Catalyst 2940 Switch Software Configuration Guide, 12.1(22)EA2
Index

Table Of Contents

Numerics - A - B - C - D - E - F - G - H - I - J - L - M - N - P - Q - R - S - T - U - V - W - X -

Index

Numerics

802.1D

See STP

802.1Q

and trunk ports     8-2

configuration limitations     13-16

encapsulation     13-14

native VLAN for untagged traffic     13-20

802.1s

See MSTP

802.1w

See RSTP

802.1x

See port-based authentication

802.3x flow control     8-12

A

abbreviating commands     2-3

access control list

See ACL

access-denied response, VMPS     13-25

access list

See ACL

access ports

defined     8-2

accounting

with 802.1x     7-5, 7-21

with RADIUS     6-28

with TACACS+     6-11, 6-17

ACL     1-5

addresses

displaying the MAC address table     5-26

dynamic

accelerated aging     10-8

changing the aging time     5-22

default aging     10-8

defined     5-20

learning     5-21

removing     5-23

MAC, discovering     5-26

multicast STP address management     10-8

static

adding and removing     5-25

defined     5-20

address resolution     5-26

Address Resolution Protocol

See ARP table

advertisements

CDP     19-1

VTP     13-17, 14-3

aggregated ports

See EtherChannel

aging, accelerating     10-8

aging time

accelerated

for MSTP     11-20

for STP     10-8, 10-21

MAC address table     5-22

maximum

for MSTP     11-21

for STP     10-21

alarms, RMON     21-3

allowed-VLAN list     13-18

ARP table

address resolution     5-26

managing     5-26

attributes, RADIUS

vendor-proprietary     6-30

vendor-specific     6-29

audience     xix

authentication

local mode with AAA     6-32

NTP associations     5-4

RADIUS

defined     6-18

key     6-21

login     6-23

TACACS+

defined     6-11

key     6-13

login     6-14

See also port-based authentication

authoritative time source, described     5-2

authorization

with RADIUS     6-27

with TACACS+     6-11, 6-16

authorized ports with 802.1x     7-4

autoconfiguration     3-3

autonegotiation

interface configuration guidelines     8-10

mismatches     26-10

auxiliary VLAN

See voice VLAN

B

BackboneFast

described     12-5

enabling     12-14

support for     1-4

banners

configuring

login     5-20

message-of-the-day login     5-18

default configuration     5-18

when displayed     5-18

booting

boot loader, function of     3-1

boot process     3-1

boot loader

described     3-1

trap-door mechanism     3-2

BPDU

error-disabled state     12-2

filtering     12-3

RSTP format     11-9

BPDU filtering

described     12-3

enabling     12-12

support for     1-4

BPDU guard

described     12-2

enabling     12-11

support for     1-4

broadcast storm control

See storm control

C

cables, monitoring for unidirectional links     18-1

candidate switch

defined     4-2

requirements     4-2

See also command switch, cluster standby group, and member switch

caution, described     xx

CDP

and trusted boundary     24-7

configuring     19-2

CDP (continued)

default configuration     19-2

described     19-1

disabling for routing device     19-3, 19-4

enabling and disabling

on an interface     19-4

on a switch     19-3

monitoring     19-5

overview     19-1

transmission timer and holdtime, setting     19-2

updates     19-2

Cisco Access Analog Trunk Gateway     1-11

Cisco CallManager software     1-11

Cisco Discovery Protocol

See CDP

Cisco IOS command-line interface

See CLI

Cisco IP Phones     1-11

Cisco Network Assistant

See Network Assistant

Cisco SoftPhone software     1-11

CiscoWorks 2000     1-7, 23-4

clearing interfaces     8-15

CLI

abbreviating commands     2-3

command modes     2-1

described     1-6

editing features

enabling and disabling     2-6

keystroke editing     2-6

wrapped lines     2-7

error messages     2-4

getting help     2-3

history

changing the buffer size     2-4

described     2-4

disabling     2-5

recalling commands     2-5

managing clusters     4-3

CLI (continued)

no and default forms of commands     2-3

client mode, VTP     14-3

clock

See system clock

clusters, switch

described     4-1

managing

through CLI     4-3

through SNMP     4-4

planning considerations

CLI     4-3

SNMP     4-4

cluster standby group, requirements     4-2

command-line interface

See CLI

command modes     2-1

commands

abbreviating     2-3

no and default     2-3

setting privilege levels     6-8

command switch

configuration conflicts     26-10

defined     4-1

password privilege levels     4-3

recovery

from failure     26-6

from lost member connectivity     26-10

replacing

with another switch     26-9

with cluster member     26-7

requirements     4-2

See also candidate switch, cluster standby group, member switch, and standby command switch

community strings

configuring     23-7

for cluster switches     23-4

overview     23-4

configuration conflicts, recovering from lost member connectivity     26-10

configuration examples, network

collapsed backbone and switch cluster     1-10

design concepts

network performance     1-8

network services     1-8

large campus     1-11

small to medium-sized network     1-9

configuration files

limiting TFTP server access     23-13

obtaining with DHCP     3-7

password recovery disable considerations     6-5

system contact and location information     23-13

VMPS database     13-25

configuration settings, saving     3-10

configure terminal command     8-5

config-vlan mode     2-2, 13-6

conflicts, configuration     26-10

connections, secure remote     6-33

connectivity problems     26-11

consistency checks in VTP version 2     14-4

console port, connecting to     2-9

conventions

command     xx

for examples     xx

publication     xx

text     xx

CoS

configuring     24-2

configuring priority queues     24-9

defining     24-3

override priority     15-5

trust priority     15-5

counters, clearing interface     8-15

crashinfo file     26-16

D

daylight saving time     5-13

debugging

enabling all system diagnostics     26-15

enabling for a specific feature     26-14

redirecting error message output     26-15

using commands     26-14

default commands     2-3

default configuration

802.1x     7-9

banners     5-18

CDP     19-2

DNS     5-17

EtherChannel     25-8

IGMP filtering     16-21

IGMP snooping     16-7

IGMP throttling     16-21

initial switch information     3-3

Layer 2 interfaces     8-9

MAC address table     5-22

MSTP     11-12

MVR     16-16

NTP     5-4

optional spanning-tree features     12-10

password and privilege level     6-2

port security     17-6

QoS     24-4

RADIUS     6-20

RMON     21-3

RSPAN     20-5

SNMP     23-5

SPAN     20-5

storm control     17-2

STP     10-11

system message logging     22-3

system name and prompt     5-15

TACACS+     6-13

UDLD     18-4

default configuration (continued)

VLAN, Layer 2 Ethernet interfaces     13-16

VLANs     13-7

VMPS     13-26

voice VLAN     15-2

VTP     14-6

default gateway     3-10

deleting VLANs     13-9

description command     8-14

detecting indirect link failures, STP     12-5

device discovery protocol     19-1

device manager

described     1-1, 1-6

DHCP-based autoconfiguration

client request message exchange     3-4

configuring

client side     3-3

DNS     3-6

relay device     3-6

server-side     3-5

TFTP server     3-5

example     3-8

lease options

for IP address information     3-5

for receiving the configuration file     3-5

overview     3-3

relationship to BOOTP     3-3

DNS

and DHCP-based autoconfiguration     3-6

default configuration     5-17

displaying the configuration     5-18

overview     5-16

setting up     5-17

documentation, related     xx

document conventions     xx

domain names

DNS     5-16

VTP     14-8

Domain Name System

See DNS

downloading

image files

using HTTP     1-2

using Network Assistant     1-2

DTP     1-4, 13-15

duplex mode, configuring     8-10

dynamic access ports

characteristics     13-3

configuring     13-27

defined     8-2

dynamic addresses

See addresses

dynamic desirable trunking mode     13-15

dynamic port VLAN membership

described     13-25

reconfirming     13-28

troubleshooting     13-30

types of connections     13-27

VMPS database configuration file     13-25

Dynamic Trunking Protocol

See DTP

E

editing features

enabling and disabling     2-6

keystrokes used     2-6

wrapped lines     2-7

enable password     6-4

enable secret password     6-4

encapsulation     24-2

encryption for passwords     6-4

error messages

during command entry     2-4

setting the display destination device     22-4

severity levels     22-8

system message format     22-2

EtherChannel

automatic creation of     25-3

configuration guidelines     25-8

default configuration     25-8

destination MAC address forwarding     25-6

displaying status     25-14

forwarding methods     25-11

load balancing     25-6, 25-11

number of interfaces per     25-2

overview     25-1

PAgP

aggregate-port learners     25-5

compatibility with Catalyst 1900     25-12

displaying status     25-14

interaction with other features     25-6

learn method and priority configuration     25-12

modes     25-4

overview     25-3

silent mode     25-4

support for     1-2

port-channel interfaces

described     25-2

numbering of     25-2

port groups     8-3

source MAC address forwarding     25-6

EtherChannel guard

described     12-7

enabling     12-14

Ethernet VLANs

adding     13-8

defaults and ranges     13-7

modifying     13-8

events, RMON     21-3

examples

conventions for     xx

network configuration     1-8

extended-range VLANs

configuration guidelines     13-12

configuring     13-11

extended-range VLANs (continued)

creating     13-12

defined     13-1

extended system ID

MSTP     11-14

STP     10-3, 10-14

Extensible Authentication Protocol over LAN     7-1

F

fallback VLAN name     13-26

fiber-optic, detecting unidirectional links     18-1

files, crashinfo

description     26-16

displaying the contents of     26-16

location     26-16

filtering show and more command output     2-8

flow control     8-12

forward-delay time

MSTP     11-20

STP     10-5, 10-21

forwarding

See storm control

FTP

accessing MIB files     A-2

G

GBICs

security and identification     26-11

get-bulk-request operation     23-3

get-next-request operation     23-3, 23-4

get-request operation     23-3, 23-4

get-response operation     23-3

global configuration mode     2-2

guide

audience     xix

purpose of     xix

guide mode     1-1

GUIs

See device manager and Network Assistant     1-6

H

hello time

MSTP     11-19

STP     10-20

help, for the command line     2-3

history

changing the buffer size     2-4

described     2-4

disabling     2-5

recalling commands     2-5

history table, level and number of syslog messages     22-10

hosts, limit on dynamic ports     13-30

HP OpenView     1-7

I

ICMP ping

executing     26-12

overview     26-11

IDS, using with SPAN     20-2

IEEE 802.1p     15-1

IGMP

joining multicast group     16-3

join messages     16-3

leave processing, enabling     16-10

leaving multicast group     16-5

queries     16-3

report suppression

described     16-5

disabling     16-11

throttling action     16-21

IGMP, joining multicast group     16-3

IGMP filtering

configuring     16-21

default configuration     16-21

described     16-20

monitoring     16-26

IGMP groups

configuring the throttling action     16-24

setting the maximum number     16-24

IGMP profile

applying     16-23

configuration mode     16-21

configuring     16-22

IGMP snooping

configuring     16-6

default configuration     16-7

definition     16-2

enabling and disabling     16-7

global configuration     16-7

Immediate Leave     16-5

method     16-8

monitoring     16-12

VLAN configuration     16-8

IGMP throttling

configuring     16-24

default configuration     16-21

described     16-21

displaying action     16-26

Immediate-Leave, IGMP     16-5

ingress port scheduling     24-3

interface

number     8-4

range macros     8-7

interface command     8-4, 8-5

interface configuration mode     2-2

interfaces

Cisco IOS supported     1-6

configuration guidelines     8-10

configuring     8-5

configuring duplex mode     8-10

interfaces (continued)

configuring speed     8-10

counters, clearing     8-15

described     8-14

descriptive name, adding     8-14

displaying information about     8-14

flow control     8-12

IOS supported     1-6

monitoring     8-14

naming     8-14

physical, identifying     8-4

range of     8-5

restarting     8-16

shutting down     8-16

supported     8-8

types of     8-1

interfaces range macro command     8-7

Intrusion Detection System

See IDS

IP addresses

candidate or member     4-2

command switch     4-2

discovering     5-26

See also IP information

ip igmp profile command     16-21

IP information

assigned

manually     3-9

through DHCP-based autoconfiguration     3-3

default configuration     3-3

IP multicast routing and IGMP snooping     16-2, 16-6

IP phones

and 802.1x authentication     7-7

and QoS     15-1

configuring     15-3

trusted boundary for QoS     24-7

IPv4     1-1

IPv6     1-1

IP version 4     1-1

IP version 6     1-1

J

join messages, IGMP     16-3

L

LACP

See EtherChannel

Layer 2 frames, classification with CoS     24-1

Layer 2 interfaces, default configuration     8-9

Layer 2 traceroute

and ARP     26-13

and CDP     26-13

described     26-13

IP addresses and subnets     26-13

MAC addresses and VLANs     26-13

multicast traffic     26-13

multiple devices on a port     26-14

unicast traffic     26-13

usage guidelines     26-13

leave processing, IGMP     16-10

line configuration mode     2-2

links, unidirectional     18-1

login authentication

with RADIUS     6-23

with TACACS+     6-14

login banners     5-18

log messages

See system message logging

loop guard

described     12-9

enabling     12-16

support for     1-4

M

MAC addresses

aging time     5-22

and VLAN association     5-21

building the address table     5-21

default configuration     5-22

discovering     5-26

displaying     5-26

dynamic

learning     5-21

removing     5-23

static

adding     5-25

characteristics of     5-25

removing     5-25

sticky secure, adding     17-5

MAC address multicast entries, monitoring     16-13

MAC address-to-VLAN mapping     13-24

macros

See Smartports macros

management options

benefits

clustering     1-7

Network Assistant     1-7

CLI     2-1

Network Assistant     1-1

overview     1-6

maximum aging time

MSTP     11-21

STP     10-21

maximum hop count, MSTP     11-21

membership mode, VLAN port     13-3

member switch

defined     4-1

managing     4-3

recovering from lost connectivity     26-10

requirements     4-2

member switch (continued)

See also candidate switch, cluster standby group, and standby command switch

messages to users through banners     5-18

MIBs

accessing files with FTP     A-2

location of files     A-2

overview     23-1

SNMP interaction with     23-4

supported     A-1

mirroring traffic for analysis     20-1

mismatches, autonegotiation     26-10

monitoring

cables for unidirectional links     18-1

CDP     19-5

IGMP

filters     16-26

snooping     16-12

interfaces     8-14

multicast router interfaces     16-13

MVR     16-20

network traffic for analysis with probe     20-1

port protection     17-11

speed and duplex mode     8-11

traffic flowing among switches     21-1

traffic suppression     17-11

VLANs     13-13

VMPS     13-29

VTP     14-15

MSTP

boundary ports

configuration guidelines     11-12

described     11-5

BPDU filtering

described     12-3

enabling     12-12

MSTP (continued)

BPDU guard

described     12-2

enabling     12-11

CIST, described     11-3

configuration guidelines     11-12, 12-10

configuring

forward-delay time     11-20

hello time     11-19

link type for rapid convergence     11-22

maximum aging time     11-21

maximum hop count     11-21

MST region     11-13

path cost     11-18

port priority     11-17

root switch     11-14

secondary root switch     11-16

switch priority     11-19

CST

defined     11-3

operations between regions     11-3

default configuration     11-12

default optional feature configuration     12-10

described     11-2

displaying status     11-23

enabling the mode     11-13

EtherChannel guard

described     12-7

enabling     12-14

extended system ID

effects on root switch     11-14

effects on secondary root switch     11-16

unexpected behavior     11-15

instances supported     10-9

interface state, blocking to forwarding     12-2

interoperability and compatibility among modes     10-10

interoperability with 802.1D

described     11-5

restarting migration process     11-22

MSTP (continued)

IST

defined     11-2

master     11-3

operations within a region     11-3

loop guard

described     12-9

enabling     12-16

mapping VLANs to MST instance     11-13

MST region

described     11-2

hop-count mechanism     11-4

supported spanning-tree instances     11-2

Port Fast

described     12-2

enabling     12-10

preventing root switch selection     12-8

root guard

described     12-8

enabling     12-15

root switch

configuring     11-15

effects of extended system ID     11-14

unexpected behavior     11-15

shutdown Port Fast-enabled port     12-2

multicast groups

and IGMP snooping     16-6

Immediate Leave     16-5

joining     16-3

leaving     16-5

static joins     16-9

multicast router interfaces, monitoring     16-13

multicast router ports, adding     16-9

multicast storm control

See storm control

Multicast VLAN Registration

See MVR

Multiple Spanning Tree Protocol

See MSTP

MVR

configuring interfaces     16-18

default configuration     16-16

described     16-13

modes     16-17

monitoring     16-20

setting global parameters     16-17

N

native VLAN

configuring     13-20

default     13-20

Network Assistant

advantages with switch clustering     1-7

described     1-6

guide mode     1-1

management options     1-1

wizards     1-2

network examples

collapsed backbone and switch cluster     1-10

design concepts

network performance     1-8

network services     1-8

large campus     1-11

small to medium-sized network     1-9

network management

CDP     19-1

RMON     21-1

SNMP     23-1

Network Time Protocol

See NTP

no commands     2-3

nontrunking mode     13-15

normal-range VLANs

configuration modes     13-6

defined     13-1

note, described     xx

NTP

associations

authenticating     5-4

defined     5-2

enabling broadcast messages     5-6

peer     5-5

server     5-5

default configuration     5-4

displaying the configuration     5-10

overview     5-2

restricting access

creating an access group     5-8

disabling NTP services per interface     5-9

source IP address, configuring     5-10

stratum     5-2

synchronizing devices     5-5

time

services     5-2

synchronizing     5-2

P

PAgP

See EtherChannel

pass-through mode     24-8

passwords

default configuration     6-2

disabling recovery of     6-5

encrypting     6-4

overview     6-1

setting

enable     6-3

enable secret     6-4

Telnet     6-6

with usernames     6-7

VTP domain     14-8

path cost

MSTP     11-18

STP     10-18

per-VLAN spanning-tree plus

See PVST+

physical ports     8-1

PIM-DVMRP, as snooping method     16-8

ping

character output description     26-12

executing     26-12

overview     26-11

Port Aggregation Protocol

See EtherChannel

See PAgP

port-based authentication

accounting     7-5

accounting services     1-5

authentication server

defined     7-2

RADIUS server     7-2

client, defined     7-2

configuration guidelines     7-10

configuring

802.1x accounting     7-21

802.1x authentication     7-11, 7-19

guest VLAN     7-17

host mode     7-17

manual re-authentication of a client     7-14

periodic re-authentication     7-14

quiet period     7-15

RADIUS server     7-14

RADIUS server parameters on the switch     7-13

switch-to-client frame-retransmission number     7-16

switch-to-client retransmission time     7-15

default configuration     7-9

described     7-1

device roles     7-2

displaying statistics     7-22

EAPOL-start frame     7-3

port-based authentication (continued)

EAP-request/identity frame     7-3

EAP-response/identity frame     7-3

enabling

802.1x with guest VLAN     7-8

802.1x with port security     7-6

802.1x with VLAN assignment     7-7, 7-11

802.1x with voice VLAN     7-7

encapsulation     7-3

guest VLAN

configuration guidelines     7-8

host mode     7-5

initiation and message exchange     7-3

method lists     7-11, 7-19

multiple-hosts mode, described     7-5

per-user ACLs, AAA authorization     7-19

ports

authorization state and dot1x port-control command     7-4

authorized and unauthorized     7-4

port security, multiple-hosts mode     7-5

resetting to default values     7-19

software upgrade changes     7-11

switch

as proxy     7-2

RADIUS client     7-2

VLAN assignment, AAA authorization     7-19

port-channel

See EtherChannel

Port Fast

described     12-2

enabling     12-10

mode, spanning tree     13-26

support for     1-4

port membership modes, VLAN     13-3

port priority

MSTP     11-17

STP     10-16

ports

access     8-2

dynamic access     13-3

priority     24-2

protected     17-3

secure     17-4

static-access     13-3, 13-10

switch     8-1

trunks     13-14

VLAN assignments     13-10

port security

aging     17-9

configuration guidelines     17-6

configuring     17-7

default configuration     17-6

described     17-4

displaying     17-11

sticky learning     17-5

violations     17-5

with other features     17-6

port-shutdown response, VMPS     13-25

preferential treatment of traffic

See QoS

preventing unauthorized access     6-1

priority

overriding CoS     15-5

port, described     24-2

trusting CoS     15-5

private VLAN edge ports

See protected ports

privileged EXEC mode     2-2

privilege levels

changing the default for lines     6-9

command switch     4-3

exiting     6-10

logging into     6-10

mapping on member switches     4-3

overview     6-2, 6-8

setting a command with     6-8

protected ports     1-3, 17-3

pruning, VTP

enabling     14-13

enabling on a port     13-19

examples     14-5

overview     14-4

pruning-eligible list

changing     13-19

for VTP pruning     14-4

VLANs     14-13

PSTN     1-11

publications, related     xx

PVST+

802.1Q trunking interoperability     10-10

described     10-9

instances supported     10-9

Q

QoS

classification

in frames and packets     24-2

pass-through mode, described     24-8

trusted boundary, described     24-7

configuring

CoS and WRR     24-9

default port CoS value     24-6

egress queues     24-9

port trust states within the domain     24-4

trusted boundary     24-7

default configuration     24-4

ingress port scheduling     24-3

IP phones, detection and trusted settings     24-7

overview     24-1

pass-through mode     24-8

support for     1-5

trusted boundary     24-7

understanding     24-1

quality of service

See QoS

queries, IGMP     16-3

R

RADIUS

attributes

vendor-proprietary     6-30

vendor-specific     6-29

configuring

accounting     6-28

authentication     6-23

authorization     6-27

communication, global     6-21, 6-29

communication, per-server     6-20, 6-21

multiple UDP ports     6-21

default configuration     6-20

defining AAA server groups     6-25

described     6-18

displaying the configuration     6-31

identifying the server     6-20

limiting the services to the user     6-27

method list, defined     6-20

operation of     6-19

suggested network environments     6-18

tracking services accessed by user     6-28

range

macro     8-7

of interfaces     8-6

rapid convergence     11-7

rapid per-VLAN spanning-tree plus

See rapid PVST+

rapid PVST+

802.1Q trunking interoperability     10-10

described     10-9

instances supported     10-9

Rapid Spanning Tree Protocol

See RSTP

rcommand command     4-3

reconfirmation interval, VMPS, changing     13-28

recovery procedures     26-1

redundancy

EtherChannel     25-2

STP

backbone     10-7

path cost     13-23

port priority     13-21

redundant links and UplinkFast     12-13

Remote Authentication Dial-In User Service

See RADIUS

Remote Network Monitoring

See RMON

report suppression, IGMP

described     16-5

disabling     16-11

resetting a UDLD-shutdown interface     18-6

restricting access

NTP services     5-8

overview     6-1

passwords and privilege levels     6-2

RADIUS     6-17

TACACS+     6-10

retry count, VMPS, changing     13-29

RFC

1112, IP multicast and IGMP     16-2

1157, SNMPv1     23-2

1305, NTP     5-2

1757, RMON     21-2

1901, SNMPv2C     23-2

1902 to 1907, SNMPv2     23-2

2236, IP multicast and IGMP     16-2

2273-2275, SNMPv3     23-2

RMON

default configuration     21-3

displaying status     21-6

enabling alarms and events     21-3

groups supported     21-2

RMON (continued)

overview     21-1

statistics

collecting group Ethernet     21-5

collecting group history     21-5

root guard

described     12-8

enabling     12-15

support for     1-4

root switch

MSTP     11-14

STP     10-14

RSPAN

default configuration     20-5

displaying status     20-10

interaction with other features     20-4

overview     20-1

sessions

defined     20-2

RSTP

active topology, determining     11-6

BPDU

format     11-9

processing     11-10

designated port, defined     11-6

designated switch, defined     11-6

interoperability with 802.1D

described     11-5

restarting migration process     11-22

topology changes     11-10

overview     11-6

port roles

described     11-6

synchronized     11-8

proposal-agreement handshake process     11-7

rapid convergence

described     11-7

edge ports and Port Fast     11-7

point-to-point links     11-7, 11-22

RSTP (continued)

rapid convergence (continued)

root ports     11-7

root port, defined     11-6

See also MSTP

running configuration, saving     3-10

S

secure ports, configuring     17-4

secure remote connections     6-33

Secure Shell

See SSH

security, port     17-4

sequence numbers in log messages     22-8

server mode, VTP     14-3

service-provider network, MSTP and RSTP     11-1

set-request operation     23-4

setup program, failed command switch replacement     26-7, 26-9

severity levels, defining in system messages     22-8

show and more command output, filtering     2-8

show cdp traffic command     19-5

show cluster members command     4-3

show configuration command     8-14

show interfaces command     8-11, 8-14

show running-config command

interface description in     8-14

shutdown command on interfaces     8-16

Simple Network Management Protocol

See SNMP

Smartports macros

applying Cisco-default macros     9-6

applying global parameter values     9-5, 9-6

applying macros     9-5

applying parameter values     9-5, 9-7

configuration guidelines     9-2

creating     9-4

default configuration     9-2

Smartports macros (continued)

defined     9-1

displaying     9-8

tracing     9-3

website     9-2

SNAP     19-1

SNMP

accessing MIB variables with     23-4

agent

described     23-3

disabling     23-7

community strings

configuring     23-7

for cluster switches     23-4

overview     23-4

configuration examples     23-14

default configuration     23-5

groups     23-8

informs

and trap keyword     23-10

described     23-4

differences from traps     23-5

enabling     23-12

limiting access by TFTP servers     23-13

limiting system log messages to NMS     22-10

manager functions     23-3

managing clusters with     4-4

MIBs

location of     A-2

supported     A-1

notifications     23-4

overview     23-1, 23-4

status, displaying     23-15

system contact and location     23-13

trap manager, configuring     23-11

traps

described     23-3, 23-4

differences from informs     23-5

enabling     23-10

SNMP (continued)

traps (continued)

enabling MAC address notification     5-23

overview     23-1, 23-4

types of     23-10

users     23-8

versions supported     23-2

snooping, IGMP     16-2

software images

recovery procedures     26-2

See also downloading and uploading

SPAN

configuration guidelines     20-5

default configuration     20-5

destination ports     20-3

displaying status     20-10

IDS     20-2

interaction with other features     20-4

monitored ports     20-3

monitoring ports     20-3

overview     1-5, 20-1

ports, restrictions     17-7

received traffic     20-2

session limits     20-5

sessions

creating     20-6

defined     20-2

removing destination (monitoring) ports     20-9

removing source (monitored) ports     20-9

specifying monitored ports     20-6

source ports     20-3

transmitted traffic     20-3

spanning tree and native VLANs     13-16

Spanning Tree Protocol

See STP

speed

configuring on interfaces     8-10

SSH

configuring     6-34

cryptographic software image     6-33

described     6-33

encryption methods     6-33

user authentication methods, supported     6-34

standby command switch, requirements     4-2

static access ports

assigning to VLAN     13-10

defined     8-2, 13-3

static addresses

See addresses

static VLAN membership     13-2

statistics

802.1x     7-22

CDP     19-5

interface     8-15

RMON group Ethernet     21-5

RMON group history     21-5

SNMP input and output     23-15

VTP     14-15

sticky learning

configuration file     17-5

defined     17-5

disabling     17-5

enabling     17-5

saving addresses     17-5

storm control

configuring     17-2

default configuration     17-2

described     17-1

disabling     17-3

displaying     17-11

STP

accelerating root port selection     12-4

BackboneFast

described     12-5

enabling     12-14

STP (continued)

BPDU filtering

described     12-3

enabling     12-12

BPDU guard

described     12-2

enabling     12-11

BPDU message exchange     10-2

configuration guidelines     10-11, 12-10

configuring

forward-delay time     10-21

hello time     10-20

maximum aging time     10-21

path cost     10-18

port priority     10-16

root switch     10-14

secondary root switch     10-16

spanning-tree mode     10-12

switch priority     10-19

counters, clearing     10-22

default configuration     10-11

default optional feature configuration     12-10

designated port, defined     10-3

designated switch, defined     10-3

detecting indirect link failures     12-5

disabling     10-13

displaying status     10-22

EtherChannel guard

described     12-7

enabling     12-14

extended system ID

affects on root switch     10-14

affects on the secondary root switch     10-16

overview     10-3

unexpected behavior     10-14

features supported     1-4

inferior BPDU     10-3

instances supported     10-9

interface state, blocking to forwarding     12-2

STP (continued)

interface states

blocking     10-5

disabled     10-6

forwarding     10-5, 10-6

learning     10-6

listening     10-6

overview     10-4

interoperability and compatibility among modes     10-10

limitations with 802.1Q trunks     10-10

load sharing

overview     13-21

using path costs     13-23

using port priorities     13-21

loop guard

described     12-9

enabling     12-16

modes supported     10-9

multicast addresses, affect of     10-8

overview     10-2

path costs     13-23

Port Fast

described     12-2

enabling     12-10

port priorities     13-22

preventing root switch selection     12-8

protocols supported     10-9

redundant connectivity     10-7

root guard

described     12-8

enabling     12-15

root port, defined     10-3

root switch

affects of extended system ID     10-3, 10-14

configuring     10-14

election     10-3

unexpected behavior     10-14

shutdown Port Fast-enabled port     12-2

superior BPDU     10-3

STP (continued)

timers, described     10-20

UplinkFast

described     12-3

enabling     12-13

stratum, NTP     5-2

summer time     5-13

SunNet Manager     1-7

switch clustering technology

See clusters, switch

switched ports     8-1

switchport protected command     17-3

switch priority

MSTP     11-19

STP     10-19

syslog

See system message logging

system clock

configuring

daylight saving time     5-13

manually     5-11

summer time     5-13

time zones     5-12

displaying the time and date     5-12

overview     5-1

See also NTP

system message logging

default configuration     22-3

defining error message severity levels     22-8

disabling     22-4

displaying the configuration     22-12

enabling     22-4

facility keywords, described     22-12

level keywords, described     22-9

limiting messages     22-10

message format     22-2

overview     22-1

sequence numbers, enabling and disabling     22-8

setting the display destination device     22-4

system message logging (continued)

synchronizing log messages     22-6

timestamps, enabling and disabling     22-7

UNIX syslog servers

configuring the daemon     22-11

configuring the logging facility     22-11

facilities supported     22-12

system name

default configuration     5-15

default setting     5-15

manual configuration     5-15

See also DNS

system prompt

default setting     5-15

manual configuration     5-16

T

TACACS+

accounting, defined     6-11

authentication, defined     6-11

authorization, defined     6-11

configuring

accounting     6-17

authentication key     6-13

authorization     6-16

login authentication     6-14

default configuration     6-13

displaying the configuration     6-17

identifying the server     6-13

limiting the services to the user     6-16

operation of     6-12

overview     6-10

tracking services accessed by user     6-17

Telnet

accessing management interfaces     2-9

accessing the CLI     1-6

setting a password     6-6

Terminal Access Controller Access Control System Plus

See TACACS+

terminal lines, setting a password     6-6

TFTP

configuration files in base directory     3-6

configuring for autoconfiguration     3-5

limiting access by servers     23-13

time

See NTP and system clock

timestamps in log messages     22-7

time zones     5-12

Token Ring VLANs

support for     13-5

VTP support     14-4

traceroute, Layer 2

and ARP     26-13

and CDP     26-13

described     26-13

IP addresses and subnets     26-13

MAC addresses and VLANs     26-13

multicast traffic     26-13

multiple devices on a port     26-14

unicast traffic     26-13

usage guidelines     26-13

transparent mode, VTP     14-3, 14-11

trap-door mechanism     3-2

traps

configuring MAC address notification     5-23

configuring managers     23-10

defined     23-3

enabling     5-23, 23-10

notification types     23-10

overview     23-1, 23-4

troubleshooting

connectivity problems     26-11

detecting unidirectional links     18-1

displaying crash information     26-16

GBIC security and identification     26-11

with CiscoWorks     23-4

troubleshooting (continued)

with debug commands     26-14

with ping     26-11

with system message logging     22-1

trunk ports

configuring     13-17

defined     8-2

trunks

allowed-VLAN list     13-18

load sharing

setting STP path costs     13-23

using STP port priorities     13-21, 13-22

native VLAN for untagged traffic     13-20

parallel     13-23

pruning-eligible list     13-19

to non-DTP device     13-15

VLAN 1 minimization     13-18

trusted boundary     24-7

twisted-pair Ethernet, detecting unidirectional links     18-1

U

UDLD

default configuration     18-4

echoing detection mechanism     18-3

enabling

globally     18-5

per interface     18-5

link-detection mechanism     18-1

neighbor database     18-2

overview     18-1

resetting an interface     18-6

status, displaying     18-7

unauthorized ports with 802.1x     7-4

unicast storm control

See storm control

UniDirectional Link Detection protocol

See UDLD

UNIX syslog servers

daemon configuration     22-11

facilities supported     22-12

message logging configuration     22-11

unrecognized Type-Length-Value (TLV) support     14-4

UplinkFast

described     12-3

enabling     12-13

support for     1-4

user EXEC mode     2-2

username-based authentication     6-7

V

version-dependent transparent mode     14-4

vlan.dat file     13-4

VLAN 1 minimization, support for     1-4

VLAN configuration

at bootup     13-7

saving     13-7

VLAN configuration mode     2-2, 13-6

VLAN database

and startup configuration file     13-7

and VTP     14-1

VLAN configuration saved in     13-7

VLANs saved in     13-4

vlan database command     13-6

vlan global configuration command     13-6

VLAN ID, discovering     5-26

VLAN management domain     14-2

VLAN Management Policy Server

See VMPS

VLAN membership

confirming     13-28

modes     13-3

VLAN Query Protocol

See VQP

VLANs

adding     13-8

adding to VLAN database     13-8

aging dynamic addresses     10-8

allowed on trunk     13-18

and spanning-tree instances     13-2, 13-6, 13-12

configuration guidelines, normal-range VLANs     13-5

configuration options     13-6

configuring     13-1

configuring IDs 1006 to 4094     13-12

creating in config-vlan mode     13-8

creating in VLAN configuration mode     13-9

default configuration     13-7

deleting     13-9

described     8-3, 13-1

displaying     13-13

extended-range     13-1, 13-11

illustrated     13-2

modifying     13-8

native, configuring     13-20

normal-range     13-1, 13-4

parameters     13-4

port membership modes     13-3

static-access ports     13-10

STP and 802.1Q trunks     10-10

supported     13-2

Token Ring     13-5

trunks, VLAN 1 minimization     13-18

VTP modes     14-3

VLAN Trunking Protocol

See VTP

VLAN trunks     13-14

VMPS

administering     13-29

configuration example     13-30

configuration guidelines     13-26

default configuration     13-26

description     13-24

dynamic port membership

VMPS (continued)

described     13-25

reconfirming     13-28

troubleshooting     13-30

entering server address     13-27

mapping MAC addresses to VLANs     13-24

monitoring     13-29

reconfirmation interval, changing     13-28

reconfirming membership     13-28

retry count, changing     13-29

voice VLAN

Cisco 7960 phone, port connections     15-1

configuration guidelines     15-3

configuring IP phones for data traffic

override CoS of incoming frame     15-5

trust CoS priority of incoming frame     15-5

configuring ports for voice traffic in

802.1p priority tagged frames     15-4

802.1Q frames     15-4

connecting to an IP phone     15-3

default configuration     15-2

described     15-1

displaying     15-6

VQP     13-24

VTP

adding a client to a domain     14-14

advertisements     13-17, 14-3

and extended-range VLANs     14-1

and normal-range VLANs     14-1

client mode, configuring     14-10

configuration

global configuration mode     14-7

guidelines     14-8

privileged EXEC mode     14-7

requirements     14-9

saving     14-7

VLAN configuration mode     14-7

configuration mode options     14-7

configuration requirements     14-9

VTP (continued)

configuration revision number

guideline     14-14

resetting     14-14

configuring

client mode     14-10

server mode     14-9

transparent mode     14-11

consistency checks     14-4

default configuration     14-6

described     14-1

disabling     14-11

domain names     14-8

domains     14-2

modes

client     14-3, 14-10

server     14-3, 14-9

transitions     14-3

transparent     14-3, 14-11

monitoring     14-15

passwords     14-8

pruning

disabling     14-13

enabling     14-13

examples     14-5

overview     14-4

pruning-eligible list, changing     13-19

server mode, configuring     14-9

statistics     14-15

Token Ring support     14-4

transparent mode, configuring     14-11

using     14-1

version, guidelines     14-8

version 1     14-4

version 2

configuration guidelines     14-8

disabling     14-13

enabling     14-12

overview     14-4

W

Weighted Round Robin

See WRR

wizards     1-2

WRR

configuring     24-9

defining     24-3

description     24-3

X

Xmodem protocol     26-2