no default configuration Example The following example configures port g15 default CoS ...

Page 215: ...mple displays the DSCP port queue map The following table describes the fields used above d1 x 10 d2 Value of DSCP console show qos map Dscp queue map d1 d2 0 1 2 3 4 5 6 7 8 9 0 01 01 01 01 01 01 01 01 01 01 1 01 01 01 01 01 01 02 02 02 02 2 02 02 02 02 02 02 02 02 02 02 3 02 02 03 03 03 03 03 03 03 03 4 03 03 03 03 03 03 03 03 04 04 5 04 04 04 04 04 04 04 04 04 04 6 04 04 04 04 Column Descriptio...

Page 216: ...196 QoS Commands ...

Page 217: ... 30 retransmit Specifies the re transmit value If no re transmit value is specified the global value is used Range 1 10 deadtime Length of time in minutes for which a RADIUS server is skipped over by transaction requests Range 0 2000 key Specifies the authentication and encryption key for all RADIUS communications between the Ethernet Switch Module and the RADIUS server This key must match the enc...

Page 218: ...imeout period 20 seconds radius server key The radius server key Global Configuration mode command sets the authentication and encryption key for all RADIUS communications between the Ethernet Switch Module and the RADIUS daemon To reset to the default use the no form of this command Syntax radius server key key string no radius server key key string Specifies the authentication and encryption key...

Page 219: ... retransmit retries no radius server retransmit retries Specifies the retransmit value Range 1 10 Default Configuration The default is 3 attempts Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example configures the number of times the software searches the list of RADIUS server hosts to 5 attempts radius server source ip ...

Page 220: ...vers to 10 1 1 1 radius server timeout The radius server timeout Global Configuration mode command sets the interval for which the Ethernet Switch Module waits for a server host to reply To restore the default use the no form of this command Syntax radius server timeout timeout no radius server timeout timeout Specifies the timeout value in seconds Range 1 30 Default Configuration The default valu...

Page 221: ...e deadtime Length of time in minutes for which a RADIUS server is skipped over by transaction requests Range 0 2000 Default Configuration The default dead time is 0 minutes Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example sets a dead time where a RADIUS server is skipped over by transaction requests for this period t...

Page 222: ...xamples The following example displays the RADIUS server settings console show radius servers IP address Auth TimeOut Retran DeadTime source IP Prio Usage 25 2 6 10 1812 5 Global Global 45 1 1 1 1 All 112 2 2 1 1812 Global 2 Global Global 0 All Global values TimeOut 3 Retransmit 3 Deadtime 0 Source IP 172 16 8 1 ...

Page 223: ...ation Command Mode User EXEC mode User Guidelines The following RMON Groups are supported Ethernet Statistics Group1 History Group 2 Alarms Group 3 and Events Group 4 Example The following example displays RMON Ethernet Statistics for port g11 console show rmon statistics ethernet g11 Port g11 Dropped 8 Octets 878128 Packets 978 Broadcast 7 Multicast 1 CRC Align Errors 0 Collisions 0 Undersize Pkt...

Page 224: ... of the total number of collisions on this Ethernet segment Undersize Pkts The total number of packets received less than 64 octets long excluding framing bits but including FCS octets and otherwise well formed Oversize Pkts The total number of packets received longer than 1518 octets excluding framing bits but including FCS octets and otherwise well formed Fragments The total number of packets re...

Page 225: ...specified defaults to 50 Range 1 65535 seconds The number of seconds in each polling cycle If unspecified defaults to 1800 Range 1 3600 Default Configuration This command has no default configuration Command Mode Interface Configuration Ethernet port channel mode User Guidelines This command cannot be executed on multiple ports using the interface range ethernet command 256 to 511 Octets The total...

Page 226: ... number interface Valid Ethernet port port channel number Valid port channel index Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays all RMON group statistics The following table describes the significant fields shown in the display console config interface...

Page 227: ...ion counters seconds Specifies the requested period time to display Range 1 4294967295 Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Index An index that uniquely identifies the entry Interface The sampled Ethernet interface Interval The interval in seconds between samples Requested Samples T...

Page 228: ...11 Interval 1800 Requested samples 50 Granted samples 50 Maximum table size 500 Time Octets Packets Broadcast Multicast Jan 18 2002 21 57 00 303595962 357568 3289 7287 19 98 Jan 18 2002 21 57 30 287696304 275686 2789 2789 20 17 console show rmon history 5 errors Sample Set 1 Owner CLI Interface g11 Interval 1800 Requested samples 50 Granted samples 50 Maximum table size 500 Time CRC Align Undersiz...

Page 229: ...received during this sampling interval that were directed to the broadcast address Multicast The number of good packets received during this sampling interval that were directed to a multicast address This number does not include packets addressed to the broadcast address Utilization The best estimate of the mean physical layer network utilization on this interface during this sampling interval in...

Page 230: ...se well formed Fragments The total number of packets received during this sampling interval that were less than 64 octets in length excluding framing bits but including FCS octets had either a bad Frame Check Sequence FCS with an integral number of octets FCS Error or a bad FCS with a non integral number of octets AlignmentError It is normal for etherHistoryFragments to increment because it counts...

Page 231: ... than or equal to the fthreshold and direction is equal to falling or rising falling then a single falling alarm is generated name Enter a name that specifies who configured this alarm If unspecified the name is an empty string Default Configuration The following parameters have the following default values type If unspecified the type is absolute direction If unspecified the startup direction is ...

Page 232: ...lds shown in the display show rmon alarm The show rmon alarm User EXEC mode command displays alarm configuration Syntax show rmon alarm number number Alarm index Range 1 65535 Default Configuration This command has no default configuration console show rmon alarm table Index OID Owner 1 1 3 6 1 2 1 2 2 1 10 1 CLI 2 1 3 6 1 2 1 2 2 1 10 1 Manager 3 1 3 6 1 2 1 2 2 1 10 9 CLI Field Description Index...

Page 233: ...arm rising Rising Threshold 8700000 Falling Threshold 78 Rising Event 1 Falling Event 1 Owner CLI Field Description Alarm Alarm index OID Monitored variable OID Last Sample Value The statistic value during the last sampling period For example if the sample type is delta this value is the difference between the samples at the beginning and end of the period If the sample type is absolute this value...

Page 234: ... the value of the variable is compared directly with the thresholds at the end of the sampling interval If the value is delta the value of the variable at the last sample is subtracted from the current value and the difference compared with the thresholds Startup Alarm The alarm that may be sent when this entry is first set If the first sample is greater than or equal to the rising threshold and s...

Page 235: ...ommand has no default configuration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays the RMON event table The following table describes the significant fields shown in the display console config rmon event 10 log console show rmon events Index Description Type Community Owner Last time sent 1 Errors Log CLI Jan 18 2002...

Page 236: ... Switch Module generates about this event Can have the following values none log trap log trap In the case of log an entry is made in the log table for each event In the case of trap an SNMP trap is sent to one or more management stations Community If an SNMP trap is to be sent it is sent to the SNMP community specified by this octet string Owner The entity that configured this event Last time sen...

Page 237: ...history table entries Range 20 32767 log entries Maximum number of log table entries Range 20 32767 Default Configuration History table size is 270 Log table size is 200 Command Mode Global Configuration mode User Guidelines The configured table size is effective after the Ethernet Switch Module is rebooted Example The following example configures the maximum RMON history table sizes to 1000 entri...

Page 238: ...218 RMON Commands ...

Page 239: ...reviously defined view The view defines the objects available to the community It s not relevant for su which has an access to the whole MIB If unspecified all the objects except of the community table and SNMPv3 user and access tables are available Range 1 30 chars ip address Management station IP address Default is all IP addresses An out of band IP address can be specified as described in the u...

Page 240: ... an SNMP perspective the OOB port is treated as a separate device Therefore when defining an SNMP community the administrator must indicate which tables are being configured If type is oob this indicates that OOB tables are being configured If type is router it means that the device s tables are being configured Examples The following example sets up the community access string public to permit ad...

Page 241: ...lly and can t be deleted or modified Example The following example creates a view that includes all objects in the MIB II system group except for sysServices System 7 and all objects for interface 1 in the MIB II interfaces group snmp server filter To create or update a filter entry use the snmp server filter global configuration command To remove the specified Simple Network Management Protocol S...

Page 242: ...uded in two or more lines Example The following example creates a filter that includes all objects in the MIB II system group except for sysServices System 7 and all objects for interface 1 in the MIB II interfaces group snmp server contact The snmp server contact Global Configuration mode command sets up a system contact To remove the system contact information use the no form of the command Synt...

Page 243: ...string up to 160 characters describing the system location Default Configuration This command has no default configuration Command Mode Global Configuration mode User Guidelines Do not include spaces in the text string Example The following example sets the Ethernet Switch Module location as New_York snmp server enable traps The snmp server enable traps Global Configuration mode command enables th...

Page 244: ...ailed traps use the no form of this command Syntax snmp server trap authentication no snmp server trap authentication Default Configuration This command has no default configuration Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Examples The following example displays the command to enable authentication failed SNMP traps snmp server host To sp...

Page 245: ...iltername A string that is the name of the filter that defines the filter for this host If unspecified does not filter anything Range Up to 30 characters timeout seconds Number of seconds to wait for an acknowledgment before resending informs The default is 15 seconds Range 1 300 retries retries Maximum number of times to resend an inform request when response is not received for generated message...

Page 246: ...n equivalent command In order to generate configuration files that support those situations the snmp server set command is used This command is context sensitive Examples The following example sets the scalar MIB sysName to have the value dell The following example sets the entry MIB rndCommunityTable with keys 0 0 0 0 and public The field rndCommunityAccess gets the value super and the rest of th...

Page 247: ...o SNMP Version 3 security model context name Specifies context of packet read readview A string that is the name of the view that enables you only to view the contents of the agent If unspecified all the objects except of the community table and SNMPv3 user and access tables are available Range Up to 30 characters write writeview A string that is the name of the view that enables you to enter data...

Page 248: ...byte in hexadecimal character strings is two hexadecimal digits Each byte can be separated by a period or colon Range 5 32 characters auth md5 The HMAC MD5 96 authentication level The user should enter password auth sha The HMAC SHA 96 authentication level The user should enter password password A password not to exceed 32 characters for authentication and generation of DES key for privacy Range U...

Page 249: ...neID should be defined in order to add users to the device Changing or removing the value of snmpEngineID deletes the SNMPv3 users database Example The following example configures a new SNMP Version 3 user snmp server v3 host The snmp server v3 host Global Configuration mode command specifies the recipient of Simple Network Management Protocol Version 3 notifications To remove the specified host ...

Page 250: ...r of times to resend an inform request If unspecified the default maximum number of retries is 3 Range 1 255 Default Setting This command has no default configuration Command Mode Global Configuration mode User Guidelines A user and notification view are not automatically created Use the snmp server user snmp server group and snmp server view Global Configuration mode commands to generate a user g...

Page 251: ...cal Engine ID If you want to specify your own ID you do not have to specify the entire 32 character engine ID if it contains trailing zeros Specify only the portion of the engine ID up to the point where just zeros remain in the value For example to configure an engine ID of 123400000000000000000000 you can specify snmp server engineID local 1234 Since the engine ID should be unique within an admi...

Page 252: ...ode command displays the ID of the local Simple Network Management Protocol SNMP engine Syntax show snmp engineID Default Setting This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays the SNMP engine ID show snmp The show snmp Privileged EXEC mode command displays the SNMP sta...

Page 253: ...the show snmp views Privileged EXEC command Syntax show snmp views viewname viewname The name of the view Range Up to 30 characters console sh snmp Traps are enabled Authentication trap is enabled Version 1 2 notifications Target Address Type Communit y Version UDP Port Filter name TO sec Retrie s Version 3 notifications Target Address Type Username Secu rity Level UDP Port Filter name TO sec Retr...

Page 254: ...ommand show snmp groups To display the configuration of groups use the show snmp groups Privileged EXEC command Syntax show snmp groups groupname groupnam The name of the group Default Configuration There is no default configuration for this command Command Modes Privileged EXEC User Guidelines There are no user guidelines for this command Console show snmp views Name OID Tree Type user view 1 3 6...

Page 255: ...EC command Syntax show snmp filters filtername filternam The name of the view Range Up to 30 character Console show snmp groups Name Security Views Model Level Context Read Write Notify user group V3 priv Default managers group V3 priv Default Default managers group V3 priv Default Console show snmp groups user group Name user group Security Model V3 Security Level priv Security Context Read View ...

Page 256: ...snmp users To display the configuration of groups use the show snmp users Privileged EXEC command Syntax show snmp users username username The name of the user Range Up to 30 character Default Configuration There is no default configuration for this command Command Modes Privileged EXEC User Guidelines There are no user guidelines for this command Console show snmp filters Name OID Tree Type user ...

Page 257: ...leged EXEC command Console show snmp users Name group name Auto Method Remote John 1 3 6 1 2 1 1 md5 John 1 3 6 1 2 1 1 7 md5 08009009020C0B09 9C075879 Console show snmp users John Name John Group name user group Auth Method md5 Remote Name John Group name user group Auth Method md5 Remote 08009009020C0B099C075879 ...

Page 258: ...238 SNMP Commands ...

Page 259: ...enabled Command Modes Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example enables spanning tree functionality spanning tree mode The spanning tree mode Global Configuration mode command configures the spanning tree protocol To return to the default configuration use the no form of this command Syntax spanning tree mode stp rstp mstp...

Page 260: ...h is the amount of time a port remains in the listening and learning states before entering the forwarding state To reset the default forward time use the no form of this command Syntax spanning tree forward time seconds no spanning tree forward time seconds Time in seconds Range 4 30 Default Configuration The default forwarding time for IEEE Spanning tree Protocol STP is 15 seconds Command Modes ...

Page 261: ...otocol STP is 2 seconds Command Modes Global Configuration mode User Guidelines When configuring the Hello Time the following relationship should be kept Max Age 2 Hello Time 1 Example The following example configures spanning tree bridge hello time to 5 seconds spanning tree max age The spanning tree max age Global Configuration mode command configures the spanning tree bridge maximum age To rese...

Page 262: ... of this command Syntax spanning tree priority priority no spanning tree priority priority Priority of the bridge Range 0 61440 in steps of 4096 Default Configuration The default bridge priority for IEEE STP is 32768 Command Modes Global Configuration mode User Guidelines The priority value must be a multiple of 4096 or 0 The bridge with the lowest priority is elected to be the Root Bridge Example...

Page 263: ...st Interface Configuration Ethernet port channel mode command configures the spanning tree path cost for a port To reset the default port path cost use the no form of this command Syntax spanning tree cost cost no spanning tree cost cost The port path cost Range 1 200000000 Default Configuration For the default short pathcost method the cost values are port channel 4 1000 mbps 4 100 mbps 19 10 mbp...

Page 264: ...nterface Configuration Ethernet port channel mode User Guidelines The port priority value must be a multiple of 16 or 0 Example The following example configures the spanning priority on port g15 to 96 spanning tree portfast The spanning tree portfast Interface Configuration Ethernet port channel mode command enables PortFast mode In PortFast mode the interface is immediately put into the forwardin...

Page 265: ...rnet port channel mode command overrides the default link type setting To reset the default use the no form of this command Syntax spanning tree link type point to point shared no spanning tree spanning tree link type point to point Specifies the port link type as point to point shared Specifies that the port link type is shared Default Configuration There is no default configuration for this comm...

Page 266: ...efault Configuration Short pathcost method Command Mode Global configuration mode User Guidelines The cost is set using the spanning tree cost command Example The following example sets the default path cost method to long spanning tree bpdu The spanning tree bpdu Global Configuration mode command defines BPDU handling when spanning tree is disabled on an interface Syntax spanning tree bpdu filter...

Page 267: ... neighboring Ethernet Switch Modulees on all interfaces or on the specified interface Syntax clear spanning tree detected protocols ethernet interface port channel port channel number interface A valid Ethernet port port channel number A valid port channel index Default Configuration If no interface is specified the action is applied to all interfaces Command Modes Privileged EXEC mode User Guidel...

Page 268: ...ber Rang Valid Ethernet port port channel number Port channel index Rang Valid Ethernet port instance id ID associated with a spanning tree instance 0 Product Specific Default Configuration Disabled Command Modes Privileged EXEC User Guidelines This command can be enabled when all the ports are Access ports This command is relevant in MSTP mode only When this feature is enabled incoming IEEE RSTP ...

Page 269: ... Console show spanning tree Spanning tree enabled mode RSTP Default port cost method long Root ID Priority 32768 Address 00 01 42 97 e0 00 Path Cost 2000 Root Port 1 g1 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 36864 Address 00 02 4b 29 7a 00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Interfaces Name State Prio Nbr Cost Sts Role PortFast Type g1 Enabled 128 ...

Page 270: ...tree enabled mode RSTP Default port cost method long Root ID Priority 36864 Address 00 02 4b 29 7a 00 This switch is the Root Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Name State Prio Nbr Cost Sts Role PortFast Type g1 Enabled 128 1 20000 FWD Desg No Shared STP g2 Enabled 128 2 20000 Desg No g3 Disabled 128 3 20000 BLK No Shared STP g4 Enabled 128 4 20000 DIS Altn No g5 Enabled 128 5 20...

Page 271: ...ddress N A Path Cost N A Root Port N A Hello Time N A Max Age N A Forward Delay N A Bridge ID Priority 36864 Address 00 02 4b 29 7a 00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Name State Prio Nbr Cost Sts Role PortFast Type g1 Enabled 128 1 20000 g2 Disabled 128 2 20000 g3 Enabled 128 3 20000 g4 Enabled 128 4 20000 g5 Enabled 128 5 20000 DIS ...

Page 272: ...Root Port 1 g1 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 36864 Address 00 02 4b 29 7a 00 This switch is the Root Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Interfaces Name State Prio Nbr Cost Sts Role PortFast Type g1 Enabled 128 1 20000 FWD Root No P2P RSTP g2 Enabled 128 2 20000 FWD Desg No Shared STP g4 Enabled 128 4 20000 BLK Altn No Shared STP ...

Page 273: ...ID Priority 32768 Address 00 01 42 97 e0 00 Path Cost 20000 Root Port 1 g1 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 36864 Address 00 02 4b 29 7a 00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Interfaces Name State Prio Nbr Cost Sts Role PortFast Type g4 Enabled 128 4 20000 BLK Altn No Shared STP ...

Page 274: ...s 2 last change occurred 2d18h ago Times hold 1 topology change 35 notification 2 hello 2 max age 20 forward delay 15 Desinated port id N A Designated path cost N A Number of transitions to forwarding state N A BPDU sent N A received N A Console show spanning tree ethernet g1 Port 1 g1 enabled State Forwarding Port id 128 1 Type p2p configured auto RSTP Designated bridge Priority 32768 Designated ...

Page 275: ...EE Spanning Tree Protocol STP is 32768 Command Mode Global Configuration mode User Guidelines The device with the lowest priority is selected as the root of the spanning tree Example The following example configures the spanning tree priority of instance 1 to 4096 spanning tree mst max hops The spanning tree mst priority Global Configuration mode command configures the number of hops in an MST reg...

Page 276: ...form of this command Syntax spanning tree mst instance id port priority priority no spanning tree mst instance id port priority instance ID ID of the spanning tree instance Range 1 16 priority The port priority Range 0 240 in multiples of 16 Default Setting The default port priority for IEEE Multiple Spanning Tree Protocol MSTP is 128 Command Modes Interface Configuration Ethernet port channel mod...

Page 277: ...ault Setting Default path cost is determined by port speed and path cost method long or short as shown below Command Modes Interface Configuration Ethernet port channel mode Default Configuration There is no default configuration for this command Example The following example configures the MSTP instance 1 path cost for Ethernet port 1 e9 to 4 spanning tree mst configuration The spanning tree mst ...

Page 278: ...ID ID of the MST instance Range 1 16 vlan range VLANs to be added to or removed from the specified MST instance To specify a range of VLANs use a hyphen To specify a series of VLANs use a comma Range 1 4094 Default Setting VLANs are mapped to the common and internal spanning tree CIST instance instance 0 Command Modes MST Configuration mode User Guidelines All VLANs that are not explicitly mapped ...

Page 279: ... 1 32 characters Default Setting The default name is a bridge ID Command Mode MST Configuration mode User Guidelines There are no user guidelines for this command Example The following example defines the configuration name as region1 revision mst The revision MST configuration command defines the configuration revision number To return to the default configuration use the no form of this command ...

Page 280: ...guration Syntax show current pending current Indicates the current region configuration pending Indicates the pending region configuration Default Setting This command has no default configuration Command Mode MST Configuration mode User Guidelines The pending MST region configuration takes effect only after exiting the MST configuration mode Example The following example displays a pending MST re...

Page 281: ...re no user guidelines for this command Example The following example exits the MST configuration mode and saves changes abort mst The abort MST Configuration mode command exits the MST configuration mode without applying the configuration changes Syntax abort Default Setting This command has no default configuration Name Region1 Revision 1 Instance Vlans Mapped State 0 1 9 21 4094 Enabled 1 10 20 ...

Page 282: ...g tree mst mstp rstp This command has no arguments or keywords Default Configuration Disabled Command Modes Global configuration User Guidelines This command can be enabled when all the ports are Access ports This command is relevant in MSTP mode only When this feature is enabled incoming IEEE RSTP STP packets would be mapped to the MSTP instance according to the port s VLAN Outgoing MSTP packets ...

Page 283: ...Syntax spanning tree guard root no spanning tree guard root Default Configuration Root guard is disabled Command Modes Interface configuration Ethernet port channel User Guidelines Root guard can be enabled when the switch work in STP RSTP and MSTP When root guard is enabled if spanning tree calculations cause a port to be selected as the root port the port transitions to the alternate state Examp...

Page 284: ...264 Spanning Tree Commands ...

Page 285: ...server is in standby until the keys are generated To generate SSH server keys use the commands crypto key generate rsa and crypto key generate dsa Example The following example enables the Ethernet Switch Module to be configured from a SSH server ip ssh port The ip ssh port Global Configuration mode command specifies the port to be used by the SSH server To use the default port use the no form of ...

Page 286: ...s one public DSA key and one private DSA key If the Ethernet Switch Module already has DSA keys a warning and prompt to replace the existing keys with new keys is displayed This command is not saved in the startup configuration however the keys generated by this command are saved in the FLASH The SSH keys can be displayed with the show crypto key mypubkey dsa command This command may take up to 10...

Page 287: ...wever the keys generated by this command are saved in the FLASH The SSH keys can be displayed with the show crypto key mypubkey rsa command This command may take up to 5 minutes to execute Example The following example generates RSA key pairs ip ssh pubkey auth The ip ssh pubkey auth Global Configuration mode command enables public key authentication for incoming SSH sessions To disable this funct...

Page 288: ... to enter public key chain configuration mode This command can also be used when you need to manually specify SSH client s public keys Example The following example enters the SSH Public Key chain configuration mode user key The user key SSH Public Key Chain Configuration mode command specifies which SSH public key is manually configured and enters the SSH public key string configuration command T...

Page 289: ...e command manually specifies a SSH public key Syntax key string row row Specify SSH public key row by row Default Configuration By default the keys do not exist Command Mode SSH Public Key string configuration User Guidelines Use the key string row command to specify the SSH public key row by row Each row must begin with the key string row command This command is useful for configuration files UU ...

Page 290: ...his command console config crypto key pubkey chain ssh console config pubkey chain user key bob rsa console config pubkey key key string AAAAB3NzaC1yc2EAAAADAQABAAABAQCvTnRwPWl Al4kpqIw9GBRonZQZxjHKcqKL6rMlQ ZNXfZSkvHG QusIZ 76ILmFT34v7u7ChFAE Vu4GRfpSwoQUvV35LqJJk67IOU zfwOl1g kTwml75QR9gHujS6KwGN2QWXgh3ub8gDjTSq muSn Wd05iDX2IExQWu08licglk02LYciz Z4TrEU 9FJxwPiVQOjc KBXuR0juNg5nFYsY 0ZCk0N W9a t...

Page 291: ... key dsa DSA key Default Configuration This command has no default configuration Command Mode Privileged EXEC mode console show ip ssh SSH server enabled Port 22 RSA key was generated DSA DSS key was generated SSH Public Key Authentication is enabled Active incoming sessions IP address SSH username Version Cipher Auth Code 172 16 0 1 John Brown 2 0 3 DES HMAC SHA1 Field Description IP address Clie...

Page 292: ...rmat If fingerprint is unspecified it defaults to Hex format Default Configuration This command has no default configuration Command Mode Privileged EXEC mode console show crypto key mypubkey rsa rsa key data ssh rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA17aQFtz jPEO0bVnoLeaTXZR U9eOKONq2g6GIrCXfNPRGWSectPlOsSrDtKaFybYPHO 9BUjSqe3Unzw zg8 FIR1Rej9PK4VtrAvsRi Y4Cktqoke1aLqOQMgjhC l NE63Zii2rTki8Kw63 QumeeJiF...

Page 293: ...ed on the Ethernet Switch Module The following example displays the SSH public called bob console show crypto key pubkey chain ssh Username Fingerprint bob 9A CC 01 C5 78 39 27 86 79 CC 23 C5 98 59 F1 86 john 98 F7 6E 28 F2 79 87 C8 18 F8 88 CC F8 89 87 C8 console show crypto key pubkey chain ssh username bob Username bob Key 005C300D 06092A86 ...

Page 294: ...274 SSH Commands ...

Page 295: ...g buffer logging file or syslog server Logging on and off for these destinations can be individually configured using the logging buffered logging file and logging Global Configuration mode commands However if the logging on command is disabled no messages are sent to these destinations Only the console receives messages Example The following example shows how logging is enabled logging The loggin...

Page 296: ...iguration As described in the field descriptions Command Mode Global Configuration mode User Guidelines Multiple syslog servers can be used If no specific severity level is specified the global values apply to each server Example The following example configures messages with a critical severity level so that they are logged to a syslog server with an IP address 10 1 1 1 logging console The loggin...

Page 297: ...ritical errors warnings notifications informational debugging Default Configuration The default level is informational Command Mode Global Configuration mode User Guidelines All the syslog messages are logged to the internal buffer This command limits the commands displayed to the user Example The following example limits syslog messages displayed from an internal buffer based on the severity leve...

Page 298: ...ssages is 200 Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example changes the number of syslog messages stored in the internal buffer to 300 clear logging The clear logging Privileged EXEC mode command clears messages from the internal logging buffer Syntax clear logging Default Configuration This command has no default...

Page 299: ...erts critical errors warnings notifications informational and debugging Default Configuration The default severity level is errors Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example limits syslog messages sent to the logging file based on the severity level alerts clear logging file The clear logging file Privileged EX...

Page 300: ... file show logging The show logging Privileged EXEC mode command displays the state of logging and the syslog messages stored in the internal buffer Syntax show logging Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command console clear logging file Clear Logging File y n y ...

Page 301: ...EC mode console show logging Logging is enabled Console Logging Level debug Console Messages 5 Dropped Buffer Logging Level debug Buffer Messages 16 Logged 16 Displayed 200 Max File Logging Level error File Messages 0 Logged 209 Dropped SysLog server 31 1 1 2 Logging error Messages 22 Dropped SysLog server 5 2 2 2 Logging info Messages 0 Dropped SysLog server 10 2 2 2 Logging critical Messages 21 ...

Page 302: ...nsole show logging file Logging is enabled Console Logging Level debug Console Messages 5 Dropped Buffer Logging Level debug Buffer Messages 21 Logged 21 Displayed 200 Max File Logging Level debug File Messages 4 Logged 210 Dropped SysLog server 31 1 1 2 Logging error Messages 27 Dropped SysLog server 5 2 2 2 Logging info Messages 0 Dropped SysLog server 10 2 2 2 Logging critical Messages 26 Dropp...

Page 303: ...no user guidelines for this command Example The following example displays the syslog server settings console show syslog servers IP address Port Severity Facility Description 192 180 2 275 14 Informational local 7 192 180 2 285 14 Warning local 7 ...

Page 304: ...284 Syslog Commands ...

Page 305: ...header information Range 56 1472 bytes packet_count Number of packets to send If 0 is entered it pings until stopped Range 0 65535 packets time_out Timeout in milliseconds to wait for each reply Range 50 65535 milliseconds Default Configuration Default timeout value is 2000 msec Command Mode User EXEC mode User Guidelines Press Esc to stop pinging Destination host network unreachable The gateway f...

Page 306: ...or when this value is reached Range 1 255 packet_count The number of probes to be sent at each TTL level Range 1 10 time_out The number of seconds to wait for a response to a probe packet Range 1 60 ip address One of the interface addresses of the Ethernet Switch Module to use as a source address for the probes The Ethernet Switch Module will normally pick what it feels is the best source address ...

Page 307: ...rror message The traceroute command sends several probes at each TTL level and displays the round trip time for each The traceroute command sends out one probe at a time Each outgoing packet may result in one or two error messages A time exceeded error message indicates that an intermediate node has seen and discarded the probe A destination unreachable error message indicates that the destination...

Page 308: ...t 198 32 249 162 1 msec 1 msec 1 msec 5 kscyng snvang abilene ucaid edu 198 32 8 103 33 msec 35 msec 35 msec 6 iplsng kscyng abilene ucaid edu 198 32 8 80 47 msec 45 msec 45 msec 7 so 0 2 0x1 aa1 mich net 192 122 183 9 56 msec 53 msec 54 msec 8 atm1 0x24 michnet8 mich net 198 108 23 82 56 msec 56 msec 57 msec 9 10 A ARB3 LSA NG c SEB umnet umich edu 141 211 5 22 58 msec 58 msec 58 msec 11 umaxp1 p...

Page 309: ...the host keyword Can be one or more keywords from the keywords table in the User Guidelines Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines The Telnet software supports special Telnet commands in the form of Telnet sequences that map generic terminal control functions to operating system specific functions To issue a special Telnet comman...

Page 310: ...cape sequence Ctrl Shift 6 and x to return to the system command prompt Then open a new connection with the telnet command Escape Sequence Purpose Ctrl shift 6 b Break Ctrl shift 6 c Interrupt Process IP Ctrl shift 6 h Erase Character EC Ctrl shift 6 o Abort Output AO Ctrl shift 6 t Are You There AYT Ctrl shift 6 u Erase Line EL Ctrl shift 6 x Suspends the Session console Ctrl shift 6 Special teln...

Page 311: ...X Copy Program UUCP and other non Telnet protocols Ctrl shift 6 x Return to System Command Prompt Keyword Description Port Number bgp Border Gateway Protocol 179 chargen Character generator 19 cmd Remote commands 514 daytime Daytime 13 discard Discard 9 domain Domain Name Service 53 echo Echo 7 exec Exec 512 finger Finger 79 ftp File Transfer Protocol 21 ftp data FTP data connections 20 gopher Gop...

Page 312: ...s no default configuration for this command Command Mode User EXEC mode User Guidelines There are no user guidelines for this command pim auto rp PIM Auto RP 496 pop2 Post Office Protocol v2 109 pop3 Post Office Protocol v3 110 smtp Simple Mail Transport Protocol 25 sunrpc Sun Remote Procedure Call 111 syslog Syslog 514 tacacs TAC Access Control System 49 talk Talk 517 telnet Telnet 23 time Time 3...

Page 313: ...cular the user should verify that no configuration files are being downloaded at the time of reset Example The following example reloads the operating system hostname The hostname Global Configuration mode command specifies or modifies the Ethernet Switch Module host name To remove the existing host name use the no form of the command Syntax hostname name no hostname name The Ethernet Switch Modul...

Page 314: ...tive users Syntax show users Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Example The following example displays information about the active users show sessions The show sessions User EXEC mode command lists the open Telnet sessions console config hostname Dell Dell config console show use...

Page 315: ...r of sessions opened from PowerConnect 5316M is displayed d Enter the command resume number of session to return to the relevant telnet session Examples The following table describes the significant fields shown in the display console show sessions Connection Host Address Port Byte 1 Remote device 172 16 1 1 23 89 2 172 16 1 2 172 16 1 2 23 8 Field Description Connection Connection number Host Rem...

Page 316: ...ng example displays the system information show version The show version User EXEC mode command displays the system version information Syntax show version Default Configuration This command has no default configuration Command Mode User EXEC mode console show system System Description System Up Time days hour min sec System Contact System Name System location System MAC Address Sys Object ID Type...

Page 317: ...tag no asset tag tag The Ethernet Switch Module asset tag Range 1 16 characters Default Configuration No asset tag is defined by default Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example specifies the Ethernet Switch Module asset tag as 1qwepot show system id The show system id User EXEC mode command displays the ID i...

Page 318: ...iguration Command Mode User EXEC mode User Guidelines The tag information is on a Ethernet Switch Module by Ethernet Switch Module basis Example The following example displays the system service tag information console show system id Service Tag 89788978 Serial number 8936589782 Asset tag 7843678957 ...

Page 319: ... the daemon port number Specify a server port number If unspecified the port number defaults to 49 Range 0 65535 timeout Specifies the timeout value in seconds If no timeout value is specified the global value is used Range 1 30 key string Specifies the authentication and encryption key for all TACACS communications between the Ethernet Switch Module and the TACACS server This key must match the e...

Page 320: ...the authentication and encryption key for all TACACS communications between the Ethernet Switch Module and the TACACS server This key must match the encryption used on the TACACS daemon Range 0 128 characters Default Configuration Key string is empty string Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Examples The following example sets the a...

Page 321: ...e source IP address that will be used for the communication with TACACS servers To return to default use the no form of this command Syntax tacacs server source ip source no tacacs server source ip source source Specifies the source IP address Range Valid IP Address Default Configuration The IP address would be of the outgoing IP interface Command Mode Global Configuration mode User Guidelines The...

Page 322: ... Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command Examples The following example displays configuration and statistic for a TACACS server console show tacacs IP address Status Port Single Connection TimeOut Source IP Priority 172 16 1 1 Connected 49 No Global Global 1 Global values TimeOut 3 Sour...

Page 323: ...Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Example The following example shows how to enter Privileged EXEC mode disable The disable Privileged EXEC mode command returns to User EXEC mode Syntax disable privilege level privilege level Privilege level to enter the system Range 1 15 Default Configuration The default privilege level is 1 Command Mode Pri...

Page 324: ...nd password Syntax login Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines There are no user guidelines for this command Example The following example shows how to enter Privileged EXEC mode with username admin configure The configure Privileged EXEC mode command enters the Global Configuration mode Syntax configure console disable console ...

Page 325: ...The exit command exits any configuration mode to the next highest mode in the CLI mode hierarchy Syntax exit Default Configuration This command has no default configuration Command Mode All command modes User Guidelines There are no user guidelines for this command Example The following example changes the configuration mode from Interface Configuration mode to User EXEC mode console configure con...

Page 326: ...C mode User Guidelines There are no user guidelines for this command Example The following example closes an active terminal session end The end Configuration mode command ends the current configuration session and returns to the Privileged EXEC mode Syntax end Default Configuration This command has no default configuration Command Mode Any configuration mode User Guidelines There are no user guid...

Page 327: ...ration Command Mode All command modes User Guidelines There are no user guidelines for this command history The history Line Configuration mode command enables the command history function To disable the command history feature use the no form of this command Syntax history no history Default Configuration The history function is enabled Command Mode Line Configuration mode User Guidelines There a...

Page 328: ... of commands that the system records in its history buffer Range 10 216 Default Configuration The default history buffer size is 10 Command Mode Line Configuration mode User Guidelines The maximum number of commands in all terminal sessions is 256 The maximum number of commands in a single terminal session is 216 If this maximum is specified in one session the other sessions operate with the minim...

Page 329: ...e show history User EXEC mode command lists the commands entered in the current session Syntax show history Default Configuration This command has no default configuration Command Mode User EXEC mode User Guidelines The commands are listed from the first to the latest command The buffer is kept unchanged when entering to configuration mode and returning back Commands that were not executed are not...

Page 330: ...re no user guidelines for this command Example The following example displays the current privilege level terminal history The terminal history User EXEC mode command enables the command history function for the current terminal session To disable the command history function use the no form of this command Syntax terminal history no terminal history Default Configuration The default is determined...

Page 331: ...ommands no terminal history size number of commands Number of commands that the system records in its history buffer Range 10 216 Default Configuration The default value is specified by history size settings for particular line Command Mode User EXEC mode User Guidelines The maximum number of commands in all terminal sessions is 256 The maximum number of commands in a single terminal session is 21...

Page 332: ...312 User Interface ...

Page 333: ...nes There are no user guidelines for this command Example The following example enters the VLAN database mode vlan Use the vlan VLAN Configuration mode command to create a VLAN To delete a VLAN use the no form of this command Syntax vlan vlan range no vlan vlan range vlan range A list of valid VLAN IDs to be added List separate non consecutive VLAN IDs separated by commas without spaces use a hyph...

Page 334: ...VLAN excluding GVRP dynamic VLANs Default Configuration This command has no default configuration Command Mode Global Configuration mode User Guidelines There are no user guidelines for this command Example The following example enters VLAN 1 interface mode interface range vlan The interface range vlan Global Configuration mode command enters the Interface Configuration mode to configure multiple ...

Page 335: ...ror on one of the interfaces an error message is displayed and execution continues on other interfaces Example The following example groups VLAN 221 until 228 and VLAN 889 to receive the same command name The name Interface Configuration mode command adds a name to a VLAN To remove the VLAN name use the no form of this command Syntax name string no name string Unique name up to 32 characters in le...

Page 336: ...etwork access Untagged layer 2 VLAN interface trunk Trunking layer 2 VLAN interface general Full 802 1q support VLAN interface Default Configuration All ports are in access mode and belong to the default VLAN whose VID 1 Command Modes Interface configuration Ethernet port channel User Guidelines There are no user guidelines for this command Example The following example configures the VLAN members...

Page 337: ...nd automatically removes the port from the previous VLAN and adds it to the new VLAN Example The following example configures a VLAN ID of 23 to the untagged layer 2 VLAN interface number g16 switchport customer vlan Use the switchport customer vlan interface configuration command to set the port s VLAN when the interface is in customer mode Use the no form of this command to revert to default Syn...

Page 338: ... a range of IDs The option all adds all configured VLAN IDs remove vlan list List of VLAN IDs to remove Separate non consecutive VLAN IDs with a comma and no spaces A hyphen designate a range of IDs The option all removes all configured VLAN IDs Default Configuration This command has no default configuration Command Mode Interface Configuration Ethernet port channel mode User Guidelines There are ...

Page 339: ...ffic in this VLAN on this port is sent untagged despite the normal situation where traffic sent from a trunk mode port is all tagged The command adds the port as a member in the VLAN If the port is already a member in the VLAN not as a native it should be first removed from the VLAN Example The following example g16 in trunk mode is configured to use VLAN number 123 as the native VLAN switchport g...

Page 340: ...mple from tagged to untagged without first removing the VLAN from the list Example The following example shows how to add VLANs 2 5 and 6 to the allowed list switchport general pvid The switchport general pvid Interface Configuration mode command configures the PVID when the interface is in general mode To configure the default value use the no form of this command Syntax switchport general pvid v...

Page 341: ...ring disable no switchport general ingress filtering disable Default Configuration Ingress filtering is enabled Command Mode Interface Configuration Ethernet port channel mode User Guidelines There are no user guidelines for this command Example The following example shows how to disable port ingress filtering on g16 switchport general acceptable frame type tagged only The switchport general accep...

Page 342: ...Ns to a port This may be used to prevent GVRP from automatically making these VLANs active on the selected ports To revert to allowing the addition of specific VLANs to the port use the remove parameter for this command Syntax switchport forbidden vlan add vlan list remove vlan list vlan list List of VLAN IDs to perform the selected action add or remove Separate non consecutive VLAN IDs with a com...

Page 343: ...or one of the following names ip arp or ipx The protocol number is in Hex format Range 0600 FFFF encapsulation One of the following values ethernet rfc1042 llcOther If no option is indicated the default is ethernet group Protocol group number Range 1 2147483647 Default Configuration This command has no default configuration Command Mode VLAN Configuration mode User Guidelines The following protoco...

Page 344: ...figuration This command has no default configuration Command Mode Interface Configuration Ethernet port channel mode User Guidelines There are no user guidelines for this command Example The following example sets a protocol based classification rule of protocol group 1 to VLAN 8 show vlan The show vlan Privileged EXEC mode command displays VLAN information Syntax show vlan tag vlan id name vlan n...

Page 345: ...red VLAN permanent Suser configured VLAN dynamicGvrp GVRP configured VLAN show vlan protocols groups The show vlan protocols groups Privileged EXEC mode command displays protocols groups information Syntax show vlan protocols groups Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command console...

Page 346: ...rt channel port channel number Interface Specific interface such as ethernet g16 port channel number Valid port channel index Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command console show vlan protocols groups Encapsulation Protocol Group Id ethernet 08 00 213 ethernet 08 06 213 ethernet ...

Page 347: ...hernet g11 Port g11 Port mode General GVRP Status disabled Ingress Filtering true Acceptable Frame Type admitAll Ingress Untagged VLAN NATIVE 1 Port is member in Vlan Name Egress rule Type 1 default untagged System 8 VLAN008 tagged Dynamic 11 VLAN011 tagged Static Forbidden VLANS VLAN Name 73 Out Classification rules Group ID VLAN 219 372 ...

Page 348: ...328 VLAN Commands ...

Page 349: ...level 15 can use the web server Example The following example enables the Ethernet Switch Module to be configured from a browser ip http port The ip http port Global Configuration mode command specifies which TCP port the server uses to configure the Ethernet Switch Module through the web browser To use the default TCP port use the no form of this command Syntax ip http port port number no ip http...

Page 350: ...ult Configuration The default for the Ethernet Switch Module is disabled Command Mode Global Configuration mode User Guidelines You must use the crypto certificate generate command to generate the HTTPS certificate Example The following example enables the Ethernet Switch Module to be configured from a browser ip https port The ip https port Global Configuration mode command specifies which TCP po...

Page 351: ...1 Range 1 2 key generate Regenerate SSL RSA key length Specifies the SSL RSA key length If unspecified length defaults to 1024 Range 512 2048 common name Specifies the fully qualified URL or IP address of the Ethernet Switch Module If unspecified defaults to the lowest IP address of the Ethernet Switch Module where the certificate is generated Range 1 64 organization Specifies the organization nam...

Page 352: ...t loc location st state cu country number Specifies the certificate number Range 1 2 common name Specifies the fully qualified URL or IP address of the Ethernet Switch Module Range 1 64 organization Specifies the organization name Range 1 64 organization unit Specifies the organization unit or department name Range 1 64 location Specifies the location or city name Range 1 64 state Specifies the st...

Page 353: ...rts a certificate signed by Certification Authority for HTTPS Syntax crypto certificate number import number Specifies the certificate number Range 1 2 console crypto certificate 1 request BEGIN CERTIFICATE REQUEST MIwTCCASoCAQAwYjELMAkGA1UEBhMCUFAxCzAJBgNVBAgTAkNDMQswCQYDVQQH EwRDEMMAoGA1UEChMDZGxkMQwwCgYDVQQLEwNkbGQxCzAJBgNVBAMTAmxkMRAw DgKoZIhvcNAQkBFgFsMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8e...

Page 354: ... the session enter a new line enter period and add another new line The imported certificate must be based on a certificate request created by the crypto certificate request Privileged EXEC mode command If the public key found in the certificate does not match the Ethernet Switch Module s SSL RSA key the command will fail This command is not saved in the Ethernet Switch Module configuration howeve...

Page 355: ...tion mode console config crypto certificate 1 import BEGIN CERTIFICATE dHmUgUm9vdCBDZXJ0aWZpZXIwXDANBgkqhkiG9w0BAQEFAANLADBIAkEAp4HS nnH xQSGA2ffkRBwU2XIxb7n8VPsTm1xyJ1t11a1GaqchfMqqe0kmfhcoHSWr yf1FpD0MWOTgDAwIDAQABo4IBojCCAZ4wEwYJKwYBBAGCNxQCBAYeBABDAEEw CwR0PBAQDAgFGMA8GA1UdEwEB wQFMAMBAf8wHQYDVR0OBBYEFAf4MT9BRD47 ZvKBAEL9Ggp 6MIIBNgYDVR0fBIIBLTCCASkwgdKggc ggcyGgclsZGFwOi8v L0VByb3h5JTIwU29mdH...

Page 356: ...he show crypto certificate mycertificate Privileged EXEC mode command allows you to view the SSH certificates of your Ethernet Switch Module Syntax show crypto certificate mycertificate number number Specifies the certificate number Range 1 2 Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this comma...

Page 357: ...te mycertificate 1 BEGIN CERTIFICATE dHmUgUm9vdCBDZXJ0aWZpZXIwXDANBgkqhkiG9w0BAQEFAANLADBIAkEAp4HS nnH xQSGA2ffkRBwU2XIxb7n8VPsTm1xyJ1t11a1GaqchfMqqe0kmfhcoHSWr yf1FpD0MWOTgDAwIDAQABo4IBojCCAZ4wEwYJKwYBBAGCNxQCBAYeBABDAEEw CwR0PBAQDAgFGMA8GA1UdEwEB wQFMAMBAf8wHQYDVR0OBBYEFAf4MT9BRD47 ZvKBAEL9Ggp 6MIIBNgYDVR0fBIIBLTCCASkwgdKggc ggcyGgclsZGFwOi8v L0VByb3h5JTIwU29mdHdhcmUlMjBSb290JTIwQ2VydGlmaWVyLENO...

Page 358: ... ip http Privileged EXEC mode command displays the HTTPS server configuration Syntax show ip https Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command console show ip http HTTP server enabled Port 80 ...

Page 359: ...ate 1 is active Issued by www verisign com Valid from 8 9 2003 to 8 9 2004 Subject CN router gm com 0 General Motors C US Finger print DC789788 DC88A988 127897BC BB789788 Certificate 2 is inactive Issued by self signed Valid from 8 9 2003 to 8 9 2004 Subject CN router gm com 0 General Motors C US Finger print 1873B936 88DC3411 BC8932EF 782134BA ...

Page 360: ...340 Web Server ...

Page 361: ...failed to authenticate If the 802 1x calls the AAA for authentication services it will receive a fail status Command Mode Global Configuration mode User Guidelines The additional methods of authentication are used only if the previous method returns an error for example the authentication server is down and not if the request for authenticate is denied access To ensure that the authentication succ...

Page 362: ...yntax dot1x port control auto force authorized force unauthorized no dot1x port control auto Enable 802 1X authentication on the interface and cause the port to transition to the authorized or unauthorized state based on the 802 1X authentication exchange between the port and the client force authorized Disable 802 1X authentication on the interface and cause the port to transition to the authoriz...

Page 363: ...e authentication The dot1x re authentication Interface Configuration mode command enables periodic re authentication of the client Use the no form of this command to return to the default setting Syntax dot1x re authentication no dot1x re authentication Default Configuration Periodic re authentication is disabled Command Mode Interface Configuration Ethernet User Guidelines It is recommended to us...

Page 364: ... Configuration Re authentication period is 3600 seconds Command Mode Interface Configuration Ethernet mode User Guidelines There are no user guidelines for this command Examples The following example sets the number of seconds between re authentication attempts to 300 dot1x re authenticate The dot1x re authenticate Privileged EXEC mode command manually initiates a re authentication of all 802 1X e...

Page 365: ...e default setting Syntax dot1x timeout quiet period seconds no dot1x timeout quiet period seconds Time in seconds that the Ethernet Switch Module remains in the quiet state following a failed authentication exchange with the client Range 0 65535 seconds Default Configuration Period is 60 seconds Command Mode Interface Configuration Ethernet mode User Guidelines During the quiet period the Ethernet...

Page 366: ... seconds Time in seconds that the Ethernet Switch Module should wait for a response to an EAP request identity frame from the client before resending the request Range 1 65535 seconds Default Configuration Period set to 30 seconds Command Mode Interface Configuration Ethernet mode User Guidelines You should change the default value of this command only to adjust for unusual circumstances such as u...

Page 367: ...u should change the default value of this command only to adjust for unusual circumstances such as unreliable links or specific behavioral problems with certain clients Examples The following example sets the number of times that the Ethernet Switch Module sends an EAP request identity frame to 6 dot1x timeout supp timeout The dot1x timeout supp timeout Interface Configuration mode command sets th...

Page 368: ...nfiguration mode command sets the time that the Ethernet Switch Module waits for a response from the authentication server Use the no form of this command to return to the default setting Syntax dot1x timeout server timeout seconds no dot1x timeout server timeout seconds Time in seconds that the Ethernet Switch Module waits for a response from the authentication server Range 1 65535 seconds Defaul...

Page 369: ... EXEC mode command displays 802 1X status for the Ethernet Switch Module or for the specified interface Syntax show dot1x ethernet interface interface Ethernet port name Default Configuration This command has no default configuration Command Mode Privileged EXEC mode User Guidelines There are no user guidelines for this command console config if dot1x timeout server timeout 3600 ...

Page 370: ...uth Period Username g11 Auto Unauthorized Ena 3600 Clark Quiet period 60 Seconds Tx period 30 Seconds Max req 2 Supplicant timeout 30 Seconds Server timeout 30 Seconds Session Time HH MM SS 00 02 43 MAC Address 00 08 78 32 98 78 Authentication Method Remote Termination Cause Supplicant logoff Authenticator State Machine State HELD Backend State Machine State IDLE Authentication success 9 Authentic...

Page 371: ...le Authentication Protocol EAP request identity frame from the client before resending the request Max req The maximum number of times that the Ethernet Switch Module sends an Extensible Authentication Protocol EAP request frame assuming that no response is received to the client before restarting the authentication process Supplicant timeout Time in seconds the switch waits for a response to an E...

Page 372: ... statistics Privileged EXEC mode command displays 802 1X statistics for the specified interface Syntax show dot1x statistics ethernet interface console show dot1x users Port Username Session Time Auth MAC Method Address g11 Bob 00 02 23 Remote 00 80 c8 b9 dc 1d g13 John 00 02 14 Remote 00 80 c8 b9 dc 20 g14 Clark 00 00 36 Remote 00 03 47 05 7f b8 Field Description Port The interface number Usernam...

Page 373: ...n in the display console show dot1x statistics ethernet g11 EapolFramesRx 11 EapolFramesTx 12 EapolStartFramesRx 1 EapolLogoffFramesRx 1 EapolRespIdFramesRx 3 EapolRespFramesRx 6 EapolReqIdFramesTx 3 EapolReqFramesTx 6 InvalidEapolFramesRx 0 EapLengthErrorFramesRx 0 LastEapolFrameVersion 1 LastEapolFrameSource 00 80 c8 b9 dc 1d Field Description EapolFramesRx The number of valid EAPOL frames of an...

Page 374: ...of EAP Resp Id frames that have been received by this Authenticator EapolRespFramesRx The number of valid EAP Response frames other than Resp Id frames that have been received by this Authenticator EapolReqIdFramesTx The number of EAP Req Id frames that have been transmitted by this Authenticator EapolReqFramesTx The number of EAP Request frames other than Rq Id frames that have been transmitted b...

Page 375: ...efault setting Syntax dot1x multiple hosts no dot1x multiple hosts Default Configuration Multiple hosts are disabled Command Mode Interface Configuration Ethernet mode User Guidelines This command enables the attachment of multiple clients to a single 802 1X enabled port In this mode only one of the attached hosts must be successfully authorized for all hosts to be granted network access If the po...

Page 376: ...not the supplicant address The port is also shutdown trap seconds Send SNMP traps and specifies the minimum time between consecutive traps Range 1 1000000 Default Configuration Discard frames with source addresses not the supplicant address No traps Command Mode Interface configuration Ethernet mode User Guidelines The command is relevant when Multiple hosts is disabled and the user has been succe...

Page 377: ...ort control is force unauthorized its link is down or port control is auto but still no client has been authenticated through this port Not in auto mode Port control is force authorized and clients have full port access console show dot1x advanced Interface Multiple Hosts g11 Disabled g12 Enabled Unauthenticated VLANs 91 92 console show dot1x advanced ethernet g11 Interface Multiple Hosts g11 Disa...

Page 378: ...358 802 1x Commands Single host locked Port control is auto and a single client has been authenticated through this port No Single host Multiple Hosts is enabled ...

Reviews: