Table Of Contents
A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - Q - R - S - T - U - V -
Index
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5
AAA methods 2-3
abort command 2-766
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-144
MAC, displaying 2-529
access list, IPv6 2-209
access map configuration mode 2-276
access mode 2-708
access ports 2-708
ACEs 2-83, 2-344
ACLs
deny 2-81
displaying 2-392
for non-IP protocols 2-254
IP 2-144
matching 2-276
on Layer 2 interfaces 2-144
permit 2-342
action command 2-6
aggregate-port learner 2-331
allowed VLANs 2-728
apply command 2-766
archive copy-sw command 2-8
archive download-sw command 2-11
archive tar command 2-15
archive upload-sw command 2-18
arp (boot loader) command A-2
arp access-list command 2-20
authentication failed VLAN
See dot1x auth-fail vlan
auth-fail max-attempts
See dot1x auth-fail max-attempts
auth-fail vlan
See dot1x auth-fail vlan
authorization state of controlled port 2-114
autonegotiation of duplex mode 2-122
auto qos voip command 2-22
B
BackboneFast, for STP 2-633
backup interfaces
configuring 2-703
displaying 2-454
boot (boot loader) command A-3
boot auto-copy-sw command 2-26
boot auto-download-sw command 2-27
boot config-file command 2-29
boot enable-break command 2-30
boot helper command 2-31
boot helper-config file command 2-32
booting
Cisco IOS image 2-35
displaying environment variables 2-401
interrupting 2-30
manually 2-33
boot loader
accessing A-1
booting
Cisco IOS image A-3
helper image 2-31
directories
creating A-19
displaying a list of A-8
removing A-23
displaying
available commands A-13
memory heap utilization A-14
version A-30
environment variables
described A-24
displaying settings A-24
location of A-25
setting A-24
unsetting A-28
files
copying A-6
deleting A-7
displaying a list of A-8
displaying the contents of A-5, A-20, A-27
renaming A-21
file system
formatting A-11
initializing flash A-10
running a consistency check A-12
prompt A-1
resetting the system A-22
boot manual command 2-33
boot private-config-file command 2-34
boot system command 2-35
BPDU filtering, for spanning tree 2-634, 2-668
BPDU guard, for spanning tree 2-636, 2-668
broadcast storm control 2-689
C
cat (boot loader) command A-5
CDP, enabling protocol tunneling for 2-235
channel-group command 2-37
channel-protocol command 2-41
Cisco SoftPhone
auto-QoS configuration 2-22
trusting packets sent from 2-317
class command 2-42
class-map command 2-44
class maps
creating 2-44
defining the match criteria 2-278
displaying 2-406
class of service
See CoS
clear dot1x command 2-46
clear eap command 2-47
clear errdisable interface 2-48
clear ip arp inspection log command 2-49
clear ip arp inspection statistics command 2-50
clear ipc command 2-55
clear ip dhcp snooping database command 2-51, 2-53
clear ipv6 dhcp conflict command 2-56
clear l2protocol-tunnel counters command 2-57
clear lacp command 2-58
clear logging command 2-59
clear mac address-table command 2-60, 2-61
clear pagp command 2-62
clear port-security command 2-63
clear spanning-tree counters command 2-65
clear spanning-tree detected-protocols command 2-66
clear vmps statistics command 2-67
clear vtp counters command 2-68
command modes defined 1-2
configuration files
password recovery disable considerations A-1
specifying the name 2-29, 2-34
configuring multiple interfaces 2-140
config-vlan mode
commands 2-752
description 1-5
entering 2-751
summary 1-2
copy (boot loader) command A-6
copy logging onboard command 2-69
CoS
assigning default value to incoming packets 2-287
assigning to Layer 2 protocol packets 2-238
overriding the incoming value 2-287
CoS-to-DSCP map 2-291
CPU ASIC statistics, displaying 2-407
crashinfo files 2-131
D
debug auto qos command B-2
debug backup command B-4
debug dot1x command B-5
debug dtp command B-6
debug eap command B-7
debug etherchannel command B-8
debug fastethernet command B-9
debug interface command B-12
debug ip dhcp snooping command B-10
debug ip igmp filter command B-13
debug ip igmp max-groups command B-14
debug ip igmp snooping command B-15
debug ip verify source packet command B-11
debug lacp command B-16
debug mac-notification command B-17
debug matm command B-18
debug matm move update command B-19
debug monitor command B-20
debug mvrdbg command B-21
debug nvram command B-22
debug pagp command B-23
debug platform acl command B-24
debug platform backup interface command B-26
debug platform cli-redirection main command B-27
debug platform configuration command B-28
debug platform cpu-queues command B-29
debug platform device-manager command B-31
debug platform dot1x command B-32
debug platform etherchannel command B-33
debug platform fallback-bridging command B-34
debug platform forw-tcam command B-35
debug platform ip arp inspection command B-36
debug platform ipc command B-45
debug platform ip dhcp command B-37
debug platform ip igmp snooping command B-38
debug platform ip multicast command B-40
debug platform ip unicast command B-42
debug platform ip wccp command B-44
debug platform led command B-46
debug platform matm command B-47
debug platform messaging application command B-48
debug platform phy command B-50
debug platform pm command B-52
debug platform port-asic command B-54
debug platform port-security command B-55
debug platform qos-acl-tcam command B-56
debug platform remote-commands command B-57
debug platform resource-manager command B-58
debug platform snmp command B-59
debug platform span command B-60
debug platform stack-manager command B-61
debug platform supervisor-asic command B-62
debug platform sw-bridge command B-63
debug platform tcam command B-64
debug platform udld command B-67
debug platform vlan command B-68
debug pm command B-69
debug port-security command B-71
debug qos-manager command B-72
debug spanning-tree backbonefast command B-75
debug spanning-tree bpdu command B-76
debug spanning-tree bpdu-opt command B-77
debug spanning-tree command B-73
debug spanning-tree mstp command B-78
debug spanning-tree switch command B-80
debug spanning-tree uplinkfast command B-82
debug sw-vlan command B-83
debug sw-vlan ifs command B-85
debug sw-vlan notification command B-86
debug sw-vlan vtp command B-88
debug udld command B-90
debug vqpc command B-92
define interface-range command 2-71
delete (boot loader) command A-7
delete command 2-73
deny (ARP access-list configuration) command 2-74
deny (IPv6) command 2-76
deny command 2-81
detect mechanism, causes 2-124
DHCP snooping
accepting untrusted packets from edge switch 2-172
enabling
on a VLAN 2-178
option 82 2-170, 2-172
trust on an interface 2-176
error recovery timer 2-128
rate limiting 2-175
DHCP snooping binding database
binding file, configuring 2-168
bindings
adding 2-166
deleting 2-166
displaying 2-475
clearing database agent statistics 2-51, 2-53
database agent, configuring 2-168
DHCP snooping binding database (continued)
displaying
binding entries 2-475
database agent status 2-477, 2-479
renewing 2-373
dir (boot loader) command A-8
directories, deleting 2-73
domain name, VTP 2-777, 2-781
dot1x auth-fail max-attempts 2-93
dot1x auth-fail vlan 2-95
dot1x command 2-91
dot1x control-direction command 2-97
dot1x critical global configuration command 2-99
dot1x critical interface configuration command 2-101
dot1x default command 2-103
dot1x fallback command 2-104
dot1x guest-vlan command 2-105
dot1x host-mode command 2-107
dot1x initialize command 2-108
dot1x mac-auth-bypass command 2-109
dot1x max-reauth-req command 2-111
dot1x max-req command 2-112
dot1x pae command 2-113
dot1x port-control command 2-114
dot1x re-authenticate command 2-116
dot1x reauthentication command 2-117
dot1x timeout command 2-118
dot1x violation-mode command 2-120
dropping packets, with ACL matches 2-6
drop threshold, Layer 2 protocol tunneling 2-235
DSCP-to-CoS map 2-291
DSCP-to-DSCP-mutation map 2-291
DTP 2-709
DTP flap
error detection for 2-124
error recovery timer 2-128
DTP negotiation 2-713
dual IPv4 and IPv6 templates 2-337
duplex command 2-122
dynamic-access ports
configuring 2-699
restrictions 2-700
dynamic ARP inspection
ARP ACLs
apply to a VLAN 2-152
define 2-20
deny packets 2-74
display 2-396
permit packets 2-335
clear
log buffer 2-49
statistics 2-50
display
ARP ACLs 2-396
configuration and operating state 2-470
log buffer 2-470
statistics 2-470
trust state and rate limit 2-470
enable per VLAN 2-162
error detection for 2-124
error recovery timer 2-128
log buffer
clear 2-49
configure 2-156
display 2-470
rate-limit incoming ARP packets 2-154
statistics
clear 2-50
display 2-470
trusted interface state 2-158
type of packet logged 2-163
validation checks 2-160
dynamic auto VLAN membership mode 2-708
dynamic desirable VLAN membership mode 2-708
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-112
response time before retransmitting 2-118
encapsulation methods 2-728
environment variables, displaying 2-401
errdisable detect cause command 2-124
errdisable detect cause small-frame comand 2-126
errdisable recovery cause small-frame 2-130
errdisable recovery command 2-128
error conditions, displaying 2-442
error disable detection 2-124
error-disabled interfaces, displaying 2-454
EtherChannel
assigning Ethernet interface to channel group 2-37
creating port-channel logical interface 2-138
debug EtherChannel/PAgP, display B-8
debug platform-specific events, display B-33
displaying 2-445
enabling Layer 2 protocol tunneling for
LACP 2-236
PAgP 2-236
UDLD 2-236
interface information, displaying 2-454
LACP
clearing channel-group information 2-58, 2-59
debug messages, display B-16
displaying 2-515
modes 2-37
port priority for hot-standby ports 2-239
restricting a protocol 2-41
system priority 2-241
load-distribution methods 2-353
EtherChannel (continued)
PAgP
aggregate-port learner 2-331
clearing channel-group information 2-62
debug messages, display B-23
displaying 2-575
error detection for 2-124
error recovery timer 2-128
learn method 2-331
modes 2-37
physical-port learner 2-331
priority of interface for transmitted traffic 2-333
Ethernet controller, internal register display 2-409, 2-416
Ethernet Management port, debugging B-9
Ethernet statistics, collecting 2-375
exception crashinfo command 2-131, 2-136
exit command 2-766
extended-range VLANs
and allowed VLAN list 2-728
and pruning-eligible list 2-728
configuring 2-751
extended system ID for STP 2-642
F
fallback profile command 2-132
fallback profiles, displaying 2-448
fan information, displaying 2-438
file name, VTP 2-777
files, deleting 2-73
flash_init (boot loader) command A-10
Flex Links
configuring 2-703
displaying 2-454
flowcontrol command 2-134
format (boot loader) command A-11
forwarding packets, with ACL matches 2-6
forwarding results, display C-9
frame forwarding information, displaying C-9
front-end controller counter and status information C-11
fsck (boot loader) command A-12
G
global configuration mode 1-2, 1-4
H
hardware ACL statistics 2-392
health monitoring diagnostic tests 2-84
help (boot loader) command A-13
hierarchical policy maps 2-351
host connection, port configuration 2-707
host ports, private VLANs 2-711
I
IEEE 802.1Q trunk ports and native VLANs 2-768
IEEE 802.1Q tunnel ports
configuring 2-708
displaying 2-428
limitations 2-709
IEEE 802.1x
and switchport modes 2-709
violation error recovery 2-128
See also port-based authentication
IGMP filters
applying 2-181
debug messages, display B-13
IGMP groups, setting maximum 2-183
IGMP maximum groups, debugging B-14
IGMP profiles
creating 2-185
displaying 2-482
IGMP snooping
adding ports as a static member of a group 2-201
displaying 2-483, 2-488, 2-490
enabling 2-187
enabling the configurable-leave timer 2-189
enabling the Immediate-Leave feature 2-198
flooding query count 2-195
interface topology change notification behavior 2-197
multicast table 2-486
querier 2-191
query solicitation 2-195
report suppression 2-193
switch topology change notification behavior 2-195
images
See software images
Immediate-Leave processing
IGMP 2-198
IPv6 2-231
MVR 2-327
interface configuration mode 1-2, 1-4
interface port-channel command 2-138
interface range command 2-140
interface-range macros 2-71
interfaces
assigning Ethernet interface to channel group 2-37
configuring 2-122
configuring multiple 2-140
creating port-channel logical 2-138
debug messages, display B-12
disabling 2-619
displaying the MAC address table 2-541
restarting 2-619
interface speed, configuring 2-679
interface vlan command 2-142
internal registers, displaying 2-409, 2-416, 2-419
Internet Group Management Protocol
See IGMP
ip access-group command 2-144
ip address command 2-147
IP addresses, setting 2-147
IP address matching 2-276
ip admission command 2-149
ip admission name proxy http command 2-150
ip arp inspection filter vlan command 2-152
ip arp inspection limit command 2-154
ip arp inspection log-buffer command 2-156
ip arp inspection trust command 2-158
ip arp inspection validate command 2-160
ip arp inspection vlan command 2-162
ip arp inspection vlan logging command 2-163
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-166
ip dhcp snooping command 2-165
ip dhcp snooping database command 2-168
ip dhcp snooping information option allow-untrusted command 2-172
ip dhcp snooping information option command 2-170
ip dhcp snooping information option format remote-id command 2-174
ip dhcp snooping limit rate command 2-175
ip dhcp snooping trust command 2-176
ip dhcp snooping verify command 2-177
ip dhcp snooping vlan command 2-178
ip dhcp snooping vlan information option format-type circuit-id string command 2-179
ip igmp filter command 2-181
ip igmp max-groups command 2-183
ip igmp profile command 2-185
ip igmp snooping command 2-187
ip igmp snooping last-member-query-interval command 2-189
ip igmp snooping querier command 2-191
ip igmp snooping report-suppression command 2-193
ip igmp snooping tcn command 2-195
ip igmp snooping tcn flood command 2-197
ip igmp snooping vlan immediate-leave command 2-198
ip igmp snooping vlan mrouter command 2-199
ip igmp snooping vlan static command 2-201
IP multicast addresses 2-324
IP phones
auto-QoS configuration 2-22
trusting packets sent from 2-317
IP-precedence-to-DSCP map 2-291
ip snap forwarding command 2-203
ip source binding command 2-204
IP source guard
disabling 2-208
displaying
binding entries 2-492
configuration 2-493
dynamic binding entries only 2-475
enabling 2-208
static IP source bindings 2-204
ip ssh command 2-206
IPv6 access list, deny conditions 2-76
ipv6 access-list command 2-209
ipv6 address dhcp command 2-211
ipv6 dhcp client request vendor command 2-212
ipv6 dhcp ping packets command 2-213
ipv6 dhcp pool command 2-215
ipv6 dhcp server command 2-217
ipv6 mld snooping command 2-219
ipv6 mld snooping last-listener-query count command 2-221
ipv6 mld snooping last-listener-query-interval command 2-223
ipv6 mld snooping listener-message-suppression command 2-225
ipv6 mld snooping robustness-variable command 2-227
ipv6 mld snooping tcn command 2-229
ipv6 mld snooping vlan command 2-231
IPv6 SDM template 2-376
ipv6 traffic-filter command 2-233
ip verify source command 2-208
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-235
l2protocol-tunnel cos command 2-238
LACP
See EtherChannel
lacp port-priority command 2-239
lacp system-priority command 2-241
Layer 2 mode, enabling 2-697
Layer 2 protocol ports, displaying 2-512
Layer 2 protocol-tunnel
error detection for 2-124
error recovery timer 2-128
Layer 2 protocol tunnel counters 2-57
Layer 2 protocol tunneling error recovery 2-236
Layer 2 traceroute
IP addresses 2-742
MAC addresses 2-739
Layer 3 mode, enabling 2-697
line configuration mode 1-3, 1-6
Link Aggregation Control Protocol
See EtherChannel
link flap
error detection for 2-124
error recovery timer 2-128
link state group command 2-243
link state track command 2-245
load-distribution methods for EtherChannel 2-353
location (global configuration) command 2-246
location (interface configuration) command 2-248
logging file command 2-250
logical interface 2-138
loopback error
detection for 2-124
recovery timer 2-128
loop guard, for spanning tree 2-644, 2-648
M
mac access-group command 2-252
MAC access-groups, displaying 2-529
MAC access list configuration mode 2-254
mac access-list extended command 2-254
MAC access lists 2-81
MAC addresses
disabling MAC address learning per VLAN 2-257
displaying
aging time 2-535
all 2-533
dynamic 2-539
MAC address-table move updates 2-544
notification settings 2-543, 2-546
number of addresses in a VLAN 2-537
per interface 2-541
per VLAN 2-550
static 2-548
static and dynamic entries 2-531
dynamic
aging time 2-256
deleting 2-60
displaying 2-539
enabling MAC address notification 2-261
enabling MAC address-table move update 2-259
matching 2-276
persistent stack 2-687
static
adding and removing 2-263
displaying 2-548
dropping on an interface 2-264
tables 2-533
MAC address notification, debugging B-17
mac address-table aging-time 2-252, 2-276
mac address-table aging-time command 2-256
mac address-table learning command 2-257
mac address-table move update command 2-259
mac address-table notification command 2-261
mac address-table static command 2-263
mac address-table static drop command 2-264
MAC frames
See MTU
macro apply command 2-266
macro description command 2-269
macro global command 2-270
macro global description command 2-273
macro name command 2-274
macros
adding a description 2-269
adding a global description 2-273
applying 2-270
creating 2-274
displaying 2-577
interface range 2-71, 2-140
specifying parameter values 2-270
tracing 2-270
maps
QoS
defining 2-291
displaying 2-560
VLAN
creating 2-763
defining 2-276
displaying 2-611
match (access-map configuration) command 2-276
match (class-map configuration) command 2-278
maximum transmission unit
See MTU
mdix auto command 2-281
memory (boot loader) command A-14
mgmt_clr (boot loader) command A-16
mgmt_init (boot loader) command A-17, A-18
mkdir (boot loader) command A-19
MLD snooping
configuring 2-225, 2-227
configuring queries 2-221, 2-223
configuring topology change notification 2-229
displaying 2-502, 2-504, 2-506, 2-508
enabling 2-219
enabling on a VLAN 2-231
mls qos aggregate-policer command 2-285
mls qos command 2-283
mls qos cos command 2-287
mls qos dscp-mutation command 2-289
mls qos map command 2-291
mls qos queue-set output buffers command 2-295
mls qos queue-set output threshold command 2-297
mls qos rewrite ip dscp command 2-299
mls qos srr-queue input bandwidth command 2-301
mls qos srr-queue input buffers command 2-303
mls qos-srr-queue input cos-map command 2-305
mls qos srr-queue input dscp-map command 2-307
mls qos srr-queue input priority-queue command 2-309
mls qos srr-queue input threshold command 2-311
mls qos-srr-queue output cos-map command 2-313
mls qos srr-queue output dscp-map command 2-315
mls qos trust command 2-317
mls qos vlan-based command 2-319
mode, MVR 2-324
Mode button, and password recovery 2-379
modes, commands 1-2
monitor session command 2-320
more (boot loader) command A-20
MSTP
displaying 2-590
interoperability 2-66
link type 2-646
MSTP (continued)
MST region
aborting changes 2-652
applying changes 2-652
configuration name 2-652
configuration revision number 2-652
current or pending display 2-652
displaying 2-590
MST configuration mode 2-652
VLANs-to-instance mapping 2-652
path cost 2-654
protocol mode 2-650
restart protocol migration process 2-66
root port
loop guard 2-644
preventing from becoming designated 2-644
restricting which can be root 2-644
root guard 2-644
root switch
affects of extended system ID 2-642
hello-time 2-657, 2-664
interval between BDPU messages 2-658
interval between hello BPDU messages 2-657, 2-664
max-age 2-658
maximum hop count before discarding BPDU 2-659
port priority for selection of 2-660
primary or secondary 2-664
switch priority 2-663
state changes
blocking to forwarding state 2-671
enabling BPDU filtering 2-634, 2-668
enabling BPDU guard 2-636, 2-668
enabling Port Fast 2-668, 2-671
forward-delay time 2-656
length of listening and learning states 2-656
MSTP (continued)
state changes (continued)
rapid transition to forwarding 2-646
shutting down Port Fast-enabled ports 2-668
state information display 2-589
MTU
configuring size 2-736
displaying global setting 2-600
Multicase Listener Discovery
See MLD
multicast group address, MVR 2-327
multicast groups, MVR 2-325
Multicast Listener Discovery
See MLD
multicast router learning method 2-199
multicast router ports, configuring 2-199
multicast router ports, IPv6 2-231
multicast storm control 2-689
multicast VLAN, MVR 2-324
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-107
Multiple Spanning Tree Protocol
See MSTP
MVR
configuring 2-324
configuring interfaces 2-327
debug messages, display B-21
displaying 2-569
displaying interface information 2-571
members, displaying 2-573
mvr (global configuration) command 2-324
mvr (interface configuration) command 2-327
mvr vlan group command 2-328
N
native VLANs 2-728
native VLAN tagging 2-768
nonegotiate
DTP messaging 2-713
non-IP protocols
denying 2-81
forwarding 2-342
non-IP traffic access lists 2-254
non-IP traffic forwarding
denying 2-81
permitting 2-342
non-stop forwarding 2-329
normal-range VLANs 2-751, 2-757
no vlan command 2-751, 2-761
nsf command 2-329
O
online diagnostics
configuring health monitoring diagnostic tests 2-84
displaying
configured boot-up coverage level 2-423
current scheduled tasks 2-423
event logs 2-423
supported test suites 2-423
test ID 2-423
test results 2-423
test statistics 2-423
enabling
scheduling 2-86
syslog messages 2-84
global configuration mode
clearing health monitoring diagnostic test schedule 2-84
clearing test-based testing schedule 2-86
setting health monitoring diagnostic testing 2-84
setting test-based testing 2-86
setting up health monitoring diagnostic test schedule 2-84
setting up test-based testing 2-86
removing scheduling 2-86
online diagnostics (continued)
scheduled switchover
disabling 2-86
enabling 2-86
setting test interval 2-86
specifying health monitoring diagnostic tests 2-84
starting testing 2-88
P
PAgP
See EtherChannel
pagp learn-method command 2-331
pagp port-priority command 2-333
password, VTP 2-777, 2-781
password-recovery mechanism, enabling and disabling 2-379
permit (ARP access-list configuration) command 2-335
permit (IPv6) command 2-337
permit (MAC access-list configuration) command 2-342
per-VLAN spanning-tree plus
See STP
physical-port learner 2-331
PID, displaying 2-469
PIM-DVMRP, as multicast router learning method 2-199
platform chassis-management command 2-345
police aggregate command 2-348
police command 2-346
policed-DSCP map 2-291
policy-map command 2-350
policy maps
applying to an interface 2-381, 2-387
creating 2-350
displaying 2-580
hierarchical 2-351
policy maps (continued)
policers
displaying 2-553
for a single class 2-346
for multiple classes 2-285, 2-348
policed-DSCP map 2-291
traffic classification
defining the class 2-42
defining trust states 2-744
setting DSCP or IP precedence values 2-385
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
configuring violation modes 2-120
debug messages, display B-5
enabling guest VLAN supplicant 2-94, 2-104
enabling IEEE 802.1x
globally 2-91
per interface 2-114
guest VLAN 2-105
host modes 2-107
IEEE 802.1x AAA accounting methods 2-1
initialize an interface 2-108
MAC authentication bypass 2-109
manual control of authorization state 2-114
multiple hosts on authorized port 2-107
PAE as authenticator 2-113
periodic re-authentication
enabling 2-117
time between attempts 2-118
quiet period between failed authentication exchanges 2-118
re-authenticating IEEE 802.1x-enabled ports 2-116
resetting configurable IEEE 802.1x parameters 2-103
switch-to-authentication server retransmission time 2-118
switch-to-client frame-retransmission number2-111to 2-112
switch-to-client retransmission time 2-118
port-channel load-balance command 2-353
Port Fast, for spanning tree 2-671
port ranges, defining 2-69, 2-71
ports, debugging B-69
ports, protected 2-726
port security
aging 2-720
debug messages, display B-71
enabling 2-715
violation error recovery 2-128
port trust states for QoS 2-317
port types, MVR 2-327
power information, displaying 2-438
priority-queue command 2-355
priority value, stack member 2-597, 2-692
private-vlan command 2-357
private-vlan mapping command 2-360
private VLANs
association 2-724
configuring 2-357
configuring ports 2-711
displaying 2-606
host ports 2-711
mapping
configuring 2-724
displaying 2-454
promiscuous ports 2-711
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-469
promiscuous ports, private VLANs 2-711
protected ports, displaying 2-460
pruning
VLANs 2-728
VTP
displaying interface information 2-454
enabling 2-777, 2-781
pruning-eligible VLAN list 2-730
PVST+
See STP
Q
QoS
auto-QoS
configuring 2-22
debug messages, display B-2
displaying 2-397
class maps
creating 2-44
defining the match criteria 2-278
displaying 2-406
defining the CoS value for an incoming packet 2-287
displaying configuration information 2-397, 2-552
DSCP transparency 2-299
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-289
defining DSCP-to-DSCP-mutation map 2-291
egress queues
allocating buffers 2-295
defining the CoS output queue threshold map 2-313
defining the DSCP output queue threshold map 2-315
displaying buffer allocations 2-556
displaying CoS output queue threshold map 2-560
displaying DSCP output queue threshold map 2-560
displaying queueing strategy 2-556
displaying queue-set settings 2-563
enabling bandwidth shaping and scheduling 2-683
enabling bandwidth sharing and scheduling 2-685
limiting the maximum output on a port 2-681
mapping a port to a queue-set 2-362
mapping CoS values to a queue and threshold 2-313
mapping DSCP values to a queue and threshold 2-315
QoS (continued)
egress queues (continued)
setting maximum and reserved memory allocations 2-297
setting WTD thresholds 2-297
enabling 2-283
ingress queues
allocating buffers 2-303
assigning SRR scheduling weights 2-301
defining the CoS input queue threshold map 2-305
defining the DSCP input queue threshold map 2-307
displaying buffer allocations 2-556
displaying CoS input queue threshold map 2-560
displaying DSCP input queue threshold map 2-560
displaying queueing strategy 2-556
displaying settings for 2-554
enabling the priority queue 2-309
mapping CoS values to a queue and threshold 2-305
mapping DSCP values to a queue and threshold 2-307
setting WTD thresholds 2-311
maps
defining 2-291, 2-305, 2-307, 2-313, 2-315
displaying 2-560
policy maps
applying an aggregate policer 2-348
applying to an interface 2-381, 2-387
creating 2-350
defining policers 2-285, 2-346
displaying policers 2-553
displaying policy maps 2-580
hierarchical 2-351
policed-DSCP map 2-291
setting DSCP or IP precedence values 2-385
traffic classifications 2-42
trust states 2-744
QoS (continued)
port trust states 2-317
queues, enabling the expedite 2-355
statistics
in-profile and out-of-profile packets 2-556
packets enqueued or dropped 2-556
sent and received CoS values 2-556
sent and received DSCP values 2-556
trusted boundary for IP phones 2-317
VLAN-based 2-319
quality of service
See QoS
querytime, MVR 2-324
queue-set command 2-362
R
radius-server dead-criteria command 2-363
radius-server host command 2-365
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
re-authenticating IEEE 802.1x-enabled ports 2-116
re-authentication
periodic 2-117
time between attempts 2-118
receiver ports, MVR 2-327
receiving flow-control packets 2-134
recovery mechanism
causes 2-128
display 2-48, 2-404, 2-440, 2-443
timer interval 2-128
reload command 2-367
remote command 2-369
remote-span command 2-371
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-21
renew ip dhcp snooping database command 2-373
reset (boot loader) command A-22
reset command 2-766
resource templates, displaying 2-585
restricted VLAN
See dot1x auth-fail vlan
rmdir (boot loader) command A-23
rmon collection stats command 2-375
root guard, for spanning tree 2-644
routed ports
IP addresses on 2-148
number supported 2-148
routing frames
See MTU
RSPAN
configuring 2-320
displaying 2-566
filter RSPAN traffic 2-320
remote-span command 2-371
sessions
add interfaces to 2-320
displaying 2-566
start new 2-320
S
scheduled switchover
disabling 2-86
enabling 2-86
SDM mismatch mode 2-377, 2-598
sdm prefer command 2-376
SDM templates
allowed resources 2-377
and stacking 2-377
displaying 2-585
dual IPv4 and IPv6 2-376
secure ports, limitations 2-717
sending flow-control packets 2-134
service password-recovery command 2-379
service-policy command 2-381
session command 2-384
set (boot loader) command A-24
set command 2-385
setup command 2-387
setup express command 2-390
show access-lists command 2-392
show archive status command 2-395
show arp access-list command 2-396
show auto qos command 2-397
show boot command 2-401
show cable-diagnostics tdr command 2-404
show changes command 2-766
show class-map command 2-406
show controllers cpu-interface command 2-407
show controllers ethernet-controller command 2-409
show controllers ethernet-controller fastethernet command 2-416
show controllers tcam command 2-419
show controller utilization command 2-421
show current command 2-766
show dot1q-tunnel command 2-428
show dot1x command 2-429
show dtp 2-433
show eap command 2-435
show env command 2-438
show errdisable detect command 2-440
show errdisable flap-values command 2-442
show errdisable recovery command 2-443
show etherchannel command 2-445
show fallback profile command 2-448
show flowcontrol command 2-450
show idprom command 2-452
show interfaces command 2-454
show interfaces counters command 2-466
show inventory command 2-469
show ip arp inspection command 2-470
show ipc command 2-495
show ip dhcp snooping binding command 2-475
show ip dhcp snooping command 2-474
show ip dhcp snooping database command 2-477, 2-479
show ip igmp profile command 2-482
show ip igmp snooping address command 2-504
show ip igmp snooping command 2-483, 2-502
show ip igmp snooping groups command 2-486
show ip igmp snooping mrouter command 2-488, 2-506
show ip igmp snooping querier command 2-490, 2-508
show ip source binding command 2-492
show ipv6 access-list command 2-499
show ipv6 dhcp conflict command 2-501
show ipv6 route updated 2-510
show ip verify source command 2-493
show l2protocol-tunnel command 2-512
show lacp command 2-515
show link state group command 2-519
show location 2-521
show location command 2-521
show logging command 2-524
show mac access-group command 2-529
show mac address-table address command 2-533
show mac address-table aging time command 2-535
show mac address-table command 2-531
show mac address-table count command 2-537
show mac address-table dynamic command 2-539
show mac address-table interface command 2-541
show mac address-table learning command 2-543
show mac address-table move update command 2-544
show mac address-table notification command 2-61, 2-546, B-19
show mac address-table static command 2-548
show mac address-table vlan command 2-550
show mls qos aggregate-policer command 2-553
show mls qos command 2-552
show mls qos input-queue command 2-554
show mls qos interface command 2-556
show mls qos maps command 2-560
show mls qos queue-set command 2-563
show mls qos vlan command 2-565
show monitor command 2-566
show mvr command 2-569
show mvr interface command 2-571
show mvr members command 2-573
show pagp command 2-575
show parser macro command 2-577
show platform acl command C-2
show platform backup interface command C-3
show platform chassis command C-4
show platform configuration command C-6
show platform dl command C-7
show platform etherchannel command C-8
show platform forward command C-9
show platform frontend-controller command C-11
show platform igmp snooping command C-12
show platform ipc trace command C-20
show platform ip multicast command C-14
show platform ip unicast command C-15
show platform ipv6 unicast command C-21
show platform ip wccp command C-19
show platform layer4op command C-23
show platform mac-address-table command C-24
show platform messaging command C-25
show platform monitor command C-26
show platform mvr table command C-27
show platform pm command C-28
show platform port-asic command C-30
show platform port-security command C-35
show platform qos command C-36
show platform resource-manager command C-37
show platform snmp counters command C-39
show platform spanning-tree command C-40
show platform stack-manager command C-42
show platform stp-instance command C-41
show platform summary command C-44
show platform tb command C-45
show platform tcam command C-47
show platform vlan command C-50
show policy-map command 2-580
show port security command 2-582
show proposed command 2-766
show sdm prefer command 2-585
show setup express command 2-588
show spanning-tree command 2-589
show storm-control command 2-595
show switch command 2-597
show system mtu command 2-600
show trust command 2-744
show udld command 2-601
show version command 2-604
show vlan access-map command 2-611
show vlan command 2-606
show vlan command, fields 2-608
show vlan filter command 2-612
show vmps command 2-613
show vtp command 2-615
shutdown command 2-619
shutdown threshold, Layer 2 protocol tunneling 2-235
shutdown vlan command 2-620
small violation-rate command 2-621
Smartports macros
See macros
SNMP host, specifying 2-627
SNMP informs, enabling the sending of 2-623
snmp-server enable traps command 2-623
snmp-server host command 2-627
snmp trap mac-notification command 2-631
SNMP traps
enabling MAC address notification trap 2-631
enabling the MAC address notification feature 2-261
enabling the sending of 2-623
SoftPhone
See Cisco SoftPhone
software images
copying 2-8
deleting 2-73
downloading 2-11
upgrading 2-8, 2-11
uploading 2-18
software version, displaying 2-604
source ports, MVR 2-327
SPAN
configuring 2-320
debug messages, display B-20
displaying 2-566
filter SPAN traffic 2-320
sessions
add interfaces to 2-320
displaying 2-566
start new 2-320
spanning-tree backbonefast command 2-633
spanning-tree bpdufilter command 2-634
spanning-tree bpduguard command 2-636
spanning-tree cost command 2-638
spanning-tree etherchannel command 2-640
spanning-tree extend system-id command 2-642
spanning-tree guard command 2-644
spanning-tree link-type command 2-646
spanning-tree loopguard default command 2-648
spanning-tree mode command 2-650
spanning-tree mst configuration command 2-652
spanning-tree mst cost command 2-654
spanning-tree mst forward-time command 2-656
spanning-tree mst hello-time command 2-657
spanning-tree mst max-age command 2-658
spanning-tree mst max-hops command 2-659
spanning-tree mst port-priority command 2-660
spanning-tree mst pre-standard command 2-662
spanning-tree mst priority command 2-663
spanning-tree mst root command 2-664
spanning-tree portfast (global configuration) command 2-668
spanning-tree portfast (interface configuration) command 2-671
spanning-tree port-priority command 2-666
Spanning Tree Protocol
See STP
spanning-tree transmit hold-count command 2-673
spanning-tree uplinkfast command 2-674
spanning-tree vlan command 2-676
speed command 2-679
srr-queue bandwidth limit command 2-681
srr-queue bandwidth shape command 2-683
srr-queue bandwidth share command 2-685
SSH, configuring version 2-206
stack-mac persistent timer command 2-687
stack member
access 2-384
number 2-597, 2-695
priority value 2-692
provisioning 2-693
reloading 2-367
stacks, switch
MAC address 2-687
provisioning a new member 2-693
reloading 2-367
stack member access 2-384
stack member number 2-597, 2-695
stack member priority value 2-597, 2-692
static-access ports, configuring 2-699
statistics, Ethernet group 2-375
sticky learning, enabling 2-715
storm-control command 2-689
STP
BackboneFast 2-633
counters, clearing 2-65
debug messages, display
BackboneFast events B-75
MSTP B-78
optimized BPDUs handling B-77
spanning-tree activity B-73
switch shim B-80
transmitted and received BPDUs B-76
UplinkFast B-82
detection of indirect link failures 2-633
enabling protocol tunneling for 2-235
EtherChannel misconfiguration 2-640
extended system ID 2-642
path cost 2-638
protocol modes 2-650
root port
accelerating choice of new 2-674
loop guard 2-644
preventing from becoming designated 2-644
restricting which can be root 2-644
root guard 2-644
UplinkFast 2-674
root switch
affects of extended system ID 2-642, 2-677
hello-time 2-676
interval between BDPU messages 2-676
interval between hello BPDU messages 2-676
max-age 2-676
port priority for selection of 2-666
primary or secondary 2-676
switch priority 2-676
STP (continued)
state changes
blocking to forwarding state 2-671
enabling BPDU filtering 2-634, 2-668
enabling BPDU guard 2-636, 2-668
enabling Port Fast 2-668, 2-671
enabling timer to recover from error state 2-128
forward-delay time 2-676
length of listening and learning states 2-676
shutting down Port Fast-enabled ports 2-668
state information display 2-589
VLAN options 2-663, 2-676
SVIs, creating 2-142
SVI status calculation 2-701
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-697
returning to interfaces 2-697
switchport access command 2-699
switchport autostate exclude command 2-701
switchport backup interface command 2-703
switchport block command 2-706
switchport command 2-697
switchport host command 2-707
switchport mode command 2-708
switchport mode private-vlan command 2-711
switchport nonegotiate command 2-713
switchport port-security aging command 2-720
switchport port-security command 2-715
switchport priority extend command 2-722
switchport private-vlan command 2-724
switchport protected command 2-726
switchports, displaying 2-454
switchport trunk command 2-728
switchport voice detect 2-731
switchport voice vlan command 2-732
switch priority command 2-692
switch provision command 2-693
switch renumber command 2-695
system env temperature threshold yellow command 2-734
system message logging, save message to flash 2-250
system mtu command 2-736
system resource templates 2-376
T
tar files, creating, listing, and extracting 2-15
TDR, running 2-738
temperature information, displaying 2-438
templates, system resources 2-376
test cable-diagnostics tdr command 2-738
traceroute mac command 2-739
traceroute mac ip command 2-742
trunking, VLAN mode 2-708
trunk mode 2-708
trunk ports 2-708
trunks, to non-DTP device 2-709
trusted boundary for QoS 2-317
trusted port states for QoS 2-317
tunnel ports, Layer 2 protocol, displaying 2-512
type (boot loader) command A-27
U
UDLD
aggressive mode 2-746, 2-748
debug messages, display B-90
enable globally 2-746
enable per interface 2-748
error recovery timer 2-128
message timer 2-746
normal mode 2-746, 2-748
reset a shutdown interface 2-750
status 2-601
udld command 2-746
udld port command 2-748
udld reset command 2-750
unicast storm control 2-689
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-706
unknown unicast traffic, preventing 2-706
unset (boot loader) command A-28
upgrading
copying software images 2-8
downloading software images 2-11
software images, monitoring status of 2-395
UplinkFast, for STP 2-674
user EXEC mode 1-2, 1-3
V
version (boot loader) command A-30
version mismatch mode 2-598
vlan (global configuration) command 2-751
vlan (VLAN configuration) command 2-757
vlan access-map command 2-763
VLAN access map configuration mode 2-763
VLAN access maps
actions 2-6
displaying 2-611
VLAN-based QoS 2-319
VLAN configuration
rules 2-754, 2-759
saving 2-751, 2-761
VLAN configuration mode
commands
VLAN 2-757
VTP 2-781
description 1-5
entering 2-765
summary 1-3
vlan database command 2-765
vlan dot1q tag native command 2-768
vlan filter command 2-770
VLAN filters, displaying 2-612
VLAN ID range 2-751, 2-757
VLAN maps
applying 2-770
creating 2-763
defining 2-276
displaying 2-611
VLAN Query Protocol
See VQP
VLANs
adding 2-751
configuring 2-751, 2-757
debug messages, display
ISL B-86
VLAN IOS file system error tests B-85
VLAN manager activity B-83
VTP B-88
displaying configurations 2-606
extended-range 2-751
MAC addresses
displaying 2-550
number of 2-537
media types 2-754, 2-759
normal-range 2-751, 2-757
private 2-711
configuring 2-357
displaying 2-606
See also private VLANs
restarting 2-620
saving the configuration 2-751
shutting down 2-620
SNMP traps for VTP 2-625, 2-628
suspending 2-620
variables 2-757
VLAN Trunking Protocol
See VTP
VM mode 2-598
VMPS
configuring servers 2-775
displaying 2-613
error recovery timer 2-128
reconfirming dynamic VLAN assignments 2-772
vmps reconfirm (global configuration) command 2-773
vmps reconfirm (privileged EXEC) command 2-772
vmps retry command 2-774
vmps server command 2-775
voice VLAN
configuring 2-731, 2-732
setting port priority 2-722
VQP
and dynamic-access ports 2-700
clearing client statistics 2-67
displaying information 2-613
per-server retry count 2-774
reconfirmation interval 2-773
reconfirming dynamic VLAN assignments 2-772
VTP
changing characteristics 2-777
clearing pruning counters 2-68
configuring
domain name 2-777, 2-781
file name 2-777
mode 2-777, 2-781
password 2-777, 2-781
counters display fields 2-616
displaying information 2-615
enabling
pruning 2-777, 2-781
tunneling for 2-235
Version 2 2-777, 2-781
mode 2-777, 2-781
pruning 2-777, 2-781
saving the configuration 2-751, 2-761
statistics 2-615
status 2-615
status display fields 2-617
vtp (global configuration) command 2-777
vtp (VLAN configuration) command 2-781