Enterasys SecureStack C3
Page
Page
 Enterasys Networks, Inc. Firmware License Agreement
 Iii
Page
 Contents
Page
 Activating Licensed Features
 Discovery Protocol Configuration
Configuring System Power and PoE
 Port Configuration
 Show port broadcast Set port broadcast Clear port broadcast
 Snmp Configuration
 Spanning Tree Configuration
 Configuring Spanning Tree Port Parameters Purpose Commands
 802.1Q Vlan Configuration
 Port Priority Configuration
Policy Classification Configuration
 Logging and Network Management
Igmp Configuration
 14-3
 Rmon Configuration
 Dhcp Server Configuration
 IP Configuration
Preparing for Router Mode
Dhcp Snooping and Dynamic ARP Inspection
 IPv4 Routing Protocol Configuration
 20-11
 IPv6 Management
IPv6 Configuration
 IPv6 Proxy Routing
DHCPv6 Configuration
 OSPFv3 Configuration
 Authentication and Authorization Configuration
 26-37
 TACACS+ Configuration
 Appendix a Policy and Authentication Capacities
SFlow Configuration
Index
Tables
 10-4
 22-26
 Xxxii
 About This Guide
Using This Guide
Structure of This Guide
Important Notice
 Structure of This Guide
 Related Documents
SecureStack C3 Installation Guides
 Following conventions are used in the text of this document
Conventions Used in This Guide
Following icons are used in this guide
 Support@enterasys.com
Getting Help
 Getting Help Xxxviii About This Guide
 Introduction
Switch Management Methods
SecureStack C3 CLI Overview
 Default Settings for Basic Switch Operation
Factory Default Settings
 Feature Default Setting
 Sntp
Default Settings for Router Operation
 Dvmrp
 Connecting Using the Console Port
Using the Command Line Interface
Starting a CLI Session
 Using a Default User Account
Connecting Using Telnet
Using an Administratively Configured User Account
Logging
 CLI Command Defaults Descriptions
Navigating the Command Line Interface
CLI Command Modes
Getting Help with CLI Syntax
 Displaying Scrolling Screens
Abbreviating and Completing Commands
 Basic Line Editing Commands
Basic Line Editing Commands
 About SecureStack C3 Switch Operation in a Stack
Configuring Switches in a Stack
 Installing a New Stackable System of Up to Eight Units
 Creating a Virtual Switch Configuration
Installing Previously-Configured Systems in a Stack
Adding a New Unit to an Existing Stack
 SID
 Issues Related to Mixed Type Stacks
Considerations About Using Clear Config in a Stack
Feature Support
Configuration
 Show switch
Stacking Configuration and Management Commands
Commands
Purpose
 Examples
Show switch switchtype
 None
Show switch stack-ports
 Switch command, read‐write
Set switch
Example
Priority value
 Set switch description
Set switch copy-fw
This example shows how to assign priority 3 to switch
This example shows how to renumber switch 5 to switch
 Set switch member
Set switch movemanagement
 Use this command to remove a member entry from the stack
Clear switch member
 Quick Start Setup Commands
Basic Configuration
Required CLI Setup Commands
 Optional CLI Setup Commands
Setting User Accounts and Passwords
 Show system login Output Details
Show system login
Parameters
 Clear system login
Set system login
Use this command to remove a local login user account
Super‐user read‐write read‐only
 This example shows how to remove the netops user account
Set password
Switch command, read‐write Switch command, super‐user
 Set system password aging
Set system password length
 Disable
Set system password history
Show system lockout
 Show system lockout Output Details
Set system lockout
Attempts attempts
Time time
 Setting Basic Switch Properties
 Show ip address
 Set ip address
Use this command to clear the system IP address
Clear ip address
 Show ip protocol
This example shows how to clear the system IP address
Set ip protocol
 Show system
This example shows how to display system information
 Show system Output Details
Show system hardware
 Slot Hardware Information
Show system utilization
 Set system utilization
Default threshold value is 80%
This example sets the CPU utilization threshold to 75%
 Show system enhancedbuffermode
Clear system utilization
 Enable disable Enables or disables enhanced buffer mode
Set system temperature
This example shows how to enable enhanced buffer mode
Set system enhancedbuffermode
 Syslog enable
Clear system temperature
Disable
Trap enable disable
 Set time
Show time
 Use this command to display daylight savings time settings
This example shows how to set the system clock to 750 a.m
Show summertime
 Set summertime date
Set summertime
If a zone name is not specified, none will be applied
If an offset is not specified, none will be applied
 Set summertime recurring
 This example shows how to set the command prompt to Switch
Use this command to modify the command prompt
Clear summertime
Set prompt
 Set banner motd
Show banner motd
 Show version
Clear banner motd
 Use this command to configure a name for the system
‐5 provides an explanation of the command output
Set system name
Show version Output Details
 This example shows how to set the system location string
Use this command to identify the location of the system
Set system location
Set system contact
 This example shows how to set the terminal columns to
This example shows how to set the system contact string
Set width
Set length
 This example shows how to display the CLI logout setting
This example shows how to set the terminal length to
Show logout
Set logout
 This example shows how to display all console settings
Use this command to display console settings
Use this command to set the console port baud rate
Show console
 Downloading a Firmware Image
This example shows how to set the console port baud rate to
Downloading from a Tftp Server
Downloading via the Serial Port
 Type 2. The following baud rate selection screen displays
 Reverting to a Previous Image
 Show boot system
Reviewing and Selecting a Boot Firmware Image
Reboot the system using the reset command page 3‐50
 Compatibility platform specific
Set boot system
 This example shows how to display Telnet status
Starting and Configuring Telnet
Use this command to enable or disable Telnet on the switch
Show telnet
 Telnet
Enable disable
Inbound
Outbound all
 Configuration Persistence Mode
Managing Switch Configuration and Files
 Set snmp persistmode
Show snmp persistmode
 Dir
Save config
Auto
Manual
 Show file
Use this command to display the contents of a file
 Show config
 All
Configure
Outfile
 Append
Copy
Systemimage
 This example shows how to download an image via Tftp
Show tftp settings
Delete
 Clear tftp timeout
Set tftp timeout
This example shows the output of this command
This example sets the timeout period to 4 seconds
 Clear tftp retry
Set tftp retry
This example sets the retry count to
 Clearing and Closing the CLI
This example shows how to clear the CLI screen
Cls clear screen
To clear the CLI screen or to close your CLI session
 Reset
Resetting the Switch
Use either of these commands to leave a CLI session
This example shows how to exit a CLI session
 If no unit ID is specified, the entire system will be reset
Clear config
This example shows how to reset the system
This example shows how to reset unit
 Use this command to display WebView status
Using and Configuring WebView
Show webview
 Show ssl
Set webview
 This example shows how to enable SSL
This example shows how to display SSL status
Set ssl
 Gathering Technical Support Information
Command
Show support
To gather common technical support information
 Hostprotect is enabled by default
Configuring Hostprotect
Show system hostprotect
Set system hostprotect
 This example disables hostprotect
This feature is disabled by default
Default state is enabled
Clear system hostprotect
 Usage
 Licensing Procedure in a Stack Environment
Activating Licensed Features
License Key Field Descriptions
 Adding a New Member to a Licensed Stack
Clearing, Showing, and Applying Licenses
 Usage
Set license
 FeatureID feature The name of the feature being cleared
Use this command to clear the license key settings
Show license
Clear license
 C3rw-clear license featureId advrouter
 Clear license Activating Licensed Features
 Commands
Configuring System Power and PoE
Show inlinepower
Use this command to display system power properties
 This example shows how to display system power properties
Set inlinepower threshold
Show inlinepower Output Details
 Set inlinepower detectionmode
Set inlinepower trap
Sending of traps is disabled by default
 Ieee
Show port inlinepower
 Admin off auto
Set port inlinepower
Priority critical
High low
 Set port inlinepower Configuring System Power and PoE
 Configuring CDP
Discovery Protocol Configuration
 Show cdp Output Details
Show cdp
 Enable
Auto disable
Set cdp state
 Set cdp auth
Use this command to set a global CDP authentication code
Set cdp interval
 Clear cdp
Set cdp hold-time
 Show neighbors
 Show ciscodp
Configuring Cisco Discovery Protocol
 ‐3 provides an explanation of the command output
‐2 provides an explanation of the command output
Show ciscodp port info
Show ciscodp Output Details
 This example shows how to globally enable CiscoDP
Set ciscodp timer
Set ciscodp status
Show ciscodp port info Output Details
 Set ciscodp port
Set ciscodp holdtime
 Dot1p
Vvid
Untagged
Trusted
 Clear ciscodp
 To review and configure Llpd and LLPD‐MED
Configuring Link Layer Discovery Protocol and LLDP-MED
Overview
 Configuration Tasks
 Show lldp
Use this command to display Lldp configuration information
 Show lldp port trap
Show lldp port status
 Show lldp port location-info
Show lldp port tx-tlv
Show lldp port tx‐tlv port‐string
 Show lldp port local-info
 1000BASE-TFD
Show lldp port local-info Output Details
 ECS Elin
 Show lldp port remote-info
 Guest‐voice‐signaling
Voice‐signaling
Show lldp port network-policy
Voice
 Set lldp tx-interval
Video‐signaling
Softphone‐voice
Video‐conferencing
 Set lldp trap-interval
Set lldp hold-multiplier
This example sets the transmit interval to 20 seconds
 Set lldp med-fast-repeat
 Rx‐enable
Tx‐enable
Set lldp port status
Set lldp port trap
 Set lldp port location-info
Set lldp port med-trap
Elin
 Set lldp port tx-tlv
 Mac‐phy
Gvrp
Poe
Link‐aggr
 Set lldp port network-policy
State enable disable
Tag tagged untagged
Vid vlan‐id dot1p
 Tx‐interval
Clear lldp
Hold‐multiplier
Trap‐interval
 Clear lldp port trap
Clear lldp port status
 Clear lldp port location-info
Clear lldp port med-trap
Cleared
 Tag
Clear lldp port network-policy
Vid
Dscp
 Clear lldp port tx-tlv
 Disables the LLDP‐MED Extended Power via MDI TLV from being
Disables the LLDP‐MED Location Identification TLV from being
 Port Configuration Summary
Port Configuration
Port String Syntax Used in the CLI
Port type.unitorslot number.port number
 Port Slot/Unit Parameters Used in the CLI
Reviewing Port Status
 Show port status
Show port
 Show port counters
Switch mib2
Show port status Output Details
 Show port counters Output Details
 Show port cablestatus
Clear port counters
This example clears the port counters for ge.3.1
 This example shows the cable status for 1 GE port ge.1.31
Disabling / Enabling and Naming Ports
Show port cablestatus Output Details
 Set port enable
Set port disable
This example shows how to disable ge.1.1
This example shows how to enable ge.1.3
 Show port alias
Use this command to assign an alias name to a port
Set port alias
 This example shows how to clear the alias for ge.3.3
This example shows how to assign the alias Admin to ge.3.3
 Show port speed
Setting Speed and Duplex Mode
 Show port duplex
Set port speed
10 100
Mbps
 Set port duplex
This example shows how to set ge.1.17 to full duplex
Full half
 Show port jumbo
Enabling / Disabling Jumbo Frame Support
 Set port jumbo
Enables or disables jumbo frame support
Clear port jumbo
 Show port negotiation
Setting Auto-Negotiation and Advertised Ability
 Set port negotiation
Enable disable
Show port advertise
 Set port advertise
 Clear port advertise
 Set port mdix
Show port mdix
Forced‐auto
Mdi
 Configure ports to use Mdix mode only
Configure ports to use MDI mode only
Optional Specify the port or ports to configure
 Show flowcontrol
Setting Flow Control
Set flowcontrol
 This example shows how to enable flow control
 Show port trap
Setting Port Link Traps and Link Flap Detection
 Set port trap
Following example disables sending trap on ge.3.1
Show linkflap
 Portstate
Globalstate
Parameters
Metrics
 Show linkflap metrics Output Details
Show linkflap parameters Output Details
 Disables or enables the link flap detection function
Disable enable
Set linkflap globalstate
Set linkflap portstate
 Set linkflap action
Set linkflap interval
 Clear linkflap action
Use this command to set the link flap action trigger count
Set linkflap threshold
 Clear linkflap down
Set linkflap downtime
 All stats
Clear linkflap
Parameter
Threshold interval
 Show port broadcast
Configuring Broadcast Suppression
 Clear port broadcast
Set port broadcast
 Syntax Used in the CLI on page 7‐1
 Port Mirroring
Mirroring Features
Remote Port Mirroring
 Procedures
Configuring Smon MIB Port Mirroring
Overview
 Show port mirroring
To review and configure port mirroring on the device
 Can be configured per stack, if applicable
Create disable
Set port mirroring
 Clear port mirroring
Use this command to clear a port mirroring relationship
Set mirror vlan
 Clear mirror vlan
 Lacp Operation
Link Aggregation Control Protocol Lacp
 Lacp Terminology
‐6 defines key terminology used in Lacp configuration
SecureStack C3 Usage Considerations
Lacp Terms and Definitions
 Commands
 Show lacp
‐7 provides an explanation of the command output
 This example shows how to disable Lacp
Disable enable Disables or enables Lacp
Set lacp
Show lacp Output Details
 Set lacp asyspri
Set lacp aadminkey
Asyspri
 Clear lacp
Disable enable Disables or enables static link aggregation
Set lacp static
 Clear lacp static
 Set lacp singleportlag
This example enables the formation of single port LAGs
Clear lacp singleportlag
 Status detail
Show port lacp
Summary Counters
 Set port lacp
Aadminkey
 Lacptimeout
Aadminstate
Padminkey
Padminport
 Clear port lacp
 C3su-clear port lacp port ge.3.16
 Set port protected
Configuring Protected Ports
Protected Port Operation
 Clear port protected
Show port protected
Read‐only
 Show port protected name
Set port protected name
 Clear port protected name
Use this command to clear the name of a protected group
 Clear port protected name Port Configuration
 Snmp Configuration Summary
Snmp Configuration
 SNMPv3
SNMPv1 and SNMPv2c
About Snmp Security Models and Levels
 Configuration Considerations
Using Snmp Contexts to Access Specific MIBs
Reviewing Snmp Statistics
Snmp Security Levels
 Show snmp engineid
This example shows how to display Snmp engine properties
Show snmp engineid Output Details
 This example shows how to display Snmp counter values
Use this command to display Snmp traffic counter values
Show snmp counters
 Show snmp counters Output Details
 Engine or otherwise unavailable
 Show snmp user
Configuring Snmp Users, Groups, and Communities
 ‐4 provides an explanation of the command output
This example shows how to display an Snmp user list
Use this command to create a new SNMPv3 user
Set snmp user
 Sha
Aes
Volatile
Nonvolatile
 Show snmp group
Clear snmp user
Remote remote
 User user
Set snmp group
Security‐model
V2c usm Volatile
 Show snmp community
Clear snmp group
V2c usm
 Set snmp community
Use this command to configure an Snmp community group
Securityname
Context context
 Use this command to delete an Snmp community name
Configuring Snmp Access Rights
This example shows how to delete the community name vip
Clear snmp community
 Noauthentication
Show snmp access
Authentication Privacy Context context
Nonvolatile read‐ Only
 ‐6 provides an explanation of the command output
This example shows how to display Snmp access information
Show snmp access Output Details
 Set snmp access
 Configuring Snmp MIB Views
Clear snmp access
 Show snmp view
 Set snmp view
Show snmp context
Show snmp view Output Details
 Clear snmp view
 Show snmp targetparams
Configuring Snmp Target Parameters
Volatile nonvolatile
Read‐only
 Set snmp targetparams
‐8 provides an explanation of the command output
Show snmp targetparams Output Details
Message‐
 Clear snmp targetparams
Authentication
Privacy
Protected from disclosure
 Use this command to display Snmp target address information
Configuring Snmp Target Addresses
Show snmp targetaddr
 Set snmp targetaddr
Timeout timeout
Param param
Udpport udpport
 Clear snmp targetaddr
Use this command to delete an Snmp target address entry
Taglist taglist
Tag 1 tag
 About Snmp Notify Filters
Configuring Snmp Notification Parameters
 Show newaddrtrap
By default, this function is disabled globally and per port
Set newaddrtrap
 Show snmp notify
 Set snmp notify
‐10 provides an explanation of the command output
10 show snmp notify Output Details
Trap inform
 Clear snmp notify
Use this command to clear an Snmp notify configuration
Show snmp notifyfilter
 Subtree oid‐or‐
Set snmp notifyfilter
 Clear snmp notifyfilter
 Set snmp notifyprofile
Show snmp notifyprofile
Targetparam
 This example shows how to delete Snmp notify profile area51
Creating a Basic Snmp Trap Configuration
Clear snmp notifyprofile
 Example
11 Basic Snmp Trap Configuration
 How Snmp Will Use This Configuration
Configuring the Snmp Management Interface
Show snmp interface
 Loopback loop‐ID
Set snmp interface
 Clear snmp interface
 Clear snmp interface Snmp Configuration
 Spanning Tree Configuration Summary
Spanning Tree Configuration
 Loop Protect
Spanning Tree Features
 Configuring Spanning Tree Bridge Parameters
 For information about
 Sid sid
Show spantree stats
Active
 Show spantree Output Details
‐1 shows a detailed explanation of command output
 Set spantree
Disable enable Globally disables or enables Spanning Tree
Show spantree version
 Set spantree version
 Clear spantree version
This example shows how to reset the Spanning Tree version
Show spantree bpdu-forwarding
 By default Bpdu forwarding is disabled
Disable enable Disables or enables Bpdu forwarding
This example shows how to enable Bpdu forwarding
Set spantree bpdu-forwarding
 Clear spantree bridgeprioritymode
Set spantree bridgeprioritymode
8021d
8021t
 Set spantree msti
Show spantree mstilist
Create delete
 Show spantree mstmap
Clear spantree msti
Fid fid
 Use this command to map a FID back to SID
This example shows how to map FID 3 to SID
Set spantree mstmap
Clear spantree mstmap
 Show spantree vlanlist
This example shows how to map FID 2 back to SID
Show spantree mstcfgid
 Set spantree mstcfgid
Cfgname name Specifies an MST configuration name
Clear spantree mstcfgid
 Set spantree priority
Use this command to set the device’s Spanning Tree priority
Clear spantree priority
 Set spantree hello
This example shows how to reset the bridge priority on SID
Clear spantree hello
 Set spantree maxage
Use this command to set the bridge maximum aging time
 Use this command to set the Spanning Tree forward delay
Set spantree fwddelay
Clear spantree maxage
 Show spantree backuproot
Clear spantree fwddelay
 Clear spantree backuproot
Set spantree backuproot
 Set spantree tctrapsuppress
Show spantree tctrapsuppress
 Set spantree protomigration
Clear spantree tctrapsuppress
 Show spantree spanguard
Enable disable Enables or disables the SpanGuard function
Set spantree spanguard
 Clear spantree spanguard
This example shows how to enable the SpanGuard function
 Set spantree spanguardtimeout
Show spantree spanguardtimeout
 Show spantree spanguardlock
Clear spantree spanguardtimeout
 This example shows how to unlock port ge.1.16
Show spantree spanguardtrapenable
Clear / set spantree spanguardlock
 Clear spantree spanguardtrapenable
Set spantree spanguardtrapenable
Is enabled
 Set spantree legacypathcost
Show spantree legacypathcost
 Show spantree autoedge
Clear spantree legacypathcost
Set spantree autoedge
This example clears the legacy path cost to 802.1t values
 Clear spantree autoedge
 Set spantree portadmin
Configuring Spanning Tree Port Parameters
Disable enable
To display and set Spanning Tree port parameters
 Show spantree portadmin
Clear spantree portadmin
This example shows how to disable Spanning Tree on ge.1.5
 Show spantree portpri
Use this command to set a port’s Spanning Tree priority
Set spantree portpri
 Clear spantree portpri
 Set spantree adminpathcost
Show spantree adminpathcost
 Show spantree adminedge
Clear spantree adminpathcost
 Clear spantree adminedge
Set spantree adminedge
This example shows how to set ge.1.11 as an edge port
True false
 Show spantree operedge
This example shows how to reset ge.1.11 as a non‐edge port
 Configuring Spanning Tree Loop Protect Parameters
 Set spantree lp
This example shows how to enable Loop Protect on ge.2.3
Show spantree lp
If no SID is specified, SID 0 is assumed
 Show spantree lplock
Clear spantree lp
 SID Locked
Clear spantree lplock
 Show spantree lpcapablepartner
Set spantree lpcapablepartner
 Clear spantree lpcapablepartner
Use this command to set the Loop Protect event threshold
Set spantree lpthreshold
 Show spantree lpthreshold
None. The default event threshold is
Clear spantree lpthreshold
 Show spantree lpwindow
Set spantree lpwindow
 Disabled
Set spantree lptrapenable
Clear spantree lpwindow
 Clear spantree lptrapenable
Show spantree lptrapenable
 Set spantree disputedbpduthreshold
 Clear spantree disputedbpduthreshold
Show spantree disputedbpduthreshold
 Show spantree nonforwardingreason
 Vlan Configuration Summary
802.1Q Vlan Configuration
 Creating a Secure Management Vlan
Command Set for Creating a Secure Management Vlan
 Show vlan
Viewing VLANs
Static
Portinfo
 Vlan Vlan ID Name
Show vlan Output Details
 This example shows how to create Vlan
Create enable Creates, enables or disables VLANs. disable
Creating and Naming Static VLANs
Set vlan
 Set vlan name
This example shows how to set the name for Vlan 7 to green
Clear vlan
 Clear vlan name
This example shows how to clear the name for Vlan
 Show port vlan
Assigning Port Vlan IDs PVIDs and Ingress Filtering
 Clear port vlan
Set port vlan
Modify‐egress
No‐modify‐egress
 Show port ingress filter
 Show port discard
Set port ingress filter
 Tagged untagged both none
Set port discard
 Show port egress
Configuring the Vlan Egress List
 Set vlan forbidden
 Set vlan egress
Use this command to remove ports from a VLAN’s egress list
Clear vlan egress
Untagged forbidden tagged
 Forbidden
Show vlan dynamicegress
 This example shows how to enable dynamic egress on Vlan
Enable disable Enables or disables dynamic egress
Set vlan dynamicegress
 Show host vlan
Setting the Host Vlan
Set host vlan
 Clear host vlan
This example shows how to set Vlan 7 as the host Vlan
 About Garp Vlan Registration Protocol Gvrp
Enabling/Disabling Gvrp Garp Vlan Registration Protocol
How It Works
 Example of Vlan Propagation via Gvrp
 Use this command to display Gvrp configuration information
Show garp timer
Show gvrp
 Disables or enables Gvrp on the device
Show gvrp configuration Output Details
Set gvrp
 This example shows how to enable Gvrp on ge.1.3
Set garp timer
Clear gvrp
 Leaveall timer‐
Clear garp timer
Join
Leave
 C3su-clear garp timer leave ge.1.1
 Policy Classification Configuration Summary
Policy Classification Configuration
 Use this command to display policy profile information
Configuring Policy Profiles
Show policy profile
‐verbose
 Show policy profile Output Details
 Set policy profile
 This example shows how to delete policy profile
Use this command to delete a policy profile entry
Clear policy profile
 All admin‐ profile profile‐ index
Configuring Classification Rules
Show policy rule
 Admin‐pid
Not‐in‐service Not‐ready Storage‐type non‐
Tcpsourceport
Udpdestport
 Show policy rule Output Details
Show policy capability
 Vlan
 Set policy rule
Admin‐profile
Vlantag data
 Ipproto
Ether
Ipdestsocket
Ipsourcesocket
 Data value Mask bits
Valid Values for Policy Classification Rules
 Clear policy rule
Following parameters apply to deleting an admin rule
Range from 1 to 4094 or 0xFFF
All‐pid‐entries
 Clear policy all-rules
Use this command to remove all policy classification rules
 Assigning Ports to Policy Profiles
Use this command to assign ports to a policy profile
Set policy port
To assign and unassign ports to policy profiles
 Clear policy port
 About Policy-Based CoS Configurations
Configuring Policy Class of Service CoS
Procedure 11-1 User-Defined CoS Configuration
 Configuring Policy Class of Service CoS
 About CoS-Based Flood Control
Procedure
 Set cos state
Use this command to enable or disable Class of Service
 Show cos state
This example shows how to enable Class of Service
Clear cos state
 Priority priority
Set cos settings
Tos‐value tos‐value
Irl‐reference
 Show cos settings
Clear cos settings
Priority
Tos‐value
 Set cos port-config
 Should be displayed
Show cos port-config
 Entry
Clear cos port-config
Name
Ports
 Set cos port-resource irl
 Group#.port‐type
Set cos port-resource flood-ctrl
Unicast
Multicast
 Group#.port‐type
Show cos port-resource
 Unit
Clear cos port-resource irl
Rate
Type
 Set cos reference
Clear cos port-resource flood-ctrl
Unicast
Multicast
 Show cos reference
Specifies that an IRL reference is being configured
IRL reference number associated with this entry
Rate‐limit irl‐index
 Clear cos reference
 Port‐typ e index
Show cos unit
Kbps
Pps
 Show cos port-type
Clear cos all-entries
 This example shows flood control information for port type
 Port Priority Configuration Summary
Port Priority Configuration
 Show port priority
Configuring Port Priority
 Clear port priority
Set port priority
 Show port priority-queue
Configuring Priority to Transmit Queue Mapping
 Set port priority-queue
 Clear port priority-queue
 Show port txq
Configuring Quality of Service QoS
 Set port txq
 Clear port txq
By default, transmit queues are defined as follows
 Clear port txq Port Priority Configuration
 Igmp Overview
Igmp Configuration
About IP Multicast Group Management
 To configure Igmp snooping from the switch CLI
Configuring Igmp at Layer
About Multicasting
 Use this command to display Igmp snooping information
Set igmpsnooping adminmode
This example shows how to display Igmp snooping information
Use this command to enable or disable Igmp on the system
 Enable disable Enables or disables Igmp
This example shows how to enable Igmp on the system
This example shows how to enable Igmp on port ge.1.10
Set igmpsnooping interfacemode
 Set igmpsnooping maxresponse
 Set igmpsnooping add-static
Set igmpsnooping mcrtrexpiretime
Modify
If no ports are specified, all ports are added to the entry
 Show igmpsnooping static
Set igmpsnooping remove-static
If modify is not specified, a new entry is created
 Group group
Show igmpsnooping mfdb
This example displays the static Igmp ports for Vlan
Stats Optional Displays Mfdb statistics
 This example shows how to clear all Igmp snooping entries
Use this command to clear all Igmp snooping entries
Clear igmpsnooping
 To configure Igmp on routing interfaces
Configuring Igmp on Routing Interfaces
Global configuration C3su‐routerConfig#
Ip igmp
 This example shows how to enable Igmp on the router
Ip igmp enable
Interface configuration C3su‐routerConfig‐ifVlan 1#
Ip igmp version
 Show ip igmp interface
Any router mode
 Ip igmp query-interval
Show ip igmp groups
 Ip igmp startup-query-interval
Ip igmp query-max-response-time
 Ip igmp last-member-query-interval
Ip igmp startup-query-count
 Ip igmp robustness
Ip igmp last-member-query-count
 Interface configuration C3 su‐routerConfig‐ifVlan 1#
 Ip igmp robustness Igmp Configuration
 Logging and Network Management
Configuring System Logging
 Show logging server
 Set logging server
 Clear logging server
Show logging default
 Use this command to set logging default values
Set logging default
 Show logging application
Clear logging default
Facility
Severity
 Show logging application Output Details
Set logging application
 If level is not specified, none will be applied
Level level
 Show logging local
Clear logging application
 Clear logging local
Set logging local
 Show logging buffer
This example shows how to clear local logging
Show logging interface
 Set logging interface
 Clear logging interface
 History
Monitoring Network Events and Status
 Default
Use this command to set the size of the history buffer
Show history
Set history
 Show users
Ping
This example, the host at IP address is not responding
 Show netstat
Disconnect
Console
 Following table describes the output of this command
Following example shows the output of this command
Show netstat Output Details
 Use this command to display the switch’s ARP table
Managing Switch Network Addresses and Routes
Show arp
 Set arp
This example shows how to display the ARP table
Show arp Output Details
 Traceroute
Clear arp
 Each response
Show mac
Type other learned
Self mgmt
 Show mac Output Details
Show mac agetime
 This example shows how to set the MAC timeout period
This example shows how to display the MAC timeout period
Set mac agetime
Clear mac agetime
 Set mac algorithm
Default MAC algorithm is mac‐crc16‐upperbits
Show mac algorithm
 Set mac multicast
Clear mac algorithm
 Clear mac address
Use this command to remove a multicast MAC address
Append clear
 Set mac unreserved-flood
Show mac unreserved-flood
 This example enables multicast flood protection
Configuring Simple Network Time Protocol Sntp
Use this command to display Sntp client settings
Show sntp
 Show sntp Output Details
This example shows how to display Sntp client settings
 Clear sntp client
Set sntp client
 Clear sntp server
Set sntp server
If precedence is not specified, 1 will be applied
 Clear sntp poll-interval
Set sntp poll-interval
 Set sntp poll-retry
This example shows how to clear the Sntp poll interval
Clear sntp poll-retry
 Clear sntp poll-timeout
Set sntp poll-timeout
Use this command to clear the Sntp poll timeout
This example shows how to clear the Sntp poll timeout
 Set timezone
 Set sntp interface
Show sntp interface
 Clear sntp interface
 C3rw-show sntp interface Vlan 100 C3rw-clear sntp interface
 Show nodealias config
Configuring Node Aliases
 Set nodealias
Show nodealias config Output Details
Maxentries maxentries
 Clear nodealias config
 Rmon Monitoring Group Functions and Commands
Rmon Configuration
Rmon Monitoring Group Functions
 Design Considerations
Group What It Does What It Monitors CLI Commands
 To display, configure, and clear Rmon statistics
Statistics Group Commands
 Show rmon stats
Use this command to configure an Rmon statistics entry
Set rmon stats
 This example shows how to delete Rmon statistics entry
To‐defaults
Clear rmon stats
If owner is not specified, monitor will be applied
 Show rmon history
History Group Commands
 Clear rmon history
Set rmon history
Buckets buckets
Interval interval
 This example shows how to delete Rmon history entry
 Show rmon alarm
Alarm Group Commands
This example shows how to display Rmon alarm entry
 Show rmon alarm Output Details
Set rmon alarm properties
Object object
Type absolute
 Set rmon alarm status
 Enable
Clear rmon alarm
This example shows how to enable Rmon alarm entry
Use this command to delete an Rmon alarm entry
 Use this command to display Rmon event entry properties
Event Group Commands
This example shows how to display Rmon event entry
Show rmon event
 Description
Set rmon event properties
Type none log
Trap both
 Set rmon event status
This example shows how to enable Rmon event entry
Clear rmon event
 This example shows how to clear Rmon event
 Show rmon channel
Filter Group Commands
 Set rmon channel
Use this command to configure an Rmon channel entry
Accept matched
Failed
 Show rmon filter
Clear rmon channel
Index index
Channel channel
 Set rmon filter
 This example shows how to clear Rmon filter entry
Use this command to clear an Rmon filter entry
Clear rmon filter
 Show rmon capture
Packet Capture Commands
Nodata
 Action lock
Set rmon capture
Slice slice
Loadsize loadsize
 This example shows how to clear Rmon capture entry
Use this command to clears an Rmon capture entry
Clear rmon capture
 Dhcp Overview
Dhcp Server Configuration
Dhcp Relay Agent
Dhcp Server
 Configuring a Dhcp Server
 Configuring General Dhcp Server Parameters
 This example enables Dhcp server functionality
Set dhcp bootp
Set dhcp
 This example enables Dhcp conflict logging
This example enables address allocation for Bootp clients
Set dhcp conflict logging
Show dhcp conflict
 This example disables Dhcp conflict logging
Logging Disables conflict logging
Clear dhcp conflict
Clears the conflict information for all IP addresses
 Set dhcp exclude
100, with the set dhcp exclude command
Clear dhcp exclude
 Clear dhcp ping
Set dhcp ping
This example sets the number of ping packets sent to
 Clear dhcp binding
Show dhcp binding
 Use this command to clear all Dhcp server counters
Use this command to display Dhcp server statistics
Show dhcp server statistics
Clear dhcp server statistics
 This example clears all Dhcp server counters
 Manual Pool Configuration Considerations
Configuring IP Address Pools
 This example creates an address pool named auto1
Set dhcp pool
 Clear dhcp pool
Use this command to delete a Dhcp server pool of addresses
Set dhcp pool network
This example deletes the address pool named auto1
 Set dhcp pool hardware-address
Clear dhcp pool network
 Set dhcp pool host
Clear dhcp pool hardware-address
If no type is specified, Ethernet is assumed
 Set dhcp pool client-identifier
Clear dhcp pool host
 Clear dhcp pool client-identifier
 Clear dhcp pool client-name
Set dhcp pool client-name
 Clear dhcp pool bootfile
Set dhcp pool bootfile
 Clear dhcp pool next-server
Set dhcp pool next-server
 Clear dhcp pool lease
Set dhcp pool lease
Infinite
 Clear dhcp pool default-router
Set dhcp pool default-router
 Clear dhcp pool dns-server
Set dhcp pool dns-server
 Clear dhcp pool domain-name
Set dhcp pool domain-name
 Clear dhcp pool netbios-name-server
Set dhcp pool netbios-name-server
 Clear dhcp pool netbios-node-type
Set dhcp pool netbios-node-type
‐node
 Ascii string
Set dhcp pool option
 Clear dhcp pool option
Show dhcp pool configuration
This example removes option 19 from address pool auto1
 Show dhcp pool configuration
 Dhcp Snooping Overview
Dhcp Snooping Dynamic ARP Inspection
Dhcp Message Processing
 Building and Maintaining the Database
 Configuration Notes
Basic Configuration
Procedure 17-1 Basic Configuration for Dhcp Snooping
Rate Limiting
 Disabled globally
Dhcp Snooping Commands
Set dhcpsnooping
 Set dhcpsnooping vlan
Set dhcpsnooping database write-delay
 Set dhcpsnooping trust
By default, ports are untrusted
 Set dhcpsnooping binding
This example configures port ge.1.1 as a trusted port
Set dhcpsnooping verify
 Set dhcpsnooping log-invalid
Source MAC address verification is enabled by default
Against the client hardware address
 None
Set dhcpsnooping limit
Rate pps
Burst interval secs
 This example configures rate limit parameters on port ge.1.1
 Show dhcpsnooping port
Show dhcpsnooping database
 Dynamic static
Show dhcpsnooping binding
Entry, either dynamic or static
 Show dhcpsnooping statistics
 Clear dhcpsnooping statistics
Clear dhcpsnooping binding
Clear dhcpsnooping database
 Default value of 300 seconds
Write‐delay
Clear dhcpsnooping limit
Dynamic ARP Inspection Overview
 Static Mappings
Functional Description
Optional ARP Packet Validation
 Packet Forwarding
Logging Invalid Packets
Rate Limiting
Eligible Interfaces
 Step Task Commands
Procedure 17-2 Basic Dynamic ARP Inspection Configuration
 Router Configuration
Example Configuration
Vlan Configuration
 Set arpinspection vlan
Dynamic ARP Inspection Commands
Dhcp Snooping Configuration
Dynamic ARP Inspection Configuration
 Logging is disabled by default
Set arpinspection trust
By default, all physical ports and LAGs are untrusted
Logging
 Src‐mac
Set arpinspection validate
Dst‐mac
 Set arpinspection limit
 Show arpinspection access-list
Set arpinspection filter
Permit
Mac host
 This example displays the ARP configuration of lag.0.1
Show arpinspection ports
 Show arpinspection statistics
Show arpinspection vlan
 With an invalid address
Clear arpinspection validate
This example removes all 3 additional validation conditions
 Clear arpinspection vlan
 Clear arpinspection filter
 This example removes the ARP ACL named staticARP from Vlan
Clear arpinspection limit
 This example clears all DAI statistics from the switch
Clear arpinspection statistics
Page
 Pre-Routing Configuration Tasks
Preparing for Router Mode
 Enabling the Switch for Routing
Enabling Router Configuration Modes
Router CLI Configuration Modes
 Router CLI Configuration Modes
Page
 Configuring Routing Interface Settings
IP Configuration
 Vlan vlan ‐id
Show interface
 Router global configuration mode C3su‐routerConfig#
Use this command to configure interfaces for IP routing
Interface
Vlan vlan‐ id
 Show ip interface
This example shows how to enter configuration mode for Vlan
 Ip address
Router interface configuration C3su‐routerConfig‐ifVlan 1#
Show ip interface Output Details
Secondary
 No shutdown
Show running-config
 No ip routing
This example shows how to enable Vlan 1 for IP routing
 Use this command to configure a tunnel interface
Configuring Tunnel Interfaces
Interface tunnel
 Router interface configuration C3su‐routerConfig‐ifTnnl 1#
This example creates a configured tunnel interface
Tunnel source
 This command specifies the mode of the tunnel interface
Tunnel mode
Ipv6ip Specifies that the tunnel mode is IPv6 over IPv4
No form of this command removes the mode of the tunnel
 Show interface tunnel
This example sets the tunnel mode to IPv6 over IPv4
 Show ip arp
Reviewing and Configuring the ARP Table
 Arp
This example shows how to use the show ip arp command
Show ip arp Output Details
 Ip proxy-arp
This example shows how to enable proxy ARP on Vlan
 Clear arp-cache
Arp timeout
14,400 seconds
Privileged Exec C3su‐router#
 Interface configuration C3su‐Router1Config‐ifVlan 1#
Configuring Broadcast Settings
Ip directed-broadcast
 Udp
Ip forward-protocol
Specifies UDP as the IP forwarding protocol
Are forwarded
 Ip helper-address
 Show ip route
Reviewing IP Traffic and Configuring Routes
 OSPF, IA
 Ping
Ip route
Preference in route selection
 There is also a traceroute command available in switch mode
This command is also available in switch mode
Traceroute
 Ip icmp redirect enable
Configuring Icmp Redirects
 Interface
Show ip icmp redirect
 Activating Advanced Routing Features
IPv4 Routing Protocol Configuration
 RIP Configuration Task List and Commands
Configuring RIP
RIP Configuration Task List and Commands
Router rip
 This example shows how to enable RIP
Ip rip enable
Distance
 R1compatible
Ip rip send version
 Specifies RIP version 1. This is the default setting
Ip rip authentication-key
Ip rip receive version
Specifies RIP version
 Md5
Ip rip message-digest-key
 Router configuration C3su‐routerConfig‐router#
Use this command to disable automatic route summarization
No auto-summary
Split-horizon poison
 Passive-interface
 Redistribute
Receive-interface
Connected
Ospf
 Protocol
Command detailed in ip route on page 19‐21
Subnets
Subnetted will be redistributed
 Ospf Configuration Task List and Commands
Configuring Ospf
Ospf Configuration Task List and Commands
Advanced License Required
 Routes
Router id
 Router ospf
This example shows how to enable routing for Ospf process
1583compatibility
 This example shows how to enable RFC 1583 compatibility
Ip ospf enable
Ip ospf areaid
 Ip ospf priority
Ip ospf cost
 Timers spf
 Ip ospf retransmit-interval
Ip ospf transmit-delay
 Ip ospf dead-interval
Ip ospf hello-interval
65535
 Ip ospf authentication-key
 Distance ospf
Ip ospf message digest key md5
 External inter‐
Area range
Area intra‐area
Intra‐area routes
 Area stub
If not specified, advertise mode will be set
Advertise no‐
Advertise
 Area nssa
Area default cost
 This example shows how to configure area 10 as an Nssa area
Default‐
Area virtual-link
Information‐
 Transmit‐delay
Authentication‐
Key key
Dead‐interval
 Rip
Show ip ospf
Metric‐type type
 Use this command to display the Ospf link state database
This example shows how to display Ospf information
Show ip ospf database
 Show ip ospf database Output Details
Show ip ospf interface
 Show ip ospf interface Output Details
 Show ip ospf neighbor Output Details
Show ip ospf neighbor
 Clear ip ospf process
Show ip ospf virtual-links
Show ip ospf virtual links Output Details
 This example shows how to reset Ospf process
 Enabling Dvmrp on an Interface
Configuring Dvmrp
 Commands to Enable Dvmrp on an Interface
Ip dvmrp enable
This example shows how to enable the Dvmrp process
Ip dvmrp
 Ip dvmrp metric
Use this command to display Dvmrp routing information
Show ip dvmrp
 This example shows how to display Dvmrp status information
 Ip irdp enable
Configuring Irdp
 Ip irdp minadvertinterval
Ip irdp maxadvertinterval
 Ip irdp preference
Ip irdp holdtime
9000
 Ip irdp broadcast
Use this command to display Irdp information
Show ip irdp
 Configuration Tasks on page 18‐1
 Router vrrp
Configuring Vrrp
 Create
This example shows how enable Vrrp configuration mode
 Address
 Advertise-interval
Priority
 Preempt
Described in Pre‐Routing Configuration Tasks on page 18‐1
 Enable
 Use this command to display Vrrp routing information
Ip vrrp authentication-key
This example shows how to display Vrrp information
Show ip vrrp
 Design Considerations
Configuring PIM-SM
 This example shows how to globally enable and disable PIM
Global router configuration C3su‐routerConfig#
Ip pimsm
Ip pimsm staticrp
 Ip pimsm enable
 Ip pimsm query-interval
This example shows how to display PIM information
Show ip pimsm
 Show ip pimsm componenttable
This example shows how to display PIM router information
Show ip pimsm Output Details
 Show ip pimsm interface
This example shows how to display PIM interface information
Show ip pimsm componenettable Output Details
Stats
 Show ip pimsm neighbor
This example shows how to display PIM interface statistics
Show ip pimsm interface vlan Output Details
10 show ip pimsm interface stats Output Details
 Show ip pimsm rp
‐11 provides an explanation of the command output
11 show ip pimsm neighbor Output Details
Candidate
 Show ip pimsm rphash
‐12 provides an explanation of the command output
12 show ip pimsm rp Output Details
 Show ip pimsm staticrp
‐13 provides an explanation of the command output
Display the PIM‐SM static Rendezvous Point information
 Show ip mroute
Use this command to display the IP multicast routing table
13 show ip pimsm staticrp Output Details
 20-60 IPv4 Routing Protocol Configuration
 Show ipv6 status
IPv6 Management
 This example shows how to enable IPv6 management
By default, IPv6 management is disabled
Set ipv6
 Set ipv6 address
No global unicast IPv6 address is defined by default
Eui64
 Show ipv6 address
Use this command to clear IPv6 global addresses
Clear ipv6 address
 Set ipv6 gateway
 Clear ipv6 gateway
Use this command to clear an IPv6 gateway address
Show ipv6 neighbors
 Use this command to display IPv6 netstat information
This example shows example output of this command
Show ipv6 netstat
 Ping ipv6
This command is also available in router mode
Size num
 Traceroute ipv6
 Traceroute ipv6 21-10 IPv6 Management
 Overview
IPv6 Configuration
IPv6 Routing License Required
 Following table lists the default IPv6 conditions
Default Conditions
 Ipv6 forwarding
General Configuration Commands
Ipv6 hop-limit
 This command configures static IPv6 routes
Default maximum number of IPv6 hops is
Ipv6 route
This example sets the hop limit to
 Ipv6 route distance
Default preference or administrative distance is
 Ipv6 unicast-routing
This command sets the default distance value to
 Link‐local‐address
Ping ipv6 interface
 Router privileged exec C3 su‐router#
 20010db8123455551
 Ipv6 address
Interface Configuration Commands
No IPv6 addresses are defined for any interface
 IPv6 is disabled
Ipv6 enable
 Bytes
Ipv6 mtu
 This example sets the MTU value to 1500 bytes
 Clear ipv6 neighbors
Neighbor Cache and Neighbor Discovery Commands
This example clears all dynamically learned cache entries
 Ipv6 nd dad attempts
Duplicate address detection enabled, for 1 attempt
Ipv6 nd ns-interval
 Router interface configurationC3su‐routerConfig‐ifVlan 1#
By default, a value of 0 is advertised in RA messages
Ipv6 nd reachable-time
This example sets the NS interval to 2 seconds
 Flag is set to false by default
Ipv6 nd other-config-flag
Router interface configuration C3su‐routerConfig‐if Vlan 1#
This example sets the reachable time to 60 seconds
 Ipv6 nd ra-lifetime
Ipv6 nd ra-interval
 This example disables router advertisement transmission
Suppression disabled
Ipv6 nd suppress-ra
Ipv6 nd prefix
 Router interface configurationC3su‐routerConfig‐if Vlan 1#
No‐autoconfig
Off‐link
 Example
 Show ipv6
Query Commands
Show ipv6 interface
Router privileged execution C3su‐router#
 This example displays information about IPv6 interface Vlan
 This example displays the neighbors in the cache
This command displays IPv6 Neighbor Cache information
 Show ipv6 route
This command displays the IPv6 routing table
Show ipv6 neighbor Output Details
Interface interface
 Show ipv6 route Output Details
This example displays all active IPv6 routes
 Show ipv6 route preferences Output Details
Show ipv6 route preferences
 Show ipv6 route summary
This command displays the summary of the routing table
Non‐best routes
 Show ipv6 traffic
Following example displays the output of this command
Show ipv6 summary Output Details
 Show ipv6 traffic Output Details
 Options, etc
 Counter would include datagrams counted
 Send. Note that this counter includes all those counted by
 Router privileged executionC3su‐router#
Clear ipv6 statistics
This example clears the statistics for Vlan
 IPv6 Proxy Routing
 Limitations
Preparing a Mixed Stack for IPv6 Proxy Routing
 Router global configuration C2su‐routerConfig#
IPv6 proxy routing is disabled by default
This example enables IPv6 proxy routing
Ipv6 proxy-routing
 Any routing mode
 DHCPv6 Configuration
 Ipv6 dhcp enable
Global Configuration Commands
Following table lists the default DHCPv6 conditions
This command enables DHCPv6 on the router
 This example enables DHCPv6
By default, DHCPv6 is disabled
Ipv6 dhcp relay-agent-info-opt
 Ipv6 dhcp pool
Ipv6 dhcp relay-agent-info-remote-id-subopt
 Ipv6 dhcp pool
 Domain-name
Address Pool Configuration Commands
 Prefix-delegation
Dns-server
 Preferred‐lifetime
Valid‐lifetime secs
Secs infinite
 C3su-routerConfig-dhcp6s-pool# exit C3su-routerConfig#
 Ipv6 dhcp server
By default, DHCPv6 functionality is disabled
Rapid‐commit
Preference pref
 Destination dest‐addr
Ipv6 dhcp relay
Interface intf
Remote‐id duid‐ifid
 Examples
 Show ipv6 dhcp
DHCPv6 Show Commands
 Statistics
Show ipv6 dhcp interface
 This example displays the DHCPv6 statistics for Vlan
Output of show ipv6 dhcp interface Command
 Output of show ipv6 dhcp statistics Command
This example displays the output of this command
Show ipv6 dhcp statistics
 This example clears DHCPv6 statistics for Vlan
Clear ipv6 dhcp statistics
 Show ipv6 dhcp pool
This command displays information about DHCPv6 bindings
Show ipv6 dhcp binding
 If no IPv6 address is specified, all bindings are displayed
 Show ipv6 dhcp binding DHCPv6 Configuration
 OSPFv3 Configuration
 Following table lists the default OSPFv3 conditions
 Use this command to configure the OSPFv3 router ID
Global OSPFv3 Configuration Commands
Ipv6 router id
 Ipv6 router ospf
Default-information originate
Always
Metric value
 Router OSPFv3 configuration C3su‐routerConfig‐router#
Default-metric
No default metric is configured
Router OSPFv3 configuration C3su-routerConfig-router#
 Intra
Exit-overflow-interval
Inter
Type1
 Default value is ‐1
This command configures the external Lsdb limit for OSPFv3
External-lsdb-limit
This example sets the exit overflow interval to 10 seconds
 Connected static
Maximum-paths
Tag tag
 Metric = unspecified Metric type = Type Tag =
 Area default-cost
Area Configuration Commands
These commands are used to configure area parameters
 This example shows how to configure area 20 as an Nssa
This example sets the default route cost to 50 for area
 Default metric value is
Area nssa default-info-originate
Area nssa no-redistribute
Comparable
 Area nssa no-summary
 By default, the translator role is disabled
This command configures the translator role of the router
Area nssa translator role
Area nssa translator-stab-intv
 Area address ranges are not configured by default
Default interval is 40 seconds
Summarylink
Nssaexternallink
 This command creates a stub area for the specified area ID
 Area stub no-summary
Example disables the import of summary LSAs into stub area
This example creates a stub area with the ID
 Area virtual-link dead-interval
Default dead interval is 40 seconds
 Area virtual-link hello-interval
Default hello interval is 10 seconds
Area virtual-link retransmit-interval
 Default retransmit interval is 5 seconds
Area virtual-link transmit-delay
Default transmit delay is 1 second
 OSPFv3 is disabled by default
Ipv6 ospf enable
 Ipv6 ospf cost
Ipv6 ospf areaid
 Ipv6 ospf dead-interval
Default dead interval value is 40 seconds
 Ipv6 ospf mtu-ignore
Ipv6 ospf hello-interval
 Default network type is broadcast
By default, MTU mismatch detection is enabled
Ipv6 ospf network
 Ipv6 ospf priority
Default priority value is
Ipv6 ospf retransmit-interval
 Default value is 4 seconds
Ipv6 ospf transmit-delay
Default value is 1 second
 Ipv6 ospf transmit-delay
 This command displays OSPFv3 router information
OSPFv3 Show Commands
This example shows how to display OSPFv3 router information
Show ipv6 ospf
 Show ipv6 ospf Output Details
 Show ipv6 ospf area Output Details
Show ipv6 ospf area
 Show ipv6 ospf abr Output Details
Show ipv6 ospf abr
 Show ipv6 ospf asbr Output Details
Show ipv6 ospf asbr
 Show ipv6 ospf database
 Adv Router Link Id Age Sequence Csum Options Rtr Opt
 Show ipv6 ospf database Output Details
 Show ipv6 ospf database database-summary Output Details
 Show ipv6 ospf interface
This command displays information about OSPFv3 interfaces
Loopback loopid
 Show ipv6 ospf interface Command Output Details
 Show ipv6 ospf interface stats
This example shows how to display statistics for Vlan
 Show ipv6 ospf interface stats Output Details
 Show ipv6 ospf neighbor
This command displays information about OSPFv3 neighbors
Specify the Vlan interface to display information about
Specify the tunnel interface to display
 Show ipv6 ospf neighbor Output Details
 10 show ipv6 ospf neighbor routerid Output Details
Show ipv6 ospf range
This example displays range information for area
 11 show ipv6 ospf range Output Details
Show ipv6 ospf stub table
This example displays the OSPFv3 stub table information
12 show ipv6 ospf stub table Output Details
 13 show ipv6 ospf virtual-link Output Details
Show ipv6 ospf virtual-link
 Show ipv6 ospf virtual-link
 Show ipv6 ospf virtual-link OSPFv3 Configuration
 Overview of Authentication and Authorization Methods
Authentication and Authorization Configuration
 Overview of Authentication and Authorization Methods
 Filter-ID Attribute Formats
 Show authentication login
Setting the Authentication Login Method
Set authentication login
Use this command to set the authentication login method
 Any
Clear authentication login
Local
Radius
 Timeout
Configuring Radius
Show radius
Retries
 Set radius
Optional Displays Radius server configuration information
Server
Servers or a specific Radius server as defined by an index
 Realm management‐ access any network‐access
Timeout timeout
Server index
 Realm
Clear radius
 Set radius accounting
Show radius accounting
Retries retries
 Timeout
This example shows how to set Radius accounting retries to
Clear radius accounting
Retries
 Set radius interface
Show radius interface
 Clear radius interface
 Example
 Show dot1x
Configuring 802.1X Authentication
Auth‐diag
Auth‐stats
 This example shows how to display 802.1X status
 Show dot1x auth-config
 Init reauth
Set dot1x
True false
 Set dot1x auth-config
 Portcontrol Maxreq
Clear dot1x auth-config
 Show eapol
 Show eapol Output Details
Connecting state, via disconnected
 Clear eapol
Set eapol
Auth‐mode
Forced‐auth
 Optional Globally clears the Eapol authentication mode
 Show macauthentication
Configuring MAC Authentication
 Nopassword
Show macauthentication Output Details
 This example shows how to display MAC session information
Show macauthentication session
Show macauthentication session Output Details
 Set macauthentication password
Set macauthentication
Use this command to set a MAC authentication password
 Set macauthentication port
Clear macauthentication password
Use this command to clear the MAC authentication password
Enables or disables MAC authentication
 Set macauthentication portquietperiod
Set macauthentication portinitialize
 Set macauthentication macinitialize
Clear macauthentication portquietperiod
This example resets the default quiet period on port
 Set macauthentication portreauthenticate
Set macauthentication reauthentication
Enables or disables MAC reauthentication
 Set macauthentication reauthperiod
Set macauthentication macreauthenticate
 Clear macauthentication reauthperiod
 Clear macauthentication significant-bits
Set macauthentication significant-bits
 C3su-clear macauthentication significant-bits
 About Multiple Authentication Types
Configuring Multiple Authentication Methods
About Multi-User Authentication
 Show multiauth
 Clear multiauth mode
Set multiauth mode
Multi
Strict
 Set multiauth precedence
Default precedence order is dot1x, pwa, mac
Clear multiauth precedence
 Set multiauth port
Show multiauth port
 Clear multiauth port
 Show multiauth session
Show multiauth station
 Agent dot1x mac
Show multiauth idle-timeout
 Authentication method for which to set the timeout value
Set multiauth idle-timeout
Which to set the timeout value
Idle timeout value is provided by the authenticating server
 Show multiauth session-timeout
Clear multiauth idle-timeout
Default
Which to reset the timeout value to its default
 Which to set the session timeout value
Set multiauth session-timeout
 Configuring User + IP Phone Authentication
Clear multiauth session-timeout
 Configuring Vlan Authorization RFC
 Set vlanauthorization egress
Set vlanauthorization
Tagged
 Show vlanauthorization
Clear vlanauthorization
By default, administrative egress is set to untagged
 Show vlanauthorization Output Details
Configuring Policy Maptable Response
 Operational Description
When Policy Maptable Response is Both
 When Policy Maptable Response is Tunnel
When Policy Maptable Response is Policy
Show policy maptable
 Response
Set policy maptable
Both
Policy
 Clear policy maptable
 To review, disable, enable, and configure MAC locking
Configuring MAC Locking
 Show maclock
 Show maclock Output Details
Show maclock stations
Firstarrival
Connected to MAC locked ports
 Set maclock enable port‐string
Set maclock enable
Show maclock stations Output Details
 This example shows how to enable MAC locking on ge.2.3
Set maclock disable
This example shows how to disable MAC locking on ge.2.3
Set maclock
 Create
Clear maclock
Specified MAC address and port
 Clear maclock static
Set maclock static
 Set maclock firstarrival
 Set maclock agefirstarrival
Clear maclock firstarrival
 This example disables first arrival aging on port ge.1.1
This example enables first arrival aging on port ge.1.1
Clear maclock agefirstarrival
Set maclock move
 Set maclock trap
 About PWA
Configuring Port Web Authentication PWA
 Show pwa Output Details
Show pwa
 This example shows how to enable port web authentication
Enable disable Enables or disables port web authentication
Set pwa
 Show pwa banner
This example shows how to display the PWA login banner
Set pwa banner
 Clear pwa banner
This example shows how to hide the Enterasys Networks logo
Set pwa displaylogo
Display hide
 Set pwa protocol
Set pwa ipaddress
Chap pap
 This example shows how to clear the PWA guest user name
Use this command to clear the PWA guest user name
Set pwa guestname
Clear pwa guestname
 Set pwa gueststatus
Set pwa guestpassword
Authnone
Authradius
 Set pwa initialize
This example shows how to initialize ports ge.1.5‐7
Set pwa quietperiod
 Set pwa portcontrol
Set pwa maxrequest
 This example shows how to enable PWA on ports 1‐22
Enables or disables PWA on specified ports
This example shows how to display PWA session information
Show pwa session
 This example shows how to enable PWA enhancedmode
Enable disable Enables or disables PWA enhancedmode
Set pwa enhancedmode
 This example shows how to display SSH status on the switch
Configuring Secure Shell SSH
Show ssh status
Set ssh
 This example shows how to regenerate SSH keys
This example shows how to disable SSH
Set ssh hostkey
 Show access-lists
Configuring Access Lists
Show access‐lists number
 Deny permit
Access-list standard
 Insert replace
Access-list extended
This example moves entry 16 to the beginning of ACL
 Insert replace
 Interface configuration C3su‐routerConfig‐ifVlan vlanid#
Ip access-group
Filters inbound frames
 Example
Page
 TACACS+ Configuration
 State Optional Displays only the TACACS+ client status
Show tacacs
Show tacacs Output Details
 Enable disable Enables or disables the Tacacs client
Use this command to enable or disable the TACACS+ client
This example shows how to enable the TACACS+ client
Set tacacs
 Set tacacs server
Timeout seconds
 Specifies one TACACS+ server to be affected
Clear tacacs server
 This example removes TACACS+ server
Show tacacs session
 Set tacacs session
 Clear tacacs session
Service
Read‐write
Super‐user
 Set tacacs command
Show tacacs command
 Set tacacs singleconnect
Show tacacs singleconnect
Connection
 Set tacacs interface
Show tacacs interface
 Clear tacacs interface
 Clear tacacs interface TACACS+ Configuration
 27-14
 Using sFlow in Your Network
SFlow Configuration
Advantages of using sFlow include
 SFlow Agent Functionality
Definitions
Sampling Mechanisms
SFlow Definitions
 Counter Sampling
Packet Flow Sampling
Usage Notes
 28-5
 Show sflow receivers
Contents of the sFlow Receivers Table is displayed
This example displays the sFlow Receivers Table
 Show sflow receivers Output Descriptions
Following table describes the output fields
 Set sflow receiver ip
Set sflow receiver owner
 Default maximum datagram size is 1400 bytes
Default IP address is
Set sflow receiver maxdatagram
Maxdatagram bytes
 Set sflow receiver port
Default port value is
Clear sflow receiver
Maxdatagram
 Owner
Set sflow port poller
Port port
 Show sflow pollers
 Set sflow port sampler
Clear sflow port poller
Interval
This example removes the poller instance on port ge.1.1
 Show sflow samplers
 Set sflow interface
Clear sflow port sampler
Maxheadersize
Rate
 Show sflow interface
 Clear sflow interface
 Show sflow agent
 28-18
 Policy Capacities
Policy and Authentication Capacities
Table A-1 Policy Capacities
 Table A-2 Authentication Capacities
Authentication Capacities
 Numerics
Index
 Ospf 20-30Network Management
 Tftp
 Index