Index

A

aaa accounting dot1x command 2-1

aaa authentication dot1x command 2-3

aaa authorization network command 2-5, 2-26, 2-33, 2-35, 2-38, 2-40, 2-42, 2-168, 2-349, 2-551, B-7, B-39

AAA methods 2-3

access control entries

See ACEs

access control lists

See ACLs

access groups

IP 2-222

MAC, displaying 2-696

access list, IPv6 2-299

access map configuration mode 2-366

access mode 2-908

access ports 2-908

ACEs 2-152, 2-456

ACLs

deny 2-150

displaying 2-532

for non-IP protocols 2-353

IP 2-222

matching 2-366

on Layer 2 interfaces 2-222

permit 2-454

action command 2-8

address aliasing 2-424

aggregate-port learner 2-440

allowed VLANs 2-928

archive copy-sw command 2-10

archive download-sw command 2-13

archive tar command 2-17

archive upload-sw command 2-20

arp (boot loader) command A-2

arp access-list command 2-22

authentication command bounce-port ignore 2-24

authentication command disable-port ignore 2-25

authentication control-direction command 2-26

authentication event command 2-28

authentication event linksec fail action command 2-32

authentication failed VLAN

See dot1x auth-fail vlan

authentication fallback command 2-33

authentication host-mode command 2-35

authentication linksec policy command 2-37

authentication mac-move permit command 2-38

authentication open command 2-40

authentication order command 2-42

authentication periodic command 2-44

authentication port-control command 2-46

authentication priority command 2-48

authentication timer command 2-50

authentication violation command 2-52

auth-fail max-attempts

See dot1x auth-fail max-attempts

auth-fail vlan

See dot1x auth-fail vlan

auth open command 2-40

auth order command 2-42

authorization state of controlled port 2-185

auth timer command 2-50

autonegotiation of duplex mode 2-197

auto qos classify command 2-54

auto qos trust command 2-57

auto qos video command 2-60

auto qos voip command 2-63

B

BackboneFast, for STP 2-828

backup interfaces

configuring 2-902

displaying 2-616

boot (boot loader) command A-3

boot auto-copy-sw command 2-70

boot auto-download-sw command 2-71

boot config-file command 2-74

boot enable-break command 2-75

boot helper command 2-76

boot helper-config file command 2-77

booting

Cisco IOS image 2-80

displaying environment variables 2-545

interrupting 2-75

manually 2-78

boot loader

accessing A-1

booting

Cisco IOS image A-3

helper image 2-76

directories

creating A-19

displaying a list of A-8

removing A-23

displaying

available commands A-13

memory heap utilization A-14

version A-30

environment variables

described A-24

displaying settings A-24

location of A-25

setting A-24

unsetting A-28

files

copying A-6

deleting A-7

displaying a list of A-8

displaying the contents of A-5, A-20, A-27

renaming A-21

file system

formatting A-11

initializing flash A-10

running a consistency check A-12

resetting the system A-22

boot manual command 2-78

boot private-config-file command 2-79

boot system command 2-80

boot time-copy-sw command 2-69

BPDU filtering, for spanning tree 2-829, 2-863

BPDU guard, for spanning tree 2-831, 2-863

broadcast storm control 2-886

C

candidate switches

See clusters

cat (boot loader) command A-5

CDP, enabling protocol tunneling for 2-326

channel-group command 2-84

channel-protocol command 2-88

Cisco Redundant Power System 2300

configuring 2-478

managing 2-478

Cisco SoftPhone

auto-QoS configuration 2-63

trusting packets sent from 2-413

CISP

See Client Information Signalling Protocol

cisp

debug platform cisp command B-39

cisp enable command 2-89

class command 2-90

class-map command 2-93

class maps

creating 2-93

defining the match criteria 2-368

displaying 2-552

class of service

See CoS

clear dot1x command 2-95

clear eap sessions command 2-96

clear errdisable interface 2-97

clear ip arp inspection log command 2-98

clear ip arp inspection statistics command 2-99

clear ipc command 2-102

clear ip dhcp snooping database command 2-100

clear ipv6 dhcp conflict command 2-103

clear l2protocol-tunnel counters command 2-104

clear lacp command 2-105

clear logging onboard command 2-106

clear logging smartlog statistics interface command 2-107

clear mac address-table command 2-108, 2-109

clear macsec counters interface command 2-110

clear mka command 2-111

clear nmsp statistics command 2-113

clear pagp command 2-114

clear port-security command 2-115

clear psp counter 2-117

clear psp counter command 2-117

clear spanning-tree counters command 2-118

clear spanning-tree detected-protocols command 2-119

clear vmps statistics command 2-120

clear vtp counters command 2-121

Client Information Signalling Protocol 2-89, 2-168, 2-551, B-7, B-39

cluster commander-address command 2-122

cluster discovery hop-count command 2-124

cluster enable command 2-125

cluster holdtime command 2-127

cluster member command 2-128

cluster outside-interface command 2-130

cluster run command 2-131

clusters

adding candidates 2-128

binding to HSRP group 2-132

building manually 2-128

communicating with

devices outside the cluster 2-130

members by using Telnet 2-500

debug messages, display B-8

displaying

candidate switches 2-555

debug messages B-8

member switches 2-557

status 2-553

hop-count limit for extended discovery 2-124

HSRP standby groups 2-132

redundancy 2-132

SNMP trap 2-817

cluster standby-group command 2-132

cluster timer command 2-134

command modes defined 1-2

command switch

See clusters

confidentiality-offset command 2-137

configuration files

password recovery disable considerations A-1

specifying the name 2-74, 2-79

configuring multiple interfaces 2-218

config-vlan mode

commands 2-954

copy (boot loader) command A-6

copy logging onboard command 2-135

CoS

assigning default value to incoming packets 2-383

assigning to Layer 2 protocol packets 2-329

overriding the incoming value 2-383

CoS-to-DSCP map 2-387

CPU ASIC statistics, displaying 2-559

crashinfo files 2-209

critical VLAN 2-29

D

debug authentication B-2

debug auto qos command B-4

debug backup command B-6

debug cisp command B-7

debug cluster command B-8

debug dot1x command B-10

debug dtp command B-11

debug eap command B-12

debug etherchannel command B-13

debug fastethernet command B-14

debug ilpower command B-15

debug interface command B-16

debug ip dhcp snooping command B-17

debug ip igmp filter command B-19

debug ip igmp max-groups command B-20

debug ip igmp snooping command B-21

debug ip verify source packet command B-18

debug lacp command B-22

debug lldp packets command B-23

debug mac-notification command B-25

debug macsec command B-26

debug matm command B-27

debug matm move update command B-28

debug mka command B-29

debug monitor command B-31

debug mvrdbg command B-32

debug nmsp command B-33

debug nvram command B-34

debug pagp command B-35

debug platform acl command B-36

debug platform backup interface command B-38

debug platform cisp command B-39

debug platform cli-redirection main command B-40

debug platform configuration command B-41, B-49

debug platform cpu-queues command B-42

debug platform device-manager command B-44

debug platform dot1x command B-45

debug platform etherchannel command B-46

debug platform fallback-bridging command B-47

debug platform forw-tcam command B-48

debug platform ip arp inspection command B-50

debug platform ipc command B-59

debug platform ip dhcp command B-51

debug platform ip igmp snooping command B-52

debug platform ip multicast command B-54

debug platform ip unicast command B-56

debug platform ip wccp command B-58

debug platform led command B-60

debug platform matm command B-61

debug platform messaging application command B-62

debug platform phy command B-63

debug platform pm command B-65

debug platform port-asic command B-67

debug platform port-security command B-68

debug platform qos-acl-tcam command B-69

debug platform remote-commands command B-70

debug platform resource-manager command B-71

debug platform snmp command B-72

debug platform span command B-73

debug platform stack-manager command B-74

debug platform supervisor-asic command B-75

debug platform sw-bridge command B-76

debug platform tcam command B-77

debug platform udld command B-80

debug platform vlan command B-81

debug pm command B-82

debug port-security command B-84

debug qos-manager command B-85

debug spanning-tree backbonefast command B-88

debug spanning-tree bpdu command B-89

debug spanning-tree bpdu-opt command B-90

debug spanning-tree command B-86

debug spanning-tree mstp command B-91

debug spanning-tree switch command B-93

debug spanning-tree uplinkfast command B-95

debug sw-vlan command B-96

debug sw-vlan ifs command B-98

debug sw-vlan notification command B-99

debug sw-vlan vtp command B-101

debug udld command B-103

debug vqpc command B-105

default policy, MKA 2-374

define interface-range command 2-138

delete (boot loader) command A-7

delete command 2-140

deny (ARP access-list configuration) command 2-143

deny (IPv6) command 2-145

deny command 2-150

detect mechanism, causes 2-200

DHCP snooping

accepting untrusted packets from edge switch 2-256

enabling

on a VLAN 2-262

option 82 2-254, 2-256

trust on an interface 2-260

error recovery timer 2-205

rate limiting 2-259

DHCP snooping binding database

binding file, configuring 2-252

bindings

adding 2-250

deleting 2-250

displaying 2-638

clearing database agent statistics 2-100

database agent, configuring 2-252

displaying

binding entries 2-638

database agent status 2-640, 2-642

renewing 2-508

Digital Optical Monitoring

see DoM

dir (boot loader) command A-8

directories, deleting 2-140

DoM

displaying supported transceivers 2-629

domain name, VTP 2-969

dot1x auth-fail max-attempts 2-162

dot1x auth-fail vlan 2-164

dot1x command 2-160

dot1x control-direction command 2-166

dot1x credentials (global configuration) command 2-168

dot1x critical global configuration command 2-169

dot1x critical interface configuration command 2-171

dot1x default command 2-173

dot1x fallback command 2-174

dot1x guest-vlan command 2-175

dot1x host-mode command 2-177

dot1x initialize command 2-178

dot1x mac-auth-bypass command 2-179

dot1x max-reauth-req command 2-181

dot1x max-req command 2-183

dot1x pae command 2-184

dot1x port-control command 2-185

dot1x re-authenticate command 2-187

dot1x reauthentication command 2-188

dot1x supplicant force-multicast command 2-189

dot1x test eapol-capable command 2-190

dot1x test timeout command 2-191

dot1x timeout command 2-192

dot1x violation-mode command 2-195

dropping packets, with ACL matches 2-8

drop threshold, Layer 2 protocol tunneling 2-326

DSCP-to-CoS map 2-387

DSCP-to-DSCP-mutation map 2-387

DTP 2-909

DTP flap

error detection for 2-200

error recovery timer 2-205

DTP negotiation 2-913

dual IPv4 and IPv6 templates 2-448

duplex command 2-196

dynamic-access ports

configuring 2-898

restrictions 2-899

dynamic ARP inspection

ARP ACLs

apply to a VLAN 2-230

define 2-22

deny packets 2-143

display 2-536

permit packets 2-446

clear

log buffer 2-98

statistics 2-99

display

ARP ACLs 2-536

configuration and operating state 2-633

log buffer 2-633

statistics 2-633

trust state and rate limit 2-633

enable per VLAN 2-242

error detection for 2-200

error recovery timer 2-205

log buffer

clear 2-98

configure 2-234

display 2-633

rate-limit incoming ARP packets 2-232

statistics

clear 2-99

display 2-633

trusted interface state 2-238

type of packet logged 2-243

validation checks 2-240

dynamic auto VLAN membership mode 2-908

dynamic desirable VLAN membership mode 2-908

Dynamic Host Configuration Protocol (DHCP)

See DHCP snooping

Dynamic Trunking Protocol

See DTP

E

EAP-request/identity frame

maximum number to send 2-183

response time before retransmitting 2-192

encapsulation methods 2-928

environment variables, displaying 2-545

epm access-control open 2-198

errdisable detect cause command 2-200

errdisable detect cause small-frame command 2-203

errdisable recovery cause small-frame 2-208

errdisable recovery command 2-205

error conditions, displaying 2-603

error disable detection 2-200

error-disabled interfaces, displaying 2-615

EtherChannel

assigning Ethernet interface to channel group 2-84

creating port-channel logical interface 2-216

debug EtherChannel/PAgP, display B-13

debug platform-specific events, display B-46

displaying 2-606

enabling Layer 2 protocol tunneling for

LACP 2-327

PAgP 2-327

UDLD 2-327

interface information, displaying 2-615

LACP

clearing channel-group information 2-105, 2-106

debug messages, display B-22

displaying 2-679

modes 2-84

port priority for hot-standby ports 2-330

restricting a protocol 2-88

system priority 2-332

load-distribution methods 2-464

PAgP

aggregate-port learner 2-440

clearing channel-group information 2-114

debug messages, display B-35

displaying 2-759

error detection for 2-200

error recovery timer 2-205

learn method 2-440

modes 2-84

physical-port learner 2-440

priority of interface for transmitted traffic 2-442

Ethernet controller, internal register display 2-561, 2-568

Ethernet Management port, debugging B-14

Ethernet statistics, collecting 2-513

exception crashinfo command 2-209, 2-214

extended discovery of candidate switches 2-124

extended-range VLANs

and allowed VLAN list 2-928

and pruning-eligible list 2-928

configuring 2-953

extended system ID for STP 2-837

F

fallback profile command 2-210

fallback profiles, displaying 2-609

fan information, displaying 2-594

file name, VTP 2-969

files, deleting 2-140

flash_init (boot loader) command A-10

flexible authentication ordering 2-42

Flex Links

configuring 2-902

displaying 2-616

flow-based SPAN 2-418

flowcontrol command 2-212

format (boot loader) command A-11

forwarding packets, with ACL matches 2-8

forwarding results, display C-7

frame forwarding information, displaying C-7

front-end controller counter and status information C-9

fsck (boot loader) command A-12

FSPAN 2-418

G

global configuration mode 1-2, 1-4

H

hardware ACL statistics 2-532

health monitoring diagnostic tests 2-153

help (boot loader) command A-13

hierarchical policy maps 2-462

hop-count limit for clusters 2-124

host connection, port configuration 2-907

host ports, private VLANs 2-911

Hot Standby Router Protocol

See HSRP

HSRP

binding HSRP group to cluster 2-132

standby group 2-132

I

IEEE 802.1Q trunk ports and native VLANs 2-960

IEEE 802.1Q tunnel ports

configuring 2-908

displaying 2-584

limitations 2-909

IEEE 802.1x

and switchport modes 2-909

violation error recovery 2-205

See also port-based authentication

IGMP filters

applying 2-266

debug messages, display B-19

IGMP groups, setting maximum 2-267

IGMP maximum groups, debugging B-20

IGMP profiles

creating 2-269

displaying 2-645

IGMP snooping

adding ports as a static member of a group 2-285

displaying 2-646, 2-651, 2-653

enabling 2-271

enabling the configurable-leave timer 2-273

enabling the Immediate-Leave feature 2-282

flooding query count 2-279

interface topology change notification behavior 2-281

multicast table 2-649

querier 2-275

query solicitation 2-279

report suppression 2-277

switch topology change notification behavior 2-279

images

See software images

Immediate-Leave processing

IGMP 2-282

IPv6 2-322

MVR 2-426

interface configuration mode 1-2, 1-4

interface port-channel command 2-216

interface range command 2-218

interface-range macros 2-138

interfaces

assigning Ethernet interface to channel group 2-84

configuring 2-196

configuring multiple 2-218

creating port-channel logical 2-216

debug messages, display B-16

disabling 2-813

displaying the MAC address table 2-707

restarting 2-813

interface speed, configuring 2-874

interface vlan command 2-220

internal power supplies

See power supplies

internal registers, displaying 2-561, 2-568, 2-575

Internet Group Management Protocol

See IGMP

invalid GBIC

error detection for 2-200

error recovery timer 2-205

ip access-group command 2-222

ip address command 2-225

IP addresses, setting 2-225

IP address matching 2-366

ip admission command 2-227

ip admission name proxy http command 2-228

ip arp inspection filter vlan command 2-230

ip arp inspection limit command 2-232

ip arp inspection log-buffer command 2-234

ip arp inspection trust command 2-238

ip arp inspection validate command 2-240

ip arp inspection vlan command 2-242

ip arp inspection vlan logging command 2-243

ip device tracking command 2-245

ip device tracking probe command 2-247

IP DHCP snooping

See DHCP snooping

ip dhcp snooping binding command 2-250

ip dhcp snooping command 2-249

ip dhcp snooping database command 2-252

ip dhcp snooping information option allow-untrusted command 2-256

ip dhcp snooping information option command 2-254

ip dhcp snooping information option format remote-id command 2-258

ip dhcp snooping limit rate command 2-259

ip dhcp snooping trust command 2-260

ip dhcp snooping verify command 2-261

ip dhcp snooping vlan command 2-262

ip dhcp snooping vlan information option format-type circuit-id string command 2-264

ip igmp filter command 2-266

ip igmp max-groups command 2-267, 2-292, 2-294

ip igmp profile command 2-269

ip igmp snooping command 2-271

ip igmp snooping last-member-query-interval command 2-273

ip igmp snooping querier command 2-275

ip igmp snooping report-suppression command 2-277

ip igmp snooping tcn command 2-279

ip igmp snooping tcn flood command 2-281

ip igmp snooping vlan immediate-leave command 2-282

ip igmp snooping vlan mrouter command 2-283

ip igmp snooping vlan static command 2-285

IP multicast addresses 2-423

IP phones

auto-QoS configuration 2-63

trusting packets sent from 2-413

IP-precedence-to-DSCP map 2-387

ip snap forwarding command 2-287

ip source binding command 2-288

IP source guard

disabling 2-296

displaying

binding entries 2-655

configuration 2-657

dynamic binding entries only 2-638

enabling 2-296

static IP source bindings 2-288

ip ssh command 2-290

IPv4 and IPv6

port-based trust 2-414

IPv6 access list, deny conditions 2-145

ipv6 access-list command 2-299

ipv6 address dhcp command 2-302

ipv6 dhcp client request vendor command 2-303

ipv6 dhcp ping packets command 2-304

ipv6 dhcp pool command 2-306

ipv6 dhcp server command 2-309

ipv6 mld snooping command 2-311

ipv6 mld snooping last-listener-query count command 2-313

ipv6 mld snooping last-listener-query-interval command 2-315

ipv6 mld snooping listener-message-suppression command 2-317

ipv6 mld snooping robustness-variable command 2-318

ipv6 mld snooping tcn command 2-320

ipv6 mld snooping vlan command 2-322

IPv6 QoS

enabling 2-379

IPv6 SDM template 2-515

ipv6 traffic-filter command 2-324

ip verify source command 2-296

ip verify source smartlog command 2-298

J

jumbo frames

See MTU

L

l2protocol-tunnel command 2-326

l2protocol-tunnel cos command 2-329

LACP

See EtherChannel

lacp port-priority command 2-330

lacp system-priority command 2-332

Layer 2 mode, enabling 2-896

Layer 2 protocol ports, displaying 2-676

Layer 2 protocol-tunnel

error detection for 2-200

error recovery timer 2-205

Layer 2 protocol tunnel counters 2-104

Layer 2 protocol tunneling error recovery 2-327

Layer 2 traceroute

IP addresses 2-943

MAC addresses 2-940

Layer 3 mode, enabling 2-896

license boot command 2-334

line configuration mode 1-3, 1-5

Link Aggregation Control Protocol

See EtherChannel

link flap

error detection for 2-200

error recovery timer 2-205

link-security authentication 2-32

link-security policies 2-37

link state group command 2-336

link state track command 2-338

load-distribution methods for EtherChannel 2-464

location (global configuration) command 2-339

location (interface configuration) command 2-341

logging event command 2-343

logging event power-inline-status command 2-344

logging file command 2-345

logical interface 2-216

loopback error

detection for 2-200

recovery timer 2-205

loop guard, for spanning tree 2-839, 2-843

M

mab request format attribute 32 command 2-349

mac access-group command 2-351

MAC access-groups, displaying 2-696

MAC access list configuration mode 2-353

mac access-list extended command 2-353

MAC access lists 2-150

MAC addresses

disabling MAC address learning per VLAN 2-356

displaying

aging time 2-701

all 2-699

dynamic 2-705

MAC address-table move updates 2-710

notification settings 2-709, 2-712

number of addresses in a VLAN 2-703

per interface 2-707

per VLAN 2-716

static 2-714

static and dynamic entries 2-697

dynamic

aging time 2-355

deleting 2-108

displaying 2-705

enabling MAC address notification 2-360

enabling MAC address-table move update 2-358

matching 2-366

persistent stack 2-882

static

adding and removing 2-362

displaying 2-714

dropping on an interface 2-363

tables 2-699

MAC address notification, debugging B-25

mac address-table aging-time 2-351, 2-366

mac address-table aging-time command 2-355

mac address-table learning command 2-356

mac address-table move update command 2-358

mac address-table notification command 2-360

mac address-table static command 2-362

mac address-table static drop command 2-363

MAC frames

See MTU

macros

interface range 2-138, 2-218

MACsec

counters 2-110, 2-571

debugging B-26

displaying 2-718

enabling 2-365

registers 2-571

macsec command 2-365

maps

QoS

defining 2-387

displaying 2-742

VLAN

creating 2-958

defining 2-366

displaying 2-804

match (access-map configuration) command 2-366

match (class-map configuration) command 2-368

maximum transmission unit

See MTU

mdix auto command 2-371

Media Access Control Security

See MACsec.

media-type rj45 command 2-373

member switches

See clusters

memory (boot loader) command A-14

mgmt_clr (boot loader) command A-16

mgmt_init (boot loader) command A-17, A-18

MKA

confidentiality 2-137

debugging B-29

displaying default policy 2-720

displaying policies 2-722

displaying sessions 2-725

displaying sessions and statistics 2-731

displaying statistics 2-728

policy configuration mode 2-375

MKA, enabling 2-377

mka default policy command 2-374

mka policy global configuration command 2-375

mka policy interface configuration command 2-377

mkdir (boot loader) command A-19

MLD snooping

configuring 2-317, 2-318

configuring queries 2-313, 2-315

configuring topology change notification 2-320

displaying 2-666, 2-668, 2-670, 2-672

enabling 2-311

enabling on a VLAN 2-322

mls qos aggregate-policer command 2-381

mls qos command 2-379

mls qos cos command 2-383

mls qos dscp-mutation command 2-385

mls qos map command 2-387

mls qos queue-set output buffers command 2-391

mls qos queue-set output threshold command 2-393

mls qos rewrite ip dscp command 2-395

mls qos srr-queue input bandwidth command 2-397

mls qos srr-queue input buffers command 2-399

mls qos-srr-queue input cos-map command 2-401

mls qos srr-queue input dscp-map command 2-403

mls qos srr-queue input priority-queue command 2-405

mls qos srr-queue input threshold command 2-407

mls qos-srr-queue output cos-map command 2-409

mls qos srr-queue output dscp-map command 2-411

mls qos trust command 2-413

mls qos vlan-based command 2-415

mode, MVR 2-423

Mode button, and password recovery 2-519

mode command 2-416

modes, commands 1-2

monitor session command 2-418

more (boot loader) command A-20

MSTP

displaying 2-778

interoperability 2-119

link type 2-841

MST region

aborting changes 2-847

applying changes 2-847

configuration name 2-847

configuration revision number 2-847

current or pending display 2-847

displaying 2-778

MST configuration mode 2-847

VLANs-to-instance mapping 2-847

path cost 2-849

protocol mode 2-845

restart protocol migration process 2-119

root port

loop guard 2-839

preventing from becoming designated 2-839

restricting which can be root 2-839

root guard 2-839

root switch

affects of extended system ID 2-837

hello-time 2-852, 2-859

interval between BDPU messages 2-853

interval between hello BPDU messages 2-852, 2-859

max-age 2-853

maximum hop count before discarding BPDU 2-854

port priority for selection of 2-855

primary or secondary 2-859

switch priority 2-858

state changes

blocking to forwarding state 2-866

enabling BPDU filtering 2-829, 2-863

enabling BPDU guard 2-831, 2-863

enabling Port Fast 2-863, 2-866

forward-delay time 2-851

length of listening and learning states 2-851

rapid transition to forwarding 2-841

shutting down Port Fast-enabled ports 2-863

state information display 2-777

MTU

configuring size 2-936

displaying global setting 2-793

MAC 2-937

system jumbo 2-937

system routing 2-937

Multicase Listener Discovery

See MLD

multicast group address, MVR 2-426

multicast groups, MVR 2-424

Multicast Listener Discovery

See MLD

multicast router learning method 2-283

multicast router ports, configuring 2-283

multicast router ports, IPv6 2-322

multicast storm control 2-886

multicast VLAN, MVR 2-423

multicast VLAN registration

See MVR

multiple hosts on authorized port 2-177

Multiple Spanning Tree Protocol

See MSTP

MVR

and address aliasing 2-424

configuring 2-423

configuring interfaces 2-426

debug messages, display B-32

displaying 2-749

displaying interface information 2-751

members, displaying 2-753

mvr (global configuration) command 2-423

mvr (interface configuration) command 2-426

mvr vlan group command 2-427

N

native VLANs 2-928

native VLAN tagging 2-960

network-policy (global configuration) command 2-430

network-policy command 2-429

network-policy profile (network-policy configuration) command 2-431

nmsp attachment suppress command 2-434

nmsp command 2-433

no authentication logging verbose 2-435

no dot1x logging verbose 2-436

no mab logging verbose 2-437

nonegotiate

DTP messaging 2-913

speed 2-874

non-IP protocols

denying 2-150

forwarding 2-454

non-IP traffic access lists 2-353

non-IP traffic forwarding

denying 2-150

permitting 2-454

non-stop forwarding 2-438

normal-range VLANs 2-953

no vlan command 2-953

nsf command 2-438

O

online diagnostics

configuring health monitoring diagnostic tests 2-153

displaying

configured boot-up coverage level 2-579

current scheduled tasks 2-579

event logs 2-579

supported test suites 2-579

test ID 2-579

test results 2-579

test statistics 2-579

enabling

scheduling 2-155

syslog messages 2-153

global configuration mode

clearing health monitoring diagnostic test schedule 2-153

clearing test-based testing schedule 2-155

setting health monitoring diagnostic testing 2-153

setting test-based testing 2-155

setting up health monitoring diagnostic test schedule 2-153

setting up test-based testing 2-155

removing scheduling 2-155

scheduled switchover

disabling 2-155

enabling 2-155

setting test interval 2-155

specifying health monitoring diagnostic tests 2-153

starting testing 2-157

P

PAgP

See EtherChannel

pagp learn-method command 2-440

pagp port-priority command 2-442

password, VTP 2-970

password-recovery mechanism, enabling and disabling 2-519

permit (ARP access-list configuration) command 2-446

permit (IPv6) command 2-448

permit (MAC access-list configuration) command 2-454

per-VLAN spanning-tree plus

See STP

physical-port learner 2-440

PID, displaying 2-632

PIM-DVMRP, as multicast router learning method 2-283

PoE

configuring the power budget 2-469

configuring the power management mode 2-466

displaying controller register values 2-573

displaying power management information 2-765

error detection for 2-200

error recovery timer 2-205

logging of status 2-344

monitoring power 2-472

policing power consumption 2-472

police aggregate command 2-459

police command 2-457

policed-DSCP map 2-387

policy-map command 2-461

policy maps

applying to an interface 2-521, 2-527

creating 2-461

displaying 2-761

hierarchical 2-462

policers

displaying 2-735

for a single class 2-457

for multiple classes 2-381, 2-459

policed-DSCP map 2-387

traffic classification

defining the class 2-90

defining trust states 2-945

setting DSCP or IP precedence values 2-525

Port Aggregation Protocol

See EtherChannel

port-based authentication

AAA method list 2-3

configuring violation modes 2-195

debug messages, display B-10

enabling guest VLAN supplicant 2-163, 2-174

enabling IEEE 802.1x

globally 2-160

per interface 2-185

guest VLAN 2-175

host modes 2-177

IEEE 802.1x AAA accounting methods 2-1

initialize an interface 2-178, 2-191

MAC authentication bypass 2-179

manual control of authorization state 2-185

multiple hosts on authorized port 2-177

PAE as authenticator 2-184

periodic re-authentication

enabling 2-188

time between attempts 2-192

quiet period between failed authentication exchanges 2-192

re-authenticating IEEE 802.1x-enabled ports 2-187

resetting configurable IEEE 802.1x parameters 2-173

switch-to-authentication server retransmission time 2-192

switch-to-client frame-retransmission number 2-181 to 2-183

switch-to-client retransmission time 2-192

test for IEEE 802.1x readiness 2-190

port-based trust

IPv4 and IPv6 2-414

port-channel load-balance command 2-464

Port Fast, for spanning tree 2-866

port ranges, defining 2-135, 2-138

ports, debugging B-82

ports, protected 2-926

port security

aging 2-920

debug messages, display B-84

enabling 2-915

violation error recovery 2-205

port trust states for QoS 2-413

port types, MVR 2-426

power information, displaying 2-594

power inline command 2-466

power inline consumption command 2-469

power inline police command 2-472

Power over Ethernet

See PoE

power-priority command 2-475

power rps command (global configuration) 2-481

power rps command (user EXEC) 2-477

power supply

configuring 2-479

managing 2-479

power supply command 2-479

power xps command privileged EXEC) 2-483

power xps port command 2-485

priority-queue command 2-487

priority value, stack member 2-788, 2-891

private-vlan command 2-489

private-vlan mapping command 2-492

private VLANs

association 2-924

configuring 2-489

configuring ports 2-911

displaying 2-799

host ports 2-911

mapping

configuring 2-924

displaying 2-615

promiscuous ports 2-911

privileged EXEC mode 1-2, 1-3

product identification information, displaying 2-632

promiscuous ports, private VLANs 2-911

protected ports, displaying 2-621

pruning

VLANs 2-928

VTP

enabling 2-970

pruning-eligible VLAN list 2-930

psp 2-494

psp command 2-494

PVST+

See STP

Q

QoS

auto-QoS

configuring 2-63

debug messages, display B-4

displaying 2-541

auto-QoS trust

configuring 2-57

auto-QoS video

configuring 2-60

class maps

creating 2-93

defining the match criteria 2-368

displaying 2-552

defining the CoS value for an incoming packet 2-383

displaying configuration information 2-541, 2-734

DSCP transparency 2-395

DSCP trusted ports

applying DSCP-to-DSCP-mutation map to 2-385

defining DSCP-to-DSCP-mutation map 2-387

egress queues

allocating buffers 2-391

defining the CoS output queue threshold map 2-409

defining the DSCP output queue threshold map 2-411

displaying buffer allocations 2-738

displaying CoS output queue threshold map 2-742

displaying DSCP output queue threshold map 2-742

displaying queueing strategy 2-738

displaying queue-set settings 2-745

enabling bandwidth shaping and scheduling 2-878

enabling bandwidth sharing and scheduling 2-880

limiting the maximum output on a port 2-876

mapping a port to a queue-set 2-495

mapping CoS values to a queue and threshold 2-409

mapping DSCP values to a queue and threshold 2-411

setting maximum and reserved memory allocations 2-393

setting WTD thresholds 2-393

enabling 2-379

enabling IPv6 QoS 2-379

ingress queues

allocating buffers 2-399

assigning SRR scheduling weights 2-397

defining the CoS input queue threshold map 2-401

defining the DSCP input queue threshold map 2-403

displaying buffer allocations 2-738

displaying CoS input queue threshold map 2-742

displaying DSCP input queue threshold map 2-742

displaying queueing strategy 2-738

displaying settings for 2-736

enabling the priority queue 2-405

mapping CoS values to a queue and threshold 2-401

mapping DSCP values to a queue and threshold 2-403

setting WTD thresholds 2-407

maps

defining 2-387, 2-401, 2-403, 2-409, 2-411

displaying 2-742

policy maps

applying an aggregate policer 2-459

applying to an interface 2-521, 2-527

creating 2-461

defining policers 2-381, 2-457

displaying policers 2-735

displaying policy maps 2-761

hierarchical 2-462

policed-DSCP map 2-387

setting DSCP or IP precedence values 2-525

traffic classifications 2-90

trust states 2-945

port trust states 2-413

queues, enabling the expedite 2-487

statistics

in-profile and out-of-profile packets 2-738

packets enqueued or dropped 2-738

sent and received CoS values 2-738

sent and received DSCP values 2-738

trusted boundary for IP phones 2-413

VLAN-based 2-415

quality of service

See QoS

querytime, MVR 2-423

queue-set command 2-495

R

radius-server dead-criteria command 2-496

radius-server host command 2-498

rapid per-VLAN spanning-tree plus

See STP

rapid PVST+

See STP

rcommand command 2-500

re-authenticating IEEE 802.1x-enabled ports 2-187

re-authentication

periodic 2-188

time between attempts 2-192

receiver ports, MVR 2-426

receiving flow-control packets 2-212

recovery mechanism

causes 2-205

display 2-97, 2-548, 2-601, 2-604

timer interval 2-206

redundancy for cluster switches 2-132

redundant power supply

See RPS

redundant power system

See Cisco Redundant Power System 2300

reload command 2-502

remote command 2-504

remote-span command 2-506

Remote Switched Port Analyzer

See RSPAN

rename (boot loader) command A-21

renew ip dhcp snooping database command 2-508

replay protection, MACsec 2-510

replay-protection command 2-510

reset (boot loader) command A-22

restricted VLAN

See dot1x auth-fail vlan

rmdir (boot loader) command A-23

rmon collection stats command 2-513

root guard, for spanning tree 2-839

routed ports

IP addresses on 2-226

number supported 2-226

routing frames

See MTU

RPS

See Cisco Redundant Power System 2300

RPS 2300

configuring 2-477, 2-483, 2-485

managing 2-477, 2-483, 2-485

See Cisco Redundant Power System 2300

RSPAN

configuring 2-418

displaying 2-747

filter RSPAN traffic 2-418

remote-span command 2-506

sessions

add interfaces to 2-418

displaying 2-747

start new 2-418

rsu command 2-514

S

scheduled switchover

disabling 2-155

enabling 2-155

SDM mismatch mode 2-516, 2-789

sdm prefer command 2-515

SDM templates

allowed resources 2-517

and stacking 2-516

displaying 2-773

dual IPv4 and IPv6 2-515

secure ports, limitations 2-917

sending flow-control packets 2-212

service password-recovery command 2-519

service-policy command 2-521

session command 2-524

set (boot loader) command A-24

set command 2-525

setup command 2-527

setup express command 2-530

show access-lists command 2-532

show archive status command 2-535

show arp access-list command 2-536

show authentication command 2-537

show auto qos command 2-541

show boot command 2-545

show cable-diagnostics tdr command 2-548

show cisp command 2-551

show class-map command 2-552

show cluster candidates command 2-555

show cluster command 2-553

show cluster members command 2-557

show controllers cpu-interface command 2-559

show controllers ethernet-controller command 2-561

show controllers ethernet-controller fastethernet command 2-568

show controllers ethernet phy macsec command 2-571

show controllers power inline command 2-573

show controllers tcam command 2-575

show controller utilization command 2-577

show dot1q-tunnel command 2-584

show dot1x command 2-585

show dtp 2-589

show eap command 2-591

show env command 2-594

show env xps command 2-597

show errdisable detect command 2-601

show errdisable flap-values command 2-603

show errdisable recovery command 2-604

show etherchannel command 2-606

show fallback profile command 2-609

show flowcontrol command 2-611

show idprom command 2-613

show interfaces command 2-615

show interfaces counters command 2-626

show interface transceivers command 2-629

show inventory command 2-632

show ip arp inspection command 2-633

show ipc command 2-659

show ip dhcp snooping binding command 2-638

show ip dhcp snooping command 2-637

show ip dhcp snooping database command 2-640, 2-642

show ip igmp profile command 2-645

show ip igmp snooping address command 2-668

show ip igmp snooping command 2-646, 2-666

show ip igmp snooping groups command 2-649

show ip igmp snooping mrouter command 2-651, 2-670

show ip igmp snooping querier command 2-653, 2-672

show ip source binding command 2-655

show ipv6 access-list command 2-663

show ipv6 dhcp conflict command 2-665

show ipv6 route updated 2-674

show ip verify source command 2-657

show l2protocol-tunnel command 2-676

show lacp command 2-679

show link state group command 2-683

show location 2-685

show location command 2-685

show logging onboard command 2-688

show logging smartlog command 2-693

show mac access-group command 2-696

show mac address-table address command 2-699

show mac address-table aging time command 2-701

show mac address-table command 2-697

show mac address-table count command 2-703

show mac address-table dynamic command 2-705

show mac address-table interface command 2-707

show mac address-table learning command 2-709

show mac address-table move update command 2-710

show mac address-table notification command 2-109, 2-712, B-28

show mac address-table static command 2-714

show mac address-table vlan command 2-716

show macsec command 2-718

show mka default-policy command 2-720

show mka policy command 2-722

show mka session command 2-725

show mka statistics command 2-728

show mka summary command 2-731

show mls qos aggregate-policer command 2-735

show mls qos command 2-734

show mls qos input-queue command 2-736

show mls qos interface command 2-738

show mls qos maps command 2-742

show mls qos queue-set command 2-745

show mls qos vlan command 2-746

show monitor command 2-747

show mvr command 2-749

show mvr interface command 2-751

show mvr members command 2-753

show network-policy profile command 2-755

show nmsp command 2-756

show pagp command 2-759

show platform acl command C-2

show platform backup interface command C-3

show platform configuration command C-4

show platform dl command C-5

show platform etherchannel command C-6

show platform forward command C-7

show platform frontend-controller command C-9

show platform igmp snooping command C-10

show platform ipc trace command C-17

show platform ip multicast command C-11

show platform ip unicast command C-12

show platform ipv6 mld snooping command C-18

show platform ipv6 unicast command C-19

show platform ip wccp command C-16

show platform layer4op command C-21

show platform mac-address-table command C-22

show platform messaging command C-23

show platform monitor command C-24

show platform mvr table command C-25

show platform pm command C-26

show platform port-asic command C-27

show platform port-security command C-32

show platform qos command C-33

show platform resource-manager command C-34

show platform snmp counters command C-36

show platform spanning-tree command C-37

show platform stack-manager command C-39

show platform stp-instance command C-38

show platform tb command C-43

show platform tcam command C-44

show platform vlan command C-47

show policy-map command 2-761

show port security command 2-762

show power inline command 2-765, 2-783

show psp config 2-771

show psp config command 2-771

show psp statistics 2-772

show psp statistics command 2-772

show sdm prefer command 2-773

show setup express command 2-776

show spanning-tree command 2-777

show storm-control command 2-786

show switch command 2-788

show system mtu command 2-793

show trust command 2-945

show udld command 2-794

show version command 2-797

show vlan access-map command 2-804

show vlan command 2-799

show vlan command, fields 2-801

show vlan filter command 2-805

show vmps command 2-806

show vtp command 2-808

shutdown command 2-813

shutdown threshold, Layer 2 protocol tunneling 2-326

shutdown vlan command 2-814

small-frame violation rate command 2-815

SNMP host, specifying 2-822

SNMP informs, enabling the sending of 2-817

snmp-server enable traps command 2-817

snmp-server host command 2-822

snmp trap mac-notification change command 2-826

SNMP traps

enabling MAC address notification trap 2-826

enabling the MAC address notification feature 2-360

enabling the sending of 2-817

SoftPhone

See Cisco SoftPhone

software images

copying 2-10

deleting 2-140

downloading 2-13

upgrading 2-10, 2-13

uploading 2-20

software version, displaying 2-797

source ports, MVR 2-426

SPAN

configuring 2-418

debug messages, display B-31

displaying 2-747

filter SPAN traffic 2-418

sessions

add interfaces to 2-418

displaying 2-747

start new 2-418

spanning-tree backbonefast command 2-828

spanning-tree bpdufilter command 2-829

spanning-tree bpduguard command 2-831

spanning-tree cost command 2-833

spanning-tree etherchannel command 2-835

spanning-tree extend system-id command 2-837

spanning-tree guard command 2-839

spanning-tree link-type command 2-841

spanning-tree loopguard default command 2-843

spanning-tree mode command 2-845

spanning-tree mst configuration command 2-847

spanning-tree mst cost command 2-849

spanning-tree mst forward-time command 2-851

spanning-tree mst hello-time command 2-852

spanning-tree mst max-age command 2-853

spanning-tree mst max-hops command 2-854

spanning-tree mst port-priority command 2-855

spanning-tree mst pre-standard command 2-857

spanning-tree mst priority command 2-858

spanning-tree mst root command 2-859

spanning-tree portfast (global configuration) command 2-863

spanning-tree portfast (interface configuration) command 2-866

spanning-tree port-priority command 2-861

Spanning Tree Protocol

See STP

spanning-tree transmit hold-count command 2-868

spanning-tree uplinkfast command 2-869

spanning-tree vlan command 2-871

speed command 2-874

srr-queue bandwidth limit command 2-876

srr-queue bandwidth shape command 2-878

srr-queue bandwidth share command 2-880

SSH, configuring version 2-290

stack-mac persistent timer command 2-882

stack member

access 2-524

number 2-788, 2-894

priority value 2-891

provisioning 2-892

reloading 2-502

stacks, switch

disabling a member 2-889

enabling a member 2-889

MAC address 2-882

provisioning a new member 2-892

reloading 2-502

stack member access 2-524

stack member number 2-788, 2-894

stack member priority value 2-788, 2-891

static-access ports, configuring 2-898

statistics, Ethernet group 2-513

sticky learning, enabling 2-915

storm-control command 2-886

STP

BackboneFast 2-828

counters, clearing 2-118

debug messages, display

BackboneFast events B-88

MSTP B-91

optimized BPDUs handling B-90

spanning-tree activity B-86

switch shim B-93

transmitted and received BPDUs B-89

UplinkFast B-95

detection of indirect link failures 2-828

enabling protocol tunneling for 2-326

EtherChannel misconfiguration 2-835

extended system ID 2-837

path cost 2-833

protocol modes 2-845

root port

accelerating choice of new 2-869

loop guard 2-839

preventing from becoming designated 2-839

restricting which can be root 2-839

root guard 2-839

UplinkFast 2-869

root switch

affects of extended system ID 2-837, 2-872

hello-time 2-871

interval between BDPU messages 2-871

interval between hello BPDU messages 2-871

max-age 2-871

port priority for selection of 2-861

primary or secondary 2-871

switch priority 2-871

state changes

blocking to forwarding state 2-866

enabling BPDU filtering 2-829, 2-863

enabling BPDU guard 2-831, 2-863

enabling Port Fast 2-863, 2-866

enabling timer to recover from error state 2-205

forward-delay time 2-871

length of listening and learning states 2-871

shutting down Port Fast-enabled ports 2-863

state information display 2-777

VLAN options 2-858, 2-871

supplemental power command 2-884

SVIs, creating 2-220

SVI status calculation 2-900

Switched Port Analyzer

See SPAN

switching characteristics

modifying 2-896

returning to interfaces 2-896

switchport access command 2-898

switchport autostate exclude command 2-900

switchport backup interface command 2-902

switchport block command 2-905

switchport command 2-896

switchport host command 2-907

switchport mode command 2-908

switchport mode private-vlan command 2-911

switchport nonegotiate command 2-913

switchport port-security aging command 2-920

switchport port-security command 2-915

switchport priority extend command 2-922

switchport private-vlan command 2-924

switchport protected command 2-926

switchports, displaying 2-615

switchport trunk command 2-928

switchport voice detect 2-931

switchport voice vlan command 2-932

switch priority command 2-889, 2-891

switch provision command 2-892

switch renumber command 2-894

system env temperature threshold yellow command 2-934

system message logging 2-344

system message logging, save message to flash 2-345

system mtu command 2-936

system resource templates 2-515

T

tar files, creating, listing, and extracting 2-17

TDR, running 2-939

Telnet, using to communicate to cluster switches 2-500

temperature information, displaying 2-594

templates, system resources 2-515

test cable-diagnostics tdr command 2-939

traceroute mac command 2-940

traceroute mac ip command 2-943

trunking, VLAN mode 2-908

trunk mode 2-908

trunk ports 2-908

trunks, to non-DTP device 2-909

trusted boundary for QoS 2-413

trusted port states for QoS 2-413

tunnel ports, Layer 2 protocol, displaying 2-676

type (boot loader) command A-27

U

UDLD

aggressive mode 2-947, 2-949

debug messages, display B-103

enable globally 2-947

enable per interface 2-949

error recovery timer 2-206

message timer 2-947

normal mode 2-947, 2-949

reset a shutdown interface 2-951

status 2-794

udld command 2-947

udld port command 2-949

udld reset command 2-951

unicast storm control 2-886

UniDirectional Link Detection

See UDLD

unknown multicast traffic, preventing 2-905

unknown unicast traffic, preventing 2-905

unset (boot loader) command A-28

upgrading

copying software images 2-10

downloading software images 2-13

software images, monitoring status of 2-535

UplinkFast, for STP 2-869

usb-inactivity-timeout (console configuration) command 2-952

user EXEC mode 1-2, 1-3

V

version (boot loader) command A-30

version mismatch mode 2-789, C-40

vlan (global configuration) command 2-953

vlan access-map command 2-958

VLAN access map configuration mode 2-958

VLAN access maps

actions 2-8

displaying 2-804

VLAN-based QoS 2-415

VLAN configuration

rules 2-956

saving 2-953

VLAN configuration mode

description 1-4

entering 2-953

summary 1-3

vlan dot1q tag native command 2-960

vlan filter command 2-962

VLAN filters, displaying 2-805

VLAN ID range 2-953

VLAN maps

applying 2-962

creating 2-958

defining 2-366

displaying 2-804

VLAN Query Protocol

See VQP

VLANs

adding 2-953

configuring 2-953

debug messages, display

ISL B-99

VLAN IOS file system error tests B-98

VLAN manager activity B-96

VTP B-101

displaying configurations 2-799

extended-range 2-953

MAC addresses

displaying 2-716

number of 2-703

media types 2-956

normal-range 2-953

private 2-911

configuring 2-489

displaying 2-799

See also private VLANs

restarting 2-814

saving the configuration 2-953

shutting down 2-814

SNMP traps for VTP 2-820, 2-823

suspending 2-814

VLAN Trunking Protocol

See VTP

VM mode 2-789, C-40

VMPS

configuring servers 2-967

displaying 2-806

error recovery timer 2-206

reconfirming dynamic VLAN assignments 2-964

vmps reconfirm (global configuration) command 2-965

vmps reconfirm (privileged EXEC) command 2-964

vmps retry command 2-966

vmps server command 2-967

voice VLAN

configuring 2-931, 2-932

setting port priority 2-922

VQP

and dynamic-access ports 2-899

clearing client statistics 2-120

displaying information 2-806

per-server retry count 2-966

reconfirmation interval 2-965

reconfirming dynamic VLAN assignments 2-964

VTP

changing characteristics 2-969

clearing pruning counters 2-121

configuring

domain name 2-969

file name 2-969

mode 2-969

password 2-970

counters display fields 2-809

displaying information 2-808

enabling

pruning 2-970

tunneling for 2-326

Version 2 2-970

enabling per port 2-974

mode 2-969

pruning 2-970

saving the configuration 2-953

statistics 2-808

status 2-808

status display fields 2-811

vtp (global configuration) command 2-969

vtp interface configuration command 2-974

vtp primary command 2-975

X

XPS 2200

configuring 2-481

naming 2-481

Index

A

aaa accounting dot1x command 2-1

aaa authentication dot1x command 2-3

aaa authorization network command 2-5, 2-26, 2-33, 2-35, 2-38, 2-40, 2-42, 2-168, 2-349, 2-551, B-7, B-39

AAA methods 2-3

access control entries

See ACEs

access control lists

See ACLs

access groups

IP 2-222

MAC, displaying 2-696

access list, IPv6 2-299

access map configuration mode 2-366

access mode 2-908

access ports 2-908

ACEs 2-152, 2-456

ACLs

deny 2-150

displaying 2-532

for non-IP protocols 2-353

IP 2-222

matching 2-366

on Layer 2 interfaces 2-222

permit 2-454

action command 2-8

address aliasing 2-424

aggregate-port learner 2-440

allowed VLANs 2-928

archive copy-sw command 2-10

archive download-sw command 2-13

archive tar command 2-17

archive upload-sw command 2-20

arp (boot loader) command A-2

arp access-list command 2-22

authentication command bounce-port ignore 2-24

authentication command disable-port ignore 2-25

authentication control-direction command 2-26

authentication event command 2-28

authentication event linksec fail action command 2-32

authentication failed VLAN

See dot1x auth-fail vlan

authentication fallback command 2-33

authentication host-mode command 2-35

authentication linksec policy command 2-37

authentication mac-move permit command 2-38

authentication open command 2-40

authentication order command 2-42

authentication periodic command 2-44

authentication port-control command 2-46

authentication priority command 2-48

authentication timer command 2-50

authentication violation command 2-52

auth-fail max-attempts

See dot1x auth-fail max-attempts

auth-fail vlan

See dot1x auth-fail vlan

auth open command 2-40

auth order command 2-42

authorization state of controlled port 2-185

auth timer command 2-50

autonegotiation of duplex mode 2-197

auto qos classify command 2-54

auto qos trust command 2-57

auto qos video command 2-60

auto qos voip command 2-63

B

BackboneFast, for STP 2-828

backup interfaces

configuring 2-902

displaying 2-616

boot (boot loader) command A-3

boot auto-copy-sw command 2-70

boot auto-download-sw command 2-71

boot config-file command 2-74

boot enable-break command 2-75

boot helper command 2-76

boot helper-config file command 2-77

booting

Cisco IOS image 2-80

displaying environment variables 2-545

interrupting 2-75

manually 2-78

boot loader

accessing A-1

booting

Cisco IOS image A-3

helper image 2-76

directories

creating A-19

displaying a list of A-8

removing A-23

displaying

available commands A-13

memory heap utilization A-14

version A-30

environment variables

described A-24

displaying settings A-24

location of A-25

setting A-24

unsetting A-28

files

copying A-6

deleting A-7

displaying a list of A-8

displaying the contents of A-5, A-20, A-27

renaming A-21

file system

formatting A-11

initializing flash A-10

running a consistency check A-12

resetting the system A-22

boot manual command 2-78

boot private-config-file command 2-79

boot system command 2-80

boot time-copy-sw command 2-69

BPDU filtering, for spanning tree 2-829, 2-863

BPDU guard, for spanning tree 2-831, 2-863

broadcast storm control 2-886

C

candidate switches

See clusters

cat (boot loader) command A-5

CDP, enabling protocol tunneling for 2-326

channel-group command 2-84

channel-protocol command 2-88

Cisco Redundant Power System 2300

configuring 2-478

managing 2-478

Cisco SoftPhone

auto-QoS configuration 2-63

trusting packets sent from 2-413

CISP

See Client Information Signalling Protocol

cisp

debug platform cisp command B-39

cisp enable command 2-89

class command 2-90

class-map command 2-93

class maps

creating 2-93

defining the match criteria 2-368

displaying 2-552

class of service

See CoS

clear dot1x command 2-95

clear eap sessions command 2-96

clear errdisable interface 2-97

clear ip arp inspection log command 2-98

clear ip arp inspection statistics command 2-99

clear ipc command 2-102

clear ip dhcp snooping database command 2-100

clear ipv6 dhcp conflict command 2-103

clear l2protocol-tunnel counters command 2-104

clear lacp command 2-105

clear logging onboard command 2-106

clear logging smartlog statistics interface command 2-107

clear mac address-table command 2-108, 2-109

clear macsec counters interface command 2-110

clear mka command 2-111

clear nmsp statistics command 2-113

clear pagp command 2-114

clear port-security command 2-115

clear psp counter 2-117

clear psp counter command 2-117

clear spanning-tree counters command 2-118

clear spanning-tree detected-protocols command 2-119

clear vmps statistics command 2-120

clear vtp counters command 2-121

Client Information Signalling Protocol 2-89, 2-168, 2-551, B-7, B-39

cluster commander-address command 2-122

cluster discovery hop-count command 2-124

cluster enable command 2-125

cluster holdtime command 2-127

cluster member command 2-128

cluster outside-interface command 2-130

cluster run command 2-131

clusters

adding candidates 2-128

binding to HSRP group 2-132

building manually 2-128

communicating with

devices outside the cluster 2-130

members by using Telnet 2-500

debug messages, display B-8

displaying

candidate switches 2-555

debug messages B-8

member switches 2-557

status 2-553

hop-count limit for extended discovery 2-124

HSRP standby groups 2-132

redundancy 2-132

SNMP trap 2-817

cluster standby-group command 2-132

cluster timer command 2-134

command modes defined 1-2

command switch

See clusters

confidentiality-offset command 2-137

configuration files

password recovery disable considerations A-1

specifying the name 2-74, 2-79

configuring multiple interfaces 2-218

config-vlan mode

commands 2-954

copy (boot loader) command A-6

copy logging onboard command 2-135

CoS

assigning default value to incoming packets 2-383

assigning to Layer 2 protocol packets 2-329

overriding the incoming value 2-383

CoS-to-DSCP map 2-387

CPU ASIC statistics, displaying 2-559

crashinfo files 2-209

critical VLAN 2-29

D

debug authentication B-2

debug auto qos command B-4

debug backup command B-6

debug cisp command B-7

debug cluster command B-8

debug dot1x command B-10

debug dtp command B-11

debug eap command B-12

debug etherchannel command B-13

debug fastethernet command B-14

debug ilpower command B-15

debug interface command B-16

debug ip dhcp snooping command B-17

debug ip igmp filter command B-19

debug ip igmp max-groups command B-20

debug ip igmp snooping command B-21

debug ip verify source packet command B-18

debug lacp command B-22

debug lldp packets command B-23

debug mac-notification command B-25

debug macsec command B-26

debug matm command B-27

debug matm move update command B-28

debug mka command B-29

debug monitor command B-31

debug mvrdbg command B-32

debug nmsp command B-33

debug nvram command B-34

debug pagp command B-35

debug platform acl command B-36

debug platform backup interface command B-38

debug platform cisp command B-39

debug platform cli-redirection main command B-40

debug platform configuration command B-41, B-49

debug platform cpu-queues command B-42

debug platform device-manager command B-44

debug platform dot1x command B-45

debug platform etherchannel command B-46

debug platform fallback-bridging command B-47

debug platform forw-tcam command B-48

debug platform ip arp inspection command B-50

debug platform ipc command B-59

debug platform ip dhcp command B-51

debug platform ip igmp snooping command B-52

debug platform ip multicast command B-54

debug platform ip unicast command B-56

debug platform ip wccp command B-58

debug platform led command B-60

debug platform matm command B-61

debug platform messaging application command B-62

debug platform phy command B-63

debug platform pm command B-65

debug platform port-asic command B-67

debug platform port-security command B-68

debug platform qos-acl-tcam command B-69

debug platform remote-commands command B-70

debug platform resource-manager command B-71

debug platform snmp command B-72

debug platform span command B-73

debug platform stack-manager command B-74

debug platform supervisor-asic command B-75

debug platform sw-bridge command B-76

debug platform tcam command B-77

debug platform udld command B-80

debug platform vlan command B-81

debug pm command B-82

debug port-security command B-84

debug qos-manager command B-85

debug spanning-tree backbonefast command B-88

debug spanning-tree bpdu command B-89

debug spanning-tree bpdu-opt command B-90

debug spanning-tree command B-86

debug spanning-tree mstp command B-91

debug spanning-tree switch command B-93

debug spanning-tree uplinkfast command B-95

debug sw-vlan command B-96

debug sw-vlan ifs command B-98

debug sw-vlan notification command B-99

debug sw-vlan vtp command B-101

debug udld command B-103

debug vqpc command B-105

default policy, MKA 2-374

define interface-range command 2-138

delete (boot loader) command A-7

delete command 2-140

deny (ARP access-list configuration) command 2-143

deny (IPv6) command 2-145

deny command 2-150

detect mechanism, causes 2-200

DHCP snooping

accepting untrusted packets from edge switch 2-256

enabling

on a VLAN 2-262

option 82 2-254, 2-256

trust on an interface 2-260

error recovery timer 2-205

rate limiting 2-259

DHCP snooping binding database

binding file, configuring 2-252

bindings

adding 2-250

deleting 2-250

displaying 2-638

clearing database agent statistics 2-100

database agent, configuring 2-252

displaying

binding entries 2-638

database agent status 2-640, 2-642

renewing 2-508

Digital Optical Monitoring

see DoM

dir (boot loader) command A-8

directories, deleting 2-140

DoM

displaying supported transceivers 2-629

domain name, VTP 2-969

dot1x auth-fail max-attempts 2-162

dot1x auth-fail vlan 2-164

dot1x command 2-160

dot1x control-direction command 2-166

dot1x credentials (global configuration) command 2-168

dot1x critical global configuration command 2-169

dot1x critical interface configuration command 2-171

dot1x default command 2-173

dot1x fallback command 2-174

dot1x guest-vlan command 2-175

dot1x host-mode command 2-177

dot1x initialize command 2-178

dot1x mac-auth-bypass command 2-179

dot1x max-reauth-req command 2-181

dot1x max-req command 2-183

dot1x pae command 2-184

dot1x port-control command 2-185

dot1x re-authenticate command 2-187

dot1x reauthentication command 2-188

dot1x supplicant force-multicast command 2-189

dot1x test eapol-capable command 2-190

dot1x test timeout command 2-191

dot1x timeout command 2-192

dot1x violation-mode command 2-195

dropping packets, with ACL matches 2-8

drop threshold, Layer 2 protocol tunneling 2-326

DSCP-to-CoS map 2-387

DSCP-to-DSCP-mutation map 2-387

DTP 2-909

DTP flap

error detection for 2-200

error recovery timer 2-205

DTP negotiation 2-913

dual IPv4 and IPv6 templates 2-448

duplex command 2-196

dynamic-access ports

configuring 2-898

restrictions 2-899

dynamic ARP inspection

ARP ACLs

apply to a VLAN 2-230

define 2-22

deny packets 2-143

display 2-536

permit packets 2-446

clear

log buffer 2-98

statistics 2-99

display

ARP ACLs 2-536

configuration and operating state 2-633

log buffer 2-633

statistics 2-633

trust state and rate limit 2-633

enable per VLAN 2-242

error detection for 2-200

error recovery timer 2-205

log buffer

clear 2-98

configure 2-234

display 2-633

rate-limit incoming ARP packets 2-232

statistics

clear 2-99

display 2-633

trusted interface state 2-238

type of packet logged 2-243

validation checks 2-240

dynamic auto VLAN membership mode 2-908

dynamic desirable VLAN membership mode 2-908

Dynamic Host Configuration Protocol (DHCP)

See DHCP snooping

Dynamic Trunking Protocol

See DTP

E

EAP-request/identity frame

maximum number to send 2-183

response time before retransmitting 2-192

encapsulation methods 2-928

environment variables, displaying 2-545

epm access-control open 2-198

errdisable detect cause command 2-200

errdisable detect cause small-frame command 2-203

errdisable recovery cause small-frame 2-208

errdisable recovery command 2-205

error conditions, displaying 2-603

error disable detection 2-200

error-disabled interfaces, displaying 2-615

EtherChannel

assigning Ethernet interface to channel group 2-84

creating port-channel logical interface 2-216

debug EtherChannel/PAgP, display B-13

debug platform-specific events, display B-46

displaying 2-606

enabling Layer 2 protocol tunneling for

LACP 2-327

PAgP 2-327

UDLD 2-327

interface information, displaying 2-615

LACP

clearing channel-group information 2-105, 2-106

debug messages, display B-22

displaying 2-679

modes 2-84

port priority for hot-standby ports 2-330

restricting a protocol 2-88

system priority 2-332

load-distribution methods 2-464

PAgP

aggregate-port learner 2-440

clearing channel-group information 2-114

debug messages, display B-35

displaying 2-759

error detection for 2-200

error recovery timer 2-205

learn method 2-440

modes 2-84

physical-port learner 2-440

priority of interface for transmitted traffic 2-442

Ethernet controller, internal register display 2-561, 2-568

Ethernet Management port, debugging B-14

Ethernet statistics, collecting 2-513

exception crashinfo command 2-209, 2-214

extended discovery of candidate switches 2-124

extended-range VLANs

and allowed VLAN list 2-928

and pruning-eligible list 2-928

configuring 2-953

extended system ID for STP 2-837

F

fallback profile command 2-210

fallback profiles, displaying 2-609

fan information, displaying 2-594

file name, VTP 2-969

files, deleting 2-140

flash_init (boot loader) command A-10

flexible authentication ordering 2-42

Flex Links

configuring 2-902

displaying 2-616

flow-based SPAN 2-418

flowcontrol command 2-212

format (boot loader) command A-11

forwarding packets, with ACL matches 2-8

forwarding results, display C-7

frame forwarding information, displaying C-7

front-end controller counter and status information C-9

fsck (boot loader) command A-12

FSPAN 2-418

G

global configuration mode 1-2, 1-4

H

hardware ACL statistics 2-532

health monitoring diagnostic tests 2-153

help (boot loader) command A-13

hierarchical policy maps 2-462

hop-count limit for clusters 2-124

host connection, port configuration 2-907

host ports, private VLANs 2-911

Hot Standby Router Protocol

See HSRP

HSRP

binding HSRP group to cluster 2-132

standby group 2-132

I

IEEE 802.1Q trunk ports and native VLANs 2-960

IEEE 802.1Q tunnel ports

configuring 2-908

displaying 2-584

limitations 2-909

IEEE 802.1x

and switchport modes 2-909

violation error recovery 2-205

See also port-based authentication

IGMP filters

applying 2-266

debug messages, display B-19

IGMP groups, setting maximum 2-267

IGMP maximum groups, debugging B-20

IGMP profiles

creating 2-269

displaying 2-645

IGMP snooping

adding ports as a static member of a group 2-285

displaying 2-646, 2-651, 2-653

enabling 2-271

enabling the configurable-leave timer 2-273

enabling the Immediate-Leave feature 2-282

flooding query count 2-279

interface topology change notification behavior 2-281

multicast table 2-649

querier 2-275

query solicitation 2-279

report suppression 2-277

switch topology change notification behavior 2-279

images

See software images

Immediate-Leave processing

IGMP 2-282

IPv6 2-322

MVR 2-426

interface configuration mode 1-2, 1-4

interface port-channel command 2-216

interface range command 2-218

interface-range macros 2-138

interfaces

assigning Ethernet interface to channel group 2-84

configuring 2-196

configuring multiple 2-218

creating port-channel logical 2-216

debug messages, display B-16

disabling 2-813

displaying the MAC address table 2-707

restarting 2-813

interface speed, configuring 2-874

interface vlan command 2-220

internal power supplies

See power supplies

internal registers, displaying 2-561, 2-568, 2-575

Internet Group Management Protocol

See IGMP

invalid GBIC

error detection for 2-200

error recovery timer 2-205

ip access-group command 2-222

ip address command 2-225

IP addresses, setting 2-225

IP address matching 2-366

ip admission command 2-227

ip admission name proxy http command 2-228

ip arp inspection filter vlan command 2-230

ip arp inspection limit command 2-232

ip arp inspection log-buffer command 2-234

ip arp inspection trust command 2-238

ip arp inspection validate command 2-240

ip arp inspection vlan command 2-242

ip arp inspection vlan logging command 2-243

ip device tracking command 2-245

ip device tracking probe command 2-247

IP DHCP snooping

See DHCP snooping

ip dhcp snooping binding command 2-250

ip dhcp snooping command 2-249

ip dhcp snooping database command 2-252

ip dhcp snooping information option allow-untrusted command 2-256

ip dhcp snooping information option command 2-254

ip dhcp snooping information option format remote-id command 2-258

ip dhcp snooping limit rate command 2-259

ip dhcp snooping trust command 2-260

ip dhcp snooping verify command 2-261

ip dhcp snooping vlan command 2-262

ip dhcp snooping vlan information option format-type circuit-id string command 2-264

ip igmp filter command 2-266

ip igmp max-groups command 2-267, 2-292, 2-294

ip igmp profile command 2-269

ip igmp snooping command 2-271

ip igmp snooping last-member-query-interval command 2-273

ip igmp snooping querier command 2-275

ip igmp snooping report-suppression command 2-277

ip igmp snooping tcn command 2-279

ip igmp snooping tcn flood command 2-281

ip igmp snooping vlan immediate-leave command 2-282

ip igmp snooping vlan mrouter command 2-283

ip igmp snooping vlan static command 2-285

IP multicast addresses 2-423

IP phones

auto-QoS configuration 2-63

trusting packets sent from 2-413

IP-precedence-to-DSCP map 2-387

ip snap forwarding command 2-287

ip source binding command 2-288

IP source guard

disabling 2-296

displaying

binding entries 2-655

configuration 2-657

dynamic binding entries only 2-638

enabling 2-296

static IP source bindings 2-288

ip ssh command 2-290

IPv4 and IPv6

port-based trust 2-414

IPv6 access list, deny conditions 2-145

ipv6 access-list command 2-299

ipv6 address dhcp command 2-302

ipv6 dhcp client request vendor command 2-303

ipv6 dhcp ping packets command 2-304

ipv6 dhcp pool command 2-306

ipv6 dhcp server command 2-309

ipv6 mld snooping command 2-311

ipv6 mld snooping last-listener-query count command 2-313

ipv6 mld snooping last-listener-query-interval command 2-315

ipv6 mld snooping listener-message-suppression command 2-317

ipv6 mld snooping robustness-variable command 2-318

ipv6 mld snooping tcn command 2-320

ipv6 mld snooping vlan command 2-322

IPv6 QoS

enabling 2-379

IPv6 SDM template 2-515

ipv6 traffic-filter command 2-324

ip verify source command 2-296

ip verify source smartlog command 2-298

J

jumbo frames

See MTU

L

l2protocol-tunnel command 2-326

l2protocol-tunnel cos command 2-329

LACP

See EtherChannel

lacp port-priority command 2-330

lacp system-priority command 2-332

Layer 2 mode, enabling 2-896

Layer 2 protocol ports, displaying 2-676

Layer 2 protocol-tunnel

error detection for 2-200

error recovery timer 2-205

Layer 2 protocol tunnel counters 2-104

Layer 2 protocol tunneling error recovery 2-327

Layer 2 traceroute

IP addresses 2-943

MAC addresses 2-940

Layer 3 mode, enabling 2-896

license boot command 2-334

line configuration mode 1-3, 1-5

Link Aggregation Control Protocol

See EtherChannel

link flap

error detection for 2-200

error recovery timer 2-205

link-security authentication 2-32

link-security policies 2-37

link state group command 2-336

link state track command 2-338

load-distribution methods for EtherChannel 2-464

location (global configuration) command 2-339

location (interface configuration) command 2-341

logging event command 2-343

logging event power-inline-status command 2-344

logging file command 2-345

logical interface 2-216

loopback error

detection for 2-200

recovery timer 2-205

loop guard, for spanning tree 2-839, 2-843

M

mab request format attribute 32 command 2-349

mac access-group command 2-351

MAC access-groups, displaying 2-696

MAC access list configuration mode 2-353

mac access-list extended command 2-353

MAC access lists 2-150

MAC addresses

disabling MAC address learning per VLAN 2-356

displaying

aging time 2-701

all 2-699

dynamic 2-705

MAC address-table move updates 2-710

notification settings 2-709, 2-712

number of addresses in a VLAN 2-703

per interface 2-707

per VLAN 2-716

static 2-714

static and dynamic entries 2-697

dynamic

aging time 2-355

deleting 2-108

displaying 2-705

enabling MAC address notification 2-360

enabling MAC address-table move update 2-358

matching 2-366

persistent stack 2-882

static

adding and removing 2-362

displaying 2-714

dropping on an interface 2-363

tables 2-699

MAC address notification, debugging B-25

mac address-table aging-time 2-351, 2-366

mac address-table aging-time command 2-355

mac address-table learning command 2-356

mac address-table move update command 2-358

mac address-table notification command 2-360

mac address-table static command 2-362

mac address-table static drop command 2-363

MAC frames

See MTU

macros

interface range 2-138, 2-218

MACsec

counters 2-110, 2-571

debugging B-26

displaying 2-718

enabling 2-365

registers 2-571

macsec command 2-365

maps

QoS

defining 2-387

displaying 2-742

VLAN

creating 2-958

defining 2-366

displaying 2-804

match (access-map configuration) command 2-366

match (class-map configuration) command 2-368

maximum transmission unit

See MTU

mdix auto command 2-371

Media Access Control Security

See MACsec.

media-type rj45 command 2-373

member switches

See clusters

memory (boot loader) command A-14

mgmt_clr (boot loader) command A-16

mgmt_init (boot loader) command A-17, A-18

MKA

confidentiality 2-137

debugging B-29

displaying default policy 2-720

displaying policies 2-722

displaying sessions 2-725

displaying sessions and statistics 2-731

displaying statistics 2-728

policy configuration mode 2-375

MKA, enabling 2-377

mka default policy command 2-374

mka policy global configuration command 2-375

mka policy interface configuration command 2-377

mkdir (boot loader) command A-19

MLD snooping

configuring 2-317, 2-318

configuring queries 2-313, 2-315

configuring topology change notification 2-320

displaying 2-666, 2-668, 2-670, 2-672

enabling 2-311

enabling on a VLAN 2-322

mls qos aggregate-policer command 2-381

mls qos command 2-379

mls qos cos command 2-383

mls qos dscp-mutation command 2-385

mls qos map command 2-387

mls qos queue-set output buffers command 2-391

mls qos queue-set output threshold command 2-393

mls qos rewrite ip dscp command 2-395

mls qos srr-queue input bandwidth command 2-397

mls qos srr-queue input buffers command 2-399

mls qos-srr-queue input cos-map command 2-401

mls qos srr-queue input dscp-map command 2-403

mls qos srr-queue input priority-queue command 2-405

mls qos srr-queue input threshold command 2-407

mls qos-srr-queue output cos-map command 2-409

mls qos srr-queue output dscp-map command 2-411

mls qos trust command 2-413

mls qos vlan-based command 2-415

mode, MVR 2-423

Mode button, and password recovery 2-519

mode command 2-416

modes, commands 1-2

monitor session command 2-418

more (boot loader) command A-20

MSTP

displaying 2-778

interoperability 2-119

link type 2-841

MST region

aborting changes 2-847

applying changes 2-847

configuration name 2-847

configuration revision number 2-847

current or pending display 2-847

displaying 2-778

MST configuration mode 2-847

VLANs-to-instance mapping 2-847

path cost 2-849

protocol mode 2-845

restart protocol migration process 2-119

root port

loop guard 2-839

preventing from becoming designated 2-839

restricting which can be root 2-839

root guard 2-839

root switch

affects of extended system ID 2-837

hello-time 2-852, 2-859

interval between BDPU messages 2-853

interval between hello BPDU messages 2-852, 2-859

max-age 2-853

maximum hop count before discarding BPDU 2-854

port priority for selection of 2-855

primary or secondary 2-859

switch priority 2-858

state changes

blocking to forwarding state 2-866

enabling BPDU filtering 2-829, 2-863

enabling BPDU guard 2-831, 2-863

enabling Port Fast 2-863, 2-866

forward-delay time 2-851

length of listening and learning states 2-851

rapid transition to forwarding 2-841

shutting down Port Fast-enabled ports 2-863

state information display 2-777

MTU

configuring size 2-936

displaying global setting 2-793

MAC 2-937

system jumbo 2-937

system routing 2-937

Multicase Listener Discovery

See MLD

multicast group address, MVR 2-426

multicast groups, MVR 2-424

Multicast Listener Discovery

See MLD

multicast router learning method 2-283

multicast router ports, configuring 2-283

multicast router ports, IPv6 2-322

multicast storm control 2-886

multicast VLAN, MVR 2-423

multicast VLAN registration

See MVR

multiple hosts on authorized port 2-177

Multiple Spanning Tree Protocol

See MSTP

MVR

and address aliasing 2-424

configuring 2-423

configuring interfaces 2-426

debug messages, display B-32

displaying 2-749

displaying interface information 2-751

members, displaying 2-753

mvr (global configuration) command 2-423

mvr (interface configuration) command 2-426

mvr vlan group command 2-427

N

native VLANs 2-928

native VLAN tagging 2-960

network-policy (global configuration) command 2-430

network-policy command 2-429

network-policy profile (network-policy configuration) command 2-431

nmsp attachment suppress command 2-434

nmsp command 2-433

no authentication logging verbose 2-435

no dot1x logging verbose 2-436

no mab logging verbose 2-437

nonegotiate

DTP messaging 2-913

speed 2-874

non-IP protocols

denying 2-150

forwarding 2-454

non-IP traffic access lists 2-353

non-IP traffic forwarding

denying 2-150

permitting 2-454

non-stop forwarding 2-438

normal-range VLANs 2-953

no vlan command 2-953

nsf command 2-438

O

online diagnostics

configuring health monitoring diagnostic tests 2-153

displaying

configured boot-up coverage level 2-579

current scheduled tasks 2-579

event logs 2-579

supported test suites 2-579

test ID 2-579

test results 2-579

test statistics 2-579

enabling

scheduling 2-155

syslog messages 2-153

global configuration mode

clearing health monitoring diagnostic test schedule 2-153

clearing test-based testing schedule 2-155

setting health monitoring diagnostic testing 2-153

setting test-based testing 2-155

setting up health monitoring diagnostic test schedule 2-153

setting up test-based testing 2-155

removing scheduling 2-155

scheduled switchover

disabling 2-155

enabling 2-155

setting test interval 2-155

specifying health monitoring diagnostic tests 2-153

starting testing 2-157

P

PAgP

See EtherChannel

pagp learn-method command 2-440

pagp port-priority command 2-442

password, VTP 2-970

password-recovery mechanism, enabling and disabling 2-519

permit (ARP access-list configuration) command 2-446

permit (IPv6) command 2-448

permit (MAC access-list configuration) command 2-454

per-VLAN spanning-tree plus

See STP

physical-port learner 2-440

PID, displaying 2-632

PIM-DVMRP, as multicast router learning method 2-283

PoE

configuring the power budget 2-469

configuring the power management mode 2-466

displaying controller register values 2-573

displaying power management information 2-765

error detection for 2-200

error recovery timer 2-205

logging of status 2-344

monitoring power 2-472

policing power consumption 2-472

police aggregate command 2-459

police command 2-457

policed-DSCP map 2-387

policy-map command 2-461

policy maps

applying to an interface 2-521, 2-527

creating 2-461

displaying 2-761

hierarchical 2-462

policers

displaying 2-735

for a single class 2-457

for multiple classes 2-381, 2-459

policed-DSCP map 2-387

traffic classification

defining the class 2-90

defining trust states 2-945

setting DSCP or IP precedence values 2-525

Port Aggregation Protocol

See EtherChannel

port-based authentication

AAA method list 2-3

configuring violation modes 2-195

debug messages, display B-10

enabling guest VLAN supplicant 2-163, 2-174

enabling IEEE 802.1x

globally 2-160

per interface 2-185

guest VLAN 2-175

host modes 2-177

IEEE 802.1x AAA accounting methods 2-1

initialize an interface 2-178, 2-191

MAC authentication bypass 2-179

manual control of authorization state 2-185

multiple hosts on authorized port 2-177

PAE as authenticator 2-184

periodic re-authentication

enabling 2-188

time between attempts 2-192

quiet period between failed authentication exchanges 2-192

re-authenticating IEEE 802.1x-enabled ports 2-187

resetting configurable IEEE 802.1x parameters 2-173

switch-to-authentication server retransmission time 2-192

switch-to-client frame-retransmission number 2-181 to 2-183

switch-to-client retransmission time 2-192

test for IEEE 802.1x readiness 2-190

port-based trust

IPv4 and IPv6 2-414

port-channel load-balance command 2-464

Port Fast, for spanning tree 2-866

port ranges, defining 2-135, 2-138

ports, debugging B-82

ports, protected 2-926

port security

aging 2-920

debug messages, display B-84

enabling 2-915

violation error recovery 2-205

port trust states for QoS 2-413

port types, MVR 2-426

power information, displaying 2-594

power inline command 2-466

power inline consumption command 2-469

power inline police command 2-472

Power over Ethernet

See PoE

power-priority command 2-475

power rps command (global configuration) 2-481

power rps command (user EXEC) 2-477

power supply

configuring 2-479

managing 2-479

power supply command 2-479

power xps command privileged EXEC) 2-483

power xps port command 2-485

priority-queue command 2-487

priority value, stack member 2-788, 2-891

private-vlan command 2-489

private-vlan mapping command 2-492

private VLANs

association 2-924

configuring 2-489

configuring ports 2-911

displaying 2-799

host ports 2-911

mapping

configuring 2-924

displaying 2-615

promiscuous ports 2-911

privileged EXEC mode 1-2, 1-3

product identification information, displaying 2-632

promiscuous ports, private VLANs 2-911

protected ports, displaying 2-621

pruning

VLANs 2-928

VTP

enabling 2-970

pruning-eligible VLAN list 2-930

psp 2-494

psp command 2-494

PVST+

See STP

Q

QoS

auto-QoS

configuring 2-63

debug messages, display B-4

displaying 2-541

auto-QoS trust

configuring 2-57

auto-QoS video

configuring 2-60

class maps

creating 2-93

defining the match criteria 2-368

displaying 2-552

defining the CoS value for an incoming packet 2-383

displaying configuration information 2-541, 2-734

DSCP transparency 2-395

DSCP trusted ports

applying DSCP-to-DSCP-mutation map to 2-385

defining DSCP-to-DSCP-mutation map 2-387

egress queues

allocating buffers 2-391

defining the CoS output queue threshold map 2-409

defining the DSCP output queue threshold map 2-411

displaying buffer allocations 2-738

displaying CoS output queue threshold map 2-742

displaying DSCP output queue threshold map 2-742

displaying queueing strategy 2-738

displaying queue-set settings 2-745

enabling bandwidth shaping and scheduling 2-878

enabling bandwidth sharing and scheduling 2-880

limiting the maximum output on a port 2-876

mapping a port to a queue-set 2-495

mapping CoS values to a queue and threshold 2-409

mapping DSCP values to a queue and threshold 2-411

setting maximum and reserved memory allocations 2-393

setting WTD thresholds 2-393

enabling 2-379

enabling IPv6 QoS 2-379

ingress queues

allocating buffers 2-399

assigning SRR scheduling weights 2-397

defining the CoS input queue threshold map 2-401

defining the DSCP input queue threshold map 2-403

displaying buffer allocations 2-738

displaying CoS input queue threshold map 2-742

displaying DSCP input queue threshold map 2-742

displaying queueing strategy 2-738

displaying settings for 2-736

enabling the priority queue 2-405

mapping CoS values to a queue and threshold 2-401

mapping DSCP values to a queue and threshold 2-403

setting WTD thresholds 2-407

maps

defining 2-387, 2-401, 2-403, 2-409, 2-411

displaying 2-742

policy maps

applying an aggregate policer 2-459

applying to an interface 2-521, 2-527

creating 2-461

defining policers 2-381, 2-457

displaying policers 2-735

displaying policy maps 2-761

hierarchical 2-462

policed-DSCP map 2-387

setting DSCP or IP precedence values 2-525

traffic classifications 2-90

trust states 2-945

port trust states 2-413

queues, enabling the expedite 2-487

statistics

in-profile and out-of-profile packets 2-738

packets enqueued or dropped 2-738

sent and received CoS values 2-738

sent and received DSCP values 2-738

trusted boundary for IP phones 2-413

VLAN-based 2-415

quality of service

See QoS

querytime, MVR 2-423

queue-set command 2-495

R

radius-server dead-criteria command 2-496

radius-server host command 2-498

rapid per-VLAN spanning-tree plus

See STP

rapid PVST+

See STP

rcommand command 2-500

re-authenticating IEEE 802.1x-enabled ports 2-187

re-authentication

periodic 2-188

time between attempts 2-192

receiver ports, MVR 2-426

receiving flow-control packets 2-212

recovery mechanism

causes 2-205

display 2-97, 2-548, 2-601, 2-604

timer interval 2-206

redundancy for cluster switches 2-132

redundant power supply

See RPS

redundant power system

See Cisco Redundant Power System 2300

reload command 2-502

remote command 2-504

remote-span command 2-506

Remote Switched Port Analyzer

See RSPAN

rename (boot loader) command A-21

renew ip dhcp snooping database command 2-508

replay protection, MACsec 2-510

replay-protection command 2-510

reset (boot loader) command A-22

restricted VLAN

See dot1x auth-fail vlan

rmdir (boot loader) command A-23

rmon collection stats command 2-513

root guard, for spanning tree 2-839

routed ports

IP addresses on 2-226

number supported 2-226

routing frames

See MTU

RPS

See Cisco Redundant Power System 2300

RPS 2300

configuring 2-477, 2-483, 2-485

managing 2-477, 2-483, 2-485

See Cisco Redundant Power System 2300

RSPAN

configuring 2-418

displaying 2-747

filter RSPAN traffic 2-418

remote-span command 2-506

sessions

add interfaces to 2-418

displaying 2-747

start new 2-418

rsu command 2-514

S

scheduled switchover

disabling 2-155

enabling 2-155

SDM mismatch mode 2-516, 2-789

sdm prefer command 2-515

SDM templates

allowed resources 2-517

and stacking 2-516

displaying 2-773

dual IPv4 and IPv6 2-515

secure ports, limitations 2-917

sending flow-control packets 2-212

service password-recovery command 2-519

service-policy command 2-521

session command 2-524

set (boot loader) command A-24

set command 2-525

setup command 2-527

setup express command 2-530

show access-lists command 2-532

show archive status command 2-535

show arp access-list command 2-536

show authentication command 2-537

show auto qos command 2-541

show boot command 2-545

show cable-diagnostics tdr command 2-548

show cisp command 2-551

show class-map command 2-552

show cluster candidates command 2-555

show cluster command 2-553

show cluster members command 2-557

show controllers cpu-interface command 2-559

show controllers ethernet-controller command 2-561

show controllers ethernet-controller fastethernet command 2-568

show controllers ethernet phy macsec command 2-571

show controllers power inline command 2-573

show controllers tcam command 2-575

show controller utilization command 2-577

show dot1q-tunnel command 2-584

show dot1x command 2-585

show dtp 2-589

show eap command 2-591

show env command 2-594

show env xps command 2-597

show errdisable detect command 2-601

show errdisable flap-values command 2-603

show errdisable recovery command 2-604

show etherchannel command 2-606

show fallback profile command 2-609

show flowcontrol command 2-611

show idprom command 2-613

show interfaces command 2-615

show interfaces counters command 2-626

show interface transceivers command 2-629

show inventory command 2-632

show ip arp inspection command 2-633

show ipc command 2-659

show ip dhcp snooping binding command 2-638

show ip dhcp snooping command 2-637

show ip dhcp snooping database command 2-640, 2-642

show ip igmp profile command 2-645

show ip igmp snooping address command 2-668

show ip igmp snooping command 2-646, 2-666

show ip igmp snooping groups command 2-649

show ip igmp snooping mrouter command 2-651, 2-670

show ip igmp snooping querier command 2-653, 2-672

show ip source binding command 2-655

show ipv6 access-list command 2-663

show ipv6 dhcp conflict command 2-665

show ipv6 route updated 2-674

show ip verify source command 2-657

show l2protocol-tunnel command 2-676

show lacp command 2-679

show link state group command 2-683

show location 2-685

show location command 2-685

show logging onboard command 2-688

show logging smartlog command 2-693

show mac access-group command 2-696

show mac address-table address command 2-699

show mac address-table aging time command 2-701

show mac address-table command 2-697

show mac address-table count command 2-703

show mac address-table dynamic command 2-705

show mac address-table interface command 2-707

show mac address-table learning command 2-709

show mac address-table move update command 2-710

show mac address-table notification command 2-109, 2-712, B-28

show mac address-table static command 2-714

show mac address-table vlan command 2-716

show macsec command 2-718

show mka default-policy command 2-720

show mka policy command 2-722

show mka session command 2-725

show mka statistics command 2-728

show mka summary command 2-731

show mls qos aggregate-policer command 2-735

show mls qos command 2-734

show mls qos input-queue command 2-736

show mls qos interface command 2-738

show mls qos maps command 2-742

show mls qos queue-set command 2-745

show mls qos vlan command 2-746

show monitor command 2-747

show mvr command 2-749

show mvr interface command 2-751

show mvr members command 2-753

show network-policy profile command 2-755

show nmsp command 2-756

show pagp command 2-759

show platform acl command C-2

show platform backup interface command C-3

show platform configuration command C-4

show platform dl command C-5

show platform etherchannel command C-6

show platform forward command C-7

show platform frontend-controller command C-9

show platform igmp snooping command C-10

show platform ipc trace command C-17

show platform ip multicast command C-11

show platform ip unicast command C-12

show platform ipv6 mld snooping command C-18

show platform ipv6 unicast command C-19

show platform ip wccp command C-16

show platform layer4op command C-21

show platform mac-address-table command C-22

show platform messaging command C-23

show platform monitor command C-24

show platform mvr table command C-25

show platform pm command C-26

show platform port-asic command C-27

show platform port-security command C-32

show platform qos command C-33

show platform resource-manager command C-34

show platform snmp counters command C-36

show platform spanning-tree command C-37

show platform stack-manager command C-39

show platform stp-instance command C-38

show platform tb command C-43

show platform tcam command C-44

show platform vlan command C-47

show policy-map command 2-761

show port security command 2-762

show power inline command 2-765, 2-783

show psp config 2-771

show psp config command 2-771

show psp statistics 2-772

show psp statistics command 2-772

show sdm prefer command 2-773

show setup express command 2-776

show spanning-tree command 2-777

show storm-control command 2-786

show switch command 2-788

show system mtu command 2-793

show trust command 2-945

show udld command 2-794

show version command 2-797

show vlan access-map command 2-804

show vlan command 2-799

show vlan command, fields 2-801

show vlan filter command 2-805

show vmps command 2-806

show vtp command 2-808

shutdown command 2-813

shutdown threshold, Layer 2 protocol tunneling 2-326

shutdown vlan command 2-814

small-frame violation rate command 2-815

SNMP host, specifying 2-822

SNMP informs, enabling the sending of 2-817

snmp-server enable traps command 2-817

snmp-server host command 2-822

snmp trap mac-notification change command 2-826

SNMP traps

enabling MAC address notification trap 2-826

enabling the MAC address notification feature 2-360

enabling the sending of 2-817

SoftPhone

See Cisco SoftPhone

software images

copying 2-10

deleting 2-140

downloading 2-13

upgrading 2-10, 2-13

uploading 2-20

software version, displaying 2-797

source ports, MVR 2-426

SPAN

configuring 2-418

debug messages, display B-31

displaying 2-747

filter SPAN traffic 2-418

sessions

add interfaces to 2-418

displaying 2-747

start new 2-418

spanning-tree backbonefast command 2-828

spanning-tree bpdufilter command 2-829

spanning-tree bpduguard command 2-831

spanning-tree cost command 2-833

spanning-tree etherchannel command 2-835

spanning-tree extend system-id command 2-837

spanning-tree guard command 2-839

spanning-tree link-type command 2-841

spanning-tree loopguard default command 2-843

spanning-tree mode command 2-845

spanning-tree mst configuration command 2-847

spanning-tree mst cost command 2-849

spanning-tree mst forward-time command 2-851

spanning-tree mst hello-time command 2-852

spanning-tree mst max-age command 2-853

spanning-tree mst max-hops command 2-854

spanning-tree mst port-priority command 2-855

spanning-tree mst pre-standard command 2-857

spanning-tree mst priority command 2-858

spanning-tree mst root command 2-859

spanning-tree portfast (global configuration) command 2-863

spanning-tree portfast (interface configuration) command 2-866

spanning-tree port-priority command 2-861

Spanning Tree Protocol

See STP

spanning-tree transmit hold-count command 2-868

spanning-tree uplinkfast command 2-869

spanning-tree vlan command 2-871

speed command 2-874

srr-queue bandwidth limit command 2-876

srr-queue bandwidth shape command 2-878

srr-queue bandwidth share command 2-880

SSH, configuring version 2-290

stack-mac persistent timer command 2-882

stack member

access 2-524

number 2-788, 2-894

priority value 2-891

provisioning 2-892

reloading 2-502

stacks, switch

disabling a member 2-889

enabling a member 2-889

MAC address 2-882

provisioning a new member 2-892

reloading 2-502

stack member access 2-524

stack member number 2-788, 2-894

stack member priority value 2-788, 2-891

static-access ports, configuring 2-898

statistics, Ethernet group 2-513

sticky learning, enabling 2-915

storm-control command 2-886

STP

BackboneFast 2-828

counters, clearing 2-118

debug messages, display

BackboneFast events B-88

MSTP B-91

optimized BPDUs handling B-90

spanning-tree activity B-86

switch shim B-93

transmitted and received BPDUs B-89

UplinkFast B-95

detection of indirect link failures 2-828

enabling protocol tunneling for 2-326

EtherChannel misconfiguration 2-835

extended system ID 2-837

path cost 2-833

protocol modes 2-845

root port

accelerating choice of new 2-869

loop guard 2-839

preventing from becoming designated 2-839

restricting which can be root 2-839

root guard 2-839

UplinkFast 2-869

root switch

affects of extended system ID 2-837, 2-872

hello-time 2-871

interval between BDPU messages 2-871

interval between hello BPDU messages 2-871

max-age 2-871

port priority for selection of 2-861

primary or secondary 2-871

switch priority 2-871

state changes

blocking to forwarding state 2-866

enabling BPDU filtering 2-829, 2-863

enabling BPDU guard 2-831, 2-863

enabling Port Fast 2-863, 2-866

enabling timer to recover from error state 2-205

forward-delay time 2-871

length of listening and learning states 2-871

shutting down Port Fast-enabled ports 2-863

state information display 2-777

VLAN options 2-858, 2-871

supplemental power command 2-884

SVIs, creating 2-220

SVI status calculation 2-900

Switched Port Analyzer

See SPAN

switching characteristics

modifying 2-896

returning to interfaces 2-896

switchport access command 2-898

switchport autostate exclude command 2-900

switchport backup interface command 2-902

switchport block command 2-905

switchport command 2-896

switchport host command 2-907

switchport mode command 2-908

switchport mode private-vlan command 2-911

switchport nonegotiate command 2-913

switchport port-security aging command 2-920

switchport port-security command 2-915

switchport priority extend command 2-922

switchport private-vlan command 2-924

switchport protected command 2-926

switchports, displaying 2-615

switchport trunk command 2-928

switchport voice detect 2-931

switchport voice vlan command 2-932

switch priority command 2-889, 2-891

switch provision command 2-892

switch renumber command 2-894

system env temperature threshold yellow command 2-934

system message logging 2-344

system message logging, save message to flash 2-345

system mtu command 2-936

system resource templates 2-515

T

tar files, creating, listing, and extracting 2-17

TDR, running 2-939

Telnet, using to communicate to cluster switches 2-500

temperature information, displaying 2-594

templates, system resources 2-515

test cable-diagnostics tdr command 2-939

traceroute mac command 2-940

traceroute mac ip command 2-943

trunking, VLAN mode 2-908

trunk mode 2-908

trunk ports 2-908

trunks, to non-DTP device 2-909

trusted boundary for QoS 2-413

trusted port states for QoS 2-413

tunnel ports, Layer 2 protocol, displaying 2-676

type (boot loader) command A-27

U

UDLD

aggressive mode 2-947, 2-949

debug messages, display B-103

enable globally 2-947

enable per interface 2-949

error recovery timer 2-206

message timer 2-947

normal mode 2-947, 2-949

reset a shutdown interface 2-951

status 2-794

udld command 2-947

udld port command 2-949

udld reset command 2-951

unicast storm control 2-886

UniDirectional Link Detection

See UDLD

unknown multicast traffic, preventing 2-905

unknown unicast traffic, preventing 2-905

unset (boot loader) command A-28

upgrading

copying software images 2-10

downloading software images 2-13

software images, monitoring status of 2-535

UplinkFast, for STP 2-869

usb-inactivity-timeout (console configuration) command 2-952

user EXEC mode 1-2, 1-3

V

version (boot loader) command A-30

version mismatch mode 2-789, C-40

vlan (global configuration) command 2-953

vlan access-map command 2-958

VLAN access map configuration mode 2-958

VLAN access maps

actions 2-8

displaying 2-804

VLAN-based QoS 2-415

VLAN configuration

rules 2-956

saving 2-953

VLAN configuration mode

description 1-4

entering 2-953

summary 1-3

vlan dot1q tag native command 2-960

vlan filter command 2-962

VLAN filters, displaying 2-805

VLAN ID range 2-953

VLAN maps

applying 2-962

creating 2-958

defining 2-366

displaying 2-804

VLAN Query Protocol

See VQP

VLANs

adding 2-953

configuring 2-953

debug messages, display

ISL B-99

VLAN IOS file system error tests B-98

VLAN manager activity B-96

VTP B-101

displaying configurations 2-799

extended-range 2-953

MAC addresses

displaying 2-716

number of 2-703

media types 2-956

normal-range 2-953

private 2-911

configuring 2-489

displaying 2-799

See also private VLANs

restarting 2-814

saving the configuration 2-953

shutting down 2-814

SNMP traps for VTP 2-820, 2-823

suspending 2-814

VLAN Trunking Protocol

See VTP

VM mode 2-789, C-40

VMPS

configuring servers 2-967

displaying 2-806

error recovery timer 2-206

reconfirming dynamic VLAN assignments 2-964

vmps reconfirm (global configuration) command 2-965

vmps reconfirm (privileged EXEC) command 2-964

vmps retry command 2-966

vmps server command 2-967

voice VLAN

configuring 2-931, 2-932

setting port priority 2-922

VQP

and dynamic-access ports 2-899

clearing client statistics 2-120

displaying information 2-806

per-server retry count 2-966

reconfirmation interval 2-965

reconfirming dynamic VLAN assignments 2-964

VTP

changing characteristics 2-969

clearing pruning counters 2-121

configuring

domain name 2-969

file name 2-969

mode 2-969

password 2-970

counters display fields 2-809

displaying information 2-808

enabling

pruning 2-970

tunneling for 2-326

Version 2 2-970

enabling per port 2-974

mode 2-969

pruning 2-970

saving the configuration 2-953

statistics 2-808

status 2-808

status display fields 2-811

vtp (global configuration) command 2-969

vtp interface configuration command 2-974

vtp primary command 2-975

X

XPS 2200

configuring 2-481

naming 2-481