Powered by Accton
Page
Fast Ethernet Switch
ES3528M-SFP E122007-DG-R01 149100035500A
Installation Guide
About This Guide
Page
Contents
Page
Iii
Page
Contents
Command Line Interface
Vii
Viii
Contents
Page
Contents
Xii
Xiii
Xiv
Contents
Appendix a Software Specifications
Xvi
Xvii
Appendix B Troubleshooting
Glossary Index
Xviii
Tables
Xix
Page
Xxi
Xxii
Figures
Xxiii
Figures
Xxiv
Xxv
Xxvi
Feature Description
Key Features
Key Features
Description of Software Features
Introduction
Description of Software Features
Introduction
Description of Software Features
Function Parameter Default
System Defaults
System Defaults
Password super
System Defaults Function Parameter
Client Enabled
Clock Synchronization Disabled
NTP
Connecting to the Switch
Configuration Options
Initial Configuration
Required Connections
Console Connection
Basic Configuration
Remote Connections
Manual Configuration
Setting Passwords
Setting an IP Address
Dynamic Configuration
Enabling Snmp Management Access
154
Trap Receivers
152
159
Saving Configuration Settings
Configuring Access for Snmp Version 3 Clients
160
Managing System Files
Initial Configuration
Configuring the Switch
Using the Web Interface
Navigating the Web Browser Interface
Home
Button
Configuration Options Action
Panel Display
Revert Apply Help
System System Information
Main Menu
Main Menu Description
Https Settings Configures secure Http settings
Radius Group Settings
TACACS+ Group Settings
107
116
802.1Q Vlan 155
149
155
164
159
Current Table
176
187
Port on this switch Remote Trunk Information
Remote Port Information
190
225
Static Multicast Router Port
217
233
245 Configuration Enables Upnp and defines timeout values
Displaying System Information
Field Attributes
Main Board
Displaying Switch Hardware/Software Versions
CLI Specify the hostname, location and contact information
Management Software
Web Click System, Switch Information
Switch Information
Bridge Extension Configuration
Displaying Bridge Extension Capabilities
Command Attributes
Setting the Switch’s IP Address
CLI Enter the following command
239
310
166
309
Using DHCP/BOOTP
311
Enabling Jumbo Frames
Managing Firmware
Downloading System Software from a Server
Copy Firmware
Saving or Restoring Configuration Settings
11 Deleting Files
Downloading Configuration Settings from a Server
12 Downloading Configuration Settings for Startup
Console Port Settings
13 Setting the Startup Configuration Settings
14 Console Port Settings
Telnet Settings
15 Enabling Telnet
Basic Configuration
Displaying Log Messages
Configuring Event Logging
System Log Configuration
CLI This example shows the event message stored in RAM
Level Severity Name Description
Error resource exhausted
Logging Levels
Remote Log Configuration
Simple Mail Transfer Protocol
18 Remote Logs
19 Enabling and Configuring Smtp
Resetting the System
20 Resetting the System
Configuring Sntp
Setting the System Clock
Setting the Time Manually
Configuring NTP
21 Sntp Configuration
22 NTP Client Configuration
Setting the Time Zone
23 Setting the System Clock
Simple Network Management Protocol
Level Group Read View Write View Notify View Security
Setting Community Access Strings
SNMPv3 Security Models and Levels
User defined
Access Mode
Specifying Trap Managers and Trap Types
Enabling Snmp Agent Status
156
Web Click SNMP, Agent Status
Configuring SNMPv3 Management Access
Setting the Local Engine ID
Web Click SNMP, SNMPv3, Engine ID
Configuring SNMPv3 Users
Specifying a Remote Engine ID
Configuring the Switch
Configuring Remote SNMPv3 Users
29 Configuring SNMPv3 Users
Configuring SNMPv3 Groups
30 Configuring Remote SNMPv3 Users
Supported Notification Messages
Private Traps
SwPowerStatus 6.1.4.1.259.8.1.4.2.1.0.1
Rmon Events
ChangeTrap SwIpFilterRejectTrap 6.1.4.1.259.8.1.4.2.1.0.40
Setting SNMPv3 Views
31 Configuring SNMPv3 Groups
32 Configuring SNMPv3 Views
User Authentication
Configuring User Accounts
33 Access Levels
Configuring Local/Remote Logon Authentication
Command Usage
Radius Settings
Tacacs Settings
34 Authentication Settings
100
101
TACACS+ Settings
Configuring Encryption Keys
Command Attributes Radius Settings
AAA Authorization and Accounting
102
Configuring AAA Radius Group Settings
Configuring AAA TACACS+ Group Settings
103
Configuring AAA Accounting
37 AAA TACACS+ Group Settings
38 AAA Accounting Settings
106
AAA Accounting Update
AAA Accounting 802.1X Port Settings
AAA Accounting Exec Command Privileges
107
41 AAA Accounting Exec Command Privileges
108
AAA Accounting Summary
AAA Accounting Exec Settings
AAA Accounting Summary
AAA Accounting Statistics Summary
Web Click Security, AAA, Summary
110
Authorization Settings
44 AAA Authorization Settings
109
Authorization Exec Settings
Authorization Summary
Configuring Https
Https System Support Web Browser Operating System
Replacing the Default Secure-site Certificate
47 Https Settings
Configuring the Secure Shell
Address server ip-address
Command Usage
Authenticating SSH v1.5 Clients
Authenticating SSH v2 Clients
Configuring the SSH Server
SSH server includes basic settings for authentication
Generating the Host Key Pair
50 SSH Host-Key Settings
Importing User Public Keys
User Authentication
51 SSH User Public-Key Settings
END SSH2 Public KEY
Configuring Port Security
Configuring 802.1X Port Authentication
111
Configuring the Switch
802.1X protocol provides client authentication
Displaying 802.1X Global Settings
Configuring 802.1X Global Settings
CLI This example shows the default global setting for
113
Configuring Port Settings for
CLI This example enables 802.1X globally for the switch
55 802.1X Port Configuration
117
114
116
Parameter Description
Displaying 802.1X Statistics
802.1X Statistics
Web Authentication
CLI This example displays the 802.1X statistics for port
Configuring Web Authentication
57 Web Authentication Configuration
Configuring Web Authentication for Ports
Displaying Web Authentication Port Information
137
Re-authenticating Web Authenticated Ports
Web Click Security, Web Authentication, Port Information
Network Access MAC Address Authentication
136
Web Click Security, Network Access, Configuration
Configuring the MAC Authentication Reauthentication Time
Configuring MAC Authentication for Ports
Mode Enables MAC authentication on a port. Default None
62 Network Access Port Configuration
Configuring Port Link Detection
CLI This example configures MAC authentication for port
63 Network Access Port Link Detection Configuration
Displaying Secure MAC Address Information
Port Indicates the port being configured
MAC Authentication
Configuring MAC authentication parameters for ports
129
Access Control Lists
123
Configuring Access Control Lists
Setting the ACL Name and Type
140
Configuring a Standard IP ACL
CLI This example creates a standard IP ACL named david
Configuring an Extended IP ACL
141
103
68 Configuring Extended IP ACLs
Configuring a MAC ACL
Binding a Port to an Access Control List
146
Filtering IP Addresses for Management Access
143
108
CLI This example allows Snmp access for a specific client
71 Creating an IP Filter List
Field Attributes Web
Port Configuration
Displaying Connection Status
Basic Information
Configuration
Field Attributes CLI
Current Status
173
Configuring Interface Connections
CLI This example shows the connection status for Port
168
167
171
170
Creating Trunk Groups
Statically Configuring a Trunk
74 Configuring Static Trunks
Enabling Lacp on Selected Ports
181
75 Lacp Trunk Configuration
182
Configuring Lacp Parameters
Dynamically Creating a Port Channel
76 Lacp Port Configuration
Lacp Port Counters
Displaying Lacp Port Counters
You can display statistics for Lacp protocol messages
Field Description
77 Lacp Port Counters Information
CLI The following example displays Lacp counters
Displaying Lacp Settings and Status for the Local Side
Lacp Internal Configuration Information
78 Lacp Port Internal Information
Displaying Lacp Settings and Status for the Remote Side
79 Lacp Port Neighbors Information
Setting Broadcast Storm Thresholds
172
175
Configuring Port Mirroring
177
179
Configuring Rate Limits
Rate Limit Configuration
Showing Port Statistics
Rmon Statistics
11 Port Statistics
Etherlike Statistics
Formed Oversize Frames
Formed Fragments
83 Port Statistics
CLI This example shows statistics for port
Address Table Settings
Setting Static Addresses
174
Displaying the Address Table
190
85 Configuring a Dynamic Address Table
191
CLI This example sets the aging time to 300 seconds
Spanning Tree Algorithm Configuration
Changing the Aging Time
192
Designated Root Port Bridge
Displaying Global Settings
139
87 Displaying Spanning Tree Information
235
Basic Configuration of Global Settings
Configuring Global Settings
Global settings apply to the entire switch
Root Device Configuration
Configuration Settings for Rstp
Configuration Settings for Mstp
88 Configuring Spanning Tree
Displaying Interface Settings
AD B
89 Displaying Spanning Tree Port Information
Configuring Interface Settings
CLI This example shows the STA attributes for port
148
Configuring Multiple Spanning Trees
CLI This example sets STA attributes for port
224
223
225
Displaying Interface Settings for Mstp
MST Instance ID Instance identifier to configure. Default
92 Displaying Mstp Interface Settings
Configuring Interface Settings for Mstp
154
CLI This example sets the Mstp attributes for port
Vlan Configuration
Ieee 802.1Q VLANs
Assigning Ports to VLANs
Port-based Vlan
Forwarding Tagged/Untagged Frames
Enabling or Disabling Gvrp Global Setting
CLI This example enables Gvrp for the switch
Displaying Current VLANs
Command Attributes Web
Displaying Basic Vlan Information
96 Displaying Current VLANs Command Attributes CLI
Creating VLANs
250
242
Adding Static Members to VLANs Vlan Index
CLI This example creates a new Vlan
243
163
Adding Static Members to VLANs Port Index
248
Configuring Vlan Behavior for Interfaces
100 Configuring VLANs per Port
Configuring Ieee 802.1Q Tunneling
Layer 2 Flow for Packets Coming into a Tunnel Access Port
QinQ Tunneling
Layer 2 Flow for Packets Coming into a Tunnel Uplink Port
General Configuration Guidelines for QinQ
Enabling QinQ Tunneling on the Switch
Configuration Limitations for QinQ
101 802.1Q Tunnel Status and Ethernet Type
251
CLI This example sets the switch to operate in QinQ mode
Adding an Interface to a QinQ Tunnel
253
Private VLANs
252
Displaying Current Private VLANs
Configuring Private VLANs
103 Private Vlan Information
256
Associating VLANs
Each community Vlan must be associated with a primary Vlan
Displaying Private Vlan Interface Information
106 Private Vlan Port Information
Configuring Private Vlan Interfaces
259
257
Protocol Vlan Group Configuration
Protocol VLANs
258
Protocol Vlan System Configuration
261
Link Layer Discovery Protocol
Setting Lldp Timing Attributes
Web Click VLAN, Protocol VLAN, System Configuration
262
182
197
Configuring Lldp Interface Attributes
195
198
184
111 Lldp Port Configuration
Displaying Lldp Local Device Information
Displaying Lldp Remote Port Information
212
Displaying Lldp Remote Information Details
213
Displaying Device Statistics
115 Lldp Device Statistics
Displaying Detailed Device Statistics
116 Lldp Device Statistics Details
Setting the Default Priority for Interfaces
Class of Service Configuration
Layer 2 Queue Settings
Mapping CoS Values to Egress Queues
Port Priority Configuration
CLI This example assigns a default priority of 5 to port
265
Priority Level Traffic Type
12 Mapping CoS Values to Egress Queues
13 CoS Priority Levels
Background
269
Enabling CoS
267
Web Click Priority, Traffic Classes Status
Selecting the Queue Mode
Setting the Service Weight for Traffic Classes
268
Layer 3/4 Priority Settings
Mapping Layer 3/4 Priorities to CoS Values
Switch allows you to enable or disable the IP Dscp priority
Enabling IP Dscp Priority
IP Dscp Value CoS Value
Mapping Dscp Priority
14 Mapping Dscp Priority Values
10, 12, 14 18, 20, 22 26, 28, 30, 32, 34 38, 40
271
Quality of Service
270
Class map is used for matching packets to a specified class
Configuring Quality of Service Parameters
Configuring a Class Map
Class Map
Class Configuration
Match Class Settings
273
274
Policy Map
Policy Configuration
Creating QoS Policies
Policy Rule Settings Class Settings
Policy Options
125 Configuring Policy Maps
276
Attaching a Policy Map to Ingress Queues
275
277
VoIP Traffic Configuration
Configuring VoIP Traffic
282
Configuring VoIP Traffic Port
281
128 VoIP Traffic Port Configuration
284
Configuring Telephony OUI
283
285
129 Telephony OUI List
Multicast Filtering
Layer 2 Igmp Snooping and Query
Configuring Igmp Snooping and Query Parameters
214
Enabling Igmp Immediate Leave
Displaying Interfaces Attached to a Multicast Router
290
Specifying Static Interfaces for a Multicast Router
132 Displaying Multicast Router Port Information
Displaying Port Members of Multicast Services
133 Static Multicast Router Port Configuration
Assigning Ports to Multicast Services
134 IP Multicast Registration Table
Igmp Filtering and Throttling
291
Enabling Igmp Filtering and Throttling
136 Enabling Igmp Filtering and Throttling
302
Configuring Igmp Filter Profiles
298
299
Configuring Igmp Filtering and Throttling for Interfaces
Only one profile can be assigned to an interface
138 Igmp Filter and Throttling Port Configuration
301
Multicast Vlan Registration
300
303
Configuring Global MVR Settings
General Configuration Guidelines for MVR
Displaying MVR Interface Status
304
Displaying Port Members of Multicast Groups
307
Configuring MVR Interface Status
Web Click MVR, Group IP Information
142 MVR Port Configuration
Assigning Static Multicast Groups to Interfaces
305
Dhcp Snooping
Web Click Dhcp Snooping, Configuration
Dhcp Snooping Configuration
Dhcp Snooping Vlan Configuration
Enables Dhcp snooping on the specified Vlan
CLI This example first enables Dhcp Snooping for Vlan
Dhcp Snooping Information Option Configuration
Web Click Dhcp Snooping, Vlan Configuration
319
322
Dhcp Snooping Port Configuration
Web Click Dhcp Snooping, Information Option Configuration
324
Dhcp Snooping Binding Information
320
IP Source Guard Port Configuration
IP Source Guard
316
Static IP Source Guard Binding Configuration
313
Web Click IP Source Guard, Static Configuration
Dynamic IP Source Guard Binding Information
IP Clustering
Web Click IP Source Guard, Dynamic Information
Cluster Configuration
152 Cluster Member Choice
Adds Candidate switches to the cluster as Members
Cluster Member Configuration
Web Click Cluster, Configuration
325
Cluster Candidate Information
Displays current cluster Member switch information
Cluster Member Information
328
Web Click Cluster, Candidate Information
156 Cluster Candidate Information
UPnP
217
215
216
Using the Command Line Interface
Accessing the CLI
Telnet Connection
Getting Help on Commands
Entering Commands
Command Completion
Keywords and Arguments
Showing Commands
Lldp
Understanding Command Modes
Negating the Effect of Commands
Using Command History
Partial Keyword Lookup
Exec Commands
Command Modes
Consoleconfig-if# 166
Configuration Commands
Configuration Modes Command Prompt
Vlan database Consoleconfig-vlan 242
Consoleconfig#interface ethernet 1/5 Consoleconfig-if#exit
Keystroke Function
Command Line Processing
Command Line Processing
Command Groups
Command Groups Description
Line Commands
Line Commands Function Mode
Login
Line
Syntax Password 0 7 password no password
Password
Username 4-38 password
No password is specified
Timeout login response
Exec-timeout
Syntax Password-thresh threshold no password-thresh
Password-thresh
Syntax Exec-timeout seconds no exec-timeout
Syntax Silent-time seconds no silent-time
Silent-time
Databits
Syntax Parity none even odd no parity
Parity
Syntax Databits 7 8 no databits
Syntax Speed bps no speed
Speed
Stopbits
Syntax Stopbits 1
Syntax Disconnect session-id
Disconnect
Show line
Syntax Show line console vty
General Commands Function Mode
General Commands
Enable
Syntax Enable level
Enable
Disable
Disable Enable password
Level
End
Configure
Show history
Reload
Reload cancel
Syntax Reload cancel
Syntax Reload in hour hours minute minutes
Show reload
Syntax Show reload Default Setting
This command returns to Privileged Exec mode
End
Exit
This command exits the configuration program
This example shows how to quit a CLI session
Quit
Prompt
System Management Commands
Device Designation Commands
Hostname
Banner Commands Function Mode
Banner
Syntax Hostname name no hostname
Banner configure
Syntax Banner configure Default Setting
Banner configure company
Name The name of the company. Maximum length 32 characters
Banner configure dc-power-info
Banner configure department
Banner configure equipment-info
Banner configure equipment-location
Banner configure ip-lan
Banner configure lp-number
Lp-num- The LP number. Maximum length 32 characters
Syntax Banner configure mux muxinfo
Banner configure manager-info
Banner configure mux
Banner configure note
No banner configure mux
Show banner
This command displays all banner information
Syntax Show banner Default Setting
11 Default Login Settings Username Access-level Password
User Access Commands
10 User Access Commands Function Mode
Username
Enable password
Default is level Default password is super
Management
IP Filter Commands
12 IP Filter Commands Function Mode
Show management
Ip http server
Web Server Commands
Ip http port
Ip http port
Syntax No ip http secure-server Default Setting
Ip http secure-server
14 Https System Support Web Browser Operating System
Portnumber The UDP port used for HTTPS. Range
Ip http secure-port
Ip http secure-port4-44 Copy tftp https-certificate
Ip http secure-server4-43
Ip telnet server
Telnet Server Commands
Ip telnet port
Ip telnet port
Secure Shell Commands
16 SSH Commands Function Mode
Sets the SSH server key size Copy tftp public-key
System Management Commands
Ip ssh crypto host-key generate 4-51 show ssh
Syntax No ip ssh server Default Setting
Ip ssh server
Syntax Ip ssh timeout seconds no ip ssh timeout
Ip ssh timeout
Ip ssh authentication-retries
Exec-timeout4-15 show ip ssh
Syntax Delete public-key username dsa rsa
Ip ssh server-key size
Delete public-key
Syntax Ip ssh crypto host-key generate dsa rsa
Ip ssh crypto host-key generate
Ip ssh crypto zeroize
Syntax Ip ssh crypto zeroize dsa rsa
Syntax Ip ssh save host-key dsa rsa
Ip ssh save host-key
Show ip ssh
Terminology
Show ssh
17 show ssh display description
Username Name of an SSH user. Range 1-8 characters
Show public-key
Syntax Show public-key user username host
Shows all public keys
Syntax No logging on Default Setting
Event Logging Commands
18 Event Logging Commands Function Mode
Logging on
19 Logging Levels
Flash errors level 3 RAM warnings level 6
Logging history
Syntax No logging host hostipaddress
Logging host
Logging facility
Hostipaddress The IP address of a syslog server
Syntax Logging trap level no logging trap
Logging trap
Clear logging
Syntax Clear logging flash ram
20 show logging flash/ram display description
Show logging
Syntax Show logging flash ram sendmail trap
Syntax Show log flash ram login tail
Facility command
Logging trap command
Show log
Logging sendmail host
Smtp Alert Commands
22 Smtp Alert Commands Function Mode
Following example shows sample messages stored in RAM
Logging sendmail level
Syntax Logging sendmail level level
Syntax No logging sendmail source-email email-address
Logging sendmail source-email
Logging sendmail destination-email
This example will set the source email john@acme.com
Show logging sendmail
Syntax No logging sendmail Default Setting
Logging sendmail
Syntax No sntp client Default Setting
Time Commands
23 Time Commands Function Mode
Sntp client
Syntax Sntp server ip1 ip2 ip3
Sntp server
Sntp server 4-66 sntp poll 4-67 show sntp
Sntp client 4-65 sntp poll 4-67 show sntp
Sntp poll
Show sntp
Syntax Sntp poll seconds no sntp poll
Sntp client 4-65 ntp poll 4-70 ntp server
Syntax No ntp client Default Setting
Ntp client
Version number
Ntp server
Syntax
Ntp client 4-68 ntp poll 4-70 show ntp
Ntp poll
Ntp authenticate
Syntax No ntp authenticate Default Setting
Syntax Ntp poll seconds no ntp poll
Ntp authentication-key
Ntp authentication-key4-71
GMT-Greenwich-Mean-Time-Dublin,Edinburgh,Lisbon,London
Show ntp
Clock timezone-predefined
Clock timezone
Clock summer-time date
No clock summer-time
235959, Sunday, Week 5 of March 60 min Europe
Clock summer-time predefined
Australia
235959, Sunday, Week 3 of March 60 min
Clock summer-time recurring
Show calendar
This command displays the system clock
Calendar set
Calendar set hour min sec day month year month day year
25 System Status Commands Function Mode
System Status Commands
Show startup-config
Show running-config
Show running-config4-79
Command Line Interface
Show startup-config4-78
Show users
This command displays system information
Show system
Show version
Jumbo frame Enables support for jumbo frames
Frame Size Commands
26 Frame Size Commands Function Mode
Syntax No jumbo frame Default Setting
Copy
Flash/File Commands
27 Flash/File Commands Function Mode
Copy
None
Following example shows how to download a configuration file
Delete unit filename
This command deletes a file or image
Delete
Dir Delete public-key4-50
28 File Directory Information
Syntax Dir unit boot-rom config opcode filename
Dir
Column Heading Description
Syntax whichboot unit
Whichboot
Boot system
Syntax Boot system unit boot-romconfig opcode filename
Dir 4-89 whichboot
Authentication Commands
Authentication Sequence
29 Authentication Commands Command Group Function
Local
Authentication login
Username for setting the local user names and passwords
Authentication enable
Enable password sets the password for changing command modes
Radius Client
31 Radius Client Commands Function Mode
Show radius-server Shows the current Radius settings
Radius-server host
Default Setting Auth-port
Retransmit Command Mode
Radius-server acct-port
Syntax Radius-server key keystring no radius-server key
Radius-server auth-port
Radius-server key
Show radius-server
Radius-server timeout
Radius-server retransmit
TACACS+ Client
32 Tacacs Commands Function Mode
Show tacacs-server Shows the current TACACS+ settings 101
Tacacs-server host
Tacacs-server key
Default Setting Port
Tacacs-server port
Syntax Tacacs-server port portnumber no tacacs-server port
Syntax Tacacs-server key keystring no tacacs-server key
Tacacs-server timeout
Tacacs-server retransmit
Show tacacs-server
Aaa group server
AAA Commands
33 AAA Commands Function Mode
Syntax No aaa group server radius tacacs+ group-name
Aaa accounting dot1x
Server Group Configuration
Server
No server index ip-address
Aaa accounting exec
Accounting is not enabled No servers are specified
Command Usage Example
Aaa accounting commands
Minute
Accounting dot1x
Interface Configuration
Syntax Accounting exec default list-nameno accounting exec
Accounting exec
Accounting commands
Aaa authorization exec
Authorization exec
Authorization is not enabled No servers are specified
Ethernet unit/port
Show accounting
Interface
Unit Stack unit. Range Port Port number. Range
Status Disabled Action None Maximum Addresses
Port Security Commands
34 Port Security Commands Function Mode
Interface Configuration Ethernet
802.1X Port Authentication
35 802.1X Port Authentication Command Function Mode
117 Be re-authenticated Dot1x timeout tx-period
Dot1x default
Acquire a new client Dot1x timeout re-authperiod
Syntax No dotx system-auth-control Default Setting
Dot1x port-control
Default Command Mode
Dot1x max-req
Syntax Dot1x max-req count no dot1x max-req
Dot1x operation-mode
Dot1x re-authenticate
Syntax Dot1x re-authenticate interface
Single-host
Syntax No dot1x re-authentication Command Mode
Dot1x re-authentication
Dot1x timeout quiet-period
Seconds The number of seconds. Range
Dot1x timeout re-authperiod
Dot1x timeout tx-period
Block-traffic
Dot1x intrusion-action
Show dot1x
Syntax Show dot1x statistics interface interface
Authenticator State Machine
Backend State Machine
Reauthentication State Machine
State Current state including initialize, reauthenticate
Max-mac-count Interface Mac-authentication
Network-access mode
36 Network Access Command Function Mode
Syntax No network-access mode mac-authentication
Network-access max-mac-count
Interface Config
Mac-authentication intrusion-action
Mac-authentication max-mac-count
2048
Syntax No network-access dynamic-qos Default Setting
Network-access dynamic-qos
Network-access dynamic-vlan
Syntax No network-access dynamic-vlan Default Setting
Following example enables dynamic Vlan assignment on port
Network-access guest-vlan
Network-access link-detection
No network-access link-detection
Network-access link-detection link-down
Network-access link-detection link-up
1800
Network-access link-detection link-up-down
Mac-authentication reauth-time
Syntax Show network-access interface interface
Clear network-access
Show network-access
Unit This is unit Port Port number. Range
Displays all filters
Show network-access mac-address-table
Displays the settings for all interfaces
37 Web Authentication Command Function Mode
Login-success-page-url Successful web authentication
Login attempts
Web-auth login-attempts
Web-auth login-fail-page-url
Switch-generated login
Web-auth login-page-url
Web-auth login-success-page-url
Web-auth session-timeout
Web-auth quiet-period
No web-auth system-auth-control
Web-auth system-auth-control
Web-auth
No web-auth
Show web-auth interface
This command displays global web authentication parameters
Show web-auth
Web-auth re-authenticate Port
Web-auth re-authenticate IP
Show web-auth summary
Show web-auth summary
138
38 Access Control Lists Command Groups Function
Access Control List Commands
Access Control Lists
Syntax No access-list ip standard extended aclname
Access-list ip
39 IP ACLs Command Function Mode
IP ACLs
Syntax No permit deny any source bitmask host source
Permit, deny Ip access-group4-143 show ip access-list4-143
Access-list ip
Standard ACL
Extended ACL
Any destination address-bitmask host destination
Source-port sport end destination-port dport end
Syntax Show ip access-list standard extended aclname
Show ip access-list
Ip access-group
Syntax No ip access-group aclname
This command shows the ports assigned to IP ACLs
Show ip access-group
Show ip access-list4-143
40 MAC ACL Commands Function Mode
Aclname Name of the ACL. Maximum length 16 characters
Access-list mac
Syntax No access-list mac aclname
Permit, deny MAC ACL
Syntax Show mac access-list aclname
Show mac access-list
This command displays the rules for configured MAC ACLs
Permit, deny Mac access-group4-148
Syntax Mac access-group aclname
Mac access-group
Show mac access-group
Show mac access-list4-147
41 ACL Information Command Function Mode
Show access-list
Show access-group
ACL Information
Snmp Commands
42 Snmp Commands Function Mode
Show snmp
Syntax No snmp-server Default Setting
Snmp-server
Snmp-server community
Syntax Snmp-server contact string no snmp-server contact
Snmp-server contact
Snmp-server location
Syntax Snmp-server location text no snmp-server location
Snmp-server host
Host Address None Notification Type Traps
Snmp Version UDP Port
Issue authentication and link-up-down traps
Snmp-server enable traps
Snmp-server enable traps
Snmp-server engine-id
Show snmp engine-id
This command shows the Snmp engine ID
This example shows the default engine ID
Examples
Defaultview includes access to the entire MIB tree
Snmp-server view
This view includes MIB-2
Snmp-server group
This command shows information on the Snmp views
Show snmp view
44 show snmp view display description
Show snmp group
162
Snmp-server user
45 show snmp group display description
164
46 show snmp user display description
This command shows information on Snmp users
Show snmp user
Interface
Interface Commands
47 Interface Commands Function Mode
Port-channel channel-idRange
Syntax Description string no description
Description
Speed-duplex
Negotiation 4-168 capabilities
Syntax No negotiation Default Setting
Negotiation
Capabilities 4-169speed-duplex4-167
Following example configures port 11 to use autonegotiation
Capabilities
Negotiation 4-168speed-duplex4-167 flowcontrol
Syntax No flowcontrol Default Setting
Flowcontrol
Syntax No shutdown Default Setting
Shutdown
Clear counters
Switchport packet-rate
Port-channel channel-idRange Default Setting
Syntax Clear counters interface
Following example clears statistics on port
This command displays the status for an interface
Show interfaces status
Syntax Show interfaces status interface
Syntax Show interfaces counters interface
This command displays interface statistics
Show interfaces counters
Shows the counters for all interfaces
Shows all interfaces
Show interfaces switchport
Syntax Show interfaces switchport interface
48 Interfaces Switchport Statistics
Port monitor
Mirror Port Commands
49 Mirror Port Commands Function Mode
Interface ethernet unit/port source port
Show port monitor
This command displays mirror information
Following shows mirroring configured from port 6 to port
Syntax Show port monitor interface
Rate-limit Configures the maximum input rate for a port 179
Rate Limit Commands
50 Rate Limit Commands Function Mode
Rate-limit
185
Link Aggregation Commands
51 Link Aggregation Commands
173
General Guidelines
Channel-group
Guidelines for Creating Trunks
Dynamically Creating a Port Channel
Following example creates trunk 1 and then adds port
Syntax No lacp Default Setting
Lacp
Lacp system-priority
32768
Lacp admin-keyEthernet Interface
Lacp admin-key Port Channel
Interface Configuration Port Channel
Show lacp
This command displays Lacp information
Lacp port-priority
Type
Port Channel all
52 show lacp counters display description
LACPDUs Illegal Pkts
53 show lacp internal display description
54 show lacp neighbors display description
55 show lacp sysid display description
Mac-address-table static
Address Table Commands
56 Address Table Commands Function Mode
Action
Mac-address- MAC address Mask Bits to match in the address
Clear mac-address-table dynamic
Show mac-address-table
Mac-address-table aging-time
Sort Sort by address, vlan or interface
Show mac-address-table aging-time
Lldp Commands
57 Lldp Commands Function Mode
196
Mac-phy Physical layer specifications Lldp dot3-tlv
Vlan ID
Lldp holdtime-multiplier
Syntax no lldp Default Setting
Lldp
Holdtime multiplier TTL 4*30 = 120 seconds
Syntax Lldp medfaststartcount packets
Lldp medFastStartCount
Lldp notification-interval
Packets
Syntax Lldp refresh-interval seconds no lldp refresh-delay
Lldp refresh-interval
Syntax Lldp reinit-delay seconds no lldp reinit-delay
Lldp reinit-delay
Lldp tx-delay
Syntax Lldp tx-delay seconds no lldp tx-delay
Lldp notification
Lldp admin-status
Syntax No lldp notification Default Setting
Tx-rx
Syntax No lldp mednotification Default Setting
Lldp mednotification
Lldp basic-tlv management-ip-address
Lldp basic-tlv port-description
Lldp basic-tlv system-description
Syntax No lldp basic-tlv port-description Default Setting
Lldp basic-tlv system-capabilities
Lldp basic-tlv system-name
Syntax No lldp basic-tlv system-description Default Setting
Syntax No lldp basic-tlv system-name Default Setting
Lldp dot1-tlv proto-ident
Lldp dot1-tlv proto-vid
Syntax No lldp dot1-tlv proto-vid Default Setting
No lldp dot1-tlv proto-ident
Lldp dot1-tlv pvid
Lldp dot3-tlv link-agg
Lldp dot1-tlv vlan-name
No lldp dot1-tlv vlan-name
No lldp dot3-tlv link-agg
Lldp dot3-tlv max-frame
Syntax No lldp dot3-tlv mac-phy Default Setting
Lldp dot3-tlv mac-phy
Syntax No lldp dot3-tlv max-frame
Lldp medtlv extpoe
Syntax No lldp dot3-tlv poe Default Setting
Lldp dot3-tlv poe
Syntax No lldp medtlv extpoe
Lldp medtlv location
Lldp medtlv inventory
No lldp medtlv inventory
No lldp medtlv location
Lldp medtlv network-policy
Lldp medtlv med-cap
No lldp medtlv med-cap
No lldp medtlv network-policy
Detail Shows configuration summary
Show lldp config
Syntax Show lldp config detail interface
Port-channel channel-idRange Command Mode
211
Detail Shows detailed information
Show lldp info local-device
Syntax Show lldp info local-device detail interface
Syntax Show lldp info remote-device detail interface
Show lldp info remote-device
Show lldp info statistics
Syntax Show lldp info statistics detail interface
214
Syntax No upnp device Default Setting
UPnP Commands
UPnP Commands Function Mode
Upnp device
Syntax Upnp device ttl value
Upnp device ttl
Upnp device advertise duration
Following example, the TTL is set to
Show upnp
Spanning Tree Commands
58 Spanning Tree Commands Function Mode
Spanning-tree
Syntax No spanning-tree Default Setting
Spanning tree is enabled
Spanning-tree mode
Rstp
Spanning-tree forward-time
Spanning-tree hello-time
Spanning-tree max-age
Syntax Spanning-tree pathcost method long short
Spanning-tree priority
Spanning-tree pathcost method
No spanning-tree pathcost method
Spanning-tree mst-configuration
Spanning-tree transmission-limit
No mst instanceid vlan vlan-range
MST Configuration
Mst vlan
Mst instanceid priority priority no mst instanceid priority
Mst priority
Name
Syntax Name name
Syntax Revision number
Revision
Max-hops
Number Revision number of the spanning tree. Range
This example disables the spanning tree algorithm for port
Spanning-tree spanning-disabled
Syntax No spanning-tree spanning-disabled Default Setting
Spanning-tree cost
Spanning-tree port-priority
Priority The priority for a port. Range 0-240, in steps
Syntax No spanning-tree edge-port Default Setting
Spanning-tree edge-port
Spanning-treeedge-port4-229
Syntax No spanning-tree portfast Default Setting
Spanning-tree portfast
Auto
Spanning-tree link-type
Spanning-tree loopback-detection
Spanning-tree loopback-detection release-mode
Spanning-tree loopback-detection trap
Spanning-tree mst cost
Spanning-tree mst port-priority
Spanning-tree mst port-priority4-234
Syntax Spanning-tree protocol-migration interface
Spanning-tree protocol-migration
Show spanning-tree
Syntax Show spanning-tree interface mst instanceid
Mstp
Show spanning-tree mst configuration
59 VLANs Command Groups Function
Vlan Commands
Gvrp and Bridge Extension Commands
60 Gvrp and Bridge Extension Commands Function Mode
Show bridge-ext
Syntax No bridge-ext gvrp Default Setting
Bridge-ext gvrp
Syntax No switchport gvrp Default Setting
Switchport gvrp
Show gvrp configuration
Syntax Show gvrp configuration interface
Garp timer
Show garp timer
Editing Vlan Groups
Syntax Show garp timer interface
61 Editing Vlan Groups Command Function Mode
Vlan database
Vlan
By default only Vlan 1 exists and is active
Vlan Database Configuration
Show vlan
Interface vlan
Configuring Vlan Interfaces
62 Configuring Vlan Interfaces Command Function Mode
Interface vlan
Switchport acceptable-frame-types4-246
Switchport mode
All ports are in hybrid mode with the Pvid set to Vlan
Switchport mode
Switchport acceptable-frame-types
Switchport ingress-filtering
All frame types
Switchport native vlan
Switchport allowed vlan
Switchport forbidden vlan
No VLANs are included in the forbidden list
Show vlan
63 Show Vlan Commands Function Mode
Displaying Vlan Information
Dot1q-tunnel system-tunnel-control
64 Ieee 802.1Q Tunneling Commands Function Mode
General Configuration Guidelines for QinQ
Syntax No dot1q-tunnel system-tunnel-control
Switchport dot1q-tunnel mode
Show dot1q-tunnel4-253 Show interfaces switchport
Show dot1q-tunnel
Switchport dot1q-tunnel tpid
This command displays information about QinQ tunnel ports
0x8100
65 Private Vlan Commands
Configuring Private VLANs
Switchport dot1q-tunnel mode
Edit Private Vlan Groups Private-vlan
Display Private Vlan Information
65 Private Vlan Commands Function Mode
Configure Private Vlan Interfaces
Private-vlan
Private vlan association
Normal Vlan
Switchport mode private-vlan
No private-vlan primary-vlan-idassociation
Isolated-vlan-id- ID of isolated VLAN. Range
Switchport private-vlan host-association
Switchport private-vlan isolated
Switchport private-vlan mapping
Show vlan private-vlan
Syntax Show vlan private-vlan community isolated primary
Protocol-vlan protocol-group Configuring Groups
66 Protocol-based Vlan Commands Function Mode
No protocol groups are mapped to any VLANs
Protocol-vlan protocol-group Configuring VLANs
No protocol groups are configured
Syntax Show protocol-vlan protocol-group group-id
Show protocol-vlan protocol-group
Show protocol-vlan protocol-group-vid
67 Priority Commands Command Groups Function
Priority Commands
Priority Commands Layer
68 Priority Commands Layer Function Mode
Syntax Queue mode strict wrr no queue mode
Queue mode
Switchport priority default
Queue bandwidth
Queue bandwidth weight1...weight4 no queue bandwidth
Weights 1, 2, 4, 8 are assigned to queues 0-3 respectively
Queue cos-mapqueueid cos1 ... cosn no queue cos-map
69 Default CoS Values to Egress Queues
Queue cos-map
This command shows the current queue mode
Show queue mode
Following example shows how to change the CoS assignments
Show queue bandwidth
70 Priority Commands Layer 3 Function Mode
Priority Commands Layer 3
This command shows the class of service priority map
Show queue cos-map
71 IP Dscp to CoS Vales IP Dscp Value CoS Value
Syntax No map ip dscp Default Setting
Map ip dscp dscp-value cos cos-value no map ip dscp
Syntax Show map ip dscp interface
This command shows the IP Dscp priority map
Show map ip dscp
Quality of Service Commands
72 Quality of Service Commands Function Mode
Class-map
Syntax No class-map class-map-namematch-any
Show class map
Class Map Configuration
Match
Policy-map
No policy-mappolicy-map-name
No class class-map-name
Policy Map Configuration
Class
Police
Policy Map Class Configuration
Set
Syntax No police rate-kbpsburst-byteexceed-action drop set
No policy map is attached to an interface
Service-policy
Syntax No service-policy input policy-map-name
Syntax Show class-map class-map-name
Show class-map
Show policy-map
Show policy-mappolicy-map-name class class-map-name
Show policy-map interface
Voice Vlan Commands
73 Voice Vlan Commands Function Mode
Syntax Show policy-map interface interface input
Voice vlan
Voice vlan voice-vlan-id no voice vlan
Syntax Voice vlan aging minutes no voice vlan
Voice vlan aging
Voice vlan mac-address
Minutes
Following example adds a MAC OUI to the OUI Telephony list
Switchport voice vlan
Following example sets port 1 to Voice Vlan auto mode
Syntax No switchport voice vlan rule oui lldp
Switchport voice vlan rule
Switchport voice vlan security
OUI Enabled Lldp Disabled
Priority-value- The CoS priority value. Range
Switchport voice vlan priority
Following example enables security filtering on port
Following example sets the CoS priority to 5 on port
Show voice vlan
Syntax Show voice vlan oui status
74 Multicast Filtering Commands Command Groups Function
Multicast Filtering Commands
Igmp Snooping Commands
75 Igmp Snooping Commands Function Mode
Ip igmp snooping
Syntax No ip igmp snooping Default Setting
Following example enables Igmp snooping
Ip igmp snooping vlan static
Ip igmp snooping version
Following configures the switch to use Igmp Version
Syntax No ip igmp snooping leave-proxy Default Setting
Ip igmp snooping leave-proxy
Ip igmp snooping immediate-leave
Interface Configuration Vlan
Following shows how to enable immediate leave
Syntax No ip igmp snooping immediate-leave vlan-id
This command shows known multicast addresses
This command shows the Igmp snooping configuration
Following shows the current Igmp snooping configuration
Show ip igmp snooping
Syntax No ip igmp snooping querier Default Setting
Igmp Query Commands Layer
76 Igmp Query Commands Layer Function Mode
Ip igmp snooping querier
Ip igmp snooping query-interval
Following shows how to configure the query count to
Ip igmp snooping query-count
Times
Seconds The report delay advertised in Igmp queries. Range
Ip igmp snooping query-max-response-time
Ip igmp snooping router-port-expire-time
Static Multicast Routing Commands
77 Static Multicast Routing Commands Function Mode
Syntax No ip igmp snooping vlan vlan-idmrouter interface
Ip igmp snooping vlan mrouter
Show ip igmp snooping mrouter
Syntax Show ip igmp snooping mrouter vlan vlan-id
Multicast router port types displayed include Static
Igmp Filtering and Throttling Commands
78 Igmp Filtering and Throttling Commands Function Mode
299
Syntax No ip igmp profile profile-number
Syntax No ip igmp filter Default Setting
Ip igmp profile
Profile-number- An Igmp filter profile number. Range
Range
Syntax Permit deny Default Setting
Permit, deny
No range low-ip-address high-ip-address
Syntax Ip igmp max-groups number no ip igmp max-groups
Ip igmp max-groups
Syntax No ip igmp filter profile-number
Ip igmp max-groups action
Syntax Ip igmp max-groups action replace deny
Syntax Show ip igmp filter interface interface
Show ip igmp filter
Show ip igmp profile
Syntax Show ip igmp profile profile-number
Show ip igmp throttle interface
Syntax Show ip igmp throttle interface interface
305
Multicast Vlan Registration Commands
79 Multicast Vlan Registration Commands Function Mode
Multicast groups assigned to the MVR Vlan
Mvr Interface Configuration
306
Syntax Show mvr interface interface members ip-address
Following shows the global MVR settings
Show mvr
80 show mvr display description
81 show mvr interface display description
82 show mvr members display description
Ip address
IP Interface Commands
83 IP Interface Commands Function Mode
310
Gateway IP address of the default gateway
Ip default-gateway
Syntax Ip default-gateway gateway no ip default-gateway
Following example defines a default gateway for this device
Ip dhcp restart
This command submits a Bootp or Dhcp client request
This command displays the settings of an IP interface
Show ip interface
Show ip redirects
Ip default-gateway4-310
This command has no default for the host
Ping
Ip source-guard
IP Source Guard Commands
84 IP Source Guard Commands Function Mode
Syntax Ip source-guard sip sip-macno ip source-guard
314
Ip source-guard binding
This example enables IP source guard on port
No configured entries
No ip source-guard binding mac-addressvlan vlan-id
Show ip source-guard binding
This command shows the source guard binding table
Show ip source-guard
Ip source-guard4-313 ip dhcp snooping Ip dhcp snooping vlan
Syntax No ip dhcp snooping Default Setting
Dhcp Snooping Commands
85 Dhcp Snooping Commands Function Mode
Ip dhcp snooping
318
Ip dhcp snooping vlan
This example enables Dhcp snooping globally for the switch
This example enables Dhcp snooping for Vlan
Ip dhcp snooping vlan 4-319 ip dhcp snooping trust
Syntax No ip dhcp snooping trust Default Setting
Ip dhcp snooping trust
Ip dhcp snooping information option
This example enables MAC address verification
Ip dhcp snooping verify mac-address
Replace
This example enables the Dhcp Snooping Information Option
Ip dhcp snooping information policy
Show ip dhcp snooping
This command shows the Dhcp snooping configuration settings
Ip dhcp snooping database flash
Syntax No cluster Default Setting
IP Cluster Commands
86 Switch Cluster Commands Function Mode
Show ip dhcp snooping binding
Cluster commander
Syntax No cluster commander Default Setting
Syntax Cluster ip-pool ip-addressno cluster ip-pool
Cluster ip-pool
Cluster member
10.254.254.1
Member-id- The ID number of the Member switch. Range
Rcommand
Syntax Rcommand id member-id
This command shows the switch clustering configuration
Show cluster candidates
This command shows the current switch cluster members
Show cluster members
Appendix a Software Specifications
Software Features
Standards
Management Features
Groups 1, 2, 3, 9 Statistics, History, Alarm, Event
Igmp RFC 1112 IGMPv2 RFC
Management Information Bases
Management Information Bases a
Software Specifications
Table B-1 Troubleshooting Chart
Symptom Action
Using System Logs
Class of Service CoS
Access Control List ACL
Boot Protocol Bootp
Differentiated Services Code Point Service Dscp
Generic Multicast Registration Protocol Gmrp
Garp Vlan Registration Protocol Gvrp
Generic Attribute Registration Protocol Garp
Group Attribute Registration Protocol Garp
Internet Group Management Protocol Igmp
Igmp Snooping
Igmp Query
In-Band Management
Remote Authentication Dial-in User Service Radius
Multicast Switching
Port Authentication
Network Time Protocol NTP
Simple Network Time Protocol Sntp
Secure Shell SSH
Simple Network Management Protocol Snmp
Spanning Tree Algorithm STA
Virtual LAN Vlan
XModem
Index
Numerics
Index
Link Layer Discovery Protocol See
Index-4
Index-5
Type Length Value See also
LLDP-MED TLV
Page
ES3528M-SFP E122007-DG-R01 149100035500A