aaa accounting dot1x command 2-1

aaa authentication dot1x command 2-3

aaa authorization network command 2-5

AAA methods 2-3

abort command 2-596

access control entries

See ACEs

access control lists

See ACLs

access groups

IP 2-118

MAC, displaying 2-388

access mode 2-549

access ports 2-549

ACEs 2-67, 2-259


deny 2-65

displaying 2-295

for non-IP protocols 2-180

IP 2-118

on Layer 2 interfaces 2-118

permit 2-257

address aliasing 2-248

aggregate-port learner 2-253

allowed VLANs 2-564

apply command 2-596

archive download-sw command 2-6

archive tar command 2-8

archive upload-sw command 2-11

audience xvii

authentication failed VLAN

See dot1x auth-fail vlan

auth-fail max-attempts

See dot1x auth-fail max-attempts

auth-fail vlan

See dot1x auth-fail vlan

authorization state of controlled port 2-91

autonegotiation of duplex mode 2-99

auto qos voip command 2-13


BackboneFast, for STP 2-484

backup interfaces

configuring 2-543

displaying 2-350

boot (boot loader) command A-2

boot boothlpr command 2-17

boot config-file command 2-18

boot enable-break command 2-19

boot helper command 2-20

boot helper-config file command 2-21


Cisco IOS image 2-24

displaying environment variables 2-303

interrupting 2-19

manually 2-22

boot loader

accessing A-1


Cisco IOS image A-2

helper image 2-20


creating A-14

displaying a list of A-7

removing A-18


available commands A-12

memory heap utilization A-13

version A-25

environment variables

described A-19

displaying settings A-19

location of A-20

setting A-19

unsetting A-23


copying A-5

deleting A-6

displaying a list of A-7

displaying the contents of A-4, A-15, A-22

renaming A-16

file system

formatting A-10

initializing flash A-9

running a consistency check A-11

prompt A-1

resetting the system A-17

boot manual command 2-22

boot private-config-file command 2-23

boot system command 2-24

BPDU filtering, for spanning tree 2-485, 2-520

BPDU guard, for spanning tree 2-487, 2-520

broadcast storm control 2-538


candidate switches

See clusters

cat (boot loader) command A-4

caution, description xviii

channel-group command 2-25

channel-protocol command 2-28

Cisco Network Assistant

See Network Assistant xviii

Cisco SoftPhone

auto-QoS configuration 2-13

trusting packets sent from 2-240

class command 2-30

class-map command 2-32

class maps

creating 2-32

defining the match criteria 2-200

displaying 2-307

class of service

See CoS

clear dot1x command 2-34

clear eap sessions command 2-35

clear errdisable interface 2-36

clear ip dhcp snooping database command 2-37

clear lacp command 2-39

clear mac address-table command 2-40, 2-42

clear pagp command 2-43

clear port-security command 2-44

clear spanning-tree counters command 2-46

clear spanning-tree detected-protocols command 2-47

clear vmps statistics command 2-48

clear vtp counters command 2-49

cluster commander-address command 2-50

cluster discovery hop-count command 2-52

cluster enable command 2-53

cluster holdtime command 2-54

cluster member command 2-55

cluster outside-interface command 2-57

cluster requirements xviii

cluster run command 2-58


adding candidates 2-55

binding to HSRP group 2-59

building manually 2-55

communicating with

devices outside the cluster 2-57

members by using Telnet 2-275

debug messages, display B-5


candidate switches 2-310

debug messages B-5

member switches 2-312

status 2-308

hop-count limit for extended discovery 2-52

HSRP standby groups 2-59

redundancy 2-59

SNMP trap 2-474

cluster standby-group command 2-59

cluster timer command 2-61

command modes defined 1-1

command switch

See clusters

configuration, initial

See getting started guide and hardware installation guide

configuration files

password recovery disable considerations A-1

specifying the name 2-18, 2-23

configuring multiple interfaces 2-114

config-vlan mode

commands 2-585

description 1-4

entering 2-584

summary 1-2


command xvii

for examples xviii

publication xvii

text xvii

copy (boot loader) command A-5


assigning default value to incoming packets 2-210

overriding the incoming value 2-210

CoS-to-DSCP map 2-214

CPU ASIC statistics, displaying 2-314

crashinfo files 2-107


debug auto qos command B-2

debug backup command B-4

debug cluster command B-5

debug dot1x command B-7

debug dtp command B-8

debug eap command B-9

debug etherchannel command B-10

debug interface command B-11

debug ip dhcp snooping command B-12

debug ip igmp filter command B-13

debug ip igmp max-groups command B-14

debug ip igmp snooping command B-15

debug lacp command B-16

debug mac-notification command B-17

debug matm command B-18

debug matm move update command B-19

debug monitor command B-20

debug mvrdbg command B-21

debug nvram command B-22

debug pagp command B-23

debug platform acl command B-24

debug platform backup interface command B-25

debug platform cpu-queues command B-26

debug platform dot1x command B-28

debug platform etherchannel command B-29

debug platform forw-tcam command B-30

debug platform ip dhcp command B-31

debug platform ip igmp snooping command B-32

debug platform led command B-34

debug platform matm command B-35

debug platform messaging application command B-36

debug platform phy command B-37

debug platform pm command B-39

debug platform port-asic command B-41

debug platform port-security command B-42

debug platform qos-acl-tcam command B-43

debug platform resource-manager command B-44

debug platform snmp command B-45

debug platform span command B-46

debug platform supervisor-asic command B-47

debug platform sw-bridge command B-48

debug platform tcam command B-49

debug platform udld command B-51

debug platform vlan command B-52

debug pm command B-53

debug port-security command B-55

debug qos-manager command B-56

debug spanning-tree backbonefast command B-59

debug spanning-tree bpdu command B-60

debug spanning-tree bpdu-opt command B-61

debug spanning-tree command B-57

debug spanning-tree mstp command B-62

debug spanning-tree switch command B-64

debug spanning-tree uplinkfast command B-66

debug sw-vlan command B-67

debug sw-vlan ifs command B-69

debug sw-vlan notification command B-71

debug sw-vlan vtp command B-72

debug udld command B-74

debug vqpc command B-76

define interface-range command 2-62

delete (boot loader) command A-6

delete command 2-64

deny command 2-65

detect mechanism, causes 2-100

device manager requirements xviii

DHCP snooping

accepting untrusted packets from edge switch 2-133


on a VLAN 2-139

option 82 2-131, 2-133

trust on an interface 2-137

error recovery timer 2-105

rate limiting 2-135

DHCP snooping binding database

binding file, configuring 2-129


adding 2-127

deleting 2-127

displaying 2-362

clearing database agent statistics 2-37

database agent, configuring 2-129


binding entries 2-362

database agent status 2-364, 2-366

renewing 2-279

dir (boot loader) command A-7

directories, deleting 2-64

documentation, related xviii

document conventions xvii

domain name, VTP 2-603, 2-607

dot1x auth-fail max-attempts 2-70

dot1x auth-fail vlan 2-72

dot1x command 2-68

dot1x control-direction command 2-74

dot1x critical global configuration command 2-76

dot1x critical interface configuration command 2-78

dot1x default command 2-80

dot1x fallback command 2-81

dot1x guest-vlan command 2-82

dot1x host-mode command 2-84

dot1x initialize command 2-85

dot1x mac-auth-bypass command 2-86

dot1x max-reauth-req command 2-88

dot1x max-req command 2-89

dot1x pae command 2-90

dot1x port-control command 2-91

dot1x re-authenticate command 2-93

dot1x reauthentication command 2-94

dot1x timeout command 2-95

DSCP-to-CoS map 2-214

DSCP-to-DSCP-mutation map 2-214

DTP 2-550

DTP flap

error detection for 2-100

error recovery timer 2-105

DTP negotiation 2-551

dual-purpose uplink ports

displaying configurable options 2-352

displaying the active media 2-357

selecting the type 2-204

duplex command 2-98

dynamic-access ports

configuring 2-541

restrictions 2-542

dynamic auto VLAN membership mode 2-549

dynamic desirable VLAN membership mode 2-549

Dynamic Host Configuration Protocol (DHCP)

See DHCP snooping

Dynamic Trunking Protocol



EAP-request/identity frame

maximum number to send 2-89

response time before retransmitting 2-95

environment variables, displaying 2-303

errdisable detect cause command 2-100

errdisable detect cause small-frame comand 2-102

errdisable recovery cause small-frame 2-104

errdisable recovery command 2-105

error conditions, displaying 2-339

error disable detection 2-100

error-disabled interfaces, displaying 2-350


assigning Ethernet interface to channel group 2-25

creating port-channel logical interface 2-112

debug EtherChannel/PAgP, display B-10

debug platform-specific events, display B-29

displaying 2-343

interface information, displaying 2-350


clearing channel-group information 2-39

debug messages, display B-16

displaying 2-379

modes 2-25

port priority for hot-standby ports 2-165

restricting a protocol 2-28

system priority 2-167

load-distribution methods 2-266


aggregate-port learner 2-253

clearing channel-group information 2-43

debug messages, display B-23

displaying 2-432

error detection for 2-100

error recovery timer 2-105

learn method 2-253

modes 2-25

physical-port learner 2-253

priority of interface for transmitted traffic 2-255

Ethernet controller, internal register display 2-316

Ethernet statistics, collecting 2-281

examples, conventions for xviii

exception crashinfo command 2-107

exit command 2-596

extended discovery of candidate switches 2-52

extended-range VLANs

and allowed VLAN list 2-564

and pruning-eligible list 2-564

configuring 2-584

extended system ID for STP 2-493


fallback profile command 2-108

fallback profiles, displaying 2-346

fan information, displaying 2-336

file name, VTP 2-603

files, deleting 2-64

flash_init (boot loader) command A-9

Flex Links

configuring 2-543

configuring preferred VLAN 2-545

displaying 2-350

flowcontrol command 2-110

format (boot loader) command A-10

forwarding results, display C-5

frame forwarding information, displaying C-5

fsck (boot loader) command A-11


global configuration mode 1-2, 1-3


hardware ACL statistics 2-295

help (boot loader) command A-12

hierarchical policy maps 2-265

hop-count limit for clusters 2-52

host connection, port configuration 2-548

Hot Standby Router Protocol



binding HSRP group to cluster 2-59

standby group 2-59


IEEE 802.1x

and switchport modes 2-550

violation error recovery 2-105

See also port-based authentication

IEEE 802.1X Port Based Authentication

enabling guest VLAN supplicant 2-71, 2-81, 2-109

IGMP filters

applying 2-140

debug messages, display B-13

IGMP groups, setting maximum 2-142

IGMP maximum groups, debugging B-14

IGMP profiles

creating 2-144

displaying 2-369

IGMP snooping

adding ports as a static member of a group 2-161

displaying 2-370, 2-375, 2-377

enabling 2-146

enabling the configurable-leave timer 2-148

enabling the Immediate-Leave feature 2-157

flooding query count 2-154

interface topology change notification behavior 2-156

multicast table 2-373

querier 2-150

query solicitation 2-154

report suppression 2-152

switch topology change notification behavior 2-154


See software images

Immediate-Leave feature, MVR 2-250

immediate-leave processing 2-157

initial configuration

See getting started guide and hardware installation guide

interface configuration mode 1-2, 1-4

interface port-channel command 2-112

interface range command 2-114

interface-range macros 2-62


assigning Ethernet interface to channel group 2-25

configuring 2-98

configuring multiple 2-114

creating port-channel logical 2-112

debug messages, display B-11

disabling 2-470

displaying the MAC address table 2-400

restarting 2-470

interface speed, configuring 2-530

interface vlan command 2-117

internal registers, displaying 2-316, 2-323

Internet Group Management Protocol


invalid GBIC

error detection for 2-100

error recovery timer 2-105

ip access-group command 2-118

ip address command 2-120

IP addresses, setting 2-120

ip admission command 2-122

ip admission name proxy http command 2-124

IP DHCP snooping

See DHCP snooping

ip dhcp snooping binding command 2-127

ip dhcp snooping command 2-126

ip dhcp snooping database command 2-129

ip dhcp snooping information option allow-untrusted command 2-133

ip dhcp snooping information option command 2-131

ip dhcp snooping limit rate command 2-135

ip dhcp snooping trust command 2-137

ip dhcp snooping verify command 2-138

ip dhcp snooping vlan command 2-139

ip igmp filter command 2-140

ip igmp max-groups command 2-142

ip igmp profile command 2-144

ip igmp snooping command 2-146

ip igmp snooping last-member-query-interval command 2-148

ip igmp snooping querier command 2-150

ip igmp snooping report-suppression command 2-152

ip igmp snooping tcn command 2-154

ip igmp snooping tcn flood command 2-156

ip igmp snooping vlan immediate-leave command 2-157

ip igmp snooping vlan mrouter command 2-159

ip igmp snooping vlan static command 2-161

IP multicast addresses 2-247

IP phones

auto-QoS configuration 2-13

trusting packets sent from 2-240

IP-precedence-to-DSCP map 2-214

IP source guard


dynamic binding entries only 2-362

ip ssh command 2-163


jumbo frames




See EtherChannel

lacp port-priority command 2-165

lacp system-priority command 2-167

Layer 2 traceroute

IP addresses 2-575

MAC addresses 2-572

line configuration mode 1-2, 1-5

Link Aggregation Control Protocol

See EtherChannel

link flap

error detection for 2-100

error recovery timer 2-105

link state group command 2-172

link state track command 2-174

load-distribution methods for EtherChannel 2-266

location (global configuration) command 2-168

location (interface configuration) command 2-170

logging event command 2-175

logging file command 2-176

logical interface 2-112

loopback error

detection for 2-100

recovery timer 2-105

loop guard, for spanning tree 2-495, 2-499


mac access-group command 2-178

MAC access-groups, displaying 2-388

MAC access list configuration mode 2-180

mac access-list extended command 2-180

MAC access lists 2-65

MAC addresses


aging time 2-394

all 2-392

dynamic 2-398

MAC address-table move updates 2-402

notification settings 2-404

number of addresses in a VLAN 2-396

per interface 2-400

per VLAN 2-408

static 2-406

static and dynamic entries 2-390


aging time 2-182

deleting 2-40

displaying 2-398

enabling MAC address notification 2-185

enabling MAC address-table move update 2-183


adding and removing 2-187

displaying 2-406

dropping on an interface 2-188

tables 2-392

MAC address notification, debugging B-17

mac address-table aging-time 2-178

mac address-table aging-time command 2-182

mac address-table move update command 2-183

mac address-table notification command 2-185

mac address-table static command 2-187

mac address-table static drop command 2-188

macro apply command 2-190

macro description command 2-193

macro global command 2-194

macro global description command 2-197

macro name command 2-198


adding a description 2-193

adding a global description 2-197

applying 2-194

creating 2-198

displaying 2-434

interface range 2-62, 2-114

specifying parameter values 2-194

tracing 2-194


audience xvii

purpose of xvii



defining 2-214

displaying 2-418

match (class-map configuration) command 2-200

maximum transmission unit


mdix auto command 2-202

media-type command 2-204

member switches

See clusters

memory (boot loader) command A-13

mkdir (boot loader) command A-14

mls qos aggregate-policer command 2-208

mls qos command 2-206

mls qos cos command 2-210

mls qos dscp-mutation command 2-212

mls qos map command 2-214

mls qos queue-set output buffers command 2-218

mls qos queue-set output threshold command 2-220

mls qos rewrite ip dscp command 2-222

mls qos srr-queue input bandwidth command 2-224

mls qos srr-queue input buffers command 2-226

mls qos-srr-queue input cos-map command 2-228

mls qos srr-queue input dscp-map command 2-230

mls qos srr-queue input priority-queue command 2-232

mls qos srr-queue input threshold command 2-234

mls qos-srr-queue output cos-map command 2-236

mls qos srr-queue output dscp-map command 2-238

mls qos trust command 2-240

mode, MVR 2-247

Mode button, and password recovery 2-284

modes, commands 1-1

monitor session command 2-242

more (boot loader) command A-15


displaying 2-446

interoperability 2-47

link type 2-497

MST region

aborting changes 2-503

applying changes 2-503

configuration name 2-503

configuration revision number 2-503

current or pending display 2-503

displaying 2-446

MST configuration mode 2-503

VLANs-to-instance mapping 2-503

path cost 2-505

protocol mode 2-501

restart protocol migration process 2-47

root port

loop guard 2-495

preventing from becoming designated 2-495

restricting which can be root 2-495

root guard 2-495

root switch

affects of extended system ID 2-493

hello-time 2-508, 2-516

interval between BDPU messages 2-509

interval between hello BPDU messages 2-508, 2-516

max-age 2-509

maximum hop count before discarding BPDU 2-510

port priority for selection of 2-512

primary or secondary 2-516

switch priority 2-515

state changes

blocking to forwarding state 2-522

enabling BPDU filtering 2-485, 2-520

enabling BPDU guard 2-487, 2-520

enabling Port Fast 2-520, 2-522

forward-delay time 2-507

length of listening and learning states 2-507

rapid transition to forwarding 2-497

shutting down Port Fast-enabled ports 2-520

state information display 2-445


configuring size 2-569

displaying global setting 2-453

multicast group address, MVR 2-250

multicast groups, MVR 2-248

multicast router learning method 2-159

multicast router ports, configuring 2-159

multicast storm control 2-538

multicast VLAN, MVR 2-248

multicast VLAN registration


Multiple Spanning Tree Protocol



and address aliasing 2-248

configuring 2-247

configuring interfaces 2-250

debug messages, display B-21

displaying 2-426

displaying interface information 2-428

members, displaying 2-430

mvr (global configuration) command 2-247

mvr (interface configuration) command 2-250

mvr vlan group command 2-251


native VLANs 2-564

Network Admission Control Software Configuration Guide 2-123, 2-125

Network Assistant requirements xviii

nonegotiate, speed 2-530

nonegotiating DTP messaging 2-551

non-IP protocols

denying 2-65

forwarding 2-257

non-IP traffic access lists 2-180

non-IP traffic forwarding

denying 2-65

permitting 2-257

normal-range VLANs 2-584, 2-589

note, description xviii

no vlan command 2-584, 2-593



See EtherChannel

pagp learn-method command 2-253

pagp port-priority command 2-255

password, VTP 2-603, 2-607

password-recovery mechanism, enabling and disabling 2-284

permit (MAC access-list configuration) command 2-257

per-VLAN spanning-tree plus


physical-port learner 2-253

PID, displaying 2-360

PIM-DVMRP, as multicast router learning method 2-159

police aggregate command 2-262

police command 2-260

policed-DSCP map 2-214

policy-map command 2-264

policy maps

applying to an interface 2-286, 2-290

creating 2-264

displaying 2-437

hierarchical 2-265


displaying 2-411

for a single class 2-260

for multiple classes 2-208, 2-262

policed-DSCP map 2-214

traffic classification

defining the class 2-30

defining trust states 2-577

setting DSCP or IP precedence values 2-288

Port Aggregation Protocol

See EtherChannel

port-based authentication

AAA method list 2-3

debug messages, display B-7

enabling IEEE 802.1x

globally 2-68

per interface 2-91

guest VLAN 2-82

host modes 2-84

IEEE 802.1x AAA accounting methods 2-1

initialize an interface 2-85

MAC authentication bypass 2-86

manual control of authorization state 2-91

PAE as authenticator 2-90

periodic re-authentication

enabling 2-94

time between attempts 2-95

quiet period between failed authentication exchanges 2-95

re-authenticating IEEE 802.1x-enabled ports 2-93

resetting configurable IEEE 802.1x parameters 2-80

switch-to-authentication server retransmission time 2-95

switch-to-client frame-retransmission number2-88to 2-89

switch-to-client retransmission time 2-95

port-channel load-balance command 2-266

Port Fast, for spanning tree 2-522

port ranges, defining 2-62

ports, debugging B-53

ports, protected 2-562

port security

aging 2-558

debug messages, display B-55

enabling 2-553

violation error recovery 2-105

port trust states for QoS 2-240

port types, MVR 2-250

power information, displaying 2-336

priority-queue command 2-268

privileged EXEC mode 1-2, 1-3

product identification information, displaying 2-360

protected ports, displaying 2-355


VLANs 2-564


displaying interface information 2-350

enabling 2-603, 2-607

pruning-eligible VLAN list 2-565






configuring 2-13

debug messages, display B-2

displaying 2-299

class maps

creating 2-32

defining the match criteria 2-200

displaying 2-307

defining the CoS value for an incoming packet 2-210

displaying configuration information 2-299, 2-410

DSCP transparency 2-222

DSCP trusted ports

applying DSCP-to-DSCP-mutation map to 2-212

defining DSCP-to-DSCP-mutation map 2-214

egress queues

allocating buffers 2-218

defining the CoS output queue threshold map 2-236

defining the DSCP output queue threshold map 2-238

displaying buffer allocations 2-414

displaying CoS output queue threshold map 2-418

displaying DSCP output queue threshold map 2-418

displaying queueing strategy 2-414

egress queues (continued)

displaying queue-set settings 2-421

enabling bandwidth shaping and scheduling 2-534

enabling bandwidth sharing and scheduling 2-536

limiting the maximum output on a port 2-532

mapping a port to a queue-set 2-270

mapping CoS values to a queue and threshold 2-236

mapping DSCP values to a queue and threshold 2-238

setting maximum and reserved memory allocations 2-220

setting WTD thresholds 2-220

enabling 2-206

ingress queues

allocating buffers 2-226

assigning SRR scheduling weights 2-224

defining the CoS input queue threshold map 2-228

defining the DSCP input queue threshold map 2-230

displaying buffer allocations 2-414

displaying CoS input queue threshold map 2-418

displaying DSCP input queue threshold map 2-418

displaying queueing strategy 2-414

displaying settings for 2-412

enabling the priority queue 2-232

mapping CoS values to a queue and threshold 2-228

mapping DSCP values to a queue and threshold 2-230

setting WTD thresholds 2-234


defining 2-214, 2-228, 2-230, 2-236, 2-238

displaying 2-418


policy maps

applying an aggregate policer 2-262

applying to an interface 2-286, 2-290

creating 2-264

defining policers 2-208, 2-260

displaying policers 2-411

displaying policy maps 2-437

hierarchical 2-265

policed-DSCP map 2-214

setting DSCP or IP precedence values 2-288

traffic classifications 2-30

trust states 2-577

port trust states 2-240

queues, enabling the expedite 2-268


in-profile and out-of-profile packets 2-414

packets enqueued or dropped 2-414

sent and received CoS values 2-414

sent and received DSCP values 2-414

trusted boundary for IP phones 2-240

quality of service

See QoS

querytime, MVR 2-247

queue-set command 2-270


radius-server dead-criteria command 2-273

radius-server host command 2-271

rapid per-VLAN spanning-tree plus


rapid PVST+


rcommand command 2-275

re-authenticating IEEE 802.1x-enabled ports 2-93


periodic 2-94

time between attempts 2-95

receiver ports, MVR 2-250

receiving flow-control packets 2-110

recovery mechanism

causes 2-105

display 2-36, 2-305, 2-337, 2-341

timer interval 2-105

redundancy for cluster switches 2-59

remote-span command 2-277

Remote Switched Port Analyzer


rename (boot loader) command A-16

renew ip dhcp snooping database command 2-279


cluster xviii

device manager xviii

Network Assistant xviii

reset (boot loader) command A-17

reset command 2-596

resource templates, displaying 2-442

restricted VLAN

See dot1x auth-fail vlan

rmdir (boot loader) command A-18

rmon collection stats command 2-281

root guard, for spanning tree 2-495


configuring 2-242

displaying 2-424

filter RSPAN traffic 2-242

remote-span command 2-277


displaying 2-424


sdm prefer command 2-282

SDM templates

displaying 2-442

secure ports, limitations 2-555

sending flow-control packets 2-110

service password-recovery command 2-284

service-policy command 2-286

set (boot loader) command A-19

set command 2-288

setup command 2-290

setup express command 2-293

show access-lists command 2-295

show archive status command 2-298

show auto qos command 2-299

show boot command 2-303

show cable-diagnostics tdr command 2-305

show changes command 2-596

show class-map command 2-307

show cluster candidates command 2-310

show cluster command 2-308

show cluster members command 2-312

show controllers cpu-interface command 2-314

show controllers ethernet-controller command 2-316

show controllers tcam command 2-323

show controller utilization command 2-325

show current command 2-596

show dot1x command 2-327

show dtp 2-331

show eap command 2-333

show env command 2-336

show errdisable detect command 2-337

show errdisable flap-values command 2-339

show errdisable recovery command 2-341

show etherchannel command 2-343

show fallback profile command 2-346

show flowcontrol command 2-348

show interfaces command 2-350

show interfaces counters command 2-358

show inventory command 2-360

show ip dhcp snooping binding command 2-362

show ip dhcp snooping command 2-361

show ip dhcp snooping database command 2-364, 2-366

show ip igmp profile command 2-369

show ip igmp snooping command 2-370

show ip igmp snooping groups command 2-373

show ip igmp snooping mrouter command 2-375

show ip igmp snooping querier command 2-377

show lacp command 2-379

show link state group command 2-385

show mac access-group command 2-388

show mac address-table address command 2-392

show mac address-table aging time command 2-394

show mac address-table command 2-390

show mac address-table count command 2-396

show mac address-table dynamic command 2-398

show mac address-table interface command 2-400

show mac address-table move update command 2-402

show mac address-table notification command 2-42, 2-404, B-19

show mac address-table static command 2-406

show mac address-table vlan command 2-408

show mls qos aggregate-policer command 2-411

show mls qos command 2-410

show mls qos input-queue command 2-412

show mls qos interface command 2-414

show mls qos maps command 2-418

show mls qos queue-set command 2-421

show mls qos vlan command 2-423

show monitor command 2-424

show mvr command 2-426

show mvr interface command 2-428

show mvr members command 2-430

show pagp command 2-432

show parser macro command 2-434

show platform acl command C-2

show platform backup interface command C-3

show platform etherchannel command C-4

show platform forward command C-5

show platform igmp snooping command C-7

show platform layer4op command C-9

show platform mac-address-table command C-10

show platform messaging command C-11

show platform monitor command C-12

show platform mvr table command C-13

show platform pm command C-14

show platform port-asic command C-15

show platform port-security command C-20

show platform qos command C-21

show platform resource-manager command C-22

show platform snmp counters command C-24

show platform spanning-tree command C-25

show platform stp-instance command C-26

show platform tcam command C-27

show platform vlan command C-29

show policy-map command 2-437

show port security command 2-439

show proposed command 2-596

show sdm prefer command 2-442

show setup express command 2-444

show spanning-tree command 2-445

show storm-control command 2-451

show system mtu command 2-453

show trust command 2-577

show udld command 2-454

show version command 2-457

show vlan command 2-459

show vlan command, fields 2-460

show vmps command 2-462

show vtp command 2-465

shutdown command 2-470

shutdown vlan command 2-471

small violation-rate command 2-472

Smartports macros

See macros

SNMP host, specifying 2-478

SNMP informs, enabling the sending of 2-474

snmp-server enable traps command 2-474

snmp-server host command 2-478

snmp trap mac-notification command 2-482

SNMP traps

enabling MAC address notification trap 2-482

enabling the MAC address notification feature 2-185

enabling the sending of 2-474


See Cisco SoftPhone

software images

deleting 2-64

downloading 2-6

upgrading 2-6

uploading 2-11

software version, displaying 2-457

source ports, MVR 2-250


configuring 2-242

debug messages, display B-20

displaying 2-424

filter SPAN traffic 2-242


add interfaces to 2-242

displaying 2-424

start new 2-242

spanning-tree backbonefast command 2-484

spanning-tree bpdufilter command 2-485

spanning-tree bpduguard command 2-487

spanning-tree cost command 2-489

spanning-tree etherchannel command 2-491

spanning-tree extend system-id command 2-493

spanning-tree guard command 2-495

spanning-tree link-type command 2-497

spanning-tree loopguard default command 2-499

spanning-tree mode command 2-501

spanning-tree mst configuration command 2-503

spanning-tree mst cost command 2-505

spanning-tree mst forward-time command 2-507

spanning-tree mst hello-time command 2-508

spanning-tree mst max-age command 2-509

spanning-tree mst max-hops command 2-510

spanning-tree mst port-priority command 2-512

spanning-tree mst pre-standard command 2-514

spanning-tree mst priority command 2-515

spanning-tree mst root command 2-516

spanning-tree portfast (global configuration) command 2-520

spanning-tree portfast (interface configuration) command 2-522

spanning-tree port-priority command 2-518

Spanning Tree Protocol


spanning-tree transmit hold-count command 2-524

spanning-tree uplinkfast command 2-525

spanning-tree vlan command 2-527

speed command 2-530

srr-queue bandwidth limit command 2-532

srr-queue bandwidth share command 2-536

SSH, configuring version 2-163

static-access ports, configuring 2-541

statistics, Ethernet group 2-281

sticky learning, enabling 2-553

storm-control command 2-538


BackboneFast 2-484

counters, clearing 2-46

debug messages, display

BackboneFast events B-59


optimized BPDUs handling B-61

spanning-tree activity B-57

switch shim B-64

transmitted and received BPDUs B-60

UplinkFast B-66

detection of indirect link failures 2-484

EtherChannel misconfiguration 2-491

extended system ID 2-493

path cost 2-489

protocol modes 2-501


root port

accelerating choice of new 2-525

loop guard 2-495

preventing from becoming designated 2-495

restricting which can be root 2-495

root guard 2-495

UplinkFast 2-525

root switch

affects of extended system ID 2-493, 2-528

hello-time 2-527

interval between BDPU messages 2-527

interval between hello BPDU messages 2-527

max-age 2-527

port priority for selection of 2-518

primary or secondary 2-527

switch priority 2-527

state changes

blocking to forwarding state 2-522

enabling BPDU filtering 2-485, 2-520

enabling BPDU guard 2-487, 2-520

enabling Port Fast 2-520, 2-522

enabling timer to recover from error state 2-105

forward-delay time 2-527

length of listening and learning states 2-527

shutting down Port Fast-enabled ports 2-520

state information display 2-445

VLAN options 2-515, 2-527

Switched Port Analyzer


switchport access command 2-541

switchport backup interface command 2-543

switchport block command 2-547

switchport host command 2-548

switchport mode command 2-549

switchport nonegotiate command 2-551

switchport port-security aging command 2-558

switchport port-security command 2-553

switchport priority extend command 2-560

switchport protected command 2-562

switchports, displaying 2-350

switchport trunk command 2-564

switchport voice vlan command 2-567

system message logging, save message to flash 2-176

system mtu command 2-569

system resource templates 2-282


tar files, creating, listing, and extracting 2-8

TDR, running 2-571

Telnet, using to communicate to cluster switches 2-275

temperature information, displaying 2-336

templates, SDM 2-282

templates, system resources 2-282

test cable-diagnostics tdr command 2-571

traceroute mac command 2-572

traceroute mac ip command 2-575

trunking, VLAN mode 2-549

trunk mode 2-549

trunk ports 2-549

trunks, to non-DTP device 2-550

trusted boundary for QoS 2-240

trusted port states for QoS 2-240

type (boot loader) command A-22



aggressive mode 2-579, 2-581

debug messages, display B-74

enable globally 2-579

enable per interface 2-581

error recovery timer 2-105

message timer 2-579

normal mode 2-579, 2-581

reset a shutdown interface 2-583

status 2-454

udld command 2-579

udld port command 2-581

udld reset command 2-583

unicast storm control 2-538

UniDirectional Link Detection


unknown multicast traffic, preventing 2-547

unknown unicast traffic, preventing 2-547

unset (boot loader) command A-23


software images

downloading 2-6

monitoring status of 2-298

upgrading information

See release notes

UplinkFast, for STP 2-525

user EXEC mode 1-2, 1-3


version (boot loader) command A-25

vlan (global configuration) command 2-584

vlan (VLAN configuration) command 2-589

VLAN configuration

rules 2-587, 2-591

saving 2-584, 2-593

VLAN configuration mode


VLAN 2-589

VTP 2-607

description 1-5

entering 2-595

summary 1-2

vlan database command 2-595

VLAN ID range 2-584, 2-589

VLAN Query Protocol



adding 2-584

configuring 2-584, 2-589

debug messages, display

ISL B-71

VLAN IOS file system error tests B-69

VLAN manager activity B-67

VTP B-72

displaying configurations 2-459

enabling guest VLAN supplicant 2-71, 2-81, 2-109

extended-range 2-584

MAC addresses

displaying 2-408

number of 2-396

media types 2-586, 2-591

normal-range 2-584, 2-589

restarting 2-471

saving the configuration 2-584

shutting down 2-471

SNMP traps for VTP 2-476, 2-479

suspending 2-471

variables 2-589

VLAN Trunking Protocol



configuring servers 2-601

displaying 2-462

error recovery timer 2-105

reconfirming dynamic VLAN assignments 2-598

vmps reconfirm (global configuration) command 2-599

vmps reconfirm (privileged EXEC) command 2-598

vmps retry command 2-600

vmps server command 2-601

voice VLAN

configuring 2-567

setting port priority 2-560


and dynamic-access ports 2-542

clearing client statistics 2-48

displaying information 2-462

per-server retry count 2-600

reconfirmation interval 2-599

reconfirming dynamic VLAN assignments 2-598


changing characteristics 2-603

clearing pruning counters 2-49


domain name 2-603, 2-607

file name 2-603

mode 2-603, 2-607

password 2-603, 2-607

counters display fields 2-466

displaying information 2-465


pruning 2-603, 2-607

Version 2 2-603, 2-607

mode 2-603, 2-607

pruning 2-603, 2-607

saving the configuration 2-584, 2-593

statistics 2-465

status 2-465

status display fields 2-468

vtp (global configuration) command 2-603

vtp (VLAN configuration) command 2-607