Accton-technology ES4524D Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Acessórios para Computador Accton-technology ES4524D. Accton Technology ES4524D User Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 0
Powered by Accton
Management Guide
ES4524D
ES4548D
24/48-Port
Gigabit Ethernet Switch
tel: 08-52 400 700 fax: 08-520 18121
Vista de página 0
1 2 3 4 5 6 ... 587 588

Resumo do Conteúdo

Página 1 - Powered by Accton

Powered by AcctonManagement GuideES4524DES4548D24/48-PortGigabit Ethernet Switche-mail: [email protected]tel: 08-52 400 700 fax: 08-520 18121

Página 2

Contentsxend 33-4exit 33-4quit 33-5Chapter 34: System Management Commands 34-1hostname 34-1reload 34-2switch renumber 34-2jumbo frame 34-3show s

Página 3 - Management Guide

Setting the System Clock10-210CLI – This example configures the switch to operate as an SNTP client and then displays the current time and settings.Se

Página 4 - 149100030400A

11-1Chapter 11: Simple Network Management Protocol This chapter describes how to configure the Simple Network Management Protocol (SNMP) on the switch

Página 5 - Contents

Simple Network Management Protocol11-211security models v1 and v2c. The following table shows the security models and levels available and the system

Página 6

Setting Community Access Strings11-311CLI – The following example enables SNMP on the switch.Setting Community Access Strings You may configure up to

Página 7

Simple Network Management Protocol11-411Specifying Trap Managers and Trap TypesTraps indicating status changes are issued by the switch to specified t

Página 8

Specifying Trap Managers and Trap Types11-511Version 1 or 2c clients), or define a corresponding “User Name” in the SNMPv3 Users page (for Version 3 c

Página 9

Simple Network Management Protocol11-611Web – Click SNMP, Configuration. Enter the IP address and community string for each management station that wi

Página 10

Configuring SNMPv3 Management Access11-711Setting a Local Engine IDAn SNMPv3 engine is an independent SNMP agent that resides on the switch. This engi

Página 11

Simple Network Management Protocol11-811The engine ID can be specified by entering 1 to 26 hexadecimal characters. If less than 26 characters are spec

Página 12

Configuring SNMPv3 Management Access11-911• Authentication Password – A minimum of eight plain text characters is required.• Privacy Protocol – The en

Página 13

ContentsxiChapter 38: SMTP Alert Commands 38-1logging sendmail host 38-1logging sendmail level 38-2logging sendmail source-email 38-2logging sendm

Página 14

Simple Network Management Protocol11-1011CLI – Use the snmp-server user command to configure a new user name and assign it to a group.Configuring Remo

Página 15

Configuring SNMPv3 Management Access11-1111• Privacy Protocol – The encryption algorithm use for data privacy; only 56-bit DES is currently available.

Página 16

Simple Network Management Protocol11-1211CLI – Use the snmp-server user command to configure a new user name and assign it to a group.Configuring SNMP

Página 17

Configuring SNMPv3 Management Access11-1311Table 11-2 Supported Notification MessagesObject Label Object ID DescriptionRFC 1493 TrapsnewRoot 1.3.6.1

Página 18

Simple Network Management Protocol11-1411Private Traps - swPowerStatus ChangeTrap1.3.6.1.4.1.259.6.10.95.2.1.0.1 This trap is sent when the power stat

Página 19

Configuring SNMPv3 Management Access11-1511Web – Click SNMP, SNMPv3, Groups. Click New to configure a new group. In the New Group page, define a name,

Página 20

Simple Network Management Protocol11-1611Setting SNMPv3 ViewsSNMPv3 views are used to restrict user access to specified portions of the MIB tree. The

Página 21

Configuring SNMPv3 Management Access11-1711CLI – Use the snmp-server view command to configure a new view. This example view includes the MIB-2 interf

Página 22

Simple Network Management Protocol11-1811

Página 23

12-1Chapter 12: User Authentication This chapter describes how to configure the switch to authenticate users logging into the system for management ac

Página 24

Contentsxiiradius-server timeout 41-8show radius-server 41-8TACACS+ Client 41-9tacacs-server host 41-9tacacs-server port 41-9tacacs-server key 4

Página 25

User Authentication12-212Web – Click Security, User Accounts. To configure a new user account, enter the user name, access level, and password, then c

Página 26

Configuring Local/Remote Logon Authentication12-312RADIUS uses UDP while TACACS+ uses TCP. UDP only offers best effort delivery, while TCP offers a co

Página 27 - Section I: Getting Started

User Authentication12-412- ServerIndex – Specifies one of five RADIUS servers that may be configured. The switch attempts authentication using the lis

Página 28 - Getting Started

Configuring HTTPS12-512CLI – Specify all the required parameters to enable logon authentication.Configuring HTTPSYou can configure the switch to enabl

Página 29 - Chapter 1: Introduction

User Authentication12-612- The client and server generate session keys for encrypting and decrypting data.• The client and server establish a secure e

Página 30 - Introduction

Configuring HTTPS12-712obtain a unique certificate and a private key and password from a recognized certification authority. Note: For maximum securit

Página 31

User Authentication12-812Configuring the Secure Shell The Berkley-standard includes remote access tools originally designed for Unix systems. Some of

Página 32

Configuring the Secure Shell12-912client’s granted management access to the switch. (Note that these clients must be configured locally on the switch

Página 33

User Authentication12-1012Authenticating SSH v2 Clientsa.The client first queries the switch to determine if DSA public key authentication using a pre

Página 34 - System Defaults

Configuring the Secure Shell12-1112Web – Click Security, SSH, Host-Key Settings. Select the host-key type from the drop-down box, select the option to

Página 35

ContentsxiiiChapter 44: Access Control List Commands 44-1IPv4 ACLs 44-1access-list ip 44-2permit, deny (Standard IPv4 ACL) 44-2permit, deny (Exte

Página 36

User Authentication12-1212Configuring the SSH ServerThe SSH server includes basic settings for authentication. Field Attributes• SSH Server Status – A

Página 37 - Connecting to the Switch

Filtering IP Addresses for Management Access12-1312CLI – This example enables SSH, sets the authentication parameters, and displays the current config

Página 38 - Remote Connections

User Authentication12-1412• End IP Address – The end address of a range.Web – Click Security, IP Filter. Enter the IP addresses or range of addresses

Página 39 - Basic Configuration

13-1Chapter 13: Configuring Port Security Port security is a feature that allows you to configure a switch port with one or more device MAC addresses

Página 40 - Setting an IP Address

Configuring Port Security13-213Web – Click Security, Port Security. Set the action to take when an invalid address is detected on a port, mark the che

Página 41

14-1Chapter 14: Configuring 802.1X Port Authentication Network switches can provide open and easy access to network resources by simply attaching a c

Página 42 - Initial Configuration

Configuring 802.1X Port Authentication14-214The operation of dot1x on the switch requires the following:• The switch must have an IP address assigned.

Página 43

Configuring 802.1X Global Settings14-314Configuring 802.1X Global SettingsThe 802.1X protocol provides port authentication. The 802.1X protocol must b

Página 44 - Dynamic Configuration

Configuring 802.1X Port Authentication14-414• Max Request – Sets the maximum number of times the switch port will retransmit an EAP request packet to

Página 45

Configuring Port Settings for 802.1X14-514CLI – This example sets the 802.1X parameters on port 2. For a description of the additional fields displaye

Página 46

Contentsxivlacp port-priority 46-8show lacp 46-8show port-channel load-balance 46-11Chapter 47: Broadcast Storm Control Commands 47-1switchport br

Página 47 - Trap Receivers

Configuring 802.1X Port Authentication14-614Displaying 802.1X StatisticsThis switch can display statistics for dot1x protocol exchanges for any port.

Página 48 - Managing System Files

Displaying 802.1X Statistics14-714Web – Select Security, 802.1X, Statistics. Select the required port and then click Query. Click Refresh to update th

Página 49 - Saving Configuration Settings

Configuring 802.1X Port Authentication14-814

Página 50

15-1Chapter 15: Access Control ListsAccess Control Lists (ACL) provide packet filtering for IPv4 frames (based on address, protocol, Layer 4 protocol

Página 51 - Section II: Switch Management

Access Control Lists15-215the “TCP” protocol is specified, then you can also filter packets based on the TCP control code. • IPv6 Standard: IPv6 ACL m

Página 52 - Switch Management

Configuring an Extended IPv4 ACL15-315Web – Specify the action (i.e., Permit or Deny). Select the address type (Any, Host, or IP). If you select “Host

Página 53 - Using the Web Interface

Access Control Lists15-415• Source/Destination Port – Source/destination port number for the specified protocol type. (Range: 0-65535)• Source/Destina

Página 54 - Home Page

Configuring an Extended IPv4 ACL15-515Web – Specify the action (i.e., Permit or Deny). Specify the source and/or destination addresses. Select the add

Página 55 - Panel Display

Access Control Lists15-615Configuring a MAC ACLCommand Attributes• Action – An ACL can contain any combination of permit or deny rules.• Source/Destin

Página 56 - Main Menu

Configuring a Standard IPv6 ACL15-715Web – Specify the action (i.e., Permit or Deny). Specify the source and/or destination addresses. Select the addr

Página 57

ContentsxvChapter 52: VLAN Commands 52-1GVRP and Bridge Extension Commands 52-1bridge-ext gvrp 52-2show bridge-ext 52-2switchport gvrp 52-3show g

Página 58 - Configuring the Switch

Access Control Lists15-815• Source Prefix-Length – A decimal value indicating how many contiguous bits (from the left) of the address comprise the pre

Página 59

Configuring an Extended IPv6 ACL15-915• Destination Prefix-Length – A decimal value indicating how many contiguous bits (from the left) of the address

Página 60

Access Control Lists15-1015Web – Specify the action (i.e., Permit or Deny). Select the address type (Any or IPv6-prefix). If you select “IPv6-prefix,”

Página 61 - Displaying System Information

Binding a Port to an Access Control List15-1115Binding a Port to an Access Control ListAfter configuring the Access Control Lists (ACL), you should bi

Página 62 - Basic System Settings

Access Control Lists15-1215

Página 63

16-1Chapter 16: Port Configuration This chapter describes how to configure switch ports and display the current connection status.Displaying Connectio

Página 64

Port Configuration16-216Field Attributes (CLI)Basic information:• Port type – Indicates the port type. (1000BASE-T or SFP)• MAC address – The physical

Página 65

Displaying Connection Status16-316CLI – This example shows the connection status for Port 5.Console#show interfaces status ethernet 1/5 45-8Informatio

Página 66

Port Configuration16-416Configuring Interface Connections You can use the Port Configuration or Trunk Configuration page to enable/disable an interfac

Página 67 - Resetting the System

Configuring Interface Connections16-516Web – Click Port, Port Configuration or Trunk Configuration. Modify the required interface settings, and click

Página 68

ContentsxviPriority Commands (Layer 3 and 4) 55-7map ip port (Global Configuration) 55-7map ip port (Interface Configuration) 55-8map ip precedence

Página 69

Port Configuration16-616Showing Port StatisticsYou can display standard statistics on network traffic from the Interfaces Group and Ethernet-like MIBs

Página 70 - Manual Configuration

Showing Port Statistics16-716Transmit Discarded Packets The number of outbound packets which were chosen to be discarded even though no errors had bee

Página 71 - Using DHCP/BOOTP

Port Configuration16-816Received Frames The total number of frames (bad, broadcast and multicast) received.Broadcast Frames The total number of good f

Página 72 - Configuring an IPv6 Address

Showing Port Statistics16-916Web – Click Port, Port Statistics. Select the required interface, and click Query. You can also use the Refresh button at

Página 73

Port Configuration16-1016CLI – This example shows statistics for port 12.Console#show interfaces counters ethernet 1/12 45-9Ethernet 1/12 Iftable stat

Página 74

17-1Chapter 17: Creating Trunk Groups You can create multiple links between devices that work as one virtual, aggregate link. A port trunk offers a dr

Página 75

Creating Trunk Groups17-217Statically Configuring a TrunkCommand Usage• When configuring static trunks, you may not be able to link switches of differ

Página 76

Setting a Load-Balance Mode for Trunks17-317CLI – This example creates trunk 1 with ports 9 and 10. Just connect these ports to two static trunk ports

Página 77

Creating Trunk Groups17-417• Destination MAC Address: All traffic with the same destination MAC address is output on the same link in a trunk. This mo

Página 78

Enabling LACP on Selected Ports17-517CLI – The following example sets the load-balance method to source and destination IP address. Enabling LACP on S

Página 79

Contentsxviiip domain-lookup 58-5show hosts 58-6show dns 58-7show dns cache 58-7clear dns cache 58-8Chapter 59: IPv4 Interface Commands 59-1ip a

Página 80

Creating Trunk Groups17-617Web – Click Port, LACP, Configuration. Select any of the switch ports from the scroll-down port list and click Add. After y

Página 81

Configuring LACP Parameters17-717Configuring LACP ParametersDynamically Creating a Port Channel –Ports assigned to a common port channel must meet the

Página 82

Creating Trunk Groups17-817Web – Click Port, LACP, Aggregation Port. Set the System Priority, Admin Key, and Port Priority for the Port Actor. You can

Página 83 - Managing Firmware

Displaying LACP Port Counters17-917CLI – The following example configures LACP parameters for ports 1-10. Ports 1-8 are used as active members of the

Página 84

Creating Trunk Groups17-1017Web – Click Port, LACP, Port Counters Information. Select a member port to display the corresponding information.Figure 17

Página 85

Displaying LACP Settings and Status for the Local Side17-1117Displaying LACP Settings and Status for the Local SideYou can display configuration setti

Página 86

Creating Trunk Groups17-1217Web – Click Port, LACP, Port Internal Information. Select a port channel to display the corresponding information.Figure 1

Página 87

Displaying LACP Settings and Status for the Remote Side17-1317Displaying LACP Settings and Status for the Remote SideYou can display configuration set

Página 88

Creating Trunk Groups17-1417CLI – The following example displays the LACP configuration settings and operational state for the remote side of port cha

Página 89 - 1. CLI only

18-1Chapter 18: Broadcast Storm ControlBroadcast storms may occur when a device on your network is malfunctioning, or if application programs are not

Página 90 - Console Port Settings

ContentsxviiiSection IV: AppendicesAppendix A: Software Specifications A-1Software Features A-1Management Features A-2Standards A-2Management Infor

Página 91 - Chapter 8: Telnet Settings

Broadcast Storm Control18-218CLI – Specify any interface, and then enter the threshold. The following disables broadcast storm control for port 1, and

Página 92 - Telnet Settings

19-1Chapter 19: Configuring Port Mirroring You can mirror traffic from any source port to a target port for real-time analysis. You can then attach a

Página 93 - System Log Configuration

Configuring Port Mirroring19-219Web – Click Port, Mirror Port Configuration. Specify the source port, the traffic type to be mirrored, and the monitor

Página 94 - Remote Log Configuration

20-1Chapter 20: Configuring Rate Limits This function allows the network manager to control the maximum rate for traffic transmitted or received on an

Página 95

Configuring Rate Limits20-220CLI - This example sets the rate limit for input and output traffic passing through port 1 to 600 Mbps.Console(config)#in

Página 96 - Displaying Log Messages

21-1Chapter 21: Address Table Settings Switches store the addresses for all known devices. This information is used to pass traffic directly between t

Página 97

Address Table Settings21-221CLI – This example adds an address to the static address table, but sets it to be deleted when the switch is reset.Display

Página 98 - Configuring Event Logging

Displaying the Address Table21-321Web – Click Address Table, Dynamic Addresses. Specify the search type (i.e., mark the Interface, MAC Address, or VLA

Página 99 - Configuring SNTP

Address Table Settings21-421Changing the Aging TimeYou can set the aging time for entries in the dynamic address table. Command Attributes• Aging Stat

Página 100 - Setting the Time Zone

22-1Chapter 22: Spanning Tree Algorithm Configuration The Spanning Tree Algorithm (STA) can be used to detect and disable network loops, and to provi

Página 101 - Protocol

xixTablesTable 1-1 Key Features 1-1Table 1-2 System Defaults 1-6Table 3-1 Web Page Configuration Buttons 3-3Table 3-2 Switch Main Menu 3-4Table 9-

Página 102 - Enabling the SNMP Agent

Spanning Tree Algorithm Configuration22-222alternate route that can be used when a node or port fails, and retaining the forwarding database for ports

Página 103 - Console(config)#

Displaying Global Settings22-322MSTP connects all bridges and LAN segments with a single Common and Internal Spanning Tree (CIST). The CIST is formed

Página 104

Spanning Tree Algorithm Configuration22-422These additional parameters are only displayed for the CLI:• Spanning tree mode – Specifies the type of spa

Página 105 - (page 11-12)

Displaying Global Settings22-522Web – Click Spanning Tree, STA, Information.Figure 22-1 STA InformationCLI – This command displays global STA setting

Página 106

Spanning Tree Algorithm Configuration22-622Note: The current root port and current root cost display as zero when this device is not connected to the

Página 107 - Specifying a Remote Engine ID

Configuring Global Settings22-722• Multiple Spanning Tree Protocol- To allow multiple spanning trees to operate over the network, you must configure a

Página 108 - Configuring SNMPv3 Users

Spanning Tree Algorithm Configuration22-822• Forward Delay – The maximum time (in seconds) this device will wait before changing states (i.e., discard

Página 109

Configuring Global Settings22-922Web – Click Spanning Tree, STA, Configuration. Modify the required attributes, and click Apply.Figure 22-2 STA Globa

Página 110

Spanning Tree Algorithm Configuration22-1022CLI – This example enables Spanning Tree Protocol, sets the mode to MST, and then configures the STA and M

Página 111

Displaying Interface Settings22-1122• Designated Port – The port priority and number of the port on the designated bridging device through which this

Página 113

xxTablesTable 41-5 RADIUS Client Commands 41-5Table 41-6 TACACS+ Client Commands 41-9Table 41-7 Web Server Commands 41-11Table 41-8 HTTPS System Su

Página 114

Spanning Tree Algorithm Configuration22-1222• External path cost – The path cost for the IST. This parameter is used by the STA to determine the bes

Página 115

Configuring Interface Settings22-1322CLI – This example shows the STA attributes for port 5. Configuring Interface SettingsYou can configure RSTP and

Página 116 - Setting SNMPv3 Views

Spanning Tree Algorithm Configuration22-1422The following interface attributes can be configured:• Spanning Tree – Enables/disables STA on this interf

Página 117

Configuring Multiple Spanning Trees22-1522Migration button to manually re-check the appropriate BPDU format (RSTP or STP-compatible) to send on the se

Página 118

Spanning Tree Algorithm Configuration22-16223. Add the VLANs that will share this MSTI (MSTP VLAN Configuration). Note:All VLANs are automatically add

Página 119 - Configuring User Accounts

Configuring Multiple Spanning Trees22-1722CLI – This displays STA settings for instance 1, followed by settings for each port. CLI – This example sets

Página 120 - User Authentication

Spanning Tree Algorithm Configuration22-1822Displaying Interface Settings for MSTPThe MSTP Port Information and MSTP Trunk Information pages display t

Página 121

Configuring Interface Settings for MSTP22-1922Configuring Interface Settings for MSTPYou can configure the STA interface settings for an MST Instance

Página 122

Spanning Tree Algorithm Configuration22-2022• Default: 128• Range: 0-240, in steps of 16• Admin MST Path Cost – This parameter is used by the MSTP to

Página 123 - Configuring HTTPS

23-1Chapter 23: VLAN Configuration In large networks, routers are used to isolate broadcast traffic for each subnet into separate domains. This switch

Página 124

xxiTablesTable 57-4 Static Multicast Routing Commands 57-8Table 58-1 DNS Commands 58-1Table 58-2 show dns cache - display description 58-7Table 59-

Página 125

VLAN Configuration23-223Note: VLAN-tagged frames can pass through VLAN-aware or VLAN-unaware network interconnection devices, but the VLAN tags should

Página 126 - Configuring the Secure Shell

Assigning Ports to VLANs23-323these hosts, and core switches in the network, enable GVRP on the links between these devices. You should also determine

Página 127

VLAN Configuration23-423Enabling or Disabling GVRP (Global Setting) GARP VLAN Registration Protocol (GVRP) defines a way for switches to exchange VLAN

Página 128 - Generating the Host Key Pair

Displaying Current VLANs23-523CLI – Enter the following command.Displaying Current VLANsThe VLAN Current Table shows the current port members of each

Página 129

VLAN Configuration23-623Command Attributes (CLI)• VLAN – ID of configured VLAN (1-4093, no leading zeroes).• Type – Shows how this VLAN was added to t

Página 130 - Configuring the SSH Server

Adding Static Members to VLANs (VLAN Index)23-723Web – Click VLAN, 802.1Q VLAN, Static List. To create a new VLAN, enter the VLAN ID and VLAN name, ma

Página 131

VLAN Configuration23-823Command Attributes • VLAN – ID of configured VLAN (1-4093).• Name – Name of the VLAN (1 to 32 characters).• Status – Enables o

Página 132

Adding Static Members to VLANs (Port Index)23-923CLI – The following example adds tagged and untagged ports to VLAN 2.Adding Static Members to VLANs (

Página 133

VLAN Configuration23-1023Configuring VLAN Behavior for InterfacesYou can configure VLAN behavior for specific interfaces, including the default VLAN i

Página 134 - Configuring Port Security

Configuring VLAN Behavior for Interfaces23-1123• GARP Leave Timer2 – The interval a port waits before leaving a VLAN group. This time should be set to

Página 135

xxiiTables

Página 136

VLAN Configuration23-1223CLI – This example sets port 3 to accept only tagged frames, assigns PVID 3 as the native VLAN ID, enables GVRP, sets the GAR

Página 137

Configuring IEEE 802.1Q Tunneling23-1323When a double-tagged packet enters another trunk port in an intermediate or core switch in the service provide

Página 138

VLAN Configuration23-14233. After packet classification through the switching process, the packet is written to memory with one tag (an outer tag) or

Página 139

Configuring IEEE 802.1Q Tunneling23-1523Configuration Limitations for QinQ• The native VLAN of uplink ports should not be used as the SPVLAN. If the S

Página 140 - Displaying 802.1X Statistics

VLAN Configuration23-1623Enabling QinQ Tunneling on the SwitchThe switch can be configured to operate in normal VLAN mode or IEEE 802.1Q (QinQ) tunnel

Página 141

Configuring IEEE 802.1Q Tunneling23-1723Adding an Interface to a QinQ TunnelFollow the guidelines in the preceding section to set up a QinQ tunnel on

Página 142

VLAN Configuration23-1823Figure 23-1 Tunnel Port ConfigurationCLI – This example sets port 1 to tunnel access mode, indicates that the TPID used for

Página 143 - Setting an ACL Name and Type

24-1Chapter 24: Configuring Private VLANs Private VLANs provide port-based security and isolation between ports within the assigned VLAN. Data traffic

Página 144 - Access Control Lists

Configuring Private VLANs24-224Configuring Uplink and Downlink PortsUse the Private VLAN Link Status page to set ports as downlink or uplink ports. Po

Página 145 - Console(config-std-acl)#

25-1Chapter 25: Configuring Protocol-Based VLANs The network devices required to support multiple protocols cannot be easily grouped into a common VLA

Página 146

xxiiiFiguresFigure 3-1 Home Page 3-2Figure 3-2 Front Panel Indicators 3-3Figure 4-1 System Information 4-2Figure 4-2 Switch Information 4-4Figure

Página 147

Configuring Protocol-Based VLANs25-225Web – Click VLAN, Protocol VLAN, Configuration. Enter a protocol group ID, frame type and protocol type, then cl

Página 148 - Configuring a MAC ACL

Mapping Protocols to VLANs25-325Web – Click VLAN, Protocol VLAN, Port Configuration. Select a a port or trunk, enter a protocol group ID, the correspo

Página 149 - Console(config-mac-acl)#

Configuring Protocol-Based VLANs25-425

Página 150

26-1Chapter 26: Class of Service Configuration Class of Service (CoS) allows you to specify which data packets have greater precedence when traffic is

Página 151

Class of Service Configuration26-226Web – Click Priority, Default Port Priority or Default Trunk Priority. Modify the default priority for any interfa

Página 152

Layer 2 Queue Settings26-326Mapping CoS Values to Egress QueuesThis switch processes Class of Service (CoS) priority tagged traffic by using eight pri

Página 153 - Figure 15-7 ACL Port Binding

Class of Service Configuration26-426Web – Click Priority, Traffic Classes. Assign priorities to the traffic classes (i.e., output queues), then click

Página 154

Layer 2 Queue Settings26-526Command Attributes• WRR - Weighted Round-Robin shares bandwidth at the egress ports by using scheduling weights 1, 2, 4, 6

Página 155 - Displaying Connection Status

Class of Service Configuration26-626Web – Click Priority, Queue Scheduling. Select the interface, highlight a traffic class (i.e., output queue), ente

Página 156 - Port Configuration

Layer 3/4 Priority Settings26-726Layer 3/4 Priority SettingsMapping Layer 3/4 Priorities to CoS ValuesThis switch supports several common methods of p

Página 157

xxivFiguresFigure 12-7 IP Filter 12-14Figure 13-1 Port Security 13-2Figure 14-1 802.1X Global Information 14-2Figure 14-2 802.1X Global Configurati

Página 158

Class of Service Configuration26-826Mapping IP PrecedenceThe Type of Service (ToS) octet in the IPv4 header includes three precedence bits defining ei

Página 159

Layer 3/4 Priority Settings26-926CLI – The following example globally enables IP Precedence service on the switch, maps IP Precedence value 1 to CoS v

Página 160 - Showing Port Statistics

Class of Service Configuration26-1026Web – Click Priority, IP DSCP Priority. Select an entry from the DSCP table, enter a value in the Class of Servic

Página 161

Layer 3/4 Priority Settings26-1126Mapping IP Port PriorityYou can also map network applications to Class of Service values based on the IP port number

Página 162

Class of Service Configuration26-1226CLI – The following example globally enables IP Port Priority service on the switch, maps HTTP traffic (on port 1

Página 163

27-1Chapter 27: Quality of Service The commands described in this section are used to configure Quality of Service (QoS) classification criteria and

Página 164

Quality of Service27-227Configuring a Class MapA class map is used for matching packets to a specified class.Command Usage • To configure a Class Map,

Página 165

Configuring a Class Map27-327• IP Precedence – An IP Precedence value. (Range: 0-7) • VLAN – A VLAN. (Range:1-4093)• Add – Adds specified criteria to

Página 166 - Creating Trunk Groups

Quality of Service27-427CLI - This example creates a class map call “rd-class,” and sets it to match packets marked for DSCP service value 3.Creating

Página 167

Creating QoS Policies27-527• Add Policy – Opens the “Policy Configuration” page. Enter a policy name and description on this page, and click Add to op

Página 168

xxvFiguresFigure 24-1 Private VLAN Status 24-1Figure 24-2 Private VLAN Link Status 24-2Figure 25-1 Protocol VLAN Configuration 25-2Figure 25-2 Prot

Página 169 - Console#

Quality of Service27-627Web – Click QoS, DiffServ, Policy Map to display the list of existing policy maps. To add a new policy map click Add Policy. T

Página 170

Attaching a Policy Map to Ingress Queues27-727CLI – This example creates a policy map called “rd-policy,” sets the average bandwidth the 1 Mbps, the b

Página 172

28-1Chapter 28: Multicast Filtering Multicasting is used to support real-time applications such as videoconferencing or streaming audio. A multicast s

Página 173 - Displaying LACP Port Counters

Multicast Filtering28-228router/switch to ensure that multicast traffic is passed to all appropriate interfaces within the switch.Static IGMP Host Int

Página 174

Layer 2 IGMP (Snooping and Query)28-328• IGMP Version — Sets the protocol version for compatibility with other devices on the network. (Range: 1-2; De

Página 175

Multicast Filtering28-428Displaying Interfaces Attached to a Multicast RouterMulticast routers that are attached to ports on the switch use informatio

Página 176

Layer 2 IGMP (Snooping and Query)28-528Specifying Static Interfaces for a Multicast RouterDepending on your network connections, IGMP snooping may not

Página 177 - Remote Side

Multicast Filtering28-628Displaying Port Members of Multicast Services You can display the port members associated with a specified VLAN and multicast

Página 178

Layer 2 IGMP (Snooping and Query)28-728Assigning Ports to Multicast Services Multicast filtering can be dynamically configured using IGMP Snooping and

Página 180 - Broadcast Storm Control

Multicast Filtering28-828CLI – This example assigns a multicast address to VLAN 1, and then displays all the known multicast services supported on VLA

Página 181

29-1Chapter 29: Configuring Domain Name Service The Domain Naming System (DNS) service on this switch allows host names to be mapped to IP addresses u

Página 182 - Configuring Port Mirroring

Configuring Domain Name Service29-229Web – Select DNS, General Configuration. Set the default domain name or list of domain names, specify one or more

Página 183

Configuring Static DNS Host to Address Entries29-329Configuring Static DNS Host to Address EntriesYou can manually configure static entries in the DNS

Página 184 - Configuring Rate Limits

Configuring Domain Name Service29-429Web – Select DNS, Static Host Table. Enter a host name and one or more corresponding addresses, then click Apply.

Página 185 - Setting Static Addresses

Displaying the DNS Cache29-529Displaying the DNS CacheYou can display entries in the DNS cache that have been learned via the designated name servers.

Página 186 - Displaying the Address Table

Configuring Domain Name Service29-629CLI - This example displays all the resource records learned from the designated name servers.Console#show dns ca

Página 187

30-1Chapter 30: Switch Clustering Switch Clustering is a method of grouping switches together to enable centralized management through a single unit.

Página 188 - Changing the Aging Time

Switch Clustering30-230Web – Click Cluster, Configuration. Figure 30-1 Cluster ConfigurationCLI – This example first enables clustering on the switch

Página 189

Cluster Member Information30-330Web – Click Cluster, Member Configuration. Figure 30-2 Cluster Member ConfigurationCLI – This example creates a new c

Página 190 - (for this Region)

Section I: Getting StartedThis section provides an overview of the switch, and introduces some basic concepts about network switches. It also describe

Página 191 - Displaying Global Settings

Switch Clustering30-430CLI – This example shows information about cluster Member switches.Cluster Candidate InformationDisplays information about disc

Página 192

Section III:Command Line InterfaceThis section provides a detailed description of the Command Line Interface, along with examples for all of the comma

Página 193

Command Line InterfaceDomain Name Service Commands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .58-1IPv4 Interface Commands . . . .

Página 194 - Configuring Global Settings

31-1Chapter 31: Using the Command Line InterfaceThis chapter describes how to use the Command Line Interface (CLI).Accessing the CLIWhen accessing the

Página 195

Using the Command Line Interface31-231To access the switch through a Telnet session, you must first set the IP address for the switch, and set the def

Página 196

Entering Commands31-331Entering CommandsThis section describes how to enter CLI commands.Keywords and ArgumentsA CLI command is a series of keywords a

Página 197

Using the Command Line Interface31-431Showing CommandsIf you enter a “?” at the command prompt, the system will display the first level of keywords fo

Página 198 - Displaying Interface Settings

Entering Commands31-531Partial Keyword LookupIf you terminate a partial keyword with a question mark, alternatives that match the initial letters are

Página 199

Using the Command Line Interface31-631Understanding Command ModesThe command set is divided into Exec and Configuration classes. Exec commands general

Página 200

Entering Commands31-731Configuration CommandsConfiguration commands are privileged level commands used to modify switch settings. These commands modif

Página 201

Getting Started

Página 202

Using the Command Line Interface31-831To enter the other modes, at the configuration prompt type one of the following commands. Use the exit or end co

Página 203

Entering Commands31-931Command Line ProcessingCommands are not case sensitive. You can abbreviate commands and parameters as long as they contain enou

Página 204 - Settings,” page 22-10

Using the Command Line Interface31-1031

Página 205

32-1Chapter 32: CLI Command GroupsThe system commands can be broken down into the functional groups shown below.Table 32-1 Command Group IndexComman

Página 206

CLI Command Groups32-232The access mode shown in the following tables is indicated by these abbreviations: ACL (Access Control List Configuration) MST

Página 207

33-1Chapter 33: General CommandsThis chapter describes general system commands that apply to using the CLI.enableThis command activates Privileged Exe

Página 208 - Console(config-if)

General Commands33-233Example Related Commands disable (33-2)enable password (41-2)disableThis command returns to Normal Exec mode from privileged mod

Página 209 - Assigning Ports to VLANs

show history33-333Example Related Commands end (33-4)show historyThis command shows the contents of the command history buffer.Default Setting NoneCom

Página 210 - VLAN Configuration

General Commands33-433promptThis command customizes the CLI prompt. Use the no form to restore the default prompt.Syntax prompt stringno promptstring

Página 211

quit33-533Command Mode AnyExample This example shows how to return to the Privileged Exec mode from the Global Configuration mode, and then quit the C

Página 212

1-1Chapter 1: IntroductionThis switch provides a broad range of features for Layer 2 switching. It includes a management agent that allows you to conf

Página 214 - Creating VLANs

34-1Chapter 34: System Management CommandsThis section describes commands used to configure information that uniquely identifies the switch, and displ

Página 215

System Management Commands34-234reloadThis command restarts the system.Note:When the system is restarted, it will always run the Power-On Self-Test. I

Página 216

jumbo frame34-334jumbo frameThis command enables support for jumbo frames. Use the no form to disable it.Syntax [no] jumbo frameDefault Setting Disabl

Página 217

System Management Commands34-434Command Usage • Use this command in conjunction with the show running-config command to compare the information in run

Página 218

show running-config34-534Related Commandsshow running-config (34-5)show running-configThis command displays the configuration information currently in

Página 219

System Management Commands34-634- Multiple spanning tree instances (name and interfaces)- IP address - Layer 4 precedence settings- Spanning tree sett

Página 220

show system34-734show systemThis command displays system information.Default Setting NoneCommand Mode Normal Exec, Privileged ExecCommand Usage • For

Página 221

System Management Commands34-834Command Mode Normal Exec, Privileged ExecCommand Usage The session used to execute this command is indicated by a “*”

Página 222

show version34-934Example Console#show versionUnit1 Serial Number: 0000E8900000 Hardware Version: R01 EPLD Version: 1.02 N

Página 223

Management GuideES4524D Gigabit Ethernet SwitchLayer 2 Switchwith 20 10/100/1000BASE-T (RJ-45) Ports, and 4 Gigabit Combination Ports (RJ-45/SFP)ES454

Página 224

Introduction1-21Description of Software FeaturesThe switch provides a wide range of advanced performance enhancing features. Flow control eliminates t

Página 225

System Management Commands34-1034

Página 226

35-1Chapter 35: File Management CommandsThese commands are used to manage software and configuration files on the switch.Managing FirmwareFirmware can

Página 227 - Enabling Private VLANs

File Management Commands35-235copy This command moves (upload/download) a code image or configuration file between the switch’s flash memory and a

Página 228 - Configuring Private VLANs

copy35-335• To replace the startup configuration, you must use startup-config as the destination.•Use the copy file unit command to copy a local file

Página 229 - Configuring Protocol Groups

File Management Commands35-435The following example shows how to download a configuration file: This example shows how to copy a secure-site certifica

Página 230 - Mapping Protocols to VLANs

dir35-535Command Mode Privileged ExecCommand Usage • If the file type is used for system startup, then this file cannot be deleted. • “Factory_Default

Página 231

File Management Commands35-635• File information is shown below:Example The following example shows how to display all file information:whichbootThis

Página 232

boot system35-735boot systemThis command specifies the file or image used to start up the system.Syntax boot system [unit:] {boot-rom| config | opcode

Página 233 - Layer 2 Queue Settings

File Management Commands35-835

Página 234

36-1Chapter 36: Line Commands You can access the onboard configuration program by attaching a VT100 compatible device to the server’s serial port. The

Página 235

Description of Software Features1-31Port Configuration – You can manually configure the speed and duplex mode, and flow control used on specific ports

Página 236 - Selecting the Queue Mode

Line Commands36-236Command Mode Global Configuration Command Usage Telnet is considered a virtual terminal connection and will be shown as “VTY” in sc

Página 237

password36-336• This command controls login authentication via the switch itself. To configure user names and passwords for remote authentication serv

Página 238 - Figure 26-4 Queue Scheduling

Line Commands36-436Related Commandslogin (36-2)password-thresh (36-5)timeout login responseThis command sets the interval that the system waits for a

Página 239 - Layer 3/4 Priority Settings

password-thresh36-536Default Setting CLI: No timeoutTelnet: 10 minutesCommand Mode Line ConfigurationCommand Usage • If user input is detected within

Página 240 - Mapping IP Precedence

Line Commands36-636Related Commandssilent-time (36-6)silent-timeThis command sets the amount of time the management console is inaccessible after the

Página 241 - Mapping DSCP Priority

parity36-736Command Usage The databits command can be used to mask the high bit on input from devices that generate 7 data bits with parity. If parity

Página 242 - Figure 26-7 IP DSCP Priority

Line Commands36-836speedThis command sets the terminal line’s baud rate. This command sets both the transmit (to terminal) and receive (from terminal)

Página 243 - Mapping IP Port Priority

disconnect36-936Example To specify 2 stop bits, enter this command:disconnectThis command terminates an SSH, Telnet, or console connection.Syntax disc

Página 244

Line Commands36-1036Example To show all lines, enter this command:Console#show line Console configuration: Password threshold: 3 times Interactive

Página 245 - (see page 27-6)

37-1Chapter 37: Event Logging CommandsThis section describes commands used to configure event logging on the switch.logging onThis command controls lo

Página 246 - Configuring a Class Map

Introduction1-41Spanning Tree Algorithm – The switch supports these spanning tree protocols:Spanning Tree Protocol (STP, IEEE 802.1D) – This protocol

Página 247

Event Logging Commands37-237Related Commandslogging history (37-2)logging trap (37-4)clear log (37-5)logging historyThis command limits syslog message

Página 248 - Creating QoS Policies

logging host37-337Example logging hostThis command adds a syslog server host IP address that will receive logging messages. Use the no form to remove

Página 249

Event Logging Commands37-437Command Usage The command specifies the facility type tag sent in syslog messages. (See RFC 3164.) This type has no effect

Página 250 - Quality of Service

clear log37-537clear logThis command clears messages from the log buffer.Syntax clear log [flash | ram]• flash - Event history stored in flash memory

Página 251

Event Logging Commands37-637ExampleThe following example shows that system logging is enabled, the message level for flash memory is “errors” (i.e., d

Página 252

show log37-737show logThis command displays the log messages stored in local memory.Syntax show log {flash | ram}• flash - Event history stored in fla

Página 253 - Multicast

Event Logging Commands37-837

Página 254 - Multicast Filtering

38-1Chapter 38: SMTP Alert CommandsThese commands configure SMTP event handling, and forwarding of alert messages to the specified SMTP servers and em

Página 255

SMTP Alert Commands38-238Examplelogging sendmail levelThis command sets the severity threshold used to trigger alert messages.Syntaxlogging sendmail l

Página 256

logging sendmail destination-email38-338Command Usage You may use an symbolic email address that identifies the switch, or the address of an administr

Página 257

Description of Software Features1-51Traffic Prioritization – This switch prioritizes each packet based on the required level of service, using eight p

Página 258

SMTP Alert Commands38-438Exampleshow logging sendmailThis command displays the settings for the SMTP event handler.Command Mode Normal Exec, Privilege

Página 259

39-1Chapter 39: Time Commands The system clock can be dynamically set by polling a set of specified time servers (NTP or SNTP). Maintaining an accurat

Página 260

Time Commands39-239Example Related Commandssntp server (39-2)sntp poll (39-3)show sntp (39-3)sntp serverThis command sets the IP address of the server

Página 261

sntp poll39-339Related Commandssntp client (39-1)sntp poll (39-3)show sntp (39-3)sntp pollThis command sets the interval between sending time requests

Página 262

Time Commands39-439Example clock timezoneThis command sets the time zone for the switch’s internal clock.Syntax clock timezone name hour hours minute

Página 263

calendar set39-539calendar setThis command sets the system clock. It may be used if there is no time server on your network, or if you have not config

Página 264

Time Commands39-639

Página 265 - Displaying the DNS Cache

40-1Chapter 40: SNMP CommandsControls access to this switch from management stations using the Simple Network Management Protocol (SNMP), as well as t

Página 266

SNMP Commands40-240snmp-serverThis command enables the SNMPv3 engine and services for all management clients (i.e., versions 1, 2c, 3). Use the no for

Página 267 - Cluster Configuration

snmp-server community40-340Examplesnmp-server communityThis command defines the SNMP v1 and v2c community access string. Use the no form to remove the

Página 268 - Cluster Member Configuration

Introduction1-61System DefaultsThe switch’s system defaults are provided in the configuration file “Factory_Default_Config.cfg.” To reset the switch d

Página 269 - Cluster Member Information

SNMP Commands40-440• private - Read/write access. Authorized management stations are able to both retrieve and modify MIB objects.Command Mode Global

Página 270 - Cluster Candidate Information

snmp-server host40-540Command Mode Global ConfigurationExample Related Commandssnmp-server contact (40-4)snmp-server host This command specifies the r

Página 271

SNMP Commands40-640• SNMP Version: 1• UDP Port: 162Command Mode Global ConfigurationCommand Usage • If you do not enter an snmp-server host command, n

Página 272 - Command Line Interface

snmp-server enable traps40-740supports. If the snmp-server host command does not specify the SNMP version, the default is to send SNMP version 1 notif

Página 273 - Accessing the CLI

SNMP Commands40-840conjunction with the corresponding entries in the Notify View assigned by the snmp-server group command (page 40-11).Example Relate

Página 274

show snmp engine-id40-940• A local engine ID is automatically generated that is unique to the switch. This is referred to as the default engine ID. If

Página 275 - Entering Commands

SNMP Commands40-1040snmp-server viewThis command adds an SNMP view which controls user access to the MIB. Use the no form to remove an SNMP view.Synta

Página 276 - Showing Commands

show snmp view40-1140show snmp viewThis command shows information on the SNMP views.Command Mode Privileged ExecExample snmp-server groupThis command

Página 277 - Using Command History

SNMP Commands40-1240• writeview - Defines the view for write access. (1-64 characters)• notifyview - Defines the view for notifications. (1-64 charact

Página 278 - Exec Commands

show snmp group40-1340show snmp groupFour default groups are provided – SNMPv1 read-only access and read/write access, and SNMPv2c read-only access an

Página 279 - Configuration Commands

System Defaults1-71SNMP SNMP Agent EnabledCommunity Strings “public” (read only) “private” (read/write) Traps Authentication traps: enabledLink-up-dow

Página 280

SNMP Commands40-1440snmp-server userThis command adds a user to an SNMP group, restricting the user to a specific SNMP Read, Write, or Notify View. Us

Página 281 - Command Line Processing

show snmp user40-1540Command Usage • The SNMP engine ID is used to compute the authentication/privacy digests from the password. You should therefore

Página 282

SNMP Commands40-1640Table 40-5 show snmp user - display descriptionField DescriptionEngineId String identifying the engine ID.User Name Name of user

Página 283

41-1Chapter 41: User Authentication Commands You can configure this switch to authenticate users logging into the system for management access using l

Página 284 - CLI Command Groups

User Authentication Commands41-241• access-level level - Specifies the user level.The device has two predefined privilege levels: 0: Normal Exec, 15:

Página 285 - Chapter 33: General Commands

Authentication Sequence41-341Default Setting • The default is level 15. • The default password is “super”Command Mode Global ConfigurationCommand Usag

Página 286 - General Commands

User Authentication Commands41-441• tacacs - Use TACACS server password.Default Setting LocalCommand Mode Global ConfigurationCommand Usage • RADIUS u

Página 287

RADIUS Client41-541Command Usage • RADIUS uses UDP while TACACS+ uses TCP. UDP only offers best effort delivery, while TCP offers a connection-oriente

Página 288

User Authentication Commands41-641radius-server hostThis command specifies primary and backup RADIUS servers and authentication parameters that apply

Página 289

RADIUS Client41-741Command Mode Global ConfigurationExample radius-server keyThis command sets the RADIUS encryption key. Use the no form to restore t

Página 290

Introduction1-81Traffic Prioritization Ingress Port Priority 0Queue Mode WRRWeighted Round Robin Queue: 0 1 2 3 4 5 6 7Weight: 1 2 4

Página 291 - Console(config)#hostname RD#1

User Authentication Commands41-841radius-server timeoutThis command sets the interval between transmitting authentication requests to the RADIUS serve

Página 292 - System Management Commands

TACACS+ Client41-941TACACS+ ClientTerminal Access Controller Access Control System (TACACS+) is a logon authentication protocol that uses software run

Página 293 - Console(config)#jumbo frame

User Authentication Commands41-1041Default Setting 49Command Mode Global ConfigurationExample tacacs-server keyThis command sets the TACACS+ encryptio

Página 294

Web Server Commands41-1141Web Server CommandsThis section describes commands used to configure web browser management access to the switch.ip http por

Página 295

User Authentication Commands41-1241Command Mode Global ConfigurationExample Related Commandsip http port (41-11)ip http secure-serverThis command enab

Página 296

Web Server Commands41-1341• The following web browsers and operating systems currently support HTTPS:• To specify a secure-site certificate, see “Repl

Página 297

User Authentication Commands41-1441Related Commandsip http secure-server (41-12)Telnet Server CommandsThis section describes commands used to configur

Página 298

Secure Shell Commands41-1541Secure Shell CommandsThis section describes the commands used to configure the SSH server. Note that you also need to inst

Página 299 - Example

User Authentication Commands41-16412. Provide Host Public Key to Clients – Many SSH client programs automatically import the host public key during th

Página 300

Secure Shell Commands41-1741c.If a match is found, the switch uses its secret key to generate a random 256-bit string as a challenge, encrypts this st

Página 301

2-1Chapter 2: Initial ConfigurationConnecting to the SwitchConfiguration OptionsThe switch includes a built-in network management agent. The agent off

Página 302 - File Management Commands

User Authentication Commands41-1841Example Related Commandsip ssh crypto host-key generate (41-20)show ssh (41-22)ip ssh timeoutThis command configure

Página 303

Secure Shell Commands41-1941ip ssh authentication-retriesThis command configures the number of times the SSH server attempts to reauthenticate a user.

Página 304

User Authentication Commands41-2041delete public-keyThis command deletes the specified user’s public key.Syntax delete public-key username [dsa | rsa]

Página 305 - Console#delete test2.cfg

Secure Shell Commands41-2141Related Commandsip ssh crypto zeroize (41-21)ip ssh save host-key (41-21)ip ssh crypto zeroizeThis command clears the host

Página 306

User Authentication Commands41-2241Example Related Commandsip ssh crypto host-key generate (41-20)show ip sshThis command displays the connection sett

Página 307

Secure Shell Commands41-2341show public-keyThis command shows the public key for the specified user or for the host.Syntax show public-key [user [user

Página 308

User Authentication Commands41-2441Example IP Filter CommandsThis section describes commands used to configure IP management access to the switch.mana

Página 309

IP Filter Commands41-2541Command Mode Global ConfigurationCommand Usage • If anyone tries to access a management interface on the switch from an inval

Página 310 - Line Commands

User Authentication Commands41-2641ExampleConsole#show management all-clientManagement Ip Filter HTTP-Client: Start IP address End IP address--

Página 311 - Console(config-line)#

42-1Chapter 42: Port Security CommandsThese commands can be used to enable port security on a port. When using port security, the switch stops learnin

Página 312

Initial Configuration2-22• Configure up to 32 static or LACP trunks per switch• Enable port mirroring• Set broadcast storm control on any port• Displa

Página 313

Port Security Commands42-242Command Usage • If you enable port security, the switch stops learning new MAC addresses on the specified port when it has

Página 314

43-1Chapter 43: 802.1X Port Authentication The switch supports IEEE 802.1X (dot1x) port-based access control that prevents unauthorized access to the

Página 315

802.1X Port Authentication43-243dot1x defaultThis command sets all configurable dot1x global and port settings to their default values.Command ModeGlo

Página 316

dot1x operation-mode43-343• force-authorized – Configures the port to grant access to all clients, either dot1x-aware or otherwise. • force-unauthor

Página 317 - Console#disconnect 1

802.1X Port Authentication43-443Exampledot1x re-authenticateThis command forces re-authentication on all ports or a specific interface.Syntaxdot1x re-

Página 318

dot1x timeout quiet-period43-543• The connected client is re-authenticated after the interval specified by the dot1x timeout re-authperiod command. Th

Página 319 - Console(config)#logging on

802.1X Port Authentication43-643Command ModeInterface ConfigurationExampledot1x timeout tx-periodThis command sets the time that an interface on the s

Página 320 - Event Logging Commands

show dot1x43-743Command UsageThis command displays the following information:• Global 802.1X Parameters – Shows whether or not 802.1X port authenticat

Página 321

802.1X Port Authentication43-843• Request Count– Number of EAP Request packets sent to the Supplicant without receiving a response.• Identifier(Server

Página 322

44-1Chapter 44: Access Control List Commands Access Control Lists (ACL) provide packet filtering for IPv4 frames (based on address, protocol, Layer 4

Página 323 - Console#clear log

Basic Configuration2-32Note: This switch supports four concurrent Telnet/SSH sessions.After configuring the switch’s IP parameters, you can access the

Página 324

Access Control List Commands44-244access-list ip This command adds an IP access list and enters configuration mode for standard or extended IPv4 ACLs.

Página 325

IPv4 ACLs44-344Default SettingNoneCommand ModeStandard IPv4 ACLCommand Usage• New rules are appended to the end of the list.• Address bitmasks are sim

Página 326

Access Control List Commands44-444• host – Keyword followed by a specific IP address.• precedence – IP precedence level. (Range: 0-7)• tos – Type of S

Página 327

IPv4 ACLs44-544ExampleThis example accepts any incoming packets if the source address is within subnet 10.7.1.x. For example, if the rule is matched;

Página 328 - SMTP Alert Commands

Access Control List Commands44-644ip access-group This command binds a port to an IPv4 ACL. Use the no form to remove the port.Syntax[no] ip access-gr

Página 329

IPv6 ACLs44-744IPv6 ACLsThe commands in this section configure ACLs based on IPv6 addresses, next header type, and flow label. To configure IPv6 ACLs,

Página 330

Access Control List Commands44-844Example Related Commandspermit, deny (44-8)ipv6 access-group (44-11)show ipv6 access-list (44-10)permit, deny (Stand

Página 331 - Chapter 39: Time Commands

IPv6 ACLs44-944permit, deny (Extended IPv6 ACL) This command adds a rule to an Extended IPv6 ACL. The rule sets a filter condition for packets with sp

Página 332 - Time Commands

Access Control List Commands44-1044e.g., in a hop-by-hop option. A flow is uniquely identified by the combination of a source address and a non-zero f

Página 333 - Console(config)#sntp poll 60

IPv6 ACLs44-1144Command ModePrivileged ExecExample Related Commandspermit, deny (44-8)ipv6 access-group (44-11)ipv6 access-group This command binds a

Página 334

ES4524DES4548DF0.0.0.4 E112006-CS-R01149100030400A

Página 335 - 15:12:34 February 1 2002

Initial Configuration2-423. Type “username guest password 0 password,” for the Normal Exec level, where password is your new password. Press <Enter

Página 336

Access Control List Commands44-1244Example Related Commandsipv6 access-group (44-11)MAC ACLsThe commands in this section configure ACLs based on hardw

Página 337 - Chapter 40: SNMP Commands

MAC ACLs44-1344• An ACL can contain up to 32 rules.Example Related Commandspermit, deny (44-13)mac access-group (44-15)show mac access-list (44-14)per

Página 338 - SNMP Commands

Access Control List Commands44-1444• source – Source MAC address.• destination – Destination MAC address range with bitmask.• address-bitmask2 – Bitma

Página 339

MAC ACLs44-1544Example Related Commandspermit, deny 44-13mac access-group (44-15)mac access-groupThis command binds a port to a MAC ACL. Use the no fo

Página 340

Access Control List Commands44-1644Example Related Commandsmac access-group (44-15)ACL InformationThis section describes commands used to display ACL

Página 341

ACL Information44-1744Example Console#show access-groupInterface ethernet 1/2 IP standard access-list david MAC access-list jerryConsole#

Página 342

Access Control List Commands44-1844

Página 343

45-1Chapter 45: Interface Commands These commands are used to display or set communication parameters for an Ethernet port, aggregated link, or VLAN.

Página 344

Interface Commands45-245Command Mode Global Configuration Example To specify port 4, enter the following command:descriptionThis command adds a descri

Página 345

negotiation45-345Default Setting • Auto-negotiation is enabled by default. • When auto-negotiation is disabled, the default speed-duplex setting is: -

Página 346

Basic Configuration2-523. Type “exit” to return to the global configuration mode prompt. Press <Enter>. 4. To set the IP address of the default

Página 347

Interface Commands45-445• If autonegotiation is disabled, auto-MDI/MDI-X pin signal configuration will also be disabled for the RJ-45 ports.Example Th

Página 348

flowcontrol45-545Example The following example configures Ethernet port 5 capabilities to 100half and 100full.Related Commands negotiation (45-3)speed

Página 349 - Field Description

Interface Commands45-645Related Commands negotiation (45-3)capabilities (flowcontrol, symmetric) (45-4)media-typeThis command forces the port type sel

Página 350

clear counters45-745Command Usage This command allows you to disable a port due to abnormal behavior (e.g., excessive collisions), and then reenable i

Página 351

Interface Commands45-845show interfaces statusThis command displays the status for an interface.Syntax show interfaces status [interface]interface • e

Página 352

show interfaces counters45-945show interfaces countersThis command displays interface statistics. Syntax show interfaces counters [interface]interface

Página 353 - User Account Commands

Interface Commands45-1045show interfaces switchportThis command displays the administrative and operational status of the specified interfaces.Syntax

Página 354 - User Authentication Commands

show interfaces switchport45-1145VLAN membership mode Indicates membership mode as Trunk or Hybrid (page 52-8).Ingress rule Shows if ingress filtering

Página 355 - Authentication Sequence

Interface Commands45-1245

Página 356

46-1Chapter 46: Link Aggregation Commands Ports can be statically grouped into an aggregate link (i.e., trunk) to increase the bandwidth of a network

Página 357 - RADIUS Client

Initial Configuration2-62To configure an IPv6 link local address for the switch, complete the following steps:1. From the Global Configuration mode pr

Página 358

Link Aggregation Commands46-246• All the ports in a trunk have to be treated as a whole when moved from/to, added or deleted from a VLAN via the speci

Página 359

port channel load-balance46-346port channel load-balanceThis command sets the load-distribution method among ports in aggregated links (for both stati

Página 360

Link Aggregation Commands46-446- src-dst-ip: All traffic with the same source and destination IP address is output on the same link in a trunk. This m

Página 361 - TACACS+ Client

lacp system-priority46-546ExampleThe following shows LACP enabled on ports 10-12. Because LACP has also been enabled on the ports at the other end of

Página 362

Link Aggregation Commands46-646Command Mode Interface Configuration (Ethernet)Command Usage • Port must be configured with the same system priority to

Página 363 - Web Server Commands

lacp admin-key (Port Channel)46-746• Once the remote side of a link has been established, LACP operational settings are already in use on that side. C

Página 364

Link Aggregation Commands46-846lacp port-priorityThis command configures LACP port priority. Use the no form to restore the default setting.Syntax lac

Página 365

show lacp46-946Default Setting Port Channel: allCommand Mode Privileged ExecExample Console#show lacp 1 countersPort channel: 1-----------------

Página 366 - Telnet Server Commands

Link Aggregation Commands46-1046Table 46-3 show lacp internal - display descriptionField DescriptionOper Key Current operational value of the key fo

Página 367 - Secure Shell Commands

show port-channel load-balance46-1146show port-channel load-balanceThis command shows the setting of the aggregated link load-balance method.Default S

Página 368

Basic Configuration2-72To generate an IPv6 global unicast address for the switch using a general network prefix, complete the following steps:1. From

Página 369

Link Aggregation Commands46-1246ExampleConsole#show port-channel load-balanceSource and destination IP addressConsole#

Página 370

47-1Chapter 47: Broadcast Storm Control CommandsThese commands can be used to enable broadcast storm control on a port. You can protect your network f

Página 371

Broadcast Storm Control Commands47-247

Página 372

48-1Chapter 48: Mirror Port Commands This section describes how to mirror traffic from a source port to a target port. port monitorThis command config

Página 373

Mirror Port Commands48-248Example The following example configures the switch to mirror all packets from port 6 to 11:show port monitorThis command di

Página 374

49-1Chapter 49: Rate Limit Commands This function allows the network manager to control the maximum rate for traffic transmitted or received on an int

Página 375

Rate Limit Commands49-249

Página 376 - IP Filter Commands

50-1Chapter 50: Address Table Commands These commands are used to configure the address table for filtering specified addresses, displaying current en

Página 377

Address Table Commands50-250Command Usage The static address for a host device can be assigned to a specific port within a specific VLAN. Use this com

Página 378

show mac-address-table50-350show mac-address-tableThis command shows classes of entries in the bridge-forwarding database.Syntax show mac-address-tabl

Página 379 - Command Function Mode Page

Initial Configuration2-82Dynamic ConfigurationObtaining an IPv4 AddressIf you select the “bootp” or “dhcp” option, IP will be enabled but will not fun

Página 380 - Port Security Commands

Address Table Commands50-450mac-address-table aging-timeThis command sets the aging time for entries in the address table. Use the no form to restore

Página 381

51-1Chapter 51: Spanning Tree Commands This section includes commands that configure the Spanning Tree Algorithm (STA) globally for the switch, and co

Página 382 - 802.1X Port Authentication

Spanning Tree Commands51-251spanning-treeThis command enables the Spanning Tree Algorithm globally for the switch. Use the no form to disable it.Synta

Página 383 - Console(config-if)#

spanning-tree forward-time51-351Command Usage • Spanning Tree ProtocolUses RSTP for the internal state machine, but sends only 802.1D BPDUs. - This cr

Página 384

Spanning Tree Commands51-451Default Setting 15 secondsCommand Mode Global ConfigurationCommand Usage This command sets the maximum time (in seconds) t

Página 385

spanning-tree max-age51-551spanning-tree max-ageThis command configures the spanning tree bridge maximum age globally for this switch. Use the no form

Página 386

Spanning Tree Commands51-651Default Setting 32768Command Mode Global ConfigurationCommand Usage Bridge priority is used in selecting the root device,

Página 387

spanning-tree transmission-limit51-751spanning-tree transmission-limitThis command configures the minimum interval between the transmission of consecu

Página 388

Spanning Tree Commands51-851mst vlanThis command adds VLANs to a spanning tree instance. Use the no form to remove the specified VLANs. Using the no f

Página 389 - IPv4 ACLs

mst priority51-951mst priorityThis command configures the priority of a spanning tree instance. Use the no form to restore the default.Syntax mst inst

Página 390 - Access Control List Commands

Basic Configuration2-92Obtaining an IPv6 AddressLink Local Address — There are several ways to dynamically configure IPv6 addresses. The simplest meth

Página 391

Spanning Tree Commands51-1051Command Usage The MST region name and revision number (page 51-10) are used to designate a unique MST region. A bridge (i

Página 392

max-hops51-1151max-hopsThis command configures the maximum number of hops in the region before a BPDU is discarded. Use the no form to restore the def

Página 393

Spanning Tree Commands51-1251spanning-tree costThis command configures the spanning tree path cost for the specified interface. Use the no form to res

Página 394

spanning-tree port-priority51-1351spanning-tree port-priorityThis command configures the priority for the specified interface. Use the no form to rest

Página 395 - IPv6 ACLs

Spanning Tree Commands51-1451cause forwarding loops, they can pass directly through to the spanning tree forwarding state. Specifying Edge Ports provi

Página 396

spanning-tree link-type51-1551ExampleRelated Commandsspanning-tree edge-port (51-13)spanning-tree link-typeThis command configures the link type for R

Página 397

Spanning Tree Commands51-1651spanning-tree mst costThis command configures the path cost on a spanning instance in the Multiple Spanning Tree. Use the

Página 398

spanning-tree mst port-priority51-1751spanning-tree mst port-priorityThis command configures the interface priority on a spanning instance in the Mult

Página 399

Spanning Tree Commands51-1851Command Mode Privileged ExecCommand Usage If at any time the switch detects STP BPDUs, including Configuration or Topolog

Página 400 - MAC ACLs

show spanning-tree51-1951• For a description of the items displayed under “Spanning-tree information,” see “Configuring Global Settings” on page 22-6.

Página 401

Initial Configuration2-1022. From the interface prompt, type “ipv6 address autoconfig” and press <Enter>.Enabling SNMP Management Access The swi

Página 402

Spanning Tree Commands51-2051show spanning-tree mst configurationThis command shows the configuration of the multiple spanning tree.Command Mode Privi

Página 403

52-1Chapter 52: VLAN Commands A VLAN is a group of ports that can be located anywhere in the network, but communicate as though they belong to the sam

Página 404 - ACL Information

VLAN Commands52-252bridge-ext gvrpThis command enables GVRP globally for the switch. Use the no form to disable it.Syntax [no] bridge-ext gvrpDefault

Página 405

GVRP and Bridge Extension Commands52-352switchport gvrpThis command enables GVRP for a port. Use the no form to disable it.Syntax [no] switchport gvrp

Página 406

VLAN Commands52-452garp timerThis command sets the values for the join, leave and leaveall timers. Use the no form to restore the timers’ default valu

Página 407

Editing VLAN Groups52-552show garp timerThis command shows the GARP timers for the selected interface.Syntax show garp timer [interface]interface • et

Página 408 - Interface Commands

VLAN Commands52-652Command Usage • Use the VLAN database command mode to add, change, and delete VLANs. After finishing configuration changes, you can

Página 409

Configuring VLAN Interfaces52-752Example The following example adds a VLAN, using VLAN ID 105 and name RD5. The VLAN is activated by default.Related C

Página 410

VLAN Commands52-852Example The following example shows how to set the interface configuration mode to VLAN 1, and then assign an IP address to the VLA

Página 411

Configuring VLAN Interfaces52-952switchport acceptable-frame-types This command configures the acceptable frame types for a port. Use the no form to r

Página 412

Basic Configuration2-112The default strings are:• public - with read-only access. Authorized management stations are only able to retrieve MIB objects

Página 413 - Console(config-if)#shutdown

VLAN Commands52-1052• If ingress filtering is enabled and a port receives frames tagged for VLANs for which it is not a member, these frames will be d

Página 414

Configuring VLAN Interfaces52-1152switchport allowed vlanThis command configures VLAN groups on the selected interface. Use the no form to restore the

Página 415

VLAN Commands52-1252switchport forbidden vlanThis command configures forbidden VLANs. Use the no form to remove the list of forbidden VLANs.Syntax swi

Página 416

Configuring IEEE 802.1Q Tunneling52-1352Configuring IEEE 802.1Q TunnelingIEEE 802.1Q tunneling (QinQ tunneling) uses a single Service Provider VLAN (S

Página 417

VLAN Commands52-1452dot1q-tunnel system-tunnel-controlThis command sets the switch to operate in QinQ mode. Use the no form to disable QinQ operating

Página 418

Configuring IEEE 802.1Q Tunneling52-1552ExampleRelated Commandsshow dot1q-tunnel (52-16)show interfaces switchport (45-10)switchport dot1q-tunnel tpi

Página 419

VLAN Commands52-1652show dot1q-tunnelThis command displays information about QinQ tunnel ports.Command Mode Privileged ExecExampleRelated Commandsswit

Página 420 - Link Aggregation Commands

Displaying VLAN Information52-1752show vlanThis command shows VLAN information.Syntax show vlan [id vlan-id | name vlan-name]• id - Keyword to be foll

Página 421

VLAN Commands52-1852

Página 422

53-1Chapter 53: Private VLAN CommandsPrivate VLANs provide port-based security and isolation between ports within the assigned VLAN. This section des

Página 423

Initial Configuration2-122Configuring Access for SNMP Version 3 ClientsTo configure management access for SNMPv3 clients, you need to first create a v

Página 424

Private VLAN Commands53-253show pvlanThis command displays the configured private VLAN.Command Mode Privileged ExecExampleConsole#show pvlanPrivate VL

Página 425

54-1Chapter 54: Protocol-based VLAN CommandsThe network devices required to support multiple protocols cannot be easily grouped into a common VLAN. T

Página 426

Protocol-based VLAN Commands54-254• protocol - Protocol type. The only option for the llc_other frame type is ipx_raw. The options for all other frame

Página 427

show protocol-vlan protocol-group54-354- If the frame is untagged and the protocol type matches, the frame is forwarded to the appropriate VLAN.- If t

Página 428

Protocol-based VLAN Commands54-454show interfaces protocol-vlan protocol-groupThis command shows the mapping from protocol groups to VLANs for the sel

Página 429

55-1Chapter 55: Class of Service Commands The commands described in this section allow you to specify which data packets have greater precedence when

Página 430

Class of Service Commands55-255queue modeThis command sets the queue mode to strict priority or Weighted Round-Robin (WRR) for the class of service (C

Página 431 - Commands

Priority Commands (Layer 2)55-355switchport priority defaultThis command sets a priority for incoming untagged frames. Use the no form to restore the

Página 432

Class of Service Commands55-455queue bandwidth This command assigns weighted round-robin (WRR) weights to the eight class of service (CoS) priority qu

Página 433

Priority Commands (Layer 2)55-555Default Setting This switch supports Class of Service by using eight priority queues, with Weighted Round Robin queui

Página 434 - Mirror Port Commands

Managing System Files2-132Due to the size limit of the flash memory, the switch supports only two operation code files. However, you can have as many

Página 435

Class of Service Commands55-655show queue bandwidthThis command displays the weighted round-robin (WRR) bandwidth allocation for the eight priority qu

Página 436 - Rate Limit Commands

Priority Commands (Layer 3 and 4)55-755Priority Commands (Layer 3 and 4)This section describes commands used to configure Layer 3 and Layer 4 traffic

Página 437

Class of Service Commands55-855map ip port (Interface Configuration)This command sets IP port priority (i.e., TCP/UDP port priority). Use the no form

Página 438 - Address Table Commands

Priority Commands (Layer 3 and 4)55-955Example The following example shows how to enable IP precedence mapping globally:map ip precedence (Interface C

Página 439

Class of Service Commands55-1055map ip dscp (Global Configuration)This command enables IP DSCP mapping (i.e., Differentiated Services Code Point mappi

Página 440

Priority Commands (Layer 3 and 4)55-1155Default Setting The DSCP default values are defined in the following table. Note that all the DSCP values that

Página 441

Class of Service Commands55-1255Default SettingNoneCommand Mode Privileged ExecExample The following shows that HTTP traffic has been mapped to CoS va

Página 442 -

Priority Commands (Layer 3 and 4)55-1355Example Related Commands map ip precedence (Global Configuration) (55-8)map ip precedence (Interface Configura

Página 443

Class of Service Commands55-1455Related Commands map ip dscp (Global Configuration) (55-10)map ip dscp (Interface Configuration) (55-10)

Página 444 - Spanning Tree Commands

56-1Chapter 56: Quality of Service Commands The commands described in this section are used to configure Differentiated Services (DiffServ) classifica

Página 445

vContents Section I: Getting StartedChapter 1: Introduction 1-1Key Features 1-1Description of Software Features 1-2System Defaults 1-6Chapter 2:

Página 446

Initial Configuration2-142

Página 447 - Console(config-mstp)#

Quality of Service Commands56-256Notes: 1. You can configure up to 16 rules per Class Map. You can also include multiple classes in a Policy Map.2. Yo

Página 448

match56-356matchThis command defines the criteria used to classify traffic. Use the no form to delete the matching criteria.Syntax [no] match {access-

Página 449

Quality of Service Commands56-456policy-mapThis command creates a policy map that can be attached to multiple interfaces, and enters Policy Map config

Página 450

set56-556Default Setting NoneCommand Mode Policy Map ConfigurationCommand Usage • Use the policy-map command to specify a policy map and enter Policy

Página 451

Quality of Service Commands56-656Command Mode Policy Map Class ConfigurationExample This example creates a policy called “rd_policy,” uses the class c

Página 452

service-policy56-756Example This example creates a policy called “rd_policy,” uses the class command to specify the previously defined “rd_class,” use

Página 453

Quality of Service Commands56-856show class-mapThis command displays the QoS class maps which define matching criteria used for classifying traffic.Sy

Página 454

show policy-map interface56-956Exampleshow policy-map interfaceThis command displays the service policy assigned to the specified interface.Syntax sho

Página 455

Quality of Service Commands56-1056

Página 456

57-1Chapter 57: Multicast Filtering Commands This switch uses IGMP (Internet Group Management Protocol) to query for any attached hosts that want to r

Página 457

Section II: Switch ManagementThis section describes the basic switch features, along with a detailed description of how to configure each feature via

Página 458

Multicast Filtering Commands57-257ip igmp snooping vlan staticThis command adds a port to a multicast group. Use the no form to remove the port.Syntax

Página 459

IGMP Snooping Commands57-357Example The following configures the switch to use IGMP Version 1:show ip igmp snoopingThis command shows the IGMP snoopin

Página 460

Multicast Filtering Commands57-457Example The following shows the multicast entries learned through IGMP snooping for VLAN 1:IGMP Query CommandsThis s

Página 461 - Chapter 52: VLAN Commands

IGMP Query Commands57-557ip igmp snooping query-countThis command configures the query count. Use the no form to restore the default.Syntax ip igmp sn

Página 462 - VLAN Commands

Multicast Filtering Commands57-657Example The following shows how to configure the query interval to 100 seconds:ip igmp snooping query-max-response-t

Página 463

IGMP Query Commands57-757ip igmp snooping router-port-expire-timeThis command configures the query timeout. Use the no form to restore the default.Syn

Página 464

Multicast Filtering Commands57-857Static Multicast Routing Commandsip igmp snooping vlan mrouterThis command statically configures a multicast router

Página 465 - Editing VLAN Groups

Static Multicast Routing Commands57-957show ip igmp snooping mrouter This command displays information on statically configured and dynamically learne

Página 466

Multicast Filtering Commands57-1057

Página 467 - Configuring VLAN Interfaces

58-1Chapter 58: Domain Name Service Commands These commands are used to configure Domain Naming System (DNS) services. You can manually configure entr

Página 468

Switch ManagementConfiguring Domain Name Service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29-1Switch Clustering . . . . . . . .

Página 469

Domain Name Service Commands58-258Command Usage Servers or other network devices may support one or more connections via multiple IP addresses. If mor

Página 470

ip domain-name58-358ip domain-nameThis command defines the default domain name appended to incomplete host names (i.e., host names passed from a clien

Página 471

Domain Name Service Commands58-458Default Setting NoneCommand Mode Global ConfigurationCommand Usage • Domain names are added to the end of the list o

Página 472

ip domain-lookup58-558Command Usage The listed name servers are queried in the specified sequence until a response is received, or the end of the list

Página 473

Domain Name Service Commands58-658ExampleThis example enables DNS and then displays the configuration.Related Commands ip domain-name (58-3)ip name-se

Página 474

show dns58-758show dnsThis command displays the configuration of the DNS service.Command Mode Privileged ExecExampleshow dns cacheThis command display

Página 475

Domain Name Service Commands58-858clear dns cacheThis command clears all entries in the DNS cache.Command Mode Privileged ExecExampleConsole#clear dns

Página 476 - Displaying VLAN Information

59-1Chapter 59: IPv4 Interface Commands An IP addresses may be used for management access to the switch over your network. An IPv4 address for this sw

Página 477

IPv4 Interface Commands59-259numbers, 0 to 255, separated by periods. Anything outside this format will not be accepted by the configuration program.

Página 478

ip dhcp restart59-359• An default gateway can only be successfully set when a network interface that directly connects to the gateway has been configu

Página 479

3-1Chapter 3: Configuring the SwitchUsing the Web InterfaceThis switch provides an embedded HTTP web agent. Using a web browser you can configure the

Página 480 - Private VLAN Commands

IPv4 Interface Commands59-459show ip interfaceThis command displays the settings of an IPv4 interface.Command Mode Privileged ExecExample Related Comm

Página 481

ping59-559pingThis command sends (IPv4) ICMP echo request packets to another node on the network.Syntax ping host [count count][size size]• host - IP

Página 482 - Interfaces)

IPv4 Interface Commands59-659

Página 483

60-1Chapter 60: IPv6 Interface CommandsAn IPv6 address can either be manually configured or dynamically generated. You may also need to a establish an

Página 484 - Protocol-based VLAN Commands

IPv6 Interface Commands60-260ipv6 enableThis command enables IPv6 on an interface that has not been configured with an explicit IPv6 address. Use the

Página 485 - Priority Commands (Layer 2)

ipv6 general-prefix60-360ipv6 general-prefixThis command defines an IPv6 general prefix for the network address segment. Use the no form to remove the

Página 486 - Class of Service Commands

IPv6 Interface Commands60-460show ipv6 general-prefixThis command displays all configured IPv6 general prefixes.Command Mode Normal Exec, Privileged E

Página 487

ipv6 address60-560Command Usage • The general prefix normally applies to all interfaces, and is therefore specified at the global configuration level.

Página 488

IPv6 Interface Commands60-660ipv6 address autoconfig This command enables stateless autoconfiguration of IPv6 addresses on an interface and enables IP

Página 489

ipv6 address eui-6460-760Related Commands ipv6 address (60-4)show ipv6 interface (60-10)ipv6 address eui-64 This command configures an IPv6 address fo

Página 490

Configuring the Switch3-23Navigating the Web Browser InterfaceTo access the web-browser interface you must first enter a user name and password. The a

Página 491 - Console(config)#map ip port

IPv6 Interface Commands60-860universal/local bit in the address and inserting the hexadecimal number FFFE between the upper and lower three bytes of t

Página 492

ipv6 address link-local60-960ipv6 address link-local This command configures an IPv6 link-local address for an interface and enables IPv6 on the inter

Página 493 - 01234567

IPv6 Interface Commands60-1060Related Commands ipv6 enable (60-2)show ipv6 interface (60-10)show ipv6 interfaceThis command displays the usability and

Página 494

show ipv6 interface60-1160This example displays a brief summary of IPv6 addresses configured on the switch.Related Commands show ip interface (59-4)IP

Página 495

IPv6 Interface Commands60-1260ipv6 default-gateway This command sets an IPv6 default gateway to use when the management station in located on a differ

Página 496

ipv6 mtu60-1360Example The following shows the default gateway configured for this device:Related Commands show ip redirects (59-4)ipv6 mtu This comma

Página 497

IPv6 Interface Commands60-1460show ipv6 mtuThis command displays the maximum transmission unit (MTU) cache for destinations that have returned an ICMP

Página 498

show ipv6 traffic60-1560Example The following example shows statistics for all IPv6 unicast and multicast traffic, as well as ICMP, UDP and TCP statis

Página 499

IPv6 Interface Commands60-1660 router solicit 0 router advert 0 redirects 0 neighbor soli

Página 500 - Quality of Service Commands

show ipv6 traffic60-1760hop count exceeded Number of packets discarded because its time-to-live (TTL) field was decremented to zero. unknown protocol

Página 501

Navigating the Web Browser Interface3-33Configuration OptionsConfigurable parameters have a dialog box or a drop-down list. Once a configuration chang

Página 502

IPv6 Interface Commands60-1860Ipv6 mcastmcast received The number of multicast packets received by the interface.mcast sent The number of multicast pa

Página 503 - Console(config-pmap-c)#

show ipv6 traffic60-1960router solicit The number of ICMP Router Solicit messages received by the interface.router advert The number of ICMP Router Ad

Página 504

IPv6 Interface Commands60-2060clear ipv6 traffic This command resets IPv6 traffic counters.Command Mode Privileged ExecCommand Usage This command rese

Página 505

ping ipv660-2160ping ipv6 This command sends ICMP echo request packets to an IPv6 node on the network.ping ipv6 address {ipv6-address | host-name} [si

Página 506

IPv6 Interface Commands60-2260Example Related Commands ping (59-5)ipv6 neighbor This command configures a static entry in the IPv6 neighbor discovery

Página 507

ipv6 nd dad attempts60-2360• If the specified entry was dynamically learned through the IPv6 neighbor discovery process, and already exists in the nei

Página 508

IPv6 Interface Commands60-2460in a “pending” state. Duplicate address detection is automatically restarted when the interface is administratively re-a

Página 509 - IGMP Snooping Commands

ipv6 nd ns interval60-2560ipv6 nd ns interval This command configures the interval between transmitting IPv6 neighbor solicitation messages on an inte

Página 510 - Multicast Filtering Commands

IPv6 Interface Commands60-2660show ipv6 neighborsThis command displays information in the IPv6 neighbor discovery cache.Syntax show ipv6 neighbors [vl

Página 511

clear ipv6 neighbors60-2760Related Commands show mac-address-table (50-3)clear ipv6 neighborsThis command deletes all dynamic entries in the IPv6 neig

Página 512 - IGMP Query Commands

Configuring the Switch3-43Main Menu Using the onboard web agent, you can define system parameters, manage and control the switch, and all its ports, o

Página 513

IPv6 Interface Commands60-2860

Página 514

61-1Chapter 61: Switch Cluster CommandsSwitch Clustering is a method of grouping switches together to enable centralized management through a single u

Página 515

Switch Cluster Commands61-261• Configured switch clusters are maintained across power resets and network changes.Examplecluster commanderThis command

Página 516

cluster member61-361Command ModeGlobal ConfigurationCommand Usage • An “internal” IP address pool is used to assign IP addresses to Member switches in

Página 517

Switch Cluster Commands61-461rcommandThis command provides access to a cluster Member CLI for configuration. Syntax rcommand id <member-id>membe

Página 518

show cluster members61-561show cluster membersThis command shows the current switch cluster members.Command Mode Privileged ExecExampleshow cluster ca

Página 519

Switch Cluster Commands61-661

Página 520 - Domain Name Service Commands

Section IV:AppendicesThis section provides additional information on the following topics. Software Specifications . . . . . . . . . . . . . . . . .

Página 521

Appendices

Página 522

A-1Appendix A: Software SpecificationsSoftware FeaturesAuthenticationLocal, RADIUS, TACACS+, Port (802.1X), HTTPS, SSH, Port SecurityAccess Control Li

Página 523

Navigating the Web Browser Interface3-53SNMP 11-1Configuration Configures community strings and related trap functions 11-3Agent Status Enables or dis

Página 524

Software SpecificationsA-2AMulticast Filtering IGMP SnoopingSwitch Clustering36 groupsAdditional FeaturesCIDR (Classless Inter-Domain Routing)SNTP (Si

Página 525

Management Information BasesA-3AIGMPv2 (RFC 2236)IPv4 IGMP (RFC 3228)RADIUS+ (RFC 2618)RMON (RFC 2819 groups 1,2,3,9)SNMP (RFC 1157)SNMPv2c (RFC 2571)

Página 526

Software SpecificationsA-4ATACACS+ Authentication Client MIBTCP MIB (RFC 2012)Trap (RFC 1215)UDP MIB (RFC 2013)

Página 527

B-1Appendix B: TroubleshootingProblems Accessing the Management Interface Table B-1 Troubleshooting ChartSymptom ActionCannot connect using Telnet,

Página 528 - IPv4 Interface Commands

TroubleshootingB-2BUsing System LogsIf a fault does occur, refer to the Installation Guide to ensure that the problem you encountered is actually caus

Página 529

Glossary-1GlossaryAccess Control List (ACL)ACLs can limit network traffic and restrict access to certain users or devices by checking each packet for

Página 530

GlossaryGlossary-2Extended Universal Identifier (EUI) An address format used by IPv6 to identify the host portion of the network address. The interfac

Página 531

Glossary-3GlossaryIEEE 802.1QVLAN Tagging—Defines Ethernet frame tags which carry VLAN information. It allows switches to assign endstations to differ

Página 532

GlossaryGlossary-4IP Multicast FilteringA process whereby this switch can pass multicast traffic along to participating hosts.IP PrecedenceThe Type of

Página 533

Glossary-5GlossaryPort AuthenticationSee IEEE 802.1X.Port MirroringA method whereby data on a target port is mirrored to a monitor port for troublesho

Página 534 - IPv6 Interface Commands

Configuring the Switch3-63Trunk Membership Specifies ports to group into static trunks 17-2LACP 17-1Configuration Allows ports to dynamically join tr

Página 535

GlossaryGlossary-6Secure Shell (SSH)A secure replacement for remote access functions, including Telnet. SSH can authenticate users with a cryptographi

Página 536

Glossary-7GlossaryUser Datagram Protocol (UDP)UDP provides a datagram mode for packet-switched communications. It uses IP as the underlying transport

Página 537

GlossaryGlossary-8

Página 538

Index-1Numerics802.1Q tunnel 23-12, 52-13description 23-12interface configuration 23-17, 52-14–52-15mode selection 23-17TPID 23-17, 52-15802.1X, port

Página 539

Index-2IndexEedge port, STA 22-12, 22-14, 51-13event logging 37-1Ffirmwaredisplaying version 4-3, 34-8upgrading 6-2, 35-2GGARP VLAN Registration Proto

Página 540

Index-3IndexTACACS+ server 12-2, 41-9logon authentication, sequence 12-3, 41-3, 41-4Mmain menu 3-4Management Information Bases (MIBs) A-3mirror port,

Página 541

Index-4Indexpath cost method 22-8, 51-6port priority 22-12, 51-13protocol migration 22-14, 51-17transmission limit 22-8, 51-7standards, IEEE A-2startu

Página 542

e-mail: [email protected]tel: 08-52 400 700 fax: 08-520 18121e-mail: [email protected]tel: 08-52 400 700 fax: 08-520 18121

Página 543 - Related Commands

ES4524DES4548DE112006-CS-R01149100030400A

Página 544

Navigating the Web Browser Interface3-73Port Configuration Configures port settings for a specified MST instance 22-19Trunk Configuration Configures t

Página 545

ContentsviChapter 5: Setting an IP Address 5-1Setting the Switch’s IP Address (IP Version 4) 5-1Manual Configuration 5-2Using DHCP/BOOTP 5-3Setti

Página 546

Configuring the Switch3-83IP DSCP Priority Sets IP Differentiated Services Code Point priority, mapping a DSCP tag to a class-of-service value26-9IP P

Página 547

4-1Chapter 4: Basic System SettingsThis chapter describes the basic functions required to set up management access to the switch, display or upgrade o

Página 548

Basic System Settings4-24Web – Click System, System Information. Specify the system name, location, and contact information for the system administrat

Página 549

Displaying Switch Hardware/Software Versions4-34CLI – Specify the hostname, location and contact information.Displaying Switch Hardware/Software Versi

Página 550

Basic System Settings4-44• Boot-ROM Version – Version of Power-On Self-Test (POST) and boot code.• Operation Code Version – Version number of runtime

Página 551

Displaying Bridge Extension Capabilities4-54Displaying Bridge Extension CapabilitiesThe Bridge MIB includes extensions for managed devices that suppor

Página 552

Basic System Settings4-64CLI – Enter the following command. Configuring Support for Jumbo FramesThe switch provides more efficient throughput for larg

Página 553

Renumbering the Stack4-74Renumbering the StackIf the units are no longer numbered sequentially after several topology changes or failures, you can res

Página 554

Basic System Settings4-84

Página 555

5-1Chapter 5: Setting an IP AddressThis chapter describes how to configure an IPv4 interface for management access over the network. This switch suppo

Página 556

ContentsviiConfiguring the SSH Server 12-12Filtering IP Addresses for Management Access 12-13Chapter 13: Configuring Port Security 13-1Chapter 14:

Página 557

Setting an IP Address5-25Manual ConfigurationWeb – Click System, IP Configuration. Select the VLAN through which the management station is attached, s

Página 558 - Console#show ipv6 neighbors

Setting the Switch’s IP Address (IP Version 4)5-35Using DHCP/BOOTP If your network provides DHCP/BOOTP services, you can configure the switch to be dy

Página 559 - Console#clear ipv6 neighbors

Setting an IP Address5-45Web – If the address assigned by DHCP is no longer functioning, you will not be able to renew the IP settings via the web int

Página 560

Setting the Switch’s IP Address (IP Version 6)5-55length, and using the EUI-64 form of the interface identifier to automatically create the low-order

Página 561

Setting an IP Address5-65IP Address• Auto Configuration – Enables stateless autoconfiguration of IPv6 addresses on an interface and enables IPv6 funct

Página 562 - Switch Cluster Commands

Setting the Switch’s IP Address (IP Version 6)5-75length of the general prefix takes precedence, and some of the address bits entered in the IPv6 Addr

Página 563

Setting an IP Address5-85Current Address Table• IPv6 Address – IPv6 address assigned to this interface. In addition to the unicast addresses assigned

Página 564

Setting the Switch’s IP Address (IP Version 6)5-95Web – Click System, IPv6 Configuration, IPv6 Configuration. Set the IPv6 default gateway, specify th

Página 565

Setting an IP Address5-105CLI – This example configures an IPv6 gateway, specifies the management interface, configures a global unicast address, and

Página 566

Setting the Switch’s IP Address (IP Version 6)5-115Web – Click System, IPv6 Configuration, IPv6 General Prefix. Click Add to open the editing fields f

Página 567 - Section IV:Appendices

ContentsviiiConfiguring Global Settings 22-6Displaying Interface Settings 22-10Configuring Interface Settings 22-13Configuring Multiple Spanning Tr

Página 568 - Appendices

Setting an IP Address5-125- Configuring a value of 0 disables duplicate address detection.- Duplicate address detection determines if a new unicast IP

Página 569 - Software Features

Setting the Switch’s IP Address (IP Version 6)5-135- PROBE - A reachability confirmation is actively sought by resending neighbor solicitation message

Página 570 - Standards

Setting an IP Address5-145Web – Click System, IPv6 Configuration, IPv6 ND Neighbor. To configure the Neighbor Detection protocol settings, select a VL

Página 571 - Management Information Bases

6-1Chapter 6: Managing System FilesThis chapter describes how to upgrade the switch operating software, save and restore switch configuration files, a

Página 572 - Software Specifications

Managing System Files6-26Downloading System Software from a Server When downloading runtime code, you can specify the destination file name to replace

Página 573 - Appendix B: Troubleshooting

Managing Firmware6-36To delete a file select System, File Management, Delete. Select the file name from the given list by checking the tick box and cl

Página 574 - Using System Logs

Managing System Files6-46Saving or Restoring Configuration SettingsYou can upload/download configuration settings to/from a TFTP server. The configura

Página 575 - Glossary

Saving or Restoring Configuration Settings6-56Downloading Configuration Settings from a ServerYou can download the configuration file under a new file

Página 576

Managing System Files6-66CLI – Enter the IP address of the TFTP server, specify the source file on the server, set the startup file name on the switch

Página 577

7-1Chapter 7: Console Port SettingsYou can access the onboard configuration program by attaching a VT100 compatible device to the switch’s serial cons

Página 578

ContentsixChapter 28: Multicast Filtering 28-1Layer 2 IGMP (Snooping and Query) 28-1Configuring IGMP Snooping and Query Parameters 28-2Displaying I

Página 579

Console Port Settings7-27Web – Click System, Line, Console. Specify the console port connection parameters as required, then click Apply.Figure 7-1 C

Página 580

8-1Chapter 8: Telnet SettingsYou can access the onboard configuration program over the network using Telnet (i.e., a virtual terminal). Management acc

Página 581

Telnet Settings8-28Figure 8-1 Configuring the Telnet InterfaceCLI – Enter Line Configuration mode for a virtual terminal, then specify the connection

Página 582 - Glossary-8

9-1Chapter 9: Configuring Event LoggingThe switch allows you to control the logging of error messages, including the type of events that are recorded

Página 583

Configuring Event Logging9-29Web – Click System, Logs, System Logs. Specify System Log Status, set the level of event messages to be logged to RAM and

Página 584

Remote Log Configuration9-39• Host IP Address – Specifies a new server IP address to add to the Host IP List.Web – Click System, Logs, Remote Logs. To

Página 585

Configuring Event Logging9-49Displaying Log MessagesUse the Logs page to scroll through the logged system and event messages. The switch can store up

Página 586

Sending Simple Mail Transfer Protocol Alerts9-59• SMTP Server List – Specifies a list of up to three recipient SMTP servers. The switch attempts to co

Página 587

Configuring Event Logging9-69CLI – Enter the IP address of at least one SMTP server, set the syslog severity level to trigger an email message, and sp

Página 588 - E112006-CS-R01

10-1Chapter 10: Setting the System Clock Simple Network Time Protocol (SNTP) allows the switch to set its internal clock based on periodic updates fro

Modelos relacionados ES4548D

Comentários a estes Manuais

Sem comentários