background image

Management Commands

644

ProSafe Managed Switch 

passwords aging

Use this command to implement aging on passwords for local users. When a user’s 
password expires, the user will be prompted to change it before logging in again. The valid 
range is 1-365. The default is 0, or no aging.

Default

Format

passwords aging

 <1-365>

Mode

no passwords aging

Use this command to set the password aging to the default value.

Format

no passwords aging

Mode

passwords lock-out

Use this command to strengthen the security of the switch by locking user accounts that have 
failed login due to wrong passwords. When a lockout count is configured, a user that is 
logged in must enter the correct password within that count. Otherwise the user will be locked 
out from further switch access. Only a user with read/write access can re-activate a locked 
user account. Password lockout does not apply to logins from the serial console. The valid 
range is 1-5. The default is 0, or no lockout count enforced.

Format

passwords lock-out

 <1-5>

Mode

Default

no passwords lock-out

Use this command to set the password lock-out count to the default value.

Format

no passwords lock-out

Mode

passwords strength-check

Use this command to enable the password strength feature. It is used to verify the strength of 
a password during configuration.

0

Global Config

Global Config

Global Config

0

Global Config

Format

passwords strength-check

Содержание ProSafe M4100-26-POE

Страница 1: ...Jose CA 95134 USA October 2012 202 1xxxx 01 1 0 ProSafe Managed Switch Command Line Interface CLI User Manual 10 0 1 M7100 24X M4100 D10 POE M4100 26 POE M4100 50 POE M4100 D12G M4100 26G M4100 50G M...

Страница 2: ...hone Other Countries Check the list of phone numbers at http support netgear com general contact default aspx NETGEAR recommends that you use only the official NETGEAR support resources Trademarks NET...

Страница 3: ...iguration Commands 21 Loopback Interface Commands 27 Spanning Tree Protocol STP Commands 29 VLAN Commands 46 Double VLAN Commands 59 Voice VLAN Commands 62 Provisioning IEEE 802 1p Commands 64 Protect...

Страница 4: ...t MVR 209 MVR Commands 209 Chapter 4 Routing Commands Address Resolution Protocol ARP Commands 217 IP Routing Commands 223 Router Discovery Protocol Commands 240 Virtual LAN Routing Commands 243 Virtu...

Страница 5: ...ds 462 DiffServ Show Commands 463 MAC Access Control List ACL Commands 469 IP Access Control List ACL Commands 473 IPv6 Access Control List ACL Commands 480 Time Range Commands for Time Based ACLs 484...

Страница 6: ...P Commands 661 RADIUS Commands 672 TACACS Commands 684 Configuration Scripting Commands 689 Pre Login Banner and System Prompt Commands 691 Switch Database Management SDM Templates 692 IPv6 Management...

Страница 7: ...7 ProSafe M4100 Series Managed Switches Index...

Страница 8: ...nd Conventions Common Parameter Values Unit Slot Port Naming Convention Using a Command s No Form Managed Switch Modules Command Modes Command Completion and Abbreviation CLI Error Messages CLI Line E...

Страница 9: ...mmands Not supported Not supported PIM Commands Not supported Not supported Internet Group Message Protocol IGMP Commands Not supported Not supported IGMP Proxy Commands Not supported Not supported IP...

Страница 10: ...mmand Each command reference also contains the following information Format shows the command keywords and the required and optional parameters Mode identifies the command mode you must be in to acces...

Страница 11: ...meter Description ipaddr This parameter is a valid IP address You can enter the IP address in the following formats a b c d 8 8 8 8 In addition to these formats the CLI accepts decimal hexadecimal and...

Страница 12: ...an existing command and does not represent a new or distinct command Almost every configuration command has a no form In general use the no form to reverse the action of a command or reset a value bac...

Страница 13: ...NMP IPv6 Management Allows management of the device through an IPv6 through an IPv6 address without requiring the IPv6 Routing package in the system The management address can be associated with the n...

Страница 14: ...nterface settings Policy Map Config Switch Config policy map Contains the QoS Policy Map configuration commands Policy Class Config Switch Config policy class map Consists of class creation deletion a...

Страница 15: ...the Privileged EXEC mode enter exit or press Ctrl Z Interface Config From the Global Config mode enter interface unit slot port or interface loopback id or interface tunnel id To exit to the Global Co...

Страница 16: ...ivileged EXEC mode enter Ctrl Z MAC Access list Config From the Global Config mode enter mac access list extended name To exit to the Global Config mode enter exit To return to the Privileged EXEC mod...

Страница 17: ...r or Privileged EXEC modes Message Text Description Invalid input detected at marker Indicates that you entered an incorrect or unavailable command The carat shows where the invalid text is detected T...

Страница 18: ...meters switch network javamode Enable Disable mgmt_vlan Configure the Management VLAN ID of the switch parms Configure Network Parameters of the router protocol Select DHCP BootP or None as the networ...

Страница 19: ...llowing example switch show m mac addr table mac address table monitor Accessing the CLI You can access the CLI by using a direct console connection or by using a telnet or SSH connection from a remot...

Страница 20: ...ovisioning IEEE 802 1p Commands Protected Ports Commands Private VLAN GARP Commands GVRP Commands GMRP Commands Port Based Network Access Control Commands 802 1X Supplicant Commands Storm Control Comm...

Страница 21: ...se to view and configure port settings interface This command gives you access to the Interface Config mode which allows you to enable or modify the operation of an interface port Format interface uni...

Страница 22: ...otiate Mode no auto negotiate This command disables automatic negotiation on a port Note Automatic sensing is disabled when automatic negotiation is disabled auto negotiate all This command enables au...

Страница 23: ...tween 1522 9216 for tagged packets and a valid integer between 1518 9216 for untagged packets Note To receive and process packets the Ethernet MTU must include any extra bytes that Layer 2 headers mig...

Страница 24: ...but not on VLAN routing interfaces no shutdown all This command enables all ports Format no shutdown all Mode speed This command sets the speed and duplex setting for the interface Format speed 100 1...

Страница 25: ...pecial type of port The possible values are Mirror this port is a monitoring port For more information see Port Mirroring on page 119 PC Mbr this port is a member of a port channel LAG Probe this port...

Страница 26: ...Mode Link Status The Link is up or down Link Trap This object determines whether or not to send a trap when link status changes The factory default is enabled LACP Mode LACP is enabled or disabled on...

Страница 27: ...the loopback interface see ipv6 address on page 355 interface loopback Use this command to enter the Interface Config mode for a loopback interface The range of the loopback ID is 0 to 7 Format interf...

Страница 28: ...tion appears Interface Link Status IP Address IPv6 is enabled disabled IPv6 Prefix is MTU size Privileged EXEC Term Definition The loopback ID associated with the rest of the information in the row Th...

Страница 29: ...and can be changed but is not activated Format no spanning tree Mode spanning tree auto edge This command enables auto edge on the interface or range of interfaces When enabled the interface becomes...

Страница 30: ...dufilter Mode no spanning tree bpdufilter default Use this command to disable BPDU Filter on all the edge port interfaces Default Format no spanning tree bpdufilter default Mode spanning tree bpdufloo...

Страница 31: ...interfaces This command forces the BPDU transmission when you execute it so the command does not change the system configuration or have a no version Format spanning tree bpdumigrationcheck unit slot...

Страница 32: ...guration revision Mode spanning tree edgeport This command specifies that this port is an Edge Port within the common and internal spanning tree This allows this port to transition to Forwarding State...

Страница 33: ...range of 4 to 30 with the value being greater than or equal to Bridge Max Age 2 1 Default Format spanning tree forward time 4 30 Mode no spanning tree forward time This command sets the Bridge Forwar...

Страница 34: ...the common and internal spanning tree The max age value is in seconds within a range of 6 to 40 with the value being less than or equal to 2 x Bridge Forward Delay 1 Default Format spanning tree max...

Страница 35: ...ecify the external cost option this command sets the external path cost for MST instance 0 i e CIST instance You can set the external cost as a number in the range of 1 to 200000000 or auto If you spe...

Страница 36: ...s to the new instance ID to be added The maximum number of multiple instances supported by the switch is 4 Default Format spanning tree mst instance mstid Mode no spanning tree mst instance This comma...

Страница 37: ...n This command adds an association between a multiple spanning tree instance and one or more VLANs so that the VLAN s are no longer associated with the common and internal spanning tree The parameter...

Страница 38: ...t mode all Mode no spanning tree port mode all This command sets the Administrative Switch Port State for all ports to disabled Format no spanning tree port mode all Mode spanning tree edgeport all Th...

Страница 39: ...show spanning tree Mode Privileged EXEC User EXEC disabled Global Config Global Config Term Definition Bridge Priority Specifies the bridge priority for the Common and Internal Spanning tree CST The...

Страница 40: ...Configuration Bridge Protocol Data Units BPDUs Bridge Max Hops Bridge max hops count for the device CST Regional Root Bridge Identifier of the CST Regional Root It is made up using the bridge priorit...

Страница 41: ...c switch port within a particular multiple spanning tree instance The parameter mstid is a number that Term Definition Admin hello time for this port Enabled or disabled Enabled or disabled Enabled or...

Страница 42: ...ected MST instance The port priority is displayed in multiples of 16 Current spanning tree state of this port Each enabled MST Bridge Port receives a Port Role for each spanning tree The port role is...

Страница 43: ...Root Path Cost The root path cost to the LAN by the port Designated Bridge The bridge containing the designated port DesignatedPort Identifier Port on the Designated Bridge that offers the lowest cost...

Страница 44: ...s settings for the ports within the specified multiple spanning tree instance that are active links Format show spanning tree mst port summary mstid active Mode Privileged EXEC User EXEC Transitions I...

Страница 45: ...lays spanning tree settings and parameters for the switch The following details are displayed on execution of the command Format show spanning tree summary Mode Privileged EXEC User EXEC Term Definiti...

Страница 46: ...e VLAN settings Term Definition Enabled or disabled Version of 802 1 currently supported IEEE 802 1s IEEE 802 1w or IEEE 802 1d based upon the Force Protocol Version parameter Enabled or disabled Enab...

Страница 47: ...d assigns it an ID The ID is a valid VLAN identification number ID 1 is reserved for the default VLAN The vlan list contains VlanId s in range 1 4093 Separate non consecutive IDs with and no spaces an...

Страница 48: ...and resets the frame acceptance mode for the interface to the default value Format no vlan acceptframe Mode vlan ingressfilter This command enables ingress filtering If ingress filtering is disabled f...

Страница 49: ...LAN to a blank string Format no vlan name 1 4093 Mode vlan participation This command configures the degree of participation for a specific interface in a VLAN The ID is a valid VLAN identification nu...

Страница 50: ...frame all This command sets the frame acceptance mode for all interfaces to Admit All For Admit All mode untagged frames or priority frames received on this interface are accepted and Global Config Pa...

Страница 51: ...re members of that VLAN Default Format vlan port ingressfilter all Mode no vlan port ingressfilter all This command disables ingress filtering for all ports If ingress filtering is disabled frames rec...

Страница 52: ...ged frames The ID is a valid VLAN identification number Format no vlan port tagging all Mode vlan protocol group This command adds protocol based VLAN groups to the system When it is created the proto...

Страница 53: ...ywords ip arp and ipx and hexadecimal or decimal values ranging from 0x0600 1536 to 0xFFFF 65535 The protocol list can accept up to 16 protocols separated by a comma Default Format vlan protocol group...

Страница 54: ...are not added to the group Default Format protocol vlan group groupid Mode no protocol vlan group This command removes the interface from this protocol based VLAN group that is identified by this gro...

Страница 55: ...bled traffic is transmitted as tagged frames If tagging is disabled traffic is transmitted as untagged frames The vlan list contains VlanId s in range 1 4093 Separate non consecutive IDs with and no s...

Страница 56: ...address to a VLAN Format no vlan association mac macaddr Mode show vlan This command displays a list of all configured VLAN Format show vlan Mode Privileged EXEC User EXEC VLAN ID VLAN Name VLAN Type...

Страница 57: ...IEEE 802 1Q standard Autodetect To allow the port to be dynamically registered in this VLAN via GVRP The port will not participate in this VLAN unless a join request is received on this port This is...

Страница 58: ...all ports by using the selectors on the top line The VLAN ID that this port will assign to untagged frames or priority tagged frames received on this port The value must be for an existing VLAN The fa...

Страница 59: ...es the commands you use to configure double VLAN DVLAN Double VLAN tagging is a way to pass VLAN traffic from one customer domain to another through a Metro Core in a simple and cost effective manner...

Страница 60: ...neling on the specified interface Default Format mode dot1q tunnel Mode no mode dot1q tunnel This command is used to disable Double VLAN Tunneling on the specified interface By default Double VLAN Tun...

Страница 61: ...unneling Use the optional parameters to display detailed information about Double VLAN Tunneling for the specified interface or all interfaces Format show dvlan tunnel interface unit slot port all Mod...

Страница 62: ...traffic traveling through the port to identify the IP phone data flow voice vlan Global Config Use this command to enable the Voice VLAN capability on the switch Default Format voice vlan Mode no voi...

Страница 63: ...eter is not specified only the global mode of the Voice VLAN is displayed Administrative Mode Format voice vlan id dot1p priority none untagged Mode Interface Config Parameter Description Configure th...

Страница 64: ...default 802 1p port priority assigned for untagged packets for a specific interface The range for the priority is 0 7 Default Format vlan priority priority Mode Protected Ports Commands This section d...

Страница 65: ...blank Note Port protection occurs within a single switch Protected port configuration does not affect traffic between ports on two different switches No traffic forwarding is possible between two prot...

Страница 66: ...port unit slot port groupid Mode Privileged EXEC User EXEC Name Protected port Default unprotected Format switchport protected groupid Mode Interface Config Interface Config Term Definition The number...

Страница 67: ...te VLAN Three types of port designations exist within a private VLAN Promiscuous Ports An endpoint connected to a promiscuous port is allowed to communicate with any endpoint within the private VLAN M...

Страница 68: ...ate VLAN association or mapping from the port Format no switchport mode private vlan Mode Term Definition Defines VLAN association for community or host ports Defines the private VLAN mapping for prom...

Страница 69: ...ion Mode vlan Use this command to enter the private vlan configuration The VLAN range is 1 4094 Format vlan vlan list Mode show vlan This command displays information about the configured private VLAN...

Страница 70: ...ing GVMP or multicast groups by using GVMP set garp timer join This command sets the GVRP join time for one port Interface Config mode or all Global Config mode and per GARP Join time is the interval...

Страница 71: ...ds The value 60 centiseconds is 0 6 seconds Default Format set garp timer leave 20 600 Mode Interface Config Global Config no set garp timer leave This command sets the GVRP leave time on all ports or...

Страница 72: ...ibes the commands you use to configure and view GARP VLAN Registration Protocol GVRP information GVRP enabled switches exchange VLAN configuration information which allows GVRP to provide dynamic VLAN...

Страница 73: ...onfig Global Config show gvrp configuration This command displays Generic Attributes Registration Protocol GARP information for one or all interfaces Format show gvrp configuration unit slot port all...

Страница 74: ...before deleting the attribute Current attributes are a VLAN or multicast group This may be considered a buffer time for another station to assert registration for the same attribute in order to maint...

Страница 75: ...t channel LAG GARP functionality is disabled GARP functionality is subsequently re enabled if routing is disabled and port channel LAG membership is removed from an interface that has GARP enabled For...

Страница 76: ...me controls how frequently LeaveAll PDUs are generated A LeaveAll PDU indicates that all registrations will shortly be deregistered Participants will need to rejoin in order to maintain registration T...

Страница 77: ...ault Format dot1x guest vlan vlan id Mode no dot1x guest vlan This command disables Guest VLAN on the interface Default Format no dot1x guest vlan Mode dot1x initialize This command begins the initial...

Страница 78: ...EAPOL EAP Request Identity frame before timing out the supplicant The count value must be in the range 1 10 Default Format dot1x max req count Mode no dot1x max req This command sets the maximum numbe...

Страница 79: ...ormat dot1x port control force unauthorized force authorized auto mac based Mode no dot1x port control This command sets the 802 1x port control mode on the specified port to the default value Format...

Страница 80: ...uthenticate unit slot port Mode dot1x re authentication This command enables re authentication of the supplicant for the specified port Default Format dot1x re authentication Mode no dot1x re authenti...

Страница 81: ...t before authorizing the port and placing the port in the guest vlan if configured The guest vlan timer is only relevant when guest vlan has been configured on that specific port The value in seconds...

Страница 82: ...st be statically configured in the VLAN database to be operational By default the unauthenticated VLAN is 0 i e invalid and not operational Default Format dot1x unauthenticated vlan vlan id Mode no do...

Страница 83: ...ed VLAN does not exist in the switch Format no dot1x dynamic vlan enable Mode dot1x system auth control monitor Use this command to enable the 802 1X monitor mode on the switch The purpose of Monitor...

Страница 84: ...______________ Console_Default None Network_Default Local Enable Authentication Lists _____________________ Console_Default Enable None Network_Default Enable Line Login Method List Enable Method List...

Страница 85: ...ort or all ports are displayed Interface Control Mode Operating Control Mode Reauthenticatio n Enabled Port Status Privileged EXEC Term Definition Indicates whether authentication control on the switc...

Страница 86: ...nd will be in the range 0 and 65535 Transmit Period The timer used by the authenticator state machine on the specified port to determine when to send an EAPOL EAP Request Identity frame to the supplic...

Страница 87: ...mode This value is used only when the port control mode is not MAC based Unauthenticated VLAN ID Indicates the unauthenticated VLAN configured for this port This value is valid for the port only when...

Страница 88: ...eived by this authenticator The number of EAPOL frames of any type that have been transmitted by this authenticator The number of EAPOL start frames that have been received by this authenticator The n...

Страница 89: ...uthenticated This is a configured DiffServ policy name on the switch VLAN ID The VLAN assigned to the port VLAN Assigned The reason the VLAN identified in the VLAN ID field has been assigned to the po...

Страница 90: ...the port s attribute needs to be moved from authenticator to supplicant or supplicant to authenticator use this command Format dot1x supplicant port control auto force authorized force_unauthorized Mo...

Страница 91: ...configure the start period timer interval to wait for the EAP identity request from the authenticator Default Format dot1x supplicant timeout start period 1 65535 seconds Mode no dot1x supplicant time...

Страница 92: ...This section describes commands you use to configure storm control and view storm control configuration information A traffic storm is a condition that occurs when incoming packets flood the LAN whic...

Страница 93: ...olute rate kbps For example if the configured limit is 10 this is converted to 25000 pps and this pps limit is set in forwarding plane hardware You get the approximate desired output when 512bytes pac...

Страница 94: ...essing on an interface increases beyond the configured threshold the traffic is dropped Therefore the rate of broadcast traffic is limited to the configured threshold Default Format storm control broa...

Страница 95: ...recovery mode for all interfaces Default Format storm control broadcast level 0 100 Mode no storm control broadcast level This command sets the broadcast storm recovery threshold to the default value...

Страница 96: ...les multicast storm recovery mode for an interface Format no storm control multicast Mode storm control multicast level This command configures the multicast storm recovery threshold for an interface...

Страница 97: ...rol multicast Global This command enables multicast storm recovery mode for all interfaces If the mode is enabled multicast storm recovery is active and if the rate of L2 multicast traffic ingressing...

Страница 98: ...ingressing on an interface increases beyond the configured threshold the traffic is dropped Therefore the rate of multicast traffic is limited to the configured threshold Default Format storm control...

Страница 99: ...es unicast storm recovery mode for an interface Default Format storm control unicast level 0 100 Mode no storm control unicast level This command sets the unicast storm recovery threshold to the defau...

Страница 100: ...mited to the configured threshold Default Format storm control unicast Mode no storm control unicast This command disables unicast storm recovery mode for all interfaces Format no storm control unicas...

Страница 101: ...rate This command sets the multicast storm recovery threshold to the default value for an interface and disables multicast storm recovery Format no storm control unicast rate Mode show storm control...

Страница 102: ...flow control allows the switch to respond to received PAUSE frames but the port cannot generate PAUSE frames Symmetric flow control allows the switch to both respond to and generate MAC control PAUSE...

Страница 103: ...Oper 0 1 Active 310 611 0 2 Inactive 0 0 switch show flowcontrol interface 0 1 Admin Flow Control Symmetric Port Flow Control RxPause TxPause Oper 0 1 Active 310 611 Port Channel LAG 802 3ad Commands...

Страница 104: ...up ID of a configured port channel Note Before adding a port to a port channel set the physical mode of the port For more information see speed on page 24 deleteport Interface Config This command dele...

Страница 105: ...ort channel Format no lacp admin key Mode lacp collector max delay Use this command to configure the port channel collector max delay The valid range of delay is 0 65535 Default Format lacp collector...

Страница 106: ...p actor admin state individual Use this command to set LACP actor admin state to individual Format lacp actor admin state individual Mode Note This command is only applicable to physical interfaces no...

Страница 107: ...state to passive Format lacp actor admin state passive Mode Note This command is only applicable to physical interfaces no lacp actor admin state passive Use this command to set the LACP actor admin...

Страница 108: ...r system priority priority Mode Note This command is only applicable to physical interfaces no lacp actor system priority Use this command to configure the priority value associated with the Actor s S...

Страница 109: ...ividual Use this command to set the LACP partner admin state to aggregation Format no lacp partner admin state individual Mode lacp partner admin state longtimeout Use this command to set LACP partner...

Страница 110: ...te passive Mode lacp partner port id Use this command to configure the LACP partner port id The valid range for port id is 0 to 65535 Default Format lacp partner portid port id Mode Note This command...

Страница 111: ...t lacp partner system id system id Mode Note This command is only applicable to physical interfaces no lacp partner system id Use this command to configure the default value representing the administr...

Страница 112: ...Default Format port channel local preference Mode no port channel local preference This command disables the local preference mode on a port channel Format no port channel local preference Mode port...

Страница 113: ...tocol LACP on a port Format no port lacpmode Mode port lacpmode enable all This command enables Link Aggregation Control Protocol LACP on all ports Format port lacpmode enable all Mode no port lacpmod...

Страница 114: ...t lacptimeout This command sets the timeout for all physical interfaces of a particular device type actor or partner back to their default values Format no port lacptimeout actor partner Mode port cha...

Страница 115: ...hannel LAG by selecting one of the links in the channel over which to transmit specific packets The link is selected by creating a binary pattern from selected fields in a packet and associating that...

Страница 116: ...e packet Source Destination MAC VLAN EtherType and incoming port associated with the packet Source IP and Source TCP UDP fields of the packet Destination IP and Destination TCP UDP Port fields of the...

Страница 117: ...and to display LACP actor attributes Format show lacp actor unit slot port all Mode The following output parameters are displayed System Priority Admin Key Port Priority Admin State show lacp partner...

Страница 118: ...nit slot port all Mode Privileged EXEC User EXEC Parameter Description The administrative value of priority associated with the Partner s System ID The value representing the administrative value of t...

Страница 119: ...use tx to monitor only egress packets If you do not specify an rx tx option the destination port monitors both ingress and egress packets Use the destination interface unit slot port to Term Definiti...

Страница 120: ...Use the source interface unit slot port parameter or destination interface unit slot port to remove the specified interface from the port monitoring session Use the mode parameter to disable the admi...

Страница 121: ...c mac filters supported on the system is different for MAC filters where source ports are configured and MAC filters where destination ports are configured For unicast MAC address filters and multicas...

Страница 122: ...l number in the format of b1 b2 b3 b4 b5 b6 The vlanid parameter must identify a valid VLAN Format no macfilter macaddr vlanid Mode macfilter adddest Use this command to add the interface to the desti...

Страница 123: ...C filter with the given macaddr and VLAN of vlanid The macaddr parameter must be specified as a 6 byte hexadecimal number in the format of b1 b2 b3 b4 b5 b6 The vlanid parameter must identify a valid...

Страница 124: ...acaddr and VLAN of vlanid You must specify the macaddr parameter as a 6 byte hexadecimal number in the format of b1 b2 b3 b4 b5 b6 The vlanid parameter must identify a valid VLAN Format no macfilter a...

Страница 125: ...mmand to enable the DHCP Layer 2 Relay agent for an interface a range of interfaces or all interfaces The subsequent commands mentioned in this section can be used only when the DHCP L2 relay is enabl...

Страница 126: ...list Mode no dhcp l2relay circuit id vlan Use this parameter to clear the DHCP Option 82 Circuit ID for a VLAN Format no dhcp l2relay circuit id vlan vlan list Mode dhcp l2relay remote id vlan Use thi...

Страница 127: ...t no dhcp l2relay vlan vlan list Mode dhcp l2relay trust Use this command to configure an interface or range of interfaces as trusted for Option 82 reception Default Format dhcp l2relay trust Mode no...

Страница 128: ...h show dhcp l2relay interface all DHCP L2 Relay is Enabled Interface L2RelayMode TrustMode 1 0 2 Enabled untrusted 1 0 4 Disabled trusted show dhcp l2relay stats interface Use this command to display...

Страница 129: ...HCP Client can include vendor and configuration information in DHCP client requests relayed to a DHCP server This information is included in DHCP Option 60 Vendor Class Identifier The information is a...

Страница 130: ...this command to display the configured administration mode of the vendor id option and the vendor id string to be included in Option 43 in DHCP requests Format show dhcp client vendor id option Mode E...

Страница 131: ...Snooping on VLANs Format no ip dhcp snooping vlan vlan list Mode ip dhcp snooping verify mac address Use this command to enable verification of the source MAC address with the client hardware address...

Страница 132: ...conds Default Format ip dhcp snooping database write delay in seconds Mode no ip dhcp snooping database write delay Use this command to set the write delay value to the default value Format no ip dhcp...

Страница 133: ...s come The default rate is 15 pps with a range from 0 to 30 pps The default burst level is 1 second with a range of 1 to 15 seconds Default Format ip dhcp snooping limit rate pps burst interval second...

Страница 134: ...s command to configure the IPSG source ID attribute to filter the data traffic in the hardware Source ID is the combination of IP address and MAC address Normal command allows data traffic filtration...

Страница 135: ...o No show ip dhcp snooping binding Use this command to display the DHCP Snooping binding entries To restrict the output use the following options Dynamic Restrict the output based on DCHP snooping Int...

Страница 136: ...ple The following shows example CLI display output for the command switch show ip dhcp snooping database agent url 10 131 13 79 sai1 txt write delay 5000 Term Definition MAC Address Displays the MAC a...

Страница 137: ...ilures Mismatch Msgs Rec d 1 0 2 0 0 0 1 0 3 0 0 0 1 0 4 0 0 0 1 0 5 0 0 0 1 0 6 0 0 0 1 0 7 0 0 0 1 0 8 0 0 0 1 0 9 0 0 0 1 0 10 0 0 0 1 0 11 0 0 0 1 0 12 0 0 0 1 0 13 0 0 0 1 0 14 0 0 0 1 0 15 0 0 0...

Страница 138: ...ons on all ports Format show ip verify source Mode Privileged EXEC User EXEC Example The following shows example CLI display output for the command switch show ip verify source Interface Filter Type I...

Страница 139: ...in the middle attacks where an unfriendly station intercepts traffic for other stations by poisoning the ARP caches of its unsuspecting neighbors The miscreant sends ARP requests or responses mapping...

Страница 140: ...h command overrides the configuration of the previous command For example if a command enables src mac and dst mac validations and a second command enables IP validation only the src mac and dst mac v...

Страница 141: ...interface as untrusted for Dynamic ARP Inspection Format no ip arp inspection trust Mode ip arp inspection limit Use this command to configure the rate limit and burst interval values for an interface...

Страница 142: ...ement are dropped without consulting the DHCP snooping bindings Default No ARP ACL is configured on a VLAN Format ip arp inspection filter acl name vlan vlan list static Mode no ip arp inspection filt...

Страница 143: ...ludes the source mac validation destination mac validation and invalid IP validation information Format show ip arp inspection vlan vlan list Mode Privileged EXEC User EXEC Example The following shows...

Страница 144: ...and show ip arp inspection statistics which lists the summary of forwarded and dropped ARP packets on all DAI enabled VLANs VLAN Forwarded Dropped 10 90 14 20 10 3 Example The following shows example...

Страница 145: ...nterface is a member of is enabled for DAI Given a unit slot port interface argument the command displays the values for that interface whether the interface is enabled for DAI or not Format show ip a...

Страница 146: ...to forward IP multicast traffic only to connected hosts that request multicast traffic IGMPv3 adds source filtering capabilities to IGMP versions 1 and 2 set igmp This command enables IGMP Snooping o...

Страница 147: ...e this interface for routing or enlist it as a member of a port channel LAG IGMP Snooping functionality is disabled on that interface IGMP Snooping functionality is re enabled if you disable routing o...

Страница 148: ...d Mode no set igmp fast leave This command disables IGMP Snooping fast leave admin mode on a selected interface Format no set igmp fast leave Mode Format no set igmp fast leave vlan_id Mode set igmp g...

Страница 149: ...n that interface This value must be less than the IGMP Query Interval time value The range is 1 to 25 seconds Default Format set igmp maxresponse 1 25 Mode Global Config Interface Config Format set ig...

Страница 150: ...ulticast Router Present Expiration time to 0 The time is set for the system on a particular interface or a VLAN Format no set igmp mcrtrexpiretime Mode Global Config Interface Config Format no set igm...

Страница 151: ...mmand enables the Router Alert validation for IGMP snooping packets Default Format set igmp router alert check Mode no set igmp router alert check This command disables the Router Alert validation for...

Страница 152: ...ponse Time Multicast Router Expiry Time Global Config Privileged EXEC Term Definition Indicates whether or not IGMP Snooping is active on the switch The number of multicast control frames that are pro...

Страница 153: ...at a switch will wait for a report from a particular group on a particular interface which is participating in the VLAN before deleting the interface from the entry This value may be configured The am...

Страница 154: ...lobal Config mode or on a VLAN Using this command you can specify the IP Address that the Snooping Querier switch should use as the source address while generating periodic queries If a VLAN has IGMP...

Страница 155: ...ommand to set the IGMP Querier Query Interval time It is the amount of time in seconds that the switch waits before sending another general query Default Format set igmp querier query interval 1 18000...

Страница 156: ...ing Querier to participate in the Querier Election process when it discovers the presence of another Querier in the VLAN When this mode is enabled if the Snooping Querier finds that the other Querier...

Страница 157: ...its before sending out the periodic general query The amount of time to wait in the Non Querier operational state before moving to a Querier state Field Description Indicates whether iGMP Snooping Que...

Страница 158: ...nfig Mode or an Interface Interface Config Mode This command also enables MLD Snooping on a particular VLAN and enables MLD Snooping on all interfaces participating in a VLAN If an interface has MLD S...

Страница 159: ...eave Use this command to enable MLD Snooping fast leave admin mode on a selected interface or VLAN Enabling fast leave allows the switch to immediately remove the Layer 2 LAN interface from its forwar...

Страница 160: ...00 seconds Default Format set mld groupmembership interval vlanid 2 3600 Mode Interface Config Global Config VLAN Mode no set groupmembership interval Use this command to set the MLDv2 Group Membershi...

Страница 161: ...before the interface is removed from the list of interfaces with multicast routers attached The range is 0 to 3600 seconds A value of 0 indicates an infinite timeout that is no expiration Default Form...

Страница 162: ...se this command to disable the status of the interface as a statically configured multicast router attached interface Format no set mld mrouter interface Mode show mldsnooping Use this command to disp...

Страница 163: ...Fast Leave is active on the VLAN Shows the amount of time in seconds that a switch will wait for a report from a particular group on a particular interface which is participating in the VLAN before d...

Страница 164: ...ip on a port by port basis If the switch does not receive updated membership information in a timely fashion it will stop forwarding multicasts to the port where the end device is located This section...

Страница 165: ...the VLAN to solicit membership reports Global Config VLAN Mode no set mld querier Use this command to disable MLD Snooping Querier on the system Use the optional parameter address to reset the querier...

Страница 166: ...AN When this mode is enabled if the Snooping Querier finds that the other Querier s source address is better less than the Snooping Querier s address it stops sending periodic queries If the Snooping...

Страница 167: ...meout Displays the amount of time to wait in the Non Querier operational state before moving to a Querier state Field Description VLAN Admin Mode Indicates whether MLD Snooping Querier is active on th...

Страница 168: ...discarded Note To enable the SNMP trap specific to port security see snmp server enable traps violation on page 664 port security This command enables port locking at the system level Global Config o...

Страница 169: ...amic Mode port security max static This command sets the maximum number of statically locked MAC addresses allowed on a port Default Format port security max static maxvalue Mode no port security max...

Страница 170: ...sticky addresses are converted back to dynamically locked addresses if sticky mode is disabled on the port The vid is the VLAN ID The Global command applies the sticky mode to all valid interfaces phy...

Страница 171: ...the dynamically locked MAC addresses for the port Format show port security dynamic lag lag intf num unit slot port Mode MAC Address show port security static This command displays the statically loc...

Страница 172: ...802 LAN to advertise major capabilities and physical descriptions The advertisements allow a network management system NMS to access and display this information lldp transmit Use this command to ena...

Страница 173: ...val interval seconds hold hold value reinit reinit seconds Mode no lldp timers Use this command to return any or all timing parameters for local data transmission on ports enabled for LLDP to the defa...

Страница 174: ...lt Format lldp transmit mgmt Mode no lldp transmit mgmt Use this command to include transmission of the local system management address information in the LLDPDUs Use this command to cancel inclusion...

Страница 175: ...Mode clear lldp statistics Use this command to reset all LLDP statistics including MED related information Format clear lldp statistics Mode clear lldp remote data Use this command to delete all info...

Страница 176: ...notifications in seconds Privileged Exec Term Definition The interface in a unit slot port format Shows whether the link is up or down Shows whether the interface transmits LLDPDUs Shows whether the...

Страница 177: ...tal number of LLDP packets transmitted on the port Total number of LLDP packets received on the port Total number of LLDP frames discarded on the port for any reason The number of invalid LLDP frames...

Страница 178: ...More or q uit show lldp remote device detail Use this command to display detailed information about remote devices that transmit current LLDP data to an interface on the system Format show lldp remote...

Страница 179: ...rt ID The port number that transmitted the LLDPDU System Name The system name of the remote device System Description Describes the remote system by identifying the system name and versions of hardwar...

Страница 180: ...Power over Ethernet PoE management and inventory management Term Definition The interface in a unit slot port format The port ID associated with this interface The port description associated with th...

Страница 181: ...otification Use this command to disable notifications Format no lldp med confignotification Mode lldp med transmit tlv Use this command to specify which optional Type Length Values TLVs in the LLDP ME...

Страница 182: ...this command to configure LLDP MED on all the ports no lldp med all Use this command to remove LLDP MD on all ports Format no lldp med all Mode lldp med confignotification all U Format lldp med config...

Страница 183: ...t value Format no lldp med faststartrepeatcount Mode lldp med transmit tlv all Use this command to specify which optional Type Length Values TLVs in the LLDP MED set will be transmitted in the Link La...

Страница 184: ...of the current LLDP MED configuration for a specific interface unit slot port indicates a specific physical interface all indicates all valid LLDP interfaces Format show lldp med interface unit slot...

Страница 185: ...ed Disabled Disabled 0 1 1 0 14 Down Disabled Disabled Disabled 0 1 TLV Codes 0 Capabilities 1 Network Policy 2 Location 3 Extended PSE 4 Extended Pd 5 Inventory More or q uit Switch show lldp med int...

Страница 186: ...CP 1 Unknown False Tagged True Media Policy Application Type streamingvideo Vlan ID 20 Priority 1 DSCP 2 Privileged EXEC Term Definition Shows the application type Types are unknown voice voicesignali...

Страница 187: ...the system You can show information about LLDP remote data received on all ports or on a specific port Format show lldp med remote device unit slot port all Mode Example The following shows example C...

Страница 188: ...zed by the device remotely connected to the port Network Policy Information Shows if network policy TLV is received in the LLDP frames on this port Media Application Type Shows the application type Ty...

Страница 189: ...Inventory Hardware Rev xxx xxx xxx Serial Number Shows the serial number of the remote device Manufacturer Name Shows the manufacture name of the remote device Model Name Shows the model name of the...

Страница 190: ...o monitor and block these types of attacks SIP DIP Source IP address Destination IP address First Fragment TCP Header size smaller then configured value TCP Fragment IP Fragment Offset 1 TCP Flag TCP...

Страница 191: ...This command enables Source IP address Destination IP address SIP DIP Denial of Service protection If the mode is enabled Denial of Service prevention is active for this type of attack If packets ingr...

Страница 192: ...type of attack If packets ingress having IP Fragment Offset equal to one 1 the packets will be dropped if the mode is enabled Default Format dos control tcpfrag Mode no dos control tcpfrag This comma...

Страница 193: ...led Note Some applications mirror source and destination L4 ports RIP for example uses 520 for both If you enable dos control l4port applications such as RIP may experience packet loss which would ren...

Страница 194: ...ts ingress with SMAC DMAC the packets will be dropped if the mode is enabled Default Format dos control smacdmac Mode no dos control smacdmac This command disables Source MAC address Destination MAC a...

Страница 195: ...port Mode no dos control udpport This command disables UDP L4 source destination port number Source UDP Port Destination UDP Port Denial of Service protection Format no dos control udppport Mode dos c...

Страница 196: ...no dos control tcpoffset This command disabled TCP Offset Denial of Service protection Format no dos control tcpoffset Mode dos control tcpsyn This command enables TCP SYN and L4 source 0 1023 Denial...

Страница 197: ...Denial of Service prevention is active for this type of attack If packets ingress having TCP FIN URG and PSH all set and TCP Sequence Number set to 0 the packets will be dropped if the mode is enable...

Страница 198: ...mpv6 0 16384 Mode no dos control icmpv6 This command disables Maximum ICMP Packet Size Denial of Service protections Format no dos control icmpv6 Mode dos control icmpfrag This command enables ICMP Fr...

Страница 199: ...de May be enabled or disabled The factory default is disabled TCP Port Mode May be enabled or disabled The factory default is disabled UDP Port Mode May be enabled or disabled The factory default is d...

Страница 200: ...lue Format no bridge aging time Mode show forwardingdb agetime This command displays the timeout for address aging Default Format show forwardingdb agetime Mode Address Aging Timeout show mac address...

Страница 201: ...and VLAN ID combination of 8 bytes The type of the entry Static entries are those that are configured by the end user Dynamic entries are added to the table as a result of a learning process or proto...

Страница 202: ...n seconds Default Format isdp holdtime 10 255 Mode isdp timer This command sets the period of time between sending new ISDP packets The range is given in seconds Default Format isdp timer 5 254 Mode i...

Страница 203: ...the ISDP table Format clear isdp table Mode show isdp This command displays global ISDP settings Format show isdp Mode Enabled Interface Config Interface Config Privileged EXEC Privileged EXEC Privile...

Страница 204: ...rm specific format as the format for its Device ID Device ID Format Indicates the Device ID format of the device serialNumber indicates that the value is in the form of an ASCII string containing the...

Страница 205: ...he advertisement packet received from the neighbor Capability ISDP Functional Capabilities advertised by the neighbor Privileged EXEC Term Definition Device ID The device ID associated with the neighb...

Страница 206: ...ebug isdp packet This command disables tracing of ISDP packets on the receive or the transmit sides or on both sides Format no debug isdp packet receive transmit Mode show isdp traffic Privileged EXEC...

Страница 207: ...rticular CoS value on an interface Ensure that VLAN tagging is enabled on the interface so that the 802 1p priority values are carried through the network Ensure that 802 1p priority values are mapped...

Страница 208: ...s priorities supported is 2 Additionally the mapping of class of service levels to 802 1p priority values to must be set to one to one Format priority flow control priority priority list drop no drop...

Страница 209: ...even if there are receivers connected to only a few ports To address this problem the IGMP Snooping protocol was developed The problem still appears though when receivers are in different VLANs MVR is...

Страница 210: ...roups they need to be configured by the operator as the protocol does not forward joins from the hosts to the router To operate in this mode the IGMP router needs to be statically configured to transm...

Страница 211: ...N to the default value mvr immediate This command enables MVR immediate leave mode MVR has two modes of operating with the IGMP Leave messages normal leave and immediate leave In normal leave mode whe...

Страница 212: ...ets the MVR port type When a port is set as source it is the port to which the multicast traffic flows using the multicast VLAN When a port is set to receiver it is the port where a listening host is...

Страница 213: ...R membership groups allocated A B C D is a valid multicast address in IPv4 dotted notation Format no mvr vlan mVLAN group A B C D Mode Interface Config Format show mvr Mode Privileged EXEC Term Defini...

Страница 214: ...g inVLAN or notInVLAN indicates whether the port is part of any VLAN Example switch show mvr interface Port Type Status Immediate Leave 1 0 9 RECEIVER ACTIVE inVLAN DISABLED Term Definition MVR Group...

Страница 215: ...P Leave Received 0 IGMP Query Transmitted 2 Format show mvr traffic Mode Privileged EXEC Term Definition IGMP Query Received Number of received IGMP queries IGMP Report V1 Received Number of received...

Страница 216: ...lticast VLAN Registration MVR 216 ProSafe Managed Switch IGMP Report V1 Transmitted 0 IGMP Report V2 Transmitted 3 IGMP Leave Transmitted 1 IGMP Packet Receive Failures 0 IGMP Packet Transmit Failures...

Страница 217: ...Commands OSPF Graceful Restart Commands Routing Information Protocol RIP Commands ICMP Throttling Commands The commands in this chapter are in three functional groups Show commands display switch set...

Страница 218: ...mat no arp ipaddress macaddr Mode ip local proxy arp This command enables local proxy arp on interface or range of interfaces The switch only responds if all next hops in its route to the destination...

Страница 219: ...a platform specific integer value The default size also varies depending on the platform Format arp cachesize platform specific integer value Mode no arp cachesize This command configures the default...

Страница 220: ...s is between 1 10 seconds Default Format arp resptime 1 10 Mode no arp resptime This command configures the default ARP request response timeout Format no arp resptime Mode arp retries This command co...

Страница 221: ...e gateway Mode clear arp switch Use this command to clear the contents of the switch s Address Resolution Protocol ARP table that contains entries learned through the Management port To observe whethe...

Страница 222: ...they age out The total entries in the ARP table and the peak entry count in the ARP table The static entry count in the ARP table the active entry count in the ARP table the active entry count in the...

Страница 223: ...s Routing Mode Default Format routing Mode no routing This command disables routing for an interface DynamicRenew Mode Displays whether the ARP component automatically attempts to renew dynamic ARP en...

Страница 224: ...ts the subnet mask of the interface The subnet mask must have contiguous ones and be no longer than 30 bits for example 255 255 255 0 This command adds the label IP address in show ip interface Format...

Страница 225: ...letes all manually configured IPv4 addresses on the interface Default Format ip address dhcp Mode no ip address dhcp Use this command to release a leased address and disable DHCPv4 on an interface For...

Страница 226: ...interfaces This command does not apply to service or network ports Format show dhcp lease interface unit slot port Mode IP address Subnet mask DHCP Lease server State DHCP transaction ID Lease Renewa...

Страница 227: ...red than other static routes to the same destination A route with a preference of 255 cannot be used to forward traffic For the static routes to be visible you must perform the following steps Enable...

Страница 228: ...dual static route The default distance is used when no distance is specified in these commands Changing the default distance does not update the distance of existing static routes even if they were as...

Страница 229: ...ed by the IP stack The IP stack uses its default IP MTU and ignores the value set using the ip mtu command OSPF advertises the IP MTU in the Database Description packets it sends to its neighbors duri...

Страница 230: ...s This command resets to zero the IPv4 routing table counters reported in show ip route summary The command resets only the event counters Counters that report the current state of the routing table s...

Страница 231: ...cket can travel Maximum Routes The maximum number of routes the packet can travel ICMP Rate Limit Interval Shows how often the token bucket is initialized with burst size tokens Burst interval is from...

Страница 232: ...ts Displays whether forwarding of network directed broadcasts is enabled or disabled This value is configurable Proxy ARP Displays whether Proxy ARP is enabled or disabled on the system Local Proxy AR...

Страница 233: ...terface The IP address of the routing interface in 32 bit dotted decimal format The IP mask of the routing interface in 32 bit dotted decimal format Indicates if IP forwards net directed broadcasts on...

Страница 234: ...ted routes of this type Subnets Whether OSPF redistributes subnets of classful addresses or only classful prefixes Dist List A distribute list used to filter routes of this type Only routes that pass...

Страница 235: ...vely control the traffic destined to a particular network and prevent it from being forwarded through the router you can configure a static reject route on the router Such traffic would be discarded a...

Страница 236: ...ly connected 0 11 S 12 0 0 0 8 5 0 directly connected Null0 S 23 0 0 0 8 3 0 directly connected Null0 show ip route ecmp groups This command reports all current ECMP groups in the IPv4 routing table A...

Страница 237: ...routing table This number counts only the best route to each destination Alternate Routes The number of alternate routes currently in the routing table An alternate route is one that was not selected...

Страница 238: ...High Water The highest count of unique next hops since the counters were last cleared Next Hop Groups The current number of next hop groups in use by one or more routes Each next hop group includes on...

Страница 239: ...OSPF Inter OSPF External RIP show ip stats This command displays IP statistical information Refer to RFC 1213 for more information about the fields that are displayed Format show ip stats Modes Privi...

Страница 240: ...outers on the subnet ip irdp This command enables Router Discovery on an interface Default Format ip irdp Mode no ip irdp This command disables Router Discovery on an interface Format no ip irdp Mode...

Страница 241: ...the router advertisement sent from this interface The holdtime range is the value of maxadvertinterval to 9000 seconds Default Format ip irdp holdtime maxadvertinterval 9000 Mode no ip irdp holdtime T...

Страница 242: ...ip irdp minadvertinterval This command sets the default minimum time to the default Format no ip irdp minadvertinterval Mode ip irdp preference This command configures the preferability of the addres...

Страница 243: ...if you specify an interface ID that is already in use the CLI displays an error message and does not create the VLAN interface Format vlan routing vlanid interface ID Mode Term Definition The unit sl...

Страница 244: ...l Router Redundancy Protocol VRRP and to view VRRP status information VRRP helps provide failover and load balancing when you configure two devices as a VRRP pair ip vrrp Global Config Use this comman...

Страница 245: ...virtual router associated with the interface The virtual Router ID vrid is an integer value that ranges from 1 to 255 Format no ip vrrp vrid Mode ip vrrp mode This command enables the virtual router...

Страница 246: ...on the interface Format no ip vrrp vrid ipaddress secondary Mode ip vrrp authentication This command sets the authorization details value for the virtual router configured on a specified interface The...

Страница 247: ...ith the highest priority is elected master If a router is configured with the address used as the address of the virtual router the router is called the address owner The priority of the address owner...

Страница 248: ...e is down or the interface has been removed from the router the priority of the VRRP router will be decremented by the value specified in the priority argument When the interface is up for IP protocol...

Страница 249: ...ult priority decrement is changed using the priority argument Default Format ip vrrp vrid track ip route ip address prefix length decrement priority Mode no ip vrrp track ip route Use this command to...

Страница 250: ...to ICMP Echo Requests When Echo Replies are disabled using that command the VRRP master does not respond to Echo Requests even if this new option is enabled Default Format ip vrrp vrid accept mode Mod...

Страница 251: ...ro Priority Packets Sent The total number of VRRP packets sent by the virtual router with a priority of 0 Invalid Type Packets Received The total number of VRRP packets received by the virtual router...

Страница 252: ...01 01 Authentication Type None Priority 100 Configured priority 100 Advertisement Interval secs 1 Pre empt Mode Enable Administrative Mode Disable Accept Mode Enable State Initialized Track Interface...

Страница 253: ...tes at Layer 3 and forwards DHCP requests and replies between clients and servers when they are not on the same physical subnet bootpdhcprelay cidoptmode This command enables the circuit ID option mod...

Страница 254: ...t time in seconds for BootP DHCP Relay on the system When the BOOTP relay agent receives a BOOTREQUEST message it MAY use the seconds since client began booting field of the request as a factor in dec...

Страница 255: ...ce to another You can define many helper addresses but the total number of address port pairs is limited to 128 for the whole device The setting of a helper address for a specific interface has preced...

Страница 256: ...in isakmp mobile ip nameserver netbios dgm netbios ns ntp pim auto rip rip tacacs tftp time Mode ip helper enable Use this command to enable relay of UDP packets This command can be used to temporaril...

Страница 257: ...s ntp pim auto rip rip tacacs tftp time Mode ip helper address discard Use this command to drop matching packets Format ip helper address discard 1 65535 dhcp domain isakmp mobile ip nameserver netbio...

Страница 258: ...count includes DHCP messages and all other protocols relayed Conditions are similar to those for the first statistic in this table UDP clients messages relayed The number of UDP packets relayed This...

Страница 259: ...ommand sets the administrative mode of OSPF in the router to inactive Format no enable Mode network area OSPF Use this command to enable OSPFv2 on an interface and set its area ID if the IP address of...

Страница 260: ...s of the network area command It can also be used to configure the advertiseability of the secondary addresses on this interface into the OSPFv2 domain Default Format ip ospf area area id secondaries...

Страница 261: ...o area nssa This command disables nssa from the specified area id Format no area areaid nssa Mode area nssa default info originate OSPF This command configures the metric value and type for the defaul...

Страница 262: ...NSSA ABR so that learned external routes are redistributed to the NSSA Format no area areaid nssa no redistribute Mode area nssa no summary OSPF This command configures the NSSA so that summary LSAs...

Страница 263: ...ator stab intv stabilityinterval Mode no area nssa translator stab intv OSPF This command disables the nssa translator s stabilityinterval from the specified area id Format no area areaid nssa transla...

Страница 264: ...e summary prefix is advertised when the area range is active This is the default not advertise Optional When this keyword is given neither the summary prefix nor the contained prefixes are advertised...

Страница 265: ...interface from the given interface identified by areaid and neighbor The neighbor parameter is the Router ID of the neighbor Format no area areaid virtual link neighbor Mode area virtual link authenti...

Страница 266: ...virtual interface identified by areaid and neighbor The neighbor parameter is the Router ID of the neighbor The range for seconds is 1 to 65535 Default Format area areaid virtual link neighbor dead in...

Страница 267: ...r retransmit interval seconds Mode no area virtual link retransmit interval This command configures the default retransmit interval for the OSPF virtual interface on the virtual interface identified b...

Страница 268: ...Because the default reference bandwidth is 100 Mbps OSPF uses the same default link cost for all interfaces whose bandwidth is 100 Mbps or greater Use the auto cost command to change the reference ba...

Страница 269: ...tly by an application wishing to distribute information throughout the OSPF domain The 7000 series supports the storing and flooding of Opaque LSAs of different scopes Default Format capability opaque...

Страница 270: ...tional parameter unit slot port To drop adjacency with a specific router ID on a specific interface use the optional parameter neighbor id Format clear ip ospf neighbor interface unit slot port neighb...

Страница 271: ...metric of distributed routes Format default metric 1 16777214 Mode no default metric OSPF This command is used to set a default for the metric of distributed routes Format no default metric Mode dista...

Страница 272: ...ved from the source protocol Format no distribute list 1 199 out rip static connected Mode exit overflow interval OSPF This command configures the exit overflow interval for OSPF It describes the numb...

Страница 273: ...anges To enable logging of OSPFv2 neighbor state changes use this command in router configuration mode State changes are logged with INFORMATIONAL severity Default Format log adjacency changes detail...

Страница 274: ...ation This command sets the default OSPF Authentication Type for the specified interface Format no ip ospf authentication Mode ip ospf cost This command configures the cost on an OSPF interface The co...

Страница 275: ...rs attached to a common network This value should be some multiple of the Hello Interval i e 4 Valid values range in seconds from 1 to 2147483647 Default Format ip ospf dead interval seconds Mode no i...

Страница 276: ...ficiently by treating the network as a point to point network For point to point networks OSPF does not elect a designated router or generate a network link state advertisement LSA Both endpoints of t...

Страница 277: ...hour Default Format ip ospf retransmit interval 0 3600 Mode no ip ospf retransmit interval This command sets the default OSPF retransmit Interval for the specified interface Format no ip ospf retransm...

Страница 278: ...is not established Default Format ip ospf mtu ignore Mode no ip ospf mtu ignore This command enables the OSPF MTU mismatch detection Format no ip ospf mtu ignore Mode router id OSPF This command sets...

Страница 279: ...hs that OSPF can report for a given destination back to its default value Format no maximum paths Mode passive interface default OSPF Use this command to enable global passive mode by default for all...

Страница 280: ...s routing information in Link State Advertisements LSAs which are bundled into Link State Update LS Update packets To reduce the likelihood of sending a neighbor more packets than it can buffer OSPF r...

Страница 281: ...hen OSPF originates a new or changed LSA it selects a random refresh delay for the LSA When the refresh delay expires OSPF refreshes the LSA By selecting a random refresh delay OSPF avoids refreshing...

Страница 282: ...d packet config error virt authentication failure virt bad packet virt config error if rx lsa lsa maxage lsa originate overflow lsdb overflow lsdb approaching overflow retransmit packets virt packets...

Страница 283: ...acket lsa all lsa maxage lsa originate overflow all lsdb overflow lsdb approaching overflow retransmit all packets virt packets rtb all rtb entry info state change all if state change neighbor state c...

Страница 284: ...3 Compatibility Indicates whether 1583 compatibility is enabled or disabled This is a configured value External LSDB Limit The maximum number of non default AS external LSA link state advertisement en...

Страница 285: ...s been reduced External LSA Count The number of external LS type 5 link state advertisements in the link state database External LSA Checksum The sum of the LS checksums of external link state adverti...

Страница 286: ...The metric of the routes being redistributed If the metric is not configured this field is blank Metric Type Shows whether the routes are External Type 1 or External Type 2 Number of Active Areas The...

Страница 287: ...ernal OSPF routing table entries to Area Border Routers ABR This command takes no options Format show ip ospf abr Mode Privileged EXEC User EXEC Type intra Intra area route inter Inter area route Rout...

Страница 288: ...of link state advertisements in this area s link state database excluding AS External LSA s A number representing the Area LSA Checksum for the specified AreaID excluding the external LS type 5 link s...

Страница 289: ...The type of the route to the destination It can be one of the following values intra Intra area route inter Inter area route Router ID of the destination Cost of using this route The area ID of the ar...

Страница 290: ...router Use adv router to show the LSAs that are restricted by the advertising router self originate Use self originate to display the LSAs in that are self originated The information below is only dis...

Страница 291: ...s for the OSPF interface Secondary IP Address es The secondary IP addresses if any are configured on the interface OSPF Admin Mode States whether OSPF is enabled or disabled on a router interface OSPF...

Страница 292: ...cast The OSPF Interface Type will be broadcast The OSPF Interface States are down loopback waiting point to point designated router and backup designated router The router ID representing the designat...

Страница 293: ...s reachable within this area Area LSA Count The total number of link state advertisements in this area s link state database excluding AS External LSAs IP Address The IP address associated with this O...

Страница 294: ...pe The number of packets discarded because the authentication type specified in the OSPF header does not match the authentication type configured on the ingress interface Note This field only applies...

Страница 295: ...llo packet has recently been seen from the neighbor but bidirectional communication has not yet been established 2 way communication between the two routers is bidirectional Exchange start the first s...

Страница 296: ...with the interface An integer value that indicates the optional OSPF capabilities supported by the neighbor The neighbor s optional OSPF capabilities are also listed in its Hello packets This enables...

Страница 297: ...an how long the SPF took and the reasons why the SPF was scheduled Format show ip ospf statistics Modes Privileged EXEC User EXEC Delta T SPF Duration Reason R a router LSA has changed N a network LSA...

Страница 298: ...pe of service associated with the stub metric Switch CLI only supports Normal TOS The metric value is applied based on the TOS It defaults to the least metric of the type of service among the interfac...

Страница 299: ...o 0 10 0 500 ACK 2 12 0 1680 Data 24 47 0 500 Event 1 8 0 1000 show ip ospf virtual link This command displays the OSPF Virtual Interface information for a specific area and neighbor The areaid parame...

Страница 300: ...In helper mode a switch continues to advertise to the rest of the network that they have full adjacencies with the restarting router Hello Interval The configured hello interval for the OSPF virtual...

Страница 301: ...crash on the management unit nsf Use this command to enable the OSPF graceful restart functionality on an interface To disable graceful restart use the no form of the command no nsf Use this command t...

Страница 302: ...ormat nsf ietf restart interval 1 1800 Modes OSPF Router Configuration Parameter Description ietf This keyword is accepted but not required seconds The number of seconds that the restarting router ask...

Страница 303: ...raceful restart on a topology change a router tries to eliminate the loops or black holes as quickly as possible by routing around the restarting router A helpful neighbor considers a link down with t...

Страница 304: ...F is administratively in stub router mode the max metric router lsa command has been given and you configure OSPF to enter stub router mode on startup max metric router lsa on startup OSPF exits stub...

Страница 305: ...Description Half life period The number of seconds it takes for the penalty to reduce by half The configurable range is 1 30 seconds Default value is 5 seconds Reuse Threshold The value of the penalt...

Страница 306: ...red with dampening Format show interface dampening Mode Note The CLI command clear counters resets the flap count to zero The interface CLI command no shutdown resets the suppressed state to False Pri...

Страница 307: ...useTm HalfL ReuseV SuppV MaxSTm MaxP Restart 6 1865 TRUE 18 20 1000 2001 30 2828 1500 Routing Information Protocol RIP Commands This section describes the commands you use to view and configure RIP wh...

Страница 308: ...o summary This command disables the RIP auto summarization mode Format no auto summary Mode default information originate RIP This command is used to control the advertisement of default routes Format...

Страница 309: ...ter Lower route preference values are preferred when determining the best route A route with a preference of 255 cannot be used to forward traffic Default Format distance rip 1 255 Mode no distance ri...

Страница 310: ...0 and 255 must be specified Unauthenticated interfaces do not need an authentication key or authentication key ID Default Format ip rip authentication none simple key encrypt key keyid Mode no ip rip...

Страница 311: ...ersion 2 formatted packets via broadcast rip2 for sending RIP version 2 using multicast or none to not allow any RIP control packets to be sent Default Format ip rip send version rip1 rip1c rip2 none...

Страница 312: ...and configures RIP protocol to redistribute routes from the specified source protocol routers There are five possible match options When you submit the command redistribute ospf match match type the m...

Страница 313: ...d into single entries in order to reduce the total number of entries The default is enable Enable or disable If enabled the router accepts host routes The default is enable The number of route changes...

Страница 314: ...RIP interface This is a configured value The RIP version s used when sending updates on the specified interface The types are none RIP 1 RIP 1c RIP 2 This is a configured value The RIP version s allo...

Страница 315: ...nable the generation of ICMP Redirect messages by the router By default the generation of ICMP Redirect messages is disabled Default Format ip redirects Mode Global Config Interface Config no ip redir...

Страница 316: ...ten the token bucket is initialized with burst size tokens burst interval is from 0 to 2147483647 milliseconds msec The burst size is the number of ICMP error messages that can be sent during one burs...

Страница 317: ...mands display switch settings statistics and other information Configuration commands configure features and options of the switch For every configuration command there is a show command that displays...

Страница 318: ...ter to inactive Format no ip multicast Mode ip multicast ttl threshold This command is specific to IPv4 Use this command to apply the given Time to Live threshold value ttlthreshold to a routing inter...

Страница 319: ...incoming interface for the mroute preference is Administrative distance for the mroute The lower values have better preference If the static mroute has the same distance as the other RPF sources the...

Страница 320: ...ommand displays a summary or all the details of the multicast table Format show ip mcast mroute detail summary Modes Privileged EXEC User EXEC Table Max Size The maximum number of entries allowed in t...

Страница 321: ...terface Outgoing Interface List Term Definition The IP address of the multicast data source The IP address of the destination of the multicast packet The time of expiry of this entry in seconds The ti...

Страница 322: ...er the command displays the following column headings in the output table Source IP Group IP Protocol Incoming Interface Outgoing Interface List DVMRP Commands This section provides a detailed explana...

Страница 323: ...interface This value is used in the DVMRP messages as the cost to reach this network This field has a range of 1 to 31 Default Format ip dvmrp metric metric Mode no ip dvmrp metric This command reset...

Страница 324: ...dvmrp This command displays the system wide information for DVMRP Format show ip dvmrp Modes Privileged EXEC User EXEC Admin Mode Version Total Number of Routes Reachable Routes The following fields...

Страница 325: ...on for DVMRP Format show ip dvmrp neighbor Modes Privileged EXEC User EXEC Interface Mode The mode of this interface Possible values are Enabled and Disabled Operational stat us The current state of D...

Страница 326: ...alue for this field are ACTIVE or DOWN The time since this neighboring router was learned The time remaining for the neighbor to age out This field is not applicable if the State is DOWN The Generatio...

Страница 327: ...col that provides scalable inter domain multicast Term Definition The multicast Address that is pruned The IP address of the source that has pruned The network Mask for the prune source It should be a...

Страница 328: ...rmat no ip pim dense Mode ip pim Interface Config This command sets administrative mode of PIM on an interface to enabled Default Format ip pim Mode no ip pim Interface Config This command sets admini...

Страница 329: ...ode Sparse Hello Interval secs 30 Join Prune Interval secs 60 DR Priority 1 BSR Border Disabled Neighbor Count 1 Designated Router 192 168 10 1 Example 2 Switch show ip pim interface Interface 1 0 1 M...

Страница 330: ...02 55 00 01 15 NA Switch show ip pim neighbor Neighbor Addr Interface Uptime Expiry Time DR hh mm ss hh mm ss Priority 192 168 10 2 1 0 1 00 02 55 00 01 15 1 192 168 20 2 1 0 2 00 03 50 00 02 10 1 ip...

Страница 331: ...erval Mode hash mask length bar priority interval Global Config disabled Interface Config Interface Config Global Config Parameters Description Length of a mask 32 bits maximum that is to be ANDed wit...

Страница 332: ...ip pim dr priority Mode ip pim join prune interval This command is used to configure the interface join prune interval for the PIM router The join prune interval is specified in seconds This parameter...

Страница 333: ...a PIM candidate rendezvous point RP to the bootstrap router BSR Format ip pim rp candidate interface interface num group address group mask interval interval Mode interface num group address group mas...

Страница 334: ...ress group mask Mode ip pim trapflags This command enables the PIM trap mode for both Sparse Mode SM and Dense Mode DM Default Format ip pim trapflags Mode no ip pim trapflags This command sets the PI...

Страница 335: ...tional Status 1 0 1 Enabled Operational 1 0 3 Disabled Non Operational show ip pim ssm This command shows the configured source specific IP multicast addresses Format show ip pim ssm Mode Group Addres...

Страница 336: ...SR Priority 0 BSR Hash Mask Length 32 Next Bootstrap message hh mm ss 00 00 05 Next Candidate RP Advertisement hh mm ss 00 00 02 show ip pim rp hash This command displays the rendezvous point selected...

Страница 337: ...ss 192 168 10 1 Group Address 224 1 2 1 Group Mask 255 255 255 0 Origin Static Expiry Time hh mm ss NA RP Address 192 168 20 1 Group Address 229 2 0 0 Group Mask 255 255 0 0 Origin Static Expiry Time...

Страница 338: ...fault Format ip igmp Modes Global Config Interface Config no ip igmp This command sets the administrative mode of IGMP in the system to inactive Format no ip igmp Modes Global Config Interface Config...

Страница 339: ...Specific Queries which are sent in response to Leave Group messages The range for seconds is 0 to 255 tenths of a second Default Format ip igmp last member query interval seconds Modes no ip igmp las...

Страница 340: ...query max response time This command resets the maximum response time interval for the specified interface which is the maximum query response time advertised in IGMPv2 queries on this interface to th...

Страница 341: ...startup query count Mode ip igmp startup query interval This command sets the interval between General Queries sent on startup on the interface The time interval value is in seconds The range for inte...

Страница 342: ...led on the interface This is a configured value The current state of IGMP on this interface Possible values are Operational or Non Operational Privileged EXEC Term Definition The IP address of the int...

Страница 343: ...Group Compatibility Mode The group compatibility mode v1 v2 or v3 for this group on the specified interface Term Definition Valid slot and port number separated by forward slashes The administrative s...

Страница 344: ...parated by forward slashes The IP address of the interface participating in the multicast group The interface that has IGMP in Querier mode or Non Querier mode The group compatibility mode v1 v2 or v3...

Страница 345: ...here are no multicast routing protocols enabled on the router Format ip igmp proxy Mode no ip igmp proxy This command disables the IGMP Proxy on the router Format no ip igmp proxy Mode Term Definition...

Страница 346: ...e host interface status parameters of the IGMP Proxy router This command is valid only when you enable IGMP Proxy on the interface Format ip igmp proxy reset status Mode show ip igmp proxy This comman...

Страница 347: ...odes Privileged EXEC User EXEC Interface Index The column headings of the table associated with the interface are as follows Number of Multicast Groups The number of multicast groups that are associat...

Страница 348: ...reports received Report Sent Number of IGMP reports sent Leaves Rcvd Number of IGMP leaves received Valid for version 2 only Leaves Sent Number of IGMP leaves sent on the Proxy interface Valid for ve...

Страница 349: ...Privileged EXEC User EXEC Filter Mode Possible values are Include or Exclude Sources The number of sources attached to the multicast group Term Definition Interface The interface number of the IGMP P...

Страница 350: ...e 5 1 2 3 00 02 21 6 1 2 3 00 02 21 7 1 2 3 00 02 21 226 4 4 4 5 5 5 48 00 02 21 DELAY_MEMBER Include 3 Group Source List Expiry Time 2 1 2 3 00 02 21 6 1 2 3 00 01 44 8 1 2 3 00 01 44 227 4 4 4 5 5 5...

Страница 351: ...es and options of the switch For every configuration command there is a show command that displays the configuration setting Clear commands clear some or all of the settings to factory defaults Note F...

Страница 352: ...rs for the specified tunnel interface Format no interface tunnel tunnel id Mode tunnel source This command specifies the source transport address of the tunnel either explicitly or by reference to an...

Страница 353: ...se to configure IPv6 on the system and on the interfaces This section also describes IPv6 management commands and show commands ipv6 hop limit This command defines the unicast hop count used in ipv6 p...

Страница 354: ...t routing Mode no ipv6 unicast routing Use this command to disable the forwarding of IPv6 unicast datagrams Format no ipv6 unicast routing Mode ipv6 enable Use this command to enable IPv6 routing on a...

Страница 355: ...pping zeros 3ffe ffff 100 f101 0 0 0 1 becomes 3ffe ffff 100 f101 1 Local host 0000 0000 0000 0000 0000 0000 0000 0001 becomes 1 Any host 0000 0000 0000 0000 0000 0000 0000 0000 becomes The hexadecima...

Страница 356: ...the destination of the static route The prefix_length is the length of the IPv6 prefix a decimal value usually 0 64 that shows how many of the high order contiguous bits of the address comprise the pr...

Страница 357: ...d sets the default distance preference for IPv6 static routes Lower route distance values are preferred when determining the best route The ipv6 route command allows you to optionally set the distance...

Страница 358: ...alue to default value Format no ipv6 mtu Mode ipv6 nd dad attempts This command sets the number of duplicate address detection probes transmitted Duplicate address detection verifies that an IPv6 addr...

Страница 359: ...nd ns interval This command sets the interval between router advertisements for advertised neighbor solicitations in milliseconds An advertised value of 0 means the interval is unspecified Default Fo...

Страница 360: ...efault Format no ipv6 nd ra interval max Mode ipv6 nd ra lifetime This command sets the value in seconds that is placed in the Router Lifetime field of the router advertisements sent from the interfac...

Страница 361: ...6 nd reachable time Mode ipv6 nd suppress ra This command suppresses router advertisement transmission on an interface Default Format ipv6 nd suppress ra Mode no ipv6 nd suppress ra This command enabl...

Страница 362: ...interval Use this command to limit the rate at which ICMPv6 error messages are sent The rate limit is configured as a token bucket with two configurable parameters burst size and burst interval The b...

Страница 363: ...v6 Forwarding Mode Enable IPv6 Unicast Routing Mode Enable IPv6 Hop Limit 0 ICMPv6 Rate Limit Error Interval 1000 msec ICMPv6 Rate Limit Burst Size 100 messages Maximum Routes 3000 Global Config Privi...

Страница 364: ...terfaces with IPv6 enabled Term Definition IPv6 is enabled Appears if IPv6 is enabled on the interface Routing Mode Shows whether IPv6 routing is enabled or disabled Administrative Mode Shows whether...

Страница 365: ...Flag Autonomous Flag Router Advertisement Interval The frequency in seconds that router advertisements are sent Router Advertisement Managed Config Flag Shows whether the managed configuration flag is...

Страница 366: ...es including best and non best routes are displayed Otherwise only the best routes are displayed A T flag appended to an IPv6 route indicates that it is an ECMP route but only one of its next hops has...

Страница 367: ...Inter Area Reject routes routes of REJECT type installed by any protocol are not redistributed by OSPF RIP Reject routes are supported in both OSPFv2 and OSPFv3 Format show ipv6 route ipv6 address pr...

Страница 368: ...oute ecmp groups This command reports all current ECMP groups in the IPv6 routing table An ECMP group is a set of next hops used in one or more routes The groups are numbered arbitrarily from 1 to n T...

Страница 369: ...ination and therefore is not installed in the forwarding table When this keyword is not given the output reports for only the best routes Format show ipv6 route summary all Modes Privileged EXEC User...

Страница 370: ...d Locals The number of routing table entries reserved for a local subnet on a routing interface that is down Space for local routes is always reserved so that local routes can be installed when a rout...

Страница 371: ...gh 8 8 ECMP Groups High 3 3 ECMP Routes 12 Truncated ECMP Routes 0 ECMP Retries 0 Routes with 1 Next Hop 5 Routes with 2 Next Hops 1 Routes with 3 Next Hops 1 Routes with 4 Next Hops 10 Number of Pref...

Страница 372: ...r format errors hop count exceeded errors discovered in processing their IPv6 options etc Received Datagrams Discarded Due To MTU Number of input datagrams that could not be forwarded because their si...

Страница 373: ...lude only those packets which were Source Routed via this entity and the Source Route processing was successful Note that for a successfully forwarded datagram the counter of the outgoing interface in...

Страница 374: ...er of ICMP Router Advertisement messages received by the interface ICMPv6 Neighbor Solicit Messages Received Number of ICMP Neighbor Solicit messages received by the interface ICMPv6 Neighbor Advertis...

Страница 375: ...ages sent by the interface ICMPv6 Router Solicit Messages Transmitted Number of ICMP Router Solicitation messages sent by the interface ICMPv6 Router Advertisement Messages Transmitted Number of ICMP...

Страница 376: ...you use to route traffic within a network ipv6 ospf This command enables OSPF on a router interface or loopback interface Default Format ipv6 ospf Mode no ipv6 ospf This command disables OSPF on a rou...

Страница 377: ...lue for the length of time must be the same for all routers attached to a common network This value should be some multiple of the Hello Interval i e 4 Valid values range for seconds is from 1 to 2147...

Страница 378: ...ignore This command enables the OSPF MTU mismatch detection Format no ipv6 ospf mtu ignore Mode ipv6 ospf network This command changes the default OSPF network type for the interface Normally the net...

Страница 379: ...spf priority Mode ipv6 ospf retransmit interval This command sets the OSPF retransmit Interval for the specified interface The retransmit interval is specified in seconds The value for seconds is the...

Страница 380: ...command sets the default OSPF Transit Delay for the specified interface Format no ipv6 ospf transmit delay Mode ipv6 router ospf Use this command to enter Router OSPFv3 Config mode Format ipv6 router...

Страница 381: ...a areaid nssa default info originate metric comparable non comparable Mode no area nssa default info originate OSPFv3 This command disables the default route advertised into the NSSA Format no area ar...

Страница 382: ...ate in the translator election process when it attains border router status Format area areaid nssa translator role always candidate Mode no area nssa translator role OSPFv3 This command disables the...

Страница 383: ...mmarylink nssaexternallink advertise not advertise Mode no area range OSPFv3 This command deletes a specified area range The ipaddr is a valid IP address The subnetmask is a valid subnet mask Format n...

Страница 384: ...or Format area areaid virtual link neighbor Mode no area virtual link OSPFv3 This command deletes the OSPF virtual interface from the given interface identified by areaid and neighbor The neighbor par...

Страница 385: ...ormat area areaid virtual link neighbor hello interval seconds Mode no area virtual link hello interval OSPFv3 This command configures the default hello interval for the OSPF virtual interface on the...

Страница 386: ...nsmit delay Mode auto cost OSPFv3 By default OSPF computes the link cost of each interface from the interface bandwidth Faster links have lower metrics making them more attractive in route selection T...

Страница 387: ...ear ipv6 ospf counters Use this command to reset global and interface statistics Format clear ipv6 ospf counters Mode clear ipv6 ospf neighbor Use this command to drop the adjacency with all OSPF neig...

Страница 388: ...originate prefixes as necessary Format clear ipv6 ospf redistribution Mode default information originate OSPFv3 This command is used to control the advertisement of default routes Default metric unspe...

Страница 389: ...Format distance ospf intra area 1 255 inter area 1 255 external 1 255 Mode no distance ospf OSPFv3 This command sets the default route preference value of OSPF routes in the router The type of OSPF r...

Страница 390: ...exit overflow interval Mode external lsdb limit OSPFv3 This command configures the external LSDB limit for OSPF If the value is 1 then there is no limit When the number of non default AS external LSAs...

Страница 391: ...passive mode OSPF shall not form adjacencies over a passive interface Default Format passive interface default Mode no passive interface default OSPFv3 Use this command to disable the global passive...

Страница 392: ...otocol routers Default metric unspecified type 2 tag 0 Format redistribute static connected metric 0 16777214 metric type 1 2 tag 0 4294967295 Mode no redistribute OSPFv3 This command configures OSPF...

Страница 393: ...ups OSPFv3 errors authentication failure bad packet config error virt authentication failure virt bad packet virt config error if rx lsa lsa maxage lsa originate overflow lsdb overflow lsdb approachin...

Страница 394: ...disable the individual flag enter the group name followed by that particular flag To disable all the flags in that group give the group name followed by all To disable all the flags give the command...

Страница 395: ...finity To restore OSPF to normal operation disable and re enable OSPF Exit Overflow Interval The number of seconds that after entering overflow state a router will attempt to leave overflow state Exte...

Страница 396: ...c Type Shows whether the routes are External Type 1 or External Type 2 Number of Active Areas The number of active OSPF areas An active OSPF area is an area with at least one interface up AutoCost Ref...

Страница 397: ...rea ID The area ID of the area from which this route is learned Next Hop Next hop toward the destination Next Hop Intf The outgoing router interface to use when forwarding traffic to the next hop Term...

Страница 398: ...enabled OSPF Stub Metric Value The metric value of the stub area This field displays only if the area is a configured as a stub area Term Definition Shows whether to import summary LSAs into the NSSA...

Страница 399: ...in that are self originated The information below is only displayed if OSPF is enabled Format show ipv6 ospf areaid database external inter area prefix router link network nssa external prefix router...

Страница 400: ...Fv3 link state database Total number of inter area prefix LSAs in the OSPFv3 link state database Total number of inter area router LSAs in the OSPFv3 link state database Total number of NSSA external...

Страница 401: ...is down LSA Ack Interval The amount of time in seconds the interface waits before sending an LSA acknowledgement after receiving an LSA Iftransit Delay Interval The number of seconds the interface ad...

Страница 402: ...own Retransmit Interval The frequency in seconds at which the interface sends LSA Retransmit Delay Interval The number of seconds the interface adds to the age of LSA packets before transmission LSA A...

Страница 403: ...ing the packet Bad Version The number of received OSPF packets whose version field in the OSPF header does not match the version of the OSPF process handling the packet Virtual Link Not Found The numb...

Страница 404: ...k LSAs Dead Time If you specify an IP address for the neighbor router the following fields display Term Definition The 4 digit dotted decimal number of the neighbor router The OSPF priority for the sp...

Страница 405: ...rent length of the retransmission queue of the specified neighbor router Id of the specified interface Term Definition Area ID The area id of the requested OSPF area IP Address An IP address which rep...

Страница 406: ...The configured hello interval for the OSPF virtual interface Dead Interval The configured dead interval for the OSPF virtual interface Iftransit Delay Interval The configured transit delay for the OS...

Страница 407: ...mplements both the restarting router and helpful neighbor features described in RFC 3623 nsf OSPFv3 This command enables OSPF graceful restart The ietf parameter is used to distinguish the IETF standa...

Страница 408: ...restarting router will not immediately update its forwarding table Therefore a topology change might introduce forwarding loops or black holes that persist until the graceful restart is completed By e...

Страница 409: ...ne supported this parameter is optional The seconds parameter represents the number of seconds that the restarting router asks its neighbors to wait before exiting helper mode The restarting router in...

Страница 410: ...Relay Agent Information Option remote ID sub option to be added to relayed messages This can either be the special keyword duid ifid which causes the remote ID to be derived from the DHCPv6 server DUI...

Страница 411: ...can have up to eight domain names Format domain name dns domain name Mode no domain name This command removes the DHCPv6 domain name from the DHCPv6 pool Format no domain name dns domain name Mode dn...

Страница 412: ...lid lifetime 2592000 preferred lifetime 604800 Format prefix delegation prefix prefixlength DUID name hostname valid lifetime 0 4294967295 preferred lifetime 0 4294967295 Mode no prefix delegation Thi...

Страница 413: ...Relay forward Packets Received Number of relay forward received statistics DHCPv6 Relay reply Packets Received Number of relay reply received statistics DHCPv6 Malformed Packets Received Number of ma...

Страница 414: ...HCP statistics for the specified interface See show ipv6 dhcp statistics on page 412 for information about the output clear ipv6 dhcp Use this command to clear DHCPv6 statistics for all interfaces or...

Страница 415: ...using the combination of the local system burned in MAC address and a timestamp value Name of the client IPv6 address and mask length for delegated prefix Preferred lifetime in seconds for delegated...

Страница 416: ...IPv6 Commands 416 ProSafe Managed Switch Valid Lifetime Valid lifetime in seconds for delegated prefix Preferred Lifetime Preferred lifetime in seconds for delegated prefix Term Definition...

Страница 417: ...nds in this chapter are in three functional groups Show commands display switch settings statistics and other information Configuration commands configure features and options of the switch For every...

Страница 418: ...ags timer settings incoming and outgoing interfaces RPF neighboring routers and expiration times of all the entries in the multicast mroute table containing the given group IPv6 address group address...

Страница 419: ...ng column headings in the output table Term Definition Source IP The IP address of the multicast data source Group IP The IP address of the destination of the multicast packet Protocol The multicast r...

Страница 420: ...DM Multicast Routing Mode either across the router Global Config or on a particular router Interface Config Format no ipv6 pim dense Mode ipv6 pim Interface Config Use this command to set the administ...

Страница 421: ...v6 pim Mode Privileged EXEC User EXEC Example The following shows example CLI display output for the command Switch show ipv6 pim PIM Mode Dense Data Threshold Rate Kbps 0 Register Rate limit Kbps 0 I...

Страница 422: ...v6 pim neighbor unit slot port vlan Modes Privileged EXEC User EXEC Term Definition Interface Valid slot and port number separated by forward slashes Neighbor Address The IP address of the neighbor on...

Страница 423: ...om being the BSR border Format no ipv6 pim bsr border Mode ipv6 pim bsr candidate Use this command to configure the router to announce its candidacy as a bootstrap router BSR Default Format ipv6 pim b...

Страница 424: ...rune interval for the PIM SM router The join prune interval is specified in seconds This parameter can be configured to a value from 0 to 18000 Parameters Description Length of a mask 32 bits maximum...

Страница 425: ...if there is a conflict the RP configured with this command prevails over the RP learned by BSR Default Format ipv6 pim rp address rp address group address group mask override Mode no ipv6 pim rp addr...

Страница 426: ...s command to disable the Source Specific Multicast SSM range Format no ipv6 pim ssm Mode show ipv6 pim bsr router Use command to display the bootstrap router BSR information The output includes electe...

Страница 427: ...st group registrations However some network setup does not need a multicast router as multicast traffic is destined to hosts within the same network In this situation the 7000 series has an IGMP MLD S...

Страница 428: ...the router is the querier on that interface The range for query interval is 1 to 3600 seconds Default Format ipv6 mld query interval query interval Mode no ipv6 mld query interval Use this command to...

Страница 429: ...al Mode no ipv6 mld last member query interval Use this command to reset the last member query interval parameter of the interface to the default value Format no ipv6 mld last member query interval Mo...

Страница 430: ...Expiry Time Field Description The address of the multicast group Interface through which the multicast group is reachable Time elapsed in hours minutes and seconds since the multicast group has been k...

Страница 431: ...nclude Version1 Host Timer Group compat mode v2 Source Address ExpiryTime 2003 10 00 04 17 2003 20 00 04 17 show ipv6 mld interface Use this command to display MLD related information for the interfac...

Страница 432: ...number of Queries sent out on startup separated by the Startup Query Interval Last Member Query Interval This value indicates the configured Maximum Response Time inserted into Group Specific Queries...

Страница 433: ...de no ipv6 mld proxy Use this command to disable MLD Proxy on the router Format no ipv6 mld proxy Mode Field Description Valid MLD Packets Received The number of valid MLD packets received by the rout...

Страница 434: ...he host interface status parameters of the MLD Proxy router This command is only valid when you enable MLD Proxy on the interface Format ipv6 mld proxy reset status Mode show ipv6 mld proxy Use this c...

Страница 435: ...e column headings of the table associated with the interface are as follows Number of Multicast Groups The number of multicast groups that are associated with the MLD Proxy interface Unsolicited Repor...

Страница 436: ...of MLD leaves received Valid for version 2 only Leaves Sent Number of MLD leaves sent on the Proxy interface Valid for version 2 only Field Description Interface The interface number of the MLD Proxy...

Страница 437: ...oup Source List Expiry Time 2001 1 00 02 40 Field Description Interface The interface number of the MLD Proxy Group Address The IP address of the multicast group Last Reporter The IP address of the ho...

Страница 438: ...243 DELAY_MEMBER Include 1 Group Source List Expiry Time 3001 1 00 03 32 3002 2 00 03 32 FF1E 3 FE80 100 2 3 328 DELAY_MEMBER Exclude 0 FF1E 4 FE80 100 2 3 255 DELAY_MEMBER Include 4 Group Source Lis...

Страница 439: ...Access Control List ACL Commands Time Range Commands for Time Based ACLs AutoVOIP iSCSI Commands The commands in this chapter are in two functional groups Show commands display switch settings statis...

Страница 440: ...dot1p mapping This command maps each 802 1p priority to its default internal traffic class value Format no classofservice dot1p mapping Modes Global Config Interface Config classofservice ip dscp map...

Страница 441: ...sofservice trust command to set the mode to the default value no classofservice trust This command sets the interface mode to the default value Format no classofservice trust Modes Global Config Inter...

Страница 442: ...os queue random detect This command activates weighted random early discard WRED for each specified queue on the interface Specific WRED parameters are configured using the randomdetect queue parms an...

Страница 443: ...o random detect exponential weighting constant 0 15 Modes Global Config Interface Config random detect queue parms Use this command to configure WRED parameters for each drop precedence level supporte...

Страница 444: ...nterface as a whole Also known as rate shaping traffic shaping has the effect of smoothing temporary traffic bursts over time so that the transmitted traffic rate is bounded Format traffic shape bw Mo...

Страница 445: ...ice ip dscp mapping This command displays the current IP DSCP mapping to internal traffic classes for the global configuration settings Format show classofservice ip dscp mapping Mode The following in...

Страница 446: ...Term Definition The traffic class used for non IP traffic This is only displayed when the COS trust mode is set to trust IP Precedence or IP DSCP on platforms that support IP DSCP The traffic class us...

Страница 447: ...it finds a class match within that policy The following rules apply when you create a DiffServ class Each class can contain a maximum of one referenced nested class Class definitions do not support h...

Страница 448: ...ti Field MF classes of traffic name match criteria This set of commands consists of class creation deletion and matching with the class match commands specifying Layer 3 Layer 2 and general match crit...

Страница 449: ...ap Config when this command is successfully executed depending on the ipv4 ipv6 keyword specified no class map This command eliminates an existing DiffServ class The class map name is the name of an e...

Страница 450: ...e is the name of an existing DiffServ class whose match conditions are being referenced by the specified class definition Default none Format match class map refclassname Mode Note the following The p...

Страница 451: ...ged packet or the first or outer 802 1Q tag of a double VLAN tagged packet The value may be from 0 to 7 Default Format match cos 0 7 Mode match secondary cos This command adds to the specified class d...

Страница 452: ...arameter specifies an IP address The ipmask parameter specifies an IP address bit mask and must consist of a contiguous set of leading 1 bits Default Format match dstip ipaddr ipmask Mode match dstip6...

Страница 453: ...2 af43 be cs0 cs1 cs2 cs3 cs4 cs5 cs6 cs7 ef Note The ip dscp ip precedence and ip tos match conditions are alternative ways to specify a match criterion for the same Service Type field in the IP head...

Страница 454: ...ame Service Type field in the IP header but with a slightly different user notation Note This free form version of the IP DSCP Precedence TOS match specification gives the user complete control when s...

Страница 455: ...it hexadecimal numbers separated by colons e g ff 07 23 ff fe dc Default Format match source address mac address macmask Mode match srcip This command adds to the specified class definition a match co...

Страница 456: ...required The port number is an integer from 0 to 65535 Default Format match srcl4port portkey 0 65535 Mode match vlan This command adds to the specified class definition a match condition based on the...

Страница 457: ...cy The first class you add has the highest precedence This set of commands consists of policy creation deletion class addition removal and individual policy attributes Note The only way to remove an i...

Страница 458: ...form color class map Used in conjunction with the police command where the fields for the conform level are specified The class map name parameter is the name of an existing DiffServ class map Note Th...

Страница 459: ...value in the priority field of the 802 1p header the only tag in a single tagged packet or the first or outer 802 1Q tag of a double VLAN tagged packet If the packet does not already contain this head...

Страница 460: ...command is used to establish the traffic policing style for the specified class The simple form of the police command uses a single data rate and burst size resulting in two outcomes conform and viol...

Страница 461: ...transmit set dscp transmit set prec transmit or transmit In this two rate form of the police command the conform action defaults to send the exceed action defaults to drop and the violate action defau...

Страница 462: ...service commands to assign a DiffServ traffic conditioning policy which you specified by using the policy commands to an interface in the incoming direction The service commands attach a defined poli...

Страница 463: ...parameter is the name of an existing DiffServ policy Note This command causes a service to remove its reference to the policy This command effectively disables DiffServ on an interface in the inbound...

Страница 464: ...criterion defined for the class is evaluated simultaneously and must all be true to indicate a class match The Layer 3 protocol for this class Possible values are IPv4 and IPv6 The Match Criteria fiel...

Страница 465: ...the maximum allowed entries rows in the Class Table The current number of entries rows and the maximum allowed entries rows in the Class Rule Table The current number of entries rows and the maximum a...

Страница 466: ...pecified Mark IP Precedence The mark re mark value used as the IP Precedence for traffic matching this class This is not displayed if mark ip precedence is not specified Mirror Copies a classified tra...

Страница 467: ...y inbound is supported Class Members List of all class names associated with this policy Privileged EXEC Term Definition The current setting of the DiffServ administrative mode An attached policy is o...

Страница 468: ...on Format show service policy in out Mode OperStatus The current operational status of this DiffServ service interface Policy Name The name of the policy attached to the interface in the indicated dir...

Страница 469: ...Ethernet II frame types The maximum number of rules per MAC ACL is hardware dependent mac access list extended This command creates a MAC Access Control List ACL identified by name consisting of class...

Страница 470: ...t be deleted and re specified Note An implicit deny all MAC rule always terminates the access list A rule may either deny or permit traffic according to the specified classification fields At a minimu...

Страница 471: ...of a particular hardware queue for handling traffic that matches this rule The allowed queue id value is 0 n 1 where n is the number of user configurable queues available for the hardware platform Th...

Страница 472: ...and specified in Interface Config mode only affects a single interface whereas the Global Config mode setting is applied to all interfaces The VLAN keyword is only valid in the Global Config mode The...

Страница 473: ...ACLs regardless of type The maximum number of rules per IP ACL is hardware dependent Wildcard masking for ACLs operates differently from a subnet mask A wildcard mask is in essence the inverse of a su...

Страница 474: ...queue id mirror redirect unit slot port Mode Global Config Global Config Parameter Description 1 99 or 100 199 Range 1 to 99 is the access list number for an IP standard ACL Range 100 to 199 is the a...

Страница 475: ...ou successfully execute this command precedence precedence tos tos tosmask dscp dscp Specifies the TOS for an IP ACL rule depending on a match of precedence or DSCP values using the parameters dscp pr...

Страница 476: ...The no form of this command is not supported since the rules within an IP ACL cannot be deleted individually Rather the entire IP ACL must be deleted and re specified Note An implicit deny all IP rul...

Страница 477: ...he burst size in kbytes and allowed rate of traffic in kbps The conforming traffic is allowed to transmit and non conforming traffic is dropped This action is ignored for any deny rule since by defini...

Страница 478: ...flags Mode no acl trapflags This command disables the ACL trap mode Format no acl trapflags Mode show ip access lists This command displays an IP ACL accesslistnumber is the number used to identify th...

Страница 479: ...source IP Mask for this rule Source L4 Port Keyword The source port for this rule Destination IP Address The destination IP address for this rule Destination IP Mask The destination IP Mask for this...

Страница 480: ...6 access list If an IPv6 ACL by this name already exists this command enters IPv6 Access List config mode to allow updating the existing IPv6 ACL Note The CLI mode changes to IPv6 Access List Config m...

Страница 481: ...d Note An implicit deny all IPv6 rule always terminates the access list A rule may either deny or permit traffic according to the specified classification fields At a minimum either the every keyword...

Страница 482: ...iven direction The name parameter must be the name of an existing IPv6 ACL An optional sequence number may be specified to indicate the order of this mac access list relative to other IPv6 access list...

Страница 483: ...e Range Name Rule Status Privileged EXEC Term Definition The ordered rule number identifier defined within the IPv6 ACL The action associated with each rule The possible values are Permit or Deny Indi...

Страница 484: ...ace characters If a time range by this name already exists this command enters Time Range config mode to allow updating the time range entries Note When you successfully execute this command the CLI m...

Страница 485: ...ingle day or combinations of days Monday Tuesday Wednesday Thursday Friday Saturday Sunday Other possible values are daily Monday through Sunday weekdays Monday through Friday weekend Saturday and Sun...

Страница 486: ...VoIP streams automatically both data and signaling It detects the VoIP streams in two modes Protocol based Auto VoIP In a VoIP system various signaling protocols are used to establish the connection b...

Страница 487: ...voice session OUI based auto VOIP prioritizes the phone traffic based on the known OUI of the phone Format auto voip protocol based oui based Mode Global Config Interface Config Default no auto voip...

Страница 488: ...figured OUI then the priority of traffic from the phone is changed to OUI priority configured through this command Format auto voip oui based priority priority value Mode Default no auto voip oui base...

Страница 489: ...sed remark remark priority traffic class tc Mode Global Config Interface Config show auto voip interface This command shows the configuration of the auto voip per port Format show auto voip interface...

Страница 490: ...of classifier rules giving the data packets for the session the desired QoS treatment Installing and removing classifier rule sets as needed for the iSCSI session traffic Monitoring activity in the i...

Страница 491: ...recommended to specify the target IP address as well so the switch will only snoop frames with which the TCP destination port is one of the configured TCP ports AND there destination IP is the target...

Страница 492: ...ake care of configuring the relevant Class of Service parameters for the queue in order to complete the setting Setting the VPT DSCP sets the QoS profile which determines the egress queue to which the...

Страница 493: ...iscsi cos This command is to set the quality of service profile of SCSI flows to default Format no iscsi cos traffic class vpt vpt dscp dscp remark Mode iscsi aging time The iscsi aging time Global Co...

Страница 494: ...ing time 60 min Maximum number of sessions is 256 iSCSI targets and TCP ports TCP Port Target IP Address Name 860 3260 5000 30001 172 16 1 1 iqn 1993 11 com disk vendor diskarrays sn 45678 tape sys1 x...

Страница 495: ...essions detailed Target iqn 1993 11 com disk vendor diskarrays sn 45678 Session 1 Initiator iqn 1992 04 com os vendor plan9 cdrom 12 storage sys1 xyz Time started 17 Jul 2008 10 04 50 Time for aging o...

Страница 496: ...n only 12 95 watts is assured to be available at the powered device PD The PD needs to be designed so that it can accept power over Ethernet cabling Category 3 cables can be used to deliver power to t...

Страница 497: ...e on a global basis or per interface It is used to configure which types of PDs will be detected and powered by the switch There are three options ieee Detect resistive type devices IEEE standard pre...

Страница 498: ...device capable of figuring out power requirements through 2 event classification or LLDP no poe high power Use this command to disable the high power mode The port will support only IEEE 902 3af devi...

Страница 499: ...ower is calculated as follows Static Power Management Available power power limit of the source total allocated power Where total allocated power is calculated as the power limit configured on the por...

Страница 500: ...ed ports For ports that have the same priority level the lower numbered port will have higher priority There are three options Crit Critical priority High High priority Low Low priority no poe priorit...

Страница 501: ...ng the existing time range commands This schedule has start and stop times When this timer schedule is applied to a PoE enabled port the capability of the port to deliver power is affected At the sche...

Страница 502: ...n the threshold power in the preceding case 270 watts then the devices continue to power up If the consumed power is 269 watts or less the next device is powered up The moment consumed power exceeds t...

Страница 503: ...amount of power that can be delivered by this PoE unit when on RPS Total Power PD This indicates the maximum amount of power that can be delivered by this PoE unit when on the PD source This field is...

Страница 504: ...nd to see how the PoE ports are configured You can display information based on each individual port or all the ports collectively Switch show poe port configuration all Admin Power Power Limit High P...

Страница 505: ...age Status Fault W W mA volt Status 1 0 1 Yes 32 0 Unknown 00 000 0 00 00 Searching No Error Switch show poe port info 1 0 33 High Max Output Output Format show poe port info port all Mode Privileged...

Страница 506: ...LLDP PSE detects the PD in LLDP mode 802 1at Powered Receiving power from PSE Off No power from the PSE when main AC is in used Example switch show poe pd all Intf Mode Class Detection Mode Status 0...

Страница 507: ...Cable Test Command sFlow Commands Software License Commands IP Address Conflict Commands Link Local Protocol Filtering Commands not supported on M4100 switches RMON Stats and History Commands UDLD Com...

Страница 508: ...re are three steps to Auto Install 1 Configuration or assignment of an IP address for the device 2 Assignment of a TFTP server 3 Obtain a configuration file for the device from the TFTP server show au...

Страница 509: ...l start Mode boot autoinstall stop The command is used to A user may terminate the Auto Install process at any time prior to the downloading of the config file This is most optimally done when the swi...

Страница 510: ...s not change the current behavior of AutroInstall and saves the command to NVRAM Format no boot host dhcp Mode erase startup config Use this command to erase the text based configuration file stored i...

Страница 511: ...ntifies the node on which this command must be executed When this parameter is not supplied the command is executed on all nodes in a Stack Format boot system unit image file name Mode show bootvar Th...

Страница 512: ...d configurations show arp switch This command displays the contents of the IP stack s Address Resolution Protocol ARP table The IP stack only learns ARP entries associated with the management interfac...

Страница 513: ...are command will not be available For a description of the command output see the command show version on page 513 show version This command displays inventory information for the switch Note The show...

Страница 514: ...d replaceable unit number Manufacturer Manufacturer descriptor field Burned in MAC Address Universally assigned network address Software Version The release version revision number of the code current...

Страница 515: ...0 0 0 0 11 0 0 0 0 Term Definition The total number of packets including broadcast packets and multicast packets received by the processor The total number of packets received that were directed to t...

Страница 516: ...The total number of packets including bad packets received that were between 65 and 127 octets in length inclusive excluding framing bits but including FCS octets Packets Received 128 255 Octets The...

Страница 517: ...ctets Packets RX and TX 1523 2047 Octets The total number of packets received and transmitted that were between 1523 and 2047 octets in length inclusive excluding framing bits but including FCS octets...

Страница 518: ...clusive but had a bad Frame Check Sequence FCS with an integral number of octets Overruns The total number of frames discarded as this port was overloaded with incoming packets and could not keep up w...

Страница 519: ...ets The total number of packets transmitted that were longer than 1518 octets excluding framing bits but including FCS octets and were otherwise well formed Max Frame Size The maximum size of the Info...

Страница 520: ...f times attempted GVRP registrations could not be completed GMRP PDUs Received The count of GMRP PDUs received in the GARP layer GMRP PDUs Transmitted The count of GMRP PDUs transmitted from the GARP...

Страница 521: ...Multicast Packets Transmitted The total number of packets that higher level protocols requested be transmitted to a Multicast address including those that were discarded or not sent Broadcast Packets...

Страница 522: ...value of the corresponding instance was learned by observing the source MAC addresses of incoming traffic and is currently in use Management The value of the corresponding instance system MAC address...

Страница 523: ...tabase that were manually entered by a user Number of MAC addresses currently in the forwarding database Number of MAC addresses the forwarding database can handle Global Config Parameter Description...

Страница 524: ...10 dot1s_timer_task 0 10 dhcpsPingTask 0 20 show mbuf total This command shows the total system buffer pools status Format Mode The following shows an example of CLI display output for the command swi...

Страница 525: ...with a file name extension of scr the output is redirected to a script file Note If you issue the show running config command from a serial connection access to the switch through remote connections s...

Страница 526: ...display system and configuration information when you contact technical support The output of this command combines the output of the following commands show version show sysinfo Privileged EXEC show...

Страница 527: ...by configuring on different Line Config modes telnet ssh and console and is persistent Default Format length 0 5 48 Mode no length value Use this command to set the pagination length to the default v...

Страница 528: ...r notification is generated once the available free memory rises to 10 percent above the specified threshold To prevent generation of excessive notifications when the CPU free memory fluctuates around...

Страница 529: ...when the log file reaches full capacity logging stops Default Format logging buffered wrap Mode no logging buffered wrap This command disables wrapping of in memory logging and configures logging to...

Страница 530: ...This command enables logging to a host You can configure up to eight hosts The ipaddr hostname is the IP address of the logging host The addresstype indicates the type of address ipv4 or ipv6 or dns b...

Страница 531: ...logging Format no logging syslog Mode logging syslog source interface This command configures the syslog source interface Format logging syslog source interface u s p loopback loopback id tunnel tunne...

Страница 532: ...ther buffered logging is enabled Syslog Logging Shows whether syslog logging is enabled Log Messages Received Number of messages received by the log process This includes messages that are dropped or...

Страница 533: ...Format logging persistent severity level Mode Severity Level The minimum severity to log to the specified address The possible values are emergency 0 alert 1 critical 2 error 3 warning 4 notice 5 inf...

Страница 534: ...critical 2 error 3 warning 4 notice 5 info 6 or debug 7 Default Format logging email severitylevel Mode no logging email This command disables email alerting Format no logging email Mode logging emai...

Страница 535: ...mple admin yourcompany com Format logging email message type urgent non urgent both to addr to email addr Mode no logging email message type to addr This command removes the configured to addr field o...

Страница 536: ...how frequently non urgent email messages are sent Non urgent messages are collected and sent in a batch email at the specified interval The valid range is every 30 1440 minutes Default Format logging...

Страница 537: ...ress Table Email Alert Subject Table For Msg Type urgent subject is For Msg Type non urgent subject is Global Config Global Config Privileged EXEC Term Definition The administrative status of the feat...

Страница 538: ...e the mode to Mail Server Configuration mode The server address can be in the IPv4 IPv6 or DNS name format Format mail server ip address ipv6 address hostname Mode no mail server Use this command to r...

Страница 539: ...o security i e none it is 25 However any nonstandard port in the range 1 to 65535 is also allowed Default Format port 465 25 1 65535 Mode username Use this command to configure the login ID that the s...

Страница 540: ...ovide a synchronous response when initiated from the CLI Default count 3 probes interval 3 seconds size 0 bytes port 33434 maxTtl 30 hops maxFail 5 probes initTtl 1 hop Format traceroute ipaddr hostna...

Страница 541: ...4 1 1 289 msec 327 msec 282 msec 5 10 254 21 2 287 msec 293 msec 296 msec 6 192 168 76 2 290 msec 291 msec 289 msec 7 0 0 0 0 0 msec Parameter Description The ipaddr value should be a valid IP address...

Страница 542: ...ress hostname port port Mode clear config This command resets the configuration to the factory defaults without powering off the switch When you issue this command a prompt appears to confirm that the...

Страница 543: ...se Format clear igmpsnooping Mode clear pass This command resets all user passwords to the factory defaults without powering off the switch You are prompted to confirm that the password reset should p...

Страница 544: ...s Format enable password password encrypted Mode logout This command closes the current telnet connection or resets the current serial connection Note Save configuration changes before logging out pin...

Страница 545: ...se Unreachable Destination Received Response Unreachable Destination 192 168 254 222 PING statistics 3 packets transmitted 3 packets received 0 packet loss round trip msec min avg max 0 0 0 In Case Of...

Страница 546: ...ecify the network port interface by using the network parameter Defaults The default count is 1 The default interval is 3 seconds The default size is 0 bytes Format ping ipv6 ipv6 global address hostn...

Страница 547: ...and downloads files to and from the switch You can also use the copy command to manage the dual images image1 and image2 on the file system Upload and download files from a server by using TFTP or Xmo...

Страница 548: ...tup configuration nvram clibanner url Copies the CLI banner to a server nvram errorlog url Copies the error log file to a server nvram log url Copies the log file to a server nvram script scriptname u...

Страница 549: ...on page 630 url nvram sslpem server Downloads an HTTP secure server certificate url nvram startup config Downloads the startup configuration file to the system url nvram system image Downloads a code...

Страница 550: ...interval This command sets the poll interval for SNTP broadcast clients in seconds as a power of two where poll interval can be a value from 6 to 10 Default Format sntp broadcast client poll interval...

Страница 551: ...icast client poll interval This command sets the poll interval for SNTP unicast clients in seconds as a power of two where poll interval can be a value from 6 to 10 Default Format sntp unicast client...

Страница 552: ...l retry Mode sntp server This command configures an SNTP server a maximum of three The optional priority can be a value of 1 3 the version a value of 1 4 and the port id a value of 1 65535 Format sntp...

Страница 553: ...k summer time recurring Use the clock summer time recurring command to set the summertime offset to UTC recursively every year If the optional parameters are not specified they are read as either 0 or...

Страница 554: ...Range 1 31 month Month Range The first three letters by name jan for example year Year Range 2000 2097 hh mm Time in 24 hour format in hours and minutes Range hh 0 23 mm 0 59 offset Number of minutes...

Страница 555: ...NTP Version Port Client Mode Format no clock summer time Mode Global Config Privileged EXEC Term Definition Time of last clock update Time of last transmit query in unicast mode Status of the last SNT...

Страница 556: ...me of configured SNTP Server Address Type of Server Claimed stratum of the server for the last received valid packet Reference clock identifier of the server for the last received valid packet SNTP Se...

Страница 557: ...in administration address allocations ip dhcp pool This command configures a DHCP address pool name on a DHCP server and enters DHCP pool configuration mode Default Format ip dhcp pool name Mode no ip...

Страница 558: ...col Parameters section of RFC 1700 Assigned Numbers for a list of media type codes Default Format client identifier uniqueidentifier Mode no client identifier This command deletes the client identifie...

Страница 559: ...no dns server Mode hardware address This command specifies the hardware address of a DHCP client Hardware address is the MAC address of the hardware platform of the client consisting of 6 bytes in dot...

Страница 560: ...between 1 86400 minutes If you specify infinite the lease is set for 60 days You can also specify a lease duration Days is an integer from 0 to 59 Hours is an integer from 0 to 23 Minutes is an integ...

Страница 561: ...file Mode domain name This command specifies the domain name for a DHCP client The domain specifies the domain name string of the client Default Format domain name domain Mode no domain name This comm...

Страница 562: ...ures the NetBIOS node type for Microsoft Dynamic Host Configuration Protocol DHCP clients type specifies the NetBIOS node type Valid types are b node Broadcast p node Peer to peer m node Mixed h node...

Страница 563: ...ple a3 4f 22 0c colon for example a3 4f 22 0c or white space for example a3 4f 22 0c Default Format option code ascii string hex string1 string2 string8 ip address1 address2 address8 Mode no option Th...

Страница 564: ...s as part of a ping operation By default the number of packets sent to a pool address is 2 which is the smallest allowed number when sending packets Setting the number of packets to 0 disables this co...

Страница 565: ...ing This command enables conflict logging on DHCP server Default Format ip dhcp conflict logging Mode no ip dhcp conflict logging This command disables conflict logging on DHCP server Format no ip dhc...

Страница 566: ...DHCP server If no IP address is specified the bindings corresponding to all the addresses are displayed Format show ip dhcp binding address Modes Privileged EXEC User EXEC IP address Hardware Address...

Страница 567: ...ion The field to display the status of dhcp protocol The maximum number of Ping Packets that will be sent to verify that an ip address id not already assigned Shows whether conflict logging is enabled...

Страница 568: ...s Modes Privileged EXEC User EXEC Field Definition The number of IP addresses that have been automatically mapped to the MAC addresses of hosts that are found in the DHCP database The number of expire...

Страница 569: ...ualified host names names with a domain name By default no default domain name is configured in the system name may not be longer than 255 characters and should not include an initial period This name...

Страница 570: ...ames can be entered in to this list Default Format ip domain list name Mode no ip domain list Use this command to delete a name from a list Format no ip domain list name Mode ip name server Use this c...

Страница 571: ...st cache name is host name v6 address is the IPv6 address of the host Default Format ipv6 host name v6 address Mode no ipv6 host Use this command to remove the static host name to IPv6 address mapping...

Страница 572: ...ault Format ip domain timeout seconds Mode no ip domain timeout Use this command to return to the default setting Format no ip domain timeout seconds Mode clear host Use this command to delete entries...

Страница 573: ...list yahoo com Stanford edu rediff com Domain Name lookup Enabled Number of retries 5 Retry timeout period 1500 Name servers Preference order 176 16 1 18 176 16 1 19 Configured host name to address ma...

Страница 574: ...128 packets are captured and have not yet been displayed during a capture session It is guaranteed that packets not displayed and not saved will not be lost when capturing is in progress Use the comm...

Страница 575: ...n external PC running the Wireshark tool for Microsoft Windows A packet capture server runs on the switch side and sends the captured packets via a TCP connection to the Wireshark tool The remote capt...

Страница 576: ...line wrap command to stop automatically capturing packets when 128 packets are saved and have not yet been displayed during the capturing session When capturing is in progress unsaved not yet displaye...

Страница 577: ...323 SCCP SIP Mode no debug auto voip Use this command to disable Auto VOIP debug messages Format no debug auto voip Mode debug clear This command disables all previously enabled debug traces Default F...

Страница 578: ...e Mode debug dhcp packet Use this command to display debug information about DHCPv4 client activities and trace DHCPv4 packets to and from the local DHCPv4 client Default Format debug dhcp packet tran...

Страница 579: ...nd the interface in order to monitor packets for a particular interface Default Format debug igmpsnooping packet transmit Mode A sample output of the trace message is shown below 15 JAN 01 02 45 06 19...

Страница 580: ...ery Group 225 0 0 5 The following parameters are displayed in the trace message Src_Mac Source MAC address of the packet Dest_Mac Destination multicast MAC address of the packet Src_IP The source IP a...

Страница 581: ...nd transmit traces only transmitted DVMRP packets When neither keyword is used in the command then all DVMRP packet traces are dumped Vital Src_Mac Source MAC address of the packet Dest_Mac Destinatio...

Страница 582: ...ion address control packet type packet length and the interface on which the packet is received or transmitted is displayed on the console Default Format debug ip igmp packet receive transmit Mode no...

Страница 583: ...ip pimdm packet Use this command to disable debug tracing of PIMDM packet reception and transmission debug ip pimsm packet Use this command to trace PIMSM packet reception and transmission receive tr...

Страница 584: ...splay of debug trace output for DHCPv6 client activity Format no debug ipv6 dhcp Mode debug ipv6 mcache packet Use this command for tracing MDATAv6 packet reception and transmission receive traces onl...

Страница 585: ...packet reception and transmission Format no debug ipv6 mld packet receive transmit Mode debug ipv6 pimdm packet Use this command to trace PIMDMv6 packet reception and transmission receive traces only...

Страница 586: ...d and transmitted by the switch Default Format debug lacp packet Mode A sample output of the trace message is shown below 15 JAN 01 14 04 51 10 254 24 31 1 DOT3AD 183697744 dot3ad_debug c 385 58 Pkt T...

Страница 587: ...2 DestIp 224 0 0 5 AreaId 0 0 0 0 Type HELLO NetMask 255 255 255 0 DesigRouter 0 0 0 0 Backup 0 0 0 0 15 JAN 02 11 03 35 10 50 50 1 2 OSPF 46300472 ospf_debug c 293 25431 Pkt TX Intf 2 0 48 Src Ip 10...

Страница 588: ...received by the device The interface that the packet came in or went out on Format used is unit slot port internal interface number The source IP address in the IP header of the packet The destination...

Страница 589: ...bug ipv6 ospfv3 packet Mode no debug ipv6 ospfv3 packet Use this command to disable tracing of OSPFv3 packets Format no debug ipv6 ospfv3 packet Mode debug ping packet This command enables tracing of...

Страница 590: ...responses This command takes no options The output is directed to the log file Default Format debug rip packet Mode A sample output of the trace message is shown below 15 JAN 01 00 35 15 192 168 17 2...

Страница 591: ...cket Mode Parameter Definition TX refers to a packet transmitted by the device RX refers to packets received by the device The interface that the packet came in or went out on Format used is unit slot...

Страница 592: ...be enabled on the device and on the interface in order to monitor packets for a particular interface Default Format debug spanning tree bpdu receive Mode A sample output of the trace message is shown...

Страница 593: ...t_Priority 0x8000 Path_Cost 0 The following parameters are displayed in the trace message Source_Mac Source MAC address of the packet Version Spanning tree protocol version 0 3 0 refers to STP 2 RSTP...

Страница 594: ...lity Format no debug aaa accounting Mode debug aaa authorization This command is useful for debugging authorization configuration and functionality in User Manager Format debug aaa authorization comma...

Страница 595: ...vity enabling effective management and control of network resources Privileged EXEC Field Description Cable Status One of the following statuses is returned Normal The cable is working correctly Open...

Страница 596: ...ng to claim an sFlowRcvrTable entry must ensure that the entry is unclaimed before trying to claim it The entry is claimed by setting the owner string to a non null value The entry must be claimed bef...

Страница 597: ...Mode Interface Config Field Description Receiver Index The sFlow Receiver for this sFlow sampler to which flow samples are to be sent A value of zero 0 means that no receiver is configured no packets...

Страница 598: ...iver Index Enter the sFlow Receiver associated with the sampler poller A value of zero 0 means that no receiver is configured The range is 1 8 The default is 0 Poll Interval Enter the sFlow instance p...

Страница 599: ...with this sFlow counter poller Poller Interval The number of seconds between successive samples of the counters associated with this data source Privileged EXEC Field Description Receiver Index The s...

Страница 600: ...oad a license file only on the Master unit The file cannot be downloaded on a Slave unit There are two options to download the license file to the switch Use the Copy command to download the license f...

Страница 601: ...ense Status Active Description License key is active Managed Switches show license features This command displays the features that are licensed on the switch Format show license features Mode Example...

Страница 602: ...ion Protocol PAgP if the problems occur with proprietary protocols running on standards based switches If certain protocol PDUs cause unexpected results LLPF can be enabled to prevent those protocol P...

Страница 603: ...d History Commands The various MIBs within RFC 2819 3273 and 3434 are arranged into groups The managed switch supports some of the groups in these RFCs but not all The managed switch complies with MOD...

Страница 604: ...t occurs RMON events occur when A threshold alarm is exceeded There is a match on certain filters RFC 3273 Group 1 Media Independent Group Contains media independent statistics that provide informatio...

Страница 605: ...arm Number The Alarm number which identifies an Alarm Alarm Variable The object identifier of the particular variable to be sampled Only variables that resolve to an ASN 1 primitive type of integer Sa...

Страница 606: ...value to be compared against thresholds Possible types are Absolute or Delta Rising Threshold High Value High capacity alarm rising threshold absolute value high The upper 32 bits of the absolute val...

Страница 607: ...etes the history control group entry with the specified index number Format no rmon collection history index number Mode show rmon This command displays the entries in the RMON alarm table Format show...

Страница 608: ...n history This command displays the specified entry in the RMON history table Format show rmon history index errors other throughput Mode Example Swtich show rmon history 1 throughput Sample set 1 Max...

Страница 609: ...0 show rmon hcalarms hcalarm alarm index This command displays the entries in the RMON hcAlarmTable Format show rmon high capacity alarms Mode UDLD Commands The UDLD feature detects unidirectional li...

Страница 610: ...message time interval Mode udld timeout interval This command configures the time interval after which UDLD link is considered to be unidirectional The range is from 5 to 60 seconds Default Format ud...

Страница 611: ...dld slot port This command displays the UDLD settings for the specified slot port If the all keyword is entered it displays information for all ports Format show udld unit slot port all Mode Privilege...

Страница 612: ...the state of the port Not applicable UDLD is disabled either globally or on the port Shutdown UDLD has detected a unidirectional link and shutdown the port That is the port is in an errDisabled state...

Страница 613: ...ds User Account Commands SNMP Commands RADIUS Commands TACACS Commands Configuration Scripting Commands Pre Login Banner and System Prompt Commands Switch Database Management SDM Templates IPv6 Manage...

Страница 614: ...ord 2 Management CPU IP address and network mask 3 System name and location information The tool is interactive and uses questions to guide you through the steps required to perform its task At the en...

Страница 615: ...ia the command line interface is currently not configured Do you wish to change it Y N Q y Enter new password Confirm new password Password Changed Assigning an IP address to your switch management Cu...

Страница 616: ...his value change is effective immediately If you use the bootp parameter the switch periodically sends requests to a BootP server until a response is received If you use the dhcp parameter the switch...

Страница 617: ...of the Web interface When access is enabled the Java applet can be viewed from the Web interface When access is disabled the user cannot view the Java applet Default Format network javamode Mode no n...

Страница 618: ...factory default value is 0 0 0 0 The IP subnet mask for this interface The factory default value is 0 0 0 0 The default gateway for this IP interface The factory default value is 0 0 0 0 Whether enab...

Страница 619: ...nsole port of the switch configuration Use this command to access Global Config mode From Global Config mode you can configure a variety of system settings including user accounts You can also enter o...

Страница 620: ...at serial timeout 0 160 Mode no serial timeout Use this command to set the maximum connect time in minutes without console activity Format no serial timeout Mode login authentication Use this command...

Страница 621: ...ands This section describes the commands you use to configure and view Telnet settings You can use Telnet to manage the device from a remote management host Line Config Line Config Term Definition The...

Страница 622: ...a valid decimal integer in the range of 0 to 65535 where the default value is 23 If debug is used the current Telnet options enabled is displayed The optional line parameter sets the outbound Telnet...

Страница 623: ...tablished session remains active until the session is ended or an abnormal network error ends it Default Format transport output telnet Mode no transport output telnet Use this command to prevent new...

Страница 624: ...sion timeout value to the default The timeout value unit of time is minutes Format no session timeout Mode telnetcon maxsessions Use this command to specify the maximum number of Telnet connection ses...

Страница 625: ...ue are disconnected immediately no telnetcon timeout Use this command to set the Telnet connection session timeout value to the default Note Changing the timeout value for active sessions does not bec...

Страница 626: ...cess to the switch Use SSH to access the switch from a remote management host Note The system allows a maximum of 5 SSH sessions Term Definition The number of minutes an outbound Telnet session is all...

Страница 627: ...de ip ssh server enable Use this command to enable the IP secure shell server Default Format ip ssh server enable Mode no ip ssh server enable Use this command to disable the IP secure shell server Fo...

Страница 628: ...rmat sshcon timeout 1 160 Mode no sshcon timeout Use this command to set the SSH connection session timeout value in minutes to the default Changing the timeout value for active sessions does not beco...

Страница 629: ...Use this command to delete the HTTPS certificate files from the device regardless of whether they are self signed or downloaded from an outside source Format no crypto certificate generate Mode crypt...

Страница 630: ...ransfer Protocol HTTP Commands This section describes the commands you use to configure HTTP and secure HTTP access to the switch Access to the switch by using a Web browser is enabled by default Ever...

Страница 631: ...HTTP Format no ip http secure server Mode ip http java Use this command to enable the Web Java mode The Java mode applies to both secure and un secure Web connections Format ip http java Mode no ip ht...

Страница 632: ...returns an error not if it fails To ensure that the authentication succeeds even if all methods return an error specify none as the final method in the command line For example If none specified as an...

Страница 633: ...is value to zero will give an infinite soft timeout When this timeout expires the user will be forced to re authenticate This timer begins on initiation of the Web session and is re started with each...

Страница 634: ...t timeout 1 60 Mode no ip http secure session soft timeout Use this command to restore the soft timeout for secure HTTP sessions to the default value Format no ip http secure session soft timeout Mode...

Страница 635: ...hod2 Mode Local Radius Tacacs None no ip https authentication Use this command to restore the authentication methods to the default for http server users Format no ip https authentication method1 meth...

Страница 636: ...neration in Progress SSL3 and TLS1 Privileged EXEC Privileged EXEC Term Definition The unsecure HTTP server administrative mode The java applet administrative mode which applies to both secure and un...

Страница 637: ...e Connection From Idle Time Session Time Session Type User Account Commands This section describes the commands you use to add manage and delete system users The 7000 series software has two default u...

Страница 638: ...ide complexity check level level encrypted override complexity check override complexity check level level override complexity check password Mode no username Use this command to remove a user account...

Страница 639: ...other users You must enter the username in the same case you used when you added the user To see the case of the username enter the show users command Defaults admin readwrite other readonly Format us...

Страница 640: ...ich the specified authentication protocol is used Format no username snmpv3 authentication username Mode username snmpv3 encryption Use this command to specify the encryption protocol used for the spe...

Страница 641: ...rivileged EXEC Term Definition The name the user enters to login using the serial port Telnet or Web Shows whether the user is able to change parameters on the switch Read Write or is only able to vie...

Страница 642: ...ength UserName guest Privilege 1 Password Aging Password Expiry Lockout False Override Complexity Check Disable Password Strength show users long Format show users long Mode Use this command to displa...

Страница 643: ...d to set the number of previous passwords that shall be stored for each user account When a local user changes his or her password the user will not be able to reuse any password stored in password hi...

Страница 644: ...ckout count is configured a user that is logged in must enter the correct password within that count Otherwise the user will be locked out from further switch access Only a user with read write access...

Страница 645: ...reset the minimum number of uppercase letters to the default value Format no passwords strength minimum uppercase characters Mode passwords strength minimum lowercase letters Use this command to enfo...

Страница 646: ...n The valid range is 0 16 The default is 2 Minimum of 0 means no restriction on that set of characters Format passwords strength minimum special letters Mode Default no passwords strength minimum spec...

Страница 647: ...rength maximum repeated characters Mode Default no passwords strength maximum repeated characters Use this command to reset the maximum number of repeated characters to the default value Format no pas...

Страница 648: ...Definition Minimum Password Length Minimum number of characters required when changing passwords Password History Number of passwords to store for reuse prevention Password Aging Length in days that...

Страница 649: ...ent If local method is listed first since local authentication is always available it only has the fail condition not error As such if local method is the first in the list no other method will be tri...

Страница 650: ...method command where list name is any character string used to name this list The method argument identifies the list of methods that the authentication algorithm tries in the given sequence The addi...

Страница 651: ...aa authentication enable Use this command to remove the authentication method Format no aaa authentication enable default list name method1 method2 Mode aaa authentication dot1x Use this command to se...

Страница 652: ...e Accounting method Accounting records are notified to a TACACS server If radius is the specified Accounting method Accounting records are notified to a RADIUS server For the same set of accounting ty...

Страница 653: ...c commands Mode Term Definition Provides accounting for an user EXEC terminal sessions Provides accounting for all user executed commands The default list of methods for accounting services Character...

Страница 654: ...e configured accounting method lists Format show accounting methods Mode Example switch switch show accounting methods Acct Type Method Name Record Type Method Type Exec dfltExecList start stop TACACS...

Страница 655: ...ommands exec default list_name method1 method2 Mode commands Exec default list name method no aaa authorization This command deletes the authorization method list Format no aaa authorization commands...

Страница 656: ...ole dfltCmdAuthList Telnet dfltCmdAuthList SSH dfltCmdAuthList Exec Authorization List Method dfltExecAuthList none undefined undefined undefined Line Exec Method List Console dfltExecAuthList Telnet...

Страница 657: ...owing format Domainname username Format domain name name Mode no domain name This command is used to disable the domain name in the managed switch Format no domain name Mode domain name enable This co...

Страница 658: ...command to enable forwarding of all multicast packets on a given VLAN ID Format mac address table multicast forward all vlan 1 4093 Mode no mac address table multicast forward all vlan Use this comma...

Страница 659: ...tering Use this command to display the multicast filtering details for a given VLAN Format show mac address table multicast filtering Mode The following shows example CLI display output for the comman...

Страница 660: ...user Mode aaa session id This global aaa command specifies whether the same session id is used for Authentication Authorization and Accounting service type within a session Default common Format aaa...

Страница 661: ...section describes the commands you use to configure Simple Network Management Protocol SNMP on the switch You can configure the switch to act as an SNMP agent so that it can communicate with SNMP man...

Страница 662: ...name to be deleted Format no snmp server community name Mode snmp server community ipaddr Use this command to set a client IP address for an SNMP community The address is the associated community SNM...

Страница 663: ...ress The name is the applicable community name Default Format snmp server community ipmask ipmask name Mode no snmp server community ipmask Use this command to set a client IP mask for an SNMP communi...

Страница 664: ...information The access mode is read only also called public Format snmp server community ro name Mode snmp server community rw Use this command to restrict access to switch information The access mode...

Страница 665: ...s Mode Note This command may not be available on all platforms snmp server enable traps linkmode Use this command to enable Link Up Down traps for the entire switch When enabled link traps are sent on...

Страница 666: ...oot traps and topology change notification traps Default Format snmp server enable traps stpmode Mode no snmp server enable traps stpmode Use this command to disable sending new root traps and topolog...

Страница 667: ...mmunity on page39 no snmptrap Use this command to delete trap receivers for a community Format no snmptrap name ipaddr ipaddr hostname ip6addr ip6addr hostname Mode snmptrap snmpversion Use this comma...

Страница 668: ...ble to receive traps Disabled trap receivers are inactive not able to receive traps Format snmptrap mode name ipaddr hostname ip6addr hostname Mode no snmptrap mode Use this command to deactivate an S...

Страница 669: ...e on page 665 no snmp trap link status all Use this command to disable link status traps for all interfaces Note This command is valid only when the Link Up Down Flag is enabled For more information s...

Страница 670: ...of this table must contain a unique community name An IP address or portion thereof from which this device will accept SNMP packets with the associated community The requesting entity s IP address is...

Страница 671: ...or disabled The factory default is enabled Indicates whether link status traps will be sent Can be enabled or disabled The factory default is enabled Indicates whether a trap will be sent when the sa...

Страница 672: ...disable the switch to accept VLAN assignment by the radius server Format no authorization network radius Mode radius accounting mode Use this command to enable the RADIUS accounting function Default...

Страница 673: ...ber and server name If the authenticating and accounting servers are configured without a name the command uses the Default_RADIUS_Auth_Server and Default_RADIUS_Acct_Server as the default names respe...

Страница 674: ...To re configure a RADIUS accounting server to use the default UDP port set the port parameter to 1813 no radius server host Use the no version of this command to delete the configured server entry fr...

Страница 675: ...is used the shared secret is configured for the RADIUS authentication or RADIUS accounting server The IP address or hostname provided must match a previously configured server When this command is exe...

Страница 676: ...ry server in the group of servers that have the same server name Multiple primary servers can be configured for each number of servers that have the same name When the RADIUS client has to perform tra...

Страница 677: ...value of this global parameter to the default value Format no radius server retransmit Mode radius server timeout Use this command to configure the global parameter for the RADIUS client that specifi...

Страница 678: ...r Groups 3 Number of Retransmits 4 Time Duration 10 RADIUS Accounting Mode Disable RADIUS Attribute 4 Mode Enable RADIUS Attribute 4 Value 192 168 37 60 Privileged EXEC Term Definition The number of R...

Страница 679: ...port used for communication with the authenticating server Type Specifies whether this server is a primary or secondary type Current Host Address The IP address of the currently active authenticating...

Страница 680: ...ADIUS Accounting Mode Disable RADIUS Attribute 4 Mode Enable RADIUS Attribute 4 Value 192 168 37 60 Switch show radius servers 192 168 37 58 Server Name Default_RADIUS_Server Host Address 192 168 37 5...

Страница 681: ...le Port 1813 Secret Configured Yes show radius accounting statistics Use this command to display a summary of statistics for the configured RADIUS accounting servers Format show radius accounting stat...

Страница 682: ...does not include retransmissions Retransmission The number of RADIUS Accounting Request packets retransmitted to this RADIUS accounting server Responses The number of RADIUS packets received on the a...

Страница 683: ...ets retransmitted to this RADIUS authentication server Access Accepts The number of RADIUS Access Accept packets including both valid and invalid packets that were received from this server Access Rej...

Страница 684: ...ors 0 Pending Requests 0 Timeouts 0 Unknown Types 0 Packets Dropped 0 TACACS Commands TACACS provides access control for networked devices via one or more centralized servers Similar to RADIUS this pr...

Страница 685: ...t tacacs server host ip address hostname Mode no tacacs server host Use the no tacacs server host command to delete the specified hostname or IP address The ip address hostname parameter is the IP add...

Страница 686: ...e TACACS daemon Format no tacacs server key key string Mode tacacs server keystring Use this command to set the global authentication encryption key used for all TACACS communications between the TACA...

Страница 687: ...mat no tacacs server timeout Mode key Use the key command in TACACS Configuration mode to specify the authentication and encryption key for all TACACS communications between the device and the TACACS...

Страница 688: ...on mode to specify the timeout value in seconds If no timeout value is specified the global value is used The timeout parameter has a range of 1 30 and is the timeout value in seconds Format timeout t...

Страница 689: ...ster unit at the time of the file download The file extension must be scr A maximum of ten scripts are allowed on the switch The combined size of all script files on the switch shall not exceed 2048 K...

Страница 690: ...he all option deletes all the scripts present on the switch Format script delete scriptname all Mode script list Use this command to list all scripts present on the switch as well as the remaining ava...

Страница 691: ...describes the commands you use to configure the pre login banner and the system prompt The pre login banner is the text that displays before you login at the User prompt copy pre login banner Use a co...

Страница 692: ...mplate to provide the maximum system usage for a specific function For example you could use a routing template to optimize resources for IPv4 routing if the network environment does not use IPv6 rout...

Страница 693: ...late Format show sdm prefer dual ipv4 and ipv6 default ipv4 routing default data center Mode Parameter Description Supports IPv4 routing only data center Support more ECMP next hops in IPv4 routes def...

Страница 694: ...tic assignment of IPv6 addresses and gateways for the network ports The ability to ping an IPv6 link local address over the network port Using IPv6 Management commands you can send SNMP traps and quer...

Страница 695: ...the address option Disable the stateless global address autoconfiguration on the network port with the autoconfig option Disable the dhcpv6 client protocol on the network port with the dhcp option For...

Страница 696: ...work ndp Neighbor Age IPv6 Address MAC Address isRtr State Updated 3017 204 76FF FE73 423A 00 04 76 73 42 3a Reachable 447535 FE80 204 76FF FE73 423A 00 04 76 73 42 3a Delay 447540 show network ipv6 d...

Страница 697: ...ertisement Packets Discarded The number of DHCPv6 Advertisement packets discarded on the network interface Received DHCPv6 Reply Packets Discarded The number of DHCPv6 Reply packets discarded on the n...

Страница 698: ...mands 698 ProSafe Managed Switch clear network ipv6 dhcp statistics Use this command to clear the DHCPv6 statistics on the network management interface Format clear network ipv6 dhcp statistics Mode P...

Страница 699: ...a set of these messages in the event log along with an understanding of the system configuration and details of the problem will assist NETGEAR Inc in determining the root cause of such a problem Note...

Страница 700: ...ut of order NIM NIM event x intf x component x in wrong phase An event was issued to NIM during the wrong configuration phase probably Phase 1 2 or WMU NIM NIM Failed to notify users of interface chan...

Страница 701: ...n size expected version size differ The configuration file which was loaded was of a different size than expected for the version number This message indicates the configuration file needed to be migr...

Страница 702: ...or on call to sysapiCfgFileWrite file Error on trying to save configuration Table 8 NVStore Log Messages Component Message Cause NVStore Building defaults for file XXX A component s configuration file...

Страница 703: ...data from the RADIUS server RADIUS RADIUS Accounting Response failed to validate id xxx The RADIUS Client received an invalid message from the server RADIUS RADIUS User xxx needs to respond for chall...

Страница 704: ...ived invalid packet type from server Received packet type that is not supported TACACS TACACS invalid major version in received packet Major version mismatch TACACS TACACS invalid minor version in rec...

Страница 705: ...ction type EmWeb ewsNetHTTPReceive failure in NetReceiveLoop closing connection Socket receive failure EmWeb EmWeb connection allocation failed Memory allocation failure for the new connection EmWeb E...

Страница 706: ...t Unknown error returned while uploading file using TFTP from web interface WEB Web UI Screen with unspecified access attempted to be brought up Failed to get application specific authorization handle...

Страница 707: ...Queue is full event XXXX Failed to send the received message to the SSLT message queue as message queue is full XXXX indicates the event to be sent SSLT SSLT Unknown UI event in message event XXXX Fa...

Страница 708: ...nnot be saved Protected Ports protectedPortCnfgrInitPhase1Process Unable to create r w lock for protectedPort This appears when protectedPortCfgRWLock Fails Protected Ports protectedPortCnfgrInitPhase...

Страница 709: ...appears when a dtl fails to delete an entry from the table IPsubnet vlans vlanIpSubnetVlanChangeCallback Failed to add an Entry This appears when a dtl fails to add an entry for a vlan add notify eve...

Страница 710: ...1X dot1xSendRespToServer dot1xRadiusAccessRequestSend failed Failed sending message to RADIUS server 802 1X dot1xRadiusAcceptProcess error calling radiusAccountingStart ifIndex xxx Failed sending acco...

Страница 711: ...rface number type of message etc GARP GVRP GMRP GarpSendPDU QUEUE SEND FAILURE The garpPduQueue is full logs specific of the GPDU internal interface number vlan id buffer handle etc GARP GVRP GMRP gar...

Страница 712: ...time in the hardware Table 29 Double VLAN Tag Log Message Component Message Cause Double Vlan Tag dvlantagIntfIsConfigurable Error accessing dvlantag config data for interface d A default configurati...

Страница 713: ...dot1qVlanTaggedMemberSetModify Dynamic entry d can only be modified after it is converted to static If this vlan is a learnt via GVRP then we cannot modify it s member set via management Table 33 802...

Страница 714: ...resulted in requiring more rules than the platform supports ACL ACL name rule x This rule is not being logged The ACL configuration has resulted in a requirement for more logging rules than the platfo...

Страница 715: ...CP request whose HOPS field is larger than the maximum value allowed The relay agent will not forward a message with a hop count greater than 4 DHCP relay Request s seconds field less than the config...

Страница 716: ...tisement LSA whose checksum was incorrect Table 41 OSPFv3 Log Messages Component Message Cause OSPFv3 Best route client deregistration failed for OSPFv3 Redist OSPFv3 registers with the IPv6 routing t...

Страница 717: ...on why this count is incremented Table 43 VRRP Log Messages Component Message Cause VRRP Changing priority to 255 for virtual router with VRID 1 on interface 1 0 1 When the router is configured with t...

Страница 718: ...en creating entry When we run out of memory while creating a new cache MFC entry Cache Out of memory when creating cache When we run out of memory while creating the cache itself Table 48 IGMP Log Mes...

Страница 719: ...source list or group list or candidate Rp list or virtual interface list The xxx specifies the list for which the access is denied PIM SM Warning Could not send packet type xxx pimsm packet type on r...

Страница 720: ...ting PIM DM pipe This message is logged when the PIM DM Pipe that receives control messages creation fails Table 52 DVMRP Log Messages Component Message Cause DVMRP dvmrp_send_graft failed getting mem...

Страница 721: ...data x x x x x x x x An issue installing the policy due to a possible duplicate hash OS ACL x not found in internal table Attempting to delete a non existent ACL OS ACL internal table overflow Attempt...

Страница 722: ...n unit x Could not synchronize unit x due to a transport failure or API issue on remote unit A synchronization retry will be issued OS USL failed to sync VLAN table on unit x Could not synchronize uni...

Страница 723: ...in the file system after a write The file system is R W so this msg indicates the file system may be corrupted OSAPI ftruncate failed File is open for reading only ftruncate is called to correctly set...

Страница 724: ...he interface from the route table the attempt to get the ipv4 interface mask from the stack failed OSAPI osapiCleanupIf NetIpDel During the call to remove the interface from the route table the attemp...

Страница 725: ...y networks If configured this additional port is then used exclusively by Captive Portal Note that this optional port is in addition to the standard HTTP port 80 which is currently being used for all...

Страница 726: ...5535 Default Format http port 0 65535 Mode no http port Use this command to reset the HTTP port to the default number 80 Format no http port Mode https port Use this command to configure an additional...

Страница 727: ...the authentication timeout to the default Default 300 Format no authentication timeout Mode show captive portal Use this command to display the status of the captive portal feature Format show captiv...

Страница 728: ...on Additional HTTP Port The additional HTTP port for captive portal to monitor Captive portal only monitors port 80 by default Additional HTTP Secure Port The additional HTTPs port for captive portal...

Страница 729: ...CP configuration The default configuration cannot be deleted Format no configuration 1 10 Mode enable Instance Use this command to enable a captive portal configuration Default Format enable Mode no...

Страница 730: ...alid user name and password that must first be validated against the local database or a RADIUS server Network access is granted once user verification has been confirmed Default guest Format verifica...

Страница 731: ...Format no redirect Mode redirect url Use this command to configure the redirect URL for a captive portal configuration The url is the URL for redirection which can be up to 512 characters in length F...

Страница 732: ...s command to reset the maximum rate to the default Format no max bandwidth up Mode max input octets Use this command to configure the maximum number of octets the user is allowed to transmit After thi...

Страница 733: ...ived After this limit has been reached the user will be disconnected The number of total octets is in bytes 0 indicates limit not enforced Use the no form of this command to reset the limit to the def...

Страница 734: ...e timeout to the default Format no idle timeout Mode locale This command is not intended to be a user command The administrator must use the WEB UI to create and customize captive portal web content T...

Страница 735: ...owed through any interfaces associated with that captive portal configuration Blocking a captive portal instance is a temporary command executed by the administrator and not saved in the configuration...

Страница 736: ...configuration 1 10 interface unit slot port Mode Term Definition CP ID The captive portal ID CP Name The captive portal instance name Operational Status The operational status is enabled or disabled...

Страница 737: ...cked Authenticated Users 0 show captive portal configuration status Use this command to display information about all configured captive portal configurations or about a specific captive portal config...

Страница 738: ...0 Max Input Octets bytes 0 Max Output Octets bytes 0 Max Total Octets bytes 0 Term Definition The name of the group associated with this captive portal instance The redirect mode for this captive port...

Страница 739: ...pflags Mode Example switch show captive portal trapflags Client Authentication Failure Traps Disable Client Connection Traps Disable Client Database Full Traps Disable Client Disconnection Traps Disab...

Страница 740: ...t 0002 BC00 1290 status Client MAC Address 0002 BC00 1290 Client IP Address 10 254 96 47 Protocol Mode https Verification Mode Local CP ID 1 CP Name cp1 Interface 1 0 1 Interface Description Unit 1 Sl...

Страница 741: ...ive portal interface client status Use this command to display information about clients authenticated on all interfaces or a specific interface Format show captive portal interface unit slot port cli...

Страница 742: ...0 254 96 47 1 cp1 http local 0002 BC00 1291 10 254 96 48 2 cp2 http local show captive portal configuration client status Use this command to display the clients authenticated to all captive portal co...

Страница 743: ...54 96 48 1 0 2 Unit 1 Slot 0 Port 2 Gigabit captive portal client deauthenticate Use this command to deauthenticate a specific captive portal client The macaddr is the Client MAC address Format captiv...

Страница 744: ...his command to create a local user or change the password for an existing user The user id is user ID in the range of 1 128 The password is the user password in the range of 8 64 characters You can al...

Страница 745: ...he group ID Default 1 Format user 1 128 group 1 10 Mode no user group Use this command to dis associate a group and user Format no user 1 128 group 1 10 Mode user session timeout Use this command to s...

Страница 746: ...ive data from the network 1 128 is the user ID The range of bps is 0 536870911 bps 0 indicates use global configuration Default Format user 1 128 max bandwidth down bps Mode no user max bandwidth down...

Страница 747: ...put octets Use this command to limit the number of octets the user is allowed to receive After this limit has been reached the user will be disconnected The 1 128 is the user ID The range of the octet...

Страница 748: ...he user ID is specified the following terms are displayed Captive Portal Configuration mode Captive Portal Configuration mode Privileged EXEC mode Term Definition User ID The user ID User Name The use...

Страница 749: ...te b s Limits the bandwidth at which the client can receive data from the network If the value is 0 or then use the value configured for the captive portal Max Input Octets bytes Maximum number of oct...

Страница 750: ...to delete a user group The default user group 1 cannot be deleted Format user group 1 10 Mode user group name Use this command to configure a group name 1 10 is the user group ID The name can be a st...

Страница 751: ...sa OSPF 261 area nssa OSPFv3 380 area nssa default info originate OSPF 261 area nssa default info originate OSPFv3 381 area nssa no redistribute OSPF 262 area nssa no redistribute OSPFv3 381 area nssa...

Страница 752: ...authorization console telnet ssh 655 auto cost OSPF 268 auto cost OSPFv3 386 auto negotiate 22 auto negotiate all 22 auto summary 308 auto voip protocol based oui based 487 auto voip oui 487 auto voip...

Страница 753: ...ear ip dhcp snooping statistics 138 clear ip helper statistics 255 clear ip ospf 269 clear ip ospf configuration 269 clear ip ospf counters 270 clear ip ospf neighbor 270 clear ip ospf neighbor interf...

Страница 754: ...29 Dampening 305 datacenter bridging 207 debug aaa accounting 594 debug aaa authorization 594 debug arp 577 debug auto voip 577 debug clear 577 debug console 577 debug dhcp packet 578 debug dot1x pack...

Страница 755: ...hcp client vendor id option string 130 dhcp l2relay 125 dhcp l2relay circuit id vlan 126 dhcp l2relay remote id vlan 126 dhcp l2relay trust 127 dhcp l2relay vlan 127 diffserv 448 disconnect 637 distan...

Страница 756: ...t1x supplicant timeout start period 91 dot1x supplicant user 92 dot1x system auth control 80 dot1x system auth control monitor 83 dot1x timeout 81 dot1x unauthenticated vlan 82 dot1x user 82 drop 457...

Страница 757: ...cluded address 563 ip dhcp ping packets 564 ip dhcp pool 557 ip dhcp snooping 130 ip dhcp snooping binding 132 ip dhcp snooping database 132 ip dhcp snooping database write delay 132 ip dhcp snooping...

Страница 758: ...query interval 341 ip igmp version 338 ip igmp proxy 345 ip igmp proxy reset status 346 ip igmp proxy unsolicit rprt interval 346 ip irdp 240 ip irdp holdtime 241 ip irdp maxadvertinterval 241 ip ird...

Страница 759: ...s 315 ip verify binding 133 ip verify source 134 ip vrrp Global Config 244 ip vrrp Interface Config 245 ip vrrp vrid accept mode 249 ip vrrp authentication 246 ip vrrp ip 246 ip vrrp mode 245 ip vrrp...

Страница 760: ...ignore 378 ipv6 ospf network 378 ipv6 ospf priority 379 ipv6 ospf retransmit interval 379 ipv6 ospf transmit delay 380 ipv6 pim Interface Config 420 ipv6 pim bsr border 423 ipv6 pim bsr candidate 423...

Страница 761: ...onfignotification 181 lldp med confignotification all 182 lldp med faststartrepeatcount 183 lldp med transmit tlv 181 lldp med transmit tlv all 183 lldp notification 174 lldp notification interval 175...

Страница 762: ...recedence 460 match any 450 match class map 450 match cos 451 match destination address mac 452 match dstip 452 match dstip6 452 match dstl4port 452 match ethertype 450 match ip dscp 453 match ip prec...

Страница 763: ...detect 443 no ip vrrp vrid accept mode 250 no llpf 603 no monitor 120 no nsf 301 no nsf ietf OSPFv3 407 no nsf ietf helper strict lsa checking 303 no nsf ietf helper strict lsa checking OSPFv3 409 no...

Страница 764: ...end time 486 periodic 485 permit ip host mac host 143 ping 544 ping ipv6 545 ping ipv6 interface 546 poe 497 poe detection 497 poe high power 498 poe power limit 498 poe power management 499 poe prio...

Страница 765: ...th 676 radius server primary 676 radius server retransmit 677 radius server timeout 677 random detect exponential weighting constant 443 random detect queue parms 443 redirect 458 redirect Captive Por...

Страница 766: ...et igmp mrouter 150 set igmp mrouter interface 151 set igmp querier 154 set igmp querier election participate 156 set igmp querier query interval 155 set igmp querier timer expiry 155 set igmp querier...

Страница 767: ...gs 739 show captive portal user 748 show captive portal 727 show class map 464 show classofservice dot1p mapping 444 show classofservice ip dscp mapping 445 show classofservice ip precedence mapping 4...

Страница 768: ...66 show ip dhcp conflict 568 show ip dhcp global configuration 566 show ip dhcp pool configuration 567 show ip dhcp server statistics 568 show ip dhcp snooping 135 show ip dhcp snooping binding 135 sh...

Страница 769: ...ow ip ospf virtual link brief 300 show ip pim 334 show ip pim bsr router 336 show ip pim interface 329 show ip pim neighbor 330 show ip pim rp mapping 337 show ip pim rp hash 336 show ip pim ssm 335 s...

Страница 770: ...01 show ipv6 ospf interface stats 402 show ipv6 ospf neighbor 403 show ipv6 ospf range 405 show ipv6 ospf stub table 405 show ipv6 ospf virtual link 406 show ipv6 ospf virtual link brief 406 show ipv6...

Страница 771: ...address table igmpsnooping 154 show mac address table mldsnooping 164 show mac address table multicast 200 show mac address table static 124 show mac address table staticfiltering 125 show mac addres...

Страница 772: ...eap summary 239 show running config 525 show running config interface 526 show sdm prefer 693 show serial 621 show service policy 468 show sflow agent 598 show sflow pollers 599 show sflow receivers 5...

Страница 773: ...community ipaddr 662 snmp server community ipmask 663 snmp server community mode 663 snmp server community ro 664 snmp server community rw 664 snmp server enable traps 665 snmp server enable traps li...

Страница 774: ...trol broadcast Global 94 storm control broadcast level 93 storm control broadcast level Global 95 storm control broadcast rate 94 storm control broadcast rate Global 95 storm control multicast 96 stor...

Страница 775: ...611 udld timeout interval 610 update bootcode 512 user group Create 750 user group name 750 user group rename 750 user group 745 user idle timeout 746 user max bandwidth down 746 user max bandwidth u...

Страница 776: ...port ingressfilter all 51 vlan port priority all 64 vlan port pvid all 51 vlan port tagging all 52 vlan priority 64 vlan protocol group 52 vlan protocol group add protocol 53 vlan protocol group name...

Отзывы: