Table Of Contents
A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - Q - R - S - T - U - V - X -
Index
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5, 2-16, 2-20, 2-22, 2-24, 2-26, 2-96, 2-394, B-5, B-28
AAA methods 2-3
abort command 2-730
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-153
MAC, displaying 2-502
access list, IPv6 2-209
access map configuration mode 2-268
access mode 2-676
access ports 2-676
ACEs 2-87, 2-342
ACLs
deny 2-85
displaying 2-383
for non-IP protocols 2-247
IP 2-153
matching 2-268
on Layer 2 interfaces 2-153
permit 2-340
action command 2-6
address aliasing 2-317
aggregate-port learner 2-330
allowed VLANs 2-696
apply command 2-730
archive download-sw command 2-8
archive tar command 2-11
archive upload-sw command 2-14
audience xix
authentication control-direction command 2-16
authentication event command 2-18
authentication failed VLAN
See dot1x auth-fail vlan
authentication fallback command 2-20
authentication host-mode command 2-22
authentication open command 2-24
authentication order command 2-26
authentication periodic command 2-28
authentication port-control command 2-30
authentication priority command 2-32
authentication timer command 2-34
authentication violation command 2-36
auth-fail max-attempts
See dot1x auth-fail max-attempts
auth-fail vlan
See dot1x auth-fail vlan
auth open command 2-24
auth order command 2-26
authorization state of controlled port 2-112
auth timer command 2-34
autonegotiation of duplex mode 2-123
auto qos voip command 2-38
B
BackboneFast, for STP 2-609
backup interfaces
configuring 2-670
displaying 2-439
boot (boot loader) command A-2
boot config-file command 2-42
boot enable-break command 2-43
boot helper command 2-44
boot helper-config file command 2-45
booting
Cisco IOS image 2-48
displaying environment variables 2-392
interrupting 2-43
manually 2-46
boot loader
accessing A-1
booting
Cisco IOS image A-2
helper image 2-44
directories
creating A-15
displaying a list of A-7
removing A-19
displaying
available commands A-12
memory heap utilization A-13
version A-26
environment variables
described A-20
displaying settings A-20
location of A-21
setting A-20
unsetting A-24
boot loader (continued)
files
copying A-5
deleting A-6
displaying a list of A-7
displaying the contents of A-4, A-16, A-23
renaming A-17
file system
formatting A-10
initializing flash A-9
running a consistency check A-11
resetting the system A-18
boot manual command 2-46
boot private-config-file command 2-47
boot system command 2-48
BPDU filtering, for spanning tree 2-610, 2-643
BPDU guard, for spanning tree 2-612, 2-643
break key detection 2-373, A-1
broadcast storm control 2-661
C
cat (boot loader) command A-4
caution, description xx
CDP, enabling protocol tunneling for 2-227
channel-group command 2-49
channel-protocol command 2-52
Cisco SoftPhone
auto-QoS configuration 2-38
trusting packets sent from 2-308
CISP
See Client Information Signalling Protocol
cisp
debug platform cisp command B-28
cisp enable command 2-53
class command 2-54
class-map command 2-56
class maps
creating 2-56
defining the match criteria 2-270
displaying 2-395
class of service
See CoS
clear dot1x command 2-58
clear eap sessions command 2-59
clear energywise neighbors command 2-60
clear errdisable interface 2-61
clear ipc command 2-62
clear ip dhcp snooping database command 2-64
clear l2protocol-tunnel counters command 2-63
clear lacp command 2-66
clear mac address-table command 2-67, 2-68
clear nmsp statistics command 2-69
clear pagp command 2-70
clear port-security command 2-71
clear spanning-tree counters command 2-73
clear spanning-tree detected-protocols command 2-74
clear vmps statistics command 2-75
clear vtp counters command 2-76
Client Information Signalling Protocol 2-53, 2-96, 2-394, B-5, B-28
clusters
SNMP trap 2-599
command modes defined 1-1
configuration, initial
See getting started guide and hardware installation guide
configuration files
password recovery disable considerations A-1
specifying the name 2-42, 2-47
configuring multiple interfaces 2-149
config-vlan mode
commands 2-716
description 1-4
entering 2-715
summary 1-2
conventions
command xx
for examples xx
publication xx
text xx
copy (boot loader) command A-5
CoS
assigning default value to incoming packets 2-278
assigning to Layer 2 protocol packets 2-230
overriding the incoming value 2-278
CoS-to-DSCP map 2-282
CPU ASIC statistics, displaying 2-396
crashinfo files 2-142
D
debug auto qos command B-2
debug backup command B-4
debug cisp command B-5
debug dot1x command B-6
debug dtp command B-7
debug eap command B-8
debug etherchannel command B-9
debug interface command B-12
debug ip dhcp snooping command B-10
debug ip igmp filter command B-13
debug ip igmp max-groups command B-14
debug ip igmp snooping command B-15
debug ip verify source packet command B-11
debug lacp command B-16
debug lldp packets command B-17
debug mac-notification command B-18
debug matm command B-19
debug matm move update command B-20
debug monitor command B-21
debug mvrdbg command B-22
debug nmsp command B-23
debug nvram command B-24
debug pagp command B-25
debug platform acl command B-26
debug platform backup interface command B-27
debug platform cisp command B-28
debug platform cli-redirection main command B-29
debug platform cpu-queues command B-30
debug platform dot1x command B-32
debug platform etherchannel command B-33
debug platform fallback-bridging command B-34
debug platform forw-tcam command B-35
debug platform ip arp inspection command B-36
debug platform ipc command B-44
debug platform ip dhcp command B-37
debug platform ip igmp snooping command B-38
debug platform ip multicast command B-40
debug platform ip unicast command B-42
debug platform led command B-45
debug platform matm command B-46
debug platform messaging application command B-47
debug platform phy command B-48
debug platform pm command B-50
debug platform port-asic command B-52
debug platform port-security command B-53
debug platform qos-acl-tcam command B-54
debug platform remote-commands command B-55
debug platform resource-manager command B-56
debug platform snmp command B-57
debug platform span command B-58
debug platform supervisor-asic command B-59
debug platform sw-bridge command B-60
debug platform tcam command B-61
debug platform udld command B-64
debug platform vlan command B-65
debug pm command B-66
debug port-security command B-68
debug qos-manager command B-69
debug spanning-tree backbonefast command B-72
debug spanning-tree bpdu command B-73
debug spanning-tree bpdu-opt command B-74
debug spanning-tree command B-70
debug spanning-tree mstp command B-75
debug spanning-tree switch command B-77
debug spanning-tree uplinkfast command B-79
debug sw-vlan command B-80
debug sw-vlan ifs command B-82
debug sw-vlan notification command B-83
debug sw-vlan vtp command B-84
debug udld command B-86
debug vqpc command B-88
define interface-range command 2-77
delete (boot loader) command A-6
delete command 2-79
deny (IPv6) command 2-80
deny command 2-85
detect mechanism, causes 2-134
device manager requirements xx
DHCP snooping
accepting untrusted packets from edge switch 2-168
enabling
on a VLAN 2-174
option 82 2-166, 2-168
trust on an interface 2-172
error recovery timer 2-139
rate limiting 2-171
DHCP snooping binding database
binding file, configuring 2-164
bindings
adding 2-162
deleting 2-162
displaying 2-453
clearing database agent statistics 2-64
database agent, configuring 2-164
displaying
binding entries 2-453
database agent status 2-455, 2-457
renewing 2-366
dir (boot loader) command A-7
directories, deleting 2-79
documentation, related xx
document conventions xx
domain name, VTP 2-740, 2-744
dot1x auth-fail max-attempts 2-90
dot1x auth-fail vlan 2-92
dot1x command 2-88
dot1x control-direction command 2-94
dot1x credentials (global configuration) command 2-96
dot1x critical global configuration command 2-97
dot1x critical interface configuration command 2-99
dot1x default command 2-101
dot1x fallback command 2-102
dot1x guest-vlan command 2-103
dot1x host-mode command 2-105
dot1x initialize command 2-106
dot1x mac-auth-bypass command 2-107
dot1x max-reauth-req command 2-109
dot1x max-req command 2-110
dot1x pae command 2-111
dot1x port-control command 2-112
dot1x re-authenticate command 2-114
dot1x reauthentication command 2-115
dot1x test eapol-capable command 2-116
dot1x test timeout command 2-117
dot1x timeout command 2-118
dot1x violation-mode command 2-121
dropping packets, with ACL matches 2-6
drop threshold, Layer 2 protocol tunneling 2-227
DSCP-to-CoS map 2-282
DSCP-to-DSCP-mutation map 2-282
DTP 2-677
DTP flap
error detection for 2-134
error recovery timer 2-139
DTP negotiation 2-681
dual IPv4 and IPv6 templates 2-334
duplex command 2-122
dynamic-access ports
configuring 2-666
restrictions 2-666
dynamic ARP inspection
error detection for 2-134
dynamic auto VLAN membership mode 2-676
dynamic desirable VLAN membership mode 2-676
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-110
response time before retransmitting 2-118
encapsulation methods 2-696
energywise (global configuration) command 2-124, 2-126
energywise domain command 2-128
energywise query command 2-130
environment variables, displaying 2-392
errdisable detect cause command 2-134
errdisable detect cause small-frame command 2-136
errdisable recovery cause small-frame 2-138
errdisable recovery command 2-139
error conditions, displaying 2-426
error disable detection 2-134
error-disabled interfaces, displaying 2-439
EtherChannel
assigning Ethernet interface to channel group 2-49
creating port-channel logical interface 2-147
debug EtherChannel/PAgP, display B-9
debug platform-specific events, display B-33
displaying 2-430
enabling Layer 2 protocol tunneling for
LACP 2-228
PAgP 2-228
UDLD 2-228
interface information, displaying 2-439
EtherChannel (continued)
LACP
clearing channel-group information 2-66
debug messages, display B-16
displaying 2-491
modes 2-49
port priority for hot-standby ports 2-231
restricting a protocol 2-52
system priority 2-233
load-distribution methods 2-350
PAgP
aggregate-port learner 2-330
clearing channel-group information 2-70
debug messages, display B-25
displaying 2-553
error detection for 2-134
error recovery timer 2-139
learn method 2-330
modes 2-49
physical-port learner 2-330
priority of interface for transmitted traffic 2-332
Ethernet controller, internal register display 2-398
Ethernet statistics, collecting 2-369
examples, conventions for xx
exception crashinfo command 2-142
exit command 2-730
extended-range VLANs
and allowed VLAN list 2-696
and pruning-eligible list 2-696
configuring 2-715
extended system ID for STP 2-618
F
fallback profile command 2-143
fallback profiles
displaying 2-433
file name, VTP 2-740
files, deleting 2-79
flash_init (boot loader) command A-9
flexible authentication ordering 2-26
Flex Links
configuring 2-670
configuring preferred VLAN 2-672
displaying 2-439
flowcontrol command 2-145
format (boot loader) command A-10
forwarding packets, with ACL matches 2-6
forwarding results, display C-6
frame forwarding information, displaying C-6
fsck (boot loader) command A-11
G
global configuration mode 1-2, 1-3
H
hardware ACL statistics 2-383
help (boot loader) command A-12
hierarchical policy maps 2-348
host connection, port configuration 2-675
host ports, private VLANs 2-679
I
IEEE 802.1Q trunk ports and native VLANs 2-732
IEEE 802.1Q tunnel ports
configuring 2-676
displaying 2-409
limitations 2-677
IEEE 802.1x
and switchport modes 2-677
violation error recovery 2-139
See also port-based authentication
IEEE 802.1X Port Based Authentication
enabling guest VLAN supplicant 2-91, 2-102, 2-144
IGMP filters
applying 2-177
debug messages, display B-13
IGMP groups, setting maximum 2-179
IGMP maximum groups, debugging B-14
IGMP profiles
creating 2-181
displaying 2-460
IGMP snooping
adding ports as a static member of a group 2-197
displaying 2-461, 2-466, 2-468
enabling 2-183
enabling the configurable-leave timer 2-185
enabling the Immediate-Leave feature 2-194
flooding query count 2-191
interface topology change notification behavior 2-193
multicast table 2-464
querier 2-187
query solicitation 2-191
report suppression 2-189
switch topology change notification behavior 2-191
images
See software images
Immediate-Leave feature, MVR 2-319
Immediate-Leave processing
IPv6 2-223
immediate-leave processing 2-194
initial configuration
See getting started guide and hardware installation guide
interface configuration mode 1-2, 1-4
interface port-channel command 2-147
interface range command 2-149
interface-range macros 2-77
interfaces
assigning Ethernet interface to channel group 2-49
configuring 2-122
configuring multiple 2-149
creating port-channel logical 2-147
interfaces (continued)
debug messages, display B-12
disabling 2-595
displaying the MAC address table 2-514
restarting 2-595
interface speed, configuring 2-653
interface vlan command 2-151
internal registers, displaying 2-398, 2-405
Internet Group Management Protocol
See IGMP
invalid GBIC
error detection for 2-134
error recovery timer 2-139
ip access-group command 2-153
ip address command 2-156
IP addresses, setting 2-156
IP address matching 2-268
ip admission command 2-158
ip admission name proxy http command 2-159
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-162
ip dhcp snooping command 2-161
ip dhcp snooping database command 2-164
ip dhcp snooping information option allow-untrusted command 2-168
ip dhcp snooping information option command 2-166
ip dhcp snooping information option format remote-id command 2-170
ip dhcp snooping limit rate command 2-171
ip dhcp snooping trust command 2-172
ip dhcp snooping verify command 2-173
ip dhcp snooping vlan command 2-174
ip dhcp snooping vlan information option format-type circuit-id string command 2-175
ip igmp filter command 2-177
ip igmp max-groups command 2-179, 2-204, 2-206
ip igmp profile command 2-181
ip igmp snooping command 2-183
ip igmp snooping last-member-query-interval command 2-185
ip igmp snooping querier command 2-187
ip igmp snooping report-suppression command 2-189
ip igmp snooping tcn command 2-191
ip igmp snooping tcn flood command 2-193
ip igmp snooping vlan immediate-leave command 2-194
ip igmp snooping vlan mrouter command 2-195
ip igmp snooping vlan static command 2-197
IP multicast addresses 2-316
IP phones
auto-QoS configuration 2-38
trusting packets sent from 2-308
IP-precedence-to-DSCP map 2-282
ip snap forwarding command 2-199
ip source binding command 2-200
IP source guard
disabling 2-208
displaying
binding entries 2-470
configuration 2-472
dynamic binding entries only 2-453
enabling 2-208
static IP source bindings 2-200
ip ssh command 2-202
IPv6 access list
deny conditions 2-80
ipv6 access-list command 2-209
ipv6 mld snooping command 2-211
ipv6 mld snooping last-listener-query count command 2-213
ipv6 mld snooping last-listener-query-interval command 2-215
ipv6 mld snooping listener-message-suppression command 2-217
ipv6 mld snooping robustness-variable command 2-219
ipv6 mld snooping tcn command 2-221
ipv6 mld snooping vlan command 2-223
IPv6 SDM template 2-370
ipv6 traffic-filter command 2-225
ip verify source command 2-208
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-227
l2protocol-tunnel cos command 2-230
LACP
See EtherChannel
lacp port-priority command 2-231
lacp system-priority command 2-233
Layer 2 mode, enabling 2-664
Layer 2 protocol ports, displaying 2-488
Layer 2 protocol-tunnel
error detection for 2-134
error recovery timer 2-139
Layer 2 protocol tunnel counters 2-63
Layer 2 protocol tunneling error recovery 2-228
Layer 2 traceroute
IP addresses 2-706
MAC addresses 2-703
Layer 3 mode, enabling 2-664
line configuration mode 1-2, 1-5
Link Aggregation Control Protocol
See EtherChannel
link flap
error detection for 2-134
error recovery timer 2-139
link state group command 2-239
link state track command 2-241
load-distribution methods for EtherChannel 2-350
location (global configuration) command 2-235
location (interface configuration) command 2-237
logging event command 2-242
logging file command 2-243
logical interface 2-147
loopback error
detection for 2-134
recovery timer 2-139
loop guard, for spanning tree 2-619, 2-623
M
mac access-group command 2-245
MAC access-groups, displaying 2-502
MAC access list configuration mode 2-247
mac access-list extended command 2-247
MAC access lists 2-85
MAC addresses
disabling MAC address learning per VLAN 2-250
displaying
aging time 2-508
all 2-506
dynamic 2-512
MAC address-table move updates 2-517
notification settings 2-516, 2-519
number of addresses in a VLAN 2-510
per interface 2-514
per VLAN 2-523
static 2-521
static and dynamic entries 2-504
dynamic
aging time 2-249
deleting 2-67
displaying 2-512
enabling MAC address notification 2-254
enabling MAC address-table move update 2-252
matching 2-268
static
adding and removing 2-256
displaying 2-521
dropping on an interface 2-257
tables 2-506
mac address notification, debugging B-18
mac address-table aging-time 2-245, 2-268
mac address-table aging-time command 2-249
mac address-table learning command 2-250
mac address-table move update command 2-252
mac address-table notification command 2-254
mac address-table static command 2-256
mac address-table static drop command 2-257
macro apply command 2-259
macro description command 2-262
macro global command 2-263
macro global description command 2-265
macro name command 2-266
macros
adding a description 2-262
adding a global description 2-265
applying 2-263
creating 2-266
displaying 2-555
interface range 2-77, 2-149
specifying parameter values 2-263
tracing 2-263
manual
audience xix
purpose of xix
maps
QoS
defining 2-282
displaying 2-533
VLAN
creating 2-727
defining 2-268
displaying 2-586
match (access-map configuration) command 2-268
match (class-map configuration) command 2-270
maximum transmission unit
See MTU
mdix auto command 2-272
MDL snooping
displaying 2-482
memory (boot loader) command A-13
mkdir (boot loader) command A-15
MLD snooping
configuring 2-217, 2-219
configuring queries 2-213, 2-215
configuring topology change notification 2-221
displaying 2-480, 2-484, 2-486
enabling 2-211
MLD snooping on a VLAN
enabling 2-223
mls qos aggregate-policer command 2-276
mls qos command 2-274
mls qos cos command 2-278
mls qos dscp-mutation command 2-280
mls qos map command 2-282
mls qos queue-set output buffers command 2-286
mls qos queue-set output threshold command 2-288
mls qos rewrite ip dscp command 2-290
mls qos srr-queue input bandwidth command 2-292
mls qos srr-queue input buffers command 2-294
mls qos-srr-queue input cos-map command 2-296
mls qos srr-queue input dscp-map command 2-298
mls qos srr-queue input priority-queue command 2-300
mls qos srr-queue input threshold command 2-302
mls qos-srr-queue output cos-map command 2-304
mls qos srr-queue output dscp-map command 2-306
mls qos trust command 2-308
mls qos vlan-based command 2-310
mode, MVR 2-316
Mode button, and password recovery 2-373
modes, commands 1-1
monitor session command 2-311
more (boot loader) command A-16
MSTP
displaying 2-567
interoperability 2-74
link type 2-621
MSTP (continued)
MST region
aborting changes 2-627
applying changes 2-627
configuration name 2-627
configuration revision number 2-627
current or pending display 2-627
displaying 2-567
MST configuration mode 2-627
VLANs-to-instance mapping 2-627
path cost 2-629
protocol mode 2-625
restart protocol migration process 2-74
root port
loop guard 2-619
preventing from becoming designated 2-619
restricting which can be root 2-619
root guard 2-619
root switch
affects of extended system ID 2-618
hello-time 2-632, 2-639
interval between BDPU messages 2-633
interval between hello BPDU messages 2-632, 2-639
max-age 2-633
maximum hop count before discarding BPDU 2-634
port priority for selection of 2-635
primary or secondary 2-639
switch priority 2-638
state changes
blocking to forwarding state 2-645
enabling BPDU filtering 2-610, 2-643
enabling BPDU guard 2-612, 2-643
enabling Port Fast 2-643, 2-645
forward-delay time 2-631
length of listening and learning states 2-631
rapid transition to forwarding 2-621
shutting down Port Fast-enabled ports 2-643
MSTP (continued)
state information display 2-566
MTU
configuring size 2-701
displaying global setting 2-574
multicast group address, MVR 2-319
multicast groups, MVR 2-317
Multicast Listener Discovery
See MLD
multicast router learning method 2-195
multicast router ports
IPv6 2-223
multicast router ports, configuring 2-195
multicast storm control 2-661
multicast VLAN, MVR 2-316
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-105
Multiple Spanning Tree Protocol
See MSTP
MVR
and address aliasing 2-317
configuring 2-316
configuring interfaces 2-319
debug messages, display B-22
displaying 2-542
displaying interface information 2-544
members, displaying 2-546
mvr (global configuration) command 2-316
mvr (interface configuration) command 2-319
mvr vlan group command 2-320
N
native VLANs 2-696
native VLAN tagging 2-732
network-policy (global configuration) command 2-323
network-policy command 2-322
network-policy profile (network-policy configuration) command 2-325
nmsp attachment suppress command 2-329
nmsp command 2-327
nonegotiate
DTP messaging 2-681
nonegotiate, speed 2-653
non-IP protocols
denying 2-85
forwarding 2-340
non-IP traffic access lists 2-247
non-IP traffic forwarding
denying 2-85
permitting 2-340
normal-range VLANs 2-715, 2-721
note, description xx
no vlan command 2-715, 2-725
O
online diagnostics
displaying
configured boot-up coverage level 2-409
current scheduled tasks 2-409
event logs 2-409
supported test suites 2-409
test ID 2-409
test results 2-409
test statistics 2-409
P
PAgP
See EtherChannel
pagp learn-method command 2-330
pagp port-priority command 2-332
password, VTP 2-740, 2-744
password-recovery mechanism, enabling and disabling 2-373
permit (IPv6) command 2-334
permit (MAC access-list configuration) command 2-340
per-VLAN spanning-tree plus
See STP
physical-port learner 2-330
PID, displaying 2-450
PIM-DVMRP, as multicast router learning method 2-195
police aggregate command 2-345
police command 2-343
policed-DSCP map 2-282
policy-map command 2-347
policy maps
applying to an interface 2-375, 2-380
creating 2-347
displaying 2-558
hierarchical 2-348
policers
displaying 2-526
for a single class 2-343
for multiple classes 2-276, 2-345
policed-DSCP map 2-282
traffic classification
defining the class 2-54
defining trust states 2-708
setting DSCP or IP precedence values 2-378
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
configuring violation modes 2-121
debug messages, display B-6
enabling IEEE 802.1x
globally 2-88
per interface 2-112
guest VLAN 2-103
host modes 2-105
IEEE 802.1x AAA accounting methods 2-1
initialize an interface 2-106, 2-117
MAC authentication bypass 2-107
port-based authentication (continued)
manual control of authorization state 2-112
multiple hosts on authorized port 2-105
PAE as authenticator 2-111
periodic re-authentication
enabling 2-115
time between attempts 2-118
quiet period between failed authentication exchanges 2-118
re-authenticating IEEE 802.1x-enabled ports 2-114
resetting configurable IEEE 802.1x parameters 2-101
switch-to-authentication server retransmission time 2-118
switch-to-client frame-retransmission number2-109to 2-110
switch-to-client retransmission time 2-118
test for IEEE 802.1x readiness 2-116
port-channel load-balance command 2-350
Port Fast, for spanning tree 2-645
port ranges, defining 2-77
ports, debugging B-66
ports, protected 2-694
port security
aging 2-688
debug messages, display B-68
enabling 2-683
violation error recovery 2-139
port trust states for QoS 2-308
port types, MVR 2-319
priority-queue command 2-352
private-vlan command 2-354
private-vlan mapping command 2-357
private VLANs
association 2-692
configuring 2-354
configuring ports 2-679
displaying 2-580
host ports 2-679
private VLANs (continued)
mapping
configuring 2-692
displaying 2-439
promiscuous ports 2-679
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-450
promiscuous ports, private VLANs 2-679
protected ports, displaying 2-445
pruning
VLANs 2-696
VTP
displaying interface information 2-439
enabling 2-740, 2-744
pruning-eligible VLAN list 2-698
PVST+
See STP
Q
QoS
auto-QoS
configuring 2-38
debug messages, display B-2
displaying 2-388
class maps
creating 2-56
defining the match criteria 2-270
displaying 2-395
defining the CoS value for an incoming packet 2-278
displaying configuration information 2-388, 2-525
DSCP transparency 2-290
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-280
defining DSCP-to-DSCP-mutation map 2-282
egress queues
allocating buffers 2-286
defining the CoS output queue threshold map 2-304
QoS (continued)
defining the DSCP output queue threshold map 2-306
displaying buffer allocations 2-529
displaying CoS output queue threshold map 2-533
displaying DSCP output queue threshold map 2-533
displaying queueing strategy 2-529
displaying queue-set settings 2-536
enabling bandwidth shaping and scheduling 2-657
enabling bandwidth sharing and scheduling 2-659
limiting the maximum output on a port 2-655
mapping a port to a queue-set 2-359
mapping CoS values to a queue and threshold 2-304
mapping DSCP values to a queue and threshold 2-306
setting maximum and reserved memory allocations 2-288
setting WTD thresholds 2-288
enabling 2-274
ingress queues
allocating buffers 2-294
assigning SRR scheduling weights 2-292
defining the CoS input queue threshold map 2-296
defining the DSCP input queue threshold map 2-298
displaying buffer allocations 2-529
displaying CoS input queue threshold map 2-533
displaying DSCP input queue threshold map 2-533
displaying queueing strategy 2-529
displaying settings for 2-527
enabling the priority queue 2-300
mapping CoS values to a queue and threshold 2-296
mapping DSCP values to a queue and threshold 2-298
setting WTD thresholds 2-302
QoS (continued)
maps
defining 2-282, 2-296, 2-298, 2-304, 2-306
displaying 2-533
policy maps
applying an aggregate policer 2-345
applying to an interface 2-375, 2-380
creating 2-347
defining policers 2-276, 2-343
displaying policers 2-526
displaying policy maps 2-558
hierarchical 2-348
policed-DSCP map 2-282
setting DSCP or IP precedence values 2-378
traffic classifications 2-54
trust states 2-708
port trust states 2-308
queues, enabling the expedite 2-352
statistics
in-profile and out-of-profile packets 2-529
packets enqueued or dropped 2-529
sent and received CoS values 2-529
sent and received DSCP values 2-529
trusted boundary for IP phones 2-308
VLAN-based 2-310
quality of service
See QoS
querytime, MVR 2-316
queue-set command 2-359
R
radius-server dead-criteria command 2-360
radius-server host command 2-362
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
re-authenticating IEEE 802.1x-enabled ports 2-114
re-authentication
periodic 2-115
time between attempts 2-118
receiver ports, MVR 2-319
receiving flow-control packets 2-145
recovery mechanism
causes 2-139
display 2-61, 2-424, 2-428
timer interval 2-140
remote-span command 2-364
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-17
renew ip dhcp snooping database command 2-366
requirements
device manager xx
reset (boot loader) command A-18
reset command 2-730
resource templates, displaying 2-563
restricted VLAN
See dot1x auth-fail vlan
rmdir (boot loader) command A-19
rmon collection stats command 2-369
root guard, for spanning tree 2-619
routed ports
IP addresses on 2-157
number supported 2-157
RSPAN
configuring 2-311
displaying 2-539
filter RSPAN traffic 2-311
remote-span command 2-364
sessions
add interfaces to 2-311
displaying 2-539
start new 2-311
S
sdm prefer command 2-370
SDM templates
allowed resources 2-371
displaying 2-563
dual IPv4 and IPv6 2-370
secure ports, limitations 2-685
sending flow-control packets 2-145
service password-recovery command 2-373
service-policy command 2-375
set (boot loader) command A-20
set command 2-378
setup command 2-380
show access-lists command 2-383
show archive status command 2-386
show authentication command 2-387
show auto qos command 2-388
show boot command 2-392
show changes command 2-730
show cisp command 2-394
show class-map command 2-395
show controllers cpu-interface command 2-396
show controllers ethernet-controller command 2-398
show controllers tcam command 2-405
show controller utilization command 2-407
show current command 2-730
show dot1q-tunnel command 2-409
show dot1x command 2-410
show dtp 2-414
show eap command 2-416
show energywise command 2-419
show env command 2-423
show errdisable detect command 2-424
show errdisable flap-values command 2-426
show errdisable recovery command 2-428
show etherchannel command 2-430
show fallback profile command 2-433
show flowcontrol command 2-435
show idprom command 2-437
show interfaces command 2-439
show interfaces counters command 2-447
show inventory command 2-450
show ipc command 2-474
show ip dhcp snooping binding command 2-453
show ip dhcp snooping command 2-452
show ip dhcp snooping database command 2-455, 2-457
show ip igmp profile command 2-460
show ip igmp snooping address command 2-482
show ip igmp snooping command 2-461, 2-480
show ip igmp snooping groups command 2-464
show ip igmp snooping mrouter command 2-466, 2-484
show ip igmp snooping querier command 2-468, 2-486
show ip source binding command 2-470
show ipv6 access-list command 2-478
show ip verify source command 2-472
show l2protocol-tunnel command 2-488
show lacp command 2-491
show link state group command 2-498, 2-500
show location 2-495
show mac access-group command 2-502
show mac address-table address command 2-506
show mac address-table aging time command 2-508
show mac address-table command 2-504
show mac address-table count command 2-510
show mac address-table dynamic command 2-512
show mac address-table interface command 2-514
show mac address-table learning command 2-516
show mac address-table move update command 2-517
show mac address-table notification command 2-68, 2-519, B-20
show mac address-table static command 2-521
show mac address-table vlan command 2-523
show mls qos aggregate-policer command 2-526
show mls qos command 2-525
show mls qos input-queue command 2-527
show mls qos interface command 2-529
show mls qos maps command 2-533
show mls qos queue-set command 2-536
show mls qos vlan command 2-538
show monitor command 2-539
show mvr command 2-542
show mvr interface command 2-544
show mvr members command 2-546
show network-policy profile command 2-548
show nmsp command 2-550
show pagp command 2-553
show parser macro command 2-555
show platform acl command C-2
show platform backup interface command C-3
show platform configuration command C-4
show platform etherchannel command C-5
show platform forward command C-6
show platform igmp snooping command C-8
show platform ipc trace command C-15
show platform ip multicast command C-10
show platform ip unicast command C-11
show platform ipv6 unicast command C-16
show platform layer4op command C-18
show platform mac-address-table command C-19
show platform messaging command C-20
show platform monitor command C-21
show platform mvr table command C-22
show platform pm command C-23
show platform port-asic command C-24
show platform port-security command C-29
show platform qos command C-30
show platform resource-manager command C-31
show platform snmp counters command C-33
show platform spanning-tree command C-34
show platform stp-instance command C-35
show platform tcam command C-36
show platform vlan command C-39
show policy-map command 2-558
show port security command 2-560
show proposed command 2-730
show sdm prefer command 2-563
show spanning-tree command 2-566
show storm-control command 2-572
show system mtu command 2-574
show trust command 2-708
show udld command 2-575
show version command 2-578
show vlan access-map command 2-586
show vlan command 2-580
show vlan command, fields 2-582
show vlan filter command 2-587
show vmps command 2-588
show vtp command 2-590
shutdown command 2-595
shutdown threshold, Layer 2 protocol tunneling 2-227
shutdown vlan command 2-596
small violation-rate command 2-597
Smartports macros
See macros
SNMP host, specifying 2-603
SNMP informs, enabling the sending of 2-599
snmp-server enable traps command 2-599
snmp-server host command 2-603
snmp trap mac-notification command 2-607
SNMP traps
enabling MAC address notification trap 2-607
enabling the MAC address notification feature 2-254
enabling the sending of 2-599
SoftPhone
See Cisco SoftPhone
software images
deleting 2-79
downloading 2-8
upgrading 2-8
uploading 2-14
software version, displaying 2-578
source ports, MVR 2-319
SPAN
configuring 2-311
debug messages, display B-21
displaying 2-539
filter SPAN traffic 2-311
sessions
add interfaces to 2-311
displaying 2-539
start new 2-311
spanning 2-647
spanning-tree backbonefast command 2-609
spanning-tree bpdufilter command 2-610
spanning-tree bpduguard command 2-612
spanning-tree cost command 2-614
spanning-tree etherchannel command 2-616
spanning-tree extend system-id command 2-618
spanning-tree guard command 2-619
spanning-tree link-type command 2-621
spanning-tree loopguard default command 2-623
spanning-tree mode command 2-625
spanning-tree mst configuration command 2-627
spanning-tree mst cost command 2-629
spanning-tree mst forward-time command 2-631
spanning-tree mst hello-time command 2-632
spanning-tree mst max-age command 2-633
spanning-tree mst max-hops command 2-634
spanning-tree mst port-priority command 2-635
spanning-tree mst pre-standard command 2-637
spanning-tree mst priority command 2-638
spanning-tree mst root command 2-639
spanning-tree portfast (global configuration) command 2-643
spanning-tree portfast (interface configuration) command 2-645
spanning-tree port-priority command 2-641
Spanning Tree Protocol
See STP
spanning-tree transmit hold-count command 2-647
spanning-tree uplinkfast command 2-648
spanning-tree vlan command 2-650
speed command 2-653
srr-queue bandwidth limit command 2-655
srr-queue bandwidth shape command 2-657
srr-queue bandwidth share command 2-659
SSH, configuring version 2-202
static-access ports, configuring 2-666
statistics, Ethernet group 2-369
sticky learning, enabling 2-683
storm-control command 2-661
STP
BackboneFast 2-609
counters, clearing 2-73
debug messages, display
BackboneFast events B-72
MSTP B-75
optimized BPDUs handling B-74
spanning-tree activity B-70
switch shim B-77
transmitted and received BPDUs B-73
UplinkFast B-79
detection of indirect link failures 2-609
enabling protocol tunneling for 2-227
EtherChannel misconfiguration 2-616
extended system ID 2-618
path cost 2-614
protocol modes 2-625
root port
accelerating choice of new 2-648
loop guard 2-619
preventing from becoming designated 2-619
restricting which can be root 2-619
root guard 2-619
UplinkFast 2-648
STP (continued)
root switch
affects of extended system ID 2-618, 2-651
hello-time 2-650
interval between BDPU messages 2-650
interval between hello BPDU messages 2-650
max-age 2-650
port priority for selection of 2-641
primary or secondary 2-650
switch priority 2-650
state changes
blocking to forwarding state 2-645
enabling BPDU filtering 2-610, 2-643
enabling BPDU guard 2-612, 2-643
enabling Port Fast 2-643, 2-645
enabling timer to recover from error state 2-139
forward-delay time 2-650
length of listening and learning states 2-650
shutting down Port Fast-enabled ports 2-643
state information display 2-566
VLAN options 2-638, 2-650
SVIs, creating 2-151
SVI status calculation 2-668
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-664
returning to interfaces 2-664
switchport access command 2-666
switchport autostate exclude command 2-668
switchport backup interface command 2-670
switchport block command 2-674
switchport command 2-664
switchport host command 2-675
switchport mode command 2-676
switchport mode private-vlan command 2-679
switchport nonegotiate command 2-681
switchport port-security aging command 2-688
switchport port-security command 2-683
switchport priority extend command 2-690
switchport private-vlan command 2-692
switchport protected command 2-694
switchports, displaying 2-439
switchport trunk command 2-696
switchport voice vlan command 2-699
system message logging, save message to flash 2-243
system mtu command 2-701
system resource templates 2-370
T
tar files, creating, listing, and extracting 2-11
templates, system resources 2-370
traceroute mac command 2-703
traceroute mac ip command 2-706
trunking, VLAN mode 2-676
trunk mode 2-676
trunk ports 2-676
trunks, to non-DTP device 2-677
trusted boundary for QoS 2-308
trusted port states for QoS 2-308
tunnel ports, Layer 2 protocol, displaying 2-488
type (boot loader) command A-23
U
UDLD
aggressive mode 2-710, 2-712
debug messages, display B-86
enable globally 2-710
enable per interface 2-712
error recovery timer 2-139
message timer 2-710
normal mode 2-710, 2-712
reset a shutdown interface 2-714
status 2-575
udld command 2-710
udld port command 2-712
udld reset command 2-714
unicast storm control 2-661
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-674
unknown unicast traffic, preventing 2-674
unset (boot loader) command A-24
upgrading
software images 2-8
monitoring status of 2-386
upgrading information
See release notes
UplinkFast, for STP 2-648
user EXEC mode 1-2, 1-3
V
version (boot loader) command A-26
VLAN
enabling guest VLAN supplicant 2-91, 2-102
vlan (global configuration) command 2-715
vlan (VLAN configuration) command 2-721
vlan access-map command 2-727
VLAN access map configuration mode 2-727
VLAN access maps
actions 2-6
displaying 2-586
VLAN-based QoS 2-310
VLAN configuration
rules 2-718, 2-723
saving 2-715, 2-725
VLAN configuration mode
commands
VLAN 2-721
VTP 2-744
description 1-5
entering 2-729
summary 1-2
vlan database command 2-729
vlan dot1q tag native command 2-732
vlan filter command 2-733
VLAN filters, displaying 2-587
VLAN ID range 2-715, 2-721
VLAN maps
applying 2-733
creating 2-727
defining 2-268
displaying 2-586
VLAN Query Protocol
See VQP
VLANs
adding 2-715
configuring 2-715, 2-721
debug messages, display
ISL B-83
VLAN IOS file system error tests B-82
VLAN manager activity B-80
VTP B-84
displaying configurations 2-580
enabling guest VLAN supplicant 2-144
extended-range 2-715
MAC addresses
displaying 2-523
number of 2-510
media types 2-718, 2-723
normal-range 2-715, 2-721
private 2-679
configuring 2-354
displaying 2-580
See also private VLANs
restarting 2-596
saving the configuration 2-715
shutting down 2-596
SNMP traps for VTP 2-601, 2-604
suspending 2-596
variables 2-721
VLAN Trunking Protocol
See VTP
VMPS
configuring servers 2-738
displaying 2-588
error recovery timer 2-140
reconfirming dynamic VLAN assignments 2-735
vmps reconfirm (global configuration) command 2-736
vmps reconfirm (privileged EXEC) command 2-735
vmps retry command 2-737
vmps server command 2-738
voice VLAN
configuring 2-699
setting port priority 2-690
VQP
and dynamic-access ports 2-666
clearing client statistics 2-75
displaying information 2-588
per-server retry count 2-737
reconfirmation interval 2-736
reconfirming dynamic VLAN assignments 2-735
VTP
changing characteristics 2-740
clearing pruning counters 2-76
configuring
domain name 2-740, 2-744
file name 2-740
mode 2-740, 2-744
password 2-740, 2-744
counters display fields 2-591
displaying information 2-590
enabling
pruning 2-740, 2-744
tunneling for 2-227
Version 2 2-740, 2-744
mode 2-740, 2-744
pruning 2-740, 2-744
saving the configuration 2-715, 2-725
statistics 2-590
VTP (continued)
status 2-590
status display fields 2-592
vtp (global configuration) command 2-740
vtp (VLAN configuration) command 2-744
X
XENPAK module serial EERPOM information 2-437