Table Of Contents
A - B - C - D - E - F - G - H - I - J - L - M - N - O - P - Q - R - S - T - U - V -
Index
A
aaa accounting dot1x command 2-1
aaa authentication dot1x command 2-3
aaa authorization network command 2-5, 2-24, 2-30, 2-32, 2-34, 2-36, 2-38, 2-130, 2-291, 2-458, B-7, B-32
AAA methods 2-3
access control entries
See ACEs
access control lists
See ACLs
access groups
IP 2-177
MAC, displaying 2-582
access list, IPv6 2-248
access map configuration mode 2-317
access mode 2-773
access ports 2-773
ACEs 2-114, 2-391
ACLs
deny 2-112
displaying 2-440
for non-IP protocols 2-295
IP 2-177
matching 2-317
on Layer 2 interfaces 2-177
permit 2-389
action command 2-6
aggregate-port learner 2-378
allowed VLANs 2-793
archive copy-sw command 2-8
archive download-sw command 2-11
archive tar command 2-15
archive upload-sw command 2-18
arp (boot loader) command A-2
arp access-list command 2-20
authentication command disable-port ignore 2-23
authentication control-direction command 2-24
authentication event command 2-26
authentication failed VLAN
See dot1x auth-fail vlan
authentication fallback command 2-30
authentication host-mode command 2-32
authentication mac-move permit command 2-34
authentication open command 2-36
authentication order command 2-38
authentication periodic command 2-40
authentication port-control command 2-42
authentication priority command 2-44
authentication timer command 2-46
authentication violation command 2-48
auth-fail max-attempts
See dot1x auth-fail max-attempts
auth-fail vlan
See dot1x auth-fail vlan
auth open command 2-36
auth order command 2-38
authorization state of controlled port 2-146
auth timer command 2-46
autonegotiation of duplex mode 2-155
auto qos voip command 2-50
B
BackboneFast, for STP 2-695
backup interfaces
configuring 2-767
displaying 2-507
boot (boot loader) command A-3
boot auto-copy-sw command 2-54
boot auto-download-sw command 2-56
boot config-file command 2-58
boot enable-break command 2-59
boot helper command 2-60
boot helper-config file command 2-61
booting
Cisco IOS image 2-64
displaying environment variables 2-453
interrupting 2-59
manually 2-62
boot loader
accessing A-1
booting
Cisco IOS image A-3
helper image 2-60
directories
creating A-19
displaying a list of A-8
removing A-23
displaying
available commands A-13
memory heap utilization A-14
version A-30
environment variables
described A-24
displaying settings A-24
location of A-25
setting A-24
unsetting A-28
files
copying A-6
deleting A-7
displaying a list of A-8
displaying the contents of A-5, A-20, A-27
renaming A-21
file system
formatting A-11
initializing flash A-10
running a consistency check A-12
prompt A-1
resetting the system A-22
boot manual command 2-62
boot private-config-file command 2-63
boot system command 2-64
BPDU filtering, for spanning tree 2-696, 2-730
BPDU guard, for spanning tree 2-698, 2-730
broadcast storm control 2-751
C
cat (boot loader) command A-5
CDP, enabling protocol tunneling for 2-274
channel-group command 2-66
channel-protocol command 2-70
Cisco SoftPhone
auto-QoS configuration 2-50
trusting packets sent from 2-358
CISP
See Client Information Signalling Protocol
cisp
debug platform cisp command B-32
cisp enable command 2-71
class command 2-72
class-map command 2-74
class maps
creating 2-74
defining the match criteria 2-319
displaying 2-459
class of service
See CoS
clear dot1x command 2-76
clear eap command 2-77
clear errdisable interface 2-78
clear ip arp inspection log command 2-79
clear ip arp inspection statistics command 2-80
clear ipc command 2-85
clear ip dhcp snooping database command 2-81, 2-83
clear ipv6 dhcp conflict command 2-86
clear l2protocol-tunnel counters command 2-87
clear lacp command 2-88
clear logging command 2-89
clear mac address-table command 2-90, 2-91
clear nmsp statistics command 2-92
clear pagp command 2-93
clear port-security command 2-94
clear spanning-tree counters command 2-96
clear spanning-tree detected-protocols command 2-97
clear vmps statistics command 2-98
clear vtp counters command 2-99
Client Information Signalling Protocol 2-71, 2-130, 2-458, B-7, B-32
command modes defined 1-2
configuration files
password recovery disable considerations A-1
specifying the name 2-58, 2-63
configuring multiple interfaces 2-173
config-vlan mode
commands 2-817
entering 2-816
copy (boot loader) command A-6
copy logging onboard command 2-100
CoS
assigning default value to incoming packets 2-328
assigning to Layer 2 protocol packets 2-277
overriding the incoming value 2-328
CoS-to-DSCP map 2-332
CPU ASIC statistics, displaying 2-460
crashinfo files 2-164
critical VLAN 2-27
D
debug authentication B-2
debug auto qos command B-4
debug backup command B-6
debug cisp command B-7
debug dot1x command B-8
debug dtp command B-9
debug eap command B-10
debug etherchannel command B-11
debug fastethernet command B-12
debug interface command B-15
debug ip dhcp snooping command B-13
debug ip igmp filter command B-16
debug ip igmp max-groups command B-17
debug ip igmp snooping command B-18
debug ip verify source packet command B-14
debug lacp command B-19
debug lldp packets command B-20
debug mac-notification command B-21
debug matm command B-22
debug matm move update command B-23
debug monitor command B-24
debug mvrdbg command B-25
debug nmsp command B-26
debug nvram command B-27
debug pagp command B-28
debug platform acl command B-29
debug platform backup interface command B-31
debug platform cisp command B-32
debug platform cli-redirection main command B-33
debug platform configuration command B-34
debug platform cpu-queues command B-35
debug platform device-manager command B-37
debug platform dot1x command B-38
debug platform etherchannel command B-39
debug platform fallback-bridging command B-40
debug platform forw-tcam command B-41
debug platform ip arp inspection command B-42
debug platform ipc command B-51
debug platform ip dhcp command B-43
debug platform ip igmp snooping command B-44
debug platform ip multicast command B-46
debug platform ip unicast command B-48
debug platform ip wccp command B-50
debug platform led command B-52
debug platform matm command B-53
debug platform messaging application command B-54
debug platform phy command B-56
debug platform pm command B-58
debug platform port-asic command B-60
debug platform port-security command B-61
debug platform qos-acl-tcam command B-62
debug platform remote-commands command B-63
debug platform resource-manager command B-64
debug platform snmp command B-65
debug platform span command B-66
debug platform stack-manager command B-67
debug platform supervisor-asic command B-68
debug platform sw-bridge command B-69
debug platform tcam command B-70
debug platform udld command B-73
debug platform vlan command B-74
debug pm command B-75
debug port-security command B-77
debug qos-manager command B-78
debug spanning-tree backbonefast command B-81
debug spanning-tree bpdu command B-82
debug spanning-tree bpdu-opt command B-83
debug spanning-tree command B-79
debug spanning-tree mstp command B-84
debug spanning-tree switch command B-86
debug spanning-tree uplinkfast command B-88
debug sw-vlan command B-89
debug sw-vlan ifs command B-91
debug sw-vlan notification command B-92
debug sw-vlan vtp command B-94
debug udld command B-96
debug vqpc command B-98
define interface-range command 2-102
delete (boot loader) command A-7
delete command 2-104
deny (ARP access-list configuration) command 2-105
deny (IPv6) command 2-107
deny command 2-112
detect mechanism, causes 2-157
DHCP snooping
accepting untrusted packets from edge switch 2-206
enabling
on a VLAN 2-212
option 82 2-204, 2-206
trust on an interface 2-210
error recovery timer 2-161
rate limiting 2-209
DHCP snooping binding database
binding file, configuring 2-202
bindings
adding 2-200
deleting 2-200
displaying 2-528
clearing database agent statistics 2-81, 2-83
database agent, configuring 2-202
displaying
binding entries 2-528
database agent status 2-530, 2-532
renewing 2-420
dir (boot loader) command A-8
directories, deleting 2-104
domain name, VTP 2-835
dot1x auth-fail max-attempts 2-124
dot1x auth-fail vlan 2-126
dot1x command 2-122
dot1x control-direction command 2-128
dot1x credentials (global configuration) command 2-130
dot1x critical global configuration command 2-131
dot1x critical interface configuration command 2-133
dot1x default command 2-135
dot1x fallback command 2-136
dot1x guest-vlan command 2-137
dot1x host-mode command 2-139
dot1x initialize command 2-140
dot1x mac-auth-bypass command 2-141
dot1x max-reauth-req command 2-143
dot1x max-req command 2-144
dot1x pae command 2-145
dot1x port-control command 2-146
dot1x re-authenticate command 2-148
dot1x reauthentication command 2-149
dot1x supplicant force-multicast command 2-150
dot1x timeout command 2-151
dot1x violation-mode command 2-153
dropping packets, with ACL matches 2-6
drop threshold, Layer 2 protocol tunneling 2-274
DSCP-to-CoS map 2-332
DSCP-to-DSCP-mutation map 2-332
DTP 2-774
DTP flap
error detection for 2-157
error recovery timer 2-161
DTP negotiation 2-778
dual IPv4 and IPv6 templates 2-384
duplex command 2-155
dynamic-access ports
configuring 2-763
restrictions 2-764
dynamic ARP inspection
ARP ACLs
apply to a VLAN 2-185
define 2-20
deny packets 2-105
display 2-444
permit packets 2-382
clear
log buffer 2-79
statistics 2-80
display
ARP ACLs 2-444
configuration and operating state 2-523
log buffer 2-523
statistics 2-523
trust state and rate limit 2-523
enable per VLAN 2-195
error detection for 2-157
error recovery timer 2-161
log buffer
clear 2-79
configure 2-189
display 2-523
rate-limit incoming ARP packets 2-187
statistics
clear 2-80
display 2-523
trusted interface state 2-191
type of packet logged 2-196
validation checks 2-193
dynamic auto VLAN membership mode 2-773
dynamic desirable VLAN membership mode 2-773
Dynamic Host Configuration Protocol (DHCP)
See DHCP snooping
Dynamic Trunking Protocol
See DTP
E
EAP-request/identity frame
maximum number to send 2-144
response time before retransmitting 2-151
encapsulation methods 2-793
environment variables, displaying 2-453
errdisable detect cause command 2-157
errdisable detect cause small-frame comand 2-159
errdisable recovery cause small-frame 2-163
errdisable recovery command 2-161
error conditions, displaying 2-495
error disable detection 2-157
error-disabled interfaces, displaying 2-507
EtherChannel
assigning Ethernet interface to channel group 2-66
creating port-channel logical interface 2-171
debug EtherChannel/PAgP, display B-11
debug platform-specific events, display B-39
displaying 2-498
enabling Layer 2 protocol tunneling for
LACP 2-275
PAgP 2-275
UDLD 2-275
interface information, displaying 2-507
LACP
clearing channel-group information 2-88, 2-89
debug messages, display B-19
displaying 2-568
modes 2-66
port priority for hot-standby ports 2-278
restricting a protocol 2-70
system priority 2-280
load-distribution methods 2-400
PAgP
aggregate-port learner 2-378
clearing channel-group information 2-93
debug messages, display B-28
displaying 2-633
error detection for 2-157
error recovery timer 2-161
learn method 2-378
modes 2-66
physical-port learner 2-378
priority of interface for transmitted traffic 2-380
Ethernet controller, internal register display 2-462, 2-469
Ethernet Management port, debugging B-12
Ethernet statistics, collecting 2-423
exception crashinfo command 2-164, 2-169
extended-range VLANs
and allowed VLAN list 2-793
and pruning-eligible list 2-793
configuring 2-816
extended system ID for STP 2-704
F
fallback profile command 2-165
fallback profiles, displaying 2-501
fan information, displaying 2-491
file name, VTP 2-835
files, deleting 2-104
flash_init (boot loader) command A-10
flexible authentication ordering 2-38
Flex Links
configuring 2-767
displaying 2-507
flowcontrol command 2-167
format (boot loader) command A-11
forwarding packets, with ACL matches 2-6
forwarding results, display C-9
frame forwarding information, displaying C-9
front-end controller counter and status information C-11
fsck (boot loader) command A-12
G
global configuration mode 1-2, 1-4
H
hardware ACL statistics 2-440
health monitoring diagnostic tests 2-115
help (boot loader) command A-13
hierarchical policy maps 2-398
host connection, port configuration 2-772
host ports, private VLANs 2-776
I
IEEE 802.1Q trunk ports and native VLANs 2-826
IEEE 802.1Q tunnel ports
configuring 2-773
displaying 2-481
limitations 2-774
IEEE 802.1x
and switchport modes 2-774
violation error recovery 2-161
See also port-based authentication
IGMP filters
applying 2-215
debug messages, display B-16
IGMP groups, setting maximum 2-217
IGMP maximum groups, debugging B-17
IGMP profiles
creating 2-219
displaying 2-535
IGMP snooping
adding ports as a static member of a group 2-235
displaying 2-536, 2-541, 2-543
enabling 2-221
enabling the configurable-leave timer 2-223
enabling the Immediate-Leave feature 2-232
flooding query count 2-229
interface topology change notification behavior 2-231
multicast table 2-539
querier 2-225
query solicitation 2-229
report suppression 2-227
switch topology change notification behavior 2-229
images
See software images
Immediate-Leave processing
IGMP 2-232
IPv6 2-270
MVR 2-368
interface configuration mode 1-2, 1-4
interface port-channel command 2-171
interface range command 2-173
interface-range macros 2-102
interfaces
assigning Ethernet interface to channel group 2-66
configuring 2-155
configuring multiple 2-173
creating port-channel logical 2-171
debug messages, display B-15
disabling 2-681
displaying the MAC address table 2-594
restarting 2-681
interface speed, configuring 2-741
interface vlan command 2-175
internal registers, displaying 2-462, 2-469, 2-472
Internet Group Management Protocol
See IGMP
ip access-group command 2-177
ip address command 2-180
IP addresses, setting 2-180
IP address matching 2-317
ip admission command 2-182
ip admission name proxy http command 2-183
ip arp inspection filter vlan command 2-185
ip arp inspection limit command 2-187
ip arp inspection log-buffer command 2-189
ip arp inspection trust command 2-191
ip arp inspection validate command 2-193
ip arp inspection vlan command 2-195
ip arp inspection vlan logging command 2-196
IP DHCP snooping
See DHCP snooping
ip dhcp snooping binding command 2-200
ip dhcp snooping command 2-199
ip dhcp snooping database command 2-202
ip dhcp snooping information option allow-untrusted command 2-206
ip dhcp snooping information option command 2-204
ip dhcp snooping information option format remote-id command 2-208
ip dhcp snooping limit rate command 2-209
ip dhcp snooping trust command 2-210
ip dhcp snooping verify command 2-211
ip dhcp snooping vlan command 2-212
ip dhcp snooping vlan information option format-type circuit-id string command 2-213
ip igmp filter command 2-215
ip igmp max-groups command 2-217, 2-242, 2-244
ip igmp profile command 2-219
ip igmp snooping command 2-221
ip igmp snooping last-member-query-interval command 2-223
ip igmp snooping querier command 2-225
ip igmp snooping report-suppression command 2-227
ip igmp snooping tcn command 2-229
ip igmp snooping tcn flood command 2-231
ip igmp snooping vlan immediate-leave command 2-232
ip igmp snooping vlan mrouter command 2-233
ip igmp snooping vlan static command 2-235
IP multicast addresses 2-365
IP phones
auto-QoS configuration 2-50
trusting packets sent from 2-358
IP-precedence-to-DSCP map 2-332
ip snap forwarding command 2-237
ip source binding command 2-238
IP source guard
disabling 2-246
displaying
binding entries 2-545
configuration 2-546
dynamic binding entries only 2-528
enabling 2-246
static IP source bindings 2-238
ip ssh command 2-240
IPv6 access list, deny conditions 2-107
ipv6 access-list command 2-248
ipv6 address dhcp command 2-250
ipv6 dhcp client request vendor command 2-251
ipv6 dhcp ping packets command 2-252
ipv6 dhcp pool command 2-254
ipv6 dhcp server command 2-256
ipv6 mld snooping command 2-258
ipv6 mld snooping last-listener-query count command 2-260
ipv6 mld snooping last-listener-query-interval command 2-262
ipv6 mld snooping listener-message-suppression command 2-264
ipv6 mld snooping robustness-variable command 2-266
ipv6 mld snooping tcn command 2-268
ipv6 mld snooping vlan command 2-270
IPv6 SDM template 2-424
ipv6 traffic-filter command 2-272
ip verify source command 2-246
J
jumbo frames
See MTU
L
l2protocol-tunnel command 2-274
l2protocol-tunnel cos command 2-277
LACP
See EtherChannel
lacp port-priority command 2-278
lacp system-priority command 2-280
Layer 2 mode, enabling 2-761
Layer 2 protocol ports, displaying 2-565
Layer 2 protocol-tunnel
error detection for 2-157
error recovery timer 2-161
Layer 2 protocol tunnel counters 2-87
Layer 2 protocol tunneling error recovery 2-275
Layer 2 traceroute
IP addresses 2-807
MAC addresses 2-804
Layer 3 mode, enabling 2-761
line configuration mode 1-3, 1-5
Link Aggregation Control Protocol
See EtherChannel
link flap
error detection for 2-157
error recovery timer 2-161
link state group command 2-282
link state track command 2-284
load-distribution methods for EtherChannel 2-400
location (global configuration) command 2-285
location (interface configuration) command 2-287
logging file command 2-289
logical interface 2-171
loopback error
detection for 2-157
recovery timer 2-161
loop guard, for spanning tree 2-706, 2-710
M
mab request format attribute 32 command 2-291
mac access-group command 2-293
MAC access-groups, displaying 2-582
MAC access list configuration mode 2-295
mac access-list extended command 2-295
MAC access lists 2-112
MAC addresses
disabling MAC address learning per VLAN 2-298
displaying
aging time 2-588
all 2-586
dynamic 2-592
MAC address-table move updates 2-597
notification settings 2-596, 2-599
number of addresses in a VLAN 2-590
per interface 2-594
per VLAN 2-603
static 2-601
static and dynamic entries 2-584
dynamic
aging time 2-297
deleting 2-90
displaying 2-592
enabling MAC address notification 2-302
enabling MAC address-table move update 2-300
matching 2-317
persistent stack 2-749
static
adding and removing 2-304
displaying 2-601
dropping on an interface 2-305
tables 2-586
MAC address notification, debugging B-21
mac address-table aging-time 2-293, 2-317
mac address-table aging-time command 2-297
mac address-table learning command 2-298
mac address-table move update command 2-300
mac address-table notification command 2-302
mac address-table static command 2-304
mac address-table static drop command 2-305
MAC frames
See MTU
macro apply command 2-307
macro description command 2-310
macro global command 2-311
macro global description command 2-314
macro name command 2-315
macros
adding a description 2-310
adding a global description 2-314
applying 2-311
creating 2-315
displaying 2-635
interface range 2-102, 2-173
specifying parameter values 2-311
tracing 2-311
maps
QoS
defining 2-332
displaying 2-613
VLAN
creating 2-823
defining 2-317
displaying 2-672
match (access-map configuration) command 2-317
match (class-map configuration) command 2-319
maximum transmission unit
See MTU
mdix auto command 2-322
memory (boot loader) command A-14
mgmt_clr (boot loader) command A-16
mgmt_init (boot loader) command A-17, A-18
mkdir (boot loader) command A-19
MLD snooping
configuring 2-264, 2-266
configuring queries 2-260, 2-262
configuring topology change notification 2-268
displaying 2-555, 2-557, 2-559, 2-561
enabling 2-258
enabling on a VLAN 2-270
mls qos aggregate-policer command 2-326
mls qos command 2-324
mls qos cos command 2-328
mls qos dscp-mutation command 2-330
mls qos map command 2-332
mls qos queue-set output buffers command 2-336
mls qos queue-set output threshold command 2-338
mls qos rewrite ip dscp command 2-340
mls qos srr-queue input bandwidth command 2-342
mls qos srr-queue input buffers command 2-344
mls qos-srr-queue input cos-map command 2-346
mls qos srr-queue input dscp-map command 2-348
mls qos srr-queue input priority-queue command 2-350
mls qos srr-queue input threshold command 2-352
mls qos-srr-queue output cos-map command 2-354
mls qos srr-queue output dscp-map command 2-356
mls qos trust command 2-358
mls qos vlan-based command 2-360
mode, MVR 2-365
Mode button, and password recovery 2-427
modes, commands 1-2
monitor session command 2-361
more (boot loader) command A-20
MSTP
displaying 2-649
interoperability 2-97
link type 2-708
MST region
aborting changes 2-714
applying changes 2-714
configuration name 2-714
configuration revision number 2-714
current or pending display 2-714
displaying 2-649
MST configuration mode 2-714
VLANs-to-instance mapping 2-714
path cost 2-716
protocol mode 2-712
restart protocol migration process 2-97
MSTP (continued)
root port
loop guard 2-706
preventing from becoming designated 2-706
restricting which can be root 2-706
root guard 2-706
root switch
affects of extended system ID 2-704
hello-time 2-719, 2-726
interval between BDPU messages 2-720
interval between hello BPDU messages 2-719, 2-726
max-age 2-720
maximum hop count before discarding BPDU 2-721
port priority for selection of 2-722
primary or secondary 2-726
switch priority 2-725
state changes
blocking to forwarding state 2-733
enabling BPDU filtering 2-696, 2-730
enabling BPDU guard 2-698, 2-730
enabling Port Fast 2-730, 2-733
forward-delay time 2-718
length of listening and learning states 2-718
rapid transition to forwarding 2-708
shutting down Port Fast-enabled ports 2-730
state information display 2-648
MTU
configuring size 2-801
displaying global setting 2-661
Multicase Listener Discovery
See MLD
multicast group address, MVR 2-368
multicast groups, MVR 2-366
Multicast Listener Discovery
See MLD
multicast router learning method 2-233
multicast router ports, configuring 2-233
multicast router ports, IPv6 2-270
multicast storm control 2-751
multicast VLAN, MVR 2-365
multicast VLAN registration
See MVR
multiple hosts on authorized port 2-139
Multiple Spanning Tree Protocol
See MSTP
MVR
configuring 2-365
configuring interfaces 2-368
debug messages, display B-25
displaying 2-622
displaying interface information 2-624
members, displaying 2-626
mvr (global configuration) command 2-365
mvr (interface configuration) command 2-368
mvr vlan group command 2-369
N
native VLANs 2-793
native VLAN tagging 2-826
network-policy (global configuration) command 2-371
network-policy command 2-370
network-policy profile (network-policy configuration) command 2-372
nmsp attachment suppress command 2-375
nmsp command 2-374
nonegotiate
DTP messaging 2-778
non-IP protocols
denying 2-112
forwarding 2-389
non-IP traffic access lists 2-295
non-IP traffic forwarding
denying 2-112
permitting 2-389
non-stop forwarding 2-376
normal-range VLANs 2-816, 2-822
no vlan command 2-816
nsf command 2-376
O
online diagnostics
configuring health monitoring diagnostic tests 2-115
displaying
configured boot-up coverage level 2-476
current scheduled tasks 2-476
event logs 2-476
supported test suites 2-476
test ID 2-476
test results 2-476
test statistics 2-476
enabling
scheduling 2-117
syslog messages 2-115
global configuration mode
clearing health monitoring diagnostic test schedule 2-115
clearing test-based testing schedule 2-117
setting health monitoring diagnostic testing 2-115
setting test-based testing 2-117
setting up health monitoring diagnostic test schedule 2-115
setting up test-based testing 2-117
removing scheduling 2-117
scheduled switchover
disabling 2-117
enabling 2-117
setting test interval 2-117
specifying health monitoring diagnostic tests 2-115
starting testing 2-119
P
PAgP
See EtherChannel
pagp learn-method command 2-378
pagp port-priority command 2-380
password, VTP 2-836
password-recovery mechanism, enabling and disabling 2-427
permit (ARP access-list configuration) command 2-382
permit (IPv6) command 2-384
permit (MAC access-list configuration) command 2-389
per-VLAN spanning-tree plus
See STP
physical-port learner 2-378
PID, displaying 2-522
PIM-DVMRP, as multicast router learning method 2-233
platform chassis-management command 2-392
police aggregate command 2-395
police command 2-393
policed-DSCP map 2-332
policy-map command 2-397
policy maps
applying to an interface 2-429, 2-435
creating 2-397
displaying 2-638
hierarchical 2-398
policers
displaying 2-606
for a single class 2-393
for multiple classes 2-326, 2-395
policed-DSCP map 2-332
traffic classification
defining the class 2-72
defining trust states 2-809
setting DSCP or IP precedence values 2-433
Port Aggregation Protocol
See EtherChannel
port-based authentication
AAA method list 2-3
configuring violation modes 2-153
debug messages, display B-8
enabling guest VLAN supplicant 2-125, 2-136
enabling IEEE 802.1x
globally 2-122
per interface 2-146
guest VLAN 2-137
host modes 2-139
IEEE 802.1x AAA accounting methods 2-1
initialize an interface 2-140
MAC authentication bypass 2-141
manual control of authorization state 2-146
multiple hosts on authorized port 2-139
PAE as authenticator 2-145
periodic re-authentication
enabling 2-149
time between attempts 2-151
quiet period between failed authentication exchanges 2-151
re-authenticating IEEE 802.1x-enabled ports 2-148
resetting configurable IEEE 802.1x parameters 2-135
switch-to-authentication server retransmission time 2-151
switch-to-client frame-retransmission number2-143to 2-144
switch-to-client retransmission time 2-151
port-channel load-balance command 2-400
Port Fast, for spanning tree 2-733
port ranges, defining 2-100, 2-102
ports, debugging B-75
ports, protected 2-791
port security
aging 2-785
debug messages, display B-77
enabling 2-780
violation error recovery 2-161
port trust states for QoS 2-358
port types, MVR 2-368
power information, displaying 2-491
priority-queue command 2-402
priority value, stack member 2-656, 2-756
private-vlan command 2-404
private-vlan mapping command 2-407
private VLANs
association 2-789
configuring 2-404
configuring ports 2-776
displaying 2-667
host ports 2-776
mapping
configuring 2-789
displaying 2-507
promiscuous ports 2-776
privileged EXEC mode 1-2, 1-3
product identification information, displaying 2-522
promiscuous ports, private VLANs 2-776
protected ports, displaying 2-513
pruning
VLANs 2-793
VTP
displaying interface information 2-507
enabling 2-836
pruning-eligible VLAN list 2-795
PVST+
See STP
Q
QoS
auto-QoS
configuring 2-50
debug messages, display B-4
displaying 2-449
class maps
creating 2-74
defining the match criteria 2-319
displaying 2-459
QoS (continued)
defining the CoS value for an incoming packet 2-328
displaying configuration information 2-449, 2-605
DSCP transparency 2-340
DSCP trusted ports
applying DSCP-to-DSCP-mutation map to 2-330
defining DSCP-to-DSCP-mutation map 2-332
egress queues
allocating buffers 2-336
defining the CoS output queue threshold map 2-354
defining the DSCP output queue threshold map 2-356
displaying buffer allocations 2-609
displaying CoS output queue threshold map 2-613
displaying DSCP output queue threshold map 2-613
displaying queueing strategy 2-609
displaying queue-set settings 2-616
enabling bandwidth shaping and scheduling 2-745
enabling bandwidth sharing and scheduling 2-747
limiting the maximum output on a port 2-743
mapping a port to a queue-set 2-409
mapping CoS values to a queue and threshold 2-354
mapping DSCP values to a queue and threshold 2-356
setting maximum and reserved memory allocations 2-338
setting WTD thresholds 2-338
enabling 2-324
ingress queues
allocating buffers 2-344
assigning SRR scheduling weights 2-342
defining the CoS input queue threshold map 2-346
defining the DSCP input queue threshold map 2-348
displaying buffer allocations 2-609
displaying CoS input queue threshold map 2-613
displaying DSCP input queue threshold map 2-613
displaying queueing strategy 2-609
displaying settings for 2-607
enabling the priority queue 2-350
mapping CoS values to a queue and threshold 2-346
mapping DSCP values to a queue and threshold 2-348
setting WTD thresholds 2-352
maps
defining 2-332, 2-346, 2-348, 2-354, 2-356
displaying 2-613
policy maps
applying an aggregate policer 2-395
applying to an interface 2-429, 2-435
creating 2-397
defining policers 2-326, 2-393
displaying policers 2-606
displaying policy maps 2-638
hierarchical 2-398
policed-DSCP map 2-332
setting DSCP or IP precedence values 2-433
traffic classifications 2-72
trust states 2-809
port trust states 2-358
queues, enabling the expedite 2-402
statistics
in-profile and out-of-profile packets 2-609
packets enqueued or dropped 2-609
sent and received CoS values 2-609
sent and received DSCP values 2-609
trusted boundary for IP phones 2-358
VLAN-based 2-360
quality of service
See QoS
querytime, MVR 2-365
queue-set command 2-409
R
radius-server dead-criteria command 2-410
radius-server host command 2-412
rapid per-VLAN spanning-tree plus
See STP
rapid PVST+
See STP
re-authenticating IEEE 802.1x-enabled ports 2-148
re-authentication
periodic 2-149
time between attempts 2-151
receiver ports, MVR 2-368
receiving flow-control packets 2-167
recovery mechanism
causes 2-161
display 2-78, 2-456, 2-493, 2-496
timer interval 2-161
reload command 2-414
remote command 2-416
remote-span command 2-418
Remote Switched Port Analyzer
See RSPAN
rename (boot loader) command A-21
renew ip dhcp snooping database command 2-420
reset (boot loader) command A-22
resource templates, displaying 2-643
restricted VLAN
See dot1x auth-fail vlan
rmdir (boot loader) command A-23
rmon collection stats command 2-423
root guard, for spanning tree 2-706
routed ports
IP addresses on 2-181
number supported 2-181
routing frames
See MTU
RSPAN
configuring 2-361
displaying 2-619
filter RSPAN traffic 2-361
remote-span command 2-418
sessions
add interfaces to 2-361
displaying 2-619
start new 2-361
S
scheduled switchover
disabling 2-117
enabling 2-117
SDM mismatch mode 2-425, 2-657
sdm prefer command 2-424
SDM templates
allowed resources 2-425
and stacking 2-425
displaying 2-643
dual IPv4 and IPv6 2-424
secure ports, limitations 2-782
sending flow-control packets 2-167
service password-recovery command 2-427
service-policy command 2-429
session command 2-432
set (boot loader) command A-24
set command 2-433
setup command 2-435
setup express command 2-438
show access-lists command 2-440
show archive status command 2-443
show arp access-list command 2-444
show authentication command 2-445
show auto qos command 2-449
show boot command 2-453
show cable-diagnostics tdr command 2-456
show cisp command 2-458
show class-map command 2-459
show controllers cpu-interface command 2-460
show controllers ethernet-controller command 2-462
show controllers ethernet-controller fastethernet command 2-469
show controllers tcam command 2-472
show controller utilization command 2-474
show dot1q-tunnel command 2-481
show dot1x command 2-482
show dtp 2-486
show eap command 2-488
show env command 2-491
show errdisable detect command 2-493
show errdisable flap-values command 2-495
show errdisable recovery command 2-496
show etherchannel command 2-498
show fallback profile command 2-501
show flowcontrol command 2-503
show idprom command 2-505
show interfaces command 2-507
show interfaces counters command 2-519
show inventory command 2-522
show ip arp inspection command 2-523
show ipc command 2-548
show ip dhcp snooping binding command 2-528
show ip dhcp snooping command 2-527
show ip dhcp snooping database command 2-530, 2-532
show ip igmp profile command 2-535
show ip igmp snooping address command 2-557
show ip igmp snooping command 2-536, 2-555
show ip igmp snooping groups command 2-539
show ip igmp snooping mrouter command 2-541, 2-559
show ip igmp snooping querier command 2-543, 2-561
show ip source binding command 2-545
show ipv6 access-list command 2-552
show ipv6 dhcp conflict command 2-554
show ipv6 route updated 2-563
show ip verify source command 2-546
show l2protocol-tunnel command 2-565
show lacp command 2-568
show link state group command 2-572
show location 2-574
show location command 2-574
show logging command 2-577
show mac access-group command 2-582
show mac address-table address command 2-586
show mac address-table aging time command 2-588
show mac address-table command 2-584
show mac address-table count command 2-590
show mac address-table dynamic command 2-592
show mac address-table interface command 2-594
show mac address-table learning command 2-596
show mac address-table move update command 2-597
show mac address-table notification command 2-91, 2-599, B-23
show mac address-table static command 2-601
show mac address-table vlan command 2-603
show mls qos aggregate-policer command 2-606
show mls qos command 2-605
show mls qos input-queue command 2-607
show mls qos interface command 2-609
show mls qos maps command 2-613
show mls qos queue-set command 2-616
show mls qos vlan command 2-618
show monitor command 2-619
show mvr command 2-622
show mvr interface command 2-624
show mvr members command 2-626
show network-policy profile command 2-628
show nmsp command 2-630
show pagp command 2-633
show parser macro command 2-635
show platform acl command C-2
show platform backup interface command C-3
show platform chassis command C-4
show platform configuration command C-6
show platform dl command C-7
show platform etherchannel command C-8
show platform forward command C-9
show platform frontend-controller command C-11
show platform igmp snooping command C-12
show platform ipc trace command C-20
show platform ip multicast command C-14
show platform ip unicast command C-15
show platform ipv6 unicast command C-21
show platform ip wccp command C-19
show platform layer4op command C-23
show platform mac-address-table command C-24
show platform messaging command C-25
show platform monitor command C-26
show platform mvr table command C-27
show platform pm command C-28
show platform port-asic command C-30
show platform port-security command C-35
show platform qos command C-36
show platform resource-manager command C-37
show platform snmp counters command C-39
show platform spanning-tree command C-40
show platform stack-manager command C-42
show platform stp-instance command C-41
show platform summary command C-46
show platform tb command C-47
show platform tcam command C-49
show platform vlan command C-52
show policy-map command 2-638
show port security command 2-640
show sdm prefer command 2-643
show setup express command 2-647
show spanning-tree command 2-648
show storm-control command 2-654
show switch command 2-656
show system mtu command 2-661
show trust command 2-809
show udld command 2-662
show version command 2-665
show vlan access-map command 2-672
show vlan command 2-667
show vlan command, fields 2-669
show vlan filter command 2-673
show vmps command 2-674
show vtp command 2-676
shutdown command 2-681
shutdown threshold, Layer 2 protocol tunneling 2-274
shutdown vlan command 2-682
small violation-rate command 2-683
Smartports macros
See macros
SNMP host, specifying 2-689
SNMP informs, enabling the sending of 2-685
snmp-server enable traps command 2-685
snmp-server host command 2-689
snmp trap mac-notification command 2-693
SNMP traps
enabling MAC address notification trap 2-693
enabling the MAC address notification feature 2-302
enabling the sending of 2-685
SoftPhone
See Cisco SoftPhone
software images
copying 2-8
deleting 2-104
downloading 2-11
upgrading 2-8, 2-11
uploading 2-18
software version, displaying 2-665
source ports, MVR 2-368
SPAN
configuring 2-361
debug messages, display B-24
displaying 2-619
filter SPAN traffic 2-361
SPAN (continued)
sessions
add interfaces to 2-361
displaying 2-619
start new 2-361
spanning-tree backbonefast command 2-695
spanning-tree bpdufilter command 2-696
spanning-tree bpduguard command 2-698
spanning-tree cost command 2-700
spanning-tree etherchannel command 2-702
spanning-tree extend system-id command 2-704
spanning-tree guard command 2-706
spanning-tree link-type command 2-708
spanning-tree loopguard default command 2-710
spanning-tree mode command 2-712
spanning-tree mst configuration command 2-714
spanning-tree mst cost command 2-716
spanning-tree mst forward-time command 2-718
spanning-tree mst hello-time command 2-719
spanning-tree mst max-age command 2-720
spanning-tree mst max-hops command 2-721
spanning-tree mst port-priority command 2-722
spanning-tree mst pre-standard command 2-724
spanning-tree mst priority command 2-725
spanning-tree mst root command 2-726
spanning-tree portfast (global configuration) command 2-730
spanning-tree portfast (interface configuration) command 2-733
spanning-tree port-priority command 2-728
Spanning Tree Protocol
See STP
spanning-tree transmit hold-count command 2-735
spanning-tree uplinkfast command 2-736
spanning-tree vlan command 2-738
speed command 2-741
srr-queue bandwidth limit command 2-743
srr-queue bandwidth shape command 2-745
srr-queue bandwidth share command 2-747
SSH, configuring version 2-240
stack-mac persistent timer command 2-749
stack member
access 2-432
number 2-656, 2-759
priority value 2-756
provisioning 2-757
reloading 2-414
stacks, switch
disabling a member 2-754
enabling a member 2-754
MAC address 2-749
provisioning a new member 2-757
reloading 2-414
stack member access 2-432
stack member number 2-656, 2-759
stack member priority value 2-656, 2-756
static-access ports, configuring 2-763
statistics, Ethernet group 2-423
sticky learning, enabling 2-780
storm-control command 2-751
STP
BackboneFast 2-695
counters, clearing 2-96
debug messages, display
BackboneFast events B-81
MSTP B-84
optimized BPDUs handling B-83
spanning-tree activity B-79
switch shim B-86
transmitted and received BPDUs B-82
UplinkFast B-88
detection of indirect link failures 2-695
enabling protocol tunneling for 2-274
EtherChannel misconfiguration 2-702
extended system ID 2-704
path cost 2-700
protocol modes 2-712
STP (continued)
root port
accelerating choice of new 2-736
loop guard 2-706
preventing from becoming designated 2-706
restricting which can be root 2-706
root guard 2-706
UplinkFast 2-736
root switch
affects of extended system ID 2-704, 2-739
hello-time 2-738
interval between BDPU messages 2-738
interval between hello BPDU messages 2-738
max-age 2-738
port priority for selection of 2-728
primary or secondary 2-738
switch priority 2-738
state changes
blocking to forwarding state 2-733
enabling BPDU filtering 2-696, 2-730
enabling BPDU guard 2-698, 2-730
enabling Port Fast 2-730, 2-733
enabling timer to recover from error state 2-161
forward-delay time 2-738
length of listening and learning states 2-738
shutting down Port Fast-enabled ports 2-730
state information display 2-648
VLAN options 2-725, 2-738
SVIs, creating 2-175
SVI status calculation 2-765
Switched Port Analyzer
See SPAN
switching characteristics
modifying 2-761
returning to interfaces 2-761
switchport access command 2-763
switchport autostate exclude command 2-765
switchport backup interface command 2-767
switchport block command 2-770
switchport command 2-761
switchport host command 2-772
switchport mode command 2-773
switchport mode private-vlan command 2-776
switchport nonegotiate command 2-778
switchport port-security aging command 2-785
switchport port-security command 2-780
switchport priority extend command 2-787
switchport private-vlan command 2-789
switchport protected command 2-791
switchports, displaying 2-507
switchport trunk command 2-793
switchport voice detect 2-796
switchport voice vlan command 2-797
switch priority command 2-754, 2-756
switch provision command 2-757
switch renumber command 2-759
system env temperature threshold yellow command 2-799
system message logging, save message to flash 2-289
system mtu command 2-801
system resource templates 2-424
T
tar files, creating, listing, and extracting 2-15
TDR, running 2-803
temperature information, displaying 2-491
templates, system resources 2-424
test cable-diagnostics tdr command 2-803
traceroute mac command 2-804
traceroute mac ip command 2-807
trunking, VLAN mode 2-773
trunk mode 2-773
trunk ports 2-773
trunks, to non-DTP device 2-774
trusted boundary for QoS 2-358
trusted port states for QoS 2-358
tunnel ports, Layer 2 protocol, displaying 2-565
type (boot loader) command A-27
U
UDLD
aggressive mode 2-811, 2-813
debug messages, display B-96
enable globally 2-811
enable per interface 2-813
error recovery timer 2-161
message timer 2-811
normal mode 2-811, 2-813
reset a shutdown interface 2-815
status 2-662
udld command 2-811
udld port command 2-813
udld reset command 2-815
unicast storm control 2-751
UniDirectional Link Detection
See UDLD
unknown multicast traffic, preventing 2-770
unknown unicast traffic, preventing 2-770
unset (boot loader) command A-28
upgrading
copying software images 2-8
downloading software images 2-11
software images, monitoring status of 2-443
UplinkFast, for STP 2-736
user EXEC mode 1-2, 1-3
V
version (boot loader) command A-30
version mismatch mode 2-657, C-43
vlan (global configuration) command 2-816
vlan (VLAN configuration) command 2-822
vlan access-map command 2-823
VLAN access map configuration mode 2-823
VLAN access maps
actions 2-6
displaying 2-672
VLAN-based QoS 2-360
VLAN configuration
rules 2-819
saving 2-816
VLAN configuration mode
commands
VLAN 2-822
VTP 2-841
description 1-4
entering 2-825
summary 1-3
vlan database command 2-825
vlan dot1q tag native command 2-826
vlan filter command 2-828
VLAN filters, displaying 2-673
VLAN ID range 2-816
VLAN maps
applying 2-828
creating 2-823
defining 2-317
displaying 2-672
VLAN Query Protocol
See VQP
VLANs
adding 2-816
configuring 2-816, 2-822
debug messages, display
ISL B-92
VLAN IOS file system error tests B-91
VLAN manager activity B-89
VTP B-94
displaying configurations 2-667
extended-range 2-816
MAC addresses
displaying 2-603
number of 2-590
media types 2-819
normal-range 2-816, 2-822
VLANs (continued)
private 2-776
configuring 2-404
displaying 2-667
See also private VLANs
restarting 2-682
saving the configuration 2-816
shutting down 2-682
SNMP traps for VTP 2-687, 2-690
suspending 2-682
VLAN Trunking Protocol
See VTP
VM mode 2-657, C-43
VMPS
configuring servers 2-833
displaying 2-674
error recovery timer 2-161
reconfirming dynamic VLAN assignments 2-830
vmps reconfirm (global configuration) command 2-831
vmps reconfirm (privileged EXEC) command 2-830
vmps retry command 2-832
vmps server command 2-833
voice VLAN
configuring 2-796, 2-797
setting port priority 2-787
VQP
and dynamic-access ports 2-764
clearing client statistics 2-98
displaying information 2-674
per-server retry count 2-832
reconfirmation interval 2-831
reconfirming dynamic VLAN assignments 2-830
VTP
changing characteristics 2-835
clearing pruning counters 2-99
configuring
domain name 2-835
file name 2-835
mode 2-835
password 2-836
counters display fields 2-677
displaying information 2-676
enabling
pruning 2-836
tunneling for 2-274
Version 2 2-836
enabling per port 2-840
mode 2-835
pruning 2-836
saving the configuration 2-816
statistics 2-676
status 2-676
status display fields 2-679
vtp (global configuration) command 2-835
vtp (VLAN configuration) command 2-841
vtp interface configuration) command 2-840
vtp primary command 2-842