Table Of Contents
A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - Q - R - S - T - U - V - X -
Index
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5
AAA methods 2-3
abort command 2-675
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-117
MAC, displaying 2-451
access list, IPv6 2-169
access map configuration mode 2-228
access mode 2-620
access ports 2-620
ACEs 2-62, 2-295
ACLs
deny 2-60
displaying 2-337
for non-IP protocols 2-207
IP 2-117
matching 2-228
on Layer 2 interfaces 2-117
permit 2-293
action command 2-6
address aliasing 2-278
aggregate-port learner 2-283
allowed VLANs 2-640
apply command 2-675
archive download-sw command 2-8
archive tar command 2-11
archive upload-sw command 2-14
authentication failed VLAN
See dot1x auth-fail vlan
auth-fail max-attempts
See dot1x auth-fail max-attempts
auth-fail vlan
See dot1x auth-fail vlan
authorization state of controlled port 2-86
autonegotiation of duplex mode 2-97
auto qos voip command 2-16
B
BackboneFast, for STP 2-553
backup interfaces
configuring 2-614
displaying 2-389
boot (boot loader) command A-2
boot config-file command 2-20
boot enable-break command 2-21
boot helper command 2-22
boot helper-config file command 2-23
booting
Cisco IOS image 2-26
displaying environment variables 2-344
interrupting 2-21
manually 2-24
boot loader
accessing A-1
booting
Cisco IOS image A-2
helper image 2-22
directories
creating A-15
displaying a list of A-7
removing A-19
displaying
available commands A-12
memory heap utilization A-13
version A-26
environment variables
described A-20
displaying settings A-20
location of A-21
setting A-20
unsetting A-24
files
copying A-5
deleting A-6
displaying a list of A-7
displaying the contents of A-4, A-16, A-23
renaming A-17
file system
formatting A-10
initializing flash A-9
running a consistency check A-11
resetting the system A-18
boot manual command 2-24
boot private-config-file command 2-25
boot system command 2-26
BPDU filtering, for spanning tree 2-554, 2-587
BPDU guard, for spanning tree 2-556, 2-587
break key detection 2-325
broadcast storm control 2-605
C
cat (boot loader) command A-4
CDP, enabling protocol tunneling for 2-187
channel-group command 2-27
channel-protocol command 2-30
Cisco SoftPhone
auto-QoS configuration 2-16
trusting packets sent from 2-270
class command 2-31
class-map command 2-33
class maps
creating 2-33
defining the match criteria 2-230
displaying 2-348
class of service
See CoS
clear dot1x command 2-35
clear eap sessions command 2-36
clear errdisable interface 2-37
clear ipc command 2-38
clear ip dhcp snooping database command 2-40
clear l2protocol-tunnel counters command 2-39
clear lacp command 2-42
clear mac address-table command 2-43, 2-44
clear pagp command 2-45
clear port-security command 2-46
clear spanning-tree counters command 2-48
clear spanning-tree detected-protocols command 2-49
clear vmps statistics command 2-50
clear vtp counters command 2-51
clusters
SNMP trap 2-543
command modes defined 1-1
configuration files
password recovery disable considerations A-1
specifying the name 2-20, 2-25
configuring multiple interfaces 2-113
config-vlan mode
commands 2-661
description 1-4
entering 2-660
summary 1-2
copy (boot loader) command A-5
CoS
assigning default value to incoming packets 2-240
assigning to Layer 2 protocol packets 2-190
overriding the incoming value 2-240
CoS-to-DSCP map 2-244
CPU ASIC statistics, displaying 2-349
crashinfo files 2-106
D
debug auto qos command B-2
debug backup command B-4
debug dot1x command B-5
debug dtp command B-6
debug eap command B-7
debug etherchannel command B-8
debug interface command B-11
debug ip dhcp snooping command B-9
debug ip igmp filter command B-12
debug ip igmp max-groups command B-13
debug ip igmp snooping command B-14
debug ip verify source packet command B-10
debug lacp command B-15
debug mac-notification command B-16
debug matm command B-17
debug matm move update command B-18
debug monitor command B-19
debug mvrdbg command B-20
debug nvram command B-21
debug pagp command B-22
debug platform acl command B-23
debug platform backup interface command B-24
debug platform cli-redirection main command B-25
debug platform cpu-queues command B-26
debug platform dot1x command B-28
debug platform etherchannel command B-29
debug platform fallback-bridging command B-30
debug platform forw-tcam command B-31
debug platform ip arp inspection command B-32
debug platform ipc command B-40
debug platform ip dhcp command B-33
debug platform ip igmp snooping command B-34
debug platform ip multicast command B-36
debug platform ip unicast command B-38
debug platform led command B-41
debug platform matm command B-42
debug platform messaging application command B-43
debug platform phy command B-44
debug platform pm command B-46
debug platform port-asic command B-48
debug platform port-security command B-49
debug platform qos-acl-tcam command B-50
debug platform remote-commands command B-51
debug platform resource-manager command B-52
debug platform snmp command B-53
debug platform span command B-54
debug platform supervisor-asic command B-55
debug platform sw-bridge command B-56
debug platform tcam command B-57
debug platform udld command B-60
debug platform vlan command B-61
debug pm command B-62
debug port-security command B-64
debug qos-manager command B-65
debug spanning-tree backbonefast command B-68
debug spanning-tree bpdu command B-69
debug spanning-tree bpdu-opt command B-70
debug spanning-tree command B-66
debug spanning-tree mstp command B-71
debug spanning-tree switch command B-73
debug spanning-tree uplinkfast command B-75
debug sw-vlan command B-76
debug sw-vlan ifs command B-78
debug sw-vlan notification command B-79
debug sw-vlan vtp command B-80
debug udld command B-82
debug vqpc command B-84
define interface-range command 2-52
delete (boot loader) command A-6
delete command 2-54
deny (IPv6) command 2-55
deny command 2-60
detect mechanism, causes 2-98
DHCP snooping
accepting untrusted packets from edge switch 2-132
enabling
on a VLAN 2-138
option 82 2-130, 2-132
trust on an interface 2-136
error recovery timer 2-103
rate limiting 2-135
DHCP snooping binding database
binding file, configuring 2-128
bindings
adding 2-126
deleting 2-126
displaying 2-403
clearing database agent statistics 2-40
database agent, configuring 2-128
displaying
binding entries 2-403
database agent status 2-405, 2-407
renewing 2-319
dir (boot loader) command A-7
directories, deleting 2-54
domain name, VTP 2-685, 2-689
dot1x auth-fail max-attempts 2-65
dot1x auth-fail vlan 2-67
dot1x command 2-63
dot1x control-direction command 2-69
dot1x critical global configuration command 2-71
dot1x critical interface configuration command 2-73
dot1x default command 2-75
dot1x fallback command 2-76
dot1x guest-vlan command 2-77
dot1x host-mode command 2-79
dot1x initialize command 2-80
dot1x mac-auth-bypass command 2-81
dot1x max-reauth-req command 2-83
dot1x max-req command 2-84
dot1x pae command 2-85
dot1x port-control command 2-86
dot1x re-authenticate command 2-88
dot1x reauthentication command 2-89
dot1x test eapol-capable command 2-90
dot1x test timeout command 2-91
dot1x timeout command 2-92
dot1x violation-mode command 2-95
dropping packets, with ACL matches 2-6
drop threshold, Layer 2 protocol tunneling 2-187
DSCP-to-CoS map 2-244
DSCP-to-DSCP-mutation map 2-244
DTP 2-621
DTP flap
error detection for 2-98
error recovery timer 2-103
DTP negotiation 2-625
dual IPv4 and IPv6 templates 2-287
dual-purpose uplink ports
selecting the type 2-234
duplex command 2-96
dynamic-access ports
configuring 2-610
restrictions 2-610
dynamic ARP inspection
error detection for 2-98
dynamic auto VLAN membership mode 2-620
dynamic desirable VLAN membership mode 2-620
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-84
response time before retransmitting 2-92
encapsulation methods 2-640
environment variables, displaying 2-344
errdisable detect cause command 2-98
errdisable detect cause small-frame comand 2-100
errdisable recovery cause small-frame 2-102
errdisable recovery command 2-103
error conditions, displaying 2-376
error disable detection 2-98
error-disabled interfaces, displaying 2-389
EtherChannel
assigning Ethernet interface to channel group 2-27
creating port-channel logical interface 2-111
debug EtherChannel/PAgP, display B-8
debug platform-specific events, display B-29
displaying 2-380
enabling Layer 2 protocol tunneling for
LACP 2-188
PAgP 2-188
UDLD 2-188
interface information, displaying 2-389
LACP
clearing channel-group information 2-42
debug messages, display B-15
displaying 2-440
modes 2-27
port priority for hot-standby ports 2-191
restricting a protocol 2-30
system priority 2-193
load-distribution methods 2-303
PAgP
aggregate-port learner 2-283
clearing channel-group information 2-45
debug messages, display B-22
displaying 2-497
error detection for 2-98
error recovery timer 2-103
learn method 2-283
modes 2-27
physical-port learner 2-283
priority of interface for transmitted traffic 2-285
Ethernet controller, internal register display 2-351
Ethernet statistics, collecting 2-321
exception crashinfo command 2-106
exit command 2-675
extended-range VLANs
and allowed VLAN list 2-640
and pruning-eligible list 2-640
configuring 2-660
extended system ID for STP 2-562
F
fallback profile command 2-107
fallback profiles
displaying 2-383
file name, VTP 2-685
files, deleting 2-54
flash_init (boot loader) command A-9
Flex Links
configuring 2-614
configuring preferred VLAN 2-616
displaying 2-389
flowcontrol command 2-109
format (boot loader) command A-10
forwarding packets, with ACL matches 2-6
forwarding results, display C-6
frame forwarding information, displaying C-6
fsck (boot loader) command A-11
G
global configuration mode 1-2, 1-3
H
hardware ACL statistics 2-337
help (boot loader) command A-12
hierarchical policy maps 2-301
host connection, port configuration 2-619
host ports, private VLANs 2-623
I
IEEE 802.1Q trunk ports and native VLANs 2-677
IEEE 802.1Q tunnel ports
configuring 2-620
displaying 2-363
limitations 2-621
IEEE 802.1x
and switchport modes 2-621
violation error recovery 2-103
See also port-based authentication
IEEE 802.1X Port Based Authentication
enabling guest VLAN supplicant 2-65, 2-76, 2-108
IGMP filters
applying 2-141
debug messages, display B-12
IGMP groups, setting maximum 2-143
IGMP maximum groups, debugging B-13
IGMP profiles
creating 2-145
displaying 2-410
IGMP snooping
adding ports as a static member of a group 2-161
displaying 2-411, 2-416, 2-418
enabling 2-147
enabling the configurable-leave timer 2-149
enabling the Immediate-Leave feature 2-158
flooding query count 2-155
interface topology change notification behavior 2-157
multicast table 2-414
querier 2-151
query solicitation 2-155
report suppression 2-153
switch topology change notification behavior 2-155
images
See software images
Immediate-Leave feature, MVR 2-280
Immediate-Leave processing, IPv6 2-183
immediate-leave processing 2-158
interface configuration mode 1-2, 1-4
interface port-channel command 2-111
interface range command 2-113
interface-range macros 2-52
interfaces
assigning Ethernet interface to channel group 2-27
configuring 2-96
configuring multiple 2-113
creating port-channel logical 2-111
debug messages, display B-11
disabling 2-539
displaying the MAC address table 2-463
restarting 2-539
interface speed, configuring 2-597
interface vlan command 2-115
internal registers, displaying 2-351, 2-359
Internet Group Management Protocol
See IGMP
invalid GBIC
error detection for 2-98
error recovery timer 2-103
ip access-group command 2-117
ip address command 2-120
IP addresses, setting 2-120
IP address matching 2-228
ip admission command 2-122
ip admission name proxy http command 2-123
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-126
ip dhcp snooping command 2-125
ip dhcp snooping database command 2-128
ip dhcp snooping information option allow-untrusted command 2-132
ip dhcp snooping information option command 2-130
ip dhcp snooping information option format remote-id command 2-134
ip dhcp snooping limit rate command 2-135
ip dhcp snooping trust command 2-136
ip dhcp snooping verify command 2-137
ip dhcp snooping vlan command 2-138
ip dhcp snooping vlan information option format-type circuit-id string command 2-139
ip igmp filter command 2-141
ip igmp max-groups command 2-143
ip igmp profile command 2-145
ip igmp snooping command 2-147
ip igmp snooping last-member-query-interval command 2-149
ip igmp snooping querier command 2-151
ip igmp snooping report-suppression command 2-153
ip igmp snooping tcn command 2-155
ip igmp snooping tcn flood command 2-157
ip igmp snooping vlan immediate-leave command 2-158
ip igmp snooping vlan mrouter command 2-159
ip igmp snooping vlan static command 2-161
IP multicast addresses 2-277
IP phones
auto-QoS configuration 2-16
trusting packets sent from 2-270
IP-precedence-to-DSCP map 2-244
ip snap forwarding command 2-163
ip source binding command 2-164
IP source guard
disabling 2-168
displaying
binding entries 2-420
configuration 2-422
dynamic binding entries only 2-403
enabling 2-168
static IP source bindings 2-164
ip ssh command 2-166
IPv6 access list, deny conditions 2-55
ipv6 access-list command 2-169
ipv6 mld snooping command 2-171
ipv6 mld snooping last-listener-query count command 2-173
ipv6 mld snooping last-listener-query-interval command 2-175
ipv6 mld snooping listener-message-suppression command 2-177
ipv6 mld snooping robustness-variable command 2-179
ipv6 mld snooping tcn command 2-181
ipv6 mld snooping vlan command 2-183
IPv6 SDM template 2-322
ipv6 traffic-filter command 2-185
ip verify source command 2-168
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-187
l2protocol-tunnel cos command 2-190
LACP
See EtherChannel
lacp port-priority command 2-191
lacp system-priority command 2-193
Layer 2 mode, enabling 2-608
Layer 2 protocol ports, displaying 2-438
Layer 2 protocol-tunnel
error detection for 2-98
error recovery timer 2-103
Layer 2 protocol tunnel counters 2-39
Layer 2 protocol tunneling error recovery 2-188
Layer 2 traceroute
IP addresses 2-651
MAC addresses 2-648
Layer 3 mode, enabling 2-608
line configuration mode 1-2, 1-5
Link Aggregation Control Protocol
See EtherChannel
link flap
error detection for 2-98
error recovery timer 2-103
link state group command 2-199
link state track command 2-201
load-distribution methods for EtherChannel 2-303
location (global configuration) command 2-195
location (interface configuration) command 2-197
logging event command 2-202
logging file command 2-203
logical interface 2-111
loopback error
detection for 2-98
recovery timer 2-103
loop guard, for spanning tree 2-563, 2-567
M
mac access-group command 2-205
MAC access-groups, displaying 2-451
MAC access list configuration mode 2-207
mac access-list extended command 2-207
MAC access lists 2-60
MAC addresses
disabling MAC address learning per VLAN 2-210
displaying
aging time 2-457
all 2-455
dynamic 2-461
MAC address-table move updates 2-466
notification settings 2-465, 2-468
number of addresses in a VLAN 2-459
per interface 2-463
per VLAN 2-472
static 2-470
static and dynamic entries 2-453
dynamic
aging time 2-209
deleting 2-43
displaying 2-461
enabling MAC address notification 2-214
enabling MAC address-table move update 2-212
matching 2-228
static
adding and removing 2-216
displaying 2-470
dropping on an interface 2-217
tables 2-455
mac address notification, debugging B-16
mac address-table aging-time 2-205, 2-228
mac address-table aging-time command 2-209
mac address-table learning command 2-210
mac address-table move update command 2-212
mac address-table notification command 2-214
mac address-table static command 2-216
mac address-table static drop command 2-217
macro apply command 2-219
macro description command 2-222
macro global command 2-223
macro global description command 2-225
macro name command 2-226
macros
adding a description 2-222
adding a global description 2-225
applying 2-223
creating 2-226
displaying 2-499
interface range 2-52, 2-113
specifying parameter values 2-223
tracing 2-223
maps
QoS
defining 2-244
displaying 2-482
VLAN
creating 2-672
defining 2-228
displaying 2-531
match (access-map configuration) command 2-228
match (class-map configuration) command 2-230
maximum transmission unit
See MTU
mdix auto command 2-232
MDL snooping
displaying 2-432
media-type command 2-234
memory (boot loader) command A-13
mkdir (boot loader) command A-15
MLD snooping
configuring 2-177, 2-179
configuring queries 2-173, 2-175
configuring topology change notification 2-181
displaying 2-430, 2-434, 2-436
enabling 2-171
MLD snooping on a VLAN
enabling 2-183
mls qos aggregate-policer command 2-238
mls qos command 2-236
mls qos cos command 2-240
mls qos dscp-mutation command 2-242
mls qos map command 2-244
mls qos queue-set output buffers command 2-248
mls qos queue-set output threshold command 2-250
mls qos rewrite ip dscp command 2-252
mls qos srr-queue input bandwidth command 2-254
mls qos srr-queue input buffers command 2-256
mls qos-srr-queue input cos-map command 2-258
mls qos srr-queue input dscp-map command 2-260
mls qos srr-queue input priority-queue command 2-262
mls qos srr-queue input threshold command 2-264
mls qos-srr-queue output cos-map command 2-266
mls qos srr-queue output dscp-map command 2-268
mls qos trust command 2-270
mls qos vlan-based command 2-272
mode, MVR 2-277
Mode button, and password recovery 2-325
modes, commands 1-1
monitor session command 2-273
more (boot loader) command A-16
MSTP
displaying 2-512
interoperability 2-49
link type 2-565
MST region
aborting changes 2-571
applying changes 2-571
configuration name 2-571
configuration revision number 2-571
current or pending display 2-571
displaying 2-512
MST configuration mode 2-571
VLANs-to-instance mapping 2-571
path cost 2-573
protocol mode 2-569
restart protocol migration process 2-49
root port
loop guard 2-563
preventing from becoming designated 2-563
restricting which can be root 2-563
root guard 2-563
root switch
affects of extended system ID 2-562
hello-time 2-576, 2-583
interval between BDPU messages 2-577
interval between hello BPDU messages 2-576, 2-583
max-age 2-577
maximum hop count before discarding BPDU 2-578
port priority for selection of 2-579
primary or secondary 2-583
switch priority 2-582
state changes
blocking to forwarding state 2-589
enabling BPDU filtering 2-554, 2-587
enabling BPDU guard 2-556, 2-587
enabling Port Fast 2-587, 2-589
forward-delay time 2-575
length of listening and learning states 2-575
rapid transition to forwarding 2-565
shutting down Port Fast-enabled ports 2-587
state information display 2-511
MTU
configuring size 2-645
displaying global setting 2-519
Multicase Listener Discovery
See MLD
multicast group address, MVR 2-280
multicast groups, MVR 2-278
Multicast Listener Discovery
See MLD
multicast router learning method 2-159
multicast router ports, IPv6 2-183
multicast router ports, configuring 2-159
multicast storm control 2-605
multicast VLAN, MVR 2-277
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-79
Multiple Spanning Tree Protocol
See MSTP
MVR
and address aliasing 2-278
configuring 2-277
configuring interfaces 2-280
debug messages, display B-20
displaying 2-491
displaying interface information 2-493
members, displaying 2-495
mvr (global configuration) command 2-277
mvr (interface configuration) command 2-280
mvr vlan group command 2-281
N
native VLANs 2-640
native VLAN tagging 2-677
nonegotiate
DTP messaging 2-625
nonegotiate, speed 2-597
non-IP protocols
denying 2-60
forwarding 2-293
non-IP traffic access lists 2-207
non-IP traffic forwarding
denying 2-60
permitting 2-293
normal-range VLANs 2-660, 2-666
no vlan command 2-660, 2-670
O
online diagnostics
displaying
configured boot-up coverage level 2-363
current scheduled tasks 2-363
event logs 2-363
supported test suites 2-363
test ID 2-363
test results 2-363
test statistics 2-363
P
PAgP
See EtherChannel
pagp learn-method command 2-283
pagp port-priority command 2-285
password, VTP 2-685, 2-689
password-recovery mechanism, enabling and disabling 2-325
permit (IPv6) command 2-287
permit (MAC access-list configuration) command 2-293
per-VLAN spanning-tree plus
See STP
physical-port learner 2-283
PID, displaying 2-401
PIM-DVMRP, as multicast router learning method 2-159
police aggregate command 2-298
police command 2-296
policed-DSCP map 2-244
policy-map command 2-300
policy maps
applying to an interface 2-327, 2-332
creating 2-300
displaying 2-502
hierarchical 2-301
policers
displaying 2-475
for a single class 2-296
for multiple classes 2-238, 2-298
policed-DSCP map 2-244
traffic classification
defining the class 2-31
defining trust states 2-653
setting DSCP or IP precedence values 2-330
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
configuring violation modes 2-95
debug messages, display B-5
enabling IEEE 802.1x
globally 2-63
per interface 2-86
guest VLAN 2-77
host modes 2-79
IEEE 802.1x AAA accounting methods 2-1
initialize an interface 2-80, 2-91
MAC authentication bypass 2-81
manual control of authorization state 2-86
multiple hosts on authorized port 2-79
PAE as authenticator 2-85
periodic re-authentication
enabling 2-89
time between attempts 2-92
quiet period between failed authentication exchanges 2-92
re-authenticating IEEE 802.1x-enabled ports 2-88
resetting configurable IEEE 802.1x parameters 2-75
switch-to-authentication server retransmission time 2-92
switch-to-client frame-retransmission number2-83to 2-84
switch-to-client retransmission time 2-92
test for IEEE 802.1x readiness 2-90
port-channel load-balance command 2-303
Port Fast, for spanning tree 2-589
port ranges, defining 2-52
ports, debugging B-62
ports, protected 2-638
port security
aging 2-632
debug messages, display B-64
enabling 2-627
violation error recovery 2-103
port trust states for QoS 2-270
port types, MVR 2-280
priority-queue command 2-305
private-vlan command 2-307
private-vlan mapping command 2-310
private VLANs
association 2-636
configuring 2-307
configuring ports 2-623
displaying 2-525
host ports 2-623
mapping
configuring 2-636
displaying 2-389
promiscuous ports 2-623
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-401
promiscuous ports, private VLANs 2-623
protected ports, displaying 2-395
pruning
VLANs 2-640
VTP
displaying interface information 2-389
enabling 2-685, 2-689
pruning-eligible VLAN list 2-642
PVST+
See STP
Q
QoS
auto-QoS
configuring 2-16
debug messages, display B-2
displaying 2-341
class maps
creating 2-33
defining the match criteria 2-230
displaying 2-348
defining the CoS value for an incoming packet 2-240
displaying configuration information 2-341, 2-474
DSCP transparency 2-252
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-242
defining DSCP-to-DSCP-mutation map 2-244
egress queues
allocating buffers 2-248
defining the CoS output queue threshold map 2-266
defining the DSCP output queue threshold map 2-268
displaying buffer allocations 2-478
displaying CoS output queue threshold map 2-482
displaying DSCP output queue threshold map 2-482
displaying queueing strategy 2-478
displaying queue-set settings 2-485
enabling bandwidth shaping and scheduling 2-601
enabling bandwidth sharing and scheduling 2-603
limiting the maximum output on a port 2-599
mapping a port to a queue-set 2-312
mapping CoS values to a queue and threshold 2-266
mapping DSCP values to a queue and threshold 2-268
setting maximum and reserved memory allocations 2-250
setting WTD thresholds 2-250
enabling 2-236
ingress queues
allocating buffers 2-256
assigning SRR scheduling weights 2-254
defining the CoS input queue threshold map 2-258
defining the DSCP input queue threshold map 2-260
displaying buffer allocations 2-478
displaying CoS input queue threshold map 2-482
displaying DSCP input queue threshold map 2-482
displaying queueing strategy 2-478
displaying settings for 2-476
enabling the priority queue 2-262
mapping CoS values to a queue and threshold 2-258
mapping DSCP values to a queue and threshold 2-260
setting WTD thresholds 2-264
maps
defining 2-244, 2-258, 2-260, 2-266, 2-268
displaying 2-482
policy maps
applying an aggregate policer 2-298
applying to an interface 2-327, 2-332
creating 2-300
defining policers 2-238, 2-296
displaying policers 2-475
displaying policy maps 2-502
hierarchical 2-301
policed-DSCP map 2-244
setting DSCP or IP precedence values 2-330
traffic classifications 2-31
trust states 2-653
port trust states 2-270
queues, enabling the expedite 2-305
statistics
in-profile and out-of-profile packets 2-478
packets enqueued or dropped 2-478
sent and received CoS values 2-478
sent and received DSCP values 2-478
trusted boundary for IP phones 2-270
VLAN-based 2-272
quality of service
See QoS
querytime, MVR 2-277
queue-set command 2-312
R
radius-server dead-criteria command 2-313
radius-server host command 2-315
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
re-authenticating IEEE 802.1x-enabled ports 2-88
re-authentication
periodic 2-89
time between attempts 2-92
receiver ports, MVR 2-280
receiving flow-control packets 2-109
recovery mechanism
causes 2-103
display 2-37, 2-346, 2-374, 2-378
timer interval 2-104
remote-span command 2-317
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-17
renew ip dhcp snooping database command 2-319
reset (boot loader) command A-18
reset command 2-675
resource templates, displaying 2-507
restricted VLAN
See dot1x auth-fail vlan
rmdir (boot loader) command A-19
rmon collection stats command 2-321
root guard, for spanning tree 2-563
routed ports
IP addresses on 2-121
number supported 2-121
RSPAN
configuring 2-273
displaying 2-488
filter RSPAN traffic 2-273
remote-span command 2-317
sessions
add interfaces to 2-273
displaying 2-488
start new 2-273
S
sdm prefer command 2-322
SDM templates
allowed resources 2-323
displaying 2-507
dual IPv4 and IPv6 2-322
secure ports, limitations 2-629
sending flow-control packets 2-109
service password-recovery command 2-325
service-policy command 2-327
set (boot loader) command A-20
set command 2-330
setup command 2-332
setup express command 2-335
show access-lists command 2-337
show archive status command 2-340
show auto qos command 2-341
show boot command 2-344
show cable-diagnostics tdr command 2-346
show changes command 2-675
show class-map command 2-348
show controllers cpu-interface command 2-349
show controllers ethernet-controller command 2-351
show controllers tcam command 2-359
show controller utilization command 2-361
show current command 2-675
show dot1q-tunnel command 2-363
show dot1x command 2-364
show dtp 2-368
show eap command 2-370
show env command 2-373
show errdisable detect command 2-374
show errdisable flap-values command 2-376
show errdisable recovery command 2-378
show etherchannel command 2-380
show fallback profile command 2-383
show flowcontrol command 2-385
show idprom command 2-387
show interfaces command 2-389
show interfaces counters command 2-398
show inventory command 2-401
show ipc command 2-424
show ip dhcp snooping binding command 2-403
show ip dhcp snooping command 2-402
show ip dhcp snooping database command 2-405, 2-407
show ip igmp profile command 2-410
show ip igmp snooping address command 2-432
show ip igmp snooping command 2-411, 2-430
show ip igmp snooping groups command 2-414
show ip igmp snooping mrouter command 2-416, 2-434
show ip igmp snooping querier command 2-418, 2-436
show ip source binding command 2-420
show ipv6 access-list command 2-428
show ip verify source command 2-422
show l2protocol-tunnel command 2-438
show lacp command 2-440
show link state group command 2-447, 2-449
show location 2-444
show mac access-group command 2-451
show mac address-table address command 2-455
show mac address-table aging time command 2-457
show mac address-table command 2-453
show mac address-table count command 2-459
show mac address-table dynamic command 2-461
show mac address-table interface command 2-463
show mac address-table learning command 2-465
show mac address-table move update command 2-466
show mac address-table notification command 2-44, 2-468, B-18
show mac address-table static command 2-470
show mac address-table vlan command 2-472
show mls qos aggregate-policer command 2-475
show mls qos command 2-474
show mls qos input-queue command 2-476
show mls qos interface command 2-478
show mls qos maps command 2-482
show mls qos queue-set command 2-485
show mls qos vlan command 2-487
show monitor command 2-488
show mvr command 2-491
show mvr interface command 2-493
show mvr members command 2-495
show pagp command 2-497
show parser macro command 2-499
show platform acl command C-2
show platform backup interface command C-3
show platform configuration command C-4
show platform etherchannel command C-5
show platform forward command C-6
show platform igmp snooping command C-8
show platform ipc trace command C-15
show platform ip multicast command C-10
show platform ip unicast command C-11
show platform ipv6 unicast command C-16
show platform layer4op command C-18
show platform mac-address-table command C-19
show platform messaging command C-20
show platform monitor command C-21
show platform mvr table command C-22
show platform pm command C-23
show platform port-asic command C-24
show platform port-security command C-29
show platform qos command C-30
show platform resource-manager command C-31
show platform snmp counters command C-33
show platform spanning-tree command C-34
show platform stp-instance command C-35
show platform tcam command C-36
show platform vlan command C-39
show policy-map command 2-502
show port security command 2-504
show proposed command 2-675
show sdm prefer command 2-507
show setup express command 2-510
show spanning-tree command 2-511
show storm-control command 2-517
show system mtu command 2-519
show trust command 2-653
show udld command 2-520
show version command 2-523
show vlan access-map command 2-531
show vlan command 2-525
show vlan command, fields 2-527
show vlan filter command 2-532
show vmps command 2-533
show vtp command 2-535
shutdown command 2-539
shutdown threshold, Layer 2 protocol tunneling 2-187
shutdown vlan command 2-540
small violation-rate command 2-541
Smartports macros
See macros
SNMP host, specifying 2-547
SNMP informs, enabling the sending of 2-543
snmp-server enable traps command 2-543
snmp-server host command 2-547
snmp trap mac-notification command 2-551
SNMP traps
enabling MAC address notification trap 2-551
enabling the MAC address notification feature 2-214
enabling the sending of 2-543
SoftPhone
See Cisco SoftPhone
software images
deleting 2-54
downloading 2-8
upgrading 2-8
uploading 2-14
software version, displaying 2-523
source ports, MVR 2-280
SPAN
configuring 2-273
debug messages, display B-19
displaying 2-488
filter SPAN traffic 2-273
sessions
add interfaces to 2-273
displaying 2-488
start new 2-273
spanning 2-591
spanning-tree backbonefast command 2-553
spanning-tree bpdufilter command 2-554
spanning-tree bpduguard command 2-556
spanning-tree cost command 2-558
spanning-tree etherchannel command 2-560
spanning-tree extend system-id command 2-562
spanning-tree guard command 2-563
spanning-tree link-type command 2-565
spanning-tree loopguard default command 2-567
spanning-tree mode command 2-569
spanning-tree mst configuration command 2-571
spanning-tree mst cost command 2-573
spanning-tree mst forward-time command 2-575
spanning-tree mst hello-time command 2-576
spanning-tree mst max-age command 2-577
spanning-tree mst max-hops command 2-578
spanning-tree mst port-priority command 2-579
spanning-tree mst pre-standard command 2-581
spanning-tree mst priority command 2-582
spanning-tree mst root command 2-583
spanning-tree portfast (global configuration) command 2-587
spanning-tree portfast (interface configuration) command 2-589
spanning-tree port-priority command 2-585
Spanning Tree Protocol
See STP
spanning-tree transmit hold-count command 2-591
spanning-tree uplinkfast command 2-592
spanning-tree vlan command 2-594
speed command 2-597
srr-queue bandwidth limit command 2-599
srr-queue bandwidth shape command 2-601
srr-queue bandwidth share command 2-603
SSH, configuring version 2-166
static-access ports, configuring 2-610
statistics, Ethernet group 2-321
sticky learning, enabling 2-627
storm-control command 2-605
STP
BackboneFast 2-553
counters, clearing 2-48
debug messages, display
BackboneFast events B-68
MSTP B-71
optimized BPDUs handling B-70
spanning-tree activity B-66
switch shim B-73
transmitted and received BPDUs B-69
UplinkFast B-75
detection of indirect link failures 2-553
enabling protocol tunneling for 2-187
EtherChannel misconfiguration 2-560
extended system ID 2-562
path cost 2-558
protocol modes 2-569
root port
accelerating choice of new 2-592
loop guard 2-563
preventing from becoming designated 2-563
restricting which can be root 2-563
root guard 2-563
UplinkFast 2-592
root switch
affects of extended system ID 2-562, 2-595
hello-time 2-594
interval between BDPU messages 2-594
interval between hello BPDU messages 2-594
max-age 2-594
port priority for selection of 2-585
primary or secondary 2-594
switch priority 2-594
state changes
blocking to forwarding state 2-589
enabling BPDU filtering 2-554, 2-587
enabling BPDU guard 2-556, 2-587
enabling Port Fast 2-587, 2-589
enabling timer to recover from error state 2-103
forward-delay time 2-594
length of listening and learning states 2-594
shutting down Port Fast-enabled ports 2-587
state information display 2-511
VLAN options 2-582, 2-594
SVIs, creating 2-115
SVI status calculation 2-612
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-608
returning to interfaces 2-608
switchport access command 2-610
switchport autostate exclude command 2-612
switchport backup interface command 2-614
switchport block command 2-618
switchport command 2-608
switchport host command 2-619
switchport mode command 2-620
switchport mode private-vlan command 2-623
switchport nonegotiate command 2-625
switchport port-security aging command 2-632
switchport port-security command 2-627
switchport priority extend command 2-634
switchport private-vlan command 2-636
switchport protected command 2-638
switchports, displaying 2-389
switchport trunk command 2-640
switchport voice vlan command 2-643
system message logging, save message to flash 2-203
system mtu command 2-645
system resource templates 2-322
T
tar files, creating, listing, and extracting 2-11
TDR, running 2-647
templates, system resources 2-322
test cable-diagnostics tdr command 2-647
traceroute mac command 2-648
traceroute mac ip command 2-651
trunking, VLAN mode 2-620
trunk mode 2-620
trunk ports 2-620
trunks, to non-DTP device 2-621
trusted boundary for QoS 2-270
trusted port states for QoS 2-270
tunnel ports, Layer 2 protocol, displaying 2-438
type (boot loader) command A-23
U
UDLD
aggressive mode 2-655, 2-657
debug messages, display B-82
enable globally 2-655
enable per interface 2-657
error recovery timer 2-103
message timer 2-655
normal mode 2-655, 2-657
reset a shutdown interface 2-659
status 2-520
udld command 2-655
udld port command 2-657
udld reset command 2-659
unicast storm control 2-605
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-618
unknown unicast traffic, preventing 2-618
unset (boot loader) command A-24
upgrading
software images 2-8
monitoring status of 2-340
UplinkFast, for STP 2-592
user EXEC mode 1-2, 1-3
V
version (boot loader) command A-26
VLAN
enabling guest VLAN supplicant 2-65, 2-76
vlan (global configuration) command 2-660
vlan (VLAN configuration) command 2-666
vlan access-map command 2-672
VLAN access map configuration mode 2-672
VLAN access maps
actions 2-6
displaying 2-531
VLAN-based QoS 2-272
VLAN configuration
rules 2-663, 2-668
saving 2-660, 2-670
VLAN configuration mode
commands
VLAN 2-666
VTP 2-689
description 1-5
entering 2-674
summary 1-2
vlan database command 2-674
vlan dot1q tag native command 2-677
vlan filter command 2-678
VLAN filters, displaying 2-532
VLAN ID range 2-660, 2-666
VLAN maps
applying 2-678
creating 2-672
defining 2-228
displaying 2-531
VLAN Query Protocol
See VQP
VLANs
adding 2-660
configuring 2-660, 2-666
debug messages, display
ISL B-79
VLAN IOS file system error tests B-78
VLAN manager activity B-76
VTP B-80
displaying configurations 2-525
enabling guest VLAN supplicant 2-108
extended-range 2-660
MAC addresses
displaying 2-472
number of 2-459
media types 2-663, 2-668
normal-range 2-660, 2-666
private 2-623
configuring 2-307
displaying 2-525
See also private VLANs
restarting 2-540
saving the configuration 2-660
shutting down 2-540
SNMP traps for VTP 2-545, 2-548
suspending 2-540
variables 2-666
VLAN Trunking Protocol
See VTP
VMPS
configuring servers 2-683
displaying 2-533
error recovery timer 2-104
reconfirming dynamic VLAN assignments 2-680
vmps reconfirm (global configuration) command 2-681
vmps reconfirm (privileged EXEC) command 2-680
vmps retry command 2-682
vmps server command 2-683
voice VLAN
configuring 2-643
setting port priority 2-634
VQP
and dynamic-access ports 2-610
clearing client statistics 2-50
displaying information 2-533
per-server retry count 2-682
reconfirmation interval 2-681
reconfirming dynamic VLAN assignments 2-680
VTP
changing characteristics 2-685
clearing pruning counters 2-51
configuring
domain name 2-685, 2-689
file name 2-685
mode 2-685, 2-689
password 2-685, 2-689
counters display fields 2-536
displaying information 2-535
enabling
pruning 2-685, 2-689
tunneling for 2-187
Version 2 2-685, 2-689
mode 2-685, 2-689
pruning 2-685, 2-689
saving the configuration 2-660, 2-670
statistics 2-535
status 2-535
status display fields 2-537
vtp (global configuration) command 2-685
vtp (VLAN configuration) command 2-689
X
XENPAK module serial EERPOM information 2-387