Benutzeranleitung / Produktwartung TigerSwitch 100 des Produzenten SMC Networks
Zur Seite of 334
T igerSwitch 10/100/1000 Gigabit Ether net Switch ◆ 24 auto-M DI/MDI-X 10/10 0/1000B ASE -T ports ◆ 4 ports shared with 4 SFP transcei ver s lots ◆ Non-blocking switching architecture ◆ Suppor.
.
38 T esla Irvine, CA 9261 8 Phone: (9 49) 679-80 00 T igerSwitch 10/100/1000 Manag ement Guide From SM C’ s T iger line of feature-r ich work group LAN solutions February 2003 Pub.
Infor mation fur nished by SMC Networks, Inc . (SMC) is believed to be accurate and reliable. Ho wever , no re sponsibili ty is assumed by SMC for its use, nor f or any in fringe ments of p atents or other r ights of third par ties which may result from its use.
v L IMITED W ARRANTY Limited W ar ranty Statement: SM C Networks, Inc. (“SMC ”) warra nts its p roducts to be free from defects in wor kmanship and materials , under normal use and service, for the applicable warranty term .
L IMIT ED W AR RANTY vi LIABILITY IN C ONNECTION WITH THE SALE, I NSTALLA TION, MAINTENANCE OR USE OF ITS P RODUCTS . SMC SHALL NOT BE LIABLE UNDER THIS W ARR ANTY IF ITS TESTING AND EXAMINATION DISCL.
vii C ONTENTS 1 Switch Management . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-1 Connecting to the Switc h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-1 Configurat ion Options . . . . . . . . . . . . . . . . .
C ONTENTS viii Displaying C onnectio n Status . . . . . . . . . . . . . . . . . . . . . . . . . . 2-32 Configuri ng Interface C onnections . . . . . . . . . . . . . . . . . . . . . . 2-34 Setting Br oadcast Storm Th resholds . . . . . . . . . . . . . .
C ONTENTS ix SNMP IP Filt ering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-97 Multicast Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-99 Configuri ng IGMP Paramete rs . . . . . .
C ONTENTS x delete . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-21 dir . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-22 whichb oot . . . . . . . . .
C ONTENTS xi show rad ius-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-55 tacacs-se rver host . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-56 tacacs-se rver port . . . . . . . . . . . . . .
C ONTENTS xii capabilit ies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-89 flowcont rol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-90 shutdown . . . . . . . . . . . . .
C ONTENTS xiii switchpor t ingress-filter ing . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-127 switchpor t native vlan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-128 switchpor t allowed vlan . . . . . . . . . . . . .
C ONTENTS xiv Mirror Port C ommands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-163 port moni tor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-163 show por t monitor . . . . . . . . . . .
1-1 C HAPTER 1 S WITCH M ANAGEMENT Connect ing to the Switc h Configuration Opt ions The Tig erSwitch 10/100/1000 includes a built-in netw ork managem ent age nt. T he ag ent offers a variety of ma nageme nt opt ions, includ ing SNM P , RMON and a W eb-based inte rface.
S WITCH M ANAG EMENT 1-2 The switch’ s CLI conf iguration pro g ram, W eb interf ace, and S NMP agent allow you to perf or m the following manage ment func tions: • Set user na mes and pas swords .
C ONNECTING TO THE S WITCH 1-3 Required Connections The switch provides an RS-232 serial port that enables a connection to a PC or te r minal f or moni toring and conf igurin g the s witc h.
S WITCH M ANAG EMENT 1-4 4. Once y ou hav e set up the terminal correctly , the conso le login screen will be displayed. Note: Refer to “Line Commands” on page 3-73 for a complete desc riptio n of cons ole co nfigurati on opti ons. F or a descr iption of ho w to use t he CLI, se e “Usi ng the Co mmand Line Interface” on page 3-1.
B ASIC C ONFIGURATION 1-5 Basic Configuration Console Connection The CLI program pro v id es tw o different comm and lev els — no r mal access level (Nor mal Exec) and privileged access level (Privileged Exec).
S WITCH M ANAG EMENT 1-6 P assw ords can c onsist of up to eight alphan umeric characters an d are case sensitive. T o p revent unauth orized a ccess to th e switch, set th e passwords as follows: 1. Open th e consol e interface with the default user name a nd pass wo rd “admin” to access th e Pri vileged Exe c level.
B ASIC C ONFIGURATION 1-7 Note: Only one VLA N interf ace can be assigne d an IP add ress (t he default is VLAN 1). This d efines the ma nagement VL AN, the only VLAN through w hich yo u can gai n mana geme nt acces s to th e switch.
S WITCH M ANAG EMENT 1-8 4. T o set the IP a ddre ss of th e defa ult gatew ay for the net wo rk to whic h the switch belongs, type “ip de fault-g ateway gatewa y , ” where “gatewa y” is the IP addr ess of t he defaul t gatewa y . Press < Enter>.
B ASIC C ONFIGURATION 1-9 3. T ype “exit ” to retur n to the glo bal config uration mode. Press <Ente r>. 4. T ype “ip dhcp restart” to begin br oadcasti ng service request s . Press <Ente r>. 5. W ait a few min utes , and then c hec k the I P config uration setting s , b y typi ng the “s how ip inte rface” command.
S WITCH M ANAG EMENT 1-10 Community Strings Comm unity st rings are used to control m anagement ac cess to SNMP stations , as well as to authorize SNMP stat ions to recei ve t rap messages from t he switc h. Y ou therefo re nee d to assi gn comm unity s trings to speci fied users o r user gr oups, and set the ac cess l evel.
B ASIC C ONFIGURATION 1-11 Trap Receivers Y ou ca n also specify SNMP stations that are to re ceiv e traps from t he switch. T o configure a tr ap recei v er, co mplete the follo wing s teps: 1.
S WITCH M ANAG EMENT 1-12 Managing System Files Th e switch’ s fl ash memor y sup ports three types of system file s that can be managed by the CLI prog ram, W eb interface, or SNMP . Th e switch’ s file syste m allow s files t o be up loaded and downlo aded, co pied, dele ted, an d set as a start-up file .
S YSTEM D EFAULTS 1-13 In the s ystem flash memory , one file of e ach type must b e set as the start-up file. Durin g a system boot, the diag nostic and operat ion code files set as the start-up file are r un, and then the start-up configurat ion file is loaded.
S WITCH M ANAG EMENT 1-14 Security Privileged Exec Level Username “ admin” Password “admin” Normal Exec Level Username “guest” Password “guest” Enable Privilege d Exec from Normal Exec.
S YSTEM D EFAULTS 1-15 Virtual LANs Default VLAN 1 PVID 1 Acceptable Frame Type All Ingress Filterin g Disabled GVRP (global ) Disabled GVRP (port interface) Disabled Class of Service Ingress Port Pri.
S WITCH M ANAG EMENT 1-16.
2-1 C HAPTER 2 C ONFIGU RING THE S WITCH Using the We b Interface This sw itch provides an embedded HTTP W eb agent. Usin g a W eb bro wser y ou can confi gure the s witch an d view stati stics to monitor netw ork ac tivity . T he W eb agent can be accessed by an y computer on the network us ing a standa rd W eb browser ( Inter net Expl orer 5 .
C ONFIGURING THE S WI TCH 2-2 Notes: 1. Yo u are allow ed three attempts to enter the correct p assword; on th e third fail ed atte mpt the curr ent connectio n is terminate d. 2. If you log in to the Web interface as guest (Normal Exec le vel), you can view pag e informat ion but only chan ge the gue st password.
N AVIGATIN G THE W EB B RO W S E R I NTE RFA CE 2-3 The Main Men u links are used to navigate to ot her menus , and displa y config uration p aramete rs and st atist ics. Configuration Opt ions Configur able parameters ha ve a di alog bo x or a drop-do wn lis t.
C ONFIGURING THE S WI TCH 2-4 Notes: 1. To ensur e prope r scre en ref resh, be sure that I nternet Explor er 5.x is configured as follow s: Under the men u “Tools / Internet Options / Gen eral / Temporary Internet Files / Settings,” the setting f or item “Chec k for newe r versio ns of st ored pag es” should be “Every visit to the pa ge.
M AIN M ENU 2-5 Main Menu Using the on board W eb agent, you ca n defin e system para meters , manage and control the switch, and all its por ts, or monitor network condition s . The following table briefly des cribes the selec tions av ailable from this prog ram .
C ONFIGURING THE S WI TCH 2-6 Port Security Action Configure s the port i ntrusion act ion globally for the switch 2-4 0 Port Security Status Enables po rt security on specified ports 2-40 Address Tab.
M AIN M ENU 2-7 Priority Default Port Priority Sets the default priority for each port 2 -77 Default Trunk P riority Sets the default priority for each trunk 2-77 Traffic Class Maps IE EE 802.
C ONFIGURING THE S WI TCH 2-8 Basic Configuration Displaying System I nformation Y ou ca n easily identify the sys tem b y provi ding a d escripti v e name, location an d contact info r mation. Command Att ributes • Sy stem Name – Nam e assign ed to the s witch s ystem.
B ASIC C ONFIGURATION 2-9 • Web secure server port * – Shows the TCP port number used b y the HTTPS server. • POST result * – Shows resu lts of the po wer-on se lf-test * CLI Only We b – Click Sy stem, Sy stem I nfor ma tion.
C ONFIGURING THE S WI TCH 2-10 CLI – Specify the h ostname, location and contact infor m ation. Setting the IP A ddress An IP address m ay be used fo r managemen t access to the switc h ov er your netw ork. By default, the switc h uses DHCP to ass ign IP settings to VLAN 1 on the swit c h.
B ASIC C ONFIGURATION 2-11 • Management VLAN – This is the only VLAN through w hich you can gain m anageme nt acces s to the swi tch. B y default , all ports on the switch are members of VL AN 1, so a management station can be connec ted to a ny port on the sw itch.
C ONFIGURING THE S WI TCH 2-12 Manual Con figuration We b – Clic k System, IP . Specify the m anagement in terface , IP a ddress and default g ate wa y , then cl ick Apply . CLI – Specify t he management i nterface , IP addres s and defaul t gatewa y .
S ECUR ITY 2-13 If y ou lose your m anagement co nnectio n, use a console c onnectio n and enter “sh ow ip interfa ce” to d eter mine the new switch addr ess . CLI – Specif y the ma nagement i nterface , and set the IP A ddress Mode to DHCP or BOOTP .
C ONFIGURING THE S WI TCH 2-14 as soon as possib le, and s tore it in a sa fe plac e. (If for some reas on yo ur password is lost, you can reload the factory deafults file to restore the defau lt passw ords as describe d in “Tro ublesh ooting Cha rt” on pag e A-1.
S ECUR ITY 2-15 CLI – Assign a user nam e to acc ess-lev el 15 (i. e., ad ministra tor), then speci fy the pa ssw ord. Configuring RADI US/TACACS Logon A uthentication Y ou can conf igure t his sw itc h to authentic ate user s logging in to the s ystem for man agement access using local, RAD IUS , or TA CA CS+ authenticat ion method s .
C ONFIGURING THE S WI TCH 2-16 • RADIUS uses UDP while TACACS+ uses TCP. UDP only offer s best effort d elivery , while TC P offers a c onnectio n-oriente d transpo rt. Also, note th at RADIUS en crypts only the password in the access-r equest pa cket from t he client t o the s erver, whi le TACACS+ encrypt s the e ntire bo dy of the packet.
S ECUR ITY 2-17 The local switch user database has to be set up by manually entering user names an d passw ords using the CLI. RADIUS Settings • Server IP Address – Add ress of t he RADIUS s erver. (Default: 10.1.0.1) • Server Port N umber – Ne twork (UDP) port o f the RADI US ser ver used for auth enticatio n messages.
C ONFIGURING THE S WI TCH 2-18 We b – Click System, Authentication Settings . T o configure local or remote authen ticati on pre ference s , specify the aut henticat ion se quence ( i.e ., one to three methods), fill in the parameters for RADIUS or TA CACS+ authen ticati on if selected, and cl ick App ly .
S ECUR ITY 2-19 CLI Commands CLI – Sp ecify all the required pa rameters to enable log on a uthentic ation. HTTPS Y ou ca n configu re the swi tch to enable t he Secure Hyp ertext T ransfer Proto col (HTT PS) over the Sec ure Socket Lay er (SSL), providing se cure access (i.
C ONFIGURING THE S WI TCH 2-20 The foll owi ng W eb bro wser s and op eratin g system s currentl y support HTTPS: When y ou start HTTPS , the client and server es tablish a secure e ncr ypted conne ction. A p adlock icon sh ould appe ar in the st atus bar f or Inter net Explorer 5.
S ECUR ITY 2-21 CLI Commands CLI – En ter the follo wing commands to spe cify the s ecure port n umber and to en able HTTPS . SSH The Secure Shell ( SSH) server f eature pr ovid es remo te manageme nt access via en cr ypte d paths between the swit ch and SS H-enab led ma nag ement station clie nts .
C ONFIGURING THE S WI TCH 2-22 CLI Commands CLI – En ter the follo wing commands to conf igure the SSH service. Managing Firmwa re Y ou can up load/down load fir mwa re to or fro m a TFTP ser v er . By saving r untime code to a file on a TFTP ser v er, that file can later be downloaded to the sw itch to restor e opera tion.
M ANAGIN G F IR MW AR E 2-23 • Destination File Name — File names are cas e-sensiti ve . The file name sh ould not co ntain sla shes ( or /), the le ading lett er of th e file name shou ld not be a period (.), a nd the max imum length for file names on the TFTP ser ver is 127 char acters or 31 c haracters for files on the sw itch.
C ONFIGURING THE S WI TCH 2-24 T o start the new fi r mware , rebo ot the system. CLI – Enter t he IP a ddress o f the TFTP ser v er , sele ct conf ig or opcod e file type, then enter the source and destination file names , set the new file to star t up the system, a nd then rest ar t the swit ch.
M ANAGIN G F IR MW AR E 2-25 names on the TFTP ser ver is 127 char acters or 31 c haracters for files on the switch. (Valid characters: A-Z, a-z, 0-9, “.”, “-”, “_”) Note: The maxim um number of user -defined configuration file s is limited only by available Flash memory spac e.
C ONFIGURING THE S WI TCH 2-26 CLI – Enter the IP address of the TFTP server , specify the sou rce file on the se r ver, and set the star tup file name on t he switch. If you downloa d the star tup configuration file under a new f ile name, y ou can set this file as the startup file at a later ti me, and the n restart the switch.
D ISPLA YIN G B RIDGE E XTEN SIO N C APABILITIES 2-27 CLI – If you copy the r un ning configuration to a file, you can set this file as the startup file at a later time, a nd then rest ar t the s witch.
C ONFIGURING THE S WI TCH 2-28 • Static Entry Individual Port – This switch allows static filtering for unicast and multicast add resses. (Refe r to “Setting Static Addr esses” on page 2-41.) • VLAN Learning – T his switc h uses I ndepende nt VLAN Learning (IVL), whe re each port maintain s its own filtering database.
D ISPLA YIN G B RIDGE E XTEN SIO N C APABILITIES 2-29 We b – Click System, Bridg e Extension . CLI – Enter the following command. Console#show bridge-ext 3-137 Max support vlan numbers: 255 Max su.
C ONFIGURING THE S WI TCH 2-30 Displayi ng Switc h Hardw are/So ftware Versio ns Command Att ributes Main Board • Serial Number – The ser ial number of the s witch. • Service Tag * – Not i mplem ented. • Number of Ports – Numbe r of built-in RJ -45 ports • Hardware Versi on – Hardwar e version of the main boar d.
D IS PLAYING S WITCH H ARDW AR E /S OFTWARE V ERSIONS 2-31 We b – Click System, Switch Infor mation . CLI – Use the followin g command to display version infor mation.
C ONFIGURING THE S WI TCH 2-32 Port Configura t ion Displaying Connection Status Y ou can use the Port Infor ma tion or T r unk Infor m ation pag es to display the current c onnecti on stat us , incl uding link sta te, sp eed/dupl ex mode , flow co ntrol, and auto-negotiat ion.
P ORT C ONFIGURATION 2-33 We b – Click P or t, P or t Infor matio n or T r unk In for mation. Modify the required interface settings, and c lick Apply .
C ONFIGURING THE S WI TCH 2-34 Configuring I nterface Connections Y ou can use the T r unk Configuration or Port Configuration pag e to enable/disable an int erface , manually fix t he speed and duplex mode , set flow con trol, set auto-neg otiation , and set the inte rface capabilities to adve r tise.
P ORT C ONFIGURATION 2-35 used for half-dup lex operation and IEEE 802.3x for full-du plex opera tion. (Av oid usi ng flow con trol on a port conn ected to a hub unless it is actually required to solve a problem. Otherwise back pressu re jamming signals m ay degrade overall perfo rmance for t he segm ent attach ed to t he hub.
C ONFIGURING THE S WI TCH 2-36 CLI – Sele ct the in terface, and t hen enter th e require d settings. Setting Broadcast Storm Thresholds Broadc ast storms may occu r when a d evice on y our netw ork is malfunctioning, o r if application prog rams are not well design ed or proper ly config ured.
P ORT C ONFIGURATION 2-37 500-262143 packets per second ; Default : 500 packets per sec ond) • Broadc ast Contr ol Status – Shows whethe r or not br oadcas t storm cont rol has been e nabled. (Default: E nabled) We b – Click P ort, Port Broadcast Control.
C ONFIGURING THE S WI TCH 2-38 Configuri ng Port Mirrorin g Y ou ca n mirror traffic fr om any s ource port to a ta rget port for real-ti me analysi s . Y ou can then attac h a logi c analyzer o r RMON probe to the tar get port and stud y the traffic crossing the sourc e port in a comp letely unobtrusiv e manner .
P ORT C ONFIGURATION 2-39 Configuring P ort Security P ort se curity is a feature that allows you to configure a switch port with one or more device MA C addresses t hat are a uthori zed to acces s the network thro ugh tha t por t.
C ONFIGURING THE S WI TCH 2-40 Port S ecurit y Actio n The sw itc h allo ws you to se t th e secur ity ac tion to be take n whe n a po rt intr usion is dete cted.
A DDR ESS T ABLE S ETTINGS 2-41 CLI Configuratio n Use the interface comman d to sele ct the ta rget port, then use the port security action command to c onfigure the por t intr usion acti on (applies to all por ts). Use the por t security comma nd to enable security for the por t.
C ONFIGURING THE S WI TCH 2-42 Command Usa ge Entries specified via the W eb interface are per manent. Entries specified via the CL I can be mad e per man ent or c an be set t o be delete d on rese t. We b – Click Address T able, Static Addresses. Specify the interface, the MA C addr ess and VL AN , then c lick “ A dd Static Address.
A DDR ESS T ABLE S ETTINGS 2-43 Command Usa ge • You c an displ ay entri es in t he dynam ic address table by select ing an interface ( either port or trunk), MAC addres s, or VLAN. • You ca n sort the informat ion display ed based on interfa ce (port or trunk), MAC address, or VLAN.
C ONFIGURING THE S WI TCH 2-44 Changing the Agin g Time Y ou can se t the aging tim e for entri es in the dy namic addr ess table. Command Usa ge The range for the aging time is 17 - 2184 seconds. (The default is 300 second s .) We b – Click Address Table, Address Aging .
S PANNING T REE P RO T OC O L C ONFIGURATION 2-45 Th e Spanni ng T r ee Prot ocols su ppor ted by th e switch inc lude th e following st andards: • STP – Spanning Tree Protocol (IEEE 802.1D). • RSTP – Rapid Spanning Tree Protocol (IEEE 802.1w).
C ONFIGURING THE S WI TCH 2-46 STP Information The Spanning Tree, STP Information page co ntains in form atio n on th e current status of the Sp anning T ree . Command Att ributes • Spanning Tree State — Indica tes if the Span ning Tr ee Protocol i s current ly enabled o n the swit ch.
S PANNING T REE P RO T OC O L C ONFIGURATION 2-47 • Designated Root — Iden tifies th e prior ity and MA C addr ess of the device in the Span ning Tree that t he switch h as accept ed as th e root device. - Root Port — Specifies t he por t number on the s witch tha t is cl osest to the ro ot.
C ONFIGURING THE S WI TCH 2-48 * CLI only . We b – Click Spann ing T ree, S TP Information to disp lay cu r rent Sp anning T ree info r mation..
S PANNING T REE P RO T OC O L C ONFIGURATION 2-49 CLI – This exampl e show s the current Spannin g T ree setti ngs . Console#show spanning-tree 3-11 9 Spanning-tree information ----------------------------------------------------- ---------- Spanning tree mode :RSTP Spanning tree enable/disable :enable Priority :32768 Bridge Hello Time (sec.
C ONFIGURING THE S WI TCH 2-50 STP Configuration Global sett ings apply to the ent ire switch. Command Usage RSTP su ppor ts conne ctions to e ither S TP or RSTP nodes by moni toring the inco ming pro.
S PANNING T REE P RO T OC O L C ONFIGURATION 2-51 priority, th e device with the lowe st MAC addre ss will th en become th e root de vice . - Default: 32768 - Range: 0-61440, in steps of 4096 - Option.
C ONFIGURING THE S WI TCH 2-52 - D e f a u l t : 1 5 - Mini mum: Th e higher of 4 or [ (Max. Mes sage Ag e / 2) + 1] - Maximum: 30 • Path Cost Method — The p ath cost is u sed to de termine th e best path be tween devi ces. T he path co st method is used t o determin e the range o f values th at can be assigne d to each int erface.
S PANNING T REE P RO T OC O L C ONFIGURATION 2-53 We b – Click Spanni ng T ree, STP Conf igura tion. Modify th e required attributes, then click Apply . CLI – T his exa mple enable s Spanni ng T ree Pr otocol, a nd the n sets the indicated att ributes .
C ONFIGURING THE S WI TCH 2-54 STP Port and Trunk In formation Th e Spannin g T re e, STP P or t Inf or matio n and Spa nning T ree, STP T r unk Information display the current status of po r ts and trunks in the Spanning Tr e e .
S PANNING T REE P RO T OC O L C ONFIGURATION 2-55 • Designated Bridge — Th e priori ty and M AC address o f the device through which this port must communicate to reach t he root of the Spanning Tree.
C ONFIGURING THE S WI TCH 2-56 • Path Cos t – This parame ter is used b y the STA to determine th e best path b etween devi ces. Therefo re, lower values should be a ssigned to ports attache d to fast er media, and high er values a ssigned to port s with slower m edia.
S PANNING T REE P RO T OC O L C ONFIGURATION 2-57 durin g rec onfigu rati on even ts, do es not ca use th e spann ing tr ee to reconfi gure when the in terface ch anges sta te, and also ov ercomes other STA-related time out prob lems. Howeve r, remembe r that Edge Port s hould only be enabl ed for po rts conn ected to an end-no de device.
C ONFIGURING THE S WI TCH 2-58 CLI – T his ex ampl e displ ys the cur rent S panni ng T ree st atus of a por t. STP Port and Trunk Configur ation Y ou ca n configu re RSTP attr ibutes for specifi c interfa ces , includi ng port prior ity , path cos t, lin k type , and ed ge port.
S PANNING T REE P RO T OC O L C ONFIGURATION 2-59 begins learni ng addr esses. - Forwarding — Port for wards pack ets, and continues learning addr esses. • Priority — Defines t he priority us ed for this por t in the Spannin g Tree Protoc ol. If the pa th cost f or all ports on a swit ch is the same, t he port with the high est priority (i.
C ONFIGURING THE S WI TCH 2-60 - Auto — The switch automatica lly determines if the interface is attache d to a point -to-poi nt link or to s hared me dia. • Admi n Edge Port — You can enable this optio n if an interface is attache d to a LAN se gment th at is at the e nd of a brid ged LAN or to an end n ode.
VLAN C ONFIGURATION 2-61 We b – Click S pannin g T ree, S TP P ort Config uration o r STP T r un k Configuration. Modify the requir ed attri butes , then c lick A pply . CLI – This example sets STP attribut es for port 5. VLAN C onfig urat ion In conventional networks with rou ters , broa dcast traffic is split up into separate domains.
C ONFIGURING THE S WI TCH 2-62 An IEEE 802.1Q VLAN is a g roup of por ts that can be located anywhere in the n etw ork, but commun icate as t hough th ey belong to th e same ph ysical seg ment. VLANs he lp to simplify network manag ement by allowing you to move device s to a new VLAN without h aving to chang e any p hysical conne ctions.
VLAN C ONFIGURATION 2-63 along th e path that will car r y this traffic to the same VLAN (s), either manually or dynamically using GVRP . Howev er, if you want a por t on this switch to par ticipate i.
C ONFIGURING THE S WI TCH 2-64 configu red to broa dcast a mess age to you r network indica ting the VLA N group s it wa nts to join. When this switch receiv e s these messages , it will autom aticall y place th e receivi ng port in th e specif ied VLANs , and the n forw ard the message to all other po r ts .
VLAN C ONFIGURATION 2-65 forw arding a frame from this switch along a pa th that does not cont ain any VLAN-aware devices (inc luding the destin ation host) , the switch must first strip off the VLAN tag before forw arding the frame.
C ONFIGURING THE S WI TCH 2-66 Displaying Current VLANs The VLAN Curren t T able sho ws the current port member s of ea ch VLAN and whethe r or not the po r t su pports VLAN t ag ging . P or ts assi gned to a large VLAN group that crosses se ver al swi tch es should use VLAN tag ging.
VLAN C ONFIGURATION 2-67 We b – Click V LAN , VLAN Current T able. Sel ect any ID fro m the scroll-down list. Command Att ributes for CLI Interface • VLAN – ID of co nfigured VLAN (1-4094, no leading zeroes). • Type – Shows how th is VLAN was a dded to th e switch.
C ONFIGURING THE S WI TCH 2-68 • Ports / Channel groups – Shows t he VLAN inter face m embers. CLI – Cur rent VLAN i nfor mation can be disp layed with the following command. Creati ng VLANs Use The VLAN Static List to create or r emov e VLAN g roup s .
VLAN C ONFIGURATION 2-69 • State – Shows if this VLAN is enabled or di sabled (CLI). - Active : V LAN is operation al. - Suspe nd : VLAN is suspe nded; i.e., does no t pass pac kets. • Add – Adds a n ew VLAN gro up to the c urrent list. • Remove – R emoves a VLAN gr oup fro m the c urrent list.
C ONFIGURING THE S WI TCH 2-70 Adding Interf aces Based on Membership Type Use the VLA N Static T abl e to modify the settings for an existing V LAN . Y ou ca n add o r delet e port membe rs for a VLAN , dis able or enable VLAN tag ging for any por t, or prevent a po rt from b eing autom atically added to a VLAN via the GVRP protoco l.
VLAN C ONFIGURATION 2-71 therefore not carry VL AN or CoS infor mation. Note that an interface mus t be assig ned to at least one group as an untag ged port. - Forbidden : Interface is forbid den from automatically joining the VLAN via GVRP. For more informat ion, see “GVRP” on page 81.
C ONFIGURING THE S WI TCH 2-72 CLI – The follow ing examp le sho ws ho w to ad d tag ged and un tag ged ports t o VL AN 2. Adding Interf aces Based on Static Membership Use the VLAN S tatic Membership by P ort menu to assi gn VLAN g roup s to the se lected in terface add an interf ace to the sele cted VLAN as a t ag ged member.
VLAN C ONFIGURATION 2-73 We b – Open VLAN , VLAN Stati c Membershi p . Select an interf ace from the scr oll-down box (Port or T r unk). C lick Quer y to d isplay VLAN membership in for mation for the interface. Select a VLAN ID , and then click Add t o add the int erface as a tagg ed member , or click R emov e to remov e the interface.
C ONFIGURING THE S WI TCH 2-74 Command Usa ge • GVRP – GARP VLAN Reg istratio n Protoc ol define s a way f or switch es to ex change VLAN in form ation in order to automatically regis ter VLAN m embers on interfaces across th e netwo rk.
VLAN C ONFIGURATION 2-75 port ). - If ingress filte ring is enabled, th e interface will discard inco ming frames tagged for VLANs w hich do not include th is ingress port in their member set. - Ingress filtering does not affect VLAN independent BPDU frames, such as GVR P or STP.
C ONFIGURING THE S WI TCH 2-76 - 1Q Trunk – Specifies a port as an end-point for a VLAN t runk. A trunk is a direct link betwe en two s witches, so the po rt trans mits tagged frames that ide ntify the sou rce VLAN . However, not e that frames be longing to the port’ s default VL AN (i.
C LASS OF S ER VICE C ONFIGURATION 2-77 Class of Se rvice Configura tion Class of Ser vice (CoS) allows you to sp ecify which data packets ha ve greater pr ecedence whe n traffi c is buff ered in th e switc h due to cong estion . Th is switch suppo rts CoS with fou r priorit y queue s for each port.
C ONFIGURING THE S WI TCH 2-78 • If the outpu t port is an un tagged me mber of the as sociated VL AN, these f rames a re stri pped of a ll VLAN tags pr ior to tr ansmiss ion. Command Att ributes • Default Priority – The priority that is assigned to untagged fra mes received on the speci fied por t.
C LASS OF S ER VICE C ONFIGURATION 2-79 W eighte d R ound R obin (WRR ). Up t o eigh t separ ate traff ic pri oriti es a re defined in IEEE 802.1p . The default priority leve ls are assigned according to recommendations in the IEEE 802.1p standard as shown in the foll owing table .
C ONFIGURING THE S WI TCH 2-80 • Traffic Class – Output queue buf fer. (Range: 0 - 3, where 3 is t he highest CoS priorit y queue) We b – Click Priority , T raffic Classes.
C LASS OF S ER VICE C ONFIGURATION 2-81 Setting the Service Weight for Traffic Classes Th is swit ch uses the W eight ed Round Robin (WRR ) alg orit hm to deter mine the frequency at which it ser vices each priority queu e.
C ONFIGURING THE S WI TCH 2-82 CLI – The follow ing examp le sho ws how to assi gn WRR w eights o f 1, 4, 16 and 64 to the CoS priority queues 0, 1, 2 and 3. Mapp ing Laye r 3/ 4 Pri ori ties to C oS Val ues Th is switch supp ort s a commo n method of priori tizing laye r 3/4 traf fic to meet application requireme nts .
C LASS OF S ER VICE C ONFIGURATION 2-83 Command Attributes • IP Precedence/DSCP Priority Status – Sele cts IP Pr eced ence, DSCP, or dis ables both priority s ervices. We b – Click Prio rity , IP Preceden ce Prior ity . Select IP Precede nce or IP DSCP from th e IP Precede nce , DSCP Prio rity Status menu.
C ONFIGURING THE S WI TCH 2-84 Command Attributes • IP Precedence Priority Table – Show s the I P Preced ence to CoS map. • Class of Service Value – Map s a CoS value to the sel ected IP Precende nce value. Note that “0” r epres ents low priority a n d “7” repr esent h igh pr iority.
C LASS OF S ER VICE C ONFIGURATION 2-85 We b – Click Priori ty , IP Precedence Pri ority . Select an I P Precedence v alue from t he IP Prece dence Prior ity T able b y clic king on i t with y our curs or , enter a valu e in the Cl ass of Ser vice V alue field, and then clic k Apply .
C ONFIGURING THE S WI TCH 2-86 CLI – The follow ing examp le glob ally enabl es IP Prece dence service on the swi tch, maps IP Preceden ce v alue 1 to CoS v alue 0 on port 5, and t hen disp lays all the IP Preceden ce setti ngs for that port. (N ote that the set ting is global and applie s to all ports o n the switch.
C LASS OF S ER VICE C ONFIGURATION 2-87 Command Attributes • DSCP Priori ty Table – Sho ws the D SCP Prior ity to CoS map. • Class of Service Value – Ma ps a CoS value to the selected DS CP Priority va lue. Note that “0” repres ents low priority and “7” re present high prio rity.
C ONFIGURING THE S WI TCH 2-88 CLI – T he following example globally e nables DSCP Priority ser vice on t h e s w i t c h, m a ps DS C P v a l u e 1 t o C o S v a l u e 0 o n p o r t 5 , an d t h e n d is p l ay s all the DSCP Priorit y settings fo r that por t.
P ORT T RUN K C ONFIGURATION 2-89 consist s of more than four por ts , all othe r ports will be plac ed in a standby mode. Should one link in the t runk fail, one of th e standby ports will auto matic ally b e acti vat ed to rep lace it.
C ONFIGURING THE S WI TCH 2-90 Dynamically Configuring a Trunk with LACP Command Usage • To av oid crea ting a loo p in the ne twork, be sure you en able LAC P befor e conn ecti ng the po rts, and also di sconn ect the port s befo re disabling LACP.
P ORT T RUN K C ONFIGURATION 2-91 We b – Click T r unk, LACP Configuration. Select any of the switch por ts from the scroll-down por t list and click Add.
C ONFIGURING THE S WI TCH 2-92 CLI – The follow ing exampl e enables L A CP for po rts 17 and 18. J ust connec t thes e ports to tw o LA CP- enabled tr unk po rts on anot her swit ch to for m a tr unk.
P ORT T RUN K C ONFIGURATION 2-93 We b – Click T r unk, T r unk Configuration. Enter a tr unk ID of 1-6 in the T r unk fiel d, select an y of the switc h ports fro m the scro ll-do wn port lis t, and cl ick Add. After y ou hav e comple ted ad ding ports to the memb er list, click Apply .
C ONFIGURING THE S WI TCH 2-94 CLI – This example creates tr unk 1 with port s 11 and 12. J us t connect these ports to tw o sta tic trunk ports on an other s witch to form a tr unk.
C ONFIGURING SNMP 2-95 Setting Community Access Strings Y ou ma y configure up to fi ve co mmunity str ings authorize d for manag em ent ac cess. F or se curity reaso ns , you s hould c onsider removin g the de fault str ings.
C ONFIGURING THE S WI TCH 2-96 CLI – The followi ng example ad ds the st ring “spi derman” with read/ write access . Specifying Trap Managers Y ou can specify up to five manag ement stations that will receive authentica tion failure messages and othe r trap messages from the switch.
C ONFIGURING SNMP 2-97 We b – Click SNMP , SNMP Configuratio n. Fill in the T rap Manag er IP Address bo x and the T rap Manager Commun ity String bo x, mark En able Au thenti cation T raps if requi red, an d then cl ick Add. CLI – This example adds a t rap manager and enables authenticati on traps .
C ONFIGURING THE S WI TCH 2-98 IP address 192.168.1.1 and mask 255.255.255.255 — Specifie s a valid IP address of 192.168.1.1 only . Note: IP filt ering does not affe ct management acces s to the switc h using the We b inter face o r Teln et.
M ULTICAST C ONFIGURATION 2-99 We b – Click SNMP , SNMP IP Filte ring . T o add an IP address , type the new IP address i n the IP Ad dress bo x, type the approp riate s ubnet ma sk in the Subnet M ask bo x, and the n click “ Add IP Filter ing Entr y .
C ONFIGURING THE S WI TCH 2-100 reduc es the netw ork ov erhe ad requir ed by a mu lticas t ser v er , the broa dcast traf fic must be care fully p r uned at ever y mult icast switch/ route r it pass es throug h to en sure th at traffic is only passed o n the h osts wh ich subscr ibed to this ser vice.
M ULTICAST C ONFIGURATION 2-101 • IGMP Query – A router, or multicast-e nabled switch, can pe riodically ask their ho sts if the y want to receiv e multicast traffic.
C ONFIGURING THE S WI TCH 2-102 which had been receivin g query packet s) to have exp ired. (Default : 300 seconds, Range: 300 - 500) • IGMP Version — Sets the protocol version for compat ibility with other devices on the netw ork. (D efault: 2, Range : 1 - 2) Notes: 1.
M ULTICAST C ONFIGURATION 2-103 CLI – T his example modifies the settin gs for multicast filtering, and then disp lays t he current status . Interfaces Att ached to a Multicast Ro uter Multicast rou.
C ONFIGURING THE S WI TCH 2-104 We b – Click IGMP , Mult icast Ro uter P ort I nfor mation. Select the required VLAN ID from the scroll-down list to display the associated multicast routers . CLI – T his example shows that P ort 11 h as been statically config ured as a port attached to a multicast r outer .
M ULTICAST C ONFIGURATION 2-105 • VLAN I D – Selects the VLAN to propagate all multicast traffic coming from the attached m ulticast r outer/swi tch. • Port or Trunk – Specifie s the in terface at tached to a mul ticast rout er. We b – Click IGMP , Static Multicast Ro uter P ort Configuratio n.
C ONFIGURING THE S WI TCH 2-106 • Multicast IP Address – The IP addr ess for a speci fic multicas t servi ce • Multicast Group Port L ist – Ports propagating a multic ast service; i.e., ports that be long to the in dica ted VLA N group . We b – Click IGMP , IP Multicast Registration T able.
M ULTICAST C ONFIGURATION 2-107 Adding Mu lticast Addresse s to VLAN s Multicast filte ring can be dynamic ally configured using IGM P Snooping and IGMP Query messages as de scribed i n “Conf iguring I GMP P arameters” on page 2-100.
C ONFIGURING THE S WI TCH 2-108 We b – Click I GMP , IGMP Memb er P or t T able . Specify t he inter face attached to a multicast ser vice (via an IGMP-e nabled switch or multicast router), indicate the VLAN that w ill propag ate the multicast ser vic e, specify the multicast IP address , and then click Add.
S HOWING D EVI CE S TATI STI CS 2-109 unusually hea vy loading). RMON st atistics provide access to a broad range of statistics, including a total count of d ifferent frame types and sizes passing thro ugh each por t. All values displayed ha ve been accumulated sinc e the las t syst em reboot , and are sho wn as co unts p er secon d.
C ONFIGURING THE S WI TCH 2-110 Transmit Octets The total number o f octets transmitted out of th e interface, inc luding framing chara cters. Tra nsm it U nica st Pack ets The t ota l nu mber of packets that higher- level protocols requested be transmitted to a subnetw ork-unicast addres s, including those t hat were discarde d or not sent.
S HOWING D EVI CE S TATI STI CS 2-111 Single Collisio n Frames The nu mber of successfully tran smitted frames for which trans mission is inhib ited by exactly one collision. Internal MA C Transmit Errors A count of frames for which transmissi on on a particular in terface fails due to an internal MAC sublayer tra nsmit error.
C ONFIGURING THE S WI TCH 2-112 Received Frames The total number of frames (bad, broadcas t and multicast) received. Broadcast Fram es The total num ber of good frames receive d that were directed to the broadcast address. No te that this does not include multicast packet s.
S HOWING D EVI CE S TATI STI CS 2-113 We b – Click Statistics, P or t Statistics . Select the requir ed interface , and then cl ick Query . Y ou can also us e the R efresh button a t the botto m of the page to update the s creen.
C ONFIGURING THE S WI TCH 2-114 CLI – This example show s statistics for port 13. Console#show interfaces counters ethernet 1/13 3-97 Ethernet 1/13 Iftable stats: Octets input: 868453, Octets output.
U SIN G THE C OMMAND L INE I NTE RFA CE 3-1 C HAPTER 3 C OMMAND L INE I NTERF ACE This ch apter de scribes how t o use th e Command Line In terface (CLI ).
C OMMAND L IN E I NTE RFA CE 3-2 After c onnecti ng to the sy stem thr ough th e conso le port, th e login sc reen displ ays: Telnet Connection T elnet op erates o ver the IP tran sport protocol . In th is enviro nment, y our management station and any netw ork device yo u want to manage o ver t he network must hav e a v alid IP address.
E NTERING C OMMANDS 3-3 After y o u con figure th e switch with an I P address , you can open a T elnet session by perfor ming these ste ps . 1. Fr om the rem ote ho st, ente r the T eln et comma nd and the IP addr ess of the device yo u want to access .
C OMMAND L IN E I NTE RFA CE 3-4 interfaces and status are keyw ords , ether net is an argu men t th at spe ci fies the inte rface ty pe, and 1/5 specifi es the un it/port. Y ou ca n enter commands as follo ws: • To enter a simple command , ente r the comm and keywor d.
E NTERING C OMMANDS 3-5 Sho wing C omm ands If you enter a “?” at the command prompt , the system will display the first lev el of k eyw ords for the curren t command class (No r mal Ex ec or Pri vileged Ex ec) or configur ation class (G lobal, Interfac e, Lin e, or VLAN Database).
C OMMAND L IN E I NTE RFA CE 3-6 Partial Keyword Lookup If yo u ter minate a partial keyw ord with a question mark, alternativ es that match the initial letters are provided. ( R emember not to le a ve a space betw een the com mand and quest ion mark.
E NTERING C OMMANDS 3-7 command classe s and asso ciated mo des are dis pla yed in th e followin g table: Exec Commands When y ou open a new cons ole s ession o n switc h with the use r name “gues t, ” the syst em enters Nor mal Ex ec command mo de (or gu est mode ).
C OMMAND L IN E I NTE RFA CE 3-8 Configura tion Commands Configuration commands are privileged level commands used to modify switch setting s . T hese comman ds modify the r unning configuration o nly and are n ot sa ved w hen the s witch is reboo ted.
E NTERING C OMMANDS 3-9 T o enter In terfac e, Line Conf igurati on, or VLAN mode, you must enter the “ interfac e ..., ” “ line ... ” or “ vlan database ” c ommand wh ile in Global Configuration mode.
C OMMAND L IN E I NTE RFA CE 3-10 Comman d Groups The syst em command s can be brok en do wn into the funct ional groups shown below . Command Grou p Descr iption Page General Basic comman ds for ente.
C OMMAND G RO U P S 3-11 Note that the access mode shown in the following tab les is indicated by thes e abbre viation s: NE (Nor mal Exec) PE (Privilege d Exec) GC (Global Con figuration) IC (Inter f.
C OMMAND L IN E I NTE RFA CE 3-12 General Comman ds enable Use th is command to acti v ate Pri v ile ged Exec m ode . In pri vileged mode, addition al commands are a v ailable, an d certain commands displa y additiona l infor matio n. See “Und erstanding Command Mod es” on pag e 3-6.
G ENERAL C OMMANDS 3-13 Command Usage • “super” is the default password re quired to ch ange th e command mode from Norma l Exec to Privilege d Exec.
C OMMAND L IN E I NTE RFA CE 3-14 Command Usage The “>” c haracter is appende d to the end of th e prompt to in dicate that t he system is in n or mal acces s mode . Example Related Commands enable (3-12) configure Use this command t o activate Global Co nfiguration m ode.
G ENERAL C OMMANDS 3-15 show h ist ory Use this command to sho w the co ntent s of the co mmand hist ory buffer . Default Setting None Command Mode Nor mal Exec, Pri vileged Ex ec Command Usage The his tory buffer size is fix ed at 20 comma nds .
C OMMAND L IN E I NTE RFA CE 3-16 reload Use t his co mmand to re start th e syste m. Note: When th e system is restarted, it will always run the Pow er-On Self-Test. It will also retain all config uration information s tored in nonvo latile mem ory by the copy running-config startup-config command.
G ENERAL C OMMANDS 3-17 Example This examp le sho ws how to return to the Pri vileged E xec mode from the Interface Config uration mode: exit Use this command to retur n to the previo us configuration mode or exit the configuration prog ram.
C OMMAND L IN E I NTE RFA CE 3-18 Command Mode Nor mal Exec, Pri vileged Ex ec Command Usage The quit and exit c ommand s can bot h exit t he confi gurati on program. Example This e xample sh ows how to quit a CLI session: Flash/File Commands These comman ds are use d to manage s ystem cod e and configu ration fil es .
F LASH /F ILE C OMMANDS 3-19 syste m operati on. The succes s of the file tran sfer d epends on the accessibility of the TFTP ser ver and the quality of the network connection .
C OMMAND L IN E I NTE RFA CE 3-20 • T o replace the startup co nfigura tion, you mu st use startu p-config a s the destination . • T he Boot R OM image canno t be uploa ded or do wnloaded from the TFTP ser ver.
F LASH /F ILE C OMMANDS 3-21 delete Use this command to delete a file or imag e. Syntax delete filename filename - Name of the configuration file or image name. Default Setting None Command Mode Pri vileged Ex ec Command Usage • If the file type is used for system startup, then this file cannot be delet ed.
C OMMAND L IN E I NTE RFA CE 3-22 dir Use this command t o display a list of files in Flash memor y . Syntax dir [ boot-rom | confi g | opco de [: filename ]] The type of file or image to disp lay includes: • boot-rom - Boot RO M (or diagnostic) image file • config - Switch configuratio n file • opcode - Run -time operation code image file.
F LASH /F ILE C OMMANDS 3-23 Example The following example shows how to display all file infor mation: whichboot Use this comman d to display which files bo oted. Default Setting None Command Mode Pri vileged Ex ec Example This examp le sho ws the info r mation displa yed b y the whichboot command .
C OMMAND L IN E I NTE RFA CE 3-24 boot system Use th is command to speci fy the file o r image used to sta r t up t he system . Syntax boot system { boot-rom | config | opcode }: filename The ty pe of.
S YSTE M M ANAGEME NT C OMMANDS 3-25 System Mana gement Com mands These comman ds are use d to con trol sys tem logs , passw ords , user nam e, browser configur ation o ptions, and di splay or con figure a variety of ot her system infor mation.
C OMMAND L IN E I NTE RFA CE 3-26 show ip s sh Displays the status o f the SSH serv er and the configured values for authentication timeout and retries PE 3-37 show ssh Displa ys the status of current.
S YSTE M M ANAGEME NT C OMMANDS 3-27 hostname Use this co mmand to speci fy or modify the ho st name for th is device . Use the no for m to restor e the default host name.
C OMMAND L IN E I NTE RFA CE 3-28 •{ 0 | 7 } - 0 means p lain passwo rd, 7 means en crypted p assword . • password password - The authent icatio n password fo r the user. (Maximum length: 8 characters plain text, 32 encrypted, case sensitive ) Default Setting • The default access l evel is No rmal Exec .
S YSTE M M ANAGEME NT C OMMANDS 3-29 enable password After initially log g ing onto the system, you should se t the administrator (Pri vileged Ex ec) and gues t (No r mal Ex ec) passw ords .
C OMMAND L IN E I NTE RFA CE 3-30 Related Commands enable (3-12) jumbo frame Use this command to enable ju mbo frames th rough th e switc h. Use th e no for m to d isable jumb o frames .
S YSTE M M ANAGEME NT C OMMANDS 3-31 ip http port Use this command to specify t he TCP port num ber used b y the W eb bro wser interface . Use the no fo r m to use the default port. Syntax ip http por t port-number no ip http por t por t-nu mber - Th e T C P p or t t o b e u s e d b y t h e b r o w se r i n t e r f a c e .
C OMMAND L IN E I NTE RFA CE 3-32 Command Mode Global Configura tion Example Related Commands ip http po rt (3-31) ip http secure-server Use th is command to enabl e the se cure h ypertext transfe r proto col (HTTPS) ov er the Secure Socke t Lay er (SSL), pr ovidi ng secur e access (i .
S YSTE M M ANAGEME NT C OMMANDS 3-33 for the connection . - The clie nt and s erver gener ate ses sion keys for encr ypting and decry pting d ata. • The clien t and server establ ish a secu re encrypt ed conn ection. A padl ock icon should a ppear in the st atus bar f or Intern et Expl orer 5.
C OMMAND L IN E I NTE RFA CE 3-34 Default Setting 443 Command Mode Global Configura tion Command Usage • You cannot co nfigur e the HTTP a nd HTTPS serve rs to us e the sam e port.
S YSTE M M ANAGEME NT C OMMANDS 3-35 Default Setting timeout: 120 seconds count: 3 Command Mode Global Configura tion Command Usage The tim eout specifies the int er val the switch will wait for a response from th e client durin g the SSH negotiation p hase .
C OMMAND L IN E I NTE RFA CE 3-36 Command Usage • The SSH server supports up to four clie nt sessions. The maximum number of client sessions include s both curr ent Teln et sess ions an d SSH sess ions.
S YSTE M M ANAGEME NT C OMMANDS 3-37 show ssh Use this command to displa y the cur ren t Secure Sh ell (SSH) s er ver conne ctions. Command Mode Pri vileged Ex ec Command Usage This c ommand shows the following infor mation : • Sess ion – The sessi on nu mber.
C OMMAND L IN E I NTE RFA CE 3-38 Example Related Commands ip ssh (3-34) logging on Use th is command to contro l logging of error messages . This command sends debug or er ror messag es to a log ging p roces s . The no for m dis ables the log g ing process.
S YSTE M M ANAGEME NT C OMMANDS 3-39 Related Commands log ging h istor y (3-39) log ging trap ( 3-42) clear log ging (3 -43) logging history Use this c ommand to limit syslog me ssage s sav ed to switch memo ry based on severity . Th e no for m returns t he logging of sysl og mess ages to th e default level.
C OMMAND L IN E I NTE RFA CE 3-40 * There are only Level 2, 5 and 6 error messages for the current firmware rele ase. Default Setting Flash: errors (lev el 3 - 0) RAM: warnings ( level 7 - 0) Command Mode Global Configura tion Command Usage The message lev el specified for Flash memory must be a higher p riorit y (i.
S YSTE M M ANAGEME NT C OMMANDS 3-41 Default Setting None Command Mode Global Configura tion Command Usage • By using this command m ore than once you can build up a list of host IP add resse s. • Th e maximum number of host IP addresse s allowed is five.
C OMMAND L IN E I NTE RFA CE 3-42 logging trap Use this c ommand to limit syslog messag es saved to a remo te ser ver base d on severity . Use the no for m to retur n the rem ote log ging o f syslog messages to the defaul t lev el. Syntax loggin g tr ap level no log g ing trap level leve l - One of the level arguments listed below .
S YSTE M M ANAGEME NT C OMMANDS 3-43 clear logging Use this command to clear messages fr om the lo g buffer . Syntax clear lo g ging [ fl a s h | ram ] • flash - Even t history stored in Flash memo ry (i.e., pe rmanent memory). • ram - Even t history stored in tempo rary RAM ( i.
C OMMAND L IN E I NTE RFA CE 3-44 Default Setting None Command Mode Pri vileged Ex ec Example show startup- config Use this command t o display the configuration file stored in nonv olatile memor y tha t is used to s tart u p the syst em.
S YSTE M M ANAGEME NT C OMMANDS 3-45 Command Mode Pri vileged Ex ec Example Console#show startup-config building startup-config, please wait..... ! ! snmp-server community private rw snmp-server commu.
C OMMAND L IN E I NTE RFA CE 3-46 Related Commands show r unning -config (3-46) show runnin g-config Use th is command to disp lay t he conf iguration infor mation cur rently in use .
S YSTE M M ANAGEME NT C OMMANDS 3-47 Example Related Commands show star tup-config ( 3-44) show system Use this command to displa y system information.
C OMMAND L IN E I NTE RFA CE 3-48 Example show u ser s Shows all activ e conso le and T elnet sess ions , including user name, idle time, and IP address of T elnet client .
S YSTE M M ANAGEME NT C OMMANDS 3-49 Example show ve rsion Use this command to disp lay hard war e and software version infor mation for the system. Default Setting None Command Mode Nor mal Exec, Pri.
C OMMAND L IN E I NTE RFA CE 3-50 Example Authen ticat ion Comma nds Y ou can configur e the s witch to authen ticate us ers lo g ging in to the system for management access using local or authentic ation-server meth ods .
A UTHE NTI CAT ION C OMMANDS 3-51 authentication login Use this command to de fine the l ogin au thentica tion method and preceden ce. Use the no for m to restore the default. Syntax authentication login {[ loca l ] [ radius ] [ tacacs ]} no authentication login • local - Use lo cal authen ticatio n.
C OMMAND L IN E I NTE RFA CE 3-52 manag ement acc ess via the cons ole port, a Web brow ser, or Telnet. These ac cess option s must be co nfigured on the authe ntication server. • RADIUS and TACACS+ log on authenticati on assigns a specific privilege level for each user name and password pair.
A UTHE NTI CAT ION C OMMANDS 3-53 Example radius-server p ort Use this command to set t he RADIUS ser ver netw ork port. Use the no for m to res tore the defau lt. Syntax radius-ser ver port port_number no radius-server por t por t_nu mber - RADIUS ser ver UDP por t used for authenticatio n messages .
C OMMAND L IN E I NTE RFA CE 3-54 Default Setting None Command Mode Global Configura tion Example radius-server re transmit Use this command to set the number of re tries .
A UTHE NTI CAT ION C OMMANDS 3-55 radius-server t imeout Use this comma nd to set the inter val between trans mitting auth entication request s to the RA DIUS se r ver .
C OMMAND L IN E I NTE RFA CE 3-56 tacacs-server host Use this command to speci fy the T ACA CS+ server . Use the no form to restore the default. Syntax tacacs-ser ver host host_ip_address no tacacs-ser ver host host_ip_ address - IP addre ss of a TA CA CS+ server .
A UTHE NTI CAT ION C OMMANDS 3-57 Example tacacs-server key Use this command to set t he TA CA CS+ encryption ke y . Use the no fo r m to restore th e default. Syntax tacacs-ser ver k ey ke y _ s tr i n g no tacacs-ser ver k ey key _ s t ri n g - Encr yption key used to authentica te log on access fo r the client.
C OMMAND L IN E I NTE RFA CE 3-58 Example SNMP Commands Controls access to this switch from SNMP m anagement stations, as well as the er ro r type s sent to t rap mana ger s . snmp-serv er community Use th is command to define the com munity access s tring for the Simpl e Network Man ageme nt Pr otocol.
SNMP C OMMANDS 3-59 Syntax snmp-ser ver community str in g [ ro | rw ] no snmp-ser ver community string • string - Community string that acts like a passwo rd and permits acces s to th e SNMP p rotocol . (Max imum le ngth: 32 charac ters, c ase sensitive ; Maximum nu mber of st rings: 5) • ro - Specifi es Read-on ly access.
C OMMAND L IN E I NTE RFA CE 3-60 snmp-serve r contact Use th is command to set the sys tem cont act stri ng . Use th e no for m to remo v e the sy stem co ntac t information. Syntax snmp-ser ver contact st rin g no snmp-ser ver contact string - String that describes the system co ntact infor mation .
SNMP C OMMANDS 3-61 Default Setting None Command Mode Global Configura tion Example Related Commands snmp-server con tact (3-60) snmp-serv er host Use this command to speci fy the rec ipient of a Simple Netw ork Manag ement P rotocol n otificatio n operat ion.
C OMMAND L IN E I NTE RFA CE 3-62 Default Setting Host Add ress: N one SNMP V ersion: 1 Command Mode Global Configura tion Command Usage • If you do not enter an snm p-server host comm and, no n otifi cation s are se nt. In o rder to configure the switc h to se nd SNMP notificatio ns, you mus t enter at least on e snmp-serve r host com mand.
SNMP C OMMANDS 3-63 snmp-serve r enable traps Use this command t o enable this device to send Simple Network Manag ement P rotocol tr aps (SNM P noti fications ).
C OMMAND L IN E I NTE RFA CE 3-64 Example Related Commands snmp-ser ver host (3-61) snmp ip f ilter Sets the IP addres ses of clien ts that are allowed manage ment acce ss to the switch vi a SNMP . Us e the no for m of this command to remo ve an IP address .
SNMP C OMMANDS 3-65 specified by the bitmask. • Th e default setting is null, w hich a llows all IP groups SNM P access to the switch. If one IP address is configured, the IP filtering is enabled and only addresses in th e IP group will have SNMP access .
C OMMAND L IN E I NTE RFA CE 3-66 Example Console#show snmp SNMP traps: Authentication: enable Link-up-down: enable SNMP communities: 0 SNMP packets input 0 Bad SNMP version errors 0 Unknown community.
IP C OMMANDS 3-67 IP Commands An IP address m ay be used fo r managemen t access to the switc h ov er your netw ork. By default, the switc h uses DHCP to as sign IP settings to VLAN 1 on the swit c h. If you wish to manually configure IP se ttings, y ou need to chan ge the switch ’ s use r -specified def aults (I P address 0.
C OMMAND L IN E I NTE RFA CE 3-68 • dhcp - Obtains IP address from DHCP. Default Setting IP address: 0.0.0.0 Netmask: 255.0.0.0 Command Mode Interf ace Conf igurati on (VLA N) Command Usage • You must assign an IP ad dress to this device t o gain management access ov er the n etwork.
IP C OMMANDS 3-69 Related Commands ip dhcp restart (3-69) ip dhcp rest art Use this command to submit a BOOTP or DCHP clie nt request. Default Setting None Command Mode Pri vileged Ex ec Command Usage • DHCP requires th e server to reassign the client ’s last address if available.
C OMMAND L IN E I NTE RFA CE 3-70 ip default-gateway Use th is command to a estab lish a s tatic ro ute betw een this device an d manageme nt stat ions t hat exis t on an other n etw ork s egment .
IP C OMMANDS 3-71 Command Mode Pri vileged Ex ec Command Usage This s witch can only be assig ned one IP address. This address is used for manag ing the sw itch. Example Related Commands show ip redire cts (3-71) show ip redirects Use this command to show th e default gatew ay conf igured fo r this devic e.
C OMMAND L IN E I NTE RFA CE 3-72 ping Use this command to send ICMP ech o request pack ets to an other no de on the netw ork. Syntax ping host [ co unt count ][ size size ] • host - IP addres s or IP alias of the hos t. • coun t - Number of packets to send.
L INE C OMMANDS 3-73 Example Related Commands inte rface (3 -85) Line Co mmand s Y ou can a ccess the onboard configuration program by attaching a VT100 compa tible devic e to the s er ver’ s serial port. These comman ds are us ed to set com municati on parame ters for the serial port or a virtual terminal.
C OMMAND L IN E I NTE RFA CE 3-74 line Use this command to identi fy a specifi c line for config uration, an d to proce ss subseq uent line config uratio n command s . Syntax line { console | vty } • console - Consol e terminal line. • vty - Virtual termin al for remote cons ole access.
L INE C OMMANDS 3-75 Example T o enter cons ole li ne mode , enter the follo wing com mand: Related Commands show line (3-83) show users (3-48) login Use this command to en able pass wo rd chec king at login. Use the no form to di sable passw ord chec king and allo w connecti ons wi thout a pass wo rd.
C OMMAND L IN E I NTE RFA CE 3-76 Exec (NE) mo de. - logi n loc al selec ts auth enticatio n via the u ser na me and p assword specifie d by the usern ame command (i.
L INE C OMMANDS 3-77 Command Mode Line Configuration Command Usage • W hen a c onnecti on is start ed on a lin e with password prote ction, th e system prompt s for the pass word.
C OMMAND L IN E I NTE RFA CE 3-78 Default Setting CLI: No timeout T elnet: 10 minutes Command Mode Line Configuration Command Usage • If input is detec ted, th e system resu mes the cur rent conn ection; or if no connect ions ex ist, it returns th e termin al to th e idle st ate and disco nnects th e inco ming se ssion .
L INE C OMMANDS 3-79 Command Mode Line Configuration Command Usage • W hen the logon attem pt thre shold is rea ched, the syste m interface becomes silent fo r a specified amo unt of t ime before allowing the next logon atte mpt. (Use the sile nt-time comman d to set this inte rval.
C OMMAND L IN E I NTE RFA CE 3-80 Default Setting The default value is no si lent-time. Command Mode Line Configuration Command Usage If the pa ssword thresho ld was not set with the pass word-thresh command , silen t-time be gins af ter the defau lt v alue of t hree failed log on attemp ts .
L INE C OMMANDS 3-81 Command Mode Line Configuration Command Usage The databits co mmand can be used to mas k the high bit on input from dev ices that g ene rate 7 da ta bits wi th parity . If pa rity is be ing generated, specif y 7 data bits per c haracter .
C OMMAND L IN E I NTE RFA CE 3-82 Command Usage Communic ation pr otocol s provided by devices s uch as te r minals and modems o ften req uire a spec ific parity b it setting. Example T o specify no p arity , enter t his comma nd: spee d Use this command to set th e ter min al line's baud rate.
L INE C OMMANDS 3-83 stopbit s Use this co mmand to set the number of the sto p bits transm itted per byte. Use the no for m to re store the defa ult setting.
C OMMAND L IN E I NTE RFA CE 3-84 Command Mode Nor mal Exec, Pri vileged Ex ec Example T o show all lines, enter this command: Interface Commands These comman ds are us ed to d ispla y or set co mmuni cation paramet ers for an Ethernet port, a g g regated link, o r VLAN .
I NTERFACE C OMMANDS 3-85 interface Use this command to conf igure an i nterface type and enter i nterface config uration m ode. Use the no for m to remo ve a trunk. Syntax interf ace interface no interface por t-channel channel-id interface • ethernet unit / port - unit - This is device 1.
C OMMAND L IN E I NTE RFA CE 3-86 description Use this command to add a des cription t o an interfac e. Use th e no for m to remove the desc riptio n. Syntax description stri ng no description string - Commen t or a description to help y ou remember w hat is attached to this inter face.
I NTERFACE C OMMANDS 3-87 • 1000full - Forces 1000 Mbps full-duplex operation • 100full - Forces 100 Mbps full-duplex oper ation • 100half - Forces 100 Mbps half-duplex operation • 10full - Fo.
C OMMAND L IN E I NTE RFA CE 3-88 negotiation Use this command to enable auton ego tiation fo r a given interface . Use the no form to dis able a utonegoti atio n.
I NTERFACE C OMMANDS 3-89 capabilities Use this command t o adv ertis e the port c apabilities of a given interface during auto negotiation. Use the no for m with paramete rs to remove an advertised capability , or the no for m with out parame ters to res tore the defau lt values.
C OMMAND L IN E I NTE RFA CE 3-90 Command Usage Whe n auto-neg otia tion is ena bled with th e neg otiation c ommand, the switch will n eg otiate the b est sett ings for a link based on the capab ilites command. Wh en auto-neg otiation is dis abled, you must manually specif y the link at tributes wi th the s peed-dupl ex and flow control commands .
I NTERFACE C OMMANDS 3-91 optimal s ettings will b e determined by th e capabilities co mmand. To enable flow co ntrol under aut o-negot iati on, “fl owcon trol” must b e included in the capabilities list fo r any port.
C OMMAND L IN E I NTE RFA CE 3-92 Default Setting All interfaces are enabled. Command Mode Interf ace Conf iguratio n (Eth ernet, P or t Chann el) Command Usage Th is command allows you to dis able a po rt du e to abno r mal be havior (e.g ., excessive collisions), and then re enable it after the prob lem has been res olved.
I NTERFACE C OMMANDS 3-93 Command Usage • When broadcast traffic exc eeds the spe cified th reshold, pac kets above that th reshold are d ropped. • This comma nd can en able or disable broadc ast storm contr ol for the selected interface . However, the sp ecified thr eshold value a pplies to all ports o n the switch .
C OMMAND L IN E I NTE RFA CE 3-94 Command Usa ge • If you enab le port security, the sw itch will stop dynamic ally learning new addre sses on the specif ied port. Only incomi ng traff ic with sour ce addresses already stored in the dynami c or static address table will be accepted .
I NTERFACE C OMMANDS 3-95 Syntax clear counters inte rfa ce interface • ethernet unit / port - unit - This is device 1. - port - Port number. • port-channel chann el-id (Range: 1-6) Default Setting None Command Mode Pri vileged Ex ec Command Usage Statistics are only initializ ed for a power reset.
C OMMAND L IN E I NTE RFA CE 3-96 • ethernet unit / port - unit - This is device 1. - port - Port number. • port-channel chann el-id (Range: 1-6) • vlan vlan-id (Range: 1-4094) Default Setting None ( F or a de scripti on of th e items displa yed b y this command, see “Displaying Conne ction Sta tus” on page 2 -32.
I NTERFACE C OMMANDS 3-97 show interfaces counters Use this command to displa y statistics for an interfac e. Syntax show interfaces counters [ interface ] interface • ethernet unit/p ort - unit - This is device 1. - port - Port number. • port-channel chann el-id (Range: 1-6) Default Setting Shows the counters for all interfaces.
C OMMAND L IN E I NTE RFA CE 3-98 Example show i nterface s swit chport Use th is command to disp lay the administ rativ e an d operati onal status of the spec ifie d inte rface s.. Syntax show interfaces s witchpor t [ interfac e ] interface • ethernet unit / port - unit - This is device 1.
I NTERFACE C OMMANDS 3-99 Default Setting Shows all interf aces . Command Mode Nor mal Exec, Pri vileged Ex ec Command Usage If no interface is specified, infor matio n on all interfaces is d isplayed.
C OMMAND L IN E I NTE RFA CE 3-100 Addre ss Ta ble Com mands These comma nds are use d to con figure th e addre ss table for filte ring speci fied add resses , displa ying current entri es , clearing the ta ble, o r sett ing the agin g time. mac-address-table static Use thi s comman d to map a static address t o a port in a V LAN .
A DDRESS T ABL E C OMMANDS 3-101 Syntax mac-address-tabl e static mac-address interf ace vlan vlan-id [ action ] no mac-address-table sta tic mac-address vlan vlan-id • mac-address - MAC a ddress. • interface • ethernet unit / port - unit - This is device 1.
C OMMAND L IN E I NTE RFA CE 3-102 Example show mac-address -table Use th is command to view cl asses of e ntries in the b ridge-forwa rding datab ase. Syntax show mac-address-ta ble [ addr ess mac-address [ mask ]] [ interface interface ] [ vlan vlan-id ] [ sort { address | vlan | interface }] • mac-address - MAC a ddress.
A DDRESS T ABL E C OMMANDS 3-103 - Delete-o n-reset - static en try to be deleted when syst em is re set • The mask sh ould be hexade cimal num bers (repre senti ng an equi valent bit mask) in th e form xx-xx-xx-xx-xx-xx that is applied to the spe cified MAC address.
C OMMAND L IN E I NTE RFA CE 3-104 Syntax mac-address-tabl e agin g- tim e seconds no mac-address-table aging-time seconds - Time is number of seconds (17-2184). Default Setting 300 seconds Command Mode Global Configura tion Command Usage The aging t ime is used to ag e out dynamica lly learned forward ing infor mation.
S PANNING T REE C OMMANDS 3-105 Spanni ng Tree Com mands This secti on incl udes comma nds that config ure the Sp anning T ree Protoc ol (STP) for the o verall s witch , and com mands tha t configu re STP for the s elected interfa ce.
C OMMAND L IN E I NTE RFA CE 3-106 spanning- tree Use thi s command t o enable the S panni ng T re e Protocol glob ally for th is switch. U se the no form to disable it. Syntax spanning-tree no spanning-tree Default Setting Spanning T ree is enab led.
S PANNING T REE C OMMANDS 3-107 spanning- tree mode Use this command to select the Sp anning T ree mode for this s witch. Use the no form to disable it. Syntax spanning-tree mode { stp | rstp } no spanning-tree mode • stp - Spanning Tree P rotocol (IEEE 802.
C OMMAND L IN E I NTE RFA CE 3-108 Example The follo wing ex ample con figures t he switc h to us e Rapid Spann ing T ree: spanning-tree for ward-time Use th is command to conf igure the Spanning T ree bridge forw ard ti me globally for this sw itch. Use the no form to restore the default.
S PANNING T REE C OMMANDS 3-109 spanning-tree hello-t ime Use this command to conf igure the Spanni ng T ree bri dge hello ti me globally for this sw itch. Use the no form to restore the default. Syntax spanning-tree hello-ti me tim e no spanning-tree hello-time time - Time in seconds .
C OMMAND L IN E I NTE RFA CE 3-110 Default Setting 20 seconds Command Mode Global Configura tion Command Usage This command s ets the m aximu m time (in s econds) a device can w ait without receiving a configur ation mess age be fore a ttempting to reconfi gure.
S PANNING T REE C OMMANDS 3-111 Command Mode Global Configura tion Command Usage Bridge prio rity is used in selecting the root device, root por t, and design ated po rt.
C OMMAND L IN E I NTE RFA CE 3-112 Example spanning-tree transm ission-limit Use th is command to conf igure the minim um interval bet ween t he transm issio n of consecu tiv e RSTP BPDUs .
S PANNING T REE C OMMANDS 3-113 spanning-tree cost Use this command to conf igure the Spanni ng T ree path cost fo r the specified inte rface . Use the no for m to restore the d efault. Syntax spanning-tree cost cost no spanning-tree cost cost - Th e path cost for the interface.
C OMMAND L IN E I NTE RFA CE 3-114 Example Related Commands spanning-tree port-priority (3-114) spanning- tree port-priority Use this co mmand to con figure the pri ority for th e specifie d interface .
S PANNING T REE C OMMANDS 3-115 Related Commands spanning-tree cost (3-113) spanning-tree por tfast Use this command to set an interface t o fast forw arding .
C OMMAND L IN E I NTE RFA CE 3-116 Related Commands spanning-tree edge-por t (3-116) spanning-tree edge-port Use thi s comman d to specify an inte rface as an edge port.
S PANNING T REE C OMMANDS 3-117 Related Commands spanni ng-tree por tfast (3-1 15) spanning-tree protocol-m igration Use this command to re-ch eck the ap propriate BPDU format to send on the se lected i nterface . Syntax spanning-tree protocol -mig ration in terface interface • ethernet unit / port-number - unit - This is device 1.
C OMMAND L IN E I NTE RFA CE 3-118 spanning-tree link- type Use thi s comman d to config ure the link type for the Rapid Spann ing T ree. Use the no form to restore the defau lt. Syntax spanning-tree link-type { auto | point-to-point | shar ed } no spanning-tree link-type • auto - Automatica lly derived fr om the duplex mod e setting.
S PANNING T REE C OMMANDS 3-119 show spa nning-t ree Use this command to sho w the configur ation for th e Spannin g T ree. Syntax show spanning-tree [ interfac e ] • interface • ethernet unit / port-number - unit - This is device 1.
C OMMAND L IN E I NTE RFA CE 3-120 Example Console#show spanning-tree Spanning-tree information ----------------------------------------- ---------------------- Spanning tree mode :RSTP Spanning tree enable/disable :enable Priority :32768 Bridge Hello Time (sec.
VLAN C OMMANDS 3-121 VLAN Commands A VLAN is a g roup of por ts that ca n be locate d anywhe re in the network, but co mmunicat e as th ough they belong t o the sa me ph ysical s egment.
C OMMAND L IN E I NTE RFA CE 3-122 vlan database Use this command to enter VLA N databas e mode. All com mands in t his mode will take effect immediate ly . Default Setting None Command Mode Global Configura tion Command Usage • Use the VLAN databas e command mode to a dd, change, and delete VLANs.
VLAN C OMMANDS 3-123 vlan Use this command to conf igure a VLAN . Us e the no for m to restore the default se ttings or delete a VL AN . Syntax vlan vlan-id [ name vlan -name ] m edia ether net [ state { ac tive | suspend }] no vlan vla n-id [ name | state ] • vlan -id - ID of co nfigured VL AN.
C OMMAND L IN E I NTE RFA CE 3-124 Example The following example adds a VLAN , using vlan-id 105 and name RD5. The VL AN is acti v ated b y defau lt. Related Commands show vlan (3-131) interface vlan Use this co mmand to ente r interface con figurati on mode for VL ANs , and configure a physical interface .
VLAN C OMMANDS 3-125 Related Commands show vlan (3-131) switch port mode Use this command to conf igure the VLAN mem bership mode for a p ort. Use the no for m to restore the default. Syntax swi tchpor t mode { tr unk | hy bri d } no switchpor t mode • trunk - Specifies a po rt as an end-poin t for a VLAN trunk.
C OMMAND L IN E I NTE RFA CE 3-126 switchport acceptable-frame- types Use this command to con figure th e acceptable fra me types fo r a port. Use the no for m to resto re the defa ult. Syntax swi tchpor t acceptable-frame-types { all | tagged } no switchpor t accepta ble-frame-types • all - The p ort passes al l frames, t agged or u ntagged.
VLAN C OMMANDS 3-127 switchport ingress-filter ing Use this command to enable i ngress filtering for an in terfa ce. Use the no for m to res tore the defau lt.
C OMMAND L IN E I NTE RFA CE 3-128 switchport native vlan Use this c ommand to con figure the PV ID (i.e., default V LAN ID) for a port. U se the no for m t o restore th e defau lt. Syntax swi tchpor t nativ e vlan vlan -id no switchpor t nativ e vlan vlan-id - Default VLAN ID fo r a port.
VLAN C OMMANDS 3-129 switchport allowed vlan Use this command to conf igure VLA N groups on the s electe d interf ace. Use the no for m to restore the default. Syntax • switchport allowed vlan { add vlan-l ist [ tag ged | untagged ] | remove vlan-lis t } no switchport allowed vlan • add vlan-lis t - List o f VLAN identifier s to add.
C OMMAND L IN E I NTE RFA CE 3-130 Example Th e following example shows how to add VLANs 2 , 5 an d 6 to the allowed list as tagg ed VLA Ns for port 1: switchport forbid den vlan Use this command to confi gure forbid den VLANs . Use the no for m to remov e the list of fo rbidden VLANs .
VLAN C OMMANDS 3-131 Example Th e following example shows how to pr event por t 1 fro m being ad ded to VLAN 3: show v lan Use this command t o show VLAN infor mation. Syntax show v lan [ id vlan -id | name vlan- name ] • id - Keyw ord to be f ollowed by the VLAN ID.
C OMMAND L IN E I NTE RFA CE 3-132 GVRP and Bridge E xtensio n Comma nds GARP VLA N Registration P rotocol d efines a way for switches to exc h ange VLA N infor mation in order to automat ically register VLAN members on inte rfaces a cross t he netw ork.
GVRP AND B RIDGE E XTENSION C OMMANDS 3-133 Default Setting Disabled Command Mode Interfac e Confi guration (E thern et, Po r t Channe l) Example show gvrp configuration Use this command to show if GVRP is enabled. Syntax show gvr p configuration [ interface ] interface • ethernet unit / port - unit - This is device 1.
C OMMAND L IN E I NTE RFA CE 3-134 garp timer Use this command to set the value s for th e join, lea v e and l eav eall ti mers . Use the no form to res tore the ti mers’ de fault va lues .
GVRP AND B RIDGE E XTENSION C OMMANDS 3-135 Note: Set GVRP ti mers on all Layer 2 device s conne cted in t he same network to the same values. Otherwise, GVRP will n ot operate success fully. Example Related Commands show gar p timer (3-135) show garp timer Use this command to sho w the G ARP timer s for th e selected interf ace.
C OMMAND L IN E I NTE RFA CE 3-136 Example Related Commands garp timer (3-134) bridge-ext gvrp Use this co mmand to enable GVRP . Use the no form to disable it.
GVRP AND B RIDGE E XTENSION C OMMANDS 3-137 show bridge-ext Use this command to sho w the conf iguratio n for bri dge exte nsion commands . Default Setting None Command Mode Pri vileged Ex ec Command .
C OMMAND L IN E I NTE RFA CE 3-138 IGMP Snoo ping Com mands Th is switch uses IGMP (In ter net Grou p Manag ement Pr otocol) to quer y for any a ttac hed hosts that w ant to rece iv e a spec ific m ulticast ser vice . It ident ifies the ports cont aining ho sts requ esting a service and sends data out to those po rts only .
IGMP S NOOPING C OMMANDS 3-139 ip igmp snooping Use this command to enable IGMP snooping o n this switch. Use the no for m to disable it. Syntax ip igm p snoo ping no ip igmp snooping Default Setting Enabl ed Command Mode Global Configura tion Example The follo wing example enables IGMP sno oping .
C OMMAND L IN E I NTE RFA CE 3-140 ip igmp snooping vlan static Use this c ommand to add a por t to a multicas t grou p . Use the no for m to remov e the port.
IGMP S NOOPING C OMMANDS 3-141 ip igmp snooping version Use this command to conf igure the IGMP sno oping v ers ion. Use the no for m to res tore the defau lt.
C OMMAND L IN E I NTE RFA CE 3-142 Command Mode Pri vileged Ex ec Command Usage See ““Configuring IGMP Pa rameters” on page 2-100 fo r a de scription of the d ispla yed items . Example Th e following shows the cur re nt IGMP s nooping c onfigurat ion: show mac-address -table multicast Use th is command to sho w kno wn mul ticast ad dresses .
IGMP S NOOPING C OMMANDS 3-143 Command Usage Membe r type s disp layed inclu de IGMP o r USE R, depend ing on selec ted opt ions . Example The following shows the multicast entries learned through IGMP snoopin g for VLAN 1: ip igmp snooping querier Use this command to enable the switc h as an IGMP snooping querier .
C OMMAND L IN E I NTE RFA CE 3-144 ip igmp snooping query-count Use th is command to conf igure the quer y cou nt. Use t he no for m to restore the default.
IGMP S NOOPING C OMMANDS 3-145 ip igmp snooping query-int erval Use this command to conf igure the snoo ping query int er val . Use th e no for m to res tore the defau lt. Syntax ip igmp snooping quer y-inter v al seco nds no ip igmp snooping quer y-inter v al seconds - T he freque ncy at wh ich the switch sends IG MP host-qu ery messages .
C OMMAND L IN E I NTE RFA CE 3-146 Command Mode Global Configura tion Command Usage • The switch must be us ing IGMPv2 for this command to take effect. • This comman d defines th e time after a query, during which a respo nse is expe cted from a multica st client .
IGMP S NOOPING C OMMANDS 3-147 ip igmp snooping router -port-expire-time Use this command t o configur e the snoo ping rout er-po rt-expire-time . Use the no form of this command to re store the default.
C OMMAND L IN E I NTE RFA CE 3-148 ip igmp snooping vlan mrouter Use this command to st atically config ure a m ulticast rout er port. Use the no form t o remo v e the configuration .
IGMP S NOOPING C OMMANDS 3-149 show ip igmp snooping mr outer Use this command to displa y infor mat ion on statically config ured and dynamically lear ned multicast router por ts . Syntax show ip igmp snoo ping mrouter [ vlan vlan-id ] vlan-id - VLAN ID (Range: 1-4094) Default Setting Displays multicast router por ts for all configured VLANs.
C OMMAND L IN E I NTE RFA CE 3-150 Priority Commands The com mands described in this se ction allow you to specify which data pack ets h ave g reat er precede nce when t raffic is buffer ed in the switc h due to con gestion. This switc h supp orts CoS with four p riority queues for each port.
P RIORITY C OMMANDS 3-151 switchport prior ity default Use this command to set a p riority for inc oming unt ag ged frames , or t he prior ity of fram es recei v ed by th e device co nnected t o the spec ified interface. Use the no form to res tore the defau lt val ue.
C OMMAND L IN E I NTE RFA CE 3-152 • The default prio rity applies for a n untagged fra me received on a port set to accept a ll frame types (i.e, receive s both untagg ed and t agged frames). This priority does not apply to IEEE 802.1Q VLAN tag ged frames.
P RIORITY C OMMANDS 3-153 Command Mode Global Configura tion Command Usage WRR all ows ban dwidth s haring at the e gr ess po rt by d efinin g schedul ing weights.
C OMMAND L IN E I NTE RFA CE 3-154 Default Setting This s witch supports Clas s of Ser vice by using four priorit y queues , with W eighted R ound R obin for eac h port. Eight separa te traf fic classe s are defined in IEEE 802.1p . Th e defau lt priority levels are assigned according to recommendations in the IEEE 802.
P RIORITY C OMMANDS 3-155 Related Commands show queue cos-map (3-155) show queue bandwidth Use this command to displa y the W eighted R ound-R obin (WRR) bandw idth allo cation fo r the fou r class of ser vic e (CoS) p riority qu eues.
C OMMAND L IN E I NTE RFA CE 3-156 Default Setting None Command Mode Pri vileged Ex ec Example map ip precedence (Global Configuration) Use th is command to enab le IP pr ecedence map ping (i.e ., IP T ype of Service). Use the no for m to dis able IP pre cedence mapping.
P RIORITY C OMMANDS 3-157 Example The follo wing example show s ho w to ena ble IP pr ecedence mapping globally: map ip precedence (Interface Configuration) Use this command to set IP preced ence pri ority (i .e ., IP T ype of Service prio rity ). Us e the no for m to resto re the default table.
C OMMAND L IN E I NTE RFA CE 3-158 Command Usage • The prece dence fo r priori ty mappi ng is IP Preced ence or IP DS CP, and defau lt switch port prior ity. • IP Precedence values are ma pped to defa ult Class of Service val ues on a one-to-one basis according to recommendations in the IEEE 802.
P RIORITY C OMMANDS 3-159 • IP Precedenc e and I P DSCP can not bot h be enabl ed. En abling o ne of these priority types will autom atically disable the other type. Example Th e following exa mple shows how to enab le IP DSCP mapping gl obally: map ip dscp (Interface Co nfiguration) Use this comma nd to set IP D SCP priority (i.
C OMMAND L IN E I NTE RFA CE 3-160 Command Mode Interf ace Conf iguratio n (Eth ernet, P or t Chann el) Command Usage • The preced ence for p riority mapping i s IP Por t, IP Pre cedence or IP DSCP, an d default s witchpo rt prio rity.
P RIORITY C OMMANDS 3-161 Command Mode Pri vileged Ex ec Example Related Commands map ip precedence (Global Configura tion) (3-156) map ip prece dence (Inter face Configur ation) (3-157) - Maps CoS values to IP p recedence v alues . show map ip dscp Use this command to show the IP DSCP priority map .
C OMMAND L IN E I NTE RFA CE 3-162 Command Mode Pri vileged Ex ec Example Related Commands map ip dscp (Global Configuration) (3-158) map ip dscp (Interface Configuration) (3-159) - Maps CoS valu es to IP DSCP v alues .
M IR R OR P ORT C OMMANDS 3-163 Mirror Port Commands Th is section d escribe s how to config ure po rt mi rro r sessions. port monitor Use this command to config ure a mir ror session.
C OMMAND L IN E I NTE RFA CE 3-164 Command Usage • You can mirr or tr affic from any source port to a destin ation port for real-tim e analysi s. You can then att ach a lo gic anal yzer or RMON probe t o the des tination port and study t he traffi c cross ing the so urce port in a complete ly unobtrusive manner.
M IR R OR P ORT C OMMANDS 3-165 Default Setting Sho ws all session s . Command Mode Pri vileged Ex ec Command Usage This comman d displ ays th e currently confi gured so urce port, destinat ion por t, and m ir ror mode (i.
C OMMAND L IN E I NTE RFA CE 3-166 Port Trunki ng Co mmand s P o rts can be statically g rouped into an ag g reg ate link to increase the bandw idth of a network connec tion or to en sure fau lt recover y . Or you can use the L ink Ag g reg atio n Control Pr otocol (LACP), als o known as 802.
P ORT T RUNKING C OMMANDS 3-167 • All ports in a trunk must be configured in an identical manner, including communicatio n mode (i.e., speed, dup lex mode and flow control) , VLAN assign ments, and C oS settings.
C OMMAND L IN E I NTE RFA CE 3-168 Example The follo wing ex ample crea tes trunk 1 and then adds po r t 11: lacp Use this command to enable 802.3ad L ink Ag g regation Control Protocol (LA CP) for th e cur rent int erface. Use the no form to disable it.
P ORT T RUNKING C OMMANDS 3-169 Example Th e following shows LACP enabled on por ts 11 -13. Bec ause LACP has also bee n enabl ed on the p orts at the o ther end of the l inks , the show interfaces status por t-channel 1 command sh ows that T r unk 1 has b een established.
C OMMAND L IN E I NTE RFA CE 3-170.
A-1 A PPENDIX A T ROUBLESHOOTING Troub leshoot ing Char t Troubl eshooting Ch art Symptom Action Cannot con nect using Telnet, W eb browser, or SNMP software • Be sure to have config ured the agent with a valid IP addre ss, subnet mask and def ault gate way.
T R OUBLESHOOTING A-2.
B-1 A PPENDIX B U PGRADING F IRMW ARE VIA THE S ERIAL P ORT Th e switch con tains three fi rm ware comp onen ts that ca n be upg rad ed; the diagnostics (or Boot-R OM) code, r untime ope ration code, and the loader code .
U PGRADING F IRMW ARE VIA THE S ERIAL P ORT B-2 4. When th e switch initialization screen appears, enter fir mwar e-download mode by pres sing <Ct rl><u> imme diat ely afte r power on. Scr een text sim ilar to th at shown be low displays: 5.
B-3 9. Press <X> to star t to download th e new code file. If using W indows Hyper T er min al, click the “T ransfer ” button, a nd then c lick “ Send File .... ” Select t he XModem Pr otocol and th en use the “Br owse” but ton to s elect the req uired firmware code file from your PC sy stem .
U PGRADING F IRMW ARE VIA THE S ERIAL P ORT B-4 12. T o set the new do wnloaded file as the s tartup file, use th e [S]et Star tup File menu option. 13. When you ha v e finish ed do wnloading code file s , use the [C]h an ge Baudrate menu option to c hange the ba ud rate of the switch’ s serial connection b ack to 9600 ba ud.
C-1 A PPENDIX C P IN A SSIGN MEN TS Console Port Pin Assignments The DB-9 seria l port on the swit ch’ s front panel is us ed to conn ect to th e switch for out-of-b and co nsole co nfigura tion. T he onbo ard menu-d riven config uration prog ram can be accesse d from a ter m inal, or a PC r u nning a ter mina l emulatio n prog ram.
P IN A SSIG NMEN TS C-2 Console Port to 9-Pin DTE Port on PC Console Port to 25-Pin DTE Port on PC Switch’s 9 -Pin Serial Port Nu ll Mo de m PC’s 9-Pin DTE Po rt 2 RXD <-- ---- ---T XD ---- --- ----- 3 TXD 3 TX D --- ------- -RXD ---- ------> 2 R XD 5 SGND -------- --- SGND ----- ---- - 5 SG ND No other pins are u sed.
Glossary-1 G LOSSA RY 10BASE-T IEEE 802.3 sp ecification for 1 0 Mbps Etherne t ov er two pairs of Categ or y 3, 4, or 5 U TP cable. 100BASE-TX IEEE 802.3u specifica tion for 100 Mbps Fast Ethernet over tw o pairs of Categ or y 5 UTP cable. 1000BASE-T IEEE 802.
G LOSSAR Y Glossary-2 Collis ion Doma in Single CSMA/C D LAN segme nt. CSMA/CD Car rier Sense Multiple Access/C ollision Detect is the communication method employed by Ethernet and F ast Ether net. Dynamic Ho st Control Protocol (DHC P) Provides a framework for passing c onfiguration infor ma tion to hosts on a TCP/I P network.
G LOSSAR Y Glossary-3 Generic Attr ibute Registrati on Protocol (GA RP) GARP is a protocol t hat can be used by ends tations and swi tches to register and propag ate multicast g roup member ship infor.
G LOSSAR Y Glossary-4 IEEE 802.3ab Defines CSMA/ CD access method and ph ysical layer specif ications for 1000BASE-T Gigabit Ethernet. IEEE 802.3ac Defines frame exten sions for VLAN tag ging . IEEE 802.3u Defines CSMA/ CD access method and ph ysical layer specif ications for 100BAS E-TX Fast Ethernet.
G LOSSAR Y Glossary-5 IP Multicast Filteri ng A process whereby this switch can pass multicast traffic along to par ticipating hosts. Layer 2 Data Link layer in the ISO 7- Layer Data Communications Protocol. This i s related directly to the hardware interface for ne tw ork devices an d passes on traffic based on MA C address es .
G LOSSAR Y Glossary-6 Port Mirror ing A method whereby data on a targe t port is mir rored to a m onitor port for troublesh ooting with a logic ana lyzer or RMON probe.
G LOSSAR Y Glossary-7 Virtual LAN (VLAN) A Virtual LAN is a collection of network nodes that share the same collisi on domain reg ardless of their physical location or connection point in the netw ork.
G LOSSAR Y Glossary-8.
Index-1 A addres s table 2-41 B BOOTP 2-12 broadcast st orm, threshold 2-36 C Class of S erv ice configuring 2-7 7 queue mapping 2-77 community string 2-95 configurat ion settings, s aving or restorin.
I NDE X Index-2 path cost, STP 3-111 , 3-113 pin assignm ents 25-pin DTE port C-2 9-pin DTE port C-2 console port C-1 port priority configuring 2-7 7 defaul t ingre ss 2-77 port security, config uring.
.
38 T esla Irvine, C A 9261 8 Phone: (949 ) 679-8000 FOR TECHNICAL SUPPOR T , CALL: From U.S.A. an d Canada (2 4 hours a day , 7 da ys a week) (800) SMC-4-YOU; (94 9) 679-8000; F ax: (949 ) 679-1481 From E urope (8:00 AM - 5: 30 PM UK Time) 44 (0) 118 974 870 0; Fax: 44 (0) 118 974 87 01 INTERNET E-mail a ddresses: techsupp ort@smc.
Ein wichtiger Punkt beim Kauf des Geräts SMC Networks TigerSwitch 100 (oder sogar vor seinem Kauf) ist das durchlesen seiner Bedienungsanleitung. Dies sollten wir wegen ein paar einfacher Gründe machen:
Wenn Sie SMC Networks TigerSwitch 100 noch nicht gekauft haben, ist jetzt ein guter Moment, um sich mit den grundliegenden Daten des Produkts bekannt zu machen. Schauen Sie zuerst die ersten Seiten der Anleitung durch, die Sie oben finden. Dort finden Sie die wichtigsten technischen Daten für SMC Networks TigerSwitch 100 - auf diese Weise prüfen Sie, ob das Gerät Ihren Wünschen entspricht. Wenn Sie tiefer in die Benutzeranleitung von SMC Networks TigerSwitch 100 reinschauen, lernen Sie alle zugänglichen Produktfunktionen kennen, sowie erhalten Informationen über die Nutzung. Die Informationen, die Sie über SMC Networks TigerSwitch 100 erhalten, werden Ihnen bestimmt bei der Kaufentscheidung helfen.
Wenn Sie aber schon SMC Networks TigerSwitch 100 besitzen, und noch keine Gelegenheit dazu hatten, die Bedienungsanleitung zu lesen, sollten Sie es aufgrund der oben beschriebenen Gründe machen. Sie erfahren dann, ob Sie die zugänglichen Funktionen richtig genutzt haben, aber auch, ob Sie keine Fehler begangen haben, die den Nutzungszeitraum von SMC Networks TigerSwitch 100 verkürzen könnten.
Jedoch ist die eine der wichtigsten Rollen, die eine Bedienungsanleitung für den Nutzer spielt, die Hilfe bei der Lösung von Problemen mit SMC Networks TigerSwitch 100. Sie finden dort fast immer Troubleshooting, also die am häufigsten auftauchenden Störungen und Mängel bei SMC Networks TigerSwitch 100 gemeinsam mit Hinweisen bezüglich der Arten ihrer Lösung. Sogar wenn es Ihnen nicht gelingen sollte das Problem alleine zu bewältigen, die Anleitung zeigt Ihnen die weitere Vorgehensweise – den Kontakt zur Kundenberatung oder dem naheliegenden Service.