Table Of Contents
A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - Q - R - S - T - U - V - X -
Index
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5
AAA methods 2-3
abort command 2-659
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-113
MAC, displaying 2-444
access list, IPv6 2-166
access map configuration mode 2-224
access mode 2-605
access ports 2-605
ACEs 2-58, 2-292
ACLs
deny 2-56
displaying 2-331
for non-IP protocols 2-204
IP 2-113
matching 2-224
on Layer 2 interfaces 2-113
permit 2-290
action command 2-6
address aliasing 2-273
aggregate-port learner 2-278
allowed VLANs 2-625
apply command 2-659
archive download-sw command 2-8
archive tar command 2-11
archive upload-sw command 2-14
audience xvii
authentication failed VLAN
See dot1x auth-fail vlan
auth-fail max-attempts
See dot1x auth-fail max-attempts
auth-fail vlan
See dot1x auth-fail vlan
authorization state of controlled port 2-82
autonegotiation of duplex mode 2-92
auto qos voip command 2-16
B
BackboneFast, for STP 2-544
backup interfaces
displaying 2-382
boot (boot loader) command A-2
boot boothlpr command 2-20
boot config-file command 2-21
boot enable-break command 2-22
boot helper command 2-23
boot helper-config file command 2-24
booting
Cisco IOS image 2-27
displaying environment variables 2-339
interrupting 2-22
manually 2-25
boot loader
accessing A-1
booting
Cisco IOS image A-2
helper image 2-23
directories
creating A-15
displaying a list of A-7
removing A-19
displaying
available commands A-12
memory heap utilization A-13
version A-26
environment variables
described A-20
displaying settings A-20
location of A-21
setting A-20
unsetting A-24
files
copying A-5
deleting A-6
displaying a list of A-7
displaying the contents of A-4, A-16, A-23
renaming A-17
file system
formatting A-10
initializing flash A-9
running a consistency check A-11
resetting the system A-18
boot manual command 2-25
boot private-config-file command 2-26
boot system command 2-27
BPDU filtering, for spanning tree 2-545, 2-578
BPDU guard, for spanning tree 2-547, 2-578
break key detection 2-321, A-1
broadcast storm control 2-596
C
cat (boot loader) command A-4
caution, description xviii
CDP, enabling protocol tunneling for 2-184
channel-group command 2-28
channel-protocol command 2-31
Cisco SoftPhone
auto-QoS configuration 2-16
trusting packets sent from 2-264
class command 2-32
class-map command 2-34
class maps
creating 2-34
defining the match criteria 2-226
displaying 2-341
class of service
See CoS
clear dot1x command 2-36
clear eap sessions command 2-37
clear errdisable interface 2-38
clear ipc command 2-39
clear ip dhcp snooping database command 2-41
clear l2protocol-tunnel counters command 2-40
clear lacp command 2-43
clear mac address-table command 2-44, 2-45
clear pagp command 2-46
clear port-security command 2-47
clear spanning-tree counters command 2-49
clear spanning-tree detected-protocols command 2-50
clear vmps statistics command 2-51
clear vtp counters command 2-52
clusters
SNMP trap 2-535
command modes defined 1-1
configuration, initial
See getting started guide and hardware installation guide
configuration files
password recovery disable considerations A-1
specifying the name 2-21, 2-26
configuring multiple interfaces 2-109
config-vlan mode
commands 2-645
description 1-4
entering 2-644
summary 1-2
conventions
command xvii
for examples xviii
publication xvii
text xvii
copy (boot loader) command A-5
CoS
assigning default value to incoming packets 2-234
assigning to Layer 2 protocol packets 2-187
overriding the incoming value 2-234
CoS-to-DSCP map 2-238
CPU ASIC statistics, displaying 2-342
crashinfo files 2-102
D
debug auto qos command B-2
debug backup command B-4
debug dot1x command B-5
debug dtp command B-6
debug eap command B-7
debug etherchannel command B-8
debug interface command B-11
debug ip dhcp snooping command B-9
debug ip igmp filter command B-12
debug ip igmp max-groups command B-13
debug ip igmp snooping command B-14
debug ip verify source packet command B-10
debug lacp command B-15
debug mac-notification command B-16
debug matm command B-17
debug matm move update command B-18
debug monitor command B-19
debug mvrdbg command B-20
debug nvram command B-21
debug pagp command B-22
debug platform acl command B-23
debug platform backup interface command B-24
debug platform cli-redirection main command B-25
debug platform cpu-queues command B-26
debug platform dot1x command B-28
debug platform etherchannel command B-29
debug platform fallback-bridging command B-30
debug platform forw-tcam command B-31
debug platform ip arp inspection command B-32
debug platform ipc command B-40
debug platform ip dhcp command B-33
debug platform ip igmp snooping command B-34
debug platform ip multicast command B-36
debug platform ip unicast command B-38
debug platform led command B-41
debug platform matm command B-42
debug platform messaging application command B-43
debug platform phy command B-44
debug platform pm command B-46
debug platform port-asic command B-48
debug platform port-security command B-49
debug platform qos-acl-tcam command B-50
debug platform remote-commands command B-51
debug platform resource-manager command B-52
debug platform snmp command B-53
debug platform span command B-54
debug platform supervisor-asic command B-55
debug platform sw-bridge command B-56
debug platform tcam command B-57
debug platform udld command B-60
debug platform vlan command B-61
debug pm command B-62
debug port-security command B-64
debug qos-manager command B-65
debug spanning-tree backbonefast command B-68
debug spanning-tree bpdu command B-69
debug spanning-tree bpdu-opt command B-70
debug spanning-tree command B-66
debug spanning-tree mstp command B-71
debug spanning-tree switch command B-73
debug spanning-tree uplinkfast command B-75
debug sw-vlan command B-76
debug sw-vlan ifs command B-78
debug sw-vlan notification command B-79
debug sw-vlan vtp command B-80
debug udld command B-82
debug vqpc command B-84
define interface-range command 2-53
delete (boot loader) command A-6
delete command 2-55
deny command 2-56
detect mechanism, causes 2-93
device manager requirements xviii
DHCP snooping
accepting untrusted packets from edge switch 2-128
enabling
on a VLAN 2-135
option 82 2-126, 2-128
trust on an interface 2-133
error recovery timer 2-99
rate limiting 2-132
DHCP snooping binding database
binding file, configuring 2-124
bindings
adding 2-122
deleting 2-122
displaying 2-396
clearing database agent statistics 2-41
database agent, configuring 2-124
displaying
binding entries 2-396
database agent status 2-398, 2-400
renewing 2-316
dir (boot loader) command A-7
directories, deleting 2-55
documentation, related xviii
document conventions xvii
domain name, VTP 2-670, 2-674
dot1x auth-fail max-attempts 2-61
dot1x auth-fail vlan 2-63
dot1x command 2-59
dot1x control-direction command 2-65
dot1x critical global configuration command 2-67
dot1x critical interface configuration command 2-69
dot1x default command 2-71
dot1x fallback command 2-72
dot1x guest-vlan command 2-73
dot1x host-mode command 2-75
dot1x initialize command 2-76
dot1x mac-auth-bypass command 2-77
dot1x max-reauth-req command 2-79
dot1x max-req command 2-80
dot1x pae command 2-81
dot1x port-control command 2-82
dot1x re-authenticate command 2-84
dot1x reauthentication command 2-85
dot1x test eapol-capable command 2-86
dot1x test timeout command 2-87
dot1x timeout command 2-88
dropping packets, with ACL matches 2-6
drop threshold, Layer 2 protocol tunneling 2-184
DSCP-to-CoS map 2-238
DSCP-to-DSCP-mutation map 2-238
DTP 2-606
DTP flap
error detection for 2-93
error recovery timer 2-99
DTP negotiation 2-610
dual IPv4 and IPv6 templates 2-284
duplex command 2-91
dynamic-access ports
configuring 2-601
restrictions 2-601
dynamic ARP inspection
ARP ACLs
permit packets 2-282
error detection for 2-93
dynamic auto VLAN membership mode 2-605
dynamic desirable VLAN membership mode 2-605
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-80
response time before retransmitting 2-88
encapsulation methods 2-625
environment variables, displaying 2-339
errdisable detect cause command 2-93
errdisable detect cause small-frame comand 2-96
errdisable recovery cause small-frame 2-98
errdisable recovery command 2-99
error conditions, displaying 2-368
error disable detection 2-93
error-disabled interfaces, displaying 2-382
EtherChannel
assigning Ethernet interface to channel group 2-28
creating port-channel logical interface 2-107
debug EtherChannel/PAgP, display B-8
debug platform-specific events, display B-29
displaying 2-372
enabling Layer 2 protocol tunneling for
LACP 2-185
PAgP 2-185
UDLD 2-185
interface information, displaying 2-382
LACP
clearing channel-group information 2-43
debug messages, display B-15
displaying 2-434
modes 2-28
port priority for hot-standby ports 2-188
restricting a protocol 2-31
system priority 2-190
load-distribution methods 2-300
PAgP
aggregate-port learner 2-278
clearing channel-group information 2-46
debug messages, display B-22
displaying 2-489
error detection for 2-93
error recovery timer 2-99
learn method 2-278
modes 2-28
physical-port learner 2-278
priority of interface for transmitted traffic 2-280
Ethernet controller, internal register display 2-344
Ethernet statistics, collecting 2-317
examples, conventions for xviii
exception crashinfo command 2-102
exit command 2-659
extended-range VLANs
and allowed VLAN list 2-625
and pruning-eligible list 2-625
configuring 2-644
extended system ID for STP 2-553
F
fallback profile command 2-103
fallback profiles
displaying 2-375
file name, VTP 2-670
files, deleting 2-55
flash_init (boot loader) command A-9
Flex Links
displaying 2-382
flowcontrol command 2-105
format (boot loader) command A-10
forwarding packets, with ACL matches 2-6
forwarding results, display C-6
frame forwarding information, displaying C-6
fsck (boot loader) command A-11
G
global configuration mode 1-2, 1-3
H
hardware ACL statistics 2-331
help (boot loader) command A-12
hierarchical policy maps 2-298
host connection, port configuration 2-604
host ports, private VLANs 2-608
I
IEEE 802.1Q trunk ports and native VLANs 2-661
IEEE 802.1Q tunnel ports
configuring 2-605
displaying 2-355
limitations 2-606
IEEE 802.1x
and switchport modes 2-606
violation error recovery 2-99
See also port-based authentication
IEEE 802.1X Port Based Authentication
enabling guest VLAN supplicant 2-62, 2-72, 2-104
IGMP filters
applying 2-138
debug messages, display B-12
IGMP groups, setting maximum 2-140
IGMP maximum groups, debugging B-13
IGMP profiles
creating 2-142
displaying 2-403
IGMP snooping
adding ports as a static member of a group 2-158
displaying 2-404, 2-409, 2-411
enabling 2-144
enabling the configurable-leave timer 2-146
enabling the Immediate-Leave feature 2-155
flooding query count 2-152
interface topology change notification behavior 2-154
multicast table 2-407
querier 2-148
query solicitation 2-152
report suppression 2-150
switch topology change notification behavior 2-152
images
See software images
Immediate-Leave feature, MVR 2-275
Immediate-Leave processing
IPv6 2-180
immediate-leave processing 2-155
initial configuration
See getting started guide and hardware installation guide
interface configuration mode 1-2, 1-4
interface port-channel command 2-107
interface range command 2-109
interface-range macros 2-53
interfaces
assigning Ethernet interface to channel group 2-28
configuring 2-91
configuring multiple 2-109
creating port-channel logical 2-107
debug messages, display B-11
disabling 2-531
displaying the MAC address table 2-456
restarting 2-531
interface speed, configuring 2-588
interface vlan command 2-111
internal registers, displaying 2-344, 2-351
Internet Group Management Protocol
See IGMP
invalid GBIC
error detection for 2-93
error recovery timer 2-99
ip access-group command 2-113
ip address command 2-116
IP addresses, setting 2-116
IP address matching 2-224
ip admission command 2-118
ip admission name proxy http command 2-119
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-122
ip dhcp snooping command 2-121
ip dhcp snooping database command 2-124
ip dhcp snooping information option allow-untrusted command 2-128
ip dhcp snooping information option command 2-126
ip dhcp snooping information option format remote-id command 2-130
ip dhcp snooping limit rate command 2-132
ip dhcp snooping trust command 2-133
ip dhcp snooping verify command 2-134
ip dhcp snooping vlan command 2-135
ip dhcp snooping vlan information option format-type circuit-id string command 2-136
ip igmp filter command 2-138
ip igmp max-groups command 2-140
ip igmp profile command 2-142
ip igmp snooping command 2-144
ip igmp snooping last-member-query-interval command 2-146
ip igmp snooping querier command 2-148
ip igmp snooping report-suppression command 2-150
ip igmp snooping tcn command 2-152
ip igmp snooping tcn flood command 2-154
ip igmp snooping vlan immediate-leave command 2-155
ip igmp snooping vlan mrouter command 2-156
ip igmp snooping vlan static command 2-158
IP multicast addresses 2-272
IP phones
auto-QoS configuration 2-16
trusting packets sent from 2-264
IP-precedence-to-DSCP map 2-238
ip snap forwarding command 2-160
ip source binding command 2-161
IP source guard
disabling 2-165
displaying
binding entries 2-413
configuration 2-415
dynamic binding entries only 2-396
enabling 2-165
static IP source bindings 2-161
ip ssh command 2-163
ipv6 access-list command 2-166
ipv6 mld snooping command 2-168
ipv6 mld snooping last-listener-query count command 2-170
ipv6 mld snooping last-listener-query-interval command 2-172
ipv6 mld snooping listener-message-suppression command 2-174
ipv6 mld snooping robustness-variable command 2-176
ipv6 mld snooping tcn command 2-178
ipv6 mld snooping vlan command 2-180
IPv6 SDM template 2-318
ipv6 traffic-filter command 2-182
ip verify source command 2-165
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-184
l2protocol-tunnel cos command 2-187
LACP
See EtherChannel
lacp port-priority command 2-188
lacp system-priority command 2-190
Layer 2 mode, enabling 2-599
Layer 2 protocol ports, displaying 2-431
Layer 2 protocol-tunnel
error detection for 2-93
error recovery timer 2-99
Layer 2 protocol tunnel counters 2-40
Layer 2 protocol tunneling error recovery 2-185
Layer 2 traceroute
IP addresses 2-635
MAC addresses 2-632
Layer 3 mode, enabling 2-599
line configuration mode 1-2, 1-5
Link Aggregation Control Protocol
See EtherChannel
link flap
error detection for 2-93
error recovery timer 2-99
link state group command 2-196
link state track command 2-198
load-distribution methods for EtherChannel 2-300
location (global configuration) command 2-192
location (interface configuration) command 2-194
logging event command 2-199
logging file command 2-200
logical interface 2-107
loopback error
detection for 2-93
recovery timer 2-99
loop guard, for spanning tree 2-554, 2-558
M
mac access-group command 2-202
MAC access-groups, displaying 2-444
MAC access list configuration mode 2-204
mac access-list extended command 2-204
MAC access lists 2-56
MAC addresses
displaying
aging time 2-450
all 2-448
dynamic 2-454
MAC address-table move updates 2-458
notification settings 2-460
number of addresses in a VLAN 2-452
per interface 2-456
per VLAN 2-464
static 2-462
static and dynamic entries 2-446
dynamic
aging time 2-206
deleting 2-44
displaying 2-454
enabling MAC address notification 2-209
enabling MAC address-table move update 2-207
matching 2-224
static
adding and removing 2-211
displaying 2-462
dropping on an interface 2-212
tables 2-448
mac address notification, debugging B-16
mac address-table aging-time 2-202, 2-224
mac address-table aging-time command 2-206
mac address-table move update command 2-207
mac address-table notification command 2-209
mac address-table static command 2-211
mac address-table static drop command 2-212
macro apply command 2-214
macro description command 2-217
macro global command 2-218
macro global description command 2-221
macro name command 2-222
macros
adding a description 2-217
adding a global description 2-221
applying 2-218
creating 2-222
displaying 2-491
interface range 2-53, 2-109
specifying parameter values 2-218
tracing 2-218
manual
audience xvii
purpose of xvii
maps
QoS
defining 2-238
displaying 2-474
VLAN
creating 2-656
defining 2-224
displaying 2-522
match (access-map configuration) command 2-224
match (class-map configuration) command 2-226
maximum transmission unit
See MTU
mdix auto command 2-228
MDL snooping
displaying 2-425
memory (boot loader) command A-13
mkdir (boot loader) command A-15
MLD snooping
configuring 2-174, 2-176
configuring queries 2-170, 2-172
configuring topology change notification 2-178
displaying 2-423, 2-427, 2-429
enabling 2-168
MLD snooping on a VLAN
enabling 2-180
mls qos aggregate-policer command 2-232
mls qos command 2-230
mls qos cos command 2-234
mls qos dscp-mutation command 2-236
mls qos map command 2-238
mls qos queue-set output buffers command 2-242
mls qos queue-set output threshold command 2-244
mls qos rewrite ip dscp command 2-246
mls qos srr-queue input bandwidth command 2-248
mls qos srr-queue input buffers command 2-250
mls qos-srr-queue input cos-map command 2-252
mls qos srr-queue input dscp-map command 2-254
mls qos srr-queue input priority-queue command 2-256
mls qos srr-queue input threshold command 2-258
mls qos-srr-queue output cos-map command 2-260
mls qos srr-queue output dscp-map command 2-262
mls qos trust command 2-264
mls qos vlan-based command 2-266
mode, MVR 2-272
Mode button, and password recovery 2-321
modes, commands 1-1
monitor session command 2-267
more (boot loader) command A-16
MSTP
displaying 2-503
interoperability 2-50
link type 2-556
MST region
aborting changes 2-562
applying changes 2-562
configuration name 2-562
configuration revision number 2-562
current or pending display 2-562
displaying 2-503
MST configuration mode 2-562
VLANs-to-instance mapping 2-562
path cost 2-564
protocol mode 2-560
restart protocol migration process 2-50
root port
loop guard 2-554
preventing from becoming designated 2-554
restricting which can be root 2-554
root guard 2-554
root switch
affects of extended system ID 2-553
hello-time 2-567, 2-574
interval between BDPU messages 2-568
interval between hello BPDU messages 2-567, 2-574
max-age 2-568
maximum hop count before discarding BPDU 2-569
port priority for selection of 2-570
primary or secondary 2-574
switch priority 2-573
state changes
blocking to forwarding state 2-580
enabling BPDU filtering 2-545, 2-578
enabling BPDU guard 2-547, 2-578
enabling Port Fast 2-578, 2-580
forward-delay time 2-566
length of listening and learning states 2-566
rapid transition to forwarding 2-556
shutting down Port Fast-enabled ports 2-578
state information display 2-502
MTU
configuring size 2-630
displaying global setting 2-510
Multicase Listener Discovery
See MLD
multicast group address, MVR 2-275
multicast groups, MVR 2-273
Multicast Listener Discovery
See MLD
multicast router learning method 2-156
multicast router ports
IPv6 2-180
multicast router ports, configuring 2-156
multicast storm control 2-596
multicast VLAN, MVR 2-272
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-75
Multiple Spanning Tree Protocol
See MSTP
MVR
and address aliasing 2-273
configuring 2-272
configuring interfaces 2-275
debug messages, display B-20
displaying 2-483
displaying interface information 2-485
members, displaying 2-487
mvr (global configuration) command 2-272
mvr (interface configuration) command 2-275
mvr vlan group command 2-276
N
native VLANs 2-625
native VLAN tagging 2-661
nonegotiate
DTP messaging 2-610
nonegotiate, speed 2-588
non-IP protocols
denying 2-56
forwarding 2-290
non-IP traffic access lists 2-204
non-IP traffic forwarding
denying 2-56
permitting 2-290
normal-range VLANs 2-644, 2-650
note, description xviii
no vlan command 2-644, 2-654
O
online diagnostics
displaying
configured boot-up coverage level 2-355
current scheduled tasks 2-355
event logs 2-355
supported test suites 2-355
test ID 2-355
test results 2-355
test statistics 2-355
P
PAgP
See EtherChannel
pagp learn-method command 2-278
pagp port-priority command 2-280
password, VTP 2-670, 2-674
password-recovery mechanism, enabling and disabling 2-321
permit (ARP access-list configuration) command 2-282
permit (IPv6) command 2-284
permit (MAC access-list configuration) command 2-290
per-VLAN spanning-tree plus
See STP
physical-port learner 2-278
PID, displaying 2-393
PIM-DVMRP, as multicast router learning method 2-156
police aggregate command 2-295
police command 2-293
policed-DSCP map 2-238
policy-map command 2-297
policy maps
applying to an interface 2-323, 2-328
creating 2-297
displaying 2-494
hierarchical 2-298
policers
displaying 2-467
for a single class 2-293
for multiple classes 2-232, 2-295
policed-DSCP map 2-238
traffic classification
defining the class 2-32
defining trust states 2-637
setting DSCP or IP precedence values 2-326
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
debug messages, display B-5
enabling IEEE 802.1x
globally 2-59
per interface 2-82
guest VLAN 2-73
host modes 2-75
IEEE 802.1x AAA accounting methods 2-1
initialize an interface 2-76, 2-87
MAC authentication bypass 2-77
manual control of authorization state 2-82
multiple hosts on authorized port 2-75
PAE as authenticator 2-81
periodic re-authentication
enabling 2-85
time between attempts 2-88
quiet period between failed authentication exchanges 2-88
re-authenticating IEEE 802.1x-enabled ports 2-84
resetting configurable IEEE 802.1x parameters 2-71
switch-to-authentication server retransmission time 2-88
switch-to-client frame-retransmission number2-79to 2-80
switch-to-client retransmission time 2-88
test for IEEE 802.1x readiness 2-86
port-channel load-balance command 2-300
Port Fast, for spanning tree 2-580
port ranges, defining 2-53
ports, debugging B-62
ports, protected 2-623
port security
aging 2-617
debug messages, display B-64
enabling 2-612
violation error recovery 2-99
port trust states for QoS 2-264
port types, MVR 2-275
priority-queue command 2-302
private-vlan command 2-304
private-vlan mapping command 2-307
private VLANs
association 2-621
configuring 2-304
configuring ports 2-608
displaying 2-516
host ports 2-608
mapping
configuring 2-621
displaying 2-382
promiscuous ports 2-608
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-393
promiscuous ports, private VLANs 2-608
protected ports, displaying 2-388
pruning
VLANs 2-625
VTP
displaying interface information 2-382
enabling 2-670, 2-674
pruning-eligible VLAN list 2-627
PVST+
See STP
Q
QoS
auto-QoS
configuring 2-16
debug messages, display B-2
displaying 2-335
class maps
creating 2-34
defining the match criteria 2-226
displaying 2-341
defining the CoS value for an incoming packet 2-234
displaying configuration information 2-335, 2-466
DSCP transparency 2-246
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-236
defining DSCP-to-DSCP-mutation map 2-238
egress queues
allocating buffers 2-242
defining the CoS output queue threshold map 2-260
defining the DSCP output queue threshold map 2-262
displaying buffer allocations 2-470
displaying CoS output queue threshold map 2-474
displaying DSCP output queue threshold map 2-474
displaying queueing strategy 2-470
displaying queue-set settings 2-477
enabling bandwidth shaping and scheduling 2-592
enabling bandwidth sharing and scheduling 2-594
limiting the maximum output on a port 2-590
mapping a port to a queue-set 2-309
mapping CoS values to a queue and threshold 2-260
mapping DSCP values to a queue and threshold 2-262
setting maximum and reserved memory allocations 2-244
setting WTD thresholds 2-244
enabling 2-230
ingress queues
allocating buffers 2-250
assigning SRR scheduling weights 2-248
defining the CoS input queue threshold map 2-252
defining the DSCP input queue threshold map 2-254
displaying buffer allocations 2-470
displaying CoS input queue threshold map 2-474
displaying DSCP input queue threshold map 2-474
displaying queueing strategy 2-470
displaying settings for 2-468
enabling the priority queue 2-256
mapping CoS values to a queue and threshold 2-252
mapping DSCP values to a queue and threshold 2-254
setting WTD thresholds 2-258
maps
defining 2-238, 2-252, 2-254, 2-260, 2-262
displaying 2-474
policy maps
applying an aggregate policer 2-295
applying to an interface 2-323, 2-328
creating 2-297
defining policers 2-232, 2-293
displaying policers 2-467
displaying policy maps 2-494
hierarchical 2-298
policed-DSCP map 2-238
setting DSCP or IP precedence values 2-326
traffic classifications 2-32
trust states 2-637
port trust states 2-264
queues, enabling the expedite 2-302
statistics
in-profile and out-of-profile packets 2-470
packets enqueued or dropped 2-470
sent and received CoS values 2-470
sent and received DSCP values 2-470
trusted boundary for IP phones 2-264
VLAN-based 2-266
quality of service
See QoS
querytime, MVR 2-272
queue-set command 2-309
R
radius-server dead-criteria command 2-310
radius-server host command 2-312
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
re-authenticating IEEE 802.1x-enabled ports 2-84
re-authentication
periodic 2-85
time between attempts 2-88
receiver ports, MVR 2-275
receiving flow-control packets 2-105
recovery mechanism
causes 2-99
display 2-38, 2-366, 2-370
timer interval 2-100
remote-span command 2-314
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-17
renew ip dhcp snooping database command 2-316
requirements
device manager xviii
reset (boot loader) command A-18
reset command 2-659
resource templates, displaying 2-499
restricted VLAN
See dot1x auth-fail vlan
rmdir (boot loader) command A-19
rmon collection stats command 2-317
root guard, for spanning tree 2-554
routed ports
IP addresses on 2-117
number supported 2-117
RSPAN
configuring 2-267
displaying 2-480
filter RSPAN traffic 2-267
remote-span command 2-314
sessions
add interfaces to 2-267
displaying 2-480
start new 2-267
S
sdm prefer command 2-318
SDM templates
allowed resources 2-319
displaying 2-499
dual IPv4 and IPv6 2-318
secure ports, limitations 2-614
sending flow-control packets 2-105
service password-recovery command 2-321
service-policy command 2-323
set (boot loader) command A-20
set command 2-326
setup command 2-328
show access-lists command 2-331
show archive status command 2-334
show auto qos command 2-335
show boot command 2-339
show changes command 2-659
show class-map command 2-341
show controllers cpu-interface command 2-342
show controllers ethernet-controller command 2-344
show controllers tcam command 2-351
show controller utilization command 2-353
show current command 2-659
show dot1q-tunnel command 2-355
show dot1x command 2-356
show dtp 2-360
show eap command 2-362
show env command 2-365
show errdisable detect command 2-366
show errdisable flap-values command 2-368
show errdisable recovery command 2-370
show etherchannel command 2-372
show fallback profile command 2-375
show flowcontrol command 2-377
show idprom command 2-379
show interfaces command 2-382
show interfaces counters command 2-390
show inventory command 2-393
show ipc command 2-417
show ip dhcp snooping binding command 2-396
show ip dhcp snooping command 2-395
show ip dhcp snooping database command 2-398, 2-400
show ip igmp profile command 2-403
show ip igmp snooping address command 2-425
show ip igmp snooping command 2-404, 2-423
show ip igmp snooping groups command 2-407
show ip igmp snooping mrouter command 2-409, 2-427
show ip igmp snooping querier command 2-411, 2-429
show ip source binding command 2-413
show ipv6 access-list command 2-421
show ip verify source command 2-415
show l2protocol-tunnel command 2-431
show lacp command 2-434
show link state group command 2-440, 2-442
show location 2-438
show mac access-group command 2-444
show mac address-table address command 2-448
show mac address-table aging time command 2-450
show mac address-table command 2-446
show mac address-table count command 2-452
show mac address-table dynamic command 2-454
show mac address-table interface command 2-456
show mac address-table move update command 2-458
show mac address-table notification command 2-45, 2-460, B-18
show mac address-table static command 2-462
show mac address-table vlan command 2-464
show mls qos aggregate-policer command 2-467
show mls qos command 2-466
show mls qos input-queue command 2-468
show mls qos interface command 2-470
show mls qos maps command 2-474
show mls qos queue-set command 2-477
show mls qos vlan command 2-479
show monitor command 2-480
show mvr command 2-483
show mvr interface command 2-485
show mvr members command 2-487
show pagp command 2-489
show parser macro command 2-491
show platform acl command C-2
show platform backup interface command C-3
show platform configuration command C-4
show platform etherchannel command C-5
show platform forward command C-6
show platform igmp snooping command C-8
show platform ipc trace command C-15
show platform ip multicast command C-10
show platform ip unicast command C-11
show platform ipv6 unicast command C-16
show platform layer4op command C-18
show platform mac-address-table command C-19
show platform messaging command C-20
show platform monitor command C-21
show platform mvr table command C-22
show platform pm command C-23
show platform port-asic command C-24
show platform port-security command C-30
show platform qos command C-31
show platform resource-manager command C-32
show platform snmp counters command C-34
show platform spanning-tree command C-35
show platform stp-instance command C-36
show platform tcam command C-37
show platform vlan command C-40
show policy-map command 2-494
show port security command 2-496
show proposed command 2-659
show sdm prefer command 2-499
show spanning-tree command 2-502
show storm-control command 2-508
show system mtu command 2-510
show trust command 2-637
show udld command 2-511
show version command 2-514
show vlan access-map command 2-522
show vlan command 2-516
show vlan command, fields 2-518
show vlan filter command 2-523
show vmps command 2-524
show vtp command 2-527
shutdown command 2-531
shutdown threshold, Layer 2 protocol tunneling 2-184
shutdown vlan command 2-532
small violation-rate command 2-533
Smartports macros
See macros
SNMP host, specifying 2-538
SNMP informs, enabling the sending of 2-535
snmp-server enable traps command 2-535
snmp-server host command 2-538
snmp trap mac-notification command 2-542
SNMP traps
enabling MAC address notification trap 2-542
enabling the MAC address notification feature 2-209
enabling the sending of 2-535
SoftPhone
See Cisco SoftPhone
software images
deleting 2-55
downloading 2-8
upgrading 2-8
uploading 2-14
software version, displaying 2-514
source ports, MVR 2-275
SPAN
configuring 2-267
debug messages, display B-19
displaying 2-480
filter SPAN traffic 2-267
sessions
add interfaces to 2-267
displaying 2-480
start new 2-267
spanning 2-582
spanning-tree backbonefast command 2-544
spanning-tree bpdufilter command 2-545
spanning-tree bpduguard command 2-547
spanning-tree cost command 2-549
spanning-tree etherchannel command 2-551
spanning-tree extend system-id command 2-553
spanning-tree guard command 2-554
spanning-tree link-type command 2-556
spanning-tree loopguard default command 2-558
spanning-tree mode command 2-560
spanning-tree mst configuration command 2-562
spanning-tree mst cost command 2-564
spanning-tree mst forward-time command 2-566
spanning-tree mst hello-time command 2-567
spanning-tree mst max-age command 2-568
spanning-tree mst max-hops command 2-569
spanning-tree mst port-priority command 2-570
spanning-tree mst pre-standard command 2-572
spanning-tree mst priority command 2-573
spanning-tree mst root command 2-574
spanning-tree portfast (global configuration) command 2-578
spanning-tree portfast (interface configuration) command 2-580
spanning-tree port-priority command 2-576
Spanning Tree Protocol
See STP
spanning-tree transmit hold-count command 2-582
spanning-tree uplinkfast command 2-583
spanning-tree vlan command 2-585
speed command 2-588
srr-queue bandwidth limit command 2-590
srr-queue bandwidth shape command 2-592
srr-queue bandwidth share command 2-594
SSH, configuring version 2-163
static-access ports, configuring 2-601
statistics, Ethernet group 2-317
sticky learning, enabling 2-612
storm-control command 2-596
STP
BackboneFast 2-544
counters, clearing 2-49
debug messages, display
BackboneFast events B-68
MSTP B-71
optimized BPDUs handling B-70
spanning-tree activity B-66
switch shim B-73
transmitted and received BPDUs B-69
UplinkFast B-75
detection of indirect link failures 2-544
enabling protocol tunneling for 2-184
EtherChannel misconfiguration 2-551
extended system ID 2-553
path cost 2-549
protocol modes 2-560
root port
accelerating choice of new 2-583
loop guard 2-554
preventing from becoming designated 2-554
restricting which can be root 2-554
root guard 2-554
UplinkFast 2-583
root switch
affects of extended system ID 2-553, 2-586
hello-time 2-585
interval between BDPU messages 2-585
interval between hello BPDU messages 2-585
max-age 2-585
port priority for selection of 2-576
primary or secondary 2-585
switch priority 2-585
state changes
blocking to forwarding state 2-580
enabling BPDU filtering 2-545, 2-578
enabling BPDU guard 2-547, 2-578
enabling Port Fast 2-578, 2-580
enabling timer to recover from error state 2-99
forward-delay time 2-585
length of listening and learning states 2-585
shutting down Port Fast-enabled ports 2-578
state information display 2-502
VLAN options 2-573, 2-585
SVIs, creating 2-111
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-599
returning to interfaces 2-599
switchport access command 2-601
switchport block command 2-603
switchport command 2-599
switchport host command 2-604
switchport mode command 2-605
switchport mode private-vlan command 2-608
switchport nonegotiate command 2-610
switchport port-security aging command 2-617
switchport port-security command 2-612
switchport priority extend command 2-619
switchport private-vlan command 2-621
switchport protected command 2-623
switchports, displaying 2-382
switchport trunk command 2-625
switchport voice vlan command 2-628
system message logging, save message to flash 2-200
system mtu command 2-630
system resource templates 2-318
T
tar files, creating, listing, and extracting 2-11
templates, system resources 2-318
traceroute mac command 2-632
traceroute mac ip command 2-635
trunking, VLAN mode 2-605
trunk mode 2-605
trunk ports 2-605
trunks, to non-DTP device 2-606
trusted boundary for QoS 2-264
trusted port states for QoS 2-264
tunnel ports, Layer 2 protocol, displaying 2-431
type (boot loader) command A-23
U
UDLD
aggressive mode 2-639, 2-641
debug messages, display B-82
enable globally 2-639
enable per interface 2-641
error recovery timer 2-99
message timer 2-639
normal mode 2-639, 2-641
reset a shutdown interface 2-643
status 2-511
udld command 2-639
udld port command 2-641
udld reset command 2-643
unicast storm control 2-596
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-603
unknown unicast traffic, preventing 2-603
unset (boot loader) command A-24
upgrading
software images 2-8
monitoring status of 2-334
upgrading information
See release notes
UplinkFast, for STP 2-583
user EXEC mode 1-2, 1-3
V
version (boot loader) command A-26
VLAN
enabling guest VLAN supplicant 2-62, 2-72
vlan (global configuration) command 2-644
vlan (VLAN configuration) command 2-650
vlan access-map command 2-656
VLAN access map configuration mode 2-656
VLAN access maps
actions 2-6
displaying 2-522
VLAN-based QoS 2-266
VLAN configuration
rules 2-647, 2-652
saving 2-644, 2-654
VLAN configuration mode
commands
VLAN 2-650
VTP 2-674
description 1-5
entering 2-658
summary 1-2
vlan database command 2-658
vlan dot1q tag native command 2-661
vlan filter command 2-663
VLAN filters, displaying 2-523
VLAN ID range 2-644, 2-650
VLAN maps
applying 2-663
creating 2-656
defining 2-224
displaying 2-522
VLAN Query Protocol
See VQP
VLANs
adding 2-644
configuring 2-644, 2-650
debug messages, display
ISL B-79
VLAN IOS file system error tests B-78
VLAN manager activity B-76
VTP B-80
displaying configurations 2-516
enabling guest VLAN supplicant 2-104
extended-range 2-644
MAC addresses
displaying 2-464
number of 2-452
media types 2-647, 2-652
normal-range 2-644, 2-650
private 2-608
configuring 2-304
displaying 2-516
See also private VLANs
restarting 2-532
saving the configuration 2-644
shutting down 2-532
SNMP traps for VTP 2-536, 2-539
suspending 2-532
variables 2-650
VLAN Trunking Protocol
See VTP
VMPS
configuring servers 2-668
displaying 2-524
error recovery timer 2-100
reconfirming dynamic VLAN assignments 2-665
vmps reconfirm (global configuration) command 2-666
vmps reconfirm (privileged EXEC) command 2-665
vmps retry command 2-667
vmps server command 2-668
voice VLAN
configuring 2-628
setting port priority 2-619
VQP
and dynamic-access ports 2-601
clearing client statistics 2-51
displaying information 2-524
per-server retry count 2-667
reconfirmation interval 2-666
reconfirming dynamic VLAN assignments 2-665
VTP
changing characteristics 2-670
clearing pruning counters 2-52
configuring
domain name 2-670, 2-674
file name 2-670
mode 2-670, 2-674
password 2-670, 2-674
counters display fields 2-528
displaying information 2-527
enabling
pruning 2-670, 2-674
tunneling for 2-184
Version 2 2-670, 2-674
mode 2-670, 2-674
pruning 2-670, 2-674
saving the configuration 2-644, 2-654
statistics 2-527
status 2-527
status display fields 2-529
vtp (global configuration) command 2-670
vtp (VLAN configuration) command 2-674
X
XENPAK module serial EERPOM information 2-379