Table Of Contents
Numerics - A - B - C - D - E - F - G - H - I - J - L - M - N - P - Q - R - S - T - U - V - W -
Index
Numerics
802.1X Port Based Authentication
enabling guest VLAN supplicant 2-79
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5
AAA methods 2-3
abort command 2-636
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-127
MAC
configuring 2-213
displaying 2-417
access-list hardware program nonblocking command 2-6
access lists
IP 2-127
on Layer 2 interfaces 2-127, 2-213
access map configuration mode 2-233
access mode 2-585
access ports 2-585
ACEs 2-74, 2-277
ACLs
deny 2-72
displaying 2-314
for non-IP protocols 2-215
matching 2-233
permit 2-275
action command 2-8
aggregate-port learner 2-271
allowed VLANs 2-600
apply command 2-636
archive download-sw command 2-10
archive tar command 2-13
archive upload-sw command 2-16
arp access-list command 2-18
authorization state of controlled port 2-101
autonegotiation of duplex mode 2-109
auto qos voip command 2-20
B
BackboneFast, for STP 2-521
backup interfaces
configuring 2-578
displaying 2-371
boot (boot loader) command A-2
boot buffersize command 2-24
boot config-file command 2-25
boot enable-break command 2-26
boot helper command 2-27
boot helper-config file command 2-28
booting
Cisco IOS image 2-31
displaying environment variables 2-320
interrupting 2-26
manually 2-29
boot loader
accessing A-1
booting
Cisco IOS image A-2
helper image 2-27
directories
creating A-15
displaying a list of A-6
removing A-19
displaying
available commands A-11
memory heap utilization A-13
version A-26
environment variables
described A-20
displaying settings A-20
setting A-20
unsetting A-24
files
copying A-4
deleting A-5
displaying a list of A-6
displaying the contents of A-3, A-16, A-23
renaming A-17
file system
formatting A-9
initializing flash A-8
running a consistency check A-10
loading helper images A-12
prompt A-1
resetting the system A-18
boot manual command 2-29
boot private-config-file command 2-30
boot system command 2-31
BPDU filtering, for spanning tree 2-522, 2-555
BPDU guard, for spanning tree 2-524, 2-555
broadcast storm control 2-569
C
candidate switches
See clusters
cat (boot loader) command A-3
CDP, enabling protocol tunneling for 2-202
channel-group command 2-32
channel-protocol command 2-36
Cisco SoftPhone
auto-QoS configuration 2-20
trusting packets sent from 2-258
class command 2-38
class-map command 2-40
class maps
creating 2-40
defining the match criteria 2-235
displaying 2-322
class of service
See CoS
clear ip arp inspection log command 2-42
clear ip arp inspection statistics command 2-43
clear ip dhcp snooping database command 2-44
clear l2protocol-tunnel counters command 2-46
clear lacp command 2-47
clear mac address-table command 2-48
clear pagp command 2-50
clear spanning-tree counters command 2-53
clear spanning-tree detected-protocols command 2-54
clear vmps statistics command 2-55
clear vtp counters command 2-56
cluster commander-address command 2-57
cluster discovery hop-count command 2-59
cluster enable command 2-60
cluster holdtime command 2-61
cluster member command 2-62
cluster outside-interface command 2-64
cluster run command 2-65
clusters
adding candidates 2-62
binding to HSRP group 2-66
building manually 2-62
communicating with
devices outside the cluster 2-64
members by using Telnet 2-294
debug messages, display B-6
displaying
candidate switches 2-325
debug messages B-6
member switches 2-327
status 2-323
hop-count limit for extended discovery 2-59
HSRP standby groups 2-66
redundancy 2-66
SNMP trap 2-509
cluster standby-group command 2-66
cluster timer command 2-68
command modes defined 1-1
command switch
See clusters
configuration conflicts, ACL, displaying 2-360
configuration files
password recovery disable considerations A-1
setting the NVRAM size for 2-24
specifying the name 2-25, 2-30
configuring multiple interfaces 2-123
config-vlan mode
commands 2-622
description 1-4
entering 2-621
summary 1-2
copy (boot loader) command A-4
CoS
assigning default value to incoming packets 2-245
assigning to Layer 2 protocol packets 2-205
defining in a policy map 2-247
overriding the incoming value 2-245
CoS-to-DSCP map 2-251
CoS-to-egress-queue map 2-660
CPU ASIC
debug messages, display B-8
statistics display 2-329
CPU statistics, displaying 2-329
cross-stack UplinkFast, for STP 2-559
D
debug acltcam command B-2
debug auto qos command B-3
debug backup command B-5
debug cluster command B-6
debug cpu-interface command B-8
debug dot1x command B-9
debug eap command B-11
debug etherchannel command B-12
debug ethernet-controller ram-access command B-13
debug fallback-bridging command B-14
debug gigastack command B-15
debug ilpower controller command B-16
debug ilpower event command B-17
debug ip dhcp snooping command B-18
debug ip igmp filter command B-19
debug ip igmp max-groups command B-20
debug ip verify source packet command B-21
debug l3multicast command B-22
debug l3tcam command B-23
debug l3unicast command B-24
debug mac-manager command B-25
debug mac-notification command B-26
debug met command B-27
debug mvrdbg command B-28
debug pagp command B-29
debug pbr command B-30
debug platform ip arp inspection command B-31
debug pm command B-32
debug port-security command B-34
debug spanning-tree backbonefast command B-38
debug spanning-tree bpdu command B-39
debug spanning-tree bpdu-opt command B-40
debug spanning-tree command B-36
debug spanning-tree mstp command B-41
debug spanning-tree switch command B-43
debug spanning-tree uplinkfast command B-45
debug span-session command B-35
debug sw-vlan command B-46
debug sw-vlan ifs command B-48
debug sw-vlan notification command B-49
debug sw-vlan vtp command B-51
debug udld command B-53
define interface-range command 2-69
delete (boot loader) command A-5
delete command 2-71
deny (ARP access-list configuration) command 2-75
deny command 2-72
detect mechanism, causes 2-111
DHCP snooping
accepting untrusted packets form edge switch 2-156
displaying
bindings 2-388
configuration 2-387
enabling
on a VLAN 2-165
option 82 2-154, 2-156, 2-160
trust on an interface 2-163
error recovery timer 2-113
rate limiting 2-161
DHCP snooping binding database
binding file, configuring 2-152
bindings
adding 2-150
deleting 2-150
clearing database agent statistics 2-44
database agent, configuring 2-152
displaying
database agent status 2-390, 2-392
dir (boot loader) command A-6
directories, deleting 2-71
domain name, VTP 2-648, 2-654
dot1x auth-fail max-attempts 2-79
dot1x auth-fail vlan 2-81
dot1x command 2-77
dot1x control-direction command 2-83
dot1x critical global configuration command 2-85
dot1x critical interface configuration command 2-87
dot1x default command 2-89
dot1x fallback command 2-90
dot1x guest-vlan command 2-91
dot1x host-mode command 2-93
dot1x initialize command 2-94
dot1x mac-auth-bypass command 2-95
dot1x max-req command 2-97, 2-98
dot1x multiple-hosts command 2-99
dot1x pae command 2-100
dot1x port-control command 2-101
dot1x re-authenticate command 2-103
dot1x re-authentication command 2-104
dot1x reauthentication command 2-105
dropping packets, with ACL matches 2-8
drop threshold, Layer 2 protocol tunneling 2-202
DSCP-to-CoS map 2-251
DSCP-to-DSCP-mutation map 2-251
DSCP-to-threshold map 2-662
DTP 2-586
DTP flap
error detection for 2-111
error recovery timer 2-113
duplex command 2-109
dynamic-access ports
configuring 2-576
restrictions 2-576
dynamic ARP inspection
ARP ACLs
apply to a VLAN 2-135
define 2-18
deny packets 2-75
display 2-383
permit packets 2-278
clear
log buffer 2-42
statistics 2-43
display
ARP ACLs 2-383
configuration and operating state 2-384
log buffer 2-384
statistics 2-384
trust state and rate limit 2-384
enable per VLAN 2-145
error detection for 2-111
error recovery timer 2-113
log buffer
clear 2-42
configure 2-139
display 2-384
rate-limit incoming ARP packets 2-137
statistics
clear 2-43
display 2-384
trusted interface state 2-141
type of packet logged 2-146
validation checks 2-143
dynamic auto VLAN membership mode 2-585
dynamic desirable VLAN membership mode 2-585
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-98
response time before retransmitting 2-106
encapsulation methods 2-600
environment variables, displaying 2-320
errdisable detect cause command 2-111
errdisable recovery command 2-113
error conditions, displaying 2-349
error disable detection 2-111
error-disabled interfaces, displaying 2-371
EtherChannel
assigning Ethernet interface to channel group 2-32
creating port-channel logical interface 2-121
debug messages, display B-12, B-29
displaying 2-353
enabling Layer 2 protocol tunneling for
LACP 2-203
PAgP 2-203
UDLD 2-203
interface information, displaying 2-371
LACP modes 2-32
load-distribution methods 2-287
PAgP
aggregate-port learner 2-271
clearing channel-group information 2-47, 2-50
debug messages, display B-29
displaying 2-415, 2-455
error detection for 2-111
error recovery timer 2-113
learn method 2-271
modes 2-32
physical-port learner 2-271
priority of interface for transmitted traffic 2-273
Ethernet controller
debug messages, display B-13
internal register display 2-331
Ethernet statistics, collecting 2-297
exit command 2-636
express setup-related commands 2-312, 2-471
extended discovery of candidate switches 2-59
extended-range VLANs
and allowed VLAN list 2-600
and pruning-eligible list 2-600
configuring 2-621
extended system ID for STP 2-530
F
fallback bridging, debugging B-14
fallback profiles
displaying 2-356
fan information, displaying 2-346
feature manager
displaying 2-360
displaying summaries 2-365
label information 2-360
per-interface information 2-363
per-VLAN information 2-365
file name, VTP 2-648
files, deleting 2-71
flash_init (boot loader) command A-8
Flex Links
configuring 2-578
displaying 2-371
flowcontrol command 2-117
format (boot loader) command A-9
forwarding information base (FIB), debugging B-24
forwarding packets, with ACL matches 2-8
forwarding results, display 2-366
frame forwarding information, displaying 2-366
fsck (boot loader) command A-10
G
GigaStack GBICs
debugging B-15
trunk mode on 2-586
global configuration mode 1-2, 1-3
H
hardware ACL statistics 2-314
help (boot loader) command A-11
hop-count limit for clusters 2-59
host connection, port configuration 2-583
HSRP
binding HSRP group to cluster 2-66
standby group 2-66
I
IDS, using with SPAN and RSPAN 2-263
IEEE 802.1Q tunnel ports
configuring 2-585
displaying 2-341
IEEE 802.1x
and switchport modes 2-586
authentication 2-3
enabling 2-77
See also port-based authentication
IEEE 802.1X Port Based Authentication
enabling guest VLAN supplicant 2-90, 2-115
IGMP filters
applying 2-168
debug messages, display B-19
IGMP groups
configuring throttling action 2-170
setting maximum 2-170
IGMP maximum groups, debugging B-20
IGMP profiles
creating 2-172
displaying 2-395
IGMP snooping
adding ports as a static member of a group 2-190
displaying 2-396, 2-401, 2-403
enabling 2-174
enabling the configurable-leave timer 2-176
enabling the Immediate-Leave feature 2-187
flooding query count 2-184
interface topology change notification behavior 2-186
MAC address tables 2-431
multicast table 2-399
querier 2-178
query solicitation 2-184
report suppression 2-180
source-only-learning aging time 2-182
switch topology change notification behavior 2-184
images
See software images
Immediate-Leave feature, MVR 2-268
immediate-leave processing 2-187
import map command 2-198
interface command 2-125
interface configuration mode 1-2, 1-4
interface port-channel command 2-121
interface range command 2-123
interface-range macros 2-69
interfaces
assigning Ethernet interface to channel group 2-32
configuring 2-109
configuring multiple 2-123
creating port-channel logical 2-121
disabling 2-506
displaying the MAC address table 2-429
restarting 2-506
interface speed, configuring 2-567
internal registers, displaying 2-331, 2-337
Internet Group Management Protocol
See IGMP
Intrusion Detection System
See IDS
invalid GBIC
error detection for 2-111
error recovery timer 2-113
ip address command 2-129
IP addresses, setting 2-129
IP address matching 2-233
ip admission command 2-131
ip admission name proxy http command 2-133
ip arp inspection filter vlan command 2-135
ip arp inspection limit command 2-137
ip arp inspection log-buffer command 2-139
ip arp inspection trust command 2-141
ip arp inspection validate command 2-143
ip arp inspection vlan command 2-145
ip arp inspection vlan logging command 2-146
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-150
ip dhcp snooping command 2-148
ip dhcp snooping database command 2-152
ip dhcp snooping information option allow-untrusted command 2-156
ip dhcp snooping information option command 2-154
ip dhcp snooping information option format remote-id command 2-158
ip dhcp snooping information option format snmp-ifindex command 2-160
ip dhcp snooping limit rate command 2-161
ip dhcp snooping trust command 2-163
ip dhcp snooping verify command 2-164
ip dhcp snooping vlan command 2-165
ip dhcp snooping vlan information option format-type circuit-id string command 2-166
ip igmp filter command 2-168
ip igmp max-groups command 2-170
ip igmp profile command 2-172
ip igmp snooping command 2-174
ip igmp snooping last-member-query-interval command 2-176
ip igmp snooping querier command 2-178
ip igmp snooping report-suppression command 2-180
ip igmp snooping source-only-learning command age-timer 2-182
ip igmp snooping tcn command 2-184
ip igmp snooping tcn flood command 2-186
ip igmp snooping vlan immediate-leave command 2-187
ip igmp snooping vlan mrouter command 2-188
ip igmp snooping vlan static command 2-190
IP multicast addresses 2-265
IP phones
auto-QoS configuration 2-20
trusting packets sent from 2-258
IP-precedence-to-DSCP map 2-251
ip source binding command 2-192
IP source guard
disabling 2-196
displaying
binding entries 2-405
configuration 2-406
enabling 2-196
static IP source bindings 2-192
ip ssh command 2-194
ip verify source command 2-196
ip vrf (global configuration) command 2-197
ip vrf command 2-200
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-202
l2protocol-tunnel cos command 2-205
LACP
See EtherChannel
lacp port-priority command 2-206
lacp system-priority command 2-208
Layer 2 mode, enabling 2-574
Layer 2 protocol ports, displaying 2-408
Layer 2 protocol-tunnel
error detection for 2-111
error recovery timer 2-113
Layer 2 protocol tunnel counters 2-46
Layer 2 protocol tunneling error recovery 2-203
Layer 2 traceroute
IP addresses 2-612
MAC addresses 2-609
Layer 3 mode, enabling 2-574
line configuration mode 1-2, 1-5
Link Aggregation Control Protocol
See EtherChannel
link flap
enable timer to recover from error state 2-113
error detection for 2-111
load_helper (boot loader) command A-12
load-distribution methods for EtherChannel 2-287
logging event command 2-210
logging file command 2-211
logical interface 2-121
loopback error, recovery timer 2-113
loop guard, for spanning tree 2-532, 2-535
M
mac access-group command 2-213
MAC access-groups, displaying 2-417
MAC access list configuration mode 2-215
mac access-list extended command 2-215
MAC access lists 2-72
MAC addresses
debug learning on bridge groups B-14
debug learning on VLANs B-25
displaying
aging time 2-423
all 2-421
dynamic 2-427
Layer 2 multicast entries 2-431
notification settings 2-433
number of addresses in a VLAN 2-425
per interface 2-429
per VLAN 2-437
static 2-435
static and dynamic entries 2-419
dynamic
aging time 2-217
deleting 2-48
displaying 2-427
enabling MAC address notification 2-218
matching 2-233
static
adding and removing 2-220
displaying 2-435
dropping on an interface 2-221
tables 2-421
MAC address notification, debugging B-26
mac address-table aging-time 2-217
mac address-table aging-time command 2-217
mac address-table notification command 2-218
mac address-table static command 2-220
mac address-table static drop command 2-221
MAC named extended access lists 2-215
macro description command 2-226
macro global command 2-227
macro global description command 2-230
macro name command 2-231
macros
adding a description 2-226
adding a global description 2-230
applying 2-227
creating 2-231
displaying 2-457
interface range 2-69, 2-123
specifying parameter values 2-227
tracing 2-227
maps
QoS
defining 2-251
displaying 2-445
VLAN
creating 2-633
defining 2-233
displaying 2-498
match (access-map configuration) command 2-233
match (class-map configuration) command 2-235
maximum transmission unit
See MTU
member switches
See clusters
memory (boot loader) command A-13
merge failures, displaying 2-360
mkdir (boot loader) command A-15
mls aclmerge delay command 2-238
mls qos aggregate-policer command 2-243
mls qos command 2-240
mls qos cos command 2-245
mls qos cos policy-map command 2-247
mls qos dscp-mutation command 2-249
mls qos map command 2-251
mls qos min-reserve command 2-255
mls qos monitor command 2-256
mls qos trust command 2-258
mode, MVR 2-265
modes, commands 1-1
monitor session command 2-261
more (boot loader) command A-16
MSTP
displaying 2-473, 2-474
interoperability 2-54
link type 2-534
MST region
aborting changes 2-539
applying changes 2-539
configuration name 2-539
configuration revision number 2-539
current or pending display 2-539
displaying 2-473, 2-474
MST configuration mode 2-539
VLANs-to-instance mapping 2-539
path cost 2-541
protocol mode 2-537
restart protocol migration process 2-54
root port
loop guard 2-532
preventing from becoming designated 2-532
restricting which can be root 2-532
root guard 2-532
root switch
affects of extended system ID 2-530
hello-time 2-544, 2-551
interval between BDPU messages 2-545
interval between hello BPDU messages 2-544, 2-551
max-age 2-545
maximum hop count before discarding BPDU 2-546
port priority for selection of 2-547
primary or secondary 2-551
switch priority 2-550
state changes
blocking to forwarding state 2-557
enabling BPDU filtering 2-522, 2-555
enabling BPDU guard 2-524, 2-555
enabling Port Fast 2-555, 2-557
forward-delay time 2-543
length of listening and learning states 2-543
state changes
rapid transition to forwarding 2-534
shutting down Port Fast-enabled ports 2-555
state information display 2-472
MTU
configuring size 2-607
displaying global setting 2-481
multicast expansion table (MET), debugging B-27
multicast group address, MVR 2-268
multicast groups, MVR 2-266
multicast router learning method 2-188
multicast router ports, configuring 2-188
multicast routes, debugging B-22, B-23
multicast storm control 2-569
multicast VLAN, MVR 2-265
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-93
Multiple Spanning Tree Protocol
See MSTP
multi VPN routing/forwarding instances in customer edge devices
See multi-VRF CE
multi-VRF CE 2-197, 2-200
MVR
configuring 2-265
configuring interfaces 2-268
debug messages, display B-28
displaying 2-449
displaying interface information 2-451
members, displaying 2-453
mvr (global configuration) command 2-265
mvr (interface configuration) command 2-268
mvr group command 2-266
mvr vlan group command 2-269
N
native VLANs 2-600
native VLAN tagging 2-639
nonegotiate
DTP messaging 2-589
speed 2-567
non-IP protocols
denying 2-72
forwarding 2-275
non-IP traffic access lists 2-215
non-IP traffic forwarding
denying 2-72
permitting 2-275
normal-range VLANs 2-622, 2-627
no vlan command 2-621, 2-631
P
PAgP
See EtherChannel
pagp learn-method command 2-271
pagp port-priority command 2-273
password, VTP 2-648, 2-652, 2-654
password-recovery mechanism, enabling and disabling 2-302
PBR, debug messages, display B-30
permit (ARP access-list configuration) command 2-278
permit command 2-275
per-VLAN spanning-tree plus
See STP
physical-port learner 2-271
PID, displaying 2-382
PIM-DVMRP, as multicast router learning method 2-188
PoE
debugging B-16, B-17
displaying status 2-465
enabling 2-289
police aggregate command 2-282
police command 2-280
policed-DSCP map 2-251
policy-based routing
See PBR
policy-map command 2-284
policy maps
applying to an interface 2-305, 2-309
creating 2-284
displaying 2-460
policers
displaying 2-440, 2-441
for a single class 2-280
for multiple classes 2-243, 2-282
policed-DSCP map 2-251
traffic classification
defining the class 2-38
defining trust states 2-614
setting DSCP or IP precedence values 2-307
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
auth-fail VLAN 2-81
debug messages, display B-9
enabling IEEE 802.1x 2-101
guest VLAN 2-91
IEEE 802.1x AAA accounting methods 2-1
MAC authentication bypass 2-95
manual control of authorization state 2-101
multiple hosts on authorized port 2-93
PAE as authenticator 2-100
periodic re-authentication
enabling 2-105
time between attempts 2-106
quiet period between failed authentication exchanges 2-106
re-authenticating IEEE 802.1x-enabled ports 2-103
resetting configurable IEEE 802.1x parameters 2-89
statistics and status display 2-342
switch-to-client frame-retransmission number 2-97, 2-98
switch-to-client retransmission time 2-106
port-channel load-balance command 2-287
Port Fast, for spanning tree 2-557
port labels 2-360, 2-363, 2-482
port ranges, defining 2-69
ports, debugging B-32
ports, protected 2-599
port security
aging 2-595
debug messages, display B-34
enabling 2-591
violation error recovery 2-113
port trust states for QoS 2-258
port types, MVR 2-268
power information, displaying 2-346
power inline command 2-289
Power over Ethernet
See PoE
priority-queue command 2-291
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-382
protected ports, displaying 2-377
pruning
VLANs 2-600
VTP
displaying interface information 2-371
enabling 2-648, 2-652, 2-654
PVST+
See STP
Q
QoS
automatic configuration 2-20
class maps
creating 2-40
defining the match criteria 2-235
displaying 2-322
defining the CoS value for an incoming packet 2-245
displaying configuration information 2-317, 2-439
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-249
defining DSCP-to-DSCP-mutation map 2-251
enabling 2-240
maps
defining 2-251
displaying 2-445
policy maps
applying an aggregate policer 2-282
applying to an interface 2-305, 2-309
creating 2-284
defining CoS 2-247
defining policers 2-243, 2-280
displaying policers 2-440, 2-441
displaying policy maps 2-460
policed-DSCP map 2-251
setting DSCP or IP precedence values 2-307
traffic classifications 2-38
trust states 2-614
port trust states 2-258
queues
CoS-to-egress-queue map 2-660
displaying buffer settings 2-441
displaying queueing strategies 2-441
enabling the expedite 2-291
mapping DSCPs to thresholds 2-662
minimum-reserve level 2-664
minimum-reserve level buffer sizes 2-255
ratio of queue sizes 2-665
queues
tail-drop threshold percentages 2-669
WRED threshold percentages 2-667
WRR weights 2-658
statistics
collecting on specified DSCPs 2-256
displaying DSCP information 2-441
tail-drop
assigning threshold percentages 2-669
mapping DSCPs to thresholds 2-662
trusted boundary for Cisco SoftPhones 2-258
trusted boundary for IP phones 2-258
WRED
assigning threshold percentages 2-667
enabling 2-667
mapping DSCPs to thresholds 2-662
quality of service
See QoS
querytime, MVR 2-265
R
radius-server dead-criteria command 2-292
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
rcommand command 2-294
re-authenticating IEEE 802.1x-enabled ports 2-103
re-authentication
periodic 2-105
time between attempts 2-106
receiver ports, MVR 2-268
receiving flow-control packets 2-117
recovery mechanism
causes 2-113
display 2-351
timer interval 2-113
redundancy for cluster switches 2-66
remote-span command 2-296
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-17
reset (boot loader) command A-18
reset command 2-636
resource templates, displaying 2-469
restricted VLAN
See dot1x auth-fail VLAN
rmdir (boot loader) command A-19
rmon collection stats command 2-297
root guard, for spanning tree 2-532
route distinguisher 2-198
routed ports
IP addresses on 2-130
number supported 2-130, 2-300
route-target command 2-198
RSPAN
and IDS 2-263
configuring 2-261
displaying 2-447
filter RSPAN traffic 2-261
remote-span command 2-296
sessions
add interfaces to 2-261
start new 2-261
S
sdm prefer command 2-299
secure ports, limitations 2-593
sending flow-control packets 2-117
service password-recovery command 2-302
service-policy command 2-305
set (boot loader) command A-20
set command 2-307
setup command 2-309
setup express command 2-312
show access-lists command 2-314
show archive status command 2-316
show arp access-list command 2-383
show auto qos command 2-317
show boot command 2-320
show changes command 2-636
show class-map command 2-322
show cluster candidates command 2-325
show cluster command 2-323
show cluster members command 2-327
show controllers cpu-interface command 2-329
show controllers ethernet-controller command 2-331
show controllers switch command 2-336
show controllers tcam command 2-337
show controllers utilization command 2-339
show controller utilization command 2-339
show current command 2-636
show dot1q-tunnel command 2-341
show dot1x command 2-342
show env command 2-346
show errdisable detect command 2-347
show errdisable flap-values command 2-349
show errdisable recovery command 2-351
show etherchannel command 2-353
show fallback profile command 2-356
show flowcontrol command 2-358
show fm command 2-360
show fm interface command 2-363
show fm vlan command 2-365
show forward command 2-366
show interfaces command 2-371
show interfaces counters command 2-380
show inventory command 2-382
show ip arp inspection command 2-384
show ip dhcp snooping binding command 2-388
show ip dhcp snooping command 2-387
show ip dhcp snooping database command 2-390, 2-392
show ip igmp profile command 2-395
show ip igmp snooping command 2-396
show ip igmp snooping groups command 2-399
show ip igmp snooping mrouter command 2-401
show ip igmp snooping querier command 2-403
show ip source binding command 2-405
show ip verify source command 2-406
show l2protocol-tunnel command 2-408
show l2tcam command 2-411
show l3tcam command 2-413
show lacp command 2-415
show mac access-group command 2-417
show mac address-table address command 2-421
show mac address-table aging time command 2-423
show mac address-table command 2-419
show mac address-table count command 2-425
show mac address-table dynamic command 2-427
show mac address-table interface command 2-429
show mac address-table multicast command 2-431
show mac address-table notification command 2-433
show mac address-table static command 2-435
show mac address-table vlan command 2-437
show mls qos aggregate-policer command 2-440
show mls qos command 2-439
show mls qos interface command 2-441
show mls qos maps command 2-445
show monitor command 2-447
show mvr command 2-449
show mvr interface command 2-451
show mvr members command 2-453
show pagp command 2-455
show parser macro command 2-457
show policy-map command 2-460
show port security command 2-462
show power inline command 2-465
show proposed command 2-636
show running-config vlan command 2-467
show sdm prefer command 2-469
show setup express command 2-471
show spanning-tree command 2-472
show storm-control command 2-479
show system mtu command 2-481
show tcam command 2-482
show tcam pbr command 2-485
show tcam qos command 2-487
show trust command 2-614
show udld command 2-489
show version command 2-492
show vlan access-map command 2-498
show vlan command 2-494
show vlan command fields 2-495
show vlan filter command 2-499
show vmps command 2-500
show vtp command 2-502
shutdown command 2-506
shutdown threshold, Layer 2 protocol tunneling 2-202
shutdown vlan command 2-507
skip-loopack-test command 2-508
Smartports macros
See macros
SNMP host, specifying 2-513
SNMP informs, enabling the sending of 2-509
snmp-server enable traps command 2-509
snmp-server host command 2-513
snmp-server ip command 2-517
snmp trap mac-notification command 2-519
SNMP traps
enabling MAC address notification trap 2-519
enabling the MAC address notification feature 2-218
enabling the sending of 2-509
setting DSCP or precedence of 2-517
software images
deleting 2-71
downloading 2-10
upgrading 2-10
uploading 2-16
software version, displaying 2-492
source ports, MVR 2-268
SPAN
and IDS 2-263
configuring 2-261
debug messages, display B-35
displaying 2-447
filter SPAN traffic 2-261
sessions
add interfaces to 2-261
start new 2-261
spanning 2-561
spanning-tree backbonefast command 2-521
spanning-tree bpdufilter command 2-522
spanning-tree bpduguard command 2-524
spanning-tree cost command 2-526
spanning-tree etherchannel command 2-528
spanning-tree extend system-id command 2-530
spanning-tree guard command 2-532
spanning-tree link-type command 2-534
spanning-tree loopguard default command 2-535
spanning-tree mode command 2-537
spanning-tree mst configuration command 2-539
spanning-tree mst cost command 2-541
spanning-tree mst forward-time command 2-543
spanning-tree mst hello-time command 2-544
spanning-tree mst max-age command 2-545
spanning-tree mst max-hops command 2-546
spanning-tree mst port-priority command 2-547
spanning-tree mst pre-standard command 2-549
spanning-tree mst priority command 2-550
spanning-tree mst root command 2-551
spanning-tree portfast (global configuration) command 2-555
spanning-tree portfast (interface configuration) command 2-557
spanning-tree port-priority command 2-553
spanning-tree stack-port command 2-559
spanning-tree transmit hold-count command 2-561
spanning-tree uplinkfast command 2-562
spanning-tree vlan command 2-564
speed command 2-567
SSH, configuring version 2-194
static-access ports, configuring 2-576
statistics, Ethernet group 2-297
sticky learning, enabling 2-591
storm-control command 2-569
STP
BackboneFast 2-521
debug message display
BackboneFast events B-38
MSTP B-41
optimized BPDUs handling B-40
spanning-tree activity B-36
switch shim B-43
transmitted and received BPDUs B-39
UplinkFast B-45
detection of indirect link failures 2-521
enabling protocol tunneling for 2-202
EtherChannel misconfiguration 2-528
extended system ID 2-530
path cost 2-526
protocol mode 2-537
root port
accelerating choice of new 2-562
accelerating choice of new root in a stack 2-559
cross-stack UplinkFast 2-559
loop guard 2-532
preventing from becoming designated 2-532
restricting which can be root 2-532
root guard 2-532
UplinkFast 2-562
root switch
affects of extended system ID 2-530, 2-565
hello-time 2-564
interval between BDPU messages 2-564
interval between hello BPDU messages 2-564
max-age 2-564
port priority for selection of 2-553
root switch
primary or secondary 2-564
switch priority 2-564
state changes
blocking to forwarding state 2-557
enabling BPDU filtering 2-522, 2-555
enabling BPDU guard 2-524, 2-555
enabling Port Fast 2-555, 2-557
enabling timer to recover from error state 2-113
forward-delay time 2-564
length of listening and learning states 2-564
shutting down Port Fast-enabled ports 2-555
state information display 2-472
VLAN options 2-550, 2-564
SVIs
creating 2-125
number supported 2-125, 2-130, 2-300
switchcore command 2-572
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-574, 2-589
returning to interfaces 2-574, 2-589
switchport access command 2-576
switchport backup interface command 2-578
switchport block command 2-581
switchport broadcast command 2-582
switchport command 2-574
switchport host command 2-583
switchport mode command 2-585
switchport multicast command 2-588
switchport nonegotiate command 2-589
switchport port-security aging command 2-595
switchport port-security command 2-591
switchport priority extend command 2-597
switchport protected command 2-599
switchports, displaying 2-371
switchport trunk command 2-600
switchport unicast command 2-604
switchport voice vlan command 2-605
switch resources
buffer storage priority 2-572
displaying resource-allocation priority 2-336
reserving for high-priority traffic 2-572
system message logging, save message to flash 2-211
system mtu command 2-607
system resource templates 2-299
T
tail-drop
assigning threshold percentages 2-669
mapping DSCPs to thresholds 2-662
tar files, creating, listing, and extracting 2-13
TCAM
debug messages, display B-2, B-23
displaying
ACL 2-482
Layer 2 2-411
Layer 3 2-413
PBR 2-485
QoS 2-487
Telnetting to cluster switches 2-294
temperature information, displaying 2-346
templates, system resources 2-299
traceroute mac command 2-609
traceroute mac ip command 2-612
trunking, VLAN mode 2-585
trunk mode 2-585, 2-600
trunk ports 2-585
trunks
allowed VLANs 2-600
configuring trunk characteristics 2-600
encapsulation methods 2-600
native VLANs 2-600
on GigaStack GBICs 2-586
pruning-eligible VLAN list 2-602
pruning VLANs 2-600
to non-DTP device 2-586
VLAN 1 minimization 2-602
trusted boundary for QoS 2-258
trusted port states for QoS 2-258
tunnel ports, Layer 2 protocol, displaying 2-408
type (boot loader) command A-23
U
UDLD
aggressive mode 2-616, 2-618
debug messages, display B-53
enable globally 2-616
enable per interface 2-618
error recovery timer 2-113
message timer 2-616
normal mode 2-616, 2-618
reset a shutdown interface 2-620
status 2-489
udld command 2-616
udld port command 2-618
udld reset command 2-620
unicast FIB, debugging B-24
unicast routes, debugging B-23
unicast storm control 2-569
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-581
unknown unicast traffic, preventing 2-581
unset (boot loader) command A-24
upgrading software images
from a server 2-10
monitoring status of 2-316
UplinkFast, for STP 2-562
user EXEC mode 1-2, 1-3
V
version (boot loader) command A-26
VLAN
enabling guest VLAN supplicant 2-79, 2-90, 2-115
vlan (global configuration) command 2-621
vlan (VLAN configuration) command 2-627
vlan access-map command 2-633
VLAN access map configuration mode 2-633
VLAN access maps
actions 2-8
displaying 2-498
VLAN configuration
rules 2-624, 2-629
saving 2-621, 2-631
VLAN configuration mode
commands
VLAN 2-627
VTP 2-654
description 1-4
entering 2-635
summary 1-2
vlan database command 2-635
vlan dot1q tag native command 2-639
vlan filter command 2-641
VLAN filters, displaying 2-499
VLAN ID range 2-621, 2-627
vlan labels 2-360, 2-365, 2-482
VLAN maps
applying 2-641
creating 2-633
defining 2-233
displaying 2-498
VLAN Query Protocol
See VQP
VLANs
adding 2-621
configuring 2-621, 2-627
debug message display
ISL B-49
VLAN IOS file system error tests B-48
VLAN manager activity B-46
VTP B-51
displaying configurations 2-467, 2-494
extended-range 2-621
MAC addresses
displaying 2-437
number of 2-425
media types 2-624, 2-629
normal-range 2-622, 2-627
restarting 2-507
saving the configuration 2-621
shutting down 2-507
SNMP traps for VTP 2-510, 2-514
suspending 2-507
trunks, VLAN 1 minimization 2-602
variables 2-627
VLAN Trunking Protocol
See VTP
VMPS
configuring servers 2-646
displaying 2-500
error recovery timer 2-113
reconfirming dynamic VLAN assignments 2-643
vmps reconfirm (global configuration) command 2-644
vmps reconfirm (privileged EXEC) command 2-643
vmps retry command 2-645
vmps server command 2-646
voice VLAN
configure 2-605
set port priority 2-597
VPN routing/forwarding table
See VRF
VQP
and dynamic-access ports 2-576
clearing client statistics 2-55
displaying information 2-500
per-server retry count 2-645
reconfirmation interval 2-644
reconfirming dynamic VLAN assignments 2-643
VRF 2-197, 2-200
VTP
changing characteristics 2-648
clearing pruning counters 2-56
configuring
domain name 2-648, 2-654
file name 2-648
mode 2-648, 2-654
password 2-648, 2-652, 2-654
counters display fields 2-503
displaying information 2-502
enabling
pruning 2-648, 2-652, 2-654
tunneling for 2-202
version 2 2-648, 2-652, 2-654
mode 2-648, 2-654
pruning 2-648, 2-652, 2-654
saving the configuration 2-621, 2-631
statistics 2-502
status 2-502
status display fields 2-504
vtp (global configuration) command 2-648
vtp (privileged EXEC) command 2-652
vtp (VLAN configuration) command 2-654
W
WRED
assigning threshold percentages 2-667
enabling 2-667
mapping DSCPs to thresholds 2-662
WRR, assigning weights to egress queues 2-658
wrr-queue bandwidth command 2-658
wrr-queue cos-map command 2-660
wrr-queue dscp-map command 2-662
wrr-queue min-reserve command 2-664
wrr-queue queue-limit command 2-665
wrr-queue random-detect max-threshold command 2-667
wrr-queue threshold command 2-669