CLI Reference Guide
Aug
Contents
Using the CLI
Address Table Commands
Clock
Ethernet Configuration Commands
Igmp Snooping Commands
Lacp Commands
Management ACL
Port Monitor Commands
Rmon Commands
Spanning-Tree Commands
SSH Commands
Syslog Commands
Tacacs Commands
Vlan Commands
32 802.1x Commands
382
Page
Introduction
Command Groups
Command Groups
Configures commands related to 802.1x security protocol
Configures and reports on Spanning Tree protocol
Configures Tacacs commands
AAA Commands
Address Table Commands
Defines an authentication key for Simple
Configures an external time source for
Configures the system to automatically switch
Displays statically created entries in the bridge
Configuration and Image Files Commands
Ethernet Configuration Commands
Displays the backup configuration file contents
Gvrp Commands
IP Addressing
Igmp Snooping Commands
Defines a default gateway router
Sets an IP address
Cache
Line Commands
Deletes entries from the host name-to-address
Lldp Commands
Sets the line for automatic baud rate detection
Management ACL Commands
PHY Diagnostics Commands
QoS Commands
Port Channel Commands
Port Monitor Commands
Radius Commands
Enables each port trust state
Rmon Commands
Snmp Commands
Spanning Tree Commands
MST
Sets the default path cost method
SSH Commands
Overrides the default link-type setting
Syslog Commands
Reloads the operating system
System Management Commands
Tacacs Commands
Switches the mode to debug
User Interface Commands
Vlan Commands
Disables the default Vlan functionality
Reserves a Vlan as the internal usage Vlan of an
Interface
Web Server Commands
802.1x Commands
Command Description Access Mode
Command Groups
Command Modes
GC Global Configuration Mode
Device
Notification operation
IC Interface Configuration Mode
Sntp
Reserves a Vlan as the internal usage Vlan of an interface
An Extensible Authentication Protocol EAP request/identity
Frame, from the client, before resending the request
Command Description
LC Line Configuration Mode
Enables the Simple Network Time Protocol Sntp client on an
MA Management Access-level Mode
PE Privileged User Exec Mode
Vlan
SP SSH Public Key Mode
UE User Exec Mode
Command Modes
VC Vlan Configuration Mode
W . d e l l . c o m s u p p o r t . d e l l . c o m
Introduction
Using the CLI
CLI Command Modes
User Exec Mode
Privileged Exec Mode
Global Configuration Mode
Exit End Ctrl+Z
Starting the CLI
Consoleconfig# username admin password smith
Editing Features
Entering Commands
Command Completion
Terminal Command Buffer
Negating the Effect of Commands
Config#interface ethernet
Italic font
CLI Command Conventions
Keyboard Shortcuts
Enter
Using the CLI
Default Configuration
AAA Commands
Aaa authentication login
Command Mode
Example
Aaa authentication enable
Following example configures authentication login
Login authentication
Console config# aaa authentication enable default enable
Enable authentication
Console config-line#login authentication default
Following example configures the http authentication
Ip http authentication
Console config-line#enable authentication default
Following example configures https authentication
Ip https authentication
Show authentication methods
Privileged Exec mode
Syntax Show authentication methods Default Configuration
This command has no default configuration
Following example displays the authentication configuration
Syntax Password password encrypted No password
Password
Console# show authentication methods
Following example specifies a password secret on a line
Enable password
No password is required
No user is defined
Username
Show users accounts
Syntax Show users accounts Default Configuration
Console# show users accounts
AAA Commands
Bridge address
Address Table Commands
Interface configuration Vlan mode
Console config# bridge multicast filtering
Disabled. All multicast addresses are flooded to all ports
This example, bridge multicast filtering is enabled
Bridge multicast filtering
Following example registers the MAC address
No multicast addresses are defined
Examples
No forbidden addresses are defined
Command Modes
Bridge multicast forbidden address
Bridge multicast forbidden forward-all
Disable forward-all on the specified interface
Bridge multicast forward-all
This example all multicast packets on port g8 are forwarded
Bridge aging-time
Syntax
Console# clear bridge
Clear bridge
Syntax Clear bridge
Port security
Disabled No port security
Interface Configuration Ethernet, port-channel mode
Show bridge address-table
Console config-if#port security routed secure-address
Port security routed secure-address
Mac-address-Specify a MAC address in the format
Port-channel-number-A valid port-channel number
Show bridge address-table static
Console# show bridge address-table
Syntax Show bridge address-table count vlan vlan
Show bridge address-table count
Console# show bridge address-table static
Vlan -Specific Vlan
Show bridge multicast address-table
Console# show bridge address-table count
Console # show bridge multicast address-table
Console # show bridge multicast address-table format ip
Syntax Show bridge multicast filtering vlan-id
Show bridge multicast filtering
Show ports security
Vlanid-A valid Vlan ID value
Console # show ports security
Clock source
Clock
Clock set
Syntax Clock source sntp No clock source
Console# clock source sntp
Clock timezone
No external clock source
Clock summer-time
Sntp authentication-key
No authentication key is defined
Syntax Sntp authenticate No sntp authenticate
Sntp authenticate
Consoleconfig# sntp authentication-key 8 md5 ClkKey
Sntp trusted-key
Sntp client poll timer
Following example authenticates key
Not trusted
Console config# sntp broadcast client enable
Sntp broadcast client enable
Console config# sntp client poll timer
Console config-if#sntp anycast client enable
Sntp anycast client enable
Sntp client enable interface
Syntax Sntp client enable No sntp client enable
101
Sntp unicast client enable
Console config# sntp unicast client enable
Sntp server
Console config# sntp unicast client poll
Sntp unicast client poll
Syntax Sntp unicast client poll no sntp unicast client poll
103
Show clock
Syntax Show clock detail
Console# show clock
104
Console# show sntp configuration
Show sntp configuration
Syntax Show sntp configuration
105
Following example shows the status of the Sntp
Show sntp status
Syntax Show sntp status
106
107
Clock
Console# delete startup-config
Configuration and Image Files
Delete startup-config
Copy
Understanding Invalid Combinations of Source and Destination
110
Copying image file from a Server to Flash Memory
Storing the Running or Startup Configuration on a Server
Copy Character Descriptions
111
Console# boot system image-1
Boot system
Syntax Boot system image-1 image-2
112
Sort type defaults to interface if unspecified
Show running-config
Syntax Show running-config sort type
113
Syntax Show startup-config sort type 114
Show startup-config
Console# show running-config no spanning-tree
115
Syntax Show backup-config 116
Show backup-config
Console# show startup-config no spanning-tree
Console# show backup-config software version
117
Console# show bootvar
Show bootvar
Syntax Show bootvar Default Configuration
118
Interface range ethernet
Ethernet Configuration Commands
Interface ethernet
Following example disables port g5
Syntax Shutdown No shutdown Default Configuration
Interface is enabled
Shutdown
Syntax Description string No description
Description
Speed
Syntax Speed 100 1000 No speed
122
Duplex
Syntax Duplex half full No duplex
Negotiation
Consoleconfig# interface ethernet g5
Syntax Negotiation No negotiation Default Configuration
Flowcontrol
Syntax Mdix on auto No mdix
Mdix
Syntax Flowcontrol auto on off No flowcontrol
124
125
Syntax Back-pressure No back-pressure Default Configuration
Back-pressure
126
Port jumbo-frame
Clear counters
Console# clear counters ethernet g1
Show interfaces configuration
Set interface active
Console# set interface active ethernet g5
Interfaces configuration
128
Show interfaces status
129
130
Console# show interfaces status
Show interfaces description
131
132
Show interfaces counters
Console# show interfaces description ethernet g1
133
Console# show interfaces counters
Following table describes the fields shown in the display
Following example displays counters for port g1
Console# show interfaces counters ethernet g1
134
135
Ieee Std .3, 2000 Edition, section
136
Syntax Show ports jumbo-frame Default Configuration
Show ports jumbo-frame
Port storm-control include-multicast
Port storm-control broadcast enable
Consoleconfig# port storm-control include-multicast
Console# show ports jumbo-frame
Default storm control broadcast rate is
Broadcast storm control is disabled
Consoleconfig-if#port storm-control broadcast enable
Port storm-control broadcast rate
Show ports storm-control
Consoleconfig-if#port storm-control broadcast rate
Following example displays the storm control configuration
Syntax Show ports storm-control interface
140
Gvrp enable interface
Gvrp Commands
Gvrp enable global
Syntax Gvrp enable No gvrp enable Default Configuration
142
Garp timer
Following example enables Gvrp on ethernet g8
143
By default, dynamic Vlan creation is enabled
Gvrp vlan-creation-forbid
Gvrp registration-forbid
Console config-if#gvrp vlan-creation-forbid
Console config-if#gvrp registration-forbid
Clear gvrp statistics
145
Show gvrp configuration
Console# clear gvrp statistics ethernet g8
146
Console# show gvrp configuration
Show gvrp statistics
147
Show gvrp error-statistics
Following example shows Gvrp statistics information
Console# show gvrp statistics
148
Console# show gvrp-error statistics
Following example displays Gvrp statistics information
Ip igmp snooping Interface
Igmp Snooping Commands
Ip igmp snooping Global
149
150
Ip igmp snooping mrouter
Ip igmp snooping host-time-out
151
Console config-if#ip igmp snooping host-time-out
Ip igmp snooping mrouter-time-out
Console config-if#ip igmp snooping leave-time-out
Console config-if#ip igmp snooping mrouter-time-out
Default leave-time-out configuration is 10 seconds
Ip igmp snooping leave-time-out
Console # show ip igmp snooping mrouter
Show ip igmp snooping mrouter
Show ip igmp snooping interface
Console # show ip igmp snooping interface
Show ip igmp snooping groups
Example displays Igmp snooping information
154
155
Example shows Igmp snooping information
Console # show ip igmp snooping groups
Igmp Snooping Commands
Ip address
IP Addressing Commands
Clear host dhcp
Console# clear host dhcp
No IP address is defined for interfaces
Interface configuration Ethernet, VLAN, port-channel
Ip address dhcp
158
No default gateway is defined
Ip default-gateway
Syntax Ip default-gateway ip-address No ip default-gateway
159
160
Following example defines an ip default gateway
Show ip interface
161
Arp
Console# show ip interface
Clear arp-cache
Arp timeout
Console config# arp 198.133.219.232 00000c400fbc ethernet
Console# clear arp-cache
Syntax Show arp Default Configuration
Show arp
Following example displays entries in the ARP table
Syntax Ip domain-lookup No ip domain-lookup
Ip domain-lookup
Ip domain-name
Syntax Ip domain-name name No ip domain-name
No name server addresses are specified
Ip name-server
Ip host
Following example sets the available name server
No host is defined
Clear host
Syntax Ip host name address No ip host name
Syntax Clear host name
Syntax Show hosts name
Default Configuration Command Mode
Show hosts
167
168
Lacp port-priority
Lacp Commands
Lacp system-priority
Syntax Lacp port-priority value No lacp port-priority
Default port timeout value is long
Lacp timeout
Syntax Lacp timeout long short No lacp timeout
170
Console# show lacp ethernet g1 statistics
Show lacp ethernet
Show lacp port-channel
Syntax Show lacp port-channel portchannelnumber
Console# show lacp port-channel
172
Syntax Line console telnet ssh
Line Commands
Line
Syntax Speed bps
Autobaud
Exec-timeout
Syntax Autobaud No autobaud Default Configuration
174
Syntax Show line console telnet ssh
Syntax Exec-timeout minutes seconds No exec-timeout
Show line
175
Terminal history size
Following example displays the line configuration
Terminal history
Console# show line console
Maximum for the sum of all buffers is
177
Line Commands
Lldp enable interface
Lldp Commands
Lldp enable global
Syntax
Syntax Lldp timer seconds No lldp timer
Lldp timer
Interface configuration Ethernet
Default 30 seconds
Lldp hold-multiplier
Lldp reinit-delay
Default Configuraiton
Syntax Lldp hold-multiplier number No lldp hold-multiplier
Syntax Lldp tx-delay seconds No lldp tx-delay Parameters
Lldp tx-delay
Syntax Lldp reinit-delay seconds No lldp reinit-delay
Default value is 2 seconds
Usage Guidelines
Lldp optional-tlv
Lldp management-address
No optional TLV is transmitted
Clear lldp rx
184
Switch# show lldp configuration
Show lldp configuration
Syntax Show lldp configuration ethernet interface
Show lldp local
Show lldp neighbors
186
187
Switch# show lldp neighbors
Switch# show lldp neighbors ethernet g1
Lldp Commands
Management ACL
Management access-list
Name-The access list name using up to 32 characters
189
190
Console config# management access-class mlist
Permit management
191
Management Access-list Configuration mode
Deny management
Management access-class
192
Syntax Show management access-list name
Show management access-list
Show management access-class
Console# show management access-list
194
Syntax Show management access-class Default Configuration
Console# show management access-class
Show copper-ports tdr
PHY Diagnostics Commands
Test copper-port tdr
Console# test copper-port tdr g3
Port must be active and working in 1000M
Show copper-ports cable-length
Syntax Show copper-ports cable-length interface
196
197
Show fiber-ports optical-transceiver
Console# show copper-ports cable-length
198
Console# show fiber-ports optical-transceiver
199
Console# show fiber-ports optical-transceiver detailed
PHY Diagnostics Commands
Interface port-channel
Port Channel Commands
Console config# interface port-channel
Interface range port-channel
Port is not assigned to any port-channel
Console config# interface range port-channel
Channel-group
202
Show interfaces port-channel
Console config-if#channel-group 1 mode on
Port channel load balance
Syntax Show interfaces port-channel port-channel-number
204
Interface Configuration mode
Port Monitor Commands
Default is both rx and tx
Port monitor
206
Syntax Show ports monitor Default Configuration
Show ports monitor
Console# show ports monitor
207
Port Monitor Commands
Show qos
QoS Commands
Qos
210
Following example displays a QoS mode
Wrr-queue cos-map
Following example maps CoS 3 to queue
Interface Configuration Ethernet, port channel mode
Wrr-queue bandwidth
211
All queues are expedite queues
Following example assigns WRR weights to egress queues
Priority-queue out num-of-queues
212
Following example sets queue 4, 3 to be expedite queues
Console config# priority-queue out num-of-queues
Show qos interface
213
214
Qos map dscp-queue
Console# show qos interface ethernet g1 queuing
215
Qos trust Global
Syntax Qos trust cos dscp No qos trust
Qos trust Interface
Syntax Qos trust No qos trust Default Configuration
Syntax Qos cos default-cos No qos cos 216
Qos cos
217
Show qos map
Syntax Show qos map dscp-queue
Following table describes the fields used above
Following example displays the Dscp port-queue map
Console# show qos map Dscp-queue map
D1 x 10 + D2 = Value of Dscp
Radius-server host
Radius Commands
By default, no Radius host is specified
Ip-address-IP address of the Radius server host
Radius-server key
Timeout
Default is an empty string
Syntax Radius-server key key-string No radius-server key
Radius-server source-ip
Console config# radius-server retransmit
Radius-server retransmit
221
222
Radius-server timeout
Console config# radius-server timeout
Radius-server deadtime
Console config# radius-server deadtime
Syntax Show radius-servers Default Configuration
Show radius-servers
Console# show radius-servers
Following example displays the Radius server settings
224
Console# show rmon statistics ethernet g1
Rmon Commands
Show rmon statistics
225
226
Field Description
Rmon collection history
227
Following example displays all Rmon group statistics
Console config-if#rmon collection history 1 interval
Show rmon collection history
Console# show rmon collection history
Show rmon history
229
Console# show rmon history 5 throughput
Console# show rmon history 5 errors
230
Console# show rmon history 5 other
231
Rmon alarm
232
Show rmon alarm-table
233
Console# show rmon alarm-table
Show rmon alarm
Syntax Show rmon alarm-table Default Configuration
Syntax Show rmon alarm number
235
Following example displays Rmon 1 alarms
Console# show rmon alarm
Rmon event
236
Show rmon events
Following example configures an event with the trap index
Syntax Show rmon events Default Configuration
Following example displays the Rmon event table
Syntax Show rmon log event
Show rmon log
Console# show rmon events
Event-Event index. Range 0
239
Following example displays the Rmon logging table
Console# show rmon log
History table size is Log table size is
Console config# rmon table-size history
Rmon table-size
240
Snmp-server community
Snmp Commands
There are no default communities defined
No snmp-server community community ip-address
Snmp-server view
Default Setting
Default and DefaultSuper views exists
242
243
Snmp-server filter
Product specific
Included
Snmp-server contact
Snmp-server location
Syntax Snmp-server contact text No snmp-server contact
Syntax Snmp-server location text No snmp-server location
Snmp-server enable traps
Console config# snmp-server enable traps
245
Snmp-server host
Snmp-server trap authentication
Console config# snmp-server trap authentication
246
Snmp-server set
247
Snmp-server group
248
No group entry exists
Console config# snmp-server group user-groupv3 priv read
Snmp-server user
Router context is translated to context in the MIB
250
Snmp-server v3-host
Following example configures a new Snmp Version 3 user
Console config# snmp-server user
251
252
Following example configures an SNMPv3 host
Snmp-server engineID local
Show snmp engineid
Syntax Show snmp engineID Default Setting
Consoleconfig # snmp-server engineID local default
253
Console# sh snmp
Syntax Show snmp Default Configuration
Show snmp
254
255
Show snmp views
Syntax Show snmp views viewname
256
Show snmp groups
Syntax Show snmp groups groupname
257
Show snmp filters
Syntax Show snmp filters filtername
258
Show snmp users
Syntax Show snmp users username
259
Snmp Commands
Syntax Spanning-tree No spanning-tree Default Configuration
Spanning-Tree Commands
Spanning-tree mode
Spanning-tree
Spanning-tree forward-time
Consoleconfig# spanning-tree mode rstp
Consoleconfig# spanning-tree forward-time
Seconds-Time in seconds. Range 4
Spanning-tree hello-time
263
264
Consoleconfig# spanning-tree hello-time
Spanning-tree max-age
Consoleconfig# spanning-tree priority
Spanning-tree disable
Consoleconfig# spanning-tree max-age
Spanning-tree priority
Syntax Spanning-tree cost cost No spanning-tree cost
Following example disables spanning-tree on g5
Spanning-tree cost
Cost-The port path cost Range 1 200,000,000
Spanning-tree portfast
Consoleconfig-if#spanning-tree port-priority
Spanning-tree port-priority
267
Spanning-tree link-type
Consoleconfig-if#spanning-tree portfast
Consoleconfig-if#spanning-tree link-type shared
268
Spanning-tree mst priority
Default number of hops is
Console config # spanning-tree mst 1 priority
Spanning-tree mst max-hops
Spanning-tree mst port-priority
Console config # spanning-tree mst max-hops
Consoleconfig-if#spanning-tree mst 1 port-priority
270
Interface Long Short
Spanning-tree mst configuration
Spanning-tree mst cost
271
Syntax Instance instance-id add remove vlan vlan-range
Syntax Spanning-tree mst configuration Default Setting
Instance mst
272
Syntax Name string
Name mst
Revision mst
Syntax Revision value No revision
Show mst
Default configuration revision number is
Following example sets the configuration revision to
Syntax Show current pending
Exit mst
Syntax Exit Default Setting
Syntax Abort Default Setting
Abort mst
Console# spanning-tree pathcost method long
Spanning-tree pathcost method
Spanning-tree bpdu
276
Syntax Spanning-tree bpdu filtering flooding
Consoleconfig# spanning-tree bpdu flooding
Clear spanning-tree detected-protocols
277
Following example displays spanning-tree information
Show spanning-tree
Console# clear spanning-tree detected-protocols ethernet g1
278
279
Console# show spanning-tree
280
281
282
283
284
285
Console# show spanning-tree mst-configuration
286
287
288
289
Spanning-tree mst mstp-rstp
290
Interface configuration Ethernet, port-channel
Consoleconfig# spanning-tree mst mstp-rstp
Root guard is disabled
Spanning-tree guard root
292
Following example enable root guard on port g8
Consoleconfig-if#spanning-tree guard root
Ip ssh server
SSH Commands
Ip ssh port
Crypto key generate dsa
Syntax Crypto key generate dsa Default Configuration
Console config# crypto key generate dsa
Crypto key generate rsa
Ip ssh pubkey-auth
Syntax Crypto key generate rsa Default Configuration
Console config# crypto key generate rsa
295
User-key
Consoleconfig# crypto key pubkey-chain ssh
Crypto key pubkey-chain ssh
297
Key-string
Syntax Key-string row key-string
298
Syntax Show ip ssh Default Configuration
Show ip ssh
Syntax Show crypto key mypubkey rsa dsa
Following example displays the SSH server configuration
Show crypto key mypubkey
Rsa-RSA key Dsa-DSA key
Console# show crypto key mypubkey rsa
Show crypto key pubkey-chain ssh
300
Console# show crypto key pubkey-chain ssh username bob
Console# show crypto key pubkey-chain ssh
Following example displays the SSH public called bob
301
SSH Commands
Logging on
Syslog Commands
Syntax Logging on no logging on Default Configuration
Logging
As described in the field descriptions
Default is informational
Logging console
Syntax Logging console level No logging console
Logging buffered size
Default level is informational
Logging buffered
Syntax Logging buffered level No logging buffered
Clear logging
Console config# logging buffered size
Syntax Clear logging Default Configuration
Console# clear logging
Clear logging file
Syntax Clear logging file Default Configuration
Logging file
Syntax Logging file level No logging file
Following example clears messages from the logging file
Syntax Show logging Default Configuration
Show logging
Console# clear logging file
Console# show logging
Syntax Show logging file Default Configuration
Show logging file
309
310
Syntax Show syslog-servers Default Configuration
Show syslog-servers
311
Following example displays the syslog server settings
Console# show syslog-servers
Syslog Commands
Ping
Timeout timeout-The default is 2000 milliseconds
System Management
313
314
Traceroute
Following example displays a ping to IP address
315
316
317
Special Telnet Command characters
Telnet
Keywords Table
318
Ports Table
319
Syntax Resume connection
Following command switches to another open Telnet session
Resume
320
Reload
Hostname
Console# show users
Show users
Show sessions
Console show sessions
Exec mode
Show system
Syntax Show system
Syntax Show version 324
Show version
Following example displays the system information
Console show system
Tag-The device asset tag. Range 1- 16 characters
Asset-tag
Syntax Asset-tag tag No asset-tag
325
Console show system id
Syntax Show system id Default Configuration
Show system id
326
No Tacacs host is specified
Tacacs Commands
Tacacs-server host
327
Tacacs-server key
Tacacs-server timeout
Following example sets the authentication encryption key
Following example specifies a TACACS+ host
329
Console config# tacacs-server timeout
Tacacs-server source-ip
Ip-address-Name or IP address of the host
Show tacacs
Syntax Show tacacs ip-address
Console# show tacacs
User Interface
Enable
Disable
Syntax Login Default Configuration
Login
Configure
Syntax Configure
All command modes
Exitconfiguration
Syntax Exit Default Configuration
333
End
Syntax End Default Configuration
ExitEXEC
Following example closes an active terminal session
Help
Syntax Help Default Configuration
Syntax History No history Default Configuration
History
History size
Syntax History size number-of-commands No history size
Syntax Debug-mode Default Configuration
Debug-mode
337
Syntax Show history Default Configuration
Show history
Console# show history
Syntax Show privilege Default Configuration
Show privilege
Console# show privilege
Vlan
Vlan Commands
Vlan database
Console# vlan database
Default-vlan disable
Interface vlan
341
Interface range vlan
Syntax Interface range vlan vlan-range all
Syntax Name string no name
Switchport access vlan
Name
342
343
Switchport trunk allowed vlan
Console config-if#switchport access vlan
Console config-if#switchport trunk allowed vlan add 2,5-8
Switchport trunk native vlan
Switchport general allowed vlan
Console config-if#switchport trunk native vlan
Switchport general pvid
345
346
Switchport general ingress-filtering disable
Ingress filtering is enabled
All frame types are accepted at ingress
Switchport general acceptable-frame-type tagged-only
Switchport forbidden vlan
All VLANs allowed
Following example maps protocol ip-arp to the group named
Console config-if#switchport forbidden vlan add
Map protocol protocols-group
348
Vlan-id-VLAN ID of the internal usage VLAN.Range Valid Vlan
Switchport general map protocols-group vlan
Ip internal-usage-vlan
349
Syntax Show vlan tag vlan-id name vlan-name
Console config# ip internal-usage-vlan
Show vlan
Following example displays all Vlan information
351
Syntax Show vlan internal usage Default Configuration
Show vlan internal usage
Console# show vlan internal usage
Syntax Show vlan protocols-groups Default Configuration
Show vlan protocols-groups
Following example displays protocols-groups information
353
Show interfaces switchport
Console# show vlan protocols-groups
Syntax Switchport mode customer access trunk general 354
Switchport mode
Console# show interface switchport ethernet g1
No Vlan is configured
Switchport customer vlan
No switchport mode
Vlan-id- Vlan ID of the customer
356
Ip http port
Web Server
Ip http server
Syntax Ip http port port-number No ip http port
Ip https port
Default for the device is disabled
Ip https server
Syntax Ip https port port-number No ip https port
359
Following example configures the https port number to
Crypto certificate generate
Certificate and the SSL RSA key pairs do not exist
Console enable# crypto certificate generate key-generate
Crypto certificate request
Following example regenerates a Https certificate
Console# crypto certificate 1 request
361
Number-Specifies the certificate number. Range 1
Crypto certificate import
Syntax Crypto certificate number import
362
Certificate number
Consoleconfig# crypto certificate 1 import
Ip https certificate
363
Syntax Crypto certificate number export pkcs12
Console config# ip https certificate
Crypto certificate export pkcs12
364
Console# crypto certificate 1 export pkcs12
Following example exports the certificate and RSA keys
365
Following example imports the certificate and RSA keys
Crypto certificate import pkcs12
Syntax Crypto certificate number import pkcs12 passphrase
366
367
Following example displays the certificate
Show crypto certificate mycertificate
Syntax Show crypto certificate mycertificate number
Console# show crypto certificate mycertificate
Console# show ip http
Show ip http
Show ip https
Console# show ip https
370
Console config# aaa authentication dot1x default none
802.1x Commands
Aaa authentication dot1x
Method1 method2...-At least one from the following table
Dot1x system-auto-control
Following example enables 802.1x globally
Console config# dot1x system-auto-control
Dot1x port-control
Syntax Dot1x re-authentication No dot1x re-authentication
Dot1x re-authentication
Console config-if#dot1x port-control auto
373
Console config-if#dot1x re-authentication
Dot1x timeout re-authperiod
Dot1x re-authenticate
Console config-if#dot1x timeout re-authperiod
375
Dot1x timeout quiet-period
Console# dot1x re-authenticate ethernet g8
376
Dot1x timeout tx-period
Console config-if#dot1x timeout quiet-period
Syntax Dot1x max-req count No dot1x max-req
Dot1x timeout supp-timeout
Dot1x max-req
377
Dot1x timeout server-timeout
378
Syntax Show dot1x ethernet interface
Console config# dot1x timeout server-timeout
Show dot1x
379
380
Console# show dot1x ethernet g3
Username-Supplicant username Range 1- 160 characters
Show dot1x users
Syntax Show dot1x users username username
Following example displays 802.1X users
382
Show dot1x statistics
Syntax Show dot1x statistics ethernet interface
Switch# show dot1x statistics ethernet g1
383
Syntax Dot1x auth-not-req no dot1x auth-not-req
User should be authorized to access the Vlan
Dot1x auth-not-req
384
Syntax Dot1x multiple-hosts no dot1x multiple-hosts
Dot1x multiple-hosts
Dot1x single-host-violation
385
Syntax Show dot1x advanced ethernet interface
Show dot1x advanced
Forward trap
386
387
Switch# show dot1x advanced
Switch# show dot1x advanced ethernet g1
Console# show dot1x advanced ethernet g1
388