Table Of Contents
A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - Q - R - S - T - U - V - X -
Index
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5, 2-18, 2-24, 2-26, 2-28, 2-30, 2-32, 2-124, 2-446, B-30
AAA methods 2-3
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-175
MAC, displaying 2-546
access list, IPv6 2-249
access map configuration mode 2-310
access ports 2-711
ACEs 2-110, 2-389
ACLs
deny 2-108
displaying 2-431
for non-IP protocols 2-289
IP 2-175
matching 2-310
on Layer 2 interfaces 2-175
permit 2-387
action command 2-6
address aliasing 2-359
archive download-sw command 2-8
archive tar command 2-11
archive upload-sw command 2-14
authentication command bounce-port ignore 2-16
authentication command disable-port ignore 2-17
authentication control-direction command 2-18
authentication event command 2-20
authentication failed VLAN
See dot1x auth-fail vlan
authentication fallback command 2-24
authentication host-mode command 2-26
authentication mac-move permit command 2-28
authentication open command 2-30
authentication order command 2-32
authentication periodic command 2-34
authentication port-control command 2-36
authentication priority command 2-38
authentication timer command 2-40
authentication violation command 2-42
auth-fail max-attempts
See dot1x auth-fail max-attempts
auth-fail vlan
See dot1x auth-fail vlan
auth open command 2-30
auth order command 2-32
authorization state of controlled port 2-142
auth timer command 2-40
autonegotiation of duplex mode 2-153
auto qos classify command 2-44
auto qos trust command 2-47
auto qos video command 2-50
auto qos voip command 2-53
B
BackboneFast, for STP 2-643
backup interfaces
configuring 2-704
boot (boot loader) command A-2
boot config-file command 2-59
boot enable-break command 2-60
boot helper command 2-61
boot helper-config file command 2-62
booting
Cisco IOS image 2-65
displaying environment variables 2-444
interrupting 2-60
manually 2-63
boot loader
accessing A-1
booting
Cisco IOS image A-2
helper image 2-61
directories
creating A-15
displaying a list of A-7
removing A-19
displaying
available commands A-12
memory heap utilization A-13
version A-26
environment variables
displaying settings A-20
location of A-21
setting A-20
unsetting A-24
files
copying A-5
deleting A-6
displaying a list of A-7
displaying the contents of A-4, A-16, A-23
renaming A-17
file system
formatting A-10
initializing flash A-9
running a consistency check A-11
resetting the system A-18
boot manual command 2-63
boot private-config-file command 2-64
boot system command 2-65
BPDU filtering, for spanning tree 2-644, 2-677
BPDU guard, for spanning tree 2-646, 2-677
break key detection 2-421, A-1
broadcast storm control 2-695
C
cat (boot loader) command A-4
CDP, enabling protocol tunneling for 2-267
channel-group command 2-66
channel-protocol command 2-69
CISP
See Client Information Signalling Protocol
cisp
debug platform cisp command B-30
cisp enable command 2-70
class command 2-71
class-map command 2-74
class maps
creating 2-74
defining the match criteria 2-312
displaying 2-447
class of service
See CoS
clear dot1x command 2-76
clear eap sessions command 2-77
clear errdisable interface 2-78
clear ip arp inspection log command 2-79
clear ip arp inspection statistics command 2-80
clear ipc command 2-82
clear ip dhcp snooping database command 2-81, 2-84
clear l2protocol-tunnel counters command 2-83
clear lacp command 2-86
clear mac address-table command 2-87, 2-88
clear nmsp statistics command 2-89
clear pagp command 2-90
clear port-security command 2-91
clear psp counter 2-93
clear psp counter command 2-93
clear spanning-tree counters command 2-94
clear spanning-tree detected-protocols command 2-95
clear vmps statistics command 2-96
clear vtp counters command 2-97
Client Information Signalling Protocol 2-70, 2-124, 2-446, B-7, B-30
clusters
displaying
status 2-448
command modes defined 1-1
configuration files
password recovery disable considerations A-1
specifying the name 2-59, 2-64
configuring multiple interfaces 2-171
config-vlan mode
commands 2-751
entering 2-750
copy (boot loader) command A-5
CoS
assigning default value to incoming packets 2-320
assigning to Layer 2 protocol packets 2-270
overriding the incoming value 2-320
CPU ASIC statistics, displaying 2-450
crashinfo files 2-164
D
debug authentication B-2
debug auto qos command B-4
debug backup command B-6
debug cisp command B-7
debug dot1x command B-8
debug dtp command B-9
debug eap command B-10
debug etherchannel command B-11
debug interface command B-14
debug ip dhcp snooping command B-12
debug ip igmp filter command B-15
debug ip igmp max-groups command B-16
debug ip igmp snooping command B-17
debug ip verify source packet command B-13
debug lacp command B-18
debug lldp packets command B-19
debug mac-notification command B-20
debug matm command B-21
debug matm move update command B-22
debug monitor command B-23
debug mvrdbg command B-24
debug nmsp command B-25
debug nvram command B-26
debug pagp command B-27
debug platform acl command B-28
debug platform backup interface command B-29
debug platform cisp command B-30
debug platform cli-redirection main command B-31
debug platform cpu-queues command B-32
debug platform dot1x command B-34
debug platform etherchannel command B-35
debug platform fallback-bridging command B-36
debug platform forw-tcam command B-37
debug platform ip arp inspection command B-38
debug platform ipc command B-46
debug platform ip dhcp command B-39
debug platform ip igmp snooping command B-40
debug platform ip multicast command B-42
debug platform ip unicast command B-44
debug platform led command B-47
debug platform matm command B-48
debug platform messaging application command B-49
debug platform phy command B-50
debug platform pm command B-52
debug platform port-asic command B-54
debug platform port-security command B-55
debug platform qos-acl-tcam command B-56
debug platform remote-commands command B-57
debug platform resource-manager command B-58
debug platform snmp command B-59
debug platform span command B-60
debug platform supervisor-asic command B-61
debug platform sw-bridge command B-62
debug platform tcam command B-63
debug platform udld command B-66
debug platform vlan command B-67
debug pm command B-68
debug port-security command B-70
debug qos-manager command B-71
debug spanning-tree backbonefast command B-74
debug spanning-tree bpdu command B-75
debug spanning-tree bpdu-opt command B-76
debug spanning-tree command B-72
debug spanning-tree mstp command B-77
debug spanning-tree switch command B-79
debug spanning-tree uplinkfast command B-81
debug sw-vlan command B-82
debug sw-vlan ifs command B-84
debug sw-vlan notification command B-85
debug sw-vlan vtp command B-86
debug udld command B-88
debug vqpc command B-90
define interface-range command 2-98
delete (boot loader) command A-6
delete command 2-100
deny (ARP access-list configuration) command 2-101
deny (IPv6) command 2-103
deny command 2-108
DHCP snooping
accepting untrusted packets from edge switch 2-207
enabling
on a VLAN 2-213
option 82 2-205, 2-207
trust on an interface 2-211
rate limiting 2-210
DHCP snooping binding database
binding file, configuring 2-203
bindings
adding 2-201
deleting 2-201
displaying 2-503
clearing database agent statistics 2-81, 2-84
database agent, configuring 2-203
displaying
binding entries 2-503
database agent status 2-505, 2-507
renewing 2-414
dir (boot loader) command A-7
directories, deleting 2-100
dot1x auth-fail max-attempts 2-118
dot1x auth-fail vlan 2-120
dot1x command 2-116
dot1x control-direction command 2-122
dot1x credentials (global configuration) command 2-124
dot1x critical global configuration command 2-125
dot1x critical interface configuration command 2-127
dot1x default command 2-129
dot1x fallback command 2-130
dot1x guest-vlan command 2-132
dot1x host-mode command 2-134
dot1x initialize command 2-135
dot1x mac-auth-bypass command 2-136
dot1x max-reauth-req command 2-138
dot1x max-req command 2-140
dot1x pae command 2-141
dot1x port-control command 2-142
dot1x re-authenticate command 2-144
dot1x reauthentication command 2-145
dot1x supplicant force-multicast command 2-131
dot1x test eapol-capable command 2-146
dot1x test timeout command 2-147
dot1x timeout command 2-148
dot1x violation-mode command 2-151
dropping packets, with ACL matches 2-6
DTP 2-712
DTP negotiation 2-716
dual IPv4 and IPv6 templates 2-381
duplex command 2-152
dynamic-access ports
configuring 2-700
restrictions 2-701
dynamic ARP inspection
ARP ACLs
apply to a VLAN 2-187
deny packets 2-101
display 2-435
permit packets 2-379
clear
log buffer 2-79
statistics 2-80
display
ARP ACLs 2-435
configuration and operating state 2-499
enable per VLAN 2-197
log buffer
clear 2-79
configure 2-191
rate-limit incoming ARP packets 2-189
statistics
clear 2-80
trusted interface state 2-193
type of packet logged 2-198
validation checks 2-195
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-140
encapsulation methods 2-731
environment variables, displaying 2-444
epm access-control open 2-154
errdisable detect cause command 2-155
errdisable detect cause small-frame command 2-158
errdisable recovery cause small-frame 2-160
errdisable recovery command 2-161
error conditions, displaying 2-476
error disable detection 2-155
EtherChannel
assigning Ethernet interface to channel group 2-66
creating port-channel logical interface 2-169
debug EtherChannel/PAgP, display B-11
debug platform-specific events, display B-35
displaying 2-479
enabling Layer 2 protocol tunneling for
LACP 2-268
PAgP 2-268
UDLD 2-268
LACP
clearing channel-group information 2-86
debug messages, display B-18
displaying 2-538
port priority for hot-standby ports 2-271
restricting a protocol 2-69
system priority 2-273
load-distribution methods 2-397
PAgP
aggregate-port learner 2-375
clearing channel-group information 2-90
debug messages, display B-27
displaying 2-585
learn method 2-375
physical-port learner 2-375
priority of interface for transmitted traffic 2-377
Ethernet controller, internal register display 2-452
Ethernet statistics, collecting 2-417
exception crashinfo command 2-164
extended-range VLANs
and allowed VLAN list 2-731
and pruning-eligible list 2-731
configuring 2-750
extended system ID for STP 2-652
F
fallback profile command 2-165
fallback profiles
displaying 2-482
files, deleting 2-100
flash_init (boot loader) command A-9
flexible authentication ordering 2-32
Flex Links
configuring 2-704
configuring preferred VLAN 2-706
flowcontrol command 2-167
format (boot loader) command A-10
forwarding packets, with ACL matches 2-6
forwarding results, display C-6
frame forwarding information, displaying C-6
fsck (boot loader) command A-11
G
global configuration mode 1-3
H
health monitoring diagnostic tests
configuring 2-111
help (boot loader) command A-12
hierarchical policy maps 2-395
host connection, port configuration 2-710
host ports, private VLANs 2-714
I
IEEE 802.1Q trunk ports and native VLANs 2-757
IEEE 802.1Q tunnel ports
displaying 2-463
limitations 2-712
IEEE 802.1x
and switchport modes 2-712
See also port-based authentication
IEEE 802.1X Port Based Authentication
enabling guest VLAN supplicant 2-119, 2-130
IGMP filters
debug messages, display B-15
IGMP groups, setting maximum 2-218
IGMP maximum groups, debugging B-16
IGMP profiles
displaying 2-510
IGMP snooping
adding ports as a static member of a group 2-236
displaying 2-511, 2-516, 2-517
enabling 2-222
enabling the configurable-leave timer 2-224
enabling the Immediate-Leave feature 2-233
interface topology change notification behavior 2-232
multicast table 2-514
querier 2-226
report suppression 2-228
switch topology change notification behavior 2-230
images
See software images
immediate-leave processing 2-233
interface configuration mode 1-4
interface port-channel command 2-169
interface range command 2-171
interface-range macros 2-98
interfaces
assigning Ethernet interface to channel group 2-66
configuring 2-152
configuring multiple 2-171
creating port-channel logical 2-169
debug messages, display B-14
disabling 2-629
displaying the MAC address table 2-554
restarting 2-629
interface speed, configuring 2-687
interface vlan command 2-173
internal registers, displaying 2-452, 2-459
Internet Group Management Protocol
See IGMP
ip access-group command 2-175
ip address command 2-178
IP addresses, setting 2-178
ip admission command 2-180
ip admission name proxy http command 2-181
ip arp inspection filter vlan command 2-187
ip arp inspection limit command 2-189
ip arp inspection log-buffer command 2-191
ip arp inspection trust command 2-193
ip arp inspection validate command 2-195
ip arp inspection vlan command 2-197
ip arp inspection vlan logging command 2-198
ip device tracking command 2-183
ip device tracking probe command 2-185
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-201
ip dhcp snooping command 2-200
ip dhcp snooping database command 2-203
ip dhcp snooping information option allow-untrusted command 2-207
ip dhcp snooping information option command 2-205
ip dhcp snooping information option format remote-id command 2-209
ip dhcp snooping limit rate command 2-210
ip dhcp snooping trust command 2-211
ip dhcp snooping verify command 2-212
ip dhcp snooping vlan command 2-213
ip dhcp snooping vlan information option format-type circuit-id string command 2-214
ip igmp filter command 2-216
ip igmp max-groups command 2-218, 2-243, 2-245
ip igmp profile command 2-220
ip igmp snooping command 2-222
ip igmp snooping last-member-query-interval command 2-224
ip igmp snooping querier command 2-226
ip igmp snooping report-suppression command 2-228
ip igmp snooping tcn command 2-230
ip igmp snooping tcn flood command 2-232
ip igmp snooping vlan immediate-leave command 2-233
ip igmp snooping vlan mrouter command 2-234
ip igmp snooping vlan static command 2-236
ip snap forwarding command 2-238
ip source binding command 2-239
IP source guard
disabling 2-247
displaying
binding entries 2-519
configuration 2-520
dynamic binding entries only 2-503
enabling 2-247
static IP source bindings 2-239
ip ssh command 2-241
IPv6 access list
deny conditions 2-103
ipv6 access-list command 2-249
ipv6 mld snooping command 2-251
ipv6 mld snooping last-listener-query count command 2-253
ipv6 mld snooping last-listener-query-interval command 2-255
ipv6 mld snooping listener-message-suppression command 2-257
ipv6 mld snooping robustness-variable command 2-259
ipv6 mld snooping tcn command 2-261
ipv6 mld snooping vlan command 2-263
ipv6 traffic-filter command 2-265
ip verify source command 2-247
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-267
l2protocol-tunnel cos command 2-270
lacp port-priority command 2-271
lacp system-priority command 2-273
Layer 2 mode, enabling 2-698
Layer 2 protocol ports, displaying 2-536
Layer 2 protocol tunnel counters 2-83
Layer 2 protocol tunneling error recovery 2-268
Layer 2 traceroute
IP addresses 2-741
MAC addresses 2-738
Layer 3 mode, enabling 2-698
line configuration mode 1-4
link state group command 2-279
link state track command 2-281
load-distribution methods for EtherChannel 2-397
location (global configuration) command 2-275
location (interface configuration) command 2-277
logging event command 2-282
logging file command 2-283
logical interface 2-169
loop guard, for spanning tree 2-653, 2-657
M
mab request format attribute 32 command 2-285
mac access-group command 2-287
MAC access-groups, displaying 2-546
MAC access list configuration mode 2-289
mac access-list extended command 2-289
MAC access lists 2-108
MAC addresses
disabling MAC address learning per VLAN 2-292
displaying
aging time 2-550
all 2-549
dynamic 2-553
MAC address-table move updates 2-556
notification settings 2-555, 2-557
number of addresses in a VLAN 2-552
per interface 2-554
per VLAN 2-561
static 2-559
static and dynamic entries 2-547
dynamic
deleting 2-87
displaying 2-553
enabling MAC address notification 2-296
enabling MAC address-table move update 2-294
static
adding and removing 2-298
displaying 2-559
dropping on an interface 2-299
tables 2-549
mac address notification, debugging B-20
mac address-table aging-time 2-310
mac address-table aging-time command 2-291
mac address-table learning command 2-292
mac address-table move update command 2-294
mac address-table notification command 2-296
mac address-table static command 2-298
mac address-table static drop command 2-299
macro apply command 2-301
macro description command 2-304
macro global command 2-305
macro global description command 2-307
macro name command 2-308
macros
creating 2-308
displaying 2-587
interface range 2-98, 2-171
maps
QoS
defining 2-324
displaying 2-569
VLAN
creating 2-755
defining 2-310
displaying 2-619
match (access-map configuration) command 2-310
match (class-map configuration) command 2-312
maximum transmission unit
See MTU
mdix auto command 2-314
MDL snooping
displaying 2-530
memory (boot loader) command A-13
mkdir (boot loader) command A-15
MLD snooping
configuring 2-257, 2-259
configuring queries 2-253, 2-255
configuring topology change notification 2-261
displaying 2-528, 2-532, 2-534
enabling 2-251
MLD snooping on a VLAN
enabling 2-263
mls qos aggregate-policer command 2-318
mls qos command 2-316
mls qos cos command 2-320
mls qos dscp-mutation command 2-322
mls qos map command 2-324
mls qos queue-set output buffers command 2-328
mls qos queue-set output threshold command 2-330
mls qos rewrite ip dscp command 2-332
mls qos srr-queue input bandwidth command 2-334
mls qos srr-queue input buffers command 2-336
mls qos-srr-queue input cos-map command 2-338
mls qos srr-queue input dscp-map command 2-340
mls qos srr-queue input priority-queue command 2-342
mls qos srr-queue input threshold command 2-344
mls qos-srr-queue output cos-map command 2-346
mls qos srr-queue output dscp-map command 2-348
mls qos trust command 2-350
mls qos vlan-based command 2-352
Mode button, and password recovery 2-421
modes, commands 1-1
monitor session command 2-353
more (boot loader) command A-16
MSTP
interoperability 2-95
link type 2-655
MST region
aborting changes 2-661
applying changes 2-661
configuration name 2-661
configuration revision number 2-661
current or pending display 2-661
MST configuration mode 2-661
VLANs-to-instance mapping 2-661
path cost 2-663
protocol mode 2-659
restart protocol migration process 2-95
root port
loop guard 2-653
preventing from becoming designated 2-653
restricting which can be root 2-653
root guard 2-653
root switch
affects of extended system ID 2-652
hello-time 2-666
interval between BDPU messages 2-667
interval between hello BPDU messages 2-666
max-age 2-667
maximum hop count before discarding BPDU 2-668
port priority for selection of 2-669
primary or secondary 2-673
state changes
blocking to forwarding state 2-679
enabling BPDU filtering 2-644, 2-677
enabling BPDU guard 2-646, 2-677
enabling Port Fast 2-677, 2-679
forward-delay time 2-665
length of listening and learning states 2-665
rapid transition to forwarding 2-655
shutting down Port Fast-enabled ports 2-677
state information display 2-599
MTU
configuring size 2-736
displaying global setting 2-607
multicast groups, MVR 2-359
Multicast Listener Discovery
See MLD
multicast router learning method 2-234
multicast router ports, configuring 2-234
multicast storm control 2-695
multicast VLAN, MVR 2-358
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-134
Multiple Spanning Tree Protocol
See MSTP
MVR
and address aliasing 2-359
configuring 2-358
configuring interfaces 2-361
debug messages, display B-24
displaying 2-576
displaying interface information 2-577
members, displaying 2-579
mvr (global configuration) command 2-358
mvr (interface configuration) command 2-361
mvr vlan group command 2-362
N
native VLAN tagging 2-757
network-policy (global configuration) command 2-365
network-policy command 2-364
network-policy profile (network-policy configuration) command 2-367
nmsp attachment suppress command 2-371
nmsp command 2-369
no authentication logging verbose 2-372
no dot1x logging verbose 2-373
no mab logging verbose 2-374
nonegotiate
DTP messaging 2-716
nonegotiate, speed 2-687
non-IP protocols
denying 2-108
forwarding 2-387
non-IP traffic access lists 2-289
non-IP traffic forwarding
denying 2-108
permitting 2-387
normal-range VLANs 2-750
no vlan command 2-750
O
online diagnostics
configuring
health monitoring diagnostic tests 2-111
enabling
syslog messages 2-111
global configuration mode
clearing health monitoring diagnostic test schedule 2-111
setting health monitoring diagnostic testing 2-111
setting up health monitoring diagnostic test schedule 2-111
specifying
health monitoring diagnostic tests 2-111
starting testing 2-115
P
pagp learn-method command 2-375
pagp port-priority command 2-377
password-recovery mechanism, enabling and disabling 2-421
permit (ARP access-list configuration) command 2-379
permit (IPv6) command 2-381
permit (MAC access-list configuration) command 2-387
per-VLAN spanning-tree plus
See STP
PID, displaying 2-498
police aggregate command 2-392
police command 2-390
policy-map command 2-394
policy maps
applying to an interface 2-423, 2-428
creating 2-394
displaying 2-590
hierarchical 2-395
policers
displaying 2-564
for a single class 2-390
for multiple classes 2-318, 2-392
traffic classification
defining the class 2-71
defining trust states 2-743
setting DSCP or IP precedence values 2-426
port-based authentication
AAA method list 2-3
configuring violation modes 2-151
debug messages, display B-8
enabling IEEE 802.1x
globally 2-116
per interface 2-142
guest VLAN 2-132
host modes 2-134
IEEE 802.1x AAA accounting methods 2-1
initialize an interface 2-135, 2-147
MAC authentication bypass 2-136
manual control of authorization state 2-142
multiple hosts on authorized port 2-134
PAE as authenticator 2-141
periodic re-authentication
enabling 2-145
re-authenticating IEEE 802.1x-enabled ports 2-144
resetting configurable IEEE 802.1x parameters 2-129
switch-to-client frame-retransmission number2-138to 2-140
test for IEEE 802.1x readiness 2-146
port-channel load-balance command 2-397
Port Fast, for spanning tree 2-679
ports, debugging B-68
ports, protected 2-729
port security
aging 2-723
debug messages, display B-70
enabling 2-718
port trust states for QoS 2-350
priority-queue command 2-399
private-vlan command 2-401
private-vlan mapping command 2-404
private VLANs
association 2-727
configuring 2-401
configuring ports 2-714
host ports 2-714
mapping
configuring 2-727
promiscuous ports 2-714
privileged EXEC mode 1-3
product identification information, displaying 2-498
promiscuous ports, private VLANs 2-714
pruning-eligible VLAN list 2-733
psp 2-406
psp command 2-406
PVST+
See STP
Q
QoS
auto-QoS
configuring 2-53
debug messages, display B-4
displaying 2-440
auto-QoS trust
configuring 2-47
auto-QoS video
configuring 2-50
class maps
creating 2-74
defining the match criteria 2-312
displaying 2-447
defining the CoS value for an incoming packet 2-320
displaying configuration information 2-440, 2-563
DSCP transparency 2-332
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-322
egress queues
allocating buffers 2-328
defining the CoS output queue threshold map 2-346
defining the DSCP output queue threshold map 2-348
displaying queue-set settings 2-572
enabling bandwidth shaping and scheduling 2-691
enabling bandwidth sharing and scheduling 2-693
limiting the maximum output on a port 2-689
mapping a port to a queue-set 2-407
mapping DSCP values to a queue and threshold 2-348
setting maximum and reserved memory allocations 2-330
setting WTD thresholds 2-330
enabling 2-316
ingress queues
allocating buffers 2-336
assigning SRR scheduling weights 2-334
defining the CoS input queue threshold map 2-338
defining the DSCP input queue threshold map 2-340
displaying settings for 2-565
enabling the priority queue 2-342
mapping CoS values to a queue and threshold 2-338
mapping DSCP values to a queue and threshold 2-340
setting WTD thresholds 2-344
maps
defining 2-324, 2-338, 2-340, 2-346, 2-348
displaying 2-569
policy maps
applying an aggregate policer 2-392
applying to an interface 2-423, 2-428
creating 2-394
defining policers 2-318, 2-390
displaying policers 2-564
displaying policy maps 2-590
hierarchical 2-395
setting DSCP or IP precedence values 2-426
traffic classifications 2-71
trust states 2-743
port trust states 2-350
queues, enabling the expedite 2-399
VLAN-based 2-352
quality of service
See QoS
queue-set command 2-407
R
radius-server dead-criteria command 2-408
radius-server host command 2-410
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
re-authenticating IEEE 802.1x-enabled ports 2-144
re-authentication
periodic 2-145
receiving flow-control packets 2-167
recovery mechanism
display 2-474, 2-477
remote-span command 2-412
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-17
renew ip dhcp snooping database command 2-414
reset (boot loader) command A-18
resource templates, displaying 2-596
restricted VLAN
See dot1x auth-fail vlan
rmdir (boot loader) command A-19
rmon collection stats command 2-417
root guard, for spanning tree 2-653
routed ports
IP addresses on 2-179
number supported 2-179
RSPAN
configuring 2-353
displaying 2-574
filter RSPAN traffic 2-353
remote-span command 2-412
sessions
add interfaces to 2-353
displaying 2-574
start new 2-353
S
sdm prefer command 2-418
SDM templates
allowed resources 2-419
displaying 2-596
secure ports, limitations 2-720
sending flow-control packets 2-167
service password-recovery command 2-421
service-policy command 2-423
set (boot loader) command A-20
set command 2-426
setup command 2-428
show access-lists command 2-431
show archive status command 2-434
show arp access-list command 2-435
show authentication command 2-436
show auto qos command 2-440
show boot command 2-444
show cisp command 2-446
show class-map command 2-447
show cluster command 2-448
show controllers cpu-interface command 2-450
show controllers ethernet-controller command 2-452
show controllers tcam command 2-459
show controller utilization command 2-461
show dot1q-tunnel command 2-463
show dot1x command 2-464
show dtp 2-468
show eap command 2-470
show env command 2-473
show errdisable detect command 2-474
show errdisable flap-values command 2-476
show errdisable recovery command 2-477
show etherchannel command 2-479
show fallback profile command 2-482
show flowcontrol command 2-484
show idprom command 2-486
show interfaces command 2-488
show interfaces counters command 2-496
show inventory command 2-498
show ip arp inspection command 2-499
show ipc command 2-522
show ip dhcp snooping binding command 2-503
show ip dhcp snooping command 2-502
show ip dhcp snooping database command 2-505, 2-507
show ip igmp profile command 2-510
show ip igmp snooping address command 2-530
show ip igmp snooping command 2-511, 2-528
show ip igmp snooping groups command 2-514
show ip igmp snooping mrouter command 2-516, 2-532
show ip igmp snooping querier command 2-517, 2-534
show ip source binding command 2-519
show ipv6 access-list command 2-526
show ip verify source command 2-520
show l2protocol-tunnel command 2-536
show lacp command 2-538
show link state group command 2-544
show location 2-542
show mac access-group command 2-546
show mac address-table address command 2-549
show mac address-table aging time command 2-550
show mac address-table command 2-547
show mac address-table count command 2-552
show mac address-table dynamic command 2-553
show mac address-table interface command 2-554
show mac address-table learning command 2-555
show mac address-table move update command 2-556
show mac address-table notification command 2-88, 2-557, B-22
show mac address-table static command 2-559
show mac address-table vlan command 2-561
show mls qos aggregate-policer command 2-564
show mls qos command 2-563
show mls qos input-queue command 2-565
show mls qos interface command 2-566
show mls qos maps command 2-569
show mls qos queue-set command 2-572
show mls qos vlan command 2-573
show monitor command 2-574
show mvr command 2-576
show mvr interface command 2-577
show mvr members command 2-579
show network-policy profile command 2-581
show nmsp command 2-582
show pagp command 2-585
show parser macro command 2-587
show platform acl command C-2
show platform backup interface command C-3
show platform configuration command C-4
show platform etherchannel command C-5
show platform forward command C-6
show platform igmp snooping command C-8
show platform ipc trace command C-14
show platform ip multicast command C-9
show platform ip unicast command C-10
show platform ipv6 unicast command C-15
show platform layer4op command C-17
show platform mac-address-table command C-18
show platform messaging command C-19
show platform monitor command C-20
show platform mvr table command C-21
show platform pm command C-22
show platform port-asic command C-23
show platform port-security command C-28
show platform qos command C-29
show platform resource-manager command C-30
show platform snmp counters command C-32
show platform spanning-tree command C-33
show platform stp-instance command C-34
show platform tcam command C-35
show platform vlan command C-38
show policy-map command 2-590
show port security command 2-591
show psp config 2-594
show psp config command 2-594
show psp statistics 2-595
show psp statistics command 2-595
show sdm prefer command 2-596
show spanning-tree command 2-599
show storm-control command 2-605
show system mtu command 2-607
show udld command 2-608
show version command 2-611
show vlan access-map command 2-619
show vlan command 2-613
show vlan command, fields 2-615
show vlan filter command 2-620
show vmps command 2-621
show vtp command 2-624
shutdown command 2-629
shutdown vlan command 2-630
small violation-rate command 2-631
Smartports macros
See macros
SNMP host, specifying 2-637
SNMP informs, enabling the sending of 2-633
snmp-server enable traps command 2-633
snmp-server host command 2-637
snmp trap mac-notification change command 2-641
SNMP traps
enabling MAC address notification trap 2-641
enabling the MAC address notification feature 2-296
enabling the sending of 2-633
software images
downloading 2-8
upgrading 2-8
uploading 2-14
software version, displaying 2-611
SPAN
configuring 2-353
debug messages, display B-23
displaying 2-574
filter SPAN traffic 2-353
sessions
add interfaces to 2-353
displaying 2-574
start new 2-353
spanning 2-681
spanning-tree backbonefast command 2-643
spanning-tree bpdufilter command 2-644
spanning-tree bpduguard command 2-646
spanning-tree cost command 2-648
spanning-tree etherchannel command 2-650
spanning-tree extend system-id command 2-652
spanning-tree guard command 2-653
spanning-tree link-type command 2-655
spanning-tree loopguard default command 2-657
spanning-tree mode command 2-659
spanning-tree mst configuration command 2-661
spanning-tree mst cost command 2-663
spanning-tree mst forward-time command 2-665
spanning-tree mst hello-time command 2-666
spanning-tree mst max-age command 2-667
spanning-tree mst max-hops command 2-668
spanning-tree mst port-priority command 2-669
spanning-tree mst pre-standard command 2-671
spanning-tree mst priority command 2-672
spanning-tree mst root command 2-673
spanning-tree portfast (global configuration) command 2-677
spanning-tree portfast (interface configuration) command 2-679
spanning-tree port-priority command 2-675
Spanning Tree Protocol
See STP
spanning-tree transmit hold-count command 2-681
spanning-tree uplinkfast command 2-682
spanning-tree vlan command 2-684
speed command 2-687
srr-queue bandwidth limit command 2-689
srr-queue bandwidth shape command 2-691
srr-queue bandwidth share command 2-693
SSH, configuring version 2-241
static-access ports, configuring 2-700
statistics, Ethernet group 2-417
storm-control command 2-695
STP
BackboneFast 2-643
counters, clearing 2-94
debug messages, display
BackboneFast events B-74
MSTP B-77
optimized BPDUs handling B-76
spanning-tree activity B-72
switch shim B-79
transmitted and received BPDUs B-75
UplinkFast B-81
detection of indirect link failures 2-643
enabling protocol tunneling for 2-267
EtherChannel misconfiguration 2-650
extended system ID 2-652
path cost 2-648
protocol modes 2-659
root port
accelerating choice of new 2-682
loop guard 2-653
preventing from becoming designated 2-653
restricting which can be root 2-653
root guard 2-653
UplinkFast 2-682
root switch
affects of extended system ID 2-652, 2-685
port priority for selection of 2-675
state changes
blocking to forwarding state 2-679
enabling BPDU filtering 2-644, 2-677
enabling BPDU guard 2-646, 2-677
enabling Port Fast 2-677, 2-679
shutting down Port Fast-enabled ports 2-677
state information display 2-599
VLAN options 2-672, 2-684
SVIs, creating 2-173
SVI status calculation 2-702
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-698
returning to interfaces 2-698
switchport access command 2-700
switchport autostate exclude command 2-702
switchport backup interface command 2-704
switchport block command 2-708
switchport command 2-698
switchport host command 2-710
switchport mode command 2-711
switchport mode private-vlan command 2-714
switchport nonegotiate command 2-716
switchport port-security aging command 2-723
switchport port-security command 2-718
switchport priority extend command 2-725
switchport private-vlan command 2-727
switchport protected command 2-729
switchport trunk command 2-731
switchport voice vlan command 2-734
system message logging, save message to flash 2-283
system mtu command 2-736
system resource templates 2-418
T
tar files, creating, listing, and extracting 2-11
templates, system resources 2-418
traceroute mac command 2-738
traceroute mac ip command 2-741
trunk mode 2-711
trunk ports 2-711
trunks, to non-DTP device 2-712
trust command 2-743
trusted port states for QoS 2-350
tunnel ports, Layer 2 protocol, displaying 2-536
type (boot loader) command A-23
U
UDLD
aggressive mode 2-745, 2-747
debug messages, display B-88
enable globally 2-745
enable per interface 2-747
message timer 2-745
normal mode 2-745, 2-747
reset a shutdown interface 2-749
status 2-608
udld command 2-745
udld port command 2-747
udld reset command 2-749
unicast storm control 2-695
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-708
unknown unicast traffic, preventing 2-708
unset (boot loader) command A-24
upgrading
software images 2-8
monitoring status of 2-434
UplinkFast, for STP 2-682
user EXEC mode 1-2
V
version (boot loader) command A-26
VLAN
enabling guest VLAN supplicant 2-119, 2-130
vlan (global configuration) command 2-750
vlan access-map command 2-755
VLAN access map configuration mode 2-755
VLAN access maps
actions 2-6
displaying 2-619
VLAN-based QoS 2-352
VLAN configuration
rules 2-753
saving 2-750
VLAN configuration mode
description 1-4
vlan dot1q tag native command 2-757
vlan filter command 2-758
VLAN filters, displaying 2-620
VLAN maps
creating 2-755
defining 2-310
displaying 2-619
VLAN Query Protocol
See VQP
VLANs
adding 2-750
configuring 2-750
debug messages, display
ISL B-85
VLAN IOS file system error tests B-84
VLAN manager activity B-82
VTP B-86
displaying configurations 2-613
extended-range 2-750
MAC addresses
displaying 2-561
number of 2-552
media types 2-753
normal-range 2-750
private 2-714
configuring 2-401
See also private VLANs
restarting 2-630
saving the configuration 2-750
shutting down 2-630
suspending 2-630
VLAN Trunking Protocol
See VTP
VMPS
configuring servers 2-763
displaying 2-621
reconfirming dynamic VLAN assignments 2-760
vmps reconfirm (global configuration) command 2-761
vmps reconfirm (privileged EXEC) command 2-760
vmps retry command 2-762
vmps server command 2-763
voice VLAN
configuring 2-734
setting port priority 2-725
VQP
and dynamic-access ports 2-701
clearing client statistics 2-96
displaying information 2-621
per-server retry count 2-762
reconfirmation interval 2-761
reconfirming dynamic VLAN assignments 2-760
VTP
changing characteristics 2-765
clearing pruning counters 2-97
counters display fields 2-625
displaying information 2-624
enabling
tunneling for 2-267
enabling per port 2-770
saving the configuration 2-750
status display fields 2-627
vtp (global configuration) command 2-765
vtp interface configuration command 2-770
vtp primary command 2-771
X
XENPAK module serial EERPOM information 2-486