Table Of Contents
Numerics - A - B - C - D - E - F - G - H - I - J - L - M - N - P - Q - R - S - T - U - V - W -
Index
Numerics
802.1X Port Based Authentication
enabling guest VLAN supplicant 2-78
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5
AAA methods 2-3
abort command 2-622
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-123
MAC
configuring 2-204
displaying 2-400
access-list hardware program nonblocking command 2-6
access lists
IP 2-123
on Layer 2 interfaces 2-123, 2-204
access map configuration mode 2-224
access mode 2-569
access ports 2-569
ACEs 2-73, 2-268
ACLs
deny 2-71
displaying 2-302
for non-IP protocols 2-206
ACLs (continued)
matching 2-224
permit 2-266
action command 2-8
aggregate-port learner 2-262
allowed VLANs 2-586
apply command 2-622
archive download-sw command 2-10
archive tar command 2-13
archive upload-sw command 2-16
arp access-list command 2-18
audience xvii
authorization state of controlled port 2-99
autonegotiation of duplex mode 2-107
auto qos voip command 2-20
B
BackboneFast, for STP 2-505
backup interfaces
configuring 2-562
displaying 2-357
boot (boot loader) command A-2
boot boothlpr command 2-24
boot buffersize command 2-25
boot config-file command 2-26
boot enable-break command 2-27
boot helper command 2-28
boot helper-config file command 2-29
booting
Cisco IOS image 2-32
displaying environment variables 2-308
booting (continued)
interrupting 2-27
manually 2-30
boot loader
accessing A-1
booting
Cisco IOS image A-2
helper image 2-28
directories
creating A-15
displaying a list of A-6
removing A-19
displaying
available commands A-11
memory heap utilization A-13
version A-26
environment variables
described A-20
displaying settings A-20
location of A-21
setting A-20
unsetting A-24
files
copying A-4
deleting A-5
displaying a list of A-6
displaying the contents of A-3, A-16, A-23
renaming A-17
file system
formatting A-9
initializing flash A-8
running a consistency check A-10
loading helper images A-12
prompt A-1
resetting the system A-18
boot manual command 2-30
boot private-config-file command 2-31
boot system command 2-32
BPDU filtering, for spanning tree 2-506, 2-539
BPDU guard, for spanning tree 2-508, 2-539
broadcast storm control 2-553
C
candidate switches
See clusters
cat (boot loader) command A-3
caution, description xviii
CDP, enabling protocol tunneling for 2-194
channel-group command 2-33
channel-protocol command 2-37
Cisco SoftPhone
auto-QoS configuration 2-20
trusting packets sent from 2-249
class command 2-39
class-map command 2-41
class maps
creating 2-41
defining the match criteria 2-226
displaying 2-310
class of service
See CoS
clear ip arp inspection log command 2-43
clear ip arp inspection statistics command 2-44
clear l2protocol-tunnel counters command 2-45
clear lacp command 2-46
clear mac address-table command 2-47
clear pagp command 2-49
clear spanning-tree counters command 2-52
clear spanning-tree detected-protocols command 2-53
clear vmps statistics command 2-54
clear vtp counters command 2-55
cluster commander-address command 2-56
cluster discovery hop-count command 2-58
cluster enable command 2-59
cluster holdtime command 2-60
cluster member command 2-61
cluster outside-interface command 2-63
cluster run command 2-64
clusters
adding candidates 2-61
binding to HSRP group 2-65
building manually 2-61
communicating with
devices outside the cluster 2-63
members by using Telnet 2-283
debug messages, display B-6
displaying
candidate switches 2-313
debug messages B-6
member switches 2-315
status 2-311
hop-count limit for extended discovery 2-58
HSRP standby groups 2-65
redundancy 2-65
SNMP trap 2-493
cluster standby-group command 2-65
cluster timer command 2-67
command modes defined 1-1
command switch
See clusters
configuration conflicts, ACL, displaying 2-346
configuration files
password recovery disable considerations A-1
setting the NVRAM size for 2-25
specifying the name 2-26, 2-31
configuring multiple interfaces 2-119
config-vlan mode
commands 2-608
description 1-4
entering 2-607
summary 1-2
conventions
command xviii
for examples xviii
publication xviii
text xviii
copy (boot loader) command A-4
CoS
assigning default value to incoming packets 2-236
assigning to Layer 2 protocol packets 2-197
defining in a policy map 2-238
overriding the incoming value 2-236
CoS-to-DSCP map 2-242
CoS-to-egress-queue map 2-646
CPU ASIC
debug messages, display B-8
statistics display 2-317
CPU statistics, displaying 2-317
cross-stack UplinkFast, for STP 2-543
D
debug acltcam command B-2
debug auto qos command B-3
debug backup command B-5
debug cluster command B-6
debug cpu-interface command B-8
debug dot1x command B-9
debug eap command B-11
debug etherchannel command B-12
debug ethernet-controller ram-access command B-13
debug fallback-bridging command B-14
debug gigastack command B-15
debug ilpower controller command B-16
debug ilpower event command B-17
debug ip dhcp snooping command B-18
debug ip igmp filter command B-19
debug ip igmp max-groups command B-20
debug ip verify source packet command B-21
debug l3multicast command B-22
debug l3tcam command B-23
debug l3unicast command B-24
debug mac-manager command B-25
debug mac-notification command B-26
debug met command B-27
debug mvrdbg command B-28
debug pagp command B-29
debug pbr command B-30
debug platform ip arp inspection command B-31
debug pm command B-32
debug port-security command B-34
debug spanning-tree backbonefast command B-38
debug spanning-tree bpdu command B-39
debug spanning-tree bpdu-opt command B-40
debug spanning-tree command B-36
debug spanning-tree mstp command B-41
debug spanning-tree switch command B-43
debug spanning-tree uplinkfast command B-45
debug span-session command B-35
debug sw-vlan command B-46
debug sw-vlan ifs command B-48
debug sw-vlan notification command B-49
debug sw-vlan vtp command B-51
debug udld command B-53
define interface-range command 2-68
delete (boot loader) command A-5
delete command 2-70
deny (ARP access-list configuration) command 2-74
deny command 2-71
detect mechanism, causes 2-109
DHCP snooping
accepting untrusted packets form edge switch 2-150
displaying
bindings 2-374
configuration 2-373
enabling
on a VLAN 2-157
option 82 2-148, 2-150, 2-153
trust on an interface 2-155
error recovery timer 2-111
rate limiting 2-154
DHCP snooping binding database
binding file, configuring 2-145
bindings
DHCP snooping binding database (continued)
adding 2-143
deleting 2-143
database agent, configuring 2-145
displaying
database agent status 2-376
dir (boot loader) command A-6
directories, deleting 2-70
documentation
related xviii
document conventions xviii
domain name, VTP 2-634, 2-640
dot1x auth-fail max-attempts 2-78
dot1x auth-fail vlan 2-80
dot1x command 2-76
dot1x control-direction command 2-82
dot1x critical global configuration command 2-84
dot1x critical interface configuration command 2-86
dot1x default command 2-88
dot1x guest-vlan command 2-89
dot1x host-mode command 2-91
dot1x initialize command 2-92
dot1x mac-auth-bypass command 2-93
dot1x max-req command 2-95, 2-96
dot1x multiple-hosts command 2-97
dot1x pae command 2-98
dot1x port-control command 2-99
dot1x re-authenticate command 2-101
dot1x re-authentication command 2-102
dot1x reauthentication command 2-103
dropping packets, with ACL matches 2-8
drop threshold, Layer 2 protocol tunneling 2-194
DSCP-to-CoS map 2-242
DSCP-to-DSCP-mutation map 2-242
DSCP-to-threshold map 2-648
DTP 2-570
DTP flap
error detection for 2-109
error recovery timer 2-111
duplex command 2-107
dynamic-access ports
configuring 2-560
restrictions 2-561
dynamic ARP inspection
ARP ACLs
apply to a VLAN 2-127
define 2-18
deny packets 2-74
display 2-369
permit packets 2-269
clear
log buffer 2-43
statistics 2-44
display
ARP ACLs 2-369
configuration and operating state 2-370
log buffer 2-370
statistics 2-370
trust state and rate limit 2-370
enable per VLAN 2-137
error detection for 2-109
error recovery timer 2-111
log buffer
clear 2-43
configure 2-131
display 2-370
rate-limit incoming ARP packets 2-129
statistics
clear 2-44
display 2-370
trusted interface state 2-133
type of packet logged 2-139
validation checks 2-135
dynamic auto VLAN membership mode 2-569
dynamic desirable VLAN membership mode 2-569
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-96
response time before retransmitting 2-104
encapsulation methods 2-586
environment variables, displaying 2-308
errdisable detect cause command 2-109
errdisable recovery command 2-111
error conditions, displaying 2-337
error disable detection 2-109
error-disabled interfaces, displaying 2-357
EtherChannel
assigning Ethernet interface to channel group 2-33
creating port-channel logical interface 2-117
debug messages, display B-12, B-29
displaying 2-341
enabling Layer 2 protocol tunneling for
LACP 2-195
PAgP 2-195
UDLD 2-195
interface information, displaying 2-357
LACP modes 2-33
load-distribution methods 2-278
PAgP
aggregate-port learner 2-262
clearing channel-group information 2-46, 2-49
debug messages, display B-29
displaying 2-398, 2-440
error detection for 2-109
error recovery timer 2-111
learn method 2-262
modes 2-33
physical-port learner 2-262
priority of interface for transmitted traffic 2-264
Ethernet controller
debug messages, display B-13
internal register display 2-319
Ethernet statistics, collecting 2-286
examples, conventions for xviii
exit command 2-622
express setup-related commands 2-300, 2-456
extended discovery of candidate switches 2-58
extended-range VLANs
and allowed VLAN list 2-587
and pruning-eligible list 2-587
configuring 2-607
extended system ID for STP 2-514
F
fallback bridging, debugging B-14
fan information, displaying 2-334
feature manager
displaying 2-346
displaying summaries 2-351
label information 2-346
per-interface information 2-349
per-VLAN information 2-351
file name, VTP 2-634
files, deleting 2-70
flash_init (boot loader) command A-8
Flex Links
configuring 2-562
displaying 2-357
flowcontrol command 2-113
format (boot loader) command A-9
forwarding information base (FIB), debugging B-24
forwarding packets, with ACL matches 2-8
forwarding results, display 2-352
frame forwarding information, displaying 2-352
fsck (boot loader) command A-10
G
GigaStack GBICs
debugging B-15
trunk mode on 2-570
global configuration mode 1-2, 1-3
H
hardware ACL statistics 2-302
help (boot loader) command A-11
hop-count limit for clusters 2-58
host connection, port configuration 2-567
HSRP
binding HSRP group to cluster 2-65
standby group 2-65
I
IDS, using with SPAN and RSPAN 2-254
IEEE 802.1Q tunnel ports
configuring 2-569
displaying 2-329
IEEE 802.1x
and switchport modes 2-570
authentication 2-3
enabling 2-76
See also port-based authentication
IGMP filters
applying 2-160
debug messages, display B-19
IGMP groups
configuring throttling action 2-162
setting maximum 2-162
IGMP maximum groups, debugging B-20
IGMP profiles
creating 2-164
displaying 2-378
IGMP snooping
adding ports as a static member of a group 2-182
displaying 2-379, 2-384, 2-386
enabling 2-166
enabling the configurable-leave timer 2-168
enabling the Immediate-Leave feature 2-179
flooding query count 2-176
interface topology change notification behavior 2-178
MAC address tables 2-414
multicast table 2-382
querier 2-170
query solicitation 2-176
report suppression 2-172
source-only-learning aging time 2-174
switch topology change notification behavior 2-176
images
See software images
Immediate-Leave feature, MVR 2-259
immediate-leave processing 2-179
import map command 2-190
interface command 2-121
interface configuration mode 1-2, 1-4
interface port-channel command 2-117
interface range command 2-119
interface-range macros 2-68
interfaces
assigning Ethernet interface to channel group 2-33
configuring 2-107
configuring multiple 2-119
creating port-channel logical 2-117
disabling 2-491
displaying the MAC address table 2-412
restarting 2-491
interface speed, configuring 2-551
internal registers, displaying 2-319, 2-325
Internet Group Management Protocol
See IGMP
Intrusion Detection System
See IDS
invalid GBIC
error detection for 2-109
error recovery timer 2-111
ip address command 2-125
IP addresses, setting 2-125
IP address matching 2-224
ip arp inspection filter vlan command 2-127
ip arp inspection limit command 2-129
ip arp inspection log-buffer command 2-131
ip arp inspection trust command 2-133
ip arp inspection validate command 2-135
ip arp inspection vlan command 2-137
ip arp inspection vlan logging command 2-139
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-143
ip dhcp snooping command 2-141
ip dhcp snooping database command 2-145
ip dhcp snooping information option allow-untrusted command 2-150
ip dhcp snooping information option command 2-148
ip dhcp snooping information option format remote-id command 2-152
ip dhcp snooping information option format snmp-ifindex command 2-153
ip dhcp snooping limit rate command 2-154
ip dhcp snooping trust command 2-155
ip dhcp snooping verify command 2-156
ip dhcp snooping vlan command 2-157
ip dhcp snooping vlan information option format-type circuit-id string command 2-158
ip igmp filter command 2-160
ip igmp max-groups command 2-162
ip igmp profile command 2-164
ip igmp snooping command 2-166
ip igmp snooping last-member-query-interval command 2-168
ip igmp snooping querier command 2-170
ip igmp snooping report-suppression command 2-172
ip igmp snooping source-only-learning command age-timer 2-174
ip igmp snooping tcn command 2-176
ip igmp snooping tcn flood command 2-178
ip igmp snooping vlan immediate-leave command 2-179
ip igmp snooping vlan mrouter command 2-180
ip igmp snooping vlan static command 2-182
IP multicast addresses 2-256
IP phones
auto-QoS configuration 2-20
trusting packets sent from 2-249
IP-precedence-to-DSCP map 2-242
ip source binding command 2-184
IP source guard
disabling 2-188
displaying
binding entries 2-388
configuration 2-389
enabling 2-188
static IP source bindings 2-184
ip ssh command 2-186
ip verify source command 2-188
ip vrf (global configuration) command 2-189
ip vrf command 2-192
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-194
l2protocol-tunnel cos command 2-197
LACP
See EtherChannel
lacp port-priority command 2-198
lacp system-priority command 2-200
Layer 2 mode, enabling 2-558
Layer 2 protocol ports, displaying 2-391
Layer 2 protocol-tunnel
error detection for 2-109
error recovery timer 2-111
Layer 2 protocol tunnel counters 2-45
Layer 2 protocol tunneling error recovery 2-195
Layer 2 traceroute
IP addresses 2-598
MAC addresses 2-595
Layer 3 mode, enabling 2-558
line configuration mode 1-2, 1-5
Link Aggregation Control Protocol
See EtherChannel
link flap
enable timer to recover from error state 2-111
error detection for 2-109
load_helper (boot loader) command A-12
load-distribution methods for EtherChannel 2-278
logging file command 2-202
logical interface 2-117
loopback error, recovery timer 2-111
loop guard, for spanning tree 2-516, 2-519
M
mac access-group command 2-204
MAC access-groups, displaying 2-400
MAC access list configuration mode 2-206
mac access-list extended command 2-206
MAC access lists 2-71
MAC addresses
debug learning on bridge groups B-14
debug learning on VLANs B-25
displaying
aging time 2-406
all 2-404
dynamic 2-410
Layer 2 multicast entries 2-414
notification settings 2-417
MAC addresses (continued)
number of addresses in a VLAN 2-408
per interface 2-412
per VLAN 2-421
static 2-419
static and dynamic entries 2-402
dynamic
aging time 2-208
deleting 2-47
displaying 2-410
enabling MAC address notification 2-209
matching 2-224
static
adding and removing 2-211
displaying 2-419
dropping on an interface 2-212
tables 2-404
MAC address notification, debugging B-26
mac address-table aging-time 2-208
mac address-table aging-time command 2-208
mac address-table notification command 2-209
mac address-table static command 2-211
mac address-table static drop command 2-212
MAC named extended access lists 2-206
macro description command 2-217
macro global command 2-218
macro global description command 2-221
macro name command 2-222
macros
adding a description 2-217
adding a global description 2-221
applying 2-218
creating 2-222
displaying 2-442
interface range 2-68, 2-119
specifying parameter values 2-218
tracing 2-218
manual
audience xvii
purpose of xvii
maps
QoS
defining 2-242
displaying 2-429
VLAN
creating 2-619
defining 2-224
displaying 2-483
match (access-map configuration) command 2-224
match (class-map configuration) command 2-226
maximum transmission unit
See MTU
member switches
See clusters
memory (boot loader) command A-13
merge failures, displaying 2-346
mkdir (boot loader) command A-15
mls aclmerge delay command 2-229
mls qos aggregate-policer command 2-234
mls qos command 2-231
mls qos cos command 2-236
mls qos cos policy-map command 2-238
mls qos dscp-mutation command 2-240
mls qos map command 2-242
mls qos min-reserve command 2-246
mls qos monitor command 2-247
mls qos trust command 2-249
mode, MVR 2-256
modes, commands 1-1
monitor session command 2-252
more (boot loader) command A-16
MSTP
displaying 2-458, 2-459
interoperability 2-53
link type 2-518
MST region
MSTP (continued)
aborting changes 2-523
applying changes 2-523
configuration name 2-523
configuration revision number 2-523
current or pending display 2-523
displaying 2-458, 2-459
MST configuration mode 2-523
VLANs-to-instance mapping 2-523
path cost 2-525
protocol mode 2-521
restart protocol migration process 2-53
root port
loop guard 2-516
preventing from becoming designated 2-516
restricting which can be root 2-516
root guard 2-516
root switch
affects of extended system ID 2-514
hello-time 2-528, 2-535
interval between BDPU messages 2-529
interval between hello BPDU messages 2-528, 2-535
max-age 2-529
maximum hop count before discarding BPDU 2-530
port priority for selection of 2-531
primary or secondary 2-535
switch priority 2-534
state changes
blocking to forwarding state 2-541
enabling BPDU filtering 2-506, 2-539
enabling BPDU guard 2-508, 2-539
enabling Port Fast 2-539, 2-541
forward-delay time 2-527
length of listening and learning states 2-527
rapid transition to forwarding 2-518
shutting down Port Fast-enabled ports 2-539
state information display 2-457
MTU
configuring size 2-593
displaying global setting 2-466
multicast expansion table (MET), debugging B-27
multicast group address, MVR 2-259
multicast groups, MVR 2-257
multicast router learning method 2-180
multicast router ports, configuring 2-180
multicast routes, debugging B-22, B-23
multicast storm control 2-553
multicast VLAN, MVR 2-256
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-91
Multiple Spanning Tree Protocol
See MSTP
multi VPN routing/forwarding instances in customer edge devices
See multi-VRF CE
multi-VRF CE 2-189, 2-192
MVR
configuring 2-256
configuring interfaces 2-259
debug messages, display B-28
displaying 2-434
displaying interface information 2-436
members, displaying 2-438
mvr (global configuration) command 2-256
mvr (interface configuration) command 2-259
mvr group command 2-257
mvr vlan group command 2-260
N
native VLANs 2-586
native VLAN tagging 2-625
nonegotiate
DTP messaging 2-573
speed 2-551
non-IP protocols
denying 2-71
forwarding 2-266
non-IP traffic access lists 2-206
non-IP traffic forwarding
denying 2-71
permitting 2-266
normal-range VLANs 2-608, 2-613
note, description xviii
no vlan command 2-607, 2-617
P
PAgP
See EtherChannel
pagp learn-method command 2-262
pagp port-priority command 2-264
password, VTP 2-634, 2-638, 2-640
password-recovery mechanism, enabling and disabling 2-290
PBR, debug messages, display B-30
permit (ARP access-list configuration) command 2-269
permit command 2-266
per-VLAN spanning-tree plus
See STP
physical-port learner 2-262
PID, displaying 2-368
PIM-DVMRP, as multicast router learning method 2-180
PoE
debugging B-16, B-17
displaying status 2-450
enabling 2-280
police aggregate command 2-273
police command 2-271
policed-DSCP map 2-242
policy-based routing
See PBR
policy-map command 2-275
policy maps
applying to an interface 2-293, 2-297
creating 2-275
displaying 2-445
policers
displaying 2-424, 2-425
for a single class 2-271
for multiple classes 2-234, 2-273
policed-DSCP map 2-242
traffic classification
defining the class 2-39
defining trust states 2-600
setting DSCP or IP precedence values 2-295
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
auth-fail VLAN 2-80
debug messages, display B-9
enabling IEEE 802.1x 2-99
guest VLAN 2-89
IEEE 802.1x AAA accounting methods 2-1
MAC authentication bypass 2-93
manual control of authorization state 2-99
multiple hosts on authorized port 2-91
PAE as authenticator 2-98
periodic re-authentication
enabling 2-103
time between attempts 2-104
quiet period between failed authentication exchanges 2-104
re-authenticating IEEE 802.1x-enabled ports 2-101
resetting configurable IEEE 802.1x parameters 2-88
statistics and status display 2-330
switch-to-client frame-retransmission number 2-95, 2-96
switch-to-client retransmission time 2-104
port-channel load-balance command 2-278
Port Fast, for spanning tree 2-541
port labels 2-346, 2-349, 2-467
port ranges, defining 2-68
ports, debugging B-32
ports, protected 2-584
port security
aging 2-580
debug messages, display B-34
enabling 2-575
violation error recovery 2-111
port trust states for QoS 2-249
port types, MVR 2-259
power information, displaying 2-334
power inline command 2-280
Power over Ethernet
See PoE
priority-queue command 2-282
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-368
protected ports, displaying 2-363
pruning
VLANs 2-586
VTP
displaying interface information 2-357
enabling 2-634, 2-638, 2-640
publications, related xviii
PVST+
See STP
Q
QoS
automatic configuration 2-20
class maps
creating 2-41
defining the match criteria 2-226
displaying 2-310
defining the CoS value for an incoming packet 2-236
displaying configuration information 2-305, 2-423
QoS (continued)
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-240
defining DSCP-to-DSCP-mutation map 2-242
enabling 2-231
maps
defining 2-242
displaying 2-429
policy maps
applying an aggregate policer 2-273
applying to an interface 2-293, 2-297
creating 2-275
defining CoS 2-238
defining policers 2-234, 2-271
displaying policers 2-424, 2-425
displaying policy maps 2-445
policed-DSCP map 2-242
setting DSCP or IP precedence values 2-295
traffic classifications 2-39
trust states 2-600
port trust states 2-249
queues
CoS-to-egress-queue map 2-646
displaying buffer settings 2-425
displaying queueing strategies 2-425
enabling the expedite 2-282
mapping DSCPs to thresholds 2-648
minimum-reserve level 2-650
minimum-reserve level buffer sizes 2-246
ratio of queue sizes 2-651
tail-drop threshold percentages 2-655
WRED threshold percentages 2-653
WRR weights 2-644
statistics
collecting on specified DSCPs 2-247
displaying DSCP information 2-425
tail-drop
assigning threshold percentages 2-655
mapping DSCPs to thresholds 2-648
QoS (continued)
trusted boundary for Cisco SoftPhones 2-249
trusted boundary for IP phones 2-249
WRED
assigning threshold percentages 2-653
enabling 2-653
mapping DSCPs to thresholds 2-648
quality of service
See QoS
querytime, MVR 2-256
R
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
rcommand command 2-283
re-authenticating IEEE 802.1x-enabled ports 2-101
re-authentication
periodic 2-103
time between attempts 2-104
receiver ports, MVR 2-259
receiving flow-control packets 2-113
recovery mechanism
causes 2-111
display 2-339
timer interval 2-111
redundancy for cluster switches 2-65
remote-span command 2-285
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-17
reset (boot loader) command A-18
reset command 2-622
resource templates, displaying 2-454
restricted VLAN
See dot1x auth-fail VLAN
rmdir (boot loader) command A-19
rmon collection stats command 2-286
root guard, for spanning tree 2-516
route distinguisher 2-190
routed ports
IP addresses on 2-126
number supported 2-126, 2-288
route-target command 2-190
RSPAN
and IDS 2-254
configuring 2-252
displaying 2-432
filter RSPAN traffic 2-252
remote-span command 2-285
sessions
add interfaces to 2-252
start new 2-252
S
sdm prefer command 2-287
secure ports, limitations 2-577
sending flow-control packets 2-113
service password-recovery command 2-290
service-policy command 2-293
set (boot loader) command A-20
set command 2-295
setup command 2-297
setup express command 2-300
show access-lists command 2-302
show archive status command 2-304
show arp access-list command 2-369
show auto qos command 2-305
show boot command 2-308
show changes command 2-622
show class-map command 2-310
show cluster candidates command 2-313
show cluster command 2-311
show cluster members command 2-315
show controllers cpu-interface command 2-317
show controllers ethernet-controller command 2-319
show controllers switch command 2-324
show controllers tcam command 2-325
show controllers utilization command 2-327
show controller utilization command 2-327
show current command 2-622
show dot1q-tunnel command 2-329
show dot1x command 2-330
show env command 2-334
show errdisable detect command 2-335
show errdisable flap-values command 2-337
show errdisable recovery command 2-339
show etherchannel command 2-341
show flowcontrol command 2-344
show fm command 2-346
show fm interface command 2-349
show fm vlan command 2-351
show forward command 2-352
show interfaces command 2-357
show interfaces counters command 2-366
show inventory command 2-368
show ip arp inspection command 2-370
show ip dhcp snooping binding command 2-374
show ip dhcp snooping command 2-373
show ip dhcp snooping database command 2-376
show ip igmp profile command 2-378
show ip igmp snooping command 2-379
show ip igmp snooping groups command 2-382
show ip igmp snooping mrouter command 2-384
show ip igmp snooping querier command 2-386
show ip source binding command 2-388
show ip verify source command 2-389
show l2protocol-tunnel command 2-391
show l2tcam command 2-394
show l3tcam command 2-396
show lacp command 2-398
show mac access-group command 2-400
show mac address-table address command 2-404
show mac address-table aging time command 2-406
show mac address-table command 2-402
show mac address-table count command 2-408
show mac address-table dynamic command 2-410
show mac address-table interface command 2-412
show mac address-table multicast command 2-414
show mac address-table notification command 2-417
show mac address-table static command 2-419
show mac address-table vlan command 2-421
show mls qos aggregate-policer command 2-424
show mls qos command 2-423
show mls qos interface command 2-425
show mls qos maps command 2-429
show monitor command 2-432
show mvr command 2-434
show mvr interface command 2-436
show mvr members command 2-438
show pagp command 2-440
show parser macro command 2-442
show policy-map command 2-445
show port security command 2-447
show power inline command 2-450
show proposed command 2-622
show running-config vlan command 2-452
show sdm prefer command 2-454
show setup express command 2-456
show spanning-tree command 2-457
show storm-control command 2-464
show system mtu command 2-466
show tcam command 2-467
show tcam pbr command 2-470
show tcam qos command 2-472
show trust command 2-600
show udld command 2-474
show version command 2-477
show vlan access-map command 2-483
show vlan command 2-479
show vlan command fields 2-480
show vlan filter command 2-484
show vmps command 2-485
show vtp command 2-487
shutdown command 2-491
shutdown threshold, Layer 2 protocol tunneling 2-194
shutdown vlan command 2-492
Smartports macros
See macros
SNMP host, specifying 2-497
SNMP informs, enabling the sending of 2-493
snmp-server enable traps command 2-493
snmp-server host command 2-497
snmp-server ip command 2-501
snmp trap mac-notification command 2-503
SNMP traps
enabling MAC address notification trap 2-503
enabling the MAC address notification feature 2-209
enabling the sending of 2-493
setting DSCP or precedence of 2-501
software images
deleting 2-70
downloading 2-10
upgrading 2-10
uploading 2-16
software version, displaying 2-477
source ports, MVR 2-259
SPAN
and IDS 2-254
configuring 2-252
debug messages, display B-35
displaying 2-432
filter SPAN traffic 2-252
sessions
add interfaces to 2-252
start new 2-252
spanning 2-545
spanning-tree backbonefast command 2-505
spanning-tree bpdufilter command 2-506
spanning-tree bpduguard command 2-508
spanning-tree cost command 2-510
spanning-tree etherchannel command 2-512
spanning-tree extend system-id command 2-514
spanning-tree guard command 2-516
spanning-tree link-type command 2-518
spanning-tree loopguard default command 2-519
spanning-tree mode command 2-521
spanning-tree mst configuration command 2-523
spanning-tree mst cost command 2-525
spanning-tree mst forward-time command 2-527
spanning-tree mst hello-time command 2-528
spanning-tree mst max-age command 2-529
spanning-tree mst max-hops command 2-530
spanning-tree mst port-priority command 2-531
spanning-tree mst pre-standard command 2-533
spanning-tree mst priority command 2-534
spanning-tree mst root command 2-535
spanning-tree portfast (global configuration) command 2-539
spanning-tree portfast (interface configuration) command 2-541
spanning-tree port-priority command 2-537
spanning-tree stack-port command 2-543
spanning-tree transmit hold-count command 2-545
spanning-tree uplinkfast command 2-546
spanning-tree vlan command 2-548
speed command 2-551
SSH, configuring version 2-186
static-access ports, configuring 2-560
statistics, Ethernet group 2-286
sticky learning, enabling 2-575
storm-control command 2-553
STP
BackboneFast 2-505
debug message display
BackboneFast events B-38
MSTP B-41
optimized BPDUs handling B-40
spanning-tree activity B-36
switch shim B-43
STP (continued)
debug message display
transmitted and received BPDUs B-39
UplinkFast B-45
detection of indirect link failures 2-505
enabling protocol tunneling for 2-194
EtherChannel misconfiguration 2-512
extended system ID 2-514
path cost 2-510
protocol mode 2-521
root port
accelerating choice of new 2-546
accelerating choice of new root in a stack 2-543
cross-stack UplinkFast 2-543
loop guard 2-516
preventing from becoming designated 2-516
restricting which can be root 2-516
root guard 2-516
UplinkFast 2-546
root switch
affects of extended system ID 2-514, 2-549
hello-time 2-548
interval between BDPU messages 2-548
interval between hello BPDU messages 2-548
max-age 2-548
port priority for selection of 2-537
primary or secondary 2-548
switch priority 2-548
state changes
blocking to forwarding state 2-541
enabling BPDU filtering 2-506, 2-539
enabling BPDU guard 2-508, 2-539
enabling Port Fast 2-539, 2-541
enabling timer to recover from error state 2-111
forward-delay time 2-548
length of listening and learning states 2-548
shutting down Port Fast-enabled ports 2-539
state information display 2-457
VLAN options 2-534, 2-548
SVIs
creating 2-121
number supported 2-121, 2-126, 2-288
switchcore command 2-556
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-558, 2-573
returning to interfaces 2-558, 2-573
switchport access command 2-560
switchport backup interface command 2-562
switchport block command 2-565
switchport broadcast command 2-566
switchport command 2-558
switchport host command 2-567
switchport mode command 2-569
switchport multicast command 2-572
switchport nonegotiate command 2-573
switchport port-security aging command 2-580
switchport port-security command 2-575
switchport priority extend command 2-582
switchport protected command 2-584
switchports, displaying 2-357
switchport trunk command 2-586
switchport unicast command 2-590
switchport voice vlan command 2-591
switch resources
buffer storage priority 2-556
displaying resource-allocation priority 2-324
reserving for high-priority traffic 2-556
system message logging, save message to flash 2-202
system mtu command 2-593
system resource templates 2-287
T
tail-drop
assigning threshold percentages 2-655
mapping DSCPs to thresholds 2-648
tar files, creating, listing, and extracting 2-13
TCAM
debug messages, display B-2, B-23
displaying
ACL 2-467
Layer 2 2-394
Layer 3 2-396
PBR 2-470
QoS 2-472
Telnetting to cluster switches 2-283
temperature information, displaying 2-334
templates, system resources 2-287
traceroute mac command 2-595
traceroute mac ip command 2-598
trunking, VLAN mode 2-569
trunk mode 2-569, 2-586
trunk ports 2-569
trunks
allowed VLANs 2-586
configuring trunk characteristics 2-586
encapsulation methods 2-586
native VLANs 2-586
on GigaStack GBICs 2-570
pruning-eligible VLAN list 2-588
pruning VLANs 2-586
to non-DTP device 2-570
VLAN 1 minimization 2-588
trusted boundary for QoS 2-249
trusted port states for QoS 2-249
tunnel ports, Layer 2 protocol, displaying 2-391
type (boot loader) command A-23
U
UDLD
aggressive mode 2-602, 2-604
debug messages, display B-53
enable globally 2-602
enable per interface 2-604
UDLD (continued)
error recovery timer 2-111
message timer 2-602
normal mode 2-602, 2-604
reset a shutdown interface 2-606
status 2-474
udld command 2-602
udld port command 2-604
udld reset command 2-606
unicast FIB, debugging B-24
unicast routes, debugging B-23
unicast storm control 2-553
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-565
unknown unicast traffic, preventing 2-565
unset (boot loader) command A-24
upgrading software images
from a server 2-10
monitoring status of 2-304
UplinkFast, for STP 2-546
user EXEC mode 1-2, 1-3
V
version (boot loader) command A-26
VLAN
enabling guest VLAN supplicant 2-78
vlan (global configuration) command 2-607
vlan (VLAN configuration) command 2-613
vlan access-map command 2-619
VLAN access map configuration mode 2-619
VLAN access maps
actions 2-8
displaying 2-483
VLAN configuration
rules 2-610, 2-615
saving 2-607, 2-617
VLAN configuration mode
commands
VLAN 2-613
VTP 2-640
description 1-5
entering 2-621
summary 1-2
vlan database command 2-621
vlan dot1q tag native command 2-625
vlan filter command 2-627
VLAN filters, displaying 2-484
VLAN ID range 2-607, 2-613
vlan labels 2-346, 2-351, 2-467
VLAN maps
applying 2-627
creating 2-619
defining 2-224
displaying 2-483
VLAN Query Protocol
See VQP
VLANs
adding 2-607
configuring 2-607, 2-613
debug message display
ISL B-49
VLAN IOS file system error tests B-48
VLAN manager activity B-46
VTP B-51
displaying configurations 2-452, 2-479
extended-range 2-607
MAC addresses
displaying 2-421
number of 2-408
media types 2-610, 2-615
normal-range 2-608, 2-613
restarting 2-492
saving the configuration 2-607
shutting down 2-492
SNMP traps for VTP 2-494, 2-498
VLANs (continued)
suspending 2-492
trunks, VLAN 1 minimization 2-588
variables 2-613
VLAN Trunking Protocol
See VTP
VMPS
configuring servers 2-632
displaying 2-485
error recovery timer 2-111
reconfirming dynamic VLAN assignments 2-629
vmps reconfirm (global configuration) command 2-630
vmps reconfirm (privileged EXEC) command 2-629
vmps retry command 2-631
vmps server command 2-632
voice VLAN
configure 2-591
set port priority 2-582
VPN routing/forwarding table
See VRF
VQP
and dynamic-access ports 2-561
clearing client statistics 2-54
displaying information 2-485
per-server retry count 2-631
reconfirmation interval 2-630
reconfirming dynamic VLAN assignments 2-629
VRF 2-189, 2-192
VTP
changing characteristics 2-634
clearing pruning counters 2-55
configuring
domain name 2-634, 2-640
file name 2-634
mode 2-634, 2-640
password 2-634, 2-638, 2-640
counters display fields 2-488
displaying information 2-487
enabling
VTP (continued)
pruning 2-634, 2-638, 2-640
tunneling for 2-194
version 2 2-634, 2-638, 2-640
mode 2-634, 2-640
pruning 2-634, 2-638, 2-640
saving the configuration 2-607, 2-617
statistics 2-487
status 2-487
status display fields 2-489
vtp (global configuration) command 2-634
vtp (privileged EXEC) command 2-638
vtp (VLAN configuration) command 2-640
W
WRED
assigning threshold percentages 2-653
enabling 2-653
mapping DSCPs to thresholds 2-648
WRR, assigning weights to egress queues 2-644
wrr-queue bandwidth command 2-644
wrr-queue cos-map command 2-646
wrr-queue dscp-map command 2-648
wrr-queue min-reserve command 2-650
wrr-queue queue-limit command 2-651
wrr-queue random-detect max-threshold command 2-653
wrr-queue threshold command 2-655