Command Line User’s Guide
Page
 Table of Contents
 101
 103
 181
 232
 326
 389
 462
 532
 Preface
 AT-S62 Command Line User’s Guide
 This document uses the following conventions
 Contacting Allied Telesyn
 Starting a Command Line Management Session
 Starting a Management Session
 Command Line Interface Features
 Command Formatting
 Basic Command Line Commands
 Clear Screen
This command clears the screen
Following command clears the screen
Clear screen
 Exit
Following command displays the Main Menu
Exit
 Help
Following command displays the CLI keywords
Help
 Logoff
Following command ends a management session
Logoff Logout Quit
 Menu
Following command displays the AT-S62 Main Menu
Menu
 Save Configuration
Save configuration
 Set prompt=prompt
Set prompt=Sales Switch
SET Prompt
Prompt
 Set switch consolemode=menu
SET Switch Consolemode
Set switch consolemode=menucli
 Show User
Show user
 Enhanced Stacking Commands
Guide for background information on enhanced stacking
 Macaddress
Access Switch
Access switch number=numbermacaddress=macaddress
Either of the following formats
 Access switch number=12
Access switch macaddress=003084520211
 Possible settings are
SET Switch Stackmode
Set switch stackmode=masterslaveunavailable
Stackmode
 Set switch stackmode=master
 Show remotelist sorted by=macaddressname
Following command displays the switches sorted by name
Show Remotelist
Show remotelist
 Basic Switch Commands
 AT-S62 Command Line User’s Guide
 Disable Dhcpbootp
Disable dhcpbootp
 Disable IP Remoteassign
Disable ip remoteassign
 Following command deactivates the Telnet server
Disable Telnet
Disable telnet
 Enable Bootp
Enable bootp
 Enable Dhcp
Enable dhcp
 Enable IP Remoteassign
Enable ip remoteassign
 Following command activates the Telnet server
Enable Telnet
Enable telnet
 Format drive=flash
AT-8500 Series switch supports only one
Format Device
Drive
 Basic Switch Commands
 Ping
Ping
 Purge ip ipaddress netmask
Purge IP
Purge ip ipaddress netmask route
Purge ip ipaddress route
 This command performs the functions described above
Reset Switch
Reset switch
 Reset system
Reset System
Reset system name contact location
Reset system name
 Following command resets the switch
Restart Reboot
Restart reboot
 Config
Restart Switch
Restart switch config=nonefilename.cfg
Exist on the switch. The value None returns
 Restart switch config=none
Restart switch config=switch12.cfg
Following command resets the switch to its default values
 SET Asyn
Set asyn speed=115200
 SET IP Interface
 Set ip interface=eth0 netmask=255.255.255.252
Following command sets just the subnet mask
Following command activates the Dhcp client software
Set ip interface=eth0 ipaddress=dhcp
 Set ip route ipaddress=ipaddress
Following command sets the default gateway to
SET IP Route
Set ip route ipaddress=140.35.22.12
 Following command changes the manager’s password
SET Password Manager
Set password manager
Follow the prompts to enter the new password
 Following command changes the operator’s password
SET Password Operator
Set password operator
 Following command sets the console timer to 25 minutes
SET Switch Consoletimer
Set switch consoletimer=value
Set switch consoletimer=25
 Set system name=PR Office
SET System
Set system name=name contact=contact location=location
 Password
SET User Password
Show user manageroperator password=password
Following command changes the operator’s password to newby
 Show Asyn
Show asyn
 Show config
Show Config
Show config dynamic info
Show config info
 Show Dhcpbootp
Show dhcpbootp
 Show IP Interface
Show ip interface=eth0
 Show IP Route
Show ip route
 Show Switch
Show switch
 Show system
Following command displays the above information
Show System
 Simple Network Time Protocol Sntp Commands
Guide for background information on Sntp
 Peer
ADD Sntpserver Peeripaddress
Add sntpserver peeripaddress=ipaddress
Ipaddress Parameters are equivalent
 Delete sntpserver ipaddress=148.35.16.248
Delete Sntpserver Peeripaddress
Delete sntpserver peeripaddress=ipaddress
 Following command disables Sntp on the switch
Disable Sntp
Disable sntp
 Following command enables the Sntp client software
Enable Sntp
Enable sntp
 Purge sntp
Following command resets Sntp
Purge Sntp
 Time in 24-hour format
Following command sets just the date to April 2
SET Date Time
Set date=11-03-2004 time=163452
 Set sntp dst=enabled pollinterval=300 utcoffset=-8
SET Sntp
 Show sntp
Following command displays Sntp client software information
Show Sntp
 Show Time
This command shows the switch’s current date and time
Following command shows the system’s date and time
Show time
 SNMPv1 and SNMPv2 Community Strings and Trap Commands
Guide for background information on Snmp
 Must be enclosed in double quotes if it contains a
ADD Snmp Community
Community
Point. Otherwise, the quotes are optional
 Add snmp community=public traphost=149.212.10.11
 Create Snmp Community
 Community string as closed. a community string can
Can use the community string to access the switch
This option applies if you specify the status
Have up to eight IP addresses of management
 Create snmp community=serv12 access=read open=yes
 Delete Snmp Community
 Delete snmp community=public traphost=149.212.44.45
 Destroy snmp community=wind44
Destroy Snmp Community
Destroy snmp community=community
 Following command disables Snmp on the switch
Disable Snmp
Disable snmp
 Disable snmp authenticatetrap
Disable Snmp Authenticatetrap
Disable snmp authenticatetrapauthenticatetrap
 Disable snmp community=sw1200
Disable Snmp Community
Disable snmp community=community
String must be enclosed in double quotes if it
 Following command activates Snmp on the switch
Enable Snmp
Enable snmp
 Enable snmp authenticatetrap
Enable Snmp Authenticatetrap
Enable snmp authenticatetrapauthenticatetrap
 Enable snmp community=private
Enable Snmp Community
Enable snmp community=community
 SET Snmp Community
Set snmp community=sw44 open=no
 Set snmp community=serv12 access=write open=yes
 Show Snmp
Otherwise, the quotes are optional. Default
This command displays the following Snmp information
Show snmp community=community
 Show snmp
Show snmp community=private
 SNMPv3 Commands
 Guide for background information on the SNMPv3 protocol
 ADD SNMPV3 User
 Configuration file on the switch
Entry to the configuration file on
Switch. This is the default
This command creates an SNMPv3 User Table entry
 Writeview Specifies a Write View Name that allows the users
Clear SNMPV3 Access
An optional parameter
 Parameter
Notifyview
Assigned to this security group to send traps
 Clear snmpv3 community index=1005 transporttag
Clear SNMPV3 Community
Clear snmpv3 community index=index transporttag
Clear snmpv3 community index=421 transporttag
 Clear snmpv3 notify=hwengtraptag tag
Clear SNMPV3 Notify
Clear snmpv3 notify=notify tag
Clear snmpv3 notify=hwenginform tag
 Clear snmpv3 targetaddr=snmphost44 taglist
Clear SNMPV3 Targetaddr
Clear snmpv3 targetaddr=targetaddr taglist
Clear snmpv3 targetaddr=snmphost79 taglist
 Clear snmpv3 view=1.3.6.1.2.1.1 mask
Clear SNMPV3 View
Clear snmpv3 view=view subtree=OIDtext mask
Clear snmpv3 view=private subtree=1.3.6.1.4 mask
 Create SNMPV3 Access
 This command creates an SNMPv3 Access Table entry
Parameter, then the writeview parameter defaults to
Notifyview parameter defaults to none
Information in the specified View Table. This is an
 111
 Create SNMPV3 Community
 113
 This command creates an SNMPv3 SecurityToGroup Table entry
Groupname Specifies a group name configured in the SNMPv3
SNMPV3 Access on
Create SNMPV3 Group
 115
 Create SNMPV3 Notify
NMS or manager. This is the default
This command creates an SNMPv3 Notify Table entry
Inform Inform messages are sent, with a
 117
 Create SNMPV3 Targetaddr
 119
 User Table
Create SNMPV3 Targetparams
Targetparams Specifies the name of the SNMPv3 Target
 This command creates an SNMPv3 Target Parameters Table entry
 Options are
This command creates an SNMPv3 View Table entry
Create SNMPV3 View
 123
 Delete snmpv3 user=wilson890
Delete SNMPV3 User
Delete snmpv3 user=user
Delete snmpv3 user=75murthy75
 Destroy SNMPv3 Access
 126
 Destroy snmpv3 community index=5
Destroy snmpv3 community index=index
Destroy snmpv3 community index=1001
 Destroy snmpv3 group username=Dave securitymodel=v3
Destroy snmpv3 group username=May securitymodel=v3
 Destroy snmpv3 notify=engineeringinform1
Destroy snmpv3 notify=notify
Destroy snmpv3 notify=systemtestnotifytrap
 Destroy snmpv3 targetaddr=snmpmanager
Destroy snmpv3 targetaddr=target
Destroy snmpv3 targetaddr=snmpv3host77
 Destroy snmpv3 targetparams=targetparameter1
Destroy snmpv3 targetparams=targetparams
Targetparams
Destroy snmpv3 targetparams=snmpmanager
 Subtree Specifies the view subtree view. The options are
Destroy SNMPV3 View
Destroy snmpv3 view=view subtree=OIDtext
Text Text name of the view
 Information in the specified View Table
SET SNMPV3 Access
Specified by the View Table entry
Specified View
 This command modifies an SNMPv3 Access Table entry
 This command modifies an SNMPv3 Community Table entry
SET SNMPV3 Community
 136
 This command modifies an SNMPv3 SecurityToGroup Table entry
SET SNMPV3 Group
 138
 This command modifies an SNMPv3 Notify Table entry
SET SNMPV3 Notify
 140
 Parameter Udpport
Retries Specifies the number of times the switch retries to
SET SNMPV3 Targetaddr
 This command modifies an SNMPv3 Target Address Table entry
 SET SNMPV3 Targetparams
Username Specifies the user name Securitymodel
 This command modifies a Target Parameters Table entry
 SET SNMPV3 User
 146
 Name to see the specified subtree
This command modifies an SNMPv3 View Table entry
SET SNMPV3 View
 Set snmpv3 view=internet1 subtree=internet type=included
Set snmpv3 view=system subtree=1.3.6.1.2.1 type=excluded
 Show snmpv3 access=production
Show SNMPV3 Access
Show snmpv3 access=access
Show snmpv3 access
 Show snmpv3 community index=246
Show SNMPV3 Community
Show snmpv3 community index=index
Show snmpv3 community
 Show snmpv3 group username=Dave securitymodel=v3
Show snmpv3 group
 Show snmpv3 notify=testengtrap1
Show SNMPV3 Notify
Show snmpv3 notify=notify
Show snmpv3 notify
 Show snmpv3 targetaddr=snmpv3host55
Show SNMPV3 Targetaddr
Show snmpv3 targetaddr=targetaddr
Show snmpv3 targetaddr
 Show snmpv3 targetparams=snmpv3manager95
Show SNMPV3 Targetparams
Show snmpv3 targetparams=targetparams
Show snmpv3 targetparams
 Show snmpv3 user=Robert
Show SNMPV3 User
Show snmpv3 user=user
Show snmpv3 user
 Show SNMPV3 View
Show snmpv3 view=view subtree=OIDtext
 Port Parameter Commands
Guide for background information on the port parameters
 Activate switch port=1,4 autonegotiate
Activate Switch Port
Activate switch port=port autonegotiate
 Following command disables link traps on port
Disable Interface Linktrap
Disable interface=port linktrap
Disable interface=21
 Following command disables ports 12
Disable Switch Port
Disable switch port=port
Disable switch port=12,24
 Disable switch port=6 flow=pause
Disable Switch Port Flow
Disable switch port=port flow=pause
 Following command enables Snmp link traps on port
Enable Interface Linktrap
Enable interface=port linktrap
Enable interface=21
 Following command enables ports 1 to
Enable Switch Port
Enable switch port=port
Disable switch port=1-4
 Port Specifies the port where you want to activate flow
Enable Switch Port Flow
Enable switch port=port flow=pause
This command activates flow control on port
 Following command resets ports 5 to
Reset Switch Port
Reset switch port=port
Reset switch port=5-8
 SET Switch Port
Mdimode=mdimdixauto
 To the port. This is the default setting
Default setting
Mdi Sets the port’s configuration to MDI Mdix
Auto-Negotiation
 Switch port
Is using flow control, the switch port
Is not using flow control, neither will
Default is 57,344 cells
 Only value is
Duplex mode
Softreset
A port’s operating parameters
 Set switch port=8 speed=10mhalf
Following command disables ports 1 to
Set switch port=1-6 status=disabled
Following command resets port
 No, off, false, disabled Deactivates multicast
SET Switch Port Ratelimit
Yes, on, true, enabled Activates multicast
 Set switch port=all unkucastratelimiting=enabled
 Set switch port=all unkucastratelimiting=disabled
This command changes the rate limit to 15,000 packets
Set switch port=all rate=15000
 Port Specifies the port whose interface information you
Show Interface
Show interface=port
 Following command displays the above information on port
Show interface=21
 Show switch port
Show Switch Port
Show switch port=port
Show switch port=14
 MAC Address Table Commands
Guide for background information on the MAC address table
 ADD Switch Fdbfilter
 179
 Delete switch fdb macaddress=00A0D2181A11 vlan=1
Delete Switch FDB
Delete switch fdb macaddress=macaddress vlan=namevid
Delete switch fdb macaddress=00a0c1112244 vlan=sales
 Reset switch fdb port=5
Reset Switch FDB
Reset switch fdb port=port
Specify more than one port at a time
 Set switch agingtimer=120
SET Switch Agingtimerageingtimer
Set switch agingtimerageingtimer=value
 Show switch agingtimer
Show Switch Agingtimerageingtimer
Show switch agingtimerageingtimer
 Show switch fdb status=static
Show Switch FDB
Show switch fdb
 Show switch fdb port=2
Show switch fdb status=multicast
Show switch fdb address=00A0D2181A11
Show switch fdb vlan=sales
 Port Trunking Commands
 Following command adds port 5 to a port trunk called load22
ADD Switch Trunk
Add switch trunk=name port=port
Add switch trunk=load22 port=5
 Create Switch Trunk
 Create switch trunk=load22 port=3-6 select=macdest
Create switch trunk=trunk4 port=15,17,23
 Delete switch trunk=Devtrunk port=9
Delete Switch Trunk
Delete switch trunk=name port=port
Trunk Specifies the name of the trunk to be modified Port
 Destroy switch trunk=load22
Destroy Switch Trunk
Destroy switch trunk=name
 Trunk Specifies the name of the port trunk Select
SET Switch Trunk
Set switch trunk=Load11 select=ipdest
 Following command displays port trunking information
Show Switch Trunk
Show switch trunk
 Networking Stack Commands
This chapter contains the following commands
 Delete ip arp ipaddressall
Following command deletes the ARP entry with the IP address
Delete IP ARP
Delete ip arp
 Delete tcp
Delete TCP
Delete tcp indexnumber
 Reset IP ARP
Reset ip arp
 Set ip arp timeout=600
Set ip arp timeout=integer
Following command sets the timer to 600 seconds
SET IP ARP
 Show ip arp
Following command displays the ARP table
Show IP ARP
IP addresses and their corresponding MAC addresses
 Following command displays the IP route table
IP address of a destination network, subnetwork, or end node
 Show TCP
Show tcp
 Number of segments transmitted with the RST bit set
Internal socket ID number assigned to the connection
 203
 Lacp Commands
Guide for background information and guidelines on Lacp
 ADD Lacp Port
 Add lacp port=6 adminkey=0x1a priority=0x10
Add lacp port=8,22 aggregator=agg1
 Create Lacp Aggregator
 Following command creates an Lacp aggregator named
 Delete lacp port=9
Delete Lacp Port
Delete lacp port=port aggregator=name
 Destroy lacp adminkey=0x1a
Destroy lacp aggregator=nameadminkey=key
Following command deletes an aggregator named agg15
Destroy Lacp Aggregator
 Following command disables Lacp on the switch
Disable Lacp
Disable lacp
 Following command enables Lacp
Enable Lacp
Enable lacp
 Set lacp aggregator=agg5 distribution=macsrc
Set lacp aggregator=server11trunk adminkey=0x22
SET Lacp Aggregator
 SET Lacp Port
 Following command changes the priority of port 6 to 0x2B
Set lacp port=2,5 aggregator=switchtrunk
Set lacp port=8-9 adminkey=0x11
Set lacp port=6 priority=0x2b
 Set lacp priority=priority
Following command sets the Lacp priority on the switch to
SET Lacp Priority
This is a hexadecimal value from 0x1 to 0xffff.
 SET Lacp State
Set lacp state=enabledisable
Set lacp state=enable
 Show Lacp
 Port Mirroring Commands
 Set switch mirror=11
SET Switch Mirror
Set switch mirror=port
Set switch mirror=0
 Set switch port=16-17 mirror=rx
SET Switch Port Mirror
Set switch port=port mirror=nonerxtxboth
Set switch port=5,7,10 mirror=none
 Following command displays the ports of a port mirror
Show Switch Mirror
Show switch mirror
 Statistics Commands
Guide for background information on statistics
 This command returns a port’s statistics counters to zero
Reset Switch Port Counter
Reset switch port=port counter
Reset switch port=14-15 counter
 Show Switch Counter
Show switch counter
 Show switch port=14 counter
Show Switch Port Counter
Show switch port=port counter
Show switch port counter
 File System Commands
Guide for background information on the switch’s file system
 Copy
Copy admin.cfg admin2.cfg
Copy switch 12.cfg backup.cfg
 Create config=Switch12.cfg
Create Config
Create config=filename.cfg
Filename contains spaces, it must be enclosed
 Delete file=filename
Delete file=Switch 12.cfg
Delete File
Delete file=SW55a.csr
 If the name contains spaces, enclose it
Rename Switch12.cfg Sw 44a.cfg
Rename
 Spaces, it must be enclosed in double quotes
SET Config
Set config=filename.cfg
 Set config=switch22.cfg
 Show file=
Show File
Show file=filename
Show file=*.cfg
 File Download and Upload Commands
 Block. If the filename contains a space, enclose
Load METHOD=LOCAL
System that you want to download into the application
Name in double quotes. These parameters are
 Load method=local destfile=appblock srcfile=ats62v1 3 0.img
 Load METHOD=TFTP
 Public key certificate enrollment
AT-S62 configuration file
Public key certificate
Request
 240
 241
 Load method=xmodem destfile=appblockfilename
As the new active image file on the switch
Load METHOD=XMODEM
Method Specifies an Xmodem download Destfile
 243
 Load method=xmodem destfile=appblock
Load method=xmodem destfile=switch12.cfg
Load method=xmodem destfile=sw12ssl.cer
 Load method=xmodem destfile=ats62v130.img
 Upload METHOD=LOCAL
Active AT-S62 image file is stored
 Upload method=local destfile=sw12 s62 image.img src=appblock
 Upload METHOD=REMOTESWITCH
 249
 250
 Upload method=remoteswitch srcfile=appblock switchlist=2
 252
 Upload METHOD=TFTP
 254
 255
 Specifies the name of a file
Switch’s file system
Upload METHOD=XMODEM
Appblock
 Upload method=xmodem srcfile=sw12sslenroll.csr
Upload method=xmodem srcfile=sw22 boot.cfg
Upload method=xmodem srcfile=switchcfg
 Event Log and Syslog Server Commands
 ADD LOG Output
 Add log output=5 module=all severity=all
Add log output=3 module=estack severity=e
 Add log output=4 module=stp,vlan severity=e,w
 Create LOG Output
 263
 Messages
Security Security modules Authorization
Authentication modules
Clock daemon Time- based modules Time system time and Sntp
 Syslogformat parameter defines the content of the events
LOCAL1 LOCAL2 LOCAL3 LOCAL4 LOCAL5 LOCAL6 LOCAL7
 Destroy log output=idnumber
Following command deletes syslog server definition number
Destroy LOG Output
Destroy log output=3
 Following command disables the event log on the switch
Disable LOG
Disable log
 Disable log output=7
Disable LOG Output
Disable log output=idnumber
Disable log output
 Enable LOG
Enable log
 Enable log output=4
Enable LOG Output
Enable log output=idnumber
Enable log output
 Purge LOG
Purge log=temporary
 Save LOG
 Save log=temporary filename=switch 2.log
 Set log fullaction temporary=halt
SET LOG Fullaction
Set log fullaction temporary=haltwrap
 SET LOG Output
 Address for each event. This is
Example, MAC,PACCESS. For a list
According to its impact on the switch’s operation
Normal Sends only the severity, module, Description Module
 Set log output=3 server=198.45.12.1
Set log output=11 module=stp,igmpsnooping severity=e,w
 Newest to oldest. Without it, the events are
Show LOG
Modules Reverse Specifies the order in which the events are
Displayed oldest to newest
 Command line interface commands
Port access control list
Switch configuration
Denial of service defense
 Port configuration
Management access control list
802.1x port-based access control
Power over Ethernet AT-8524POE switch only
 Selects all severity levels
Event Log Example
 Show log=temporary full
Following command displays all the entries in the event log
Show log=temporary
Show log=temporary module=file,qos
 Show log output=idnumber full
On the switch are displayed
Show LOG Output
Server definition. If an output ID number is not
 Show log output=1 full
Following command displays information about the event log
Show log output
Show log output=5 full
 Show log status
Following command displays event log status information
Show LOG Status
 Classifier Commands
Guide for background information on classifiers
 Create Classifier
 Protocol Specifies a Layer 2 protocol. Options are ARP
A specific node or a subnet. To filter using the IP
VID number
You can specify other Layer 2 protocols by entering
 Ipsaddr
 This command creates a classifier for all IP traffic
Create classifier=4 description=IP flow protocol=ip
 Destroy classifier=2,4
Destroy Classifier
Destroy classifier=idnumber
 Purge classifier
This command deletes all classifiers on the switch
Purge Classifier
 Number can be from 1 to
SET Classifier
Classifier Specifies the ID number of the classifier to be
 Hexadecimal format. For the latter, precede
You can specify additional Layer 2 protocols by
Entering the protocol number in either decimal or
Number with
 This command adds the Layer 3 protocol Igmp to classifier ID
Set classifier=6 ipprotocol=igmp
 Set classifier=5 udpdport=any
 Show classifier
Show Classifier
Show classifier=idnumber
Show classifier=12
 ACL Commands
Guide for background information on access control lists ACL
 Create ACL
 ACL Commands
 Destroy ACL
This command deletes an ACL from the switch
Following command deletes ACL IDs 14
Destroy acl=integer
 Purge acl
This command deletes all ACLs on the switch
Purge ACL
 SET ACL
 Set acl=4 description=ARP flow
This command changes the description of ACL ID
This command changes the classifiers of ACL ID
Set acl=6 action=permit portlist=4-7
 Show acl
Show ACL
Show acl=integer
Show acl=22
 Quality of Service QoS Commands
 307
 Add qos flowgroup=12 classifierlist=4,7
ADD QOS Flowgroup
Add qos flowgroup=integer classifierlist=integers
 Add qos policy=integer trafficclasslist=integers
This command adds the traffic class 16 to policy
ADD QOS Policy
11,12
 ADD QOS Trafficclass
Add qos trafficclass=17 flowgrouplist=21
 Create QOS Flowgroup
Create qos flowgroup=integer
 With the Priority parameter
Remarkpriority
New value specified with the Priority
 313
 Create QOS Policy
 This command creates a new QoS policy
Ingress ports. On switches with 24 ports plus
Uplinks, ports 1-26 form a port block. On switches
14-22
 Policy 11 Commands
Parts of the policies are
 Example 2 Video Application
 Policy 32 Commands
Example 3 Critical Database
 Policy 15 Commands
 Create QOS Trafficclass
Create qos trafficclass=integer
 Flow group level. It will override any value set at
Specified at the traffic class or policy level. a
Used only if no value has been specified at
Policy level
 Accumulate in the bucket. If the traffic
Continue to the point where all the unused
Traffic. However, no unused tokens will
Increases, the excess traffic will be discarded
 Value specified in with
Packets with the new value
Specified with the Priority
Priority parameter. This is
 Delete QOS Flowgroup
Delete qos flowgroup=22 classifierlist=6
 Delete QOS Policy
Delete qos policy=1 trafficclasslist=17
 Delete QOS Trafficclass
Delete qos trafficclass=22 flowgrouplist=5
 Destroy qos flowgroup=22
Destroy QOS Flowgroup
Destroy qos flowgroup=integer
Destroy qos flowgroup=16-20,23
 Destroy qos policy=41
Destroy QOS Policy
Destroy qos policy=integer
Destroy qos policy=5,23
 Destroy qos trafficclass=22
Destroy QOS Trafficclass
Destroy qos trafficclass=integer
Destroy qos trafficclass=16-20,23
 If the None option is used, the frame’s current
SET QOS Flowgroup
To modify. The range is 0 to
If you specify a new priority in a flow group and a
 Set qos flowgroup=25 classifierlist=23,41
Packets with the new value specified
Set qos flowgroup=15 priority=6
 Set qos flowgroup=41 markvalue=none
 SET QOS Policy
TOS field of the packets. The range is 0 to
 14-22. The None option removes the policy
To another policy with one command
Ingressport
ALL option adds it to all ports
 Set qos policy=8 ingressport=8
This command changes the ingress port for policy 8 to port
This command changes the traffic classes assigned to policy
Set qos policy=41 trafficclasslist=12,23
 Set qos port=1,5 type=egress policy=none
SET QOS Port
Set qos port=5-8 type=ingress policy=12
 SET QOS Trafficclass
Set qos trafficclass=integer
 Flow group, traffic class, and policy. a Dscp value
 This parameter should be used with
When they leave the switch
Tokens are added. The range is 4 to 512 Kbps
Bucket size without also specifying a maximum
 Set qos trafficclass=41 maxbandwidth=80 burstsize=400
With commas e.g., 4,11,13
Set qos trafficclass=42 priority=17
 Show qos flowgroup
Show QOS Flowgroup
Show qos flowgroup=idnumber
Show qos flowgroup=12
 Show qos policy
Show QOS Policy
Show qos policy=idnumber
Show qos policy=54
 Show qos trafficclass
Show QOS Trafficclass
Show qos trafficclass=idnumber
Show qos trafficclass=14
 Class of Service CoS Commands
Guide for background information on Quality of Service
 MAP QOS Cosp
 Following command maps priorities 4 and 5, to egress queue
Map qos cosp=4,5 qid=3
 Set qos cosp=5,6 qid=1
Following command maps priorities 5 and 6, to egress queue
SET QOS Cosp
 SET QOS Scheduling
Set qos scheduling=strictwrr weights=weights
Set qos scheduling=wrr weights=1,5,10,15
Set qos scheduling=strict
 Displays the QoS priority queues and scheduling
Show QOS Config
Show qos config
 Power Over Ethernet Commands
Guide for background information on Power over Ethernet PoE
 This command disables PoE on port 5
Disable POE Port
Disable poe port=port
Disable poe port=5,7
 This commands activates PoE on port
Enable POE Port
Enable poe port=port
Enable poe port=2
 SET POE Port
 This command sets the priority on port 6 and 11 to high
Following command disables PoE on ports 4
Set poe port=4-5 poefunction=disable
Set poe port=14 powerlimit=12500
 Set poe threshold=80
SET POE Threshold
Set poe threshold=value
 Show poe config
Show POE Config
Show poe config port=port
Show poe config port=4
 Show POE Status
Show poe status port=port
 Show poe status
Show poe status port=4
 Igmp Snooping Commands
Guide for background information on Igmp Snooping
 This command deactivates Igmp snooping
Disable Igmpsnooping
Disable igmpsnooping
 This command activates Igmp snooping
Enable Igmpsnooping
Enable igmpsnooping
 SET IP Igmp
 Set ip igmp snoopingstatus=disabled
Set ip igmp hoststatus=singlehost
 Show Igmpsnooping
Show igmpsnooping
 Show ip igmp
Show IP Igmp
Show ip igmp hostlist routerlist
Show ip igmp hostlist
 Show ip igmp routerlist
 Denial of Service DoS Defense Commands
 Set dos ipaddress=149.11.11.1 subnet=0.0.0.63
SET DOS
Set dos ipaddress=ipaddress subnet=mask uplinkport=port
 Than one port at a time
Set dos ipoption port=5,7,10 state=enable
SET DOS Ipoption
Mirrorport
 SET DOS Land
Set dos land port=port state=enabledisable mirrorport=port
Set dos land port=5,7 state=enable
 SET DOS Pingofdeath
 Following command activates the defense on ports 1
Set dos pingofdeath port=1,5 state=enable
 Following command activates this defense on port
Set dos smurf port=port state=enabledisable
Port Specifies the switch ports on which you want to
Set dos smurf port=17 state=enable
 Set dos synflood port=18-20 state=enable
Set dos synflood port=port state=enabledisable
Following command activates the defense on ports 18 to
SET DOS Synflood
 SET DOS Teardrop
 Following command activates the defense on port
Set dos teardrop port=22 state=enable
 Show dos defense port=port
Show DOS
Show dos ipaddress subnet uplinkport
Show dos ipaddress subnet
 Show dos smurf port=4
 STP Commands
 Activate STP
Activate stp
 Following command disables STP
Disable STP
Disable stp
 Following command enables STP on the switch
Enable STP
Enable stp
 Purge STP
Purge stp
 Represents the desired bridge priority value.
SET STP
Following table. You specify the increment that
32768
 Seconds
 Set stp priority=11
Set stp hellotime=7 forwarddelay=25
Set stp default
 SET STP Port
 Set stp port=6 portcost=15 portpriority=12
Set stp port=7-10 portcost=auto
 Where the ingress port is a member
SET Switch Multicastmode
Set switch multicastmode=abcd
Multicastmode Specifies one of the following
 Set switch multicastmode=a
 Show stp
Show STP
Show stp port=port
Show stp port=1-4
 Rstp Commands
 Activate Rstp
Activate rstp
 Following command disables Rstp
Disable Rstp
Disable rstp
 Following command enables Rstp
Enable Rstp
Enable rstp
 Purge rstp
Following command resets Rstp
Purge Rstp
 Shown in the following table. You specify
SET Rstp
Range is divided into sixteen increments, as
Increment that represents the desired bridge priority
 Parameter settings, but
Forwarddelay
STP compatible mode
Seconds
 Set rstp priority=5 hellotime=5 forwarddelay=20
Set rstp forceversion=stpcompatible
 Set rstp default
 SET Rstp Port
 Port is an edge port.
Mbps 20,000 Portpriority
You specify the increment that corresponds to
Values are equivalent. This is
 Set rstp port=4 portcost=1000000 portpriority=14
Set rstp port=6-8 edgeport=no
 Show Rstp
Show rstp portconfig=portportstate=port
Show rstp portconfig=1-4
Show rstp
 Following command displays Rstp port status for port
Show rstp portstate=15
 Mstp Commands
 407
 Activate Mstp
Activate mstp
 Add mstp mstiid=8 mstivlanassoc=4
ADD Mstp
Add mstp mstiid=mstiid mstivlanassoc=vids
Add mstp mstiid=11 mstivlanassoc=24,44
 At a time. The range is 1 to
Create Mstp
Create mstp mstiid=mstiid mstivlanassoc=vids
Create mstp mstiid=8 mstivlanassoc=4
 Delete mstp mstiid=8 mstivlanassoc=4
Delete Mstp
Delete mstp mstiid=mstiid mstivlanassoc=vids
Delete mstp mstiid=11 mstivlanassoc=24,44
 This example deletes the spanning tree instance
Destroy Mstp Mstiid
Destroy mstp mstiid=mstiid
Destroy mstp mstiid=4
 Following command disables Mstp
Disable Mstp
Disable mstp
 Following command enables Mstp
Enable Mstp
Enable mstp
 Purge Mstp
Purge mstp
 Disabled to use this parameter
Performs the same function as the Reset Mstp
Command. The spanning tree protocol must be
SET Mstp
 Configname
Seconds Forwarddelay
Those ports operating in the STP compatible mode
Maxhops Specifies the maximum hops counter. Mstp
 Set mstp default
Set mstp forceversion=forcestpcompatible
 Set mstp cist priority=priority
Default value is 32,768, which is increment
SET Mstp Cist
Is divided into sixteen increments, as shown
 Set mstp cist priority=11
 Msti Priority Value Increments
SET Mstp Msti
Set mstp msti mstiid=mstiid priority=priority
 Set mstp msti mstiid=4 priority=11
Set mstp msti mstiid=6 priority=2
 Set mstp mstivlanassoc mstiid=8 vlanlist=4
SET Mstp Mstivlanassoc
Set mstp mstivlanassoc mstiid=mstiid vlanlist=vids
Set mstp mstivlanassoc mstiid=11 vlanlist=24,44
 SET Mstp Port
 Selections are Yes, on, true Port is an edge port. These
Mbps 20,000 Edgeport
Connected to any device running STP or Mstp
BPDUs indefinitely. Set the migrationcheck
 An internal port cost. The range is 0 to 200,000,000
Default setting is Auto-detect 0, which sets port
Cost depending on the speed of the port. Default
Mbps ports, and 20,000 for one gigabit ports
 Set mstp port=2-5 extportcost=auto
Set mstp port=14,23 extportcost=500
Set mstp port=6-8 edgeport=yes
Set mstp port=6-8 ptp=yes
 Set mstp port=2-5 intportcost=auto
Set mstp port=7,10 intportcost=500
Set mstp port=7,10 portpriority=4 stpid=2
 Show Mstp
 Msti priority Regional root ID
 Show mstp portstate=4
Show mstp portconfig=5 stpid=2
Show mstp
Show mstp cist
 VLANs and Multiple Vlan Mode Commands
 ADD Vlan
Add vlan=name vid=vid port=portsall frame=untaggedtagged
 Add vlan=sales untaggedports=4,7
Add vlan=Service untaggedports=7-8 taggedports=5
Add vlan=sales port=4,7 frame=untagged
Add vlan=production port=3 frame=tagged
 Create Vlan
Create vlan=name vid=vid port=portsall frame=untaggedtagged
 Example, 1, 5, 14-22. To specify all ports on
Port Specifies the ports on the switch that are either
This command creates a new port-based or tagged Vlan
Frame parameter
 Create vlan=Sales vid=3 untaggedports=4-8,12-16
Create vlan=Service vid=16 port=1,4,5-7 frame=untagged
Create vlan=Sales vid=3 port=4-8,12-16 frame=untagged
Create vlan=Production vid=22 port=3,6 frame=tagged
 438
 Vlan Specifies the name of the Vlan to be modified Vid
Delete Vlan
Delete vlan=name vid=vid port=ports frame=untaggedtagged
This parameter must be used with the Frame
 Delete vlan=production port=13 frame=tagged
Delete vlan=sales port=4,7 frame=untagged
Delete vlan=sales untaggedports=4,7
Delete vlan=production untaggedports=13
 To 8, the commands would be
Delete vlan=Service untaggedports=6-8 taggedports=2
 Destroy vlan vlan=Sales
Destroy Vlan
Destroy vlan vlan=nameall vid=vid
Destroy vlan vlan=Sales vid=102
 Set switch infiltering=off
SET Switch Infiltering
Set switch infiltering=yesnoonofftruefalse
 Set switch managementvlan=TechSupport
SET Switch Managementvlan
Set switch managementvlan=nameVID
 SET Switch Vlanmode
Set switch vlanmode=dotqmultiple uplinkport=4
 Set switch vlanmode=userconfig
 Set vlan=gvrpvlan22 type=portbased
SET Vlan
Set vlan=name vid=vid type=portbased
 Show vlan
Show Vlan
Show vlan=namevid
Show vlan=sales
 Garp Vlan Registration Protocol Commands
Guide for background information on the Gvrp
 Disable garp=gvrp
Disable Garp
Disable garp=gvrp gip
 This commands enables Gvrp on the switch
Enable Garp
Enable garp=gvrp gip
Enable garp=gvrp
 Purge Garp
Purge garp=gvrp
 Set garp=gvrp port=1-4 mode=none
SET Garp Port
Set garp=gvrp port=port mode=normalnone
Set garp=gvrp port=3 mode=normal
 SET Garp Timer
 Following command sets the timers to their default values
Set garp=gvrp timer default
 Show garp=gvrp
Following command displays the above Gvrp information
Show Garp
 Show Garp Counter
Show garp=gvrp counter
 Following command displays the above Garp counters
 Show garp=gvrp database
Following command displays the Garp database
Show Garp Database
 Show garp=gvrp gip
Following command displays the GIP-connected ring
Show Garp GIP
 Show garp=gvrp machine
Following command displays GID state machines
Show Garp Machine
Port App Reg
 Protected Ports Vlan Commands
 ADD Vlan Group
 Add vlan=InternetGroups port=5,6 frame=untagged group=4
Following command accomplishes the same thing using syntax
Add vlan=InternetGroups untaggedports=11 group=uplink
 Add vlan=InternetGroups untaggedports=5,6 group=4
 Create vlan=InternetGroups vid=12 portprotected
Create Vlan Portprotected
Create vlan=name vid=vid portprotected
 Vlan Specifies the name or VID of the Vlan to be
VID
 Delete vlan=InternetGroups port=12 frame=untagged
Delete vlan=InternetGroups untagged=12
 Destroy vlan=namevidall
Following command deletes the Vlan called InternetGroups
Following command deletes all VLANs
Destroy vlan=InternetGroups
 Set vlan=namevid port=ports frame=taggeduntagged
Set vlan=Sales port=4 frame=untagged
 Following command displays the Sales Vlan
 MAC Address Security Commands
Guide for background information on port security
 Set switch port=12,21 intrusionaction=trap
SET Switch Port Intrusionaction
Port Specifies the port where you want to change
Snmp trap
 SET Switch Port Securitymode
 To the Limited security mode. Intrusion actions are
Trap, and disables the port
Disable. This option does not apply when intrusion
Action is set to discard. Options are
 Set switch port=2,6,18 securitymode=locked
Set switch port=8 securitymode=limited learn=5
Set switch port=15-16 learn=150
Set switch port=12-24 securitymode=secured
 Port Specifies the port where you want to view
Show Switch Port Intrusion
Show switch port=port intrusion
Show switch port=12,21 intrusion
 Show switch port=1-5 securitymode
Show Switch Port Securitymode
Show switch port=port securitymode
 802.1x Port-based Access Control Commands
 Portaccess and Portauth keywords are equivalent
Disable Portaccessportauth
Disable portaccessportauth
Disable portaccess
 Following command disables Radius accounting
Disable Radiusaccounting
Disable radiusaccounting
 Enable portaccess
Enable Portaccessportauth
Enable portaccessportauth
 Enable Radiusaccounting
Enable radiusaccounting
 Control on the port
SET Portaccessportauth Port ROLE=AUTHENTICATOR
Port-based authentication
Control
 Access the network is
Authentication messages
Authentication server. Each
Switch by using the clients
 Client before retransmitting the request. The default
Switch or the switch is
Reset or power cycled
Is disabled by default. The default value is
 Client has logged on. This is the default
Authenticator port will handle egress broadcast
Multicast traffic when in the unauthorized state. You
Client’s authentication
 Set portaccess port=12,15 role=none
This command sets ports 4 to 6 to the Authenticator role
Set portaccess port=4-6 role=authenticator
 To 60 seconds. The default is 30 seconds
SET Portaccessportauth Port ROLE=SUPPLICANT
To adjust. You can specify more than one port at a
Port Specifies the port that you want to set to
 Set portaccess port=4-6 role=supplicant
 SET Radiusaccounting
 Set radiusaccounting status=enabled trigger=stoponly
Interim accounting updates to the Radius server
Range is 30 to 300 seconds. The default is
Set radiusaccounting updateenable=enabled interval=200
 Show portaccess config
Show Portaccessportauth
Show portaccessportauth configstatus
Show portaccess status
 Show portaccess port=10 authenticator status
Show Portaccessporauth Port
Settings you want to view. You can specify more
Show portaccess port=12 supplicant config
 Show Radiusaccounting
Show radiusaccounting
 Web Server Commands
Guide for background information on the web server
 Following command disables the web server
Disable Http Server
Disable http server
 Following command activates the web server
Enable Http Server
Enable http server
 Purge Http Server
Purge http server
 SET Http Server
Secure Https mode
Will listen on. The default for non-secure Http
 Set http server security=disabled
Set http server security=enabled sslkeyid=5
 Set http server security=enabled sslkeyid=4
This command enables the web server enable http server
 503
 Create pki enrollmentrequest=sw24cer keypair=8
This command disables the web server disable http server
Set system distinguishedname=cn=149.44.44.44
 Set http server security=enabled sslkeyid=8
 Show http server
Following command displays the status of the web server
Show Http Server
 Encryption Key Commands
 Create Enco KEY
 Ssh2
Ssh
Version 1 users
Version 2 users
 Create enco key=12 type=rsa length=512
Syntax 2 Description
 Create enco key=12 type=rsa file=public12.key format=ssh
 Destroy enco key=4
Destroy Enco KEY
Destroy enco key=key-id
 Set enco key=key-iddescription=description
Set enco key=1 descriptionSwitch 22 key
SET Enco KEY
 Show enco key=key-id
This command displays information about encryption key
Show Enco
Show enco key=1
 Public Key Infrastructure PKI Certificate Commands
 ADD PKI Certificate
 517
 Create PKI Certificate
 519
 520
 Software automatically adds the .csr extension
Create PKI Enrollmentrequest
Enclosed in double quotes. The management
Type Formats the request according to Pkcs #10
 Create pki enrollmentrequest=Switch12 keypair=4
PKCS10
 Delete pki certificate=name
Delete pki certificate=Switch 12 certificate
Delete PKI Certificate
Be enclosed in double quotes. Wildcards are not
 Purge PKI
Purge pki
 Spaces, it must be enclosed in quotes
Entity EE. This is the default
SET PKI Certificate
Yes, on, true Specifies that the certificate is from a
 Set pki certificate=Switch 12 certificate trusted=true
 Set pki certstorelimit=100
SET PKI Certstorelimit
Set pki certstorelimit=value
 Set system distinguishedname=cn=169.22.22.22
SET System Distinguishedname
Set system distinguishedname=name
 Show PKI
Show pki
 Show pki certificate=name
Show pki certificate=Switch 12 certificate
Show PKI Certificate
Show pki certificate
 Secure Sockets Layer SSL Commands
 SET SSL
Set ssl cachetimeout=value maxsessions=value
Set ssl cachetimeout=180
 Show SSL
Show ssl
 Secure Shell SSH Commands
 Following command disables the Secure Shell server
Disable SSH Server
Disable ssh server
 Enable SSH Server
 Enable ssh server hostkey=0 serverkey=1
General Configuration Steps for SSH Operation
 Enable ssh server hostkey=1 serverkey=2
 SET SSH Server
 Set ssh server expirytime=1
 Show SSH
Show ssh
 TACACS+ and Radius Commands
 Add radiusserver ipaddress=149.245.22.22 order=3
ADD Radiusserver
Add radiusserver ipaddress=149.245.22.22 order=1
 TACACS+ and Radius Commands
 Add tacacsserver ipaddress=149.245.22.20 order=1
ADD Tacacsserver
Being the first server queried
Add tacacsserver ipaddress=149.245.22.26 order=3
 Delete radiusserver ipaddress=149.245.22.22
Delete Radiusserver
Delete radiusserver serveripaddress=ipaddress
 Delete tacacsserver ipaddress=149.245.22.20
Delete Tacacsserver
Delete tacacsserver serveripaddress=ipaddress
 Disable Authentication
Disable authentication
 Enable Authentication
Enable authentication
 Following command disables authentication on your switch
Purge Authentication
Purge authentication
 Set authentication method=tacacs secret=tiger54
SET Authentication
Set authentication method=tacacs
 Set authentication method=radius secret=leopard09 timeout=15
 Show authentication
Show Authentication
Show authentication=tacacsradius
Show authentication=radius
 Management ACL Commands
Guide for background information on the Management ACL
 ADD Mgmtacl
 Management ACL Commands
 Tcp Transmission control protocol Interface
Following command deletes an ACE from the Management ACL
Delete Mgmtacl
 Following command disables the Management ACL
Disable Mgmtacl
Disable mgmtacl
 Following command enables the Management ACL
Enable Mgmtacl
Enable mgmtacl
 SET Mgmtacl
 561
 Set mgmtacl state=enable
Set mgmtacl state=disableenable
Enable Enables the Management ACL Disable
SET Mgmtacl State
 Show mgmtacl state
Show Mgmtacl
Show mgmtacl stateentries
Show mgmtacl entries
 Configuring timeout value 198 aging timer
Index
 Clear Screen command
Create PKI Certificate command
 Disable Radiusaccounting command 481 Disable Rstp command
Disable Snmp command
 Flow group
Modifying 308, 324
 Aging time 182 multicast groups
 Disabling 480 displaying 493, 494
 SET POE Threshold command
SET Mgmtacl command
SET Mstp command SET Mstp Msti command
SET QOS Port command
 Show Switch command
SET Switch Port command
Show PKI Certificate command 530 Show PKI command
Show Switch Port Counter command
 Sntp
Modifying 259
 System files Deleting Downloading 238
Adding Converting dynamic VLANs Creating