A -
B -
C -
D -
E -
F -
G -
H -
I -
J -
L -
M -
N -
O -
P -
Q -
R -
S -
T -
U -
V -
Index
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5, 2-33, 2-39, 2-41, 2-43, 2-45, 2-47, 2-135, 2-286, 2-472, B-8, B-35
AAA methods 2-3
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-183
MAC, displaying 2-581
access map configuration mode 2-317
access mode 2-760
access ports 2-760
ACEs 2-126, 2-386
ACLs
deny 2-124
displaying 2-447
for non-IP protocols 2-290
IP 2-183
matching 2-317
on Layer 2 interfaces 2-183
permit 2-384
action command 2-6
address aliasing 2-366
aggregate-port learner 2-378
alarm command 2-17
alarm contact command 2-8
alarm facility fcs-hysteresis command 2-10, 2-11
alarm facility input-alarm command 2-11, 2-14
alarm facility power-supply command 2-12
alarm facility temperature command 2-15
alarm IDs 2-18, 2-450
alarm profile
attaching to a port 2-19
creating 2-17
displaying 2-451
alarm profile (global configuration) command 2-17
alarm profile (interface configuration) command 2-19
alarm profile configuration mode 2-17
alarm relay-mode
setting 2-20
alarm relay-mode command 2-20
allowed VLANs 2-774
archive download-sw command 2-21
archive tar command 2-24
archive upload-sw command 2-27
arp access-list command 2-29
authentication command bounce-port ignore 2-31
authentication command disable-port ignore 2-32
authentication control-direction command 2-33
authentication event command 2-35
authentication failed VLAN
See dot1x auth-fail vlan
authentication fallback command 2-39
authentication host-mode command 2-41
authentication mac-move permit command 2-43
authentication open command 2-45
authentication order command 2-47
authentication periodic command 2-49
authentication port-control command 2-51
authentication priority command 2-53
authentication timer command 2-55
authentication violation command 2-57
auth-fail max-attempts
See dot1x auth-fail max-attempts
auth-fail vlan
See dot1x auth-fail vlan
auth open command 2-45
auth order command 2-47
authorization state of controlled port 2-152
auth timer command 2-55
autonegotiation of duplex mode 2-163
auto qos voip command 2-59
B
BackboneFast, for STP 2-692
backup interfaces
configuring 2-753
displaying 2-520
boot (boot loader) command A-2
boot buffersize command 2-63
boot config-file command 2-64
boot enable-break command 2-65
boot fast command 2-66
boot helper command 2-67
boot helper-config file command 2-68
booting
Cisco IOS image 2-72
displaying environment variables 2-464
interrupting 2-65
manually 2-70
boot loader
accessing A-1
booting
Cisco IOS image A-2
helper image 2-67
directories
creating A-16
displaying a list of A-8
removing A-20
displaying
available commands A-13
memory heap utilization A-14
version A-28
environment variables
described A-21
displaying settings A-21
location of A-22
setting A-21
unsetting A-26
files
copying A-6
deleting A-7
displaying a list of A-8
displaying the contents of A-4, A-17, A-24
renaming A-18
file system
formatting A-11
initializing flash A-10
running a consistency check A-12
resetting the system A-19
boot manual command 2-70
boot private-config-file command 2-71
boot system command 2-72
BPDU filtering, for spanning tree 2-693, 2-728
BPDU guard, for spanning tree 2-695, 2-728
broadcast storm control 2-746
C
candidate switches
See clusters
cat (boot loader) command A-4
channel-group command 2-73
channel-protocol command 2-76
Cisco SoftPhone
auto-QoS configuration 2-59
trusting packets sent from 2-357
CISP
See Client Information Signalling Protocol
cisp
debug platform cisp command B-35
enable command 2-79
class command 2-80
class-map command 2-82
class maps
creating 2-82
defining the match criteria 2-319
displaying 2-473
class of service
See CoS
clear dot1x command 2-84
clear eap sessions command 2-85
clear errdisable interface 2-86
clear ip arp inspection log command 2-87
clear ip arp inspection statistics command 2-88
clear ipc command 2-91
clear ip dhcp snooping database command 2-89
clear ipv6 dhcp conflict command 2-92
clear lacp command 2-93
clear mac address-table command 2-94, 2-95
clear nmsp statistics command 2-96
clear pagp command 2-97, 2-101
clear port-security command 2-98
clear psp counter 2-100
clear psp counter command 2-100
clear spanning-tree counters command 2-102
clear spanning-tree detected-protocols command 2-103
clear vmps statistics command 2-105
clear vtp counters command 2-106
Client Information Signalling Protocol 2-79, 2-135, 2-472, B-8, B-35
cluster commander-address command 2-107
cluster discovery hop-count command 2-109
cluster enable command 2-110
cluster holdtime command 2-111
cluster member command 2-112
cluster outside-interface command 2-114
cluster run command 2-115
clusters
adding candidates 2-112
binding to HSRP group 2-116
building manually 2-112
communicating with
devices outside the cluster 2-114
members by using Telnet 2-412
debug messages, display B-9
displaying
candidate switches 2-476
debug messages B-9
member switches 2-478
status 2-474
hop-count limit for extended discovery 2-109
HSRP standby groups 2-116
redundancy 2-116
SNMP trap 2-683
cluster standby-group command 2-116
cluster timer command 2-118
command modes defined 1-1
command switch
See clusters
configuration files
password recovery disable considerations A-1
specifying the name 2-63, 2-64, 2-71
configuring multiple interfaces 2-181
config-vlan mode
commands 2-797
copy (boot loader) command A-6
CoS
assigning default value to incoming packets 2-327
overriding the incoming value 2-327
CoS-to-DSCP map 2-331
CPU ASIC statistics, displaying 2-480
crashinfo files 2-173
critical VLAN 2-36
D
debug authentication B-2
debug auto qos command B-4
debug backup command B-6, B-7
debug cip B-7
debug cisp command B-8
debug cluster command B-9
debug dot1x command B-11
debug dtp command B-12
debug eap command B-13, B-85
debug etherchannel command B-14
debug interface command B-15
debug ip dhcp snooping command B-16
debug ip igmp filter command B-18
debug ip igmp max-groups command B-19
debug ip igmp snooping command B-20
debug ip verify source packet command B-17
debug lacp command B-21
debug lldp packets command B-22
debug mac-notification command B-23
debug matm command B-24
debug matm move update command B-25
debug monitor command B-26
debug mvrdbg command B-28
debug nmsp command B-29
debug nvram command B-30
debug pagp command B-31
debug platform acl command B-32
debug platform backup interface command B-34
debug platform cisp command B-35
debug platform cpu-queues command B-36
debug platform dot1x command B-38
debug platform etherchannel command B-39
debug platform forw-tcam command B-40
debug platform ip arp inspection command B-41
debug platform ip dhcp command B-42
debug platform ip igmp snooping command B-43
debug platform ip source-guard command B-45
debug platform ip unicast command B-46
debug platform led command B-48
debug platform matm command B-49
debug platform messaging application command B-50
debug platform phy command B-51
debug platform pm command B-53
debug platform port-asic command B-55
debug platform port-security command B-56
debug platform qos-acl-tcam command B-57
debug platform resource-manager command B-58
debug platform snmp command B-59
debug platform span command B-60
debug platform supervisor-asic command B-61
debug platform sw-bridge command B-62
debug platform tcam command B-63
debug platform udld command B-66
debug platform vlan command B-67
debug pm command B-68
debug port-security command B-70
debug profinet alarm B-71
debug profinet cyclic B-73
debug profinet error B-75
debug profinet packet B-77
debug profinet platform B-79
debug profinet topology B-81
debug profinet trace B-83
debug qos-manager command B-86
debug spanning-tree backbonefast command B-89
debug spanning-tree bpdu command B-90
debug spanning-tree bpdu-opt command B-91
debug spanning-tree command B-87
debug spanning-tree mstp command B-92
debug spanning-tree switch command B-94
debug spanning-tree uplinkfast command B-96
debug sw-vlan command B-97
debug sw-vlan ifs command B-99
debug sw-vlan notification command B-100
debug sw-vlan vtp command B-102
debug udld command B-104
debug vqpc command B-106
defaultPort profile 2-18, 2-19
define interface-range command 2-119
delete (boot loader) command A-7
delete command 2-121
deny (ARP access-list configuration) command 2-122
deny command 2-124
detect mechanism, causes 2-164
DHCP snooping
enabling
on a VLAN 2-217
option 82 2-209, 2-211
trust on an interface 2-215
error recovery timer 2-170
rate limiting 2-214
DHCP snooping binding database
binding file, configuring 2-207
bindings
adding 2-205
deleting 2-205
displaying 2-536
clearing database agent statistics 2-89
database agent, configuring 2-207
displaying
binding entries 2-536
database agent status 2-539, 2-541
renewing 2-416
dir (boot loader) command A-8
directories, deleting 2-121
domain name, VTP 2-810
dot1x auth-fail max-attempts 2-129
dot1x auth-fail vlan 2-131
dot1x command 2-127
dot1x control-direction command 2-133
dot1x credentials (global configuration) command 2-135
dot1x critical global configuration command 2-136
dot1x critical interface configuration command 2-138
dot1x default command 2-140
dot1x fallback command 2-141
dot1x guest-vlan command 2-142
dot1x host-mode command 2-144
dot1x initialize command 2-146
dot1x mac-auth-bypass command 2-147
dot1x max-reauth-req command 2-149
dot1x max-req command 2-150
dot1x pae command 2-151
dot1x port-control command 2-152
dot1x re-authenticate command 2-154
dot1x reauthentication command 2-155
dot1x test eapol-capable command 2-156
dot1x test timeout command 2-157
dot1x timeout command 2-158
dot1x violation-mode command 2-161
dropping packets, with ACL matches 2-6
DSCP-to-CoS map 2-331
DSCP-to-DSCP-mutation map 2-331
DTP 2-761
DTP flap
error detection for 2-164
error recovery timer 2-170
DTP negotiation 2-762
duplex command 2-162
dynamic-access ports
configuring 2-749
restrictions 2-750
dynamic ARP inspection
ARP ACLs
apply to a VLAN 2-191
define 2-29
deny packets 2-122
display 2-455
permit packets 2-382
clear
log buffer 2-87
statistics 2-88
display
ARP ACLs 2-455
configuration and operating state 2-531
log buffer 2-531
statistics 2-531
trust state and rate limit 2-531
enable per VLAN 2-201
error detection for 2-164
log buffer
clear 2-87
configure 2-195
display 2-531
rate-limit incoming ARP packets 2-193
statistics
clear 2-88
display 2-531
trusted interface state 2-197
type of packet logged 2-202
validation checks 2-199
dynamic auto VLAN membership mode 2-760
dynamic desirable VLAN membership mode 2-760
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-150
response time before retransmitting 2-158
environmental alarms, displaying 2-453
environment alarm contact
display 2-504
environment variables, displaying 2-464
errdisable detect cause command 2-164
errdisable detect cause small-frame comand 2-167
errdisable recovery cause small-frame 2-169
errdisable recovery command 2-170
error conditions, displaying 2-507
error disable detection 2-164
error-disabled interfaces, displaying 2-520
EtherChannel
assigning Ethernet interface to channel group 2-73
creating port-channel logical interface 2-179
debug EtherChannel/PAgP, display B-14
debug platform-specific events, display B-39
displaying 2-510
interface information, displaying 2-520
LACP
clearing channel-group information 2-93
debug messages, display B-21
displaying 2-571
modes 2-73
port priority for hot-standby ports 2-271
restricting a protocol 2-76
system priority 2-273
load-distribution methods 2-394
PAgP
aggregate-port learner 2-378
clearing channel-group information 2-97
debug messages, display B-31
displaying 2-629
error detection for 2-164
error recovery timer 2-170
learn method 2-378
modes 2-73
physical-port learner 2-378
priority of interface for transmitted traffic 2-380
Ethernet controller, internal register display 2-482
Ethernet statistics, collecting 2-431
exception crashinfo command 2-173
extended discovery of candidate switches 2-109
extended-range VLANs
and allowed VLAN list 2-774
and pruning-eligible list 2-774
configuring 2-796
extended system ID for STP 2-701
F
facility alarm status, displaying 2-513
fallback profile command 2-174
fallback profiles, displaying 2-514
FCS bit error rate
displaying 2-516
fluctuation threshold 2-10
setting 2-176
FCS hysteresis threshold 2-10
fcs-threshold command 2-176
file name, VTP 2-810
files, deleting 2-121
flash_init (boot loader) command A-10
flexible authentication ordering 2-47
Flex Links
configuring 2-753
configuring preferred VLAN 2-755
displaying 2-520
flowcontrol command 2-177
format (boot loader) command A-11
forwarding packets, with ACL matches 2-6
forwarding results, display C-6
frame check sequence
See FCS
frame forwarding information, displaying C-6
fsck (boot loader) command A-12
G
global configuration mode 1-2, 1-3
H
hardware ACL statistics 2-447
help (boot loader) command A-13
hierarchical policy maps 2-392
hop-count limit for clusters 2-109
host connection, port configuration 2-759
Hot Standby Router Protocol
See HSRP
HSRP
binding HSRP group to cluster 2-116
standby group 2-116
I
IEEE 802.1x
and switchport modes 2-761
violation error recovery 2-170
See also port-based authentication
IEEE 802.1X Port Based Authentication
enabling guest VLAN supplicant 2-130, 2-141, 2-175
IGMP filters
applying 2-220
debug messages, display B-18
IGMP groups, setting maximum 2-221
IGMP maximum groups, debugging B-19
IGMP profiles
creating 2-223
displaying 2-544
IGMP snooping
adding ports as a static member of a group 2-239
displaying 2-545
enabling 2-225
enabling the configurable-leave timer 2-227
enabling the Immediate-Leave feature 2-236
flooding query count 2-233
interface topology change notification behavior 2-235
querier 2-229
query solicitation 2-233
report suppression 2-231
switch topology change notification behavior 2-233
images
See software images
Immediate-Leave feature, MVR 2-368
immediate-leave processing 2-236
Immediate-Leave processing, IPv6 2-269
interface configuration mode 1-2, 1-4
interface port-channel command 2-179
interface range command 2-181
interface-range macros 2-119
interfaces
assigning Ethernet interface to channel group 2-73
configuring 2-162
configuring multiple 2-181
creating port-channel logical 2-179
debug messages, display B-15
disabling 2-679
displaying the MAC address table 2-592
restarting 2-679
interface speed, configuring 2-738
internal registers, displaying 2-482, 2-489
Internet Group Management Protocol
See IGMP
invalid GBIC
error detection for 2-164
error recovery timer 2-170
ip access-group command 2-183
ip address command 2-186
IP addresses, setting 2-186
IP address matching 2-317
ip admission command 2-188
ip admission name proxy http command 2-189
ip arp inspection filter vlan command 2-191
ip arp inspection limit command 2-193
ip arp inspection log-buffer command 2-195
ip arp inspection trust command 2-197
ip arp inspection validate command 2-199
ip arp inspection vlan command 2-201
ip arp inspection vlan logging command 2-202
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-205
ip dhcp snooping command 2-204
ip dhcp snooping database command 2-207
ip dhcp snooping information option allow-untrusted command 2-211
ip dhcp snooping information option command 2-209
ip dhcp snooping information option format remote-id command 2-213
ip dhcp snooping limit rate command 2-214
ip dhcp snooping trust command 2-215
ip dhcp snooping verify command 2-216
ip dhcp snooping vlan command 2-217
ip dhcp snooping vlan information option format-type circuit-id string command 2-218
ip igmp filter command 2-220
ip igmp max-groups command 2-221, 2-245
ip igmp profile command 2-223
ip igmp snooping command 2-225
ip igmp snooping last-member-query-interval command 2-227
ip igmp snooping querier command 2-229
ip igmp snooping report-suppression command 2-231
ip igmp snooping tcn command 2-233
ip igmp snooping tcn flood command 2-235
ip igmp snooping vlan immediate-leave command 2-236
ip igmp snooping vlan mrouter command 2-237
ip igmp snooping vlan static command 2-239
IP multicast addresses 2-365
IP phones
auto-QoS configuration 2-59
trusting packets sent from 2-357
IP-precedence-to-DSCP map 2-331
ip source binding command 2-241
IP source guard
disabling 2-247
displaying
binding entries 2-553
configuration 2-554
dynamic binding entries only 2-536
enabling 2-247
static IP source bindings 2-241
ip ssh command 2-243
ipv6 address dhcp command 2-248
ipv6 dhcp client request vendor command 2-249
ipv6 dhcp ping packets command 2-250
ipv6 dhcp pool command 2-252
ipv6 dhcp server command 2-255
ipv6 mld snooping command 2-257
ipv6 mld snooping last-listener-query count command 2-259
ipv6 mld snooping last-listener-query-interval command 2-261
ipv6 mld snooping listener-message-suppression command 2-263
ipv6 mld snooping robustness-variable command 2-265
ipv6 mld snooping tcn command 2-267
ipv6 mld snooping vlan command 2-269
IPv6 SDM template 2-432
ip verify source command 2-247
J
jumbo frames
See MTU
L
LACP
See EtherChannel
lacp port-priority command 2-271
lacp system-priority command 2-273
Layer 2 traceroute
IP addresses 2-787
MAC addresses 2-784
line configuration mode 1-2, 1-4
Link Aggregation Control Protocol
See EtherChannel
link-diag error-rate command 2-275
link diagnostics 2-575
window size 2-275
link flap
error detection for 2-164
error recovery timer 2-170
link state group command 2-276
link state track command 2-278
load-distribution methods for EtherChannel 2-394
location (global configuration) command 2-279
location (interface configuration) command 2-281
logging event command 2-283
logging file command 2-284
logical interface 2-179
loopback error
detection for 2-164
recovery timer 2-170
loop guard, for spanning tree 2-703, 2-707
M
mab request format attribute 32 command 2-286
mac access-group command 2-288
MAC access list configuration mode 2-290
mac access-list extended command 2-290
MAC access lists 2-124
MAC addresses
disabling MAC address learning per VLAN 2-293
displaying
aging time 2-586
all 2-584
dynamic 2-590
MAC address-table move updates 2-595
notification settings 2-594, 2-597
number of addresses in a VLAN 2-588
per interface 2-592
per VLAN 2-601
static 2-599
static and dynamic entries 2-582
dynamic
aging time 2-292
deleting 2-94
displaying 2-590
enabling MAC address notification 2-297
enabling MAC address-table move update 2-295
matching 2-317
static
adding and removing 2-299
displaying 2-599
dropping on an interface 2-300
tables 2-584
MAC address notification, debugging B-23
mac address-table aging-time 2-288
mac address-table aging-time command 2-292
mac address-table learning command 2-293
mac address-table move update command 2-295
mac address-table notification command 2-297
mac address-table static command 2-299
mac address-table static drop command 2-300
macro apply command 2-302
macro description
predefined 2-308
macro description command 2-305, 2-308
macro global command 2-311
macro global description command 2-314
macro name command 2-315
macros
adding a description 2-305
adding a global description 2-314
applying 2-311
creating 2-315
displaying 2-631
interface range 2-119, 2-181
specifying parameter values 2-311
tracing 2-311
maps
QoS
defining 2-331
displaying 2-611
VLAN
creating 2-801
defining 2-317
displaying 2-670
match (access-map configuration) command 2-317
match (class-map configuration) command 2-319
maximum transmission unit
See MTU
mdix auto command 2-321
media-type
line console 2-322
media--type command 2-322
member switches
See clusters
memory (boot loader) command A-14
mkdir (boot loader) command A-16
MLD snooping
configuring 2-263, 2-265
configuring queries 2-259, 2-261
configuring topology change notification 2-267
displaying 2-561, 2-563, 2-567
enabling 2-257
MLD snooping on a VLAN, enabling 2-269
mls qos aggregate-policer command 2-325
mls qos command 2-323
mls qos cos command 2-327
mls qos dscp-mutation command 2-329
mls qos map command 2-331
mls qos queue-set output buffers command 2-335
mls qos queue-set output threshold command 2-337
mls qos rewrite ip dscp command 2-339
mls qos srr-queue input bandwidth command 2-341
mls qos srr-queue input buffers command 2-343
mls qos-srr-queue input cos-map command 2-345
mls qos srr-queue input dscp-map command 2-347
mls qos srr-queue input priority-queue command 2-349
mls qos srr-queue input threshold command 2-351
mls qos-srr-queue output cos-map command 2-353
mls qos srr-queue output dscp-map command 2-355
mls qos trust command 2-357
mls qos vlan-based command 2-359
mode, MVR 2-365
modes, commands 1-1
monitor session command 2-360
more (boot loader) command A-17
MSTP
displaying 2-653
interoperability 2-103
link type 2-705
MST region
aborting changes 2-711
applying changes 2-711
configuration name 2-711
configuration revision number 2-711
current or pending display 2-711
displaying 2-653
MST configuration mode 2-711
VLANs-to-instance mapping 2-711
path cost 2-713
protocol mode 2-709
restart protocol migration process 2-103
root port
loop guard 2-703
preventing from becoming designated 2-703
restricting which can be root 2-703
root guard 2-703
root switch
affects of extended system ID 2-701
hello-time 2-716, 2-724
interval between BDPU messages 2-717
interval between hello BPDU messages 2-716, 2-724
max-age 2-717
maximum hop count before discarding BPDU 2-718
port priority for selection of 2-720
primary or secondary 2-724
switch priority 2-723
state changes
blocking to forwarding state 2-730
enabling BPDU filtering 2-693, 2-728
enabling BPDU guard 2-695, 2-728
enabling Port Fast 2-728, 2-730
forward-delay time 2-715
length of listening and learning states 2-715
rapid transition to forwarding 2-705
shutting down Port Fast-enabled ports 2-728
state information display 2-652
MTU
configuring size 2-780
displaying global setting 2-660
Multicase Listener Discovery
See MLD
multicast group address, MVR 2-368
multicast groups, MVR 2-366
Multicast Listener Discovery
See MLD
multicast router learning method 2-237
multicast router ports, configuring 2-237
multicast router ports, IPv6 2-269
multicast storm control 2-746
multicast VLAN, MVR 2-365
multicast VLAN registration
See MVR
Multiple Spanning Tree Protocol
See MSTP
MVR
and address aliasing 2-366
configuring 2-365
configuring interfaces 2-368
debug messages, display B-28
displaying 2-619
displaying interface information 2-621
members, displaying 2-623
mvr (global configuration) command 2-365
mvr (interface configuration) command 2-368
mvr vlan group command 2-369
N
native VLANs 2-774
network-policy (global configuration) command 2-372
network-policy command 2-371
network-policy profile (network-policy configuration) command 2-374
nmsp attachment suppress command 2-377
nmsp command 2-376
nonegotiate, speed 2-738
nonegotiating DTP messaging 2-762
non-IP protocols
denying 2-124
forwarding 2-384
non-IP traffic access lists 2-290
non-IP traffic forwarding
denying 2-124
permitting 2-384
normal-range VLANs 2-796
notifies command 2-17
no vlan command 2-796
NVRAM
change buffersize 2-63
display buffersize 2-466
O
online diagnostics
global configuration mode
clearing health monitoring diagnostic test schedule 2-87
setting health monitoring diagnostic testing 2-87
setting up health monitoring diagnostic test schedule 2-87
P
PAgP
See EtherChannel
pagp learn-method command 2-378
pagp port-priority command 2-380
password, VTP 2-811
permit (ARP access-list configuration) command 2-382
permit (MAC access-list configuration) command 2-384
per-VLAN spanning-tree plus
See STP
physical-port learner 2-378
PID, displaying 2-530
PIM-DVMRP, as multicast router learning method 2-237
police aggregate command 2-389
police command 2-387
policed-DSCP map 2-331
policy-map command 2-391
policy maps
applying to an interface 2-437, 2-441
creating 2-391
displaying 2-634
hierarchical 2-392
policers
displaying 2-604
for a single class 2-387
for multiple classes 2-325, 2-389
policed-DSCP map 2-331
traffic classification
defining the class 2-80
defining trust states 2-789
setting DSCP or IP precedence values 2-439
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
configuring violation modes 2-161
debug messages, display B-11
enabling IEEE 802.1x
globally 2-127
per interface 2-152
guest VLAN 2-142
host modes 2-144
IEEE 802.1x AAA accounting methods 2-1
initialize an interface 2-146, 2-157
MAC authentication bypass 2-147
manual control of authorization state 2-152
PAE as authenticator 2-151
periodic re-authentication
time between attempts 2-158
periodic reauthentication
enabling 2-155
quiet period between failed authentication exchanges 2-158
reauthenticating IEEE 802.1x-enabled ports 2-154
resetting configurable IEEE 802.1x parameters 2-140
switch-to-authentication server retransmission time 2-158
switch-to-client frame-retransmission number2-149to 2-150
switch-to-client retransmission time 2-158
test for IEEE 802.1x readiness 2-156
port-channel load-balance command 2-394
Port Fast, for spanning tree 2-730
port ranges, defining 2-119
ports, debugging B-68
ports, protected 2-773
port security
aging 2-769
debug messages, display B-70
enabling 2-764
violation error recovery 2-170
port trust states for QoS 2-357
port types, MVR 2-368
power supply alarms, setting 2-12
power-supply dual command 2-396
powersupply mode 2-396
Precision Time Protocol
primary temperature alarm 2-15
priority-queue command 2-397
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-530
profinet 2-399
pruning
VLANs 2-774
VTP
displaying interface information 2-520
enabling 2-811
pruning-eligible VLAN list 2-775
psp 2-401
psp command 2-401
ptp (global configuration) command 2-403
ptp interface configuration command 2-405
ptp port
display 2-644
PTP settings 2-405
PVST+
See STP
Q
QoS
auto-QoS
configuring 2-59
debug messages, display B-4
displaying 2-460
class maps
creating 2-82
defining the match criteria 2-319
displaying 2-473
defining the CoS value for an incoming packet 2-327
displaying configuration information 2-460, 2-603
DSCP transparency 2-339
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-329
defining DSCP-to-DSCP-mutation map 2-331
egress queues
allocating buffers 2-335
defining the CoS output queue threshold map 2-353
defining the DSCP output queue threshold map 2-355
displaying buffer allocations 2-607
displaying CoS output queue threshold map 2-611
displaying DSCP output queue threshold map 2-611
displaying queueing strategy 2-607
displaying queue-set settings 2-614
enabling bandwidth shaping and scheduling 2-742
enabling bandwidth sharing and scheduling 2-744
limiting the maximum output on a port 2-740
mapping a port to a queue-set 2-407
mapping CoS values to a queue and threshold 2-353
mapping DSCP values to a queue and threshold 2-355
setting maximum and reserved memory allocations 2-337
setting WTD thresholds 2-337
enabling 2-323
ingress queues
allocating buffers 2-343
assigning SRR scheduling weights 2-341
defining the CoS input queue threshold map 2-345
defining the DSCP input queue threshold map 2-347
displaying buffer allocations 2-607
displaying CoS input queue threshold map 2-611
displaying DSCP input queue threshold map 2-611
displaying queueing strategy 2-607
displaying settings for 2-605
enabling the priority queue 2-349
mapping CoS values to a queue and threshold 2-345
mapping DSCP values to a queue and threshold 2-347
setting WTD thresholds 2-351
maps
defining 2-331, 2-345, 2-347, 2-353, 2-355
displaying 2-611
policy maps
applying an aggregate policer 2-389
applying to an interface 2-437, 2-441
creating 2-391
defining policers 2-325, 2-387
displaying policers 2-604
displaying policy maps 2-634
hierarchical 2-392
policed-DSCP map 2-331
setting DSCP or IP precedence values 2-439
traffic classifications 2-80
trust states 2-789
port trust states 2-357
queues, enabling the expedite 2-397
statistics
in-profile and out-of-profile packets 2-607
packets enqueued or dropped 2-607
sent and received CoS values 2-607
sent and received DSCP values 2-607
trusted boundary for IP phones 2-357
VLAN-based 2-359
quality of service
See QoS
querytime, MVR 2-365
queue-set command 2-407
R
radius-server dead-criteria command 2-408
radius-server host command 2-410
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
rcommand command 2-412
reauthenticating IEEE 802.1x-enabled ports 2-154
re-authentication
time between attempts 2-158
reauthentication
periodic 2-155
receiver ports, MVR 2-368
receiving flow-control packets 2-177
recovery mechanism
causes 2-170
display 2-86, 2-467, 2-505, 2-508
timer interval 2-171
redundancy for cluster switches 2-116
relay-major command 2-17
relay-minor command 2-17
remote-span command 2-414
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-18
renew ip dhcp snooping database command 2-416
rep admin vlan command 2-418
rep block port command 2-419
rep lsl-age-timer command 2-422
rep preempt delay command 2-424
rep preempt segment command 2-425
rep segment command 2-426
rep stcn command 2-429
reset (boot loader) command A-19
resource templates, displaying 2-648
restricted VLAN
See dot1x auth-fail vlan
rmdir (boot loader) command A-20
rmon collection stats command 2-431
root guard, for spanning tree 2-703
routed ports
IP addresses on 2-187
number supported 2-187
RSPAN
configuring 2-360
displaying 2-617
filter RSPAN traffic 2-360
remote-span command 2-414
sessions
displaying 2-617
S
sdflash
display information C-30
sdm prefer command 2-432
SDM templates
displaying 2-648
dual IPv4 and IPv6 2-432
secondary temperature alarm 2-15
secure ports, limitations 2-766
see PTP
sending flow-control packets 2-177
service password-recovery command 2-435
service-policy command 2-437
set (boot loader) command A-21
set command 2-439
setup command 2-441
setup express command 2-444
show access-lists command 2-447
show alarm description port 2-450
show alarm description port command 2-450
show alarm profile command 2-451
show alarm settings command 2-453
show archive status command 2-454
show arp access-list command 2-455
show authentication command 2-456
show auto qos command 2-460
show boot buffersize command 2-466
show boot command 2-464
show cable-diagnostics tdr command 2-467
show cisp command 2-472
show class-map command 2-473
show cluster candidates command 2-476
show cluster command 2-474
show cluster members command 2-478
show controllers cpu-interface command 2-480
show controllers ethernet-controller command 2-482
show controllers tcam command 2-489
show controller utilization command 2-491
show dot1x command 2-493
show dtp command 2-497
show eap command 2-499
show env command 2-502, 2-504
show errdisable detect command 2-505
show errdisable flap-values command 2-507
show errdisable recovery command 2-508
show etherchannel command 2-510
show facility-alarm status command 2-513
show fallback profile command 2-514
show fcs threshold command 2-516
show flowcontrol command 2-518
show interface rep command 2-528
show interfaces command 2-520
show interfaces counters command 2-526
show interfaces rep command 2-528
show inventory command 2-530
show ip arp inspection command 2-531
show ipc command 2-556
show ip dhcp snooping binding command 2-536
show ip dhcp snooping command 2-535
show ip dhcp snooping database command 2-539, 2-541
show ip igmp profile command 2-544
show ip igmp snooping address command 2-563
show ip igmp snooping command 2-545, 2-561
show ip igmp snooping groups command 2-548
show ip igmp snooping mrouter command 2-550, 2-565
show ip igmp snooping querier command 2-551, 2-567
show ip source binding command 2-553
show ipv6 dhcp conflict command 2-560
show ipv6 route updated 2-569
show ip verify source command 2-554
show lacp command 2-571
show link-diag error-rate command 2-575
show link state group command 2-579
show location 2-577
show mac access-group command 2-581
show mac address-table address command 2-584
show mac address-table aging time command 2-586
show mac address-table command 2-582
show mac address-table count command 2-588
show mac address-table dynamic command 2-590
show mac address-table interface command 2-592
show mac address-table learning command 2-594
show mac address-table move update command 2-595
show mac address-table notification command 2-95, 2-597, B-25
show mac address-table static command 2-599
show mac address-table vlan command 2-601
show mls qos aggregate-policer command 2-604
show mls qos command 2-603
show mls qos input-queue command 2-605
show mls qos interface command 2-607
show mls qos maps command 2-611
show mls qos queue-set command 2-614
show mls qos vlan command 2-616
show monitor command 2-617
show mvr command 2-619
show mvr interface command 2-621
show mvr members command 2-623
show network-policy profile command 2-625
show nmsp command 2-626
show pagp command 2-629
show parser macro command 2-631
show platform acl command C-2
show platform backup interface command C-3
show platform configuration command C-4
show platform etherchannel command C-5
show platform forward command C-6
show platform igmp snooping command C-8
show platform ip unicast command C-9
show platform ipv6 unicast command C-14
show platform ip wccp command C-13
show platform layer4op command C-16
show platform mac-address-table command C-17
show platform messaging command C-18
show platform monitor command C-19
show platform mvr table command C-20
show platform pm command C-21
show platform port-asic command C-22
show platform port-security command C-26
show platform qos command C-27
show platform resource-manager command C-28
show platform sdflash command C-30
show platform snmp counters command C-31
show platform spanning-tree command C-32
show platform stp-instance command C-33
show platform tcam command C-34
show platform vlan command C-36
show policy-map command 2-634
show port security command 2-635
show profinet command 2-637
show psp config command 2-639
show psp statistics command 2-640
show ptp command 2-641, 2-644
show ptp port command 2-644
show rep topology command 2-645
show sdm prefer command 2-648
show setup express command 2-651
show spanning-tree command 2-652
show storm-control command 2-658
show system mtu command 2-660
show trust command 2-789
show udld command 2-661
show version command 2-664
show vlan access-map command 2-670
show vlan command 2-666
show vlan command, fields 2-668
show vlan filter command 2-671
show vmps command 2-672
show vtp command 2-674
shutdown command 2-679
shutdown vlan command 2-680
small violation-rate command 2-681
Smartports macros
See macros
SNMP host, specifying 2-687
SNMP informs, enabling the sending of 2-683
snmp-server enable traps command 2-683
snmp-server host command 2-687
snmp trap mac-notification change command 2-690
SNMP traps
enabling MAC address notification trap 2-690
enabling the MAC address notification feature 2-297
enabling the sending of 2-683
SoftPhone
See Cisco SoftPhone
software images
deleting 2-121
downloading 2-21
upgrading 2-21
uploading 2-27
software version, displaying 2-664
source ports, MVR 2-368
SPAN
configuring 2-360
debug messages, display B-26
displaying 2-617
filter SPAN traffic 2-360
sessions
add interfaces to 2-360
displaying 2-617
start new 2-360
spanning-tree backbonefast command 2-692
spanning-tree bpdufilter command 2-693
spanning-tree bpduguard command 2-695
spanning-tree cost command 2-697
spanning-tree etherchannel command 2-699
spanning-tree extend system-id command 2-701
spanning-tree guard command 2-703
spanning-tree link-type command 2-705
spanning-tree loopguard default command 2-707
spanning-tree mode command 2-709
spanning-tree mst configuration command 2-711
spanning-tree mst cost command 2-713
spanning-tree mst forward-time command 2-715
spanning-tree mst hello-time command 2-716
spanning-tree mst max-age command 2-717
spanning-tree mst max-hops command 2-718
spanning-tree mst port-priority command 2-720
spanning-tree mst pre-standard command 2-722
spanning-tree mst priority command 2-723
spanning-tree mst root command 2-724
spanning-tree portfast (global configuration) command 2-728
spanning-tree portfast (interface configuration) command 2-730
spanning-tree port-priority command 2-726
Spanning Tree Protocol
See STP
spanning-tree transmit hold-count command 2-732
spanning-tree uplinkfast command 2-733
spanning-tree vlan command 2-735
speed command 2-738
srr-queue bandwidth limit command 2-740
srr-queue bandwidth share command 2-744
SSH, configuring version 2-243
static-access ports, configuring 2-749
statistics, Ethernet group 2-431
sticky learning, enabling 2-764
storm-control command 2-746
STP
BackboneFast 2-692
counters, clearing 2-102
debug messages, display
BackboneFast events B-89
MSTP B-92
optimized BPDUs handling B-91
spanning-tree activity B-87
switch shim B-94
transmitted and received BPDUs B-90
UplinkFast B-96
detection of indirect link failures 2-692
EtherChannel misconfiguration 2-699
extended system ID 2-701
path cost 2-697
protocol modes 2-709
root port
accelerating choice of new 2-733
loop guard 2-703
preventing from becoming designated 2-703
restricting which can be root 2-703
root guard 2-703
UplinkFast 2-733
root switch
affects of extended system ID 2-701, 2-736
hello-time 2-735
interval between BDPU messages 2-735
interval between hello BPDU messages 2-735
max-age 2-735
port priority for selection of 2-726
primary or secondary 2-735
switch priority 2-735
state changes
blocking to forwarding state 2-730
enabling BPDU filtering 2-693, 2-728
enabling BPDU guard 2-695, 2-728
enabling Port Fast 2-728, 2-730
enabling timer to recover from error state 2-170
forward-delay time 2-735
length of listening and learning states 2-735
shutting down Port Fast-enabled ports 2-728
state information display 2-652
VLAN options 2-723, 2-735
SVI status calculation 2-751
Switched Port Analyzer
See SPAN
switchport access command 2-749
switchport autostate exclude command 2-751
switchport backup interface command 2-753
switchport block command 2-757
switchport host command 2-759
switchport mode command 2-760
switchport nonegotiate command 2-762
switchport port-security aging command 2-769
switchport port-security command 2-764
switchport priority extend command 2-771
switchport protected command 2-773
switchport trunk command 2-774
switchport voice vlan command 2-777
sync
flash 2-779
saving old files 2-779
skipping files 2-779
sync flash sdflash command 2-779
syslog command 2-17
system alarm
settings 2-8
system message logging, save message to flash 2-284
system mtu command 2-780
system resource templates 2-432
T
tar files, creating, listing, and extracting 2-24
TDR, running 2-782
Telnet, using to communicate to cluster switches 2-412
temperature alarms, setting 2-15
templates, system resources 2-432
test cable-diagnostics tdr command 2-782
test relay 2-783
test relay command 2-783
traceroute mac command 2-784
traceroute mac ip command 2-787
trunking, VLAN mode 2-760
trunk mode 2-760
trunk ports 2-760
trunks, to non-DTP device 2-761
trusted boundary for QoS 2-357
trusted port states for QoS 2-357
type (boot loader) command A-24
U
UDLD
aggressive mode 2-791, 2-793
debug messages, display B-104
enable globally 2-791
enable per interface 2-793
error recovery timer 2-170
message timer 2-791
normal mode 2-791, 2-793
reset a shutdown interface 2-795
status 2-661
udld command 2-791
udld port command 2-793
udld reset command 2-795
unicast storm control 2-746
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-757
unknown unicast traffic, preventing 2-757
unset (boot loader) command A-26
upgrading
software images
downloading 2-21
monitoring status of 2-454
UplinkFast, for STP 2-733
user EXEC mode 1-2
V
version (boot loader) command A-28
vlan (global configuration) command 2-796
vlan access-map command 2-801
VLAN access map configuration mode 2-801
VLAN access maps
actions 2-6
displaying 2-670
VLAN-based QoS 2-359
VLAN configuration
rules 2-799
saving 2-796
VLAN configuration mode
description 1-4
entering 2-796
summary 1-2
vlan filter command 2-803
VLAN filters, displaying 2-671
VLAN ID range 2-796
VLAN maps
applying 2-803
creating 2-801
defining 2-317
displaying 2-670
VLAN Query Protocol
See VQP
VLANs
adding 2-796
configuring 2-796
debug messages, display
ISL B-100
VLAN IOS file system error tests B-99
VLAN manager activity B-97
VTP B-102
displaying configurations 2-666
enabling guest VLAN supplicant 2-130, 2-141, 2-175
extended-range 2-796
MAC addresses
displaying 2-601
number of 2-588
media types 2-799
normal-range 2-796
restarting 2-680
saving the configuration 2-796
shutting down 2-680
SNMP traps for VTP 2-685
suspending 2-680
VLAN Trunking Protocol
See VTP
VMPS
configuring servers 2-808
displaying 2-672
error recovery timer 2-171
reconfirming dynamic VLAN assignments 2-805
vmps reconfirm (global configuration) command 2-806
vmps reconfirm (privileged EXEC) command 2-805
vmps retry command 2-807
vmps server command 2-808
voice VLAN
configuring 2-777
setting port priority 2-771
VQP
and dynamic-access ports 2-750
clearing client statistics 2-105
displaying information 2-672
per-server retry count 2-807
reconfirmation interval 2-806
reconfirming dynamic VLAN assignments 2-805
VTP
changing characteristics 2-810
clearing pruning counters 2-106
configuring
domain name 2-810
file name 2-810
mode 2-810
password 2-811
counters display fields 2-675
displaying information 2-674
enabling
pruning 2-811
Version 2 2-811
enabling per port 2-815
mode 2-810
pruning 2-811
saving the configuration 2-796
statistics 2-674
status 2-674
status display fields 2-677
vtp (global configuration) command 2-810
vtp interface configuration) command 2-815
vtp primary command 2-816