TRENDNET TL2-E284 - Switch

TL2-E284 - Switch TRENDNET - Free user manual and instructions

Find the device manual for free TL2-E284 TRENDNET in PDF.

📄 293 pages English EN Download 💬 AI Question 10 questions ⚙️ Specs
Notice TRENDNET TL2-E284 - page 11
Pick your language and provide your email: we'll send you a specifically translated version.
Product Type Network Switch
Model TL2-E284
Brand TRENDnet
Port Count 28
Port Speeds 10/100/1000 Mbps (Gigabit Ethernet)
Uplink Ports 4 SFP Slots
Switching Capacity 56 Gbps
Forwarding Rate 41.7 Mpps
MAC Address Table 8K entries
Jumbo Frame Support 9K bytes
Management Web-based GUI, SNMP, CLI
VLAN Support 802.1Q VLAN, up to 256 groups
Quality of Service (QoS) 802.1p, 4 priority queues
Link Aggregation 802.3ad LACP, up to 8 groups
Spanning Tree Protocol 802.1D STP, 802.1w RSTP
Dimensions (W x D x H) 44.0 x 26.0 x 4.4 cm
Weight 3.5 kg
Power Supply 100-240V AC, 50/60 Hz, internal
Power Consumption ≤ 35W
Cooling Fanless
Operating Temperature 0° to 40° C
Safety Certifications CE, FCC
Warranty Limited Lifetime
Mounting Desktop or 19-inch rack mountable

Frequently Asked Questions - TL2-E284 TRENDNET

What is the default IP address for the TL2-E284?
The default IP address is typically 192.168.10.200. Refer to the manual to confirm.
Does the TL2-E284 support Power over Ethernet (PoE)?
No, the TL2-E284 is a non-PoE switch. It does not provide power to connected devices.
How do I reset the switch to factory defaults?
Press and hold the Reset button on the front panel for about 10 seconds until the LED indicators flash.
Can I use any SFP module in the SFP slots?
Yes, the switch supports standard 1000BASE-SX/LX SFP modules. Ensure compatibility with TRENDnet or third-party modules.
Is the switch rack-mountable?
Yes, the TL2-E284 comes with rack-mount brackets for installation in a standard 19-inch rack.
What is the maximum cable length for the copper ports?
The ports support 100 meters (328 feet) over Category 5e or better twisted-pair cable.
Does the switch have a fan?
No, the TL2-E284 is fanless, making it silent and suitable for quiet environments.
How many VLANs can I create?
You can create up to 256 VLAN groups using 802.1Q tagging.
What kind of warranty does TRENDnet offer?
TRENDnet provides a Limited Lifetime Warranty. For details, visit their website.
Can I manage the switch via a mobile app?
No, management is done via web interface, SNMP, or CLI. There is no dedicated mobile app.

User questions about TL2-E284 TRENDNET

0 question about this device. Answer the ones you know or ask your own.

Ask a new question about this device

The email remains private: it is only used to notify you if someone responds to your question.

No questions yet. Be the first to ask one.

Download the instructions for your Switch in PDF format for free! Find your manual TL2-E284 - TRENDNET and take your electronic device back in hand. On this page are published all the documents necessary for the use of your device. TL2-E284 by TRENDNET.

USER MANUAL TL2-E284 TRENDNET

natural_image Black RENODENET network switch device with multiple Ethernet ports and a blue indicator light (no visible text or symbols on the device body)

User's Guide

TL2-E284

1.01

Table of Contents

CHAPTER 1 PREFACE.... 1-1

ABOUT THIS GUIDE....1-1

TERMS/USAGE 1-1

CHAPTER 2 PRODUCT INTRODUCTION....2-1

PRODUCT INTRODUCTION 2-1

FRONT PANEL 2-1

REAR PANEL 2-2

CHAPTER 3 HARDWARE INSTALLATION .... 3-1

CHAPTER 4 USING THE WEB USER INTERFACE.... 4-1

CHAPTER 5 CONFIGURING SYSTEM BASIC FUNCTIONS....5-1

SYSTEM BASIC FUNCTION LIST 5-1

SYSTEM INFORMATION....5-1

USER ACCOUNT 5-2

MANAGEMENT VLAN 5-2

MANAGEMENT IP SETTINGS 5-3

IP AUTHORIZED MANAGER....5-3

SNMP 5-4

SNMP User/Group Table Configuration....5-4

SNMP Group Access Table Configuration....5-5

SNMP View Table Configuration 5-6

SNMP Community Settings....5-6

SNMP Host Table 5-7

SNMP Engine ID Configuration....5-7

SSH CONFIGURATION....5-7

SSL CONFIGURATION 5-8

SNTP and Current Time Settings 5-9

SNTP Daylight Saving Time....5-10

CONFIGURATION.... 5-11

Save Configuration....5-11

Restore Configuration....5-11

Erase Configuration 5-12

REBOOT 5-13

CHAPTER 6 CONFIGURING LAYER 2 MANAGEMENT FUNCTIONS ...... 6-1

LAYER 2 MANAGEMENT FUNCTION LIST 6-1

PORT MANAGER....6-2

Port Basic Settings....6-2

Port Monitoring 6-2

Port Control....6-3

VLAN 6-5

VLAN Basic Information....6-5

VLAN Port Settings....6-5

Static VLAN Configuration....6-6

DYNAMIC VLAN 6-6

Dynamic VLAN Global Configuration....6-6

Dynamic VLAN Port Configuration....6-7

GARP Timers Configuration....6-8

MSTP 6-6

MSTP Global Configuration....6-8

MSTP Timers Configuration....6-9

CIST Settings 6-10

MSTP Port Settings....6-11

MSTP CIST Port Status....6-11

RSTP 6-12

RSTP Global Configuration....6-12

RSTP Configuration....6-12

RSTP Port Status Configuration 6-13

RSTP Port Status....6-14

LA 6-14

LA Basic Settings....6-14

PortChannel Interface Basic Settings....6-15

LA Port Channel Settings 6-15

LA Port Settings....6-16

LA Port StateMachine Information....6-17

LA Load Balancing Policy....6-17

802.1X 6-18

802.1X Basic Settings 6-18

802.1X Port Settings....6-18

802.1X Timer Configuration 6-19

802.1X Local Authentication Server Configuration....6-20

RADIUS Server Configuration 6-21

IGMP SNOOPING 6-22

IGMP Snooping Configuration....6-22

IGMP Snooping Timer Configuration....6-22

IGMP Snooping Interface Configuration 6-23

IGMP Snooping VLAN Router Ports 6-24

MAC Based Multicast Forwarding Table 6-24

STATIC MAC ENTRIES 6-24

Static MAC Address Configuration....6-24

Static Multicast Address Configuration 6-25

Port Security Settings 6-25

CHAPTER 7 CONFIGURING ACL FUNCTIONS 7-1

ACL FUNCTION LIST 7-1

MAC ACL CONFIGURATION 7-1

IP STANDARD ACL CONFIGURATION....7-2

IP EXTENDED ACL CONFIGURATION....7-3

CLASSMAP SETTINGS 7-5

POLICYMAP SETTINGS 7-6

CHAPTER 8 CONFIGURING QOS FUNCTIONS....8-1

QoS FUNCTION LIST 8-1

RATE LIMITING....8-1

STORM CONTROL SETTINGS 8-2

802.1P QUEUE MAPPING 8-2

802.1P PORT PRIORITY 8-3

DSCP QUEUE MAPPING 8-4

EGRESS QUEUE SCHEDULING SETTINGS 8-4

CHAPTER 9 CONFIGURING RMON FUNCTIONS....9-6

RMON FUNCTION LIST 9-6

RMON BASIC SETTINGS....9-6

RMON STATISTICS CONFIGURATION 9-6

RMON HISTORY CONFIGURATION....9-7

RMON ALARMS CONFIGURATION....9-7

RMON EVENTS CONFIGURATION....9-8

CHAPTER 10 SWITCH STATISTICS....10-10

SWITCH STATISTICS LIST....10-10

INTERFACE STATISTICS 10-10

ETHERNET STATISTICS.... 10-11

VLAN STATISTICS 10-11

MSTP 10-12

MSTP Information 10-12

MSTP CIST Port Statistics....10-12

MSTP MSTI Port Statistics 10-12

RSTP 10-13

RSTP Information 10-13

RSTP Port Statistics....10-13

LA 10-13

LA Port Statistics....10-13

LA Neighbour Statistics Information 10-14

802.1X....10-15

802.1X Session Statistics....10-15

RADIUS Server Statistics....10-15

IGMP SNOOPING 10-15

IGMP Snooping Clear Statistics....10-15

IGMP Snooping V1/V2 Statistics 10-16

IP 10-16

ARP Cache....10-16

ICMP Statistics....10-16

RMON 10-17

MAC ADDRESS TABLE 10-17

SNMP 10-18

CHAPTER 11 USING THE COMMAND-LINE INTERFACE.... 11-19

ACCESSING THE SWITCH.... 11-19

PRIVILEGE LEVELS 11-20

CLI COMMAND MODES 11-20

CONVENTIONS.... 11-22

CHAPTER 12 SYSTEM INFORMATION COMMAND 12-1

SYSTEM INFORMATION COMMAND LIST 12-1

SYSTEM NAME 12-1

SYSTEM CONTACT 12-2

SYSTEM LOCATION 12-2

SYSTEM WEB-TIMEOUT 12-2

SYSTEM CLI-TIMEOUT 12-3

DEFAULT IP ADDRESS 12-3

DEFAULT IP ADDRESS ALLOCATION PROTOCOL.... 12-4

DEFAULT MODE 12-5

DEFAULT RESTORE 12-5

DEFAULT RESTORE-FILE....12-6

DEFAULT VLAN ID....12-6

SET IP HTTP 12-7

IP HTTP PORT 12-7

SHOW SYSTEM INFORMATION....12-7

SHOW NVRAM 12-8

SHOW HTTP SERVER STATUS....12-9

SHOW IP INFORMATION....12-9

SHOW LINE CONSOLE 12-10

CHAPTER 13 USER ACCOUNT COMMAND 13-1

USER ACCOUNT COMMAND LIST 13-1

USERNAME....13-1
SHOW USERS....13-1
LISTUSER 13-2

CHAPTER 14 MANAGEMENT VLAN COMMAND....14-1

MANAGEMENT VLAN COMMAND LIST 14-1
MANAGEMENT VLAN-LIST 14-1
SHOW MANAGEMENT VLAN 14-1

CHAPTER 15 IP SETTINGS COMMAND....15-1

IP SETTINGS COMMAND LIST 15-1
RELEASE DHCP VLANMGMT 15-1
RENEW DHCP VLANMGMT 15-1
IP ARP MAX-RETRIES 15-2
ARP 15-2
ARP TIMEOUT....15-3
IP ADDRESS 15-3
IP ADDRESS DHCP 15-4
DEBUG IP DHCP CLIENT 15-4
SHOW IP INTERFACE 15-5
SHOW IP ROUTE 15-5

CHAPTER 16 IP AUTHORIZED MANAGER COMMAND....16-1

IP AUTHORIZED MANAGER COMMAND LIST 16-1
AUTHORIZED-MANAGER....16-1
SHOW AUTHORIZED-MANAGERS 16-2

CHAPTER 17 SNMP COMMAND .... 17-1

SNMP COMMAND LIST 17-1
SNMP ACCESS....17-1
SNMP COMMUNITY 17-3
SNMP ENGINEID 17-3
SNMP GROUP 17-4
SNMP TRAPINFO....17-6
SNMP USER 17-6
SNMP VIEW 17-7
SNMP-SERVER ENABLE TRAPS SNMP AUTHENTICATION 17-8
SNMP-SERVER ENABLE TRAPS 17-9
SNMP-SERVER TRAP UDP-PORT 17-9
SNMP TRAP LINK-STATUS 17-10
SHOW SNMP 17-10
SHOW SNMP COMMUNITY 17-11
SHOW SNMP ENGINEID....17-12
SHOW SNMP GROUP 17-12
SHOW SNMP GROUP ACCESS 17-15
SHOW SNMP INFORM STATISTICS....17-17
SHOW SNMP TRAPINFO....17-17
SHOW SNMP USER 17-18
SHOW SNMP VIEWTREE 17-18
SHOW SNMP-SERVER TRAPS....17-19

CHAPTER 18 SSH COMMAND....18-1

SSH COMMAND LIST 18-1
SSH 18-1
IP SSH....18-1
DEBUG SSH 18-2
SHOW IP SSH 18-3

CHAPTER 19 SSL COMMAND.... 19-1

SSL COMMAND LIST....19-1

IP HTTP SECURE 19-1

DEBUG SSL 19-2

SHOW SSL SERVER-CERT 19-3

SHOW IP HTTP SECURE SERVER STATUS 19-4

CHAPTER 20 SYSTEM LOG COMMAND 20-1

SYSTEM LOG COMMAND LIST....20-1

COPY LOGS 20-1

LOGGING....20-1

MAILSERVER....20-2

CLEAR LOGS 20-3

SHOW LOGGING 20-3

SHOW EMAIL ALERTS 20-4

CHAPTER 21 SNTP COMMAND 21-1

SNTP COMMAND LIST 21-1

CLOCK SET 21-1

SET SNTP 21-1

SET SNTP DST 21-2

SNTP DST 21-2

SNTP POLL-INTERVAL 21-3

SNTP PRIMARY-IP 21-3

SNTP SECONDARY-IP 21-4

SNTP TIMEZONE 21-4

SHOW CLOCK 21-5

SHOW SNTP 21-5

CHAPTER 22 CONFIGURATION COMMAND 22-1

CONFIGURATION COMMAND LIST 22-1

WRITE 22-1

COPY STARTUP-CONFIG....22-1

COPY 22-2

ERASE 22-2

CHAPTER 23 FIRMWARE UPGRADE COMMAND....23-1

FIRMWARE UPGRADE COMMAND LIST....23-1

ARCHIVE DOWNLOAD-SW/OVERWRITE 23-1

CHAPTER 24 REBOOT COMMAND 24-1

REBOOT COMMAND LIST 24-1

RELOAD 24-1

CHAPTER 25 PORT MANAGER COMMAND 25-1

PORT MANAGER COMMAND LIST 25-1

MONITOR SESSION 25-1

NEGOTIATION....25-2

SPEED 25-2

DUPLEX 25-3

FLOWCONTROL 25-3

MDI 25-4

SHOW FLOW-CONTROL....25-4

SHOW MDI-MDIX 25-5

SHOW PORT-MONITORING....25-5

CHAPTER 26 VLAN COMMAND....26-1

VLAN COMMAND LIST 26-1

VLAN 26-1

SWITCHPORT ACCEPTABLE-FRAME-TYPE 26-1

SWITCHPORT INGRESS-FILTER 26-2
SWITCHPORT PVID 26-2
PORTS 26-3
DEBUG VLAN....26-4
SHOW VLAN 26-4
SHOW VLAN DEVICE INFO....26-7
SHOW VLAN PORT CONFIG 26-8

CHAPTER 27 DYNAMIC VLAN COMMAND....27-1

DYNAMIC VLAN COMMAND LIST 27-1
SET GVRP 27-1
SET PORT GVRP 27-1
SET GARP TIMER 27-2
VLAN RESTRICTED 27-3
SHUTDOWN GARP 27-3
DEBUG GARP 27-4
SHOW GARP TIMER....27-4

CHAPTER 28 RSTP COMMAND 28-1

RSTP COMMAND LIST 28-1
SPANNING-TREE....28-1
SPANNING-TREE COMPATIBILITY 28-1
SPANNING-TREE MODE 28-2
SPANNING-TREE PATHCOST DYNAMIC 28-3
SPANNING-TREE TRANSMIT HOLD-COUNT 28-3
SPANNING-TREE TIMERS 28-4
SPANNING-TREE AUTO-EDGE 28-4
SPANNING-TREE RESTRICTED-ROLE 28-5
SPANNING-TREE RESTRICTED-TCN 28-5
SPANNING-TREE INTERFACE ATTRIBUTES 28-6
SHUTDOWN SPANNING-TREE 28-6
CLEAR SPANNING-TREE COUNTERS 28-7
DEBUG SPANNING-TREE 28-7
SHOW SPANNING-TREE....28-9
SHOW SPANNING-TREE ACTIVE....28-12
SHOW SPANNING-TREE BRIDGE....28-14
SHOW SPANNING-TREE INTERFACE....28-16
SHOW SPANNING-TREE ROOT 28-19

CHAPTER 29 MSTP COMMAND....29-1

MSTP COMMAND LIST 29-1
SPANNING-TREE PRIORITY 29-1
SPANNING-TREE MST CONFIGURATION....29-1
SPANNING-TREE MST MAX-HOPS 29-2
SPANNING-TREE MST MAX-INSTANCE 29-2
INSTANCE....29-3
NAME 29-3
REVISION....29-4
SPANNING-TREE MST HELLO-TIME 29-4
SHOW SPANNING-TREE MST 29-5
SHOW SPANNING-TREE MST INTERFACE....29-6
SHOW SPANNING-TREE MST CONFIGURATION....29-7

LINK AGGREGATION COMMAND LIST 30-1

SET PORT-CHANNEL 30-1

LACP SYSTEM-PRIORITY 30-1

PORT-CHANNEL LOAD-BALANCE 30-2

CHANNEL-GROUP 30-3

LACP PORT-PRIORITY 30-3
LACP TIMEOUT 30-4
LACP WAIT-TIME 30-4
SHUTDOWN PORT-CHANNEL 30-5
SHOW ETHERCHANNEL 30-5
SHOW LACP 30-9
SHOW INTERFACES ETHERCHANNEL 30-10

CHAPTER 31 802.1X COMMAND .... 31-1

802.1X COMMAND LIST 31-1
DOT1X RE-AUTHENTICATE 31-1
DOT1X SYSTEM-AUTH-CONTROL 31-2
AAA AUTHENTICATION DOT1X DEFAULT 31-2
DOT1X LOCAL-DATABASE 31-2
RADIUS-SERVER HOST 31-3
DOT1X CONTROL-DIRECTION 31-4
DOT1X DEFAULT 31-5
DOT1X MAX-REQ 31-5
DOT1X MAX-START 31-6
DOT1X PORT-CONTROL 31-6
DOT1X REAUTHENITCATION 31-7
DOT1X TIMEOUT....31-7
SHUTDOWN DOT1X 31-8
DEBUG DOT1X 31-9
DEBUG RADIUS 31-9
SHOW DOT1X....31-10
SHOW RADIUS SERVER....31-12
SHOW RADIUS STATISTICS 31-12

CHAPTER 32 IGMP SNOOPING COMMAND 32-1

IGMP COMMAND LIST 32-1
IP IGMP SNOOPING 32-1
IP IGMP SNOOPING CLEAR COUNTERS....32-2
IP IGMP SNOOPING GROUP-QUERY-INTERVAL 32-2
IP IGMP SNOOPING MROUTER....32-2
IP IGMP SNOOPING MROUTER-TIME-OUT 32-3
IP IGMP SNOOPING PORT-PURGE-INTERVAL 32-3
IP IGMP SNOOPING QUERIER-QUERY-INTERVAL....32-4
IP IGMP SNOOPING REPORT-FORWARD 32-4
IP IGMP SNOOPING REPORT-SUPPRESSION-INTERVAL 32-5
IP IGMP SNOOPING RETRY-COUNT 32-5
IP IGMP SNOOPING SEND-QUERY 32-6
IP IGMP SNOOPING FAST-LEAVE 32-6
IP IGMP SNOOPING QUERIER 32-7
SHUTDOWN SNOOPING 32-7
DEBUG IP IGMP SNOOPING 32-8
SHOW IP IGMP SNOOPING 32-9
SHOW IP IGMP SNOOPING FORWARDING-DATABASE 32-9
SHOW IP IGMP SNOOPING GLOBALS 32-10
SHOW IP IGMP SNOOPING GROUPS 32-10
SHOW IP IGMP SNOOPING MROUTER.... 32-11
SHOW IP IGMP SNOOPING STATISTICS 32-12

CHAPTER 33 STATIC MAC ENTRIES COMMAND 33-1

STATIC MAC ENTRIES COMMAND LIST 33-1

MAC-ADDRESS-TABLE AGING-TIME 33-1

MAC-ADDRESS-TABLE STATIC MULTICAST 33-1

MAC-ADDRESS-TABLE STATIC UNICAST 33-3

SHOW MAC-ADDRESS-TABLE 33-4

vii

SHOW MAC-ADDRESS-TABLE AGING-TIME....33-4
SHOW MAC-ADDRESS-TABLE COUNT....33-5
SHOW MAC-ADDRESS-TABLE DYNAMIC MULTICAST....33-5
SHOW MAC-ADDRESS-TABLE DYNAMIC UNICAST 33-6
SHOW MAC-ADDRESS-TABLE STATIC MULTICAST 33-7
SHOW MAC-ADDRESS-TABLE STATIC UNICAST 33-8

CHAPTER 34 PORT SECURITY COMMAND 34-1

PORT SECURITY COMMAND LIST 34-1
MAX LEARNING ADDRESS 34-1
SHOW MAX-LEARNING-ADDRESS 34-1

CHAPTER 35 ACL COMMAND 35-1

ACL COMMAND LIST....35-1
MAC ACCESS-LIST EXTENDED....35-1
IP ACCESS-LIST 35-1
DENY (MAC ACCESS LIST CONFIGURATION) 35-2
PERMIT (MAC ACCESS LIST CONFIGURATION) 35-4
DENY (STANDARD IP ACCESS LIST CONFIGURATION) 35-5
PERMIT (STANDARD IP ACCESS LIST CONFIGURATION) 35-5
DENY (EXTENDED IP ACCESS LIST CONFIGURATION) 35-6
PERMIT (EXTENDED IP ACCESS LIST CONFIGURATION) 35-8
DENY ICMP (EXTENDED IP ACCESS LIST CONFIGURATION) 35-10
PERMIT ICMP (EXTENDED IP ACCESS LIST CONFIGURATION) 35-10
MAC ACCESS-GROUP 35-11
IP ACCESS-GROUP 35-12
SHOW ACCESS-LISTS....35-12

CHAPTER 36 CLASSMAP COMMAND 36-1

CLASSMAP COMMAND LIST 36-1
CLASS-MAP 36-1
MATCH ACCESS-GROUP 36-1
SHOW CLASS-MAP 36-2

CHAPTER 37 POLICYMAP COMMAND 37-1

POLICYMAP COMMAND LIST 37-1
POLICY-MAP 37-1
CLASS 37-1
SET 37-2
POLICE 37-2
SHOW POLICY-MAP 37-3

CHAPTER 38 RATE LIMITING COMMAND .... 38-1

RATE LIMITING COMMAND LIST....38-1
RATE-LIMIT EGRESS 38-1
RATE-LIMIT INGRESS 38-1
SHOW RATE-LIMIT 38-2

CHAPTER 39 STORM CONTROL COMMAND....39-1

STORM CONTROL COMMAND LIST 39-1
STORM-CONTROL PKT-TYPE....39-1

CHAPTER 40 QOS COMMAND....40-1

QoS COMMAND LIST 40-1
SET DSCP 40-1
VLAN MAP-PRIORITY 40-1
DSCP MAP-TYPE 40-2
COSQ SCHEDULING ALGORITHM 40-2
SWITCHPORT PRIORITY DEFAULT 40-3

viii

SHOW VLAN TRAFFIC-CLASSES 40-3
SHOW VLAN PORT CONFIG 40-4
SHOW DSCP 40-5
SHOW COSQ ALGORITHM 40-5

CHAPTER 41 RMON COMMAND....41-1

RMON COMMAND LIST 41-1
SET RMON 41-1
RMON ALARM 41-1
RMON EVENT 41-2
RMON COLLECTION HISTORY....41-3
RMON COLLECTION STATS 41-3
SHOW RMON 41-4

CHAPTER 42 STATISTICS COMMAND 42-1

STATISTICS COMMAND LIST 42-1
CLEAR INTERFACES....42-1
SHOW IP TRAFFIC 42-1

CHAPTER 43 SYSTEM OPERATION COMMAND....43-1

SYSTEM OPERATION COMMAND LIST 43-1
WATCHDOG 43-1
COPY 43-1
PING 43-2
HELP 43-3
CLEAR SCREEN....43-3
LOCK 43-4
LOGOUT 43-4
CMDBUFFS 43-4
SHOW HISTORY 43-5
DIR FLASH: 43-5
SPACE FLASH: 43-5
SPACE MEMORY: 43-6
? 43-6

CHAPTER 44 INTERFACE COMMAND 44-1

INTERFACE COMMAND LIST 44-1
INTERFACE 44-1
SHUTDOWN 44-1
MTU 44-2
SHOW INTERFACES 44-2
SHOW INTERFACE MTU 44-3
SHOW INTERFACES COUNTERS 44-4

TECHNICAL SPECIFICATIONS....44-6

Chapter 1

Preface

About This Guide

This guide provides instructions on how to install and configure the TL2-E284 24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots.

This guide is mainly divided into four parts:

  1. Hardware Installation: Step-by-step hardware installation procedure.
  2. Using Web User Interface: A startup guide to for the command line interface.
  3. Command Reference: Information about the function descriptions and configuration settings.

Terms/Usage

In this guide, the term “Switch” (first letter capitalized) refers to this Switch, and “switch” (first letter lower case) refers to other Ethernet switches. Some technologies refer to terms “switch”, “bridge” or “switching hubs” interchangeably, and both are commonly accepted for Ethernet switches.

TRENDNET TL2-E284 - Terms/Usage - 1

Alerts you to supplementary information.

TRENDNET TL2-E284 - Terms/Usage - 2

Indicates potential property damage or personal injury.

Chapter 2

Product Introduction

Product Introduction

The TL2-E284 is a Layer 2 Managed Switch with 24-10/100Mbps Ethernet ports and 4-10/100/1000Mbps Gigabit Ethernet ports shared with 2-10/100/1000Mbps Mini-GBIC slots.

Front Panel
24-Port 10/100Mbps Layer 2 Managed Switch TLR-0384 TRENDET USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB USB US US US US US US US US US US US US US US US US US US US US US US US US US US US US US US US US US US

Port/BuonAconFuncon
Console (RS-232)N/AProvide out-of-band conneccon for Switch Management
ResetPush/Hold 15 secThe switch will be restored to factory defaults
Device Status LEDColorSequenceDenion
PWR (Power)GreenSolidDevice powered On
N/AOffDevice powered O
SYS (System)GreenSolidDevice is ready
N/AOffDevice is no ready
Ethernet LED (RJ-45)ColorSequenceDenion
100M Link/ACTGreenSolid100/200Mbps (Half/Full Duplex) Connected (per port)
Blinking100/200Mbps (Half/Full Duplex) Data Transming/Receiving (per port)
OffNo conneccon to the port
10M Link/ACTAmberSolid10/20Mbps (Half/Full Duplex) Connected (per port)
Blinking10/20Mbps (Half/Full Duplex)DataTransming/Receiving (per port)
OffNo conncon to the port
Shared Gigabit Ethernet (RJ-45)/ Mini-GBIC Slot LEDColorSequenceDenion
1000M Link/ACTGreenSolid2000Mbps (Full Duplex) Connected (per port)
Blinking2000Mbps (Full Duplex) DataTransming/Receiving (per port)
OffNo conncon to the port
10/100M Link/ACTAmberSolid10/20Mbps (Half/Full Duplex) or 100/200Mbps (Half/Full Duplex) Duplex Connected (per port)
Blinking10/20Mbps (Half/Full Duplex) or 100/200Mbps (Half/Full Duplex) Data Transming/Receiving (per port)
OffNo conncon to the port

TRENDNET TL2-E284 - Product Introduction - 2

Mini-GBIC ports are shared with normal RJ-45 ports 25 and 26. When Mini-GBIC port is used, the RJ-45 port cannot be used.

Rear Panel

TRENDNET TL2-E284 - Rear Panel - 1

natural_image Front view of a black electronic device with AC input port and ports (no visible text or symbols)

Power Connector

The power port is where to connect the AC power cord.

Chapter 3

Hardware Installation

This chapter provides unpacking and installation information for TL2-E284.
UnpackingOpen the shipping carton and carefully unpack its contents. Please consult the packing list located in the User Manual to make sure all items are present and undamaged. If any item is missing or damaged, please contact your local reseller for replacement.TL2-E284Multi-Language Quick Installation GuideCD-ROM (User's Guide)Power Cord (1.8 m / 5.9 ft.)RS-232 Cable (3 m / 9.8 ft.)Rack Mounting KitRubber feetIf any item is found missing or damaged, please contact the local reseller for replacement.
Switch InstallationFor safe switch installation and operation, it is recommended that you:Visually inspect the power cord to see that it is secured fully to the AC power connector.Make sure that there is proper heat dissipation and adequate ventilation around the switch.Do not place heavy objects on the switch.
Desktop or Shelf InstallationWhen installing the switch on a desktop or shelf, the rubber feet included with the device must be attached on the bottom at each corner of the device's base. Allow enough ventilation space between the device and the objects around it.TRENDNET TL2-E284 - Hardware Installation - 1Figure 1 – Attach the adhesive rubber pads to the bottom
Rack InstallationThe switch can be mounted in an EIA standard size 19-inch rack, which can be placed in a wiring closet with other equipment. To install, attach the mounting brackets to the switch's side panels (one on each side) and secure them with the screws provided.TRENDNET TL2-E284 - Hardware Installation - 2Figure 2 – Attach the mounting brackets to the SwitchThen, use the screws provided with the equipment rack to mount the switch in the

rack.

TRENDNET TL2-E284 - Hardware Installation - 3

natural_image Line drawing of a network switch device with ports and connectors (no text or symbols)

Figure 3 - Mount the Switch in the rack or chassis

! Caution

Safety Instructions

A) Elevated Operating Ambient - If installed in a closed or multi-unit rack assembly, the operating ambient temperature of the rack environment may be greater than room ambient. Therefore, consideration should be given to installing the equipment in an environment compatible with the maximum ambient temperature (Tma) specified by the manufacturer.
B) Reduced Air Flow - Installation of the equipment in a rack should be such that the amount of air flow required for safe operation of the equipment is not compromised.
C) Mechanical Loading - Mounting of the equipment in the rack should be such that a hazardous condition is not achieved due to uneven mechanical loading.
D) Circuit Overloading - Consideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of the circuits might have on overcurrent protection and supply wiring. Appropriate consideration of equipment nameplate ratings should be used when addressing this concern.
E) Reliable Earthing - Reliable earthing of rack-mounted equipment should be maintained. Particular attention should be given to supply connections other than direct connections to the branch circuit (e.g. use of power strips).

Plugging in the AC Power Cord

Users may now connect the AC power cord into the rear of the switch and to an electrical outlet (preferably one that is grounded and surge protected).

TRENDNET TL2-E284 - Plugging in the AC Power Cord - 1

natural_image Line drawing of a network switch device with ports and an attached cable (no text or symbols)

Figure 4 – Plugging the switch into an outlet

Power Failure

As a precaution, the switch should be unplugged in case of power failure. When power is resumed, plug the switch back in.

Chapter 4

Using the Web User Interface

After a successful physical installation, you can configure the Switch, monitor the network status, and display statistics using a web browser.

Supported Web Browsers

The embedded Web-based Management currently supports the following web browsers:

A) Internet Explorer 6 or higher
B) Netscape 8 or higher
C) Mozilla
D) Firefox 1.5/2.0 or higher

Connecting to the Switch

You will need the following equipment to begin the web configuration of your device:

  1. A PC with a RJ-45 Ethernet connection
  2. A standard Ethernet cable

Connect the Ethernet cable to any of the ports on the front panel of the switch and to the Ethernet port on the PC.

TRENDNET TL2-E284 - Connecting to the Switch - 1

natural_image Line drawing of a network switch device with ports and an external laptop connected to it (no text or symbols present)

Figure 5 - Connected to an end node via Ethernet cable

Login Web-based Management

In order to login and configure the switch via an Ethernet connection, the PC must have an IP address in the same subnet as the switch. For example, if the switch has an IP address of 192.168.10.200, the PC should have an IP address of 192.168.10.x (where x is a number between 1 \~ 254), and a subnet mask of 255.255.255.0.

Open the web browser and enter 192.168.10.200 (the factory-default IP address) in the address bar. Then press .

Blank Page - Windows Internet Explorer http://192.168.10.200 File Edit View Favorites Tools Help

Figure 6 - Enter the IP address 192.168.10.200 in the web browser

When the following page appears, enter the user name and password then click Login.

TRENDnet LOGIN User Name: admin Password: •••••• Login

Figure 7 – Enter the IP address 192.168.10.200 in the web browser

TRENDNET TL2-E284 - Login Web-based Management - 3

The default user name and password are:

User Name Password Privilege

admin admin 15

guest guest123 1

After login successfully, following page will appear.

Device Status

TRENDNET LEG Out TRENDNET SNMP Switch TL2-E284 1 3 5 7 9 11 13 15 17 19 21 23 25F 26C 27 24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots The 24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots, model TL2-E284, provides a reliable foundation for a highly scalable managed network. The TL2-E284 features a 12.8Gbps switch fabric, 802.1x authentication, SNMP v3, and Multiple Spanning Tree (MSTP) support. Built-in Gigabit Ethernet ports and Mini-GBIC slots provide high speed uplinks to backbone switching or servers. Configure the switch using your choice of Telnet, HyperTerminal, SNMP, or a Browser. View statistics captured for 17 unique switching parameters. Additional management features such as Port Trunking, IGMP snooping, Static and Dynamic VLAN, Load Balancing, RMON, QoS, and RSTP allow administrators to effectively manage departmental work groups. Function Tree Main Configuration Screen

Figure 8 – Web User Interface

The three main areas are the Device Status on top, the Function Tree, and the

Main Configuration Screen.

The Device Status provides a real-time switch port link status.

By choosing different functions in the Function Tree, you can change all the settings in the Main Configuration Screen. The main configuration screen will show the current status of your Switch by clicking the model name on top of the function tree.

To terminate the web management session, click Log Out in the upper right corner.

Function Tree

Home

System

System Information

User Account

Management VLAN

IP Settings

IP Authorized Manager

SNMP

SSH

SSL

System Log

+·SNTP

Configuration

Firmware Upgrade

Reboot

Layer2 Management Port Manager Basic Settings Port Monitoring Port Control VLAN Basic Information Port Settings Static VLANs Dynamic VLAN Dynamic Vlan Global Configuration Port Settings Garp Timer MSTP Global Settings Timers Port Configuration VLAN Mapping Port Settings CIST Port Status RSTP Global Settings Basic Settings Port Settings Port Status LA Basic Settings Interface Settings Port Channel Settings Port Settings Port State Info Load Balancing 802.1X Basic Settings Port Settings Timers Local AS Radius Settings IGMP Snooping Basic Settings Timer Configuration Interface Configuration Router Ports Group Information Static MAC Entries Unicast Entries Multicast Entries Port Security Settings

TRENDNET TL2-E284 - MENU - 2

flowchart
graph TD
    A["ACL"] --> B["MAC ACL"]
    A --> C["IP Standard ACL"]
    A --> D["IP Extended ACL"]
    A --> E["Classmap"]
    A --> F["Policymap"]

    G["QoS"] --> H["Rate Limiting"]
    G --> I["Storm Global Control"]
    G --> J["802.1p"]
    G --> K["Port Priority"]
    G --> L["DSCP"]
    G --> M["Egress Algorithm"]

    N["RMON"] --> O["Global Settings"]
    N --> P["Statistics"]
    N --> Q["History"]
    N --> R["Alarms"]
    N --> S["Events"]

    T["Statistics"] --> U["Interface"]
    T --> V["Ethernet"]
    T --> W["VLAN"]

    X["MSTP"] --> Y["Information"]
    X --> Z["CIST Port Statistics"]
    X --> AA["MSTI Port Statistics"]

    AB["RSTP"] --> AC["Information"]
    AB --> AD["Port Statistics"]

    AE["LA"] --> AF["PortLACP Stats"]
    AE --> AG["Neighbour Stats"]

    AH["802.1X"] --> AI["Session Stats"]
    AH --> AJ["Radius"]

    AK["IGMP Snooping"] --> AL["Clear Statistics"]
    AK --> AM["V1/V2 Statistics"]

    AN["IP"] --> AO["ARP Cache"]
    AN --> AP["ICMP Statistics"]

    AQ["RMON"] --> AR["MAC Address Table"]
    AQ --> AS["SNMP"]

Chapter 5

Configuring System Basic

Functions

System Basic Function List

■ System Information
- User Account
- Management VLAN
- Management IP Settings
- IP Authorized Manager
SNMP
SNMP User/Group Table Configuration
SNMP Group Access Table Configuration
SNMP View Table Configuration
SNMP Community Settings
SNMP Host Table
SNMP Engine ID Configuration
- SSH Configuration
- SSL Configuration
- System Log Configuration
SNTP
SNTP and Current Time Settings
SNTP Daylight Saving Time
- Configuration
Save Configuration
Restore Configuration
Erase Configuration
- Firmware Upgrade
- Reboot

System Information

This page is to display and edit relevant system information.

System Information

Hardware Versionv1.0R
Firmware Version1.00.010
Device NameTL2-E284
Device ContactSysContact
Device LocationSysLocation
Device Up Time0 days, 4 hours, 46 mins, 22 seconds
Switch MAC Address00:02:e2:84:00:01
Web Auto Timeout (180-3600 secs)600
CLI Auto Timeout (1-18000 secs)1800

Apply

Figure 9 – System > System Information

ParameterDescription
Hardware VersionThe hardware version of this device.
Firmware VersionThe firmware version of the device.
Device NameThe name of the device. Default is TL2-E284.
Device ContactThe identification information of a contact person. Default is SysContact.
Device LocationEntering the device location description. Maximum of 50 characters is allowed and a null string is not accepted. Default is SysLocation.
Device Up TimeThe time duration since the system has been up and running.
Switch MAC AddressThe MAC address of the device.
Web Auto Timeout (180-3600 secs)The duration that the device times out when no user activity occurs on the web interface. Default is 600 seconds.
CLI Auto Timeout (1-18000 secs)The duration that the device times out when no user activity occurs on the web interface. Default is 1800 seconds.

Click Apply to submit the changes.

User Account

This page is to create and display user account information.

User Account

User Name
Password
Confirm Password
Privilege (1~15)
ADD Reset
selectUser NameNew NameOld PasswordNew PasswordConfirm PasswordPrivilege
adminadmin15
guestguest1

TRENDNET TL2-E284 - User Account - 1
Figure 10 - System > User Account

ParameterDescription
User NameUsername of an account.
PasswordPassword of an account.
Privilege (1-15)Privilege level that ranges from 1 to 15. 15 are the highest level.

Click ADD to submit the changes and the Reset button will clear the information. Select and click Delete to remove an existed account. The default accounts are admin (privilege 15) and guest (privilege 1).

Management VLAN

This page is to edit the management VLAN information.

Management VLAN
Management VLAN Add Remove Management VLAN 1

Figure 11 - System > Management VLAN

Parameter

Management VLAN

Description

The VLAN ID of management VLAN. It can be a single VLAN ID from 1 to 4094, a range of VLAN IDs separated by a hyphen (-), or a series of non-continuous numbers divided by a comma (,)

Click ADD to submit the changes and the Remove button will remove an existed VLAN ID.

TRENDNET TL2-E284 - Description - 1

There has to be at least one management VLAN ID exists.

Management IP Settings

This page is to edit the management IP settings.

Management IP Settings

IP Address ModeManual
IP Address192.168.10.200
Subnet Mask255.255.255.0
Default Gateway192.168.10.254

TRENDNET TL2-E284 - Management IP Settings - 1
Figure 12 - System > IP Settings

Parameter

IP Address Mode

IP Address

Subnet Mask

Default Gateway

Description

To configure the mode that the IP address of default interface is assigned. You can choose Manual or Dynamic. Default is Manual.

IP address of the management interface. Default is 192.168.10.200.

Subnet mask of the management interface. Default is 255.255.255.0.

IP address of default gateway. Default is 192.168.10.254.

Click Apply to submit the changes.

IP Authorized Manager

This page is to set an authorized administrator source IP address, and the services, interfaces, or VLANs that it is allowed to visit.

IP Authorized Manager
IP Address Subnet Mask Port List (Incoming) VLANs Allowed Services Allowed Add Reset Address Subnet Mask Port List (Incoming) VLANs Allowed Services Allowed

Figure 13 - System > IP Authorized Manager

ParameterDescription
IP AddressIP address of authorized manager
Subnet MaskSubnet mask of the authorized IP address
Port List (Incoming)Interface of the authorized administrator is allowed to connect to
VLANs AllowedVLAN ID of the authorized administrator is allowed to connect to. It can be a single VLAN ID from 1 to 4094, a range of VLAN IDs separated by a hyphen (-), or a series of non-continuous numbers divided by a comma (,)
Service AllowedServices that authorized administrator are allowed to access. It includes SNMP, TELNET, HTTP (Web), HTTPS (SSL), SSH services. Select ALL will cover all services.

Click ADD to submit the changes and the Reset button will clear the information. Select and click Delete to remove an existed account.

SNMP

SNMP User/Group Table Configuration

This page is to configure the SNMP user and group information.

SNMP User/Group Table Configuration
User Name Group Name SNMP Version V1 ▼ encrypted Auth-Protocol MD5 Password Priv-Protocol DES Password Add Reset

SelectUser NameGroup NameSNMP VersionAuth-ProtocolPriv-Protocol
![]('img_url')ReadOnlyReadOnlyv1NoneNone
![]('img_url')ReadOnlyReadOnlyv2cNoneNone
![]('img_url')ReadWriteReadWritev1NoneNone
![]('img_url')ReadWriteReadWritev2cNoneNone
Delete

Figure 14 - System > SNMP > User/Group Table

ParameterDescription
User NameSNMP user name
Group NameSNMP group name
SNMP VersionSpecify the SNMP version to be used, which can be v1, v2c, or v3. Select ‘encrypted’ if the encryption for user authentication is needed. Once the encryption is enabled, then you can set the authentication and privilege algorithm and passwords.
Auth-ProtocolSpecify the authentication algorithm from MD5 or SHA algorithm, and the password.
Priv-ProtocolSpecify the privilege encryption algorithm from DES or none, and the password.

Click ADD to submit the changes and the Reset button will clear the information. Select and click Delete to remove an existed entry.

SNMP Group Access Table Configuration

This page is to configure the access settings of a SNMP group.

SNMP Group Access Table Configuration
Group Name Read View Name Write View Name Notify View Name Security Model v1 Security Level NoAuthNoPriv Add Reset

SelectGroup NameRead ViewWrite ViewNotify ViewSecurity ModelSecurity Level
![]('img_url')ReadOnlyReadWrite-ReadWritev1NoAuthNoPriv
![]('img_url')ReadOnlyReadWrite-ReadWritev2cNoAuthNoPriv
![]('img_url')ReadWriteReadWriteReadWriteReadWritev1NoAuthNoPriv
![]('img_url')ReadWriteReadWriteReadWriteReadWritev2cNoAuthNoPriv
Delete

Figure 15 - System > SNMP > Group Access Table

ParameterDescription
Group NameSNMP group name
Read View NameThe name of group (view) has read privilege and is allowed to access the specified MIB object groups.
Write View NameThe name of group (view) has write privilege and is allowed to access the specified MIB object groups.
Notify View NameThe name of group (view) can receive SNMP Trap messages and is allowed to access the specified MIB object groups.
Security ModelSpecify the SNMP version to be used, which can be v1, v2c, or v3.
Security LevelSpecify if authentication and encryption are needed for SNMP messages.NoAuthNoPriv – Neither authentication or encryption is needed. It is the default setting.AuthNoPriv - Authentication is required for the SNMP messages. It is selectable only when SNMPv3 is specified.AuthPriv – Both authentication and encryption are required for the SNMP messages. It is selectable only when SNMPv3 is specified.

Click ADD to submit the changes and the Reset button will clear the information. Select and click Delete to remove an existed entry.

SNMP View Table Configuration

This page is to create a SNMP view, which limits the range of MIB objects that a SNMP administrator can access to.

SNMP View Table Configuration
View Name Subtree OID OID Mask View Type included Add Reset

SelectView NameSubtree OIDOID MaskView Type
ReadWrite11Included
Delete

Figure 16 - System > SNMP > View Table

ParameterDescription
View NameSNMP view name
Subtree OIDThe object ID of MIB tree
OID MaskThe mask of OID
View Typeincluded – Includes the object in the list that the SNMP administrator can access.excluded – Excludes the object from the list that the SNMP administrator can access.

Click ADD to submit the changes and the Reset button will clear the information. Select and click Delete to remove an existed entry.

SNMP Community Settings

This page is to create and edit SNMP community information.

SNMP Community Settings
Community Name User Name(View Policy) ReadOnly Add Reset

Select Community Name User Name(View Policy) PUBLIC ReadOnly PRIVATE ReadWrite Delete

Figure 17 - System > SNMP > Community Table

ParameterDescription
Community NameSNMP community name
User Name (View Policy)ReadOnly – The community has read-only privilege.ReadWrite - The community has read write privilege.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Click ADD to submit the changes and the Reset button will clear the information. Select and click Delete to remove an existed entry.

SNMP Host Table

This page is to create a host that can access the device by SNMP protocol.

SNMP Host Table
Add Host Table Host IP Address 0.0.0.0 * SNMP Version V1 Community Name/User Name * Add Reset

SelectHost Ip AddressSNMP VersionCommunity Name/User Name
Delete

Figure 18 - System > SNMP > Trap Manager

ParameterDescription
Host IP AddressThe IP address of a host that can access to the device by SNMP.
SNMP versionSpecify the SNMP version to be used, which can be v1, v2c, or v3.
Community Name/User NameThe name of SNMP community/user that the host belongs to.

Click ADD to submit the changes and the Reset button will clear the information. Select and click Delete to remove an existed entry.

SNMP Engine ID Configuration

This page is to configure the SNMP engine identifier of the device.

SNMP Engine ID Configuration
Engine ID 8000081c044653 * Apply Reset

Figure 19 - System > SNMP > Engine ID

ParameterDescription
Engine IDA string of between 5 and 32 octets expressed in hexadecimal. The default is 8000081c044653.

Click ADD to submit the changes and the Reset button will clear the information.

SSH Configuration

This page is to configure the SSH server function on the device.

SSH Configuration

SSH StatusEnable ▼
Versionv2 ▼
Cipher3DES-CBC ▼
AuthenticationHMAC-SHA1 ▼
Apply

Figure 20 - System > SSH

ParameterDescription
SSH StatusSelect Enable or Disable to turn on or off the SSH server function. Default is enabled.
VersionSpecify the SSH version supported.V2 – SSH v2 is supported. This is the default value.V1 & V2 – Both SSH v1 and V2 are supported.
CipherTo specify SSH Cipher algorithm.3DES-CBC - 3DES (Triple Data Encryption Standard) encryption algorithm in CBC (Cipher Blocking Chain). This is the default value.DES-CBC - DES (Data Encryption Standard) in CBC (Cipher Blocking Chain).Both – Both 3DES-CBC and DES-CBC are supported.
AuthenticationTo specify authentication encryption algorithm.HMAC-SHA1 – Hash-based Message Authentication Codes (HMAC) and SHA1 (Secure Hash Algorithm).HMAC-MD5 – Hash-based Message Authentication Codes (HMAC) and MD5 (Message-Digest algorithm 5).Both – Both HMAC-SHA1 and HMAC-MD5 are supported.

Click Apply to submit the changes.

SSL Configuration

This page is to configure the SSL server function on the device.

SSL Configuration

SSL StatusDisable
Apply
Cipher Suits
RSA-DES-SHA1
RSA-3DES-SHA1
RSA-EXP1024-DES-SHA1

Figure 21 - System > SSL

ParameterDescription
SSL StatusSelect Enable or Disable to turn on or off the SSH server function. Default is disabled. The cipher suite includes RSA-DES-SHA1, RSA-3DES-SHA1, and RSA-EXP1024-DES-SHA1 cipher algorithm.

Click Apply to submit the changes.

System Log Configuration

This page is to configure system log settings.

System Log Configuration
Syslog Status Disable ▼ Time Stamp Enable ▼ Messages Buffered Size (1~200) 50 Syslog Server IP Mail Server IP Receiver Email Address Sender Email Address Facility local0 ▼ Logging Level info ▼ Apply

Figure 22 - System > System Log

ParameterDescription
Syslog StatusThe status of syslog server function. Default is enabled.
Time StampSpecifies if time stamp is attached with syslog messages. Default is enabled.
Messages Buffered Size (1-200)The size of internal logging buffer. Default is 50.
Syslog Server IPIP address of the external syslog server
Mail Server IPSpecify the IP address of mail server to be used for sending the email alerts messages.
Receiver Email AddressThe email address of receiver that receives the alert messages.
Sender Email AddressThe email address of sender that sends out the alert messages.
FacilitySpecifies the facility that is indicated in the message. Possible values: local0, local1, local2, local3, local4, local5, local6, and local7. Default is Local0.
Logging LevelSpecifies the severity level of messages. Possible values are:Alert level: action must be taken immediately.Critical level: Critical conditions.Debug level: Debug messages.Emergency level: System is unusable.Error level: Error conditions.Informational level: Informational messages.Notification level: Normal but significant condition.Warning level: Warning conditions.Default is info.

Click Apply to submit the changes.

SNTP

SNTP and Current Time Settings

This page is to configure SNTP and time settings.

SNTP Settings

Current Time01 Jan 2009 01:02:40
SNTP StatusDisabled ▼
SNTP Poll Interval in Seconds (30~86400)30
SNTP Primary Server0.0.0.0
SNTP Secondary Server0.0.0.0
Time Zone Offset (HH:MM)GMT + ▼ 00 ▼ 00 ▼
Apply

Set Current Time

Year:Month:Day2009 ▼January ▼01 ▼
HH:MM:SS01 ▼02 ▼40 ▼
Apply

Figure 23 - System > SNTP > Time Settings

ParameterDescription
Current TimeCurrent system time.
SNTP StatusTo enable/disable the Simple Network Time Protocol (SNTP) function. Default is disabled.
SNTP Poll Interval in Seconds (30-86400)To set the time interval that SNTP synchronizes the time on SNTP server, and the range is from 30 to 86400 seconds. Default is 30.
SNTP Primary ServerTo set the primary SNTP server IP address.
SNTP Secondary ServerTo set the secondary SNTP server IP address.
Time Zone Offset (HH:MM)To specify the difference of current time zone relative to GMT.
Year:Month:DaySpecify current date
HH:MM:SSSpecify current system time.

Click Apply to submit the changes.

SNTP Daylight Saving Time

This page is to configure the daylight saving time function of system time setting.

SNTP Daylight Saving Configuration

Daylight Saving Time StatusDisabled ▼
Daylight Saving Time:
From (Month:Day:HH:MM)January ▼01 ▼00 ▼00 ▼
To (Month:Day:HH:MM)January ▼01 ▼00 ▼00 ▼
Apply

Figure 24 – System > SNTP > Daylight Saving Time

ParameterDescription
Daylight Saving Time StatusTo enable/disable the DST function. Default isdisabled.
Daylight Saving Time:From(Month:Day:HH:MM)Specify the DST period in month:day:hour:minute.

To

(Month:Day:HH:MM)

Click Apply to submit the changes.

Configuration

Save Configuration

This page is used to save the running configuration.

Save Configuration
Save option Flash Save Remote Save Startup-Config Save IP Address 0.0.0.0 File Name iss.conf Apply Reset

Configuration Save was successful

Figure 25 - System > Configuration > Save

Parameter

Save option

Description

Options to save the running configuration:

Flash Save: Save to the device's flash memory with a designated file name. Saving the configuration to flash will back up the current configuration in the device's internal memory to be restored later if necessary but will not set the configuration as active after a device reboot or power cycle.

Remote Save: Save to the remote TFTP server with a designated IP address and file name. This will back up the configuration to an external location.

Startup-Config Save: Save to the device's startup configuration.

Note: This will set the current configuration as the active configuration after a device reboot or power cycle.

IP Address

File Name

IP address of the remote TFTP server.

Specify the filename of the configuration to be saved.

Click Apply to submit the changes and the Reset button will clear the information.

Restore Configuration

This page is used to restore startup configuration from another configuration file in flash memory.

Restore Configuration

Restore Option No Restore Flash Restore File Name iss.conf Apply Reset

Figure 26 - System > Configuration > Restore

ParameterDescription
Restore OptionOptions to restore the startup configuration:No Restore: Applying this option will reset the NV-RAM to default settings.Note: This will only reset the settings in NV-RAM, not the entire device configuration. After rebooting, only the default parameters in NV-RAM will be reset to defaults. Requires a manual device reboot for changes to take effect.Please reference the default NV-RAM parameters below.Default IP Address : 192.168.10.200Default Subnet Mask: 255.255.255.0Default IP Address Config Mode: ManualDefault IP Address Allocation Protocol : DHCPDefault Interface Name: Fa0/1Default RM Interface Name: NONEConfig Restore Option: No restoreConfig Save Option: Startup saveConfig Save IP Address: 0.0.0.0Config Save Filename: iss.confConfig Restore Filename: iss.confPIM Mode: Sparse ModeIGS Forwarding Mode: MAC basedCLI Serial Console: YesSNMP EngineID: 80.00.08.1c.04.46.53SNMP Engine Boots: 1Default VLAN Identifier: 1
Flash Restore:Restore from a previously backed up configuration file in the device's flash memory to the startup-config. Note: After restoring configuration, requires a manual device reboot for changes to take effect.
File NameSpecify the file name of the configuration to be restored.

File Name

Click Apply to submit the changes and the Reset button will clear the information.

Erase Configuration

This page is used to reset the startup configuration, NV-RAM or the configuration file in flash to default value.

Erase Configuration

Erase option Erase Nvram Erase Startup-Config Erase Flash File File Name iss.conf Apply Reset

Figure 27 - System > Configuration > Erase

ParameterDescription
Erase optionSpecify the configuration to be reset:Erase Nvram: Reset the NV-RAM to default settings and reset all previously saved configuration files to default that were stored flash memory.Note: This will only reset the settings in NV-RAM, not the entire device configuration. After rebooting, only the default parameters in NV-RAM will be

reset to defaults. Requires a manual device reboot for changes to take effect. Please reference the default NV-RAM parameters below.

  • Default IP Address : 192.168.10.200
  • Default Subnet Mask: 255.255.255.0
  • Default IP Address Config Mode: Manual
  • Default IP Address Allocation Protocol : DHCP
  • Default Interface Name: Fa0/1
  • Default RM Interface Name: NONE
  • Config Restore Option: No restore
  • Config Save Option: Startup save
  • Config Save IP Address: 0.0.0.0
  • Config Save Filename: iss.conf
  • Config Restore Filename: iss.conf
  • PIM Mode: Sparse Mode
    • IGS Forwarding Mode: MAC based
    • CLI Serial Console: Yes
    • SNMP EngineID: 80.00.08.1c.04.46.53
    • SNMP Engine Boots: 1
  • Default VLAN Identifier: 1

Erase Startup-Config: Reset the all device configuration to default settings.

Note: This will reset the startup device configuration to default. Any previously saved configuration files in flash memory will NOT be deleted or erased. After a device reboot or power cycle, the default device configuration will be loaded to the device. Requires a manual device reboot for changes to take effect.

Erase Flash File: Reset the specified configuration file in the device's flash memory to default settings.

Note: This will not reset the device's active configuration.

File Name

Specify the file name of the local configuration file.

Click Apply to submit the changes and the Reset button will clear the information.

Firmware Upgrade

Firmware Upgrade
HTTP Firmware Upgrade Upgrade firmware from file : Browse... Upgrade TFTP Firmware Upgrade TFTP Server IP Address : TFTP firmware file name : Upgrade

Parameter

HTTP

Firmware Upgrade

TFTP

Firmware Upgrade

Description

Click Browse to locate the firmware file on the local hard drive and select it.

TFTP Server IP Address: Specify the IP address of the TFTP server.

TFTP firmware file name: Specify the filename of the firmware file.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Click Upgrade to upgrade the device firmware.

Reboot

This page is to reboot the system.

Reboot

Are you sure you want to proceed with the system reboot?

If yes, click the Reboot button.

Reboot

Figure 28 - System > Reboot

Click Reboot to warm start the device.

TRENDNET TL2-E284 - Reboot - 1

If the Switch reboots without write the running configurations, the last configuration wrote in NV-RAM will be loaded.

Chapter 6

Configuring Layer 2 Management

Functions

Layer 2 Management Function List

- Port Manager

Port Basic Settings

Port Monitoring

Port Control

■ VLAN

VLAN Basic Information

VLAN Port Settings

Static VLAN Configuration

- Dynamic VLAN

Dynamic VLAN Global Configuration

Dynamic VLAN Port Configuration

GARP Timers Configuration

■ MSTP

MSTP Global Configuration

MSTP Timers Configuration

CIST Settings

MSTP VLAN Mapping

MSTP Port Settings

MSTP CIST Port Status

- RS

RSTP Global Configuration

RSTP Configuration

RSTP Port Status Configuration

RSTP Port Status

• LA

LA Basic Settings

PortChannel Interface Basic Settings

LA Port Channel Settings

LA Port Settings

LA Port StateMachine Information

LA Load Balancing Policy

802.1X

802.1X Basic Settings

802.1X Port Settings

802.1X Timer Configuration

802.1X Local Authentication Server Configuration

RADIUS Server Configuration

- IGMP Snooping

IGMP Snooping Configuration

IGMP Snooping Timer Configuration

IGMP Snooping Interface Configuration

IGMP Snooping VLAN Router Ports

MAC Based Multicast Forwarding Table

- Static MAC Entries

Static MAC Address Configuration

Static Multicast Address Configuration

Port Security Settings

Port Manager

Port Basic Settings

This page is to configure basic settings of switch ports.

Port Basic Settings
1-12 | 13-24 | 25-28 |

SelectPortLink StatusAdmin StateMTU (90~1522) bytesLink Up/Down Trap
1Up ▼1522Enabled ▼
2Up ▼1522Enabled ▼
3Up ▼1522Enabled ▼
4Up ▼1522Enabled ▼
5Up ▼1522Enabled ▼
6Up ▼1522Enabled ▼
7Up ▼1522Enabled ▼
8Up ▼1522Enabled ▼
9Up ▼1522Enabled ▼
10Up ▼1522Enabled ▼
11Up ▼1522Enabled ▼
12Up ▼1522Enabled ▼

Apply

Figure 29 - Layer2 Management > Port Manager > Basic Settings

ParameterDescription
PortSpecify the switch port to be configured.
Link StateDisplay the physical connection states of the port.
Admin StateSpecify the administrative status of the port. Default is enabled.
MTU (90-1522) bytesTo setup the Maximum Transmission Unit (MTU) frame size of the interface, and the range is from 90 to 1522 bytes. Default is 1500.
Link Up/Down TrapTo enable/disable the link up/down trap information delivery. Default is enabled.

Click Apply to submit the changes.

Port Monitoring

This page is to configure the port monitoring function on the device.

Port Monitoring
TRENDNET TL2-E284 - Port Monitoring - 1
1-12 | 13-24 | 25-28 |

SelectPortReceive MonitoringTransmit Monitoring
1Disabled ▼Disabled ▼
2Disabled ▼Disabled ▼
3Disabled ▼Disabled ▼
4Disabled ▼Disabled ▼
5Disabled ▼Disabled ▼
6Disabled ▼Disabled ▼
7Disabled ▼Disabled ▼
8Disabled ▼Disabled ▼
9Disabled ▼Disabled ▼
10Disabled ▼Disabled ▼
11Disabled ▼Disabled ▼
12Disabled ▼Disabled ▼

Apply

Figure 30 - Layer2 Management > Port Manager > Port Monitoring

ParameterDescription
StatusTo enable/disable the port monitoring session on the device. Default is disabled.
Monitoring PortSpecify the source port of the mirror session.
PortSpecify the destination port of the mirror session.
Receive MonitoringMonitoring the traffic received from the source port.
Transmit MonitoringMonitoring the traffic transmitted from the source port.

Click Apply to submit the changes.

Port Control

This page is to configure the control parameters of interface.

Port Control

1-12 | 13-24 | 25-28 |

SelectPortModeDuplexSpeedFlowControl Admin StatusFlowControl Oper StatusMDI/MDIXMedia Type
1Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
2Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
3Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
4Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
5Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
6Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
7Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
8Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
9Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
10Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
11Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼
12Auto ▼Full ▼100MBPS ▼Disabled ▼Disabled ▼AUTO ▼Copper ▼

Apply

Figure 31 – Layer2 Management > Port Manager > Port Control

ParameterDescription
PortSpecify the switch port to be configured.
ModeTo enable/disable auto-negotiation function on ports. Default is Auto.
DuplexTo set the port duplex mode. Possible values are:Full: Port runs at full duplex mode.Half: Port runs at half duplex mode.
SpeedTo set the port speed. Possible values are:10MBPS: Port runs at 10Mbps.100MBPS: Port runs at 100Mbps.1GB: Port runs at 1000Mbps.Only port 25-28 can run at 1000Mbps.
FlowControl Admin StatusTo enable/disable 802.3x flow control on ports. Default is Disabled.
FlowControl Oper StatusTo display the flow control operation status.
MDI/MDIXTo set MDI or MDIX mode for ports. Possible values are:Auto: Port performs the auto MDI/MDIX function.MDI: Port fixed at MDI mode.MDIXB: Port fixed at MDIX mode.Default is Auto.

Click Apply to submit the changes.

TRENDNET TL2-E284 - 1-12 | 13-24 | 25-28 | - 1

The port speed and duplex settings can only be configured when auto-negotiation disabled.

VLAN

VLAN Basic Information

This page is to configure the basic settings of virtual local area network (VLAN) on the device.

VLAN Basic Information

VLAN Mode802.1Q VLAN
Maximum VLAN ID4094
Maximum Supported VLANs256
Number of VLANs in the System1

Apply

Figure 32 – Layer2 Management > VLAN > Basic Information

ParameterDescription
VLAN ModeChoose from 802.1Q VLAN or Asymmetric VLAN modes. Default is 802.1Q VLAN.
Maximum VLAN IDDisplay the maximum VLAN ID can be configured. Default is 4094.
Maximum Supported VLANsDisplay the maximum VLANs can be supported. Default is 256.
Number of VLANs in the SystemDisplay the current VLAN number in the system. Default is 1.

Click Apply to submit the changes.

VLAN Port Settings

This page is to configure VLAN setting on physical port interfaces.

VLAN Port Settings
1-12 | 13-24 | 25-28 |

SelectPortPVIDAcceptable Frame TypesIngress Filtering
11AllEnabled
21AllEnabled
31AllEnabled
41AllEnabled
51AllEnabled
61AllEnabled
71AllEnabled
81AllEnabled
91AllEnabled
101AllEnabled
111AllEnabled
121AllEnabled

Figure 33 - Layer2 Management > VLAN > Port Settings

ParameterDescription
PortSpecifies the switch port which is to be configured.
PVIDTo set the port VLAN ID of the port, all ingress untagged or priority tagged packet from this port will be assign to this VLAN. The range is from 1 to 4094.
Acceptable Frame TypesTo configure the acceptable frame type of a port.All: Accepts all kinds of frames.Tagged: Accepts only tagged framesUnTagged and Priority Tagged: Accepts only untagged frames and frames with priority tag.Default is All.
Ingress FilteringTo enable/disable the filter of ingress packets not with the same VLAN tag as the VLAN membership of the port. Default is Enabled.

In the left-hand Select column, check all of the ports modified and click Apply to submit the changes.

Static VLAN Configuration

This page is to set up the static VLAN configuration.

Static VLAN Configuration
VLAN ID VLAN Name Member Ports Untagged Ports Forbidden Ports Add Reset

SelectVLAN IDVLAN NameMember PortsUntagged PortsForbidden Ports
![]('img_url')11-281-28
ApplyDelete

Figure 34 – Layer2 Management > VLAN > Static VLANs

ParameterDescription
VLAN IDSpecify the VLAN ID to be created.
VLAN NameSpecify the name of VLAN.
Member PortsSpecify the ports to apply the VLAN membership.
Untagged PortsSpecify the ports to be untagged interfaces.
Forbidden PortsSpecify the ports to be forbidden interfaces.

Click Apply to submit the changes and the Reset button will clear the information. Click Delete will remove an existed VLAN.

TRENDNET TL2-E284 - Static VLAN Configuration - 2

There has to be at least one VLAN in the system.

Dynamic VLAN

Dynamic VLAN Global Configuration

This page is to set the global dynamic VLAN configuration.

Dynamic Vlan Global Configuration

Garp System Control Start Dynamic Vlan Status Disabled

Apply

Note : To Shutdown GARP, Dynamic Vlan Should Be Disabled.

Figure 35 – Layer2 Management > Dynamic VLAN > Dynamic VLAN Global Configuration

ParameterDescription
Garp System ControlChoose Start to enable GARP function, and Shutdown to disable it. It is needed for using dynamic VLAN function. Default is Start.
Dynamic VLAN StatusTo set the status of dynamic VLAN function from Enabled or Disabled. Default is Disabled.

Click Apply to submit the changes.

Dynamic VLAN Port Configuration

This page is to configure dynamic VLAN settings on switch ports.

Dynamic Vlan Port Configuration

1-12 | 13-24 | 25-28 |

SelectPortDynamic Vlan StatusRestricted VLAN Registration
1Enabled ▼Disabled ▼
2Enabled ▼Disabled ▼
3Enabled ▼Disabled ▼
4Enabled ▼Disabled ▼
5Enabled ▼Disabled ▼
6Enabled ▼Disabled ▼
7Enabled ▼Disabled ▼
8Enabled ▼Disabled ▼
9Enabled ▼Disabled ▼
10Enabled ▼Disabled ▼
11Enabled ▼Disabled ▼
12Enabled ▼Disabled ▼

Apply

Figure 36 - Layer2 Management > Dynamic VLAN > Port Settings

ParameterDescription
PortSpecify the switch port to be configured.
Dynamic VLAN StatusTo set the status of dynamic VLAN function from Enabled or Disabled.
Restricted VLAN RegistrationTo enable/disable the restricted VLAN on an interface.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Click Apply to submit the changes.

GARP Timers Configuration

This page is to set the GARP timers on an interface.

Garp Timers Configuration
1-12 | 13-24 | 25-28 |

SelectPort NoGarpJoinTime (10 ~ 2^30-14) (msecs)GarpLeaveTime (30 ~ 2^31-18) (msecs)GarpLeaveAllTime (40 ~ 2^31-8) (msecs)
120060010000
220060010000
320060010000
420060010000
520060010000
620060010000
720060010000
820060010000
920060010000
1020060010000
1120060010000
1220060010000

Apply

Note : Leave Timer must be greater than 2 times Join Timer and Leaveall Timer must be greater than Leave Timer.
Figure 37 - Layer2 Management > Dynamic VLAN > Port Settings

ParameterDescription
Port NoSpecify the switch port to be configured.
GarpJoinTime (10 ~ 2^30-14)(msecs)Specify the join time of GARP. Default is 20 milliseconds.
GarpLeaveTime (30 ~ 2^31-18)(msecs)Specify the leave time of GARP. Default is 60 milliseconds.
GarpLeaveAllTime (40 ~ 2^31-8)(msecs)Specify the leave all time of GARP. Default is 100 milliseconds.

Click Apply to submit the changes.

MSTP

MSTP Global Configuration

This page is to configure the MSTP global settings of the Switch.

Global Configuration

System ControlMSTP StatusMaximum MST InstancesBridge PriorityProtocol VersionRegion NameRegion VersionDynamic Path Cost Calculation
Shutdown ▼Disabled ▼00MSTP ▼0True ▼

Apply

Note : To enable MSTP Functionality, RSTP should be disabled.

Bridge Priority must be in increments of 4096 and can be upto 61440. Allowed values are: 0 4096 8192 12288 16384 20480 24576 28672 32768 36864 40960 45056 49152 53248 57344 61440

Figure 38 - Layer2 Management > MSTP > Global Configuration

ParameterDescription
System ControlTo activate or shutdown the MSTP function. Select Start to activate the MSTP function, Shutdown to shutdown MSTP function.
MSTP StatusTo enable or disable the MSTP. Select Enabled to enable the MSTP function, Disabled to disable the MSTP function.
Maximum MSTP InstancesSpecify the maximum number of MSTP instance allowed. The possible number is 1-64. Default is 64.
Bridge PrioritySpecify the bridge priority of spanning tree. Default is 32768.
Protocol VersionSelect the spanning tree compatibility version. The possible options are STP, RSTP and MSTP. Default is RSTP.
Region NameSpecify the region name of MST.
Region VersionSpecify the MST region revision. The possible numbers are 0~65535, default is 0.
Dynamic Path Cost CalculationSelect the path cost calculation mode of spanning tree. Select True to enable dynamic path cost according to the port speed, False to disable it. Default if False.

Click Apply to submit the changes.

TRENDNET TL2-E284 - MSTP Global Configuration - 1

  1. RSTP function must be shutdown before activate MSTP.
  2. MSTP status must be enabled before configure other MSTP details.

MSTP Timers Configuration

This page is to configure the MSTP timers of the Switch.

Timers Configuration

Maximum Hop CountMax AgeForward DelayTransmit Hold Count
0006

Apply

Figure 39 - Layer2 Management > MSTP > Timers Configuration

ParameterDescription
Maximum Hop CountSpecify the maximum hops permitted in MST. Possible value is 6-40. Default is 20.
Max AgeSpecify the maximum age in second for STP information learned from the network on any port before it is discarded. The possible value is 6-40. Defaultis 20.
Forward DelaySpecify the time period in second that a port changes the STP state from blocking to forwarding. The possible value is 4-30. Default is 15.
Transmit Hold CountSpecify the hold counter to limit maximum transmission rate of the Switch. Default is 3.
Hello TimeSpecify the time interval in second for a root bridge broadcasts the hello packets to other switches. Possible value is 1-2. Default is 2.

CIST Settings

This page is to configure the port related MSTP settings.

CIST Settings
1-12 | 13-24 | 25-28 |

SelectPortPath CostPriorityPointToPoint StatusEdge PortMSTP StatusProtocol MigrationHello TimeAutoEdge StatusRestricted RoleRestricted TCN
1200000128AutoFalseEnable2TrueFalseFalse
2200000128AutoFalseEnable2TrueFalseFalse
3200000128AutoFalseEnable2TrueFalseFalse
4200000128AutoFalseEnable2TrueFalseFalse
5200000128AutoFalseEnable2TrueFalseFalse
6200000128AutoFalseEnable2TrueFalseFalse
7200000128AutoFalseEnable2TrueFalseFalse
8200000128AutoFalseEnable2TrueFalseFalse
9200000128AutoFalseEnable2TrueFalseFalse
10200000128AutoFalseEnable2TrueFalseFalse
11200000128AutoFalseEnable2TrueFalseFalse
12200000128AutoFalseEnable2TrueFalseFalse

Apply

Figure 40 - Layer2 Management > MSTP > Port Configuration

ParameterDescription
SelectSelect a port to apply the configuration changes.
PortPort ID.
Path CostSpecify the path cost of the port. Possible value is 0-200000000. Default 200000000
PrioritySpecify the spanning tree port priority. Possible value is 0-240. Default is 128.
Point to Point StatusSpecify the link type of this port. ForceTrue means link type is point to point;ForceFalse means it is shared; Auto means the decision will made automatically. Default is auto.
Edge PortSpecify if this port is edge port or not. Select True to enable the portfast function, False to disable it. Default is false.
MSTP StatusTo enable or disable the MSTP on this port. Select Enable to enable MSTP on this port, Disable to disable it. Default is enabled.
Protocol MigrationTo control if the port will migrate among MSTP, RSTP and STP automatically if another switch runs different protocol. Select True to enable the protocol migration function, False to disable it. Default is False.
Hello TimeSpecify the hello time of this port. Possible value is 1-2. Default is 2.
AutoEdge StatusTo enable or disable the auto edge detection of this port. Select True to enable the auto edge function, False to disable it. Default true.
Restricted RoleTo enable or disable the root guard function to prevent the port becoming a root port. Select True to enable the root guard function, False to disable it. Default is false.
Restricted TCNTo enable the topology change guard function to prevent the topology change caused by this port. Select True to enable the topology change guard

function, False to disable it. Default is false.

Click Apply to submit the changes.

MSTP VLAN Mapping

This page is to configure the MST Instance and VLAN mapping.

VLAN Mapping
MSTP Instance ID Add VLAN 1 Delete VLAN Add Reset

TRENDNET TL2-E284 - MSTP VLAN Mapping - 2
Figure 41 - Layer2 Management > MSTP > VLAN Mapping

ParameterDescription
MSTP Instance IDSpecify which MST instance to be mapped.
Add VLANAdd a VLAN to the map list of this MST instance.
Delete VLANDelete a VLAN from the map list of this MST instance.

Click Add to submit the changes, Reset to clear the value.

MSTP Port Settings

This page is to configure the port related MSTP settings.

Port Settings

SelectPortMSTPInstance IDPort StatePriorityCost

Figure 42 - Layer2 Management > MSTP > Port Settings

ParameterDescription
SelectSelect a port to apply the changes.
PortPort ID.
MSTP Instance IDSpecify the MST instance IP of this port.
Port StateSpecify the current state of this port.
PrioritySpecify the spanning tree port priority. Possible value is 0-240. Default is 128.
CostSpecify the path cost of the port. Possible value is 0-200000000. Default 200000000

MSTP CIST Port Status

To display the current MSTP CIST port status.

MSTP CIST Port Status
1-12 | 13-24 | 25-28 |

PortDesignated RootRoot PriorityDesignated BridgeDesignated PortDesignated CostRegional RootRegional Root PriorityRegional Path CostTypeRolePort State
100:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLanDisabledDisabled
200:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLanDisabledDisabledLan
300:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLanLanDisabledDisabled
400:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLan LlanDisabledDisabled
500:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000PointtoPointDisabledDisabled
600:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLan LanDisabledDisabled
700:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLan LinDisabledDisabled
800:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLan .LlanDisabledDisabled
900:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLan.DisabledDisabled
1000:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLan 1lanDisabledDisabled
1100:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLan.LlanDisabledDisabled
1200:00:00:00:00:00:00:00:00000:00:00:00:00:00:00:00:0000:00000:00:00:00:00:00:00:00:0000SharedLlan .LlanDisabledDisabled

Figure 43 – Layer2 Management > MSTP > CIST Port Status

Click 1-12, 13-24, 25-28 to display the statistics for corresponding ports.

RSTP

RSTP Global Configuration

This page is to configure the RSTP global settings.

Global Configuration

System ControlStatusDynamic Path Cost Calculation
Start▼Disabled▼True▼

Apply

Note : To enable RSTP Functionality, MSTP should be disabled.
Figure 44 – Layer2 Management > RSTP > Global Settings

ParameterDescription
System ControlTo activate or shutdown the RSTP function. Select Start to activate the MSTP function, Shutdown to shutdown MSTP function.
StatusTo enable or disable the MSTP. Select Enabled to enable the MSTP function, Disabled to disable it. Default is disabled.
Dynamic Path Cost CalculationSelect the path cost calculation mode of spanning tree. Select True to enable dynamic path cost according to the port speed, False to disable it. Default if False.

Click Apply to submit the changes.

TRENDNET TL2-E284 - RSTP Global Configuration - 1

  1. MSTP function must be shutdown before activate RSTP.
  2. RSTP status must be enabled before configure other RSTP details.

RSTP Configuration

This page is to configure the timers and other details of RSTP functions.

RSTP Configuration

PriorityVersionTx Hold CountMax AgeHello TimeForward Delay
32768RSTP Compatible ▼620215

Apply

Bridge Priority must be in increments of 4096 and can be upto 61440. Allowed values are:

0 4096 8192 12288 16384 20480 24576 28672 32768 36864 40960 45056 49152 53248 57344 61440

Figure 45 – Layer2 Management > RSTP > Basic Settings

ParameterDescription
PrioritySpecify the bridge priority of spanning tree. Default is 32768.
VersionSelect the spanning tree compatibility version. The possible options are STP Compatible or RSTP Compatible. Default is RSTP Compatible.
Tx Hold CountSpecify the hold counter to limit maximum transmission rate of the Switch. Default is 6.
Max AgeSpecify the maximum age in second for STP information learned from the network on any port before it is discarded. The possible value is 6-40. Default is 20.
Help TimeSpecify the time interval in second for a root bridge broadcasts the hello packets to other switches. Possible value is 1-2. Default is 2.
Forward DelaySpecify the time period in second that a port changes the STP state from blocking to forwarding. The possible value is 4-30. Default is 15.

Click Apply to submit the changes.

RSTP Port Status Configuration

This page is to configure the port related RSTP settings

Port Status Configuration
1-12 | 13-24 | 25-28 |

SelectPortPort RolePort PriorityRSTP StatusPath CostProtocol MigrationAdminEdge PortAdmin Point To PointAuto Edge DetectionRestricted RoleRestricted TCN
1Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
2Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
3Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
4Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
5Designate128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
6Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
7Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
8Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
9Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
10Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
11Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼
12Disabled128Enable ▼200000False ▼False ▼Auto ▼True ▼False ▼False ▼

Apply

Note: Port Priority must be in increments of 16 upto 240

Figure 46 – Layer2 Management > RSTP > Port Settings

ParameterDescription
SelectSelect a port to apply the changes.
PortPort ID.
Port RoleSpecify the current role of the port.
Port PrioritySpecify the spanning tree port priority. Possible value is 0-240. Default is 128.
RSTP StatusTo enable or disable the RSTP on this port. Select Enable to enable RSTP on this port, Disable to disable it. Default is enabled.
Path CostSpecify the path cost of the port. Possible value is 0-200000000. Default 65535
Protocol MigrationTo control if the port will migrate among MSTP, RSTP and STP automatically if another switch runs different protocol. Select True to enable the protocol migration function, False to disable it. Default is False.
Admin Edge PortSpecify if this port is edge port or not. Select True to enable the portfast function, False to disable it. Default is False.
Admin Point To PointSpecify the link type of this port. ForceTrue means link type is point to point;ForceFalse means it is shared; Auto means the decision will made automatically. Default is Auto.
AutoEdge DetectionTo enable or disable the auto edge detection of this port. Select True to enable the auto edge function, False to disable it. Default True.
Restricted RoleTo enable or disable the root guard function to prevent the port becoming a root port. Select True to enable the root guard function, False to disable it. Default is False.
Restricted TCNTo enable the topology change guard function to prevent the topology change caused by this port. Select True to enable the topology change guard function, False to disable it. Default is False.

RSTP Port Status

To display the current RSTP port status.

RSTP Port Status
1-12 | 13-24 | 25-28 |

PortDesignated RootDesignated CostDesignated BridgeDesignated PortTypeRolePort State
100:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
200:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
300:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
400:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
580:00:00:02:e2:84:00:01080:00:00:02:e2:84:00:0180:05Point-to-PointDesignatedForwarding
600:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
700:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
800:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
900:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
1000:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
1100:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking
1200:00:00:00:00:00:00:00000:00:00:00:00:00:00:0000:00SharedLanDisabledBlocking

Figure 47 - Layer2 Management > RSTP > Port Status

Click 1-12, 13-24, 25-28 to display the statistics for corresponding ports.

LA

LA Basic Settings

This page is to configure the link aggregation basic settings.

Port Channel Basic Settings

System ControlStart
Port Channel StatusDisabled
System Priority32768
System ID00:07:24:00:02:03
Apply

Figure 48 - Layer2 Management > LA > Basic Settings

ParameterDescription
System ControlTo activate or shutdown link aggregation function of the Switch. Select Start to activate link aggregation function, Shutdown to shutdown it. Default is Start.
LA StatusTo enable or disable the link aggregation function of the Switch. Select Enabled to enable the LA function, Disabled to disable it. Default is Disabled.
System PriorityTo set the LACP priority of the Switch. Possible value is 0-65535. Default is 32768.
System IDSpecify the link aggregation system ID of the Switch.

Click Apply to submit the changes.

PortChannel Interface Basic Settings

This page is to configure details of a port channel.

Port Channel Interface Basic Settings

Port Channel ID
Admin StatusUp ▼
MTU (90~10000)
Add Reset
SelectPortChannel IDAdmin StateOper StateMTU (90~10000)

Figure 49 - Layer2 Management > LA > Interface Settings

ParameterDescription
Port Channel IDSpecify the ID of port channel that will apply the changes.
Admin StatusTo activate or shutdown a port channel interface. Select Up to activate i Down to shutdown it. Default is UP
MTUSpecify the Maximum Transmission Unit (MTU) frame size of the interface.

Click Add to submit the changes, Reset to clear the value.

LA Port Channel Settings

This page is to configure the details of a port channel.

Port Channel Settings
Port Channel ID Action Type Add Mode Lacp Ports MAC Selection Dynamic Force MAC Apply Reset

Port ChannelPortsNoOf Ports Per ChannelNoOf HotstandBy PortsMAC SelectionForce MAC

Figure 50 – Layer2 Management > LA > Port Channel Settings

ParameterDescription
Port Channel IDSelect a configured port channel group to submit the changes.
Action TypeTo add or delete ports from/to a port channel. Select Add to add ports, Delete to delete one.
ModeSpecify the mode of this port channel. Possible options are Lacp and Manual. Default is Lacp
PortsSpecify which port to be included in this port channel.
MAC SelectionSpecify the MAC address of the port channel. Select Dynamic to let system assign the MAC address to the port channel automatically, or select Manual to use a manual configured MAC address.
Force MACSpecify the manual configured MAC address of this port channel.

Click Apply to submit the configurations, Reset to clear the value.

LA Port Settings

This page is to configure port related link aggregation settings.

Port Channel Port Settings
1-12 | 13-24 | 25-28 |

SelectPortPort PriorityPort IdentifierModeActivityTimeoutWait Time(secs)Bundle State
11281DisableActiveLong2Down
21282DisableActiveLong2Down
31283DisableActiveLong2Down
41284DisableActiveLong2Down
51285DisableActiveLong2Down
61286DisableActiveLong2Down
71287DisableActiveLong2Down
81288DisableActiveLong2Down
91289DisableActiveLong2Down
1012810DisableActiveLong2Down
1112811DisableActiveLong2Down
1212812DisableActiveLong2Down
Apply

Figure 51 - Layer2 Management > LA > Port Settings

ParameterDescription
SelectSelect a port to submit the changes.
PortPort ID.
Port PrioritySpecify the link aggregation port priority of this port. Possible values are 0-65535. Default is 128.
Port IdentifierPort ID.
ModeSpecify the mode of this port channel. Possible options areLacp,Manualand Disable.
ActivitySpecify the LACP mode of the port. SelectActiveto activate the LACP negotiation; selectPassivethat LACP negotiation starts only when LACP packet is received. Default is Active.
TimeoutTo choose the LACP timeout period when no packet receive from peer.Longspecifies a long time out value. LACP PDU will be sent every 30 seconds and LACP timeout value is 90 seconds.Shortspecifies a short time out value. LACP PDU will be sent every 1 seconds and LACP timeout value is 3 seconds
Wait Time (secs)Specify the period that ports get aggregated after receiving LACP PDU.Possible value is 0-10 seconds. Default is 2.
Bundle StateSpecify the current LA state of this port. And the states descriptions are:Up in Bundle- This port is an active member of a port channel.Up Individual- This port is not a member of any port channel but its operation state is Up.Standby- This port is a standby member of a port channel.Down- This port operation state is down.

Click Apply to submit the changes.

Click 1-12, 13-24, 25-28 to configure LA port settings for corresponding ports.

LA Port StateMachine Information

This page is to display the LA state of each port.

Port Channel Port StateMachine Information

Port Channel Port No Aggregation State

Figure 52 - Layer2 Management > LA > Port State Info

LA Load Balancing Policy

Port Channel Load Balancing Policy

TRENDNET TL2-E284 - Port Channel Load Balancing Policy - 1
Figure 53 – Layer2 Management > LA > Load Balancing

ParameterDescription
SelectSelect a port channel to apply the configuration change.
Port ChannelPort Channel ID.
Selection PolicySelect a load balancing algorithm for the port channel. The traffic will hash between the member ports of a port channel based on the rule selected. The options are MAC Source, MAC Destination, MAC Source and Destination, IP Source, IP Destination, and IP Source and Destination. Default is MAC Source and Destination.

Click Apply to submit the changes.

802.1X

802.1X Basic Settings

This page is used to configure the 802.1X authentication global settings.

802.1x Basic Settings
System Control Start 802.1x Authentication Disable Authentication Mode Local Network Access Server ID fsNas1 Protocol Version 2 Apply

Figure 54 - Layer2 Management >802.1X> Basic Settings

ParameterDescription
System ControlTo activate or shutdown 802.1X function of the Switch. Select Start to activate the function, Shutdown to shutdown it. Default is Start.
802.1X AuthenticationTo enable or disable the 802.1X authentication of the Switch. Select Enabled to enable the function, Disabled to disable it. Default is Disabled.
Authentication ModeSelect the authentication database for 802.1X. Remote is to use the RADIUS server; Local will use the local database. Default is Local.
Network Access Server IDSpecify the remote RADIUS server authenticator ID.
Protocol VersionSpecify the protocol version of 802.1X.

Click Apply to submit the changes.

802.1X Port Settings

This page is to configure the port related setting of 802.1X.

802.1x Port Settings
1-12 | 13-24 | 25-28 |

SelectPortPort ControlAuth PortStatusAuthentication ModeConfigured Control DirectionOperational Control DirectionAuthSM StateRestart AuthenticationAuthentication Retry CountReauth
11ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
22ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
33ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
44ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
55ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
66ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
77ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
88ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
99ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
1010ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
1111ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled
1212ForceAuthorizedAuthorizedPort BasedBothBothInitializeFalse2Disabled

TRENDNET TL2-E284 - 802.1X Port Settings - 1
Figure 55 - Layer2 Management >802.1X> Port Settings

ParameterDescription
SelectSelect a port to apply the configuration changes.
PortPort ID.
Port ControlTo set the authenticator control on this port. The possible options are:ForceUnauthorized- All traffic is blocked to the port.Auto- Enable the 802.1X authentication on this port, and the port authorized or unauthorized will based on the 802.1X authentication result.ForceAuthorized- All traffic is transparent to the port.Default is ForceAuthorized.
Auth PortStatusCurrent authentication status of this port.
Authentication ModeThe authentication mode of this port. Only Port-based mode is supported currently.
Configured Control DirectionTo choose the authentication control direction on this port.In- Authentication control is only for ingress packets.Both- Authentication control is for both ingress and egress packets.Default is Both.
Operational Control DirectionThe current authentication direction on this port.
AuthSM StateThe current authentication state of this port.
Restart AuthenticationTo enable periodic re-authentication on this port.
Authentication Retry CountTo set the maximum 802.1X Extensible Authentication Protocol (EAP) retries of the client before restarting authentication process.
ReauthTo enable or disable the authentication retry function. Default is Disabled.

Click Apply to submit the changes.
Click 1-12, 13-24, 25-28 to configure 802.1X port settings for corresponding ports.

802.1X Timer Configuration

This page is to configure the 802.1X timers of the device.

802.1x Timer Configuration

1-12 | 13-24 | 25-28 |

SelectPortQuiet Period (secs)Transmit Period (secs)Re-authentication Period (secs)Supplicant Timeout (secs)Server Timeout (secs)
1603036003030
2603036003030
3603036003030
4603036003030
5603036003030
6603036003030
7603036003030
8603036003030
9603036003030
10603036003030
11603036003030
12603036003030

Apply

Figure 56 - Layer2 Management >802.1X> Timers

ParameterDescription
SelectSelect a port to apply the configuration changes.
PortPort ID.
Quiet Period (secs)The period that Switch will not do anything after a failed authentication. Possible value is 0-65535 seconds. Default is 60.
Transmit Period (secs)The period that Switch waits for a response to an EAP-request/identity frame from the client before retransmitting the request. Possible values are 1-65535 seconds. Default is 30.
Re-authentication Period (secs)The period between re-authentication attempts. Possible value is 1-65535 seconds. Default is 3600.
Supplicant Timeout (secs)The period that Switch waits for the re-transmission to the client. Possible value is 1-65535 seconds. Default is 30.
Server Timeout (secs)The period that Switch waits for the re-transmission to the RADIUS server. Possible value is 1-65535 seconds. Default is 30.

Click Apply to submit the changes.

Click 1-12, 13-24, 25-28 to configure 802.1X timer settings for corresponding ports.

802.1X Local Authentication Server Configuration

This page is to configure the 802.1X local user database.

Local Authentication Server Configuration
User Name Password Permission Allow * Auth-TimeOut Port List Add Reset

Select User Name Permission Auth-TimeOut (secs) Port List Apply Delete

Figure 57 - Layer2 Management >802.1X> Local AS

ParameterDescription
User NameSpecify the user name of the new user entry.
PasswordSpecify the password of the new user entry.
PermissionSpecify if the new user is allowed to access the network.
Auth-TimeOutSpecify the authentication timeout for the new user.
Port ListSpecify which port that the new user is allowed to access.

Click Add to add a new user entry, Reset to clear the value.

ParameterDescription
SelectSelect an existing user entry to apply new settings.
User NameThe user ID.
PermissionSpecify if the user is allowed to access the network.
Auth-TimeOutSpecify the authentication timeout for the user.
Port ListSpecify which port that the user is allowed to access.

Click Apply to submit the changes to existing user account, Delete to delete one.

RADIUS Server Configuration

This page is to configure the details of RADIUS server.

Radius Server Configuration
Server ID IP Address Shared Secret Server Type Authenticating Response Time (secs) Retry Count Add Reset

SelectServer IDIP AddressShared secretServer TypeResponse Time (secs)Retry Count
ApplyDelete

Figure 58 - Layer2 Management >802.1X> Radius Settings

ParameterDescription
Server IDSpecify the new RADIUS server ID. The possible ID is 1-10.
IP AddressSpecify the IP address of the new RADIUS server.
Shared SecretSpecify the encryption key between RADIUS server and clients.
Server TypeSpecify the server type of the RADIUS server. The options are:Authenticating – This server is only for RADIUS authentication.Accounting - This server is only for RADIUS accounting.Both - This RADIUS server support both authentication and accounting.
Response Time (secs)Specify the time period that a client waits for the response from the RADIUS server before re-sending the request. The possible number is 1-120 seconds.
Retry CountThe maximum number that a client re-sends the request when there is no response from RADIUS server. The possible number is 1-254 times.

Click Add to add a new RADIUS server, Reset to clear the value.

ParameterDescription
Select
Server IDThe RADIUS server ID.
IP AddressSpecify the IP address of the RADIUS server.
Shared SecretSpecify the encryption key between RADIUS server and clients.
Server TypeSpecify the server type of the RADIUS server. The options are:Authenticating – This server is only for RADIUS authentication.Accounting - This server is only for RADIUS accounting.Both - This RADIUS server support both authentication and accounting.
Response Time (secs)Specify the time period that a client waits for the response from the RADIUS server before re-sending the request. The possible number is 1-120 seconds.
Retry CountThe maximum number that a client re-sends the request when there is no response from RADIUS server. The possible number is 1-254 times.

Click Apply to submit the changes the setting of an existing RADIUS server, Delete to delete one.

IGMP Snooping

IGMP Snooping Configuration

This page is to configure the IGMP Snooping global settings.

IGMP Snooping Configuration
TRENDNET TL2-E284 - IGMP Snooping Configuration - 1

SelectIGMP Snooping StatusOperational StatusSnooping ModeReport ForwardingRetry Count (1~5)Query Transmit On TC
0DisabledDisabledMac BasedRouter Ports2Disabled

Apply

Figure 59 - Layer2 Management > IGMP Snooping > Basic Settings

Parameter

System Control

Description

To activate or shutdown IGMP snooping of the Switch. Select Start to activate the function, Shutdown to shutdown it. Default is Start.

Click Start to start or shutdown the IGMP Snooping globally.

Parameter

Select

IGMP Snooping Status

Operational Status

Snooping Mode

Report Forwarding

Retry Count (1\~5)

Query Transmit On TC

Description

Select a line to change the configuration.

To enable or disable IGMP Snooping globally. Default is enabled.

Specify the operational status of IGMP snooping function.

Specify the Snooping mode of IGMP snooping function.

Specify which port to forward the IGMP report. Select All Ports to forward the report to all ports, Router Ports to forward the reports to IGMP router ports only. Default is Router Ports.

To set the maximum retries for group specific queries which sent to a port received an IGMPv2 leave message. The possible number is 1-5 times. Default is 2.

Specify if the IGMP queries will still be sent when STP topology change happens. Select Enable to transmit the queries, Disabled not to transmit. Default is Disabled.

Click Apply to submit the changes.

IGMP Snooping Timer Configuration

This page is to configure the IGMP Snooping timers.

IGMP Snooping Timer Configuration

Router Port Purge Interval (60~600 Secs)125
Group-Member Port Purge Interval (130~1225 Secs)260
Report Forward Interval (1~25 Secs)5
Group Query Interval (1~5 Secs)1
Querier Query Interval (60~600 Secs)125
Apply Reset

Figure 60 - Layer2 Management > IGMP Snooping > Timer Configuration

ParameterDescription
Router Port Purge Interval (60~600 Secs)To set the time-out period that an IGMP multicast router port hasn't received IGMP router control packet, it will be deleted. Default is 125 seconds.
Group-Member Port Purge Interval (130~2335 Secs)To set the purge interval that an IGMP member port hasn't' received IGMP report packet, it will be deleted. Default is 260 seconds.
Report Forward Interval (1~25 Secs)To set the time interval that IGMPv2 report of the same group will not be forwarded to the router ports. Default is 5 seconds.
Group Query Interval (1~5 Secs)To set up the time interval to send the group specific query. Default is 125 seconds.
Querier Query Interval (60~600 Secs)To set up the time interval to send the IGMP general query. Default is 125 seconds.

Click Apply to submit the changes, Reset to clear the values.

IGMP Snooping Interface Configuration

This page is used to configure the VLAN basis IGMP snooping settings.

IGMP Snooping Interface Configuration
VLAN ID IGMP Snooping Status Fast Leave Querier Status Router Port List Add Reset

Select VLAN ID IGMP Snooping Status Current Version Fast Leave Configured Querier Status Current Querier Status Router Port List

Figure 61 - Layer2 Management > IGMP Snooping > Interface Configuration

ParameterDescription
VLAN IDSpecify which VLAN to add to the IGMP snooping interface list below.
IGMP Snooping StatusEnable or disable the IGMP Snooping on this VLAN.
Fast LeaveEnable or disable the fast leave function on this VLAN.
Querier StatusEnable or disable the IGMP querier function on this VLAN.
Router Port ListSpecify the IGMP router ports of this VLAN.

Click Add to add a new VLAN to the list, Reset to clear the value.

ParameterDescription
SelectSelect which VLAN to apply the configuration changes.
VLAN IDVLAN ID of this VLAN.
IGMP Snooping StatusEnable or disable the IGMP Snooping on this VLAN.
Current VersionSpecify the IGMP version of this VLAN.
Fast LeaveEnable or disable the fast leave function on this VLAN.
Querier StatusEnable or disable the IGMP querier function on this VLAN.
Router Port ListSpecify the IGMP router ports of this VLAN.

Click Apply to submit the changes the IGMP snooping setting of an existing VLAN, Delete to delete one VLAN from the list.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

IGMP Snooping VLAN Router Ports

This page is to display the static and dynamic learned IGMP router ports of each VLAN.

IGMP Snooping VLAN Router Ports

VLAN IDStatic Port ListDynamic Port List

Figure 62 - Layer2 Management > IGMP Snooping > Router Ports

MAC Based Multicast Forwarding Table

This page is to display the IGMP group MAC address was learned.

MAC Based Multicast Forwarding Table

IndexVLAN IDGroup MAC AddressPort List

Figure 63 - Layer2 Management > IGMP Snooping > Group Information

Static MAC Entries

Static MAC Address Configuration

This page is to create or configure static unicast MAC address in the L2 forwarding database.

Static MAC

VLAN ID MAC Address Allowed Ports Status Permanent Add Reset

SelectVLAN IDMAC AddressAllowed PortsStatus

Figure 64 – Layer2 Management > Static MAC Entries > Unicast Entries

ParameterDescription
VLAN IDSpecify the VLAN ID of the new MAC address entry.
MAC AddressSpecify the MAC address if this new entry.
Allowed PortSpecify the port allowed to forward the MAC address.
StatusSpecify the attribute of this static MAC. The options are:Permanent- The static multicast will keep alive.DeleteOnReset- The static multicast will be deleted after switch reset.DeleteOnTimeout- The static multicast will be deleted when aging time out.Default is Permanent.

Click Add to create a new static MAC, Reset to clear the value.

ParameterDescription
SelectSelect which MAC address to apply the configuration changes.
VLAN IDVLAN ID of this MAC address belongs to.
MAC AddressThe MAC address.
Allowed PortSpecify the port allowed to forward the MAC address.
StatusSpecify the attribute of this static MAC. The options are:Permanent- The static multicast will keep alive.DeleteOnReset- The static multicast will be deleted after switch reset.DeleteOnTimeout- The static multicast will be deleted when aging time out.Default is Permanent.

Click Apply to submit the changes the static MAC, Delete to delete it from the FDB.

Static Multicast Address Configuration

This page is to create/configure a static multicast MAC address in the L2 forwarding database.

Static Multicast VLAN ID MAC Address Allowed Ports Status Permanent Add Reset VLAN ID MAC Address Allowed Ports

Figure 65 - Layer2 Management > Static MAC Entries > Multicast Entries

ParameterDescription
VLAN IDSpecify the VLAN ID of the new MAC address entry.
MAC AddressSpecify the MAC address if this new entry.
Allowed PortsSpecify the port allowed to forward the MAC address.
StatusSpecify the attribute of this static MAC. The options are:Permanent- The static multicast will keep alive.DeleteOnReset- The static multicast will be deleted after switch reset.DeleteOnTimeout- The static multicast will be deleted when aging time out.Default is Permanent.

Click Add to create a new static MAC, Reset to clear the value.

ParameterDescription
SelectSelect which MAC address to apply the configuration changes.
VLAN IDVLAN ID of this MAC address belongs to.
MAC AddressThe MAC address.
Allowed PortsSpecify the port allowed to forward the MAC address.
StatusSpecify the attribute of this static MAC. The options are:Permanent- The static multicast will keep alive.DeleteOnReset- The static multicast will be deleted after switch reset.DeleteOnTimeout- The static multicast will be deleted when aging time out.Default is Permanent.

Click Apply to submit the changes the static MAC, Delete to delete it from the FDB.

Port Security Settings

This page is to configure the port security function for each port.

Port Security Settings
1-12 | 13-24 | 25-28 |

SelectPortAdmin StateMax Learning Address(0-64)
1Disable ▼0
2Disable ▼0
3Disable ▼0
4Disable ▼0
5Disable ▼0
6Disable ▼0
7Disable ▼0
8Disable ▼0
9Disable ▼0
10Disable ▼0
11Disable ▼0
12Disable ▼0

Apply

Figure 66 – Layer2 Management > Static MAC Entries > Port Security Settings

ParameterDescription
SelectSelect a port to apply the configuration changes.
PortPort ID.
Admin StateTo enable or disable the port security function. Default is disable.
Max Learning Address (0-64)Specify the maximum MAC address number of this port.

Click Apply to submit the changes.

Click 1-12, 13-24, 25-28 to configure port security function for corresponding ports.

Chapter 7

Configuring ACL Functions

ACL Function List

  • MAC ACL Configuration
  • IP Standard ACL Configuration
  • IP Extended ACL Configuration
  • Classmap Settings
  • Policymap Settings

MAC ACL Configuration

This page is to create/configure a rule to MAC Access Control List.

MAC ACL Configuration
ACL Number Source MAC Destination MAC Action VLAN ID Port List (Incoming) Protocol Add Reset 33011

SelectNumberSource MACDestination MACActionVLANIDPort List (Incoming)ProtocolProtocol Number

Figure 67 - ACL > MAC ACL

ParameterDescription
ACL NumberSpecify the ACL ID of this rule. The possible ID of MAC ACL is 1-65535.
Source MACMatching packets with a specific source MAC address.
Destination MACMatching packets with a specific destination MAC address.
ActionSpecify the action for packet matched. Select Permit to process the packets, Deny to discard them.
VLAN IDMatching packets with a specific VLAN ID.
Port List (Incoming)Specify the ports to apply this ACL rule.
ProtocolMatching packet with specific protocol (Ether type). The options are:Protocol Ether Typeaarp 0x80F3(33011).amber 0x6008(24584).dec-spanning 0x8138(33080).decnet-iv 0x6003(24579).diagnostic 0x6005(24581).dsm 0x8309(32825).etype-6000 0x6000(24576).etype-8042 0x8042(32834).lat 0x6004(24580).

lavc-sca 0x6007(24583).

mop-console 0x6002(24578).

mop-dump 0x6001(24577).

msdos 0x8041(32833).

mumps 0x6009(24585).

netbios 0x8040(32832).

vines-echo 0x0BAF(2991).

vines-ip 0x0BAD(2989).

xns-id 0x0807(2055).

others Insert a custom Ether type (0-65535) to the right column.

Click Add to create a new ACL rule, Reset to clear the value.

Parameter

Select

ACL Number

Source MAC

Destination MAC

Action

VLAN ID

Port List (Incoming)

Protocol

Description

Select an ACL rule to apply the configuration changes.

Specify the ACL ID of this rule.

Matching packets with a specific source MAC address.

Matching packets with a specific destination MAC address.

Specify the action for packet matched. Select Permit to process the packets, Deny to discard them.

Matching packets with a specific VLAN ID.

Specify the ports to apply this ACL rule.

Matching packet with specific protocol (Ether type). The options are:

Protocol Ether Type

aarp 0x80F3(33011).

amber 0x6008(24584).

dec-spanning 0x8138(33080).

decnet-iv 0x6003(24579).

diagnostic 0x6005(24581).

dsm 0x8309(32825).

etype-6000 0x6000(24576).

etype-8042 0x8042(32834).

lat 0x6004(24580).

lavc-sca 0x6007(24583).

mop-console 0x6002(24578).

mop-dump 0x6001(24577).

msdos 0x8041(32833).

mumps 0x6009(24585).

netbios 0x8040(32832).

vines-echo 0x0BAF(2991).

vines-ip 0x0BAD(2989).

xns-id 0x0807(2055).

others

Protocol Number

Specify the Ether type for the protocol.

Click Apply to submit the changes to the ACL rule, Delete to delete it.

IP Standard ACL Configuration

This page is to create/configure a rule to IP standard Access Control List.

IP Standard ACL Configuration
ACL Number Action Source IP Address Subnet Mask Destination IP Address Subnet Mask Port List (Incoming) Add Reset

Select ACL Number Action Source IP Subnet Mask Destination IP Subnet Mask Port List (Incoming)

Figure 68 - ACL > IP Standard ACL

ParameterDescription
ACL NumberSpecify the ACL ID of this rule. The possible ID of IP Standard ACL is 1-1000.
ActionSpecify the action for packet matched. Select Permit to process the packets, Deny to discard them.
Source IP AddressMatching packet with a specific source IP address.
Subnet MaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Destination IP AddressMatching packet with a specific destination IP address.
Subnet MaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Port List (Incoming)Specify the ports to apply this ACL rule.

Click Add to create a new ACL rule, Reset to clear the value.

ParameterDescription
SelectSelect an ACL rule to apply the configuration changes.
ACL NumberSpecify the ACL ID of this rule.
ActionSpecify the action for packet matched. Select Permit to process the packets, Deny to discard them.
Source IP AddressMatching packet with a specific source IP address.
Subnet MaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Destination IP AddressMatching packet with a specific destination IP address.
Subnet MaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Port List (Incoming)Specify the ports to apply this ACL rule.

Click Apply to submit the changes to the ACL rule, Delete to delete it.

IP Extended ACL Configuration

This page is to create/configure a rule to IP Extended Access Control List.

IP Extended ACL Configuration
ACL Number Action Source IP Address Subnet Mask Destination IP Address Subnet Mask Port List (Incoming) Protocol kmp Message Code Message Type DSCP TOS ACK Bit RST Bit Source Port Source Port Mask Destination Port Destination Port Mask Add Reset

SelectFilter NoActionSource IPSubnet MaskDestination IPSubnet MaskPort List (Incoming)ProtocolOtherCodeTypeDscpTOSACK BitRSI BitSource PortSource Port MaskDestination PortDestination Port Mask

Figure 69 - ACL > IP Extended ACL

ParameterDescription
ACL NumberSpecify the ACL ID of this rule. The possible ID of IP Standard ACL is 1001-65535.
ActionSpecify the action for packet matched. Select Permit to process the packets, Deny to discard them.
Source IP AddressMatching packet with a specific source IP address.
Subnet MaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Destination IP AddressMatching packet with a specific destination IP address.
Subnet MaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Port List (Incoming)Specify the ports to apply this ACL rule.
ProtocolMatching the L4 protocol type of the packet. The options are: icmp, ip, tcp, udp, ospf, pim and other.When selecting others, insert the protocol ID in the right column.
Message CodeMatching ICMP packets with specific message type. The possible code is 0-255.
Message TypeMatching ICMP packets with specific message code. The possible type is 0-255.
DscpMatching packets with specific DSCP type. The possible value is 0-63.
TOSMatching packets with specific ToS value. The possible value is 0-7
ACK BitMatching packets with a specific TCP acknowledge flag. The options are: Establish - TCP ACK packet.Not Establish - TCP ACK-not packet.Any - Any kind of TCP acknowledge packet.
RST BitMatching packets with a specific TCP reset flag. The options are:Set - TSP reset packet.Not Set - TCP reset-not packet.Any - Any kind of TCP reset packet.
Source PortMatching packets with a specific L4 source port.
Source Port MaskMatching packet with a range of source port. For example source port 23 with mask FFFE means 22~23. The mask options are: 8000, C000, E000, F000, F800, FC00, FE00, FF00, FF80, FFC0, FFE0, FFF0, FFF8, FFFC, FFFE, FFFF.
Destination PortMatching packets with a specific L4 destination port.
Destination Port MaskMatching packet with a range of destination port. For example source port 23 with mask FFFE means 22~23. The mask options are: 8000, C000, E000, F000, F800, FC00, FE00, FF00, FF80, FFC0, FFE0, FFF0, FFF8, FFFC, FFFE, FFFF.

Click Add to create a new ACL rule, Reset to clear the value.

ParameterDescription
SelectSelect an ACL rule to apply the configuration changes.
ACL NumberSpecify the ACL ID of this rule.
ActionSpecify the action for packet matched. Select Permit to process the packets, Deny to discard them.
Source IP AddressMatching packet with a specific source IP address.
Subnet MaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Destination IP AddressMatching packet with a specific destination IP address.
Subnet MaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Port List (Incoming)Specify the ports to apply this ACL rule.
ProtocolMatching the L4 protocol type of the packet. The options are: icmp, ip, tcp, udp, ospf, pim and other.When selecting others, insert the protocol ID in the right column.
Message CodeMatching ICMP packets with specific message type. The possible code is 0-255.
Message TypeMatching ICMP packets with specific message code. The possible type is 0-255.
DscpMatching packets with specific DSCP type. The possible value is 0-63.
TOSMatching packets with specific ToS value. The possible value is 0-7
ACK BitMatching packets with a specific TCP acknowledge flag. The options are: Establish - TCK ACK packet.Not Establish - TCP ACK-not packet.Any - Any kind of TCP acknowledge packet.
RST BitMatching packets with a specific TCP reset flag. The options are:Set - TSP reset packet.Not Set - TCP reset-not packet.Any - Any kind of TCP reset packet.
Source PortMatching packets with a specific L4 source port.
Source Port MaskMatching packet with a range of source port. For example source port 23 with mask FFFE means 22~23. The mask options are: 8000, C000, E000, F000, F800, FC00, FE00, FF00, FF80, FFC0, FFE0, FFF0, FFF8, FFFC, FFFE, FFFF.
Destination PortMatching packets with a specific L4 destination port.
Destination Port MaskMatching packet with a range of destination port. For example source port 23 with mask FFFE means 22~23. The mask options are: 8000, C000, E000, F000, F800, FC00, FE00, FF00, FF80, FFC0, FFE0, FFF0, FFF8, FFFC, FFFE, FFFF.

Click Apply to submit the changes to the ACL rule, Delete to delete it.

Classmap Settings

This page is to create/configure a Classmap.

QOS Classmap Settings
Classmap ID ACL ID ACL Type MAC Filter ▼ Add Reset

TRENDNET TL2-E284 - Classmap Settings - 2
Figure 70 - ACL > Classmap

ParameterDescription
Classmap IDSpecify the classmap ID. The possible value is 1-65535.
ACL IDSpecify the ACL rule ID to bind.
ACL TypeSpecify the type of the ACL rule.

Click Add to create a new classmap, Reset to clear the value.

ParameterDescription
SelectSelect a classmap to delete
Classmap IDThe classmap ID.
ACL IDThe ID of binding ACL rule.
ACL TypeThe type of binding ACL rule.

Click Delete to delete selected classmap.

Policymap Settings

This page is to create/configure a policymap.

QoS Policymap Settings
Policy Map ID Class Map ID Traffic Rate Kbps In-Profile Action - In-Profile Action Value Out-Profile Action - Out-Profile Action Value Add Reset

Select Policy Map ID Class Map ID Traffic Rate In-Profile Action type In-Profile Action value Out-Profile Action type Out-Profile Action value

Figure 71 - ACL >Pokicymap

ParameterDescription
Policy Map IDSpecify the policymap ID. The possible value is 1-65535.
Classmap IDSpecify which classmap to bind.
Traffic RateSet the traffic rate threshold in Kbps for the class map.
In-Profile ActionSpecify the action to packets do not exceed the rate threshold. The options are:
Policed-DSCP - Assign a new DSCP value to the packets.Policed-Priority - Assign a new 802.1p priority to the packets.
In-Profile Action ValueSpecify the new value of above. When rewriting DSCP tag, the possible value is 0-63; when rewriting the 802.1p priority, the possible value is 0-7.
Out-Profile ActionSpecify the action to packets exceed the rate threshold. The options are:Drop - Drop the packets.Policy DSCP - Assign a new DSCP value to the packets.
Out-Profile Action ValueSpecify the new value of DSCP tag. The possible value is 0-63.

Click Add to create a new policymap, Reset to clear the value.

ParameterDescription
Policy Map IDSpecify the policymap ID. The possible value is 1-65535.
Classmap IDSpecify which classmap to bind.
Traffic RateSet the traffic rate threshold in Kbps for the class map.
In-Profile ActionSpecify the action to packets do not exceed the rate threshold. The options are:Policed-DSCP - Assign a new DSCP value to the packets.Policed-Priority - Assign a new 802.1p priority to the packets.
In-Profile Action ValueSpecify the new value of above. When rewriting DSCP tag, the possible value is 0-63; when rewriting the 802.1p priority, the possible value is 0-7.
Out-Profile ActionSpecify the action to packets exceed the rate threshold. The options are:Drop - Drop the packets.Policy DSCP - Assign a new DSCP value to the packets.
Out-Profile Action ValueSpecify the new value of DSCP tag. The possible value is 0-63.

Click Apply to submit the changes to the policymap, Delete to delete it.

Chapter 8

Configuring QoS Functions

QoS Function List

  • Rate Limiting
    ■ Storm Control Settings
  • 802.1p Queue Mapping
    ■ 802.1p Port Priority
  • DSCP Queue Mapping
  • Egress Queue Scheduling Settings

Rate Limiting

This page is to configure the rate limiting function on each port.

Rate Limiting

1-12 | 13-24 | 25-28 |

SelectPortIngress RateLimit(0,64~1000000 Kbps)Egress RateLimit(0,64~1000000 Kbps)
100
200
300
400
500
600
700
800
900
1000
1100
1200

Note 1: It means Ingress / Egress rate limit disable if Ingress / Egress RateLimit is 0.

Note 2: The multiple of 1850 Kbits/sec will be set automatically because the resolution of Giga-port Egress RateLimit is 1850 Kbits/sec.

Note 3: In fastethernet ports, the Ingress / Egress RateLimit support to 100000 Kbps.

Apply

Figure 72 - QoS > Rate Limiting

ParameterDescription
SelectSelect a port to configure rate limiting function.
PortPort ID.
Ingress RateLimit (0,64~1000000 Kbps)Specify the traffic Kbit per second is allowed to be transmitted for an ingress port. 0 means no limit.
Egress RateLimit (0,64~1000000 Kbps)Specify the traffic Kbit per second is allowed to be transmitted for an egress port. 0 means no limit.

Click Apply to submit the changes.

Click 1-12, 13-24, 25-28 to configure rate limiting for corresponding ports.

Storm Control Settings

This page is to configure the storm control function of the device.

Storm Control Settings
Storm Control Disabled ▼ Packet Type DLF and Multicast and Broadcast ▼ Rate Limit 64 = 0 = unlimited Kbps. (N=1-16000) Apply

Figure 73 - QoS > Storm Global Settings

ParameterDescription
System ControlTo activate or shutdown storm control function of the Switch. Select Enable to activate link aggregation function, Disabled to shutdown it. Default is Start.
Packet TypeSpecify which kind of packets to be controlled. The options are:Broadcast only - Control broadcast packets only.Multicast and Broadcast - Control both multicast and broadcast packets.DLF and Multicast and Broadcast - Control Destination Lookup Failed unicast, multicast and broadcast packets.
Rate LimitSpecify the maximum packet rate is allowed per second.

802.1p Queue Mapping

This page is to configure the 802.1p priority and queue mapping.

VLAN Traffic Class Mapping

Priority 0Class-0
Priority 1Class-0
Priority 2Class-1
Priority 3Class-1
Priority 4Class-2
Priority 5Class-2
Priority 6Class-3
Priority 7Class-3

Apply

Figure 74 - QoS > 802.1p

Parameter

Priority 0\~7

Description

Specify which switch queue to map. The options are Class-0, Class-1, Class-2 and Class-3.

Click Apply to submit the changes.

802.1p Port Priority

This page is to configure the 802.1p priority for untagged packets receive from each port.

Port Priority
1-12 | 13-24 | 25-28 |

SelectPortUser Priority
![]('img_url')10✓
![]('img_url')20✓
![]('img_url')30✓
![]('img_url')40✓
![]('img_url')50✓
![]('img_url')60✓
![]('img_url')70✓
![]('img_url')80✓
![]('img_url')90✓
![]('img_url')100✓
![]('img_url')110✓
![]('img_url')120✓

Apply

Figure 75 - QoS > Port Priority

ParameterDescription
SelectSelect a port to submit the configuration changes.
PortPort ID.
User PrioritySpecify 802.1p priority of untagged packets.

Click Apply to submit the changes.

Click 1-12, 13-24, 25-28 to configure port priority for corresponding ports.

DSCP Queue Mapping

This page is to enable/configure the DSCP and queue mapping.

DSCP Class Mapping
TRENDNET TL2-E284 - DSCP Queue Mapping - 1

Apply

Type0-15 | Type16-31 | Type32-47 | Type48-63

Type00Class-0Type01Class-0Type02Class-0Type03Class-0
Type04Class-0Type05Class-0Type06Class-0Type07Class-0
Type08Class-0Type09Class-0Type10Class-0Type11Class-0
Type12Class-0Type13Class-0Type14Class-0Type15Class-0

Apply

Figure 76 - QoS > DSCP

ParameterDescription
DSCP MappingTo enable the DSCP queue mapping. When disabled, Switch will map queue with 802.1p priority.

Click Apply to submit the changes.

ParameterDescription
Type00~63Specify which switch queue to map. The options are Class-0, Class-1, Class-2 and Class-3.

Click Type0-15, 16-31, 32-47, 48-63 to configure queue mapping for corresponding DSCP levels. Click Apply to submit the changes.

Egress Queue Scheduling Settings

This page is to configure the scheduling algorithm for switch queues.

COSQ Scheduling Algorithm Settings

TRENDNET TL2-E284 - COSQ Scheduling Algorithm Settings - 1

TRENDNET TL2-E284 - COSQ Scheduling Algorithm Settings - 2
Figure 77 - QoS > Egress Algorithm

ParameterDescription
Scheduling AlgorithmSelect the algorithm of queue scheduling. The options are:Strict Priority - The traffic in highest queue always process first.Weighted RoundRobin - Using weighted round-robin algorithm to handle packets in priority queues.Default is Strict Priority.

Click Apply to submit the changes.

Chapter 9

Configuring RMON Functions

RMON Function List

  • RMON Basic Settings
    ■ RMON Statistics Configuration
  • RMON History Configuration
    ■ RMON Alarms Configuration
  • RMON Events Configuration

RMON Basic Settings

This page is to enable or disable RMON function

RMON Basic Settings

RMON Status Disabled Apply

Figure 78 - RMON > Global Settings

Parameter

RMON Status

Description

To enable or disable RMON function. Default is Disabled.

Click Apply to submit the changes.

RMON Statistics Configuration

Ethernet Statistics Configuration

Index (1~65535) * Port * Owner Add Reset

First | Prev | Next | Last |

SelectIndexPortDrop EventsOctetsPacketsBroadcast PacketsMultiast PacketsOwnerStatus

Figure 79 - RMON > Statistics

Parameter

Index (1\~65535)

Port

Owner

Description

Specify the index of the RMON statistics collection.

Specify which port to enable the RMON statistics collection.

Specify the owner of the statistics entry.

Click Add to create a new statistics entry, Reset to clear the value.

ParameterDescription
SelectSelect a RMON statistics entry to apply the
IndexThe index of the RMON statistics collection.
PortThe port of the RMON statistics collection.
Drop EventsThe number of events was dropped due to lack of resources.
OctetsThe total number of octets received from this port.
PacketsThe total number of packets received from this port.
Broadcast PacketsThe total number of broadcast packets received from this port.
Multicast PacketsThe total number of multicast packets received from this port.
OwnerSpecify the owner of the statistics.
StatusSpecify the status of this statistics entry. The options are:Valid - The statistics entry is valid.Under Creation -Invalid - The statistics entry is invalid and will be deleted.

Click Apply to submit the changes.

RMON History Configuration

This page is to configure the RMON history settings on ports.

History Control Configuration
Index (1~65535) * Port Buckets Requested (1~50) Interval (1~3600 secs) Owner Add Reset

Select | Index | Port | Buckets Requested | Buckets Granted | Interval | Owner | Status Apply

Figure 80 - RMON > History

ParameterDescription
Index (1~65535)Specify the index of the RMON history collection.
PortSpecify which port to enable the RMON history collection.
Buckets Requested (1~50)Specify the maximum number of RMON history collection.
Interval (1~3600 secs)Specify the time interval for the history collection.
OwnerSpecify the owner of the history entry.

Click Add to create a new history entry, Reset to clear the value.

ParameterDescription
SelectSelect a RMON history entry to apply the
IndexThe index of the RMON history collection.
PortThe port of the RMON history collection.
Buckets RequestedSpecify the maximum number of RMON history collection.
Buckets GrantedThe number of bucket granted for collecting the RMON history.
IntervalSpecify the time interval for the history collection.
OwnerSpecify the owner of the history entry.
StatusSpecify the status of this history entry. The options are:Valid - The history entry is valid.Under Creation -Invalid - The history entry is invalid and will be deleted.

Click Apply to submit the changes.

RMON Alarms Configuration

To set a RMON alarm to a MIB object.

RMON Alarm Configuration

Index (1~65535)*
Interval (1~2^31-1 secs)
Variable*
Sample typeAbsolute value ▼
Rising Threshold (0~2^31-1)
Falling Threshold (0~2^31-1)
Rising Event Index (1~65535)
Falling Event Index (1~65535)
Owner
Apply Reset
SelectIndexIntervalVariableSample TypeRising ThresholdFalling ThresholdRising Event IndexFalling Event IndexOwnerStatus
Apply

Figure 81 - RMON > Alarms

ParameterDescription
Index (1~65535)Specify the index of the RMON alarm.
Interval (1~2^31-1 secs)The time interval in seconds that alarm monitors the MIB variable.
VariableThe MIB OID to set alarm.
Sample typeThe type of the alarm sampling. The options are:Absolute value - To test the MIB variable directly.Delta value - To test the change between samples of a MIB variable.
Rising Threshold (0~2^31-1)The threshold value to trigger alarm when the number of sample exceeds.
Falling Threshold (0~2^31-1)The threshold value to reset alarm when the number of sample exceeds.
Rising Event Index (1~65535)The number of event to trigger when rising threshold is exceeded.
Falling Event Index (1~65535)The number of event to trigger when falling threshold is exceeded.
OwnerSpecify the owner of the alarm entry.

Click Add to create a new RMON alarm, Reset to clear the value.

ParameterDescription
SelectSelect a RMON alarm entry to apply the configuration changes.
IndexSpecify the index of the RMON alarm.
IntervalThe time interval in seconds that alarm monitors the MIB variable.
VariableThe MIB OID of this alarm entry.
Sample typeThe type of the alarm sampling. The options are:Absolute value - To test the MIB variable directly.Delta value - To test the change between samples of a MIB variable.
Rising ThresholdThe threshold value to trigger alarm when the number of sample exceeds.
Falling ThresholdThe threshold value to reset alarm when the number of sample exceeds.
Rising Event IndexThe number of event to trigger when rising threshold is exceeded.
Falling Event IndexThe number of event to trigger when falling threshold is exceeded.
OwnerSpecify the owner of the alarm entry.
StatusSpecify the status of this alarm entry. The options are:Valid - The alarm entry is valid.Under Creation -Invalid - The alarm entry is invalid and will be deleted.

Click Apply to submit the changes.

RMON Events Configuration

This page is to add an event to RMON event table.

Event Configuration
Index (1~65535) * Description Type None Community Owner Add Reset

First | Prev | Next | Last |
TRENDNET TL2-E284 - RMON Events Configuration - 2
Figure 82 - RMON > Events

ParameterDescription
Index (1~65535)Specify the index of the RMON event.
DescriptionSpecify the description of the event.
TypeSpecify the action type of the event. The options are:Log - Generating syslog when event is triggered.SNMP Trap - Generating a trap message when event is triggered.Log and Trap - Generating both log and trap message when event is triggered.
CommunitySpecify the SNMP community string used for the traps.
OwnerSpecify the owner of the event entry.

Click Add to create a new RMON event, Reset to clear the value.

ParameterDescription
IndexSpecify the index of the RMON event.
DescriptionSpecify the description of the event.
TypeSpecify the action type of the event. The options are:Log - Generating syslog when event is triggered.SNMP Trap - Generating a trap message when event is triggered.Log and Trap - Generating both log and trap message when event is triggered.
CommunitySpecify the SNMP community string used for the traps.
OwnerSpecify the owner of the alarm entry.
StatusSpecify the status of this event entry. The options are:Valid - The event entry is valid.Under Creation -Invalid - The events entry is invalid and will be deleted.

Click Apply to submit the changes.

Chapter 10

Switch Statistics

Switch Statistics List

  • Interface Statistics
  • Ethernet Statistics
    ■ VLAN Statistics
    ■ MSTP
    MSTP Information MSTP CIST Port Statistics MSTP MSTI Port Statistics
    ■ RSTP
    RSTP Information RSTP Port Statistics
    • LA
    LA Port Statistics LA Neighbour Statistics Information
    802.1X
    802.1X Session Statistics RADIUS Server Statistics
  • IGMP Snooping
    IGMP Snooping Clear Statistics IGMP Snooping V1/V2 Statistics
    IP
    ARP Cache ICMP Statistics
    ■ RMON
  • MAC Address Table
    SNMP

Interface Statistics

This page is to display the traffic statistics of each port.

Interface Statistics
1-12 | 13-24 | 25-28 |

IndexMTUSpeed (Bits Per Second)Received OctetsReceived Unicast PacketsReceived Nunicast PacketsReceived DiscardsReceived ErrorsReceived Unknown ProtocolsTransmitted OctetsTransmitted Unicast PacketsTransmitted Nunicast PacketsTransmitted DiscardsTransmitted Errors
1152210000000000000000000
2152210000000000000000000
3152210000000000000000000
4152210000000000000000000
51522100000000351286007504776900022039641583694937200
6152210000000000000000000
7152210000000000000000000
8152210000000000000000000
9152210000000000000000000
10152210000000000000000000
11152210000000000000000000
12152210000000000000000000

Figure 83 – Statistics > Interface

Click 1-12, 13-24, 25-28 to display the Ethernet related statistics of corresponding ports.

Ethernet Statistics

This page is to display the Ethernet related statistics of each port.

Ethernet Statistics
1-12 | 13-24 | 25-28 |

IndexAlignment ErrorsFCS ErrorsSingle Collision FramesMultiple Collision FramesSQE Test ErrorsDeferred TransmissionsLate CollisionsExcess CollisionsTransmitted Internal MAC ErrorsCarrier Sense ErrorsFrame Too LongReceived Internal MAC ErrorsEther ChipSetSymbol ErrorsDuplex Status
100001096427445000000010Half-Duplex
200001096427445000000010Half-Duplex
300001096427445000000010Half-Duplex
400001096427445000000010Half-Duplex
500001096427445000000010Full-Duplex
600001096427445000000010Half-Duplex
700001096427445000000010Half-Duplex
800001096427445000000010Half-Duplex
900001096427445000000010Half-Duplex
1000001096427445000000010Half-Duplex
1100001096427445000000010Half-Duplex
1200001096427445000000010Half-Duplex

Figure 84 – Statistics > Ethernet

Click 1-12, 13-24, 25-28 to display the Ethernet related statistics of corresponding ports.

VLAN Statistics

This page is to display current VLAN and its member port information of the Switch.

VLAN Current Database

VLAN IDVLAN FDB IDMember PortsUntagged PortsStatus
111-281-28Permanent

Figure 85 – Statistics > VLAN

MSTP

MSTP Information

This page is to display current MSTP settings and states of the Switch.

MSTP Information

Context IdBridge AddressCIST RootRegional RootCIST Root CostRegional Root CostRoot PortHold TimeMax AgeForward DelayConfig DigestCIST Time Since Topology ChangeTopology Changes
000:00:00:00:00:0000:00:00:00:00:00:00:0000:00:00:00:00:00:00:000001201500

Figure 86 - Statistics > MSTP > MSTP Information

MSTP CIST Port Statistics

This page is to display the MSTP traffic statistics of ports.

TRENDNET TL2-E284 - MSTP CIST Port Statistics - 1
MSTP CIST Port Statistics

1-12 | 13-24 | 25-28 |

PortReceived MST BPDUsReceived RST BPDUsReceived Config BPDUsReceived TCN BPDUsTransmitted MST BPDUsTransmitted RST BPDUsTransmitted Config BPDUsTransmitted TCN BPDUsReceived Invalid MST BPDUsReceived Invalid RST BPDUsReceived Invalid Config BPDUsReceived Invalid TCN BPDUsProtocol Migration Count

Figure 87 – Statistics > MSTP > CIST Port Statistics

ParameterDescription
Clear CountersUpdate – To display the latest statistics information.Clear – To reset all MSTP traffic counters.

Click Apply to update or clear the statistics of the Swtich.

Click 1-12, 13-24, 25-28 to display the MSTP traffic statistics of corresponding ports.

MSTP MSTI Port Statistics

This page is to display the MSTP traffic statistics of different instances in each port.

MSTP MSTI Port Statistics

InstancePortDesignated RootDesignated BridgeDesignated PortStateForward TransitionsReceived BPDUsTransmitted BPDUsInvalid Received BPDUsDesignated CostRole

Figure 88 – Statistics > MSTP > MSTI Port Statistics

RSTP

RSTP Information

This page is to display current RSTP setting and states of the Switch.

RSTP Information

Context IdProtocol SpecificationTime Since Topology ChangeDesignated RootRoot Brg PriorityRoot CostRoot PortMax AgeHello TimeHold TimeForward Delay
03300.00.00.00.00.00.00.00000202115

Figure 89 – Statistics > RSTP > RSTP Information

RSTP Port Statistics

This page is to display the RSTP traffic statistics of ports.

RSTP Port Statistics
1-12 | 13-24 | 25-28 |

Clear Counters
Apply
PortReceived RST BPDUsReceived Configuration BPDUsReceived TCNTransmitted RST BPDUsTransmitted Configuration BPDUsTransmitted TCNReceived Invalid RST BPDUsReceived Invalid Configuration BPDUsReceived Invalid TCN BPDUsProtocol Migration CountEffective Port StateEdgePort Oper StatusLink Type
10000000000Disable--

Figure 90 – Statistics > RSTP > Port Statistics

Parameter

Clear Counters

Description

Update – To display the latest statistics information.

Clear – To reset all RSTP traffic counters.

Click Apply to update or clear the statistics of the Switch.

Click 1-12, 13-24, 25-28 to display the Link Aggregation neighbours information of corresponding ports.

LA

LA Port Statistics

This page is to display the traffic statistics of Link Aggregation ports.

Port Channel Port Statistics

1-12 | 13-24 | 25-28 |

PortReceived PDUsReceived Unknown PDUsReceived Illegal PDUsTransmitted PDUs
10000
20000
30000
40000
50000
60000
70000
80000
90000
100000
110000
120000

Figure 91 – Statistics > LA > Port LACP Stats

Click 1-12, 13-24, 25-28 to display the Link Aggregation neighbours information of corresponding ports.

LA Neighbour Statistics Information

This page is to display the information of Link Aggregation neibubours.

Port Channel Neighbour Statistics Information

1-12 | 13-24 | 25-28 |

PortPartner SystemIDOper KeyPartner Port Priority
100:00:00:00:00:0000
200:00:00:00:00:0000
300:00:00:00:00:0000
400:00:00:00:00:0000
500:00:00:00:00:0000
600:00:00:00:00:0000
700:00:00:00:00:0000
800:00:00:00:00:0000
900:00:00:00:00:0000
1000:00:00:00:00:0000
1100:00:00:00:00:0000
1200:00:00:00:00:0000

Figure 92 – Statistics > LA > Neighbour Stats

Click 1-12, 13-24, 25-28 to display the Link Aggregation neighbours information of corresponding ports.

802.1X

802.1X Session Statistics

This page is to display the statistics and status of current authenticated users.

802.1x Session Statistics
1-12 | 13-24 | 25-28 |

PortSession IDReceived FramesTransmitted FramesSession Time (secs)Session Terminate CauseUser Name
11-0001980400Admin DisabledNo User
22-0001980400Admin DisabledNo User
33-0001980400Admin DisabledNo User
44-0001980400Admin DisabledNo User
55-0767971094861980400Admin DisabledNo User
66-0001980400Admin DisabledNo User
77-0001980400Admin DisabledNo User
88-0001980400Admin DisabledNo User
99-0001980400Admin DisabledNo User
1010-0001980400Admin DisabledNo User
1111-0001980400Admin DisabledNo User
1212-0001980400Admin DisabledNo User

Figure 93 – Statistics > 802.1X > Session Stats

Click 1-12, 13-24, 25-28 to display the statistics for corresponding ports.

RADIUS Server Statistics

This page is to display the traffic statistics to RADIUS server.

Radius Server Statistics

IndexRadius Server AddressUDP Port NumberRound Trip TimeNo of Request PacketsNo of Retransmitted PacketsNo of Access-Accept PacketsNo of Access-Reject PacketsNo of Access-Challenge PacketsNo of Malformed Access ResponsesNo of Bad AuthenticatorsNo of Pending RequestsNo of Time OutsNo of Unknown Types

Figure 94 - Statistics >802.1X> Radius

IGMP Snooping

IGMP Snooping Clear Statistics

This page is to reset the IGMP Snooping traffic counters.

IGMP Snooping Clear Statistics

Clear Vlan CountersAll Vlan ID
Vlan ID1 ▼

Figure 95 – Statistics > IGMP Snooping > Clear Statistics

ParameterDescription
Clear Vlan CountersAll – Reset all IGMP Snooping traffic counters.VLAN ID – Reset the IGMP Snooping traffic counter of a VLAN.
Vlan IDChoose a VLAN to reset the IGMP Snooping Counters.

Click Apply to clear the counters.

IGMP Snooping V1/V2 Statistics

This page is to display the IGMP traffic statistics snooped by the Switch.

IGMP Snooping V1/V2 Statistics

VLAN IDGeneral Queries ReceivedGroup Queries ReceivedIGMP Reports ReceivedIGMP Leaves ReceivedIGMP Packets DroppedGeneral Queries TransmittedGroup Queries TransmittedIGMP Reports TransmittedIGMP Leaves Transmitted

Figure 96 – Statistics > IGMP Snooping > V1/V2 Statistics

IP

ARP Cache

This page is to display the ARP information of direct connected hosts learned by the Switch.

ARP Cache

InterfaceMAC AddressIP AddressMedia Type
vlanMgmt00:14:d1:e1:6d:a6192.168.10.1Dynamic
vlanMgmt00:1d:92:b3:29:b2192.168.10.102Dynamic

Figure 97 – Statistics > IP > ARP Cache

ICMP Statistics

This page is to display the ICMP traffic statistics of the Switch.

ICMP Statistics

Received Message2
Received Error0
Receive Destination Unreachable0
Received Redirect0
Received Echo Requests2
Received Echo Replies0
Receive Source Quenches0
Transmitted Message118
Transmitted Error0
Transmitted Destination Unreachable116
Transmitted Redirect0
Transmitted Echo Requests0
Transmitted Echo Replies2
Transmitted Source Quenches0

Figure 98 – Statistics > IP > ICMP Statistics

RMON

This page is to display the RMON Statistics of the Switch.

RMON Ethernet Statistics
First | Prev | Next | Last |

IndexPortDrop EventsPacketsBroadcast PacketsMulticast PacketsCRC ErrorsUnder Size PacketsOver Size PacketsFragmentsJabbersCollisions64 Octets65-127 Octets128-255 Octets256-511 Octets512-1023 Octets1024-1510 Octets

Figure 99 - Statistics > RMON

Click First, Prev, Next, Last to see the first, previous, next or last page of the RMON Statistics.

MAC Address Table

This page is to show the MAC addresses learned in L2 forwarding database.

VLAN FDB Entries
VLAN ID MAC Address Port All Show Reset

First | Prev | Next | Last |

VLAN IDMAC AddressPortStatus
100:02:e2:84:00:015Learned
100:14:d1:e1:6d:a65Learned
100:1d:92:b3:29:b224Learned
100:1e:68:5d:8f:af5Learned

Page:1/1

Figure 100 - Statistics > MAC Address Table

ParameterDescription
VLAN IDDisplay the MAC addresses under a given VLAN.
MAC AddressDisplay a specific MAC address in FDB.
PortDisplay the MAC addresses learned under a given port.
AllDisplay all MAC addresses in FDB.

Click Show to display the MAC addresses in FDB with given parameter and click Reset to reset the parameter input.

Click First, Prev, Next, Last to see the first, previous, next or last page of the MAC addresses list discovered.

SNMP

This page is to show the SNMP traffic statistics of the Switch.

SNMP Statistics

SNMP Packets Input0
BAD SNMP Version Errors0
SNMP Unknown Community Name0
SNMP Get Request PDU's0
SNMP Get Next PDU's0
SNMP Set Request PDU's0
SNMP Packet Output0
SNMP Too Big Errors0
SNMP No Such Name Errors125
SNMP Bad Value Errors0
SNMP General Errors0
SNMP Trap PDU's0
SNMP Manager-Role Output Packets0
SNMP Inform Responses ReceivedNo_Sui
SNMP Inform Request GeneratedNo_Sui
SNMP Inform Messages DroppedNo_Sui
SNMP Inform Requests awaiting AcknowledgementNo_Sui

Figure 101 - Statistics > SNMP

Chapter 11

Using the Command-Line Interface

Accessing the Switch

This system may be managed out-of-band through the console port on the front panel or in-band using Telnet. The user may also choose the web-based management, accessible through a web browser. (See Web UI Reference Guide for details). Each Switch must be assigned its own IP Address, which is used for communication with an SNMP network manager or other TCP/IP application (for example BOOTP, TFTP). The Switch's default IP address is 192.168.10.1. The user can change the default Switch IP address to meet the specification of your networking address scheme

Connecting the Console Port

The Switch provides an RS-232 serial port that enables a connection to a computer or terminal for monitoring and configuring the Switch. This port is a male DB-9 connector, implemented as data communication terminal equipment (DCE) connection.

TRENDNET TL2-E284 - Connecting the Console Port - 1

natural_image Illustration of a network switch device with multiple ports and a laptop on the side (no text or symbols visible)

Figure 102 -Connected to an end node via console cable

To connect a terminal to the console port

  1. Connect the female connector of the RS-232 cable directly to the console port on the Switch, and tighten the captive retaining screws.
  2. Connect the other end of the cable to a terminal or to the serial connector of a computer running terminal emulation software. Set the terminal emulation software as follows:
  3. Select the appropriate serial port (COM port 1 or COM port 2).
  4. Set the data rate to 115200.
  5. Set the data format to 8 data bits, 1 stop bit, and no parity.
  6. Set flow control to none.
  7. Under Properties, select VT100 for Emulation mode.
  8. Select Terminal keys for Function, Arrow, and Ctrl keys. Ensure that you select Terminal keys (not Windows keys).
  9. After you have correctly set up the terminal, plug the power cable into the power receptacle on the back of the Switch. The boot sequence appears in the terminal.
  10. After the boot sequence completes, the console login screen displays.
  11. If you have not logged into the command line interface (CLI) program, press the Enter key at the User name and password prompts. There is no default user name and password for the Switch. The administrator must firstly create user names and passwords. If you have previously set up user accounts, log in and continue to configure the Switch.
  12. Enter the commands to complete your desired tasks. Many commands require administrator-level access privileges.
  13. When you have completed your tasks, exit the session with the logout

command or close the emulator program.

Telnet Management

Users may also access the switch console through Telnet using your PC's Command Prompt. To access it from your computer, users must first ensure that a valid connection is made through the Ethernet port of the Switch and your PC, and then click Start > Programs > Accessories > Command Prompt on your computer. Once the console window opens, enter the command telnet 192.168.10.1 (depending on configured IP address) and press Enter on your keyboard. You should be directed to the opening console screen for the Command Line Interface of the switch, press the Enter key at the User name and password prompts.

There are two user names and passwords by default.

User Name Password

User EXEC Mode guest guest123

Privileged EXEC Mode admin admin

TRENDNET TL2-E284 - User Name Password - 1

natural_image Line drawing of a network switch device with ports and an attached laptop (no text or symbols)

Figure 103 -Connected to an end node via Ethernet cable

Privilege Levels

TL2-E284 support 15 user privilege levels for commands, the default setting as below.

Privilege Levels12~1415
DescriptionUser EXEC ModeNot DefinedPrivileged EXEC Mode

You may use enable command to entering different privilege level, or use disable command back to last privilege.

CLI Command Modes

To execute commands correctly, you have to enter corresponding command mode. Each command mode has its own system prompt. See following chart to understand the relationship between the command modes and the commands to enter/exit the command modes.

TRENDNET TL2-E284 - CLI Command Modes - 1

flowchart
graph TD
    A["User EXEC Mode switch>"] -->|enable| B["Privileged EXEC Mode switch#"]
    B -->|configure terminal| C["Global Configuration Mode switch(config)#"]
    C -->|exit| B
    C -->|interface| D["Interface Configuration Mode switch(config-if)#"]
    C -->|exit| E["vlan"]
    C -->|exit| F["Config-vlan Mode switch(config-vlan)#"]
    C -->|exit| G["spanning-tree mst configuration"]
    G --> H["MSTP Configuration Mode switch(config-mst)#"]
    C -->|exit| I["mac access-list extended"]
    I --> J["MAC Access List Configuration Mode switch(config-ext-macl)#"]
    C -->|exit| K["ip access-list standard"]
    K --> L["Standard IP Access List Configuration Mode switch(config-std-nacl)#"]
    C -->|exit| M["ip access-list extended"]
    M --> N["Extended IP Access List Configuration Mode switch(config-EXT-nacl)#"]
    C -->|exit| O["class-map"]
    O --> P["Class-map Configuration Mode switch(config-cmap)#"]
    C -->|exit| Q["exit"]
    Q --> R["Policy-map"]
    R --> S["Policy-map Configuration Mode switch(config-pmap)#"]
    C -->|exit| T["class"]
    T --> U["Policy-map Class Configuration Mode switch(config-pmap-c)#"]
    style A fill:#f9f,stroke:#333
    style B fill:#f9f,stroke:#333
    style C fill:#ccf,stroke:#333
    style D fill:#ccf,stroke:#333
    style E fill:#ccf,stroke:#333
    style F fill:#ccf,stroke:#333
    style G fill:#ccf,stroke:#333
    style H fill:#ccf,stroke:#333
    style I fill:#ccf,stroke:#333
    style J fill:#ccf,stroke:#333
    style K fill:#ccf,stroke:#333
    style L fill:#ccf,stroke:#333
    style M fill:#ccf,stroke:#333
    style N fill:#ccf,stroke:#333
    style O fill:#ccf,stroke:#333
    style P fill:#ccf,stroke:#333
    style Q fill:#ccf,stroke:#333
    style R fill:#ccf,stroke:#333
    style S fill:#ccf,stroke:#333
    style T fill:#ccf,stroke:#333

Figure 104 – Relationship of Command Modes

User EXEC ModeWhen login the .Switch using privilege level 1 accounts, user will entering User EXEC Mode automatically. User EXEC mode is used to do the basic operation such as show commands.
Privileged EXEC ModeWhen login the .Switch using privilege level 15 accounts, user will entering Privileged EXEC Mode automatically. A password is required to enable Privileged EXEC Mode, default ispassword.
Global Configuration ModeThe Global Configuration Mode is used to configure the global commands which will take effect to whole system and all interfaces.
Interface 11-21The Interface Configuration Mode is used to configure the commands for physical
Configuration Modeinterfaces.
Config-vlan ModeThe VLAN Configuration Mode is used to configure the commands for VLAN interfaces.
MSTP Configuration ModeThe MSTP Configuration Mode is used to configure multiple spanning tree specific commands.
MAC Access List Configuration ModeThe MAC Access List Configuration Mode is used to configure L2 access rules including content such as MAC address, VLAN, or specific Ether type.
Standard IP Access List Configuration ModeThe Standard IP Access List Configuration Mode is used to configure L3 access rules with specific source/destination IP address.
Extended IP Access List Configuration ModeThe Standard IP Access List Configuration Mode is used to configure L3/4 access rules with specific IP address, protocol type or port number.
Class-map Configuration ModeThe Class-map Configuration Mode is used to configure class rules and access lists mapping.
Policy-map Configuration ModeThe Policy-map Configuration Mode is used to configure policy mapping for class rules.
Policy-map Class Configuration ModeThe Policy-map Class Configuration Mode is used to configure the actions of policies.

Conventions

This publication uses these conventions to convey instructions and information:

Command descriptions use these conventions:

  • Commands and keywords are in bold text.
  • Arguments for which you supply values are in italic.
  • Square brackets ([]) means optional elements.
  • Braces ({} ) group required choices, and vertical bars ( | ) separate the alternative elements.
  • Braces and vertical bars within square brackets ({{ | }}) mean a required choice within an optional element.

Chapter 12

System Information Command

System Information Command List

▪ system name▪ system contact▪ system location▪ system web-timeout▪ system cli-timeout▪ default ip address▪ default ip address allocation protocol▪ default mode▪ default restore▪ default restore-file▪ default vlan id▪ set ip http▪ ip http port▪ show system information▪ show nvram▪ show http server status▪ show ip information▪ show line console
system name
CommandTo define the name of the Switch
system name
Syntax Descriptionidentify info A maximum of 15 characters is allowed. A NULL string is not accepted.
Default SettingsSysName
Command ModesGlobal Configuration Mode
User GuidelinesThis command defines the name of the Switch.
Exampleswitch(config)# system name trendnet
Command HistoryVersionHistory
1.00.001This command was introduced.

system contact

CommandTo enter identification information of a contact person.
system contact
Syntax Descriptioncontact infoA maximum of 50 characters is allowed. A NULL string is not accepted.
Default SettingsSysContact
Command ModesGlobal Configuration Mode
User GuidelinesUse this command to provide the name and/or other information to identify contact person who is responsible for the Switch.
Exampleswitch(config)# system contact TechSupport
Command HistoryVersionHistory
1.00.001This command was introduced.
system location
CommandTo enter a description of the location of the Switch.
system location
Syntax Descriptionlocation infoA maximum of 50 characters is allowed. A NULL string is not accepted.
Default SettingsSysLocation
Command ModesGlobal Configuration Mode
User GuidelinesThis command enters a description of the location of the Switch.
Exampleswitch(config)# system location 5F east
Command HistoryVersionHistory
1.00.001This command was introduced.

system web-timeout

To define the amount of time the device times out when no user activity occurs on the web interface.

Commandsystem web-timeout <180-3600 seconds>
Syntax Description180-3600 secondsThe web interface logs out the current user when no user activity input for 180-3600 seconds.
Default Settings600 seconds
Command ModesGlobal Configuration Mode
User GuidelinesThis command defines the amount of time the device times out when no user activity occurs on the web interface.
Exampleswitch (config)# system web-timeout 3600
Command HistoryVersionHistory
1.00.001This command was introduced.

system cli-timeout

CommandTo define the amount of time the device times out when no user activity occurs on the CLI interface.
system cli-timeout <1-18000 seconds>
Syntax Description1-18000 secondsThe cli interface logs out the current user when no user activity input for 1-18000 seconds.
Default Settings1800 seconds
Command ModesGlobal Configuration Mode
User GuidelinesThis command defines the amount of time the device times out when no user activity occurs on the web interface.
Exampleswitch(config)# system cli-timeout 18000
Command HistoryVersionHistory
1.00.001This command was introduced.
default ip address

To configure the default IP interface.

Commanddefault ip address[ subnet-mask] [ interface ]
Syntax Descriptionip-addressIP address of the default interface
subnet-mask subnet maskSubnet mask of the default interface
interface interface-type interface-idInterface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
Default SettingsIP address - 192.168.10.200 Subnet mask - 255.255.255.0
Command ModesGlobal Configuration Mode
User GuidelinesThis command is to configure the IP address and subnet mask of default interface.
Exampleswitch(config)# default ip address 10.0.0.250 subnet-mas 255.0.0.0
Command HistoryVersionHistory
1.00.001This command was introduced.

default ip address allocation protocol

CommandTo configure the protocol that the IP address of default interface is assigned.
default ip address allocation protocol {bootp | rarp | dhcp}
Syntax DescriptionbootpBootp protocol
rarpRARP protocol
dhcpDHCP protocol
Default SettingsDHCP
Command ModesGlobal Configuration Mode
User GuidelinesThis command is to configure the protocol that the IP address of default interface is assigned.
Exampleswitch(config)# default ip address allocation protocol bootp
Command HistoryVersionHistory
1.00.001This command was introduced.

default mode

CommandTo configure the mode that the IP address of default interface is assigned.
default mode { manual | dynamic }
Syntax DescriptionmanualManual mode. The ip address of default interface is the one configured by ‘default ip address’ command.
dynamicDynamic mode. The ip address of default interface is got through the protocol configured by ‘default ip address allocation protocol’ command.
Default SettingsManual
Command ModesGlobal Configuration Mode
User GuidelinesThis command is to configure the mode that the IP address of default interface is assigned.
Exampleswitch (config) # default mode dynamic
Command HistoryVersionHistory
1.00.001This command was introduced.
default restore
CommandTo enable or disable the default mode of configuration restoration.
default restore {enable | disable}
Syntax DescriptionenableTo enable the configuration restoration option.
disableTo disable the configuration restoration.
Default SettingsDisable
Command ModesGlobal Configuration Mode
User GuidelinesThis command is to adjust the default mode of configuration restoration.
Exampleswitch (config) # default restore enable
Command HistoryVersionHistory
1.00.001This command was introduced.
default restore-file
CommandTo configure the default restoration file.default restore-file
Syntax DescriptionfilenameThe name of restoration file.
Default SettingsIss.conf
Command ModesGlobal Configuration Mode
User GuidelinesThis command is to configure the default restoration file.
Exampleswitch(config)#default restore-file restore1.conf
Command HistoryVersionHistory
1.00.001This command was introduced.
NoteDefault mode must be dynamic to make this command effective.
default vlan id
CommandTo configure the default VLAN ID.default vlan id
Syntax Descriptioncount(1-4094)Change default VLAN from 1 to 4094.
Default Settings1
Command ModesGlobal Configuration Mode
Exampleswitch(config)#default vlan id 100
Command HistoryVersionHistory
1.00.001This command was introduced.

set ip http

CommandTo enable or disable HTTP server.
set ip http {enable | disable}
Syntax DescriptionenableTo enable the embedded HTTP server.
disableTo disable the embedded HTTP server.
Default SettingsEnable
Command ModesGlobal Configuration Mode
Exampleswitch(config)#set ip http enable
Command HistoryVersionHistory
1.00.001This command was introduced.
ip http port
CommandTo configure the TCP port for HTTP server connection.ip http portno ip http port
Syntax Descriptionport-number(1-65535)TCP port number.
Default Settings80
Command ModesGlobal Configuration Mode
User GuidelinesThe no form resets the HTTP port to default.
Exampleswitch(config)#ip http port 8080
Command HistoryVersionHistory
1.00.001This command was introduced.

show system information

To display system information.

Commandshow system information
Command ModesPrivileged EXEC mode
Exampleswitch# show system information
Hardware Version: Rev.A1
Firmware Version: 1.00.002
Switch Name: SysName
System Contact: SysContact
System Location: SysLocation
Logging Option: Console Logging
Login Authentication Mode: Local
Config Save Status: Not Initiated
Remote Save Status: Not Initiated
Config Restore Status: Successful
Web Timeout Interval: 600
Cli Timeout Interval: 18000
Command HistoryVersionHistory
1.00.001This command was introduced.
show nvram
CommandTo display the current information stored in NVRAM.
show nvram
Command ModesPrivileged EXEC mode
Exampleswitch# show nvram
Default IP Address: 192.168.10.200
Default Subnet Mask: 255.255.255.0
Default IP Address Config Mode: Manual
Default IP Address Allocation Protocol: DHCP
Switch Base MAC Address: 00:74:24:00:02:00
Default Interface Name: Fa0/1
Default RM Interface Name: NONE
Config Restore Option: Restore
Config Save Option: Startup save
Config Save IP Address: 0.0.0.0
Config Save Filename: iss.conf
Config Restore Filename: iss.conf
PIM Mode: Sparse Mode
IGS Forwarding Mode: MAC based
Cli Serial Console: Yes
SNMP EngineID: 80.00.08.1c.04.46.53
SNMP Engine Boots: 2
Default VLAN Identifier: 1
Command HistoryVersionHistory
1.00.001This command was introduced.

show http server status

To display the HTTP server status.
Commandshow http server status
Command ModesPrivileged EXEC mode
Exampleswitch# show http server status
HTTP server status : Enabled
HTTP port is : 80
Command HistoryVersionHistory
1.00.001This command was introduced.

show ip information

CommandTo display the IP information.
show ip information
Command ModesPrivileged EXEC mode
Exampleswitch# show http server status
HTTP server status : Enabled
HTTP port is : 80
switch# show ip information
Global IP Configuration:
IP routing is enabledDefault TTL is 64ICMP redirects are always sentICMP unreachables are always sentICMP echo replies are always sentICMP mask replies are always sentNumber of aggregate routes is 10Number of multi-paths is 2Load sharing is disabledPath MTU discovery is disabled
Command HistoryVersionHistory
1.00.001This command was introduced.

show line console

To display the information of current session.
Commandshow line console
Command ModesPrivileged EXEC mode
Exampleswitch# show line consoleCurrent Session Timeout (in secs) = 18000
Command HistoryVersionHistory
1.00.001This command was introduced.

Chapter 13

User Account Command

User Account Command List

username
CommandTo configure a user account information
username <user-name> [password <passwd>] [privilege <1-15>]
no username <user-name>
Syntax Descriptionusername user-name Username
password passwd Password
privilege 1-15 Privilege level. It is from 1 to 15.
Command ModesGlobal Configuration Mode
User GuidelinesThe no form deletes the user.
Exampleswitch(config)# username user password user privilege 1
Command HistoryVersion History
1.00.001 This command was introduced.
show users
CommandTo display the information of current users.
show users
Command ModesPrivileged EXEC mode
Exampleswitch# show users
Line0 conUserrootPeer-AddressLocal Peer
Command HistoryVersionHistory
1.00.001This command was introduced.
listuser
CommandTo display all existing user information.
listuser
Command ModesPrivileged EXEC mode
Exampleswitch# listuser
USERPRIVILEGE
root15
guest1
user1
Command HistoryVersionHistory
1.00.001This command was introduced.

Chapter 14

Management VLAN Command

Management VLAN Command List

management vlan-list
CommandTo set the VLAN ID for the management VLAN.
management vlan-listno management vlan-list
Syntax Descriptionvlan-listIt can be a single VLAN ID from 1 to 4094, a range of VLAN IDs separated by a hyphen (-), or a series of non-continuous numbers divided by a comma (,).
Command ModesGlobal Configuration Mode
Exampleswitch(config)# management vlan-list 100
Command HistoryVersionHistory
1.00.001This command was introduced.

show management vlan

CommandTo display the management VLAN ID.
show management vlan
Command ModesPrivileged EXEC mode
Exampleswitch# show management vlanManagement VLAN-List100,
Command HistoryVersionHistory
1.00.001This command was introduced.

Chapter 15

IP Settings Command

IP Settings Command List

·release dhcp vlanMgmt
·renew dhcp vlanMgmt
·ip arp max-retries
·arp
·arp timeout
·ip address
·ip address dhcp
·debug ip dhcp client
·show ip interface
·show ip arp

release dhcp vlanMgmt

To release the DHCP lease of management VLAN interface.
Commandrelease dhcp vlanMgmt
Command ModesPrivileged EXEC mode
Exampleswitch# release dhcp vlanMgmt
Command HistoryVersionHistory
1.00.001This command was introduced.
NoteThe IP address of Management VLAN interface must be assigned by a DHCP server.

renew dhcp vlanMgmt

To renew the DHCP lease of management VLAN interface.
Commandrenew dhcp vlanMgmt
Command ModesPrivileged EXEC mode
Exampleswitch# renew dhcp vlanMgmt
Command HistoryVersionHistory
1.00.001This command was introduced.

TRENDNET TL2-E284 - IP Settings Command - 1

The IP address of Management VLAN interface must be assigned by a DHCP server.

ip arp max-retries

CommandTo set the maximum number of ARP request retries.ip arp max-retriesno ip arp max-retries
Syntax Descriptionvalue (2-10)Number of ARP request retries.
Default Settings3
Command ModesGlobal Configuration Mode
User GuidelinesThe no form resets the number of retries to default value.
Exampleswitch(config)# ip arp max-retries 4
Command HistoryVersionHistory
1.00.001This command was introduced.

arp

CommandTo add a static entry in the switch ARP table.
arp{Vlan|interface-type|Linuxvlan|Cpu0}no arp
Syntax Descriptionip addressIP address of the network node.
hardware addressMAC address of the network node.
Vlanvlan-id(1-4094)VLAN id
interface-typeinterface-idInterface type and id of the interface connects to the ARP entry.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
Linuxvlaninterface-nameInterface name of Linux VLAN interface.
Cpu0Out-of-band management interface.
Command ModesGlobal Configuration Mode
User GuidelinesThe no form is to remove the entry.
Exampleswitch(config)# arp 10.90.90.100 11:22:33:44:55 vlan 1
Command HistoryVersionHistory
1.00.001This command was introduced.
arp timeout
CommandTo set the ARP table timeout.
arp timeout
no arp timeout
Syntax Descriptionseconds (30-86400)ARP entry timeout period
Default Settings300
Command ModesGlobal Configuration Mode
User GuidelinesThe no form is to reset to default value.
Exampleswitch(config)# arp timeout 3600
Command HistoryVersionHistory
1.00.001This command was introduced.
ip address
CommandTo configure the IP address of interface.
ip address
no ip address
Syntax Descriptionip-addressIP address of the interface
subnet-maskSubnet mask of the interface
gw-addressIP address of the gateway
Command ModesInterface Configuration Mode
User GuidelinesThe no form will delete the configured IP address.
Exampleswitch(config-if)#ip address 20.0.0.1 255.0.0.0 20.0.0.254
Command HistoryVersionHistory
1.00.001This command was introduced.
ip address dhcp
CommandTo set the IP address of interface to be assigned by DHCP server.
ip address dhcp
Command ModesInterface Configuration Mode
Exampleswitch(config-if)#ip address dhcp
Command HistoryVersionHistory
1.00.001This command was introduced.

debug ip dhcp client

CommandTo enable the debug mode of DHCP client.
debug ip dhcp client { all | event | packets | errors | bind no debug ip dhcp client { all | event | packets | errors | bi
Syntax DescriptionallInformation of all DHCP client activities
eventInformation of DHCP client events.
packetsInformation of DHCP client packets
errorsInformation of errors.
bindInformation of DHCP client binding.
Default SettingsDisabled
Command ModesPrivileged EXEC mode
User GuidelinesThis command is to enable the debug mode of DHCP client, and the no form is to disable it.
Exampleswitch#debug ip dhcp client all
Command HistoryVersionHistory
1.00.001This command was introduced.
show ip interface
CommandTo display the IP interface information.
show ip interface
Command ModesPrivileged EXEC mode
User GuidelinesThis command is to display the IP interface information.
Exampleswitch#show ip interface
vlanMgmt is up, line protocol is downInternet Address is 0.0.0.0/0Broadcast Address 255.255.255.255IP address allocation method is dynamicIP address allocation protocol is dhcp
Command HistoryVersionHistory
1.00.001This command was introduced.
show ip route
CommandTo display the IP route information.
show ip route [ {,[] | bgp | connected | ospf | rip | static | summary } ]
Syntax Description<ip-address>Network address and subnet mask of IP route.
bgpBGP routes.
connectedDirectly connected routes.
ospfOSPF routes.
ripRIP routes.
staticStatic routes.
summarySummary of all IP routes.
Command ModesPrivileged EXEC mode
Exampleswitch#show ip route summary
Route SourceRoutes
connected0
static0
rip0
bgp0
ospf0
Total0
Command HistoryVersionHistory
1.00.001This command was introduced.

Chapter 16

IP Authorized Manager Command

IP Authorized Manager Command List

  • authorized-manager
    ■ show authorized-managers

authorized-manager

Command

To set an authorized administrator source IP address, and the services, interfaces, or VLANs that it is allowed to visit.

authorized-manager ip-source [{ | / }] [interface [<interface-type <0/a-b, 0/c, ...>] [<interface-type <0/a-b, 0/c, ...>] [vlan ] [cpu0] [service [snmp] [telnet] [http] [http[ssh]]

no authorized-manager ip-source [{ | / }]

Syntax Description

ip-source ip-addressIP address of authorized manager
Subnet mask of the authorized IP address
/ prefix-length(1-32)Prefix length of the authorized IP address
interface-type0/a-b, 0/cInterface of the authorized administrator is allowed to connected to
vlan a,b or a-b or a,b,c-dVLAN ID of the authorized administrator is allowed to connected to
cpu0Out-of-band management interface.
service snmpSNMP service
service telnetTelnet service
service httpHTTP (Web) service
service httpsHTTPS (SSL) service
service sshSSH service

Default Settings

By default no authorized-manager ip-source is assigned. All services, vlan, and interfaces are allowed for an authorized-manager but default expect for the out-of-band management interface.

Command Modes

Global Configuration Mode

User GuidelinesThe no form removes the administrator from the list.
Exampleswitch (config) # authorized-manager ip-source 10.90.90.100
Command HistoryVersionHistory
1.00.001This command was introduced.

show authorized-managers

CommandDisplay the authorized-manager list.show authorized-managers [ip-source]
Syntax Descriptionip-source ip-addressIP address of authorized manager
Command ModesPrivileged EXEC mode
Exampleswitch#show authorized-managers
Ip Authorized Manager Table
Ip Address : 10.90.90.100
Ip Mask : 255.255.255.255
Services allowed : ALL
Ports allowed : Fa0/1, Fa0/2, Fa0/3, Fa0/4
Fa0/5, Fa0/6, Fa0/7, Fa0/8
Fa0/9, Fa0/10, Fa0/11, Fa0/12
Fa0/13, Fa0/14, Fa0/15, Fa0/16
Fa0/17, Fa0/18, Fa0/19, Fa0/20
Fa0/21, Fa0/22, Fa0/23, Fa0/24
Gi0/1, Gi0/2, Gi0/3, Gi0/4
On cpu0 : Deny
Vlans allowed : All Available Vlans
Command HistoryVersionHistory
1.00.001This command was introduced.

Chapter 17

SNMP Command

SNMP Command List

  • snmp access
  • snmp community
  • snmp engineid
  • snmp group
  • snmp trapinfo
  • snmp user
  • snmp view
    ■ snmp-server enable traps snmp authentication
    ■ snmp-server enable traps
    ■ snmp-server trap udp-port
  • snmp trap link-status
    ■ show snmp
    ■ show snmp community
    ■ show snmp engineID
    ■ show snmp group
    ■ show snmp group access
    ■ show snmp inform statistics
    ■ show snmp trapinfo
    ■ show snmp user
    ■ show snmp viewtree
    ■ show snmp-server traps

snmp access

To configure the access settings of a SNMP group, and the no form removes the group.

Command

snmp access {v1 | v2c | v3 {auth | noauth | authpriv}} [read ] [write ] [notify ] [{volatile | nonvolatile}]

no snmp access {v1 | v2c | v3 {auth | noauth | authpriv}}

Syntax Description

GroupNameName of SNMP group
v1SNMP version 1 is to be used
v2cSNMP version 2v is to be used
v3SNMP version 3 is to be used
authAuthentication is required for the SNMP messages
noauthAuthentication is not required for the SNMP messages
authprivBoth authentication and encryption are required for the SNMP messages
read ReadViewThe SNMP group has read privilege and is allowed to access the specified MIB object groups
read noneThe SNMP group has read privilege
write WriteViewThe SNMP group has write privilege and is allowed to access the specified MIB object groups
write noneThe SNMP group has write privilege
notify NotifyViewThe SNMP group can receive SNMP Trap messages and is allowed to access the specified MIB object groups
notify noneThe SNMP group can receive SNMP Trap messages
volatileStore in volatile memory
nonvolatileStore in nonvolatile memory

Default Settings

Group Name : iso

Read View : iso

Write View : iso

Notify View : iso

Storage Type : Non-volatile

Group Name : initial

Read View : restricted

Write View : restricted

Notify View : restricted

Storage Type : Non-volatile

Group Name : initial

Read View : iso

Write View : iso

Notify View : iso

Storage Type : Non-volatile

Group Name : ReadOnly

Read View : ReadWrite

Write View :

Notify View : ReadWrite

Storage Type : Non-volatile

Group Name : ReadWrite

Read View : ReadWrite

Write View : ReadWrite

Notify View : ReadWrite

Storage Type : Non-volatile

Command ModesGlobal Configuration Mode
User GuidelinesBefore configuring the access settings, the SNMP group has to be created first.
Exampleswitch(config)# snmp access oper v2c read operv2readview writ operv2writeview notify operv2notifyview nonvolatile
Command HistoryVersionHistory
1.00.001This command was introduced
snmp community
CommandTo create a SNMP community, and the no form removes the community.
snmp community <CommunityName> security[{volatile | nonvolatile}]
no snmp community
Syntax DescriptionCommunityNameSNMP community name
security SecurityNameSecurity name
volatileStore in volatile memory
nonvolatileStore in nonvolatile memory
Default SettingsCommunity Index : NETMAN
Community Name : NETMAN
Security Name : none
Storage Type : Non-volatile
----
Community Index : PUBLIC
Community Name : PUBLIC
Security Name : none
Storage Type : Non-volatile
Command ModesGlobal Configuration Mode
Exampleswitch(config)# snmp community oper security none nonvolatile
Command HistoryVersionHistory
1.00.001This command was introduced
snmp engineid

To configure the SNMP engine identifier of the switch

Commandsnmp engineidno snmp engineid
Syntax DescriptionEngineIdentifierA string of between 5 and 32 octets expressed in hexadecimal that is separated by dots
Default Settings80.00.08.1c.04.46.53
Command ModesGlobal Configuration Mode
User GuidelinesSNMP engine ID is unique for each switches
Exampleswitch(config)# snmp engineid 80.00.08.1c.04.46.ae
Command HistoryVersionHistory
1.00.001This command was introduced
snmp group
CommandTo create a SNMP group and the no form deletes the group
snmp groupusersecurity-model {v1 | v2c | v3 } [{volatile | nonvolatile}]
no snmp groupusersecurity-model {v1 | v2c | v3}
Syntax DescriptionGroupNameSNMP group name
user UserNameSpecify the user name
security-model v1SNMP version 1 is to be used
security-model v2cSNMP version 2v is to be used
security-model v3SNMP version 3 is to be used
volatileStore in volatile memory
nonvolatileStore in nonvolatile memory

Default Settings

Security Model : v1

Security Name : none

Group Name : iso

Storage Type : Non-volatile

Security Model : v1

Security Name : ReadOnly

Group Name : ReadOnly

Storage Type : Non-volatile

Security Model : v1

Security Name : ReadWrite

Group Name : ReadWrite

Storage Type : Non-volatile

Security Model : v2c

Security Name : none

Group Name : iso

Storage Type : Non-volatile

Security Model : v2c

Security Name : ReadOnly

Group Name : ReadOnly

Storage Type : Non-volatile

Security Model : v2c

Security Name : ReadWrite

Group Name : ReadWrite

Storage Type : Non-volatile

Security Model : v3

Security Name : initial

Group Name : initial

Storage Type : Non-volatile

Security Model : v3

Security Name : templateMD5

Group Name : initial

Storage Type : Non-volatile

Security Model : v3

Security Name : templateSHA

Group Name : initial

Storage Type : Non-volatile

Command Modes

Global Configuration Mode

Example

switch(config)# snmp group oper user operuser security-model v2c nonvolatile

Command History

Version

History

1.00.001

This command was introduced

snmp trapinfo

CommandTo configure the SNMP Trap setting of a community user, and no form deletes the setting.
snmp trapinfo community-userIPAddress{|} security-model {v1 | v2c | v3 {auth | noauth | authpriv}} [{volatile | nonvolatile}]
no snmp trapinfo community-usersecurity-model {v1 | v2c | v3}
Syntax Descriptioncommunity-userUserNameSNMP community-user name
IPAddress IPAddressIPv4 address of SNMP Trap messages to be sent to
IPAddress IP6AddressIPv6 address of SNMP Trap messages to be sent to
security-model v1SNMP version 1 is to be used
security-model v2cSNMP version 2v is to be used
security-model v3 authSNMP version 3 is to be used, and authentication is used for the SNMP messages
security-model v3 noauthSNMP version 3 is to be used, and no authentication is used for the SNMP messages
security-model v3 authprivSNMP version 3 is to be used, and authentication and encryption are used for the SNMP messages
volatileStore in volatile memory
nonvolatileStore in nonvolatile memory
Default SettingsNone
Command ModesGlobal Configuration Mode
Exampleswitch(config)# snmp trapinfo community-user oper ipAddress 172.17.0.168 security-model v2c nonvolatile
Command HistoryVersion History
1.00.001 This command was introduced
snmp user
CommandTo create a SNMP user and no form deletes the user.
snmp user[auth {md5 | sha}[priv DES]] [{volatile | nonvolatile}]
no snmp user
Syntax DescriptionUserNameSNMP user name
auth md5Specify MD5 as authentication algorithm
auth shaSpecify Secure Hash as authentication algorithm
passwdAuthentication password
priv DES passwdEncryption password
volatileStore in volatile memory
nonvolatileStore in nonvolatile memory
Default SettingsUser : initial Authentication Protocol : None Privacy Protocol : None Storage Type : Non-volatile
User : ReadOnly Authentication Protocol : None Privacy Protocol : None Storage Type : Non-volatile
User : ReadWrite Authentication Protocol : None Privacy Protocol : None Storage Type : Non-volatile
User : templateMD5 Authentication Protocol : MD5 Privacy Protocol : None Storage Type : Non-volatile
User : templateSHA Authentication Protocol : SHA Privacy Protocol : DES_CBC Storage Type : Non-volatile
Command ModesGlobal Configuration Mode
Exampleswitch (config)# snmp user operator1
Command HistoryVersion History
1.00.001 This command was introduced
snmp view
CommandTo create a SNMP view which limits the range of MIB objects that a SNMP administrator can access to. The no form deletes the SNMP view.
snmp view <ViewName> <OIDTree> [mask <OIDMask>] {included | excluded} [{volatile | nonvolatile}]
no snmp view <ViewName> <OIDTree>
Syntax DescriptionViewName SNMP view name
OIDTree The object ID of MIB tree
mask OIDMask The mask of OID
included Includes the object in the list that the SNMP administrator can access
excludedExcludes the object from the list that the SNMP administrator can access
volatileStore in volatile memory
nonvolatileStore in nonvolatile memory
Default SettingsView Name : isoSubtree OID : 1Subtree Mask : 1View Type : IncludedStorage Type : Non-volatile
View Name : ReadWriteSubtree OID : 1Subtree Mask : 1View Type : IncludedStorage Type : Non-volatile
View Name : restrictedSubtree OID : 1Subtree Mask : 1View Type : IncludedStorage Type : Non-volatile
Command ModesGlobal Configuration Mode
Exampleswitch(config)# snmp view operv2readview 1.3.6.1 mask 1.1.1.1 included nonvolatile
Command HistoryVersionHistory
1.00.001This command was introduced

snmp-server enable traps snmp authentication

To enable the authentication trap messages for SNMP v1 and v2c, and the no form disables it.
Commandsnmp-server enable traps snmp authentication
no snmp-server enable traps snmp authentication
Default SettingsDisabled
Command ModesGlobal Configuration Mode
Exampleswitch(config)# snmp-server enable traps snmp authentication
Command HistoryVersionHistory
1.00.001This command was introduced

snmp-server enable traps

CommandTo enable specific SNMP trap message types, and no form disable them.
snmp-server enable traps {firewall-limit | linkup | linkdown | sip-states |sip-cfg-change | coldstart | poe-power | dhcp-pool-limit | dsx1-line}
no snmp-server enable traps {firewall-limit | linkup | linkdc sip-states | sip-cfg-change | coldstart | poe-power | dhcp-pool-limit | dsx1-line}
Syntax Descriptionfirewall-limit
linkupInterfaces are linked up
linkdownInterfaces are linked down
sip-statesThe change of SIP protocol state
sip-cfg-changeThe change of SIP configuration
coldstartThe switch is power cycled
poe-power
dhcp-pool-limit
dsx1-line
Default SettingsLinkup and Linkdown messages are enabled
Command ModesGlobal Configuration Mode
Exampleswitch(config)# snmp enable traps poe-power
Command HistoryVersionHistory
1.00.001This command was introduced

snmp-server trap udp-port

CommandTo specify the UDP port for sending SNMP trap messages snmp-server trap udp-portno snmp-server trap udp-port
Syntax DescriptionUDP port number
Default Settings162
Command ModesGlobal Configuration Mode
Exampleswitch(config)# snmp-server trap udp-port 10162
Command HistoryVersionHistory
1.00.001This command was introduced

snmp trap link-status

CommandTo enable sending link-status Trap message, and no form disables it snmp trap link-status no snmp trap link-status
Default SettingsDisabled
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# snmp trap link-status
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp

To display the SNMP settings
Commandshow snmp
Command ModesPrivileged EXEC Mode

Example

switch#show snmp

0 SNMP Packets Input
    0 Bad SNMP Version errors
    0 Unknown community name
    0 Get request PDUs
    0 Get Next PDUs
    0 Set request PDUs

0 SNMP Packets Output
    0 Too big errors
    0 No such name errors
    0 Bad value errors
    0 General errors
    0 Trap PDUs

SNMP Manager-role output packets
    0 Drops

SNMP Informs:
    0 Inform Requests generated
    0 Inform Responses received
    0 Inform messages Dropped
    0 Inform Requests awaiting Acknowledgement

SNMP Trap Listen Port is 162 

Command History

Version

History

1.00.001

This command was introduced

show snmp community

To display the SNMP community information

Command

show snmp community

Command Modes

Privileged EXEC Mode

Example
switch# show snmp community

Community Index : NETMAN
Community Name : NETMAN
Security Name : none
Context Name :
Transport Tag :
Storage Type : Non-volatile
Row Status : Active
----
Community Index : PUBLIC
Community Name : PUBLIC
Security Name : none
Context Name :
Transport Tag :
Storage Type : Non-volatile
Row Status : Active
----
----
Community Index : oper
Community Name : oper
Security Name : none
Context Name :
Transport Tag :
Storage Type : Non-volatile
Row Status : Active

Command History

VersionHistory
1.00.001This command was introduced

show snmp engineID

To display the SNMP engine ID
Commandshow snmp engineID
Command ModesPrivileged EXEC Mode
Exampleswitch# show snmp engineidEngineId: 80.00.08.1c.04.46.53
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp group

To display the SNMP group information

Commandshow snmp group

Command Modes

Privileged EXEC Mode

Example

switch# show snmp group

Security Model : vl
Security Name : none
Group Name : iso
Storage Type : Non-volatile
Row Status : Active
Security Model : v1
Security Name : ReadOnly
Group Name : ReadOnly
Storage Type : Non-volatile
Row Status : Active
Security Model : v1
Security Name : ReadWrite
Group Name : ReadWrite
Storage Type : Non-volatile
Row Status : Active
Security Model : v2c
Security Name : none
Group Name : iso
Storage Type : Non-volatile
Row Status : Active
Security Model : v2c
Security Name : ReadOnly
Group Name : ReadOnly
Storage Type : Non-volatile
Row Status : Active
Security Model : v2c
Security Name : ReadWrite
Group Name : ReadWrite
Storage Type : Non-volatile
Row Status : Active
Security Model : v3
Security Name : initial
Group Name : initial
Storage Type : Non-volatile
Row Status : Active
Security Model : v3
Security Name : templateMD5
Group Name : initial
Storage Type : Non-volatile
Row Status : Active
Security Model : v3
Security Name : templateSHA
Group Name : initial
Storage Type : Non-volatile
Row Status : Active
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp group access

To display the access setting of SNMP group
Commandshow snmp group access
Command ModesPrivileged EXEC Mode

Example

switch# show snmp group access

Group Name : iso
Read View : iso
Write View : iso
Notify View : iso
Storage Type : Non-volatile
Row Status : Active
Group Name : iso
Read View : iso
Write View : iso
Notify View : iso
Storage Type : Non-volatile
Row Status : Active
Group Name : initial
Read View : restricted
Write View : restricted
Notify View : restricted
Storage Type : Non-volatile
Row Status : Active
Group Name : initial
Read View : iso
Write View : iso
Notify View : iso
Storage Type : Non-volatile
Row Status : Active
Group Name : initial
Read View : iso
Write View : iso
Notify View : iso
Storage Type : Non-volatile
Row Status : Active
Group Name : ReadOnly
Read View : ReadWrite
Write View :
Notify View : ReadWrite
Storage Type : Non-volatile
Row Status : Active
Group Name : ReadOnly
Read View : ReadWrite
Write View :
Notify View : ReadWrite
Storage Type : Non-volatile
Row Status : Active
Group Name : ReadWrite
Read View : ReadWrite
Write View : ReadWrite
Notify View : ReadWrite
Storage Type : Non-volatile
Row Status : Active
Group Name : ReadWrite
Read View : ReadWriteWrite View : ReadWriteNotify View : ReadWriteStorage Type : Non-volatileRow Status : Active
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp inform statistics

CommandTo display the recipient information of SNMP trapsshow snmp inform statistics
Command ModesPrivileged EXEC Mode
Exampleswitch# show snmp inform statisticsTarget Address Name : operV2IP Address : 172.17.0.168
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp trapinfo

CommandTo display the SNMP trap informationshow snmp trapinfo
Command ModesPrivileged EXEC Mode
Exampleswitch# show snmp trapinfo
Host IP Address : 172.17.0.168Community/User Name : operSecurity Model : v2cSecurity Level : No Authentication, No Privacy
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp user

CommandTo display the SNMP user information
show snmp user
Command ModesPrivileged EXEC Mode
Exampleswitch# show snmp user
Engine ID: 80.00.08.1c.04.46.53
User: initial
Authentication Protocol: None
Privacy Protocol: None
Storage Type: Non-volatile
Row Status: Active
Engine ID: 80.00.08.1c.04.46.53
User: ReadOnly
Authentication Protocol: None
Privacy Protocol: None
Storage Type: Non-volatile
Row Status: Active
Engine ID: 80.00.08.1c.04.46.53
User: ReadWrite
Authentication Protocol: None
Privacy Protocol: None
Storage Type: Non-volatile
Row Status: Active
Engine ID: 80.00.08.1c.04.46.53
User: templateMD5
Authentication Protocol: MD5
Privacy Protocol: None
Storage Type: Non-volatile
Row Status: Active
Engine ID: 80.00.08.1c.04.46.53
User: templateSHA
Authentication Protocol: SHA
Privacy Protocol: DES_CBC
Storage Type: Non-volatile
Row Status: Active
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp viewtree

To display SNMP view information

Commandshow snmp viewtree
Command ModesPrivileged EXEC Mode
Exampleswitch# show snmp viewtree
View Name : isoSubtree OID : 1Subtree Mask : 1View Type : IncludedStorage Type : Non-volatileRow Status : Active
View Name : ReadWriteSubtree OID : 1Subtree Mask : 1View Type : IncludedStorage Type : Non-volatileRow Status : Active
View Name : restrictedSubtree OID : 1Subtree Mask : 1View Type : IncludedStorage Type : Non-volatileRow Status : Active
Command HistoryVersionHistory
1.00.001This command was introduced

show snmp-server traps

To display the configured trap message information
Commandshow snmp-server traps
Command ModesPrivileged EXEC Mode
Exampleswitch# show snmp-server trapsCurrently enabled traps:----linkup, linkdown,
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 18

SSH Command

SSH Command List

ssh
CommandTo activate the SSH server function on the switch. The no format is to turn it off.
ssh {enable | disable}
Syntax DescriptionenableTo turn on the SSH server function.
disableTo turn off the SSH server function.
Default SettingsEnabled
Command ModesGlobal Configuration Mode
Exampleswitch(config)# ssh enable
Command HistoryVersionHistory
1.00.001This command was introduced

ip ssh

To configure the SSH server settings. The no format will cancel the setting and go back to default value.
Commandip ssh {version compatibility | cipher ([des-cbc] [3des-cbc]) | auth ([hmac-md5] [hmac-sha1]) }
no ip ssh {version compatibility | cipher ([des-cbc] [3des-ch | auth ([hmac-md5] [hmac-sha1]) }
Syntax DescriptionversioncompatibilityThe supported version of SSH.
cipher([des-cbc][3des-cbc])To configure SSH Cipher algorithm. User can choose from DES (Data Encryption Standard) or 3DES (Triple_Data Encryption Standard) encryption algorithm in CBC (Cipher Blocking Chain) mode.
auth([hmac-md5][hmac-sha1])To configure authentication encryption algorithm. User can choose two different Hash-based Message Authentication Codes (HMAC): MD5 (Message-Digest algorithm 5) or SHA1 (Secure Hash Algorithm).
Default SettingsVersion: 2Cipher: 3DES-CBCAuthentication: HMAC-SHA1
Command ModesGlobal Configuration Mode
User GuidelinesaWhen set version compatibility, both SSH version-1 and SSH version-2 will be supported.
Exampleswitch(config)# ip ssh version compatibility
Command HistoryVersionHistory
1.00.001This command was introduced
debug ssh
CommandTo enable the trace level messages of SSH. The no format will reset all settings.
debug ssh {all | [shut] [mgmt] [data] [ctrl] [dump] [resource [failall] [buffer] [server]}
no debug ssh {all | [shut] [mgmt] [data] [ctrl] [dump] [resou [failall] [buffer] [server]}
Syntax DescriptionallEnable or disable all categories of messages.
shutShutdown messages.
mgmtManagement messages.
dataData Path messages.
ctrlControl panel messages.
dumpPacket Dump messages.
resourceAll resource messages except for buffer.
failallFailure messages.
bufferBuffer messages.
serverSSH server messages.
Default SettingsDisabled.
Command ModesPrivileged EXEC Mode
Exampleswitch# debug ssh all
Command HistoryVersionHistory
1.00.001This command was introduced
show ip ssh
CommandTo display the SSH server information.
show ip ssh
Command ModesPrivileged EXEC Mode
Exampleswitch# show ip ssh
Version : 2Cipher Algorithm : 3DES-CBCAuthentication : HMAC-SHA1Trace Level : NoneServer Status : Enable
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 19

SSL Command

SSL Command List

ip http securedebug sslshow ssl server-certshow ip http secure server status
ip http secure
CommandTo activate SSL server on the switch and configure Cipher and key settings. The no form will deactivate SSL server and all settings.ip http secure { server | ciphersuite [rsa-null-md5][rsa-null-sha1] [RSA-DES-SHA1] [RSA-3DES-SHA1][dh-rsa-des-sha1] [dh-rsa-3des-sha1] [RSA-EXP1024-DES-SHA1] | crypto key rsa [usage-keys (512|1024)] }no ip http secure { server | ciphersuite [rsa-null-[rsa-null-sha1] [RSA-DES-SHA1] [RSA-3DES-SHA1][dh-rsa-des-sha1] [dh-rsa-3des-sha1] [RSA-EXP1024-DES-SHA1]}
Syntax DescriptionserverSSL server
ciphersuiteSSL Cipher algorithm
rsa-null-md5RSA-NULL-MD5 cipher algorithm
rsa-null-sha1RSA-NULL-SHA1 cipher algorithm
RSA-DES-SHA1RSA-DES-SHA1 cipher algorithm
RSA-3DES-SHA1RSA-3DES-SHA1 cipher algorithm
dh-rsa-des-sha1DH-RSA-DES-SHA1 cipher algorithm
dh-rsa-3des-sha1DH-RSA-3DES-SHA1 cipher algorithm
RSA-EXP1024-DES-SHA1RSA-EXP1024-DES-SHA1 cipher algorithm
crypto key rsaTo specify the RSA key length
usage-keys 512The RSA key length is 512
usage-keys 1024The RSA key length is 1024
Default SettingsSSL server is disabled.Cipher Suite is RSA-DES-SHA1, RSA-3DES-SHA1, and RSA-EXP1024-DES-SHA1
Command ModesGlobal Configuration Mode
Exampleswitch(config)# ip http secure ciphersuite rsa-null-md5
Command HistoryVersionHistory
1.00.001This command was introduced
debug ssl
CommandTo enable the debug messages of SSL. The no format will reset all settings.
debug ssl {all | [shut] [mgmt] [data] [ctrl] [dump] [resource [failall] [buffer]}
no debug ssl {all | [shut] [mgmt] [data] [ctrl] [dump] [resou [failall] [buffer]}
Syntax DescriptionallEnable or disable all categories of messages.
shutShutdown messages.
mgmtManagement messages.
dataData Path messages.
ctrlControl panel messages.
dumpPacket Dump messages.
resourceAll resource messages except for buffer.
failallFailure messages.
bufferBuffer messages.
Default SettingsDisabled
Command ModesPrivileged EXEC Mode
Exampleswitch# debug ssl all
Command HistoryVersionHistory
1.00.001This command was introduced

show ssl server-cert

CommandTo display SSL server certificationshow ssl server-cert
Command ModesPrivileged EXEC Mode
User GuidelinesThe server certification has to be created first.
Exampleswitch# show ssl server-cert
Certificate:Data:Version: 1 (0x0)Serial Number:87:97:71:61:7f:72:c6:aeSignature Algorithm: shalWithRSAEncryptionIssuer: C=CA, L=Torrance, O=TRENDnetValidityNot Before: Aug 18 12:26:51 2009 GMTNot After : Aug 18 12:26:51 2011 GMTSubject: CN=TL2-E284Subject Public Key Info:Public Key Algorithm: rsaEncryptionRSA Public Key: (1024 bit)Modulus (1024 bit):00:b4:95:58:2a:04:2d:a4:6b:a2:6a:75:19:d7:c37d:f6:5b:5e:93:78:11:a5:b1:66:b7:b6:9e:65:3fde:d3:a0:84:54:58:da:18:0a:fb:d5:c3:bf:ab:a8b9:e1:76:fa:15:d3:cb:b5:2e:6a:54:dc:a4:5d:39aa:48:ea:55:81:2f:c5:16:38:57:4f:73:4c:ba:c2d5:4d:61:2e:ab:a4:79:03:6c:03:b3:3b:00:71:9193:12:8a:3b:2e:9c:bb:7d:7d:b8:a4:ca:f8:53:88c3:a5:2c:ba:e1:61:09:76:b1:4d:f7:9d:de:14:ef5e:2e:ca:a9:2e:30:46:11:29Exponent: 65537 (0x10001)Signature Algorithm: shalWithRSAEncryption3e:dc:a0:a8:6e:c0:50:5e:98:be:82:01:35:50:3a:be:c7:42:35:93:c7:f4:d7:f5:2e:eb:cd:ec:fb:fd:d4:8d:e9:26:51:7c:06:c8:1c:8b:46:92:12:43:c1:9d:0a:86:52:98:5b:f4:5a:dd:25:99:af:17:3c:ba:1a:c1:42:aa:a9:b3:63:f6:17:9d:eb:16:c6:8b:aa:26:8f:79:56:bf:6a:cb:bc:67:55:af:88:20:f5:f0:6d:1a:27:aa:50:83:64:e0:f1:ae:89:7a:5e:17:1b:f7:7b:1f:da:7f:ec:1b:69:d8:a5:e6:c6:de:5d:5b:c7:35:37:c6:ce:5b:9b:f3
Command HistoryVersion History
1.00.001 This command was introduced

show ip http secure server status

To display the SSL server status
Commandshow ip http secure server status
Command ModesPrivileged EXEC Mode
Exampleswitch# show ip http secure server status
HTTP secure server status : Disabled
HTTP secure server ciphersuite : RSA-NULL-MD5:
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 20

System Log Command

System Log Command List

copy logsloggingmailserverclear logsshow loggingshow email alerts
copy logs
CommandBackup the system log to a remote tftp server
copy logs tftp://ip-address/filename
Syntax Descriptiontftp://ip-address/filenameThe IP address the remote tftp server and the name of the system log file to be saved.
Command ModesGlobal Configuration Mode
User GuidelinesThe maximum lengths of filename are 32 characters.
Exampleswitch(config)# copy logs tftp://172.17.0.100/syslog1
Command HistoryVersionHistory
1.00.001This command was introduced
logging
CommandTo configure the syslog server settings, and the no form resets all settings.
logging {buffered| console |facility {local0 | local1 | local2 | local3 | local4 | local | local6 | local7 | } |trap [{<level (0-7)> | alerts | critic | debugging | emergencies | errors | informational | notificat | warnings }] | on}
no logging {| buffered | console | facility | trap | on}
Syntax Descriptionip-addressIP address of the syslog server
buffered size (1-200)The size of internal logging buffer
consoleEnable logging to the console
Facility local0~7Specifies the facility that is indicated in the message. Possible values: local0, local1, local2, local3, local4, local5, local 6, local7
trapEnable trap messages
level (0-7)Severity levels
alertsAlert level: action must be taken immediately
criticalCritical level: Critical conditions
debuggingDebug level: Debug messages
emergenciesEmergency level: System is unusable
errorsError level: Error conditions
informationalInformational level: Informational messages
notificationNotification level: Normal but significant condition
warningsWarning level: Warning conditions
onEnable the syslog
Default SettingsLogging: EnabledConsole: DisabledTimestamp: EnabledTrap: InformationalIP address: NoneFacility: Local0Buffered: 50
Command ModesGlobal Configuration Mode
Exampleswitch(config)# logging console
Command HistoryVersionHistory
1.00.001This command was introduced

mailserver

Specify the IP address of mail server to be used for sending the email alerts messages. The no form resets the setting.

Command

mailserver

no mailserver

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Syntax Descriptionip-addressThe IP address of mail server
Default SettingsNo mail server is configured.
Command ModesGlobal Configuration Mode
Exampleswitch(config)# mailserver 172.17.0.201
Command HistoryVersionHistory
1.00.001This command was introduced
clear logs
CommandClear the system log buffers
clear logs
Command ModesGlobal Configuration Mode
Exampleswitch(config)# clear logs
Command HistoryVersionHistory
1.00.001This command was introduced
show logging
CommandTo display the logging status, setting, and contents of buffer.
show logging
Command ModesPrivileged EXEC Mode
Exampleswitch# show logging
System Log Information
Syslog logging : enabled (Number of messages 0)
Console logging : disabled (Number of messages 0)
TimeStamp option : enabled
Trap logging : Informational
Log server IP : 20.0.0.1
Facility : Default (local0)
Buffered size : 50 Entries
LogBuffer(3 Entries, 612 bytes)
<130> Jan 1 00:07:47 2009:SYSTEM-2:System started up
<134> Jan 1 01:39:15 2009:CLI-6:Login failed : Login incorre
ATE1 V1
<134> Jan 1 01:39:19 2009:CLI-6:User root logged in
Command HistoryVersionHistory
1.00.001This command was introduced
show email alerts
CommandTo display the setting of mailserver.
show email alerts
Command ModesPrivileged EXEC Mode
Exampleswitch# show email alerts
Mail server IP : 172.17.0.201
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 21

SNTP Command

SNTP Command List

clock setset sntpset sntp dstsntp dstsntp poll-intervalsntp primary-ipsntp secondary-ipsntp timezoneshow clockshow sntp
clock set
CommandTo set the system time.
clock set
Syntax Descriptionhh:mm:ss day month year Specify the system time.
Command ModesPrivileged EXEC Mode
User GuidelinesThe format of day, month and year are:- Day: 1~31- Month: Jan, Feb, Mar, Apr, May, Jun, Jul, Aug, Sep, Oct, Nov, Dec- Year: yyyy
Exampleswitch# clock set 08:00:00 1 Jan 2010
Command HistoryVersion History
1.00.001 This command was introduced
set sntp
CommandTo enable/disable the Simple Network Time Protocol (SNTP) function, synchronizing the system time to the SNTP server..
set sntp {enable | disable}
Syntax DescriptionenableEnables the SNTP.
disableDisables the SNTP.
Default SettingsDisable
Command ModesGlobal Configuration Mode
Exampleswitch(config)# set sntp enable
Command HistoryVersionHistory
1.00.001This command was introduced
set sntp dst
CommandTo enable/disable the Daylight Saving Time (DST) function of SNTP.
set sntp dst {enable | disable}
Syntax DescriptionenableEnables the DST function.
disableDisable the DST function.
Default SettingsDisable
Command ModesGlobal Configuration Mode
Exampleswitch(config)# set sntp dst enable
Command HistoryVersionHistory
1.00.001This command was introduced

sntp dst

Commandsntp dst from {january | february | march | april | may | jun | july | august | september | october | november | december} <day (1-31)> <hour (0-23)> <minute (0-59)> to {january | february | march | april | may | june | july | august | septe | october | november | december} <day (1-31)> <hour (0-23)> <minute (0-59)>
Syntax DescriptionfromTime that DST starts from
january ~ decemberSpecify the month that DST starts.
day (1-31)Specify the day that DST starts.
hour (0-23)Specify the hour that DST starts.
minute (0-59)Specify the minute that DST starts.
toTime that DST ends from
january ~ decemberSpecify the month that DST ends.
day (1-31)Specify the day that DST ends.
hour (0-23)Specify the hour that DST ends.
minute (0-59)Specify the minute that DST ends.
Command ModesGlobal Configuration Mode
Exampleswitch(config)# sntp dst from april 1 0 0 to September 1 0 0
Command HistoryVersionHistory
1.00.001This command was introduced
sntp poll-interval
CommandTo set the time interval that SNTP synchronizes the time on SNTP server.
sntp poll-interval
Syntax Descriptionseconds (30-86400)Specify the time interval that SNTP synchronizes the time on SNTP server.
Default Settings30 seconds
Command ModesGlobal Configuration Mode
Exampleswitch(config)# sntp poll-interval 3600
Command HistoryVersionHistory
1.00.001This command was introduced
sntp primary-ip

To set the primary SNTP server IP address.

Commandsntp primary-ip
Syntax Descriptionip-addressSpecify the IP address of the primary SNTP server.
Command ModesGlobal Configuration Mode
Exampleswitch(config)# sntp primary-ip 172.17.5.254
Command HistoryVersionHistory
1.00.001This command was introduced
sntp secondary-ip
CommandTo set the secondary SNTP server IP address.
sntp secondary-ip
Syntax Descriptionip-addressSpecify the IP address of thesecondary SNTP server.
Command ModesGlobal Configuration Mode
Exampleswitch(config)# sntp secondary-ip 172.17.5.253
Command HistoryVersionHistory
1.00.001This command was introduced
sntp timezone
CommandTo determine the time zone used in order to adjust the system clock.
sntp timezone offset [-]
Syntax DescriptionoffsetThe adjustment for time zone relative to GMT.
-To subtract time to GMT.
hour (0-13)Specify the number of hours different from GMT.
minute (0-59)Specify the number of minutes different from GMT.
Command ModesGlobal Configuration Mode
Exampleswitch(config)#sntptimezone offset - 8 0
Command HistoryVersionHistory
1.00.001This command was introduced
show clock
CommandTo display the system date and time.
show clock
Command ModesPrivileged EXEC Mode
Exampleswitch#show clockWed Dec 23 18:04:11 2009
Command HistoryVersionHistory
1.00.001This command was introduced
show sntp
CommandTo display current SNTP settings.
show sntp
Command ModesPrivileged EXEC Mode
Exampleswitch#show sntpSNTP Information----SNTP status : DisabledPoll interval(Sec) : 30 sec.Primary server IP : 0.0.0.0Secondary server IP : 0.0.0.0Current Time : 01 Jan 2009 00:36:47Time Zone offset : +00:00SNTP DST status : DisabledDST from : Jan 01 00:00DST to : Jan 01 00:00
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 22

Configuration Command

Configuration Command List

write
CommandTo save the running configuration.
write { flash:filename | startup-config | tftp://ip-address/filename}
Syntax Descriptionflash:filenameWrite to a designated flash driver with designated file name.
startup-configWrite to start up configuration.
tftp://ip-address /filenameWrite to a remote TFTP site with designated file name.
Command ModesPrivileged EXEC Mode
Exampleswitch# write start-config
Command HistoryVersionHistory
1.00.001This command was introduced

copy startup-config

CommandTo backup the startup configuration to NV-RAM or a remote site.
copy startup-config { flash: filename | tftp://ip-address/filename}
Syntax Descriptionflash:filenameCopy to a designated flash driver with designated file name.
tftp://ip-address /filenameCopy to a remote TFTP site with designated file name.
Command ModesPrivileged EXEC Mode
Exampleswitch# copy startup-config flash:backupstarup
Command HistoryVersionHistory
1.00.001This command was introduced
copy
CommandTo replace the startup configuration by a another configuration file in remote TFTP site or NV-RAM.
copy { tftp://ip-address/filename startup-config | flash: filename startup-config }
Syntax Descriptiontftp://ip-address /filename startup-configSpecify the URL and file name of the remote configuration file.
flash: filename startup-configSpecify the driver and file name of the local configuration file.
Command ModesPrivileged EXEC Mode
Exampleswitch# copy flash:backupstarup startup-config
Command HistoryVersionHistory
1.00.001This command was introduced
erase
CommandTo reset the startup configuration, NV-RAM or the configuration file in flash to default value.
erase { startup-config | nvram: | flash:filename}
Syntax Descriptionstartup-configTo reset startup configuration to default.
nvram:To reset the NV-RAM to default.
flash:filenameTo reset the configuration file in flash to default.
Command ModesPrivileged EXEC Mode
Exampleswitch# erase startup-config
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 23

Firmware Upgrade Command

Firmware Upgrade Command List

- archive download-sw /overwrite

archive download-sw /overwrite

CommandTo download the image from a TFTP server.
archive download-sw /overwrite tftp://ip-address/filename
Syntax Descriptiontftp://ip-address /filenameSpecify the URL of the image file.
Command ModesPrivileged EXEC Mode
Exampleswitch# archive download-sw /overwrite tftp://172.17.5.111/image.hex
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 24

Reboot Command

Reboot Command List

reload
CommandReboot the Switch
reload
Command ModesPrivileged EXEC Mode
Exampleswitch# reload
Command HistoryVersion History
1.00.001 This command was introduced
NoteIf the Switch reboots without write the running configurations, the last configuration wrote in NV-RAM will be loaded.

Chapter 25

Port Manager Command

Port Manager Command List

  • monitor session
  • negotiation
    speed
  • duplex
  • flowcontrol
    ■ mdi
    ■ show flow-control
    ■ show mdi-mdix
    ■ show port-monitoring

monitor session

To enable and configure the port mirroring function.

Command

monitor session [session_number 1-1] { destination interface <interface-type> <interface-id> | source interface <interface-type> <interface-id> { rx | tx | both } } 
no monitor session [session_number 1-1] { destination interfa
<interface-type> <interface-id> | source interface
<interface-type> <interface-id> } 

Syntax Description

session_number 1-1Specify the ID of the mirror session.
destination interfaceinterface-typeinterface-idSpecify the destination port of the mirror session.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
source interfaceinterface-typeinterface-idSpecify the source port of the mirror session.Interface information including interface-type: Fa (Fast Ethernet) or Gi (Gigabit Ethernet), and slot/port number.
rxMonitoring the traffic received from the source port.
txMonitoring the traffic transmitted from the source port.
bothMonitoring the traffic both received and transmitted from the source port.

Default Settings

Disable

Command ModesGlobal Configuration Mode
User Guidelines1. Using no form to disable the port mirroring function.2. Destination port and source port have to be counfigured separately.3. A port-channel can be mirrored, however, a port-channel port cannot.
Exampleswitch(config)#monitor session 1 destination interface fa 0/switch(config)#monitor session 1 source interface fa 0/2 bot
Command HistoryVersionHistory
1.00.001This command was introduced
negotiation
CommandTo enable auto-negotiation function to ports.
negotiation
no negotiation
Command ModesInterface Configuration Mode
User GuidelinesThe configured port speed, duplex mode, and flow control only take effect when auto-negotiation disabled.
Exampleswitch(config-if)#no negotiation
Command HistoryVersionHistory
1.00.001This command was introduced
speed
CommandTo set the port speed.
speed { 10 | 100 | 1000 }
Syntax Description10Port runs at 10Mbps.
100Port runs at 100Mbps.
1000Port runs at 1000Mbps.
Default SettingsThe N-way result with link partner.
Command ModesInterface Configuration Mode
User GuidelinesThe configured port speed and duplex settings only takes effect when auto-negotiation disabled.
Exampleswitch(config-if)# speed 100
Command HistoryVersionHistory
1.00.001This command was introduced
duplex
CommandTo set the port duplex mode.
duplex { full | half }
Syntax DescriptionfullPort runs at full duplex mode.
halfPort runs at half duplex mode.
Default SettingsFull
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# duplex half
Command HistoryVersionHistory
1.00.001This command was introduced
flowcontrol
CommandTo enable/disable 802.3x flow control on ports.
flowcontrol { on | off }
Syntax DescriptiononEnable flow control.
offDisable flow control.
Default SettingsOff
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# flowcontrol on
Command HistoryVersionHistory
1.00.001This command was introduced
mdi
CommandTo set MDI or MDIX mode for ports.
mdi { auto | mdi | mdix }
Syntax DescriptionautoPort performs the auto MDI/MDIX function.
mdiPort fixed at MDI mode.
mdixPort fixed at MDIX mode.
Default SettingsAuto
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# mdi mdi
Command HistoryVersionHistory
1.00.001This command was introduced
show flow-control
CommandTo display the flow control settings and statistics of interfaces.
show flow-control [interface]
Syntax DescriptioninterfaceSpecify which interface to show flow-control settings.
interface-typeInterface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).
interface-idInterface-id is slot/port number.
Command ModesPrivileged EXEC Mode
Exampleswitch# show flow-control int fa 0/2
Port Tx FlowControl Rx FlowControl Tx Pause RxPause
Fa0/2 off off 0 0
Command HistoryVersionHistory
1.00.001This command was introduced

show mdi-mdix

CommandTo display the MDI/MDIX setting on ports.show mdi-mdix [interface]
Syntax Descriptioninterface interface-type interface-idSpecify which interface to show MDI/MDIX setting Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display MDI/MDIX setting for all ports when executing the command without port parameter.
Exampleswitch# show mdi-mdix
Fa0/1 AUTO/MDI/MDIX is auto
Fa0/2 AUTO/MDI/MDIX is auto
Fa0/3 AUTO/MDI/MDIX is auto
Fa0/4 AUTO/MDI/MDIX is auto
Fa0/5 AUTO/MDI/MDIX is auto
Fa0/6 AUTO/MDI/MDIX is auto
Fa0/7 AUTO/MDI/MDIX is auto
Fa0/8 AUTO/MDI/MDIX is auto
Fa0/9 AUTO/MDI/MDIX is auto
Fa0/10 AUTO/MDI/MDIX is auto
Fa0/11 AUTO/MDI/MDIX is auto
Fa0/12 AUTO/MDI/MDIX is auto
Fa0/13 AUTO/MDI/MDIX is auto
Fa0/14 AUTO/MDI/MDIX is auto
Fa0/15 AUTO/MDI/MDIX is auto
Fa0/16 AUTO/MDI/MDIX is auto
Fa0/17 AUTO/MDI/MDIX is auto
Fa0/18 AUTO/MDI/MDIX is auto
Fa0/19 AUTO/MDI/MDIX is auto
Fa0/20 AUTO/MDI/MDIX is auto
Fa0/21 AUTO/MDI/MDIX is auto
Fa0/22 AUTO/MDI/MDIX is auto
Fa0/23 AUTO/MDI/MDIX is auto
Fa0/24 AUTO/MDI/MDIX is auto
Gi0/1 AUTO/MDI/MDIX is auto
Gi0/2 AUTO/MDI/MDIX is auto
Gi0/3 AUTO/MDI/MDIX is auto
Gi0/4 AUTO/MDI/MDIX is auto
Command HistoryVersionHistory
1.00.001This command was introduced

show port-monitoring

To display the port monitoring settings.

Commandshow port-monitoring
Command ModesPrivileged EXEC Mode
Exampleswitch# show port-monitoring
Port Monitoring is enabledMonitor Port : Fa0/9
PortIngress-MonitoringEgress-Monitoring
Fa0/1EnabledEnabled
Fa0/2DisabledDisabled
Fa0/3DisabledDisabled
Fa0/4DisabledDisabled
Fa0/5DisabledDisabled
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 26

VLAN Command

VLAN Command List

vlanswitchport acceptable-frame-typeswitchport ingress-filterswitchport pvidportsdebug vlanshow vlanshow vlan device infoshow vlan port config
vlan
CommandTo create a VLAN or enter a VLAN interface configured.vlan
no vlan
Syntax Descriptionvlan-id(1-4094) Specify the VLAN ID to create or enter.
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to delete a VLAN.
Exampleswitch(config)#vlan 100switch(config-vlan)#
Command HistoryVersion History
1.00.001 This command was introduced

switchport acceptable-frame-type

To configure the acceptable frame type of a port.
Commandswitchport acceptable-frame-type {all | tagged | untaggedAndPrioritytagged}
no switchport acceptable-frame-type
Syntax DescriptionallAccepts all kinds of frames.
taggedAccepts only tagged frames
untaggedAndPrioritytaggedAccepts only untagged frames and frames with priority tag.
Default Settingsall
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# switchport acceptable-frame-type tagged
Command HistoryVersionHistory
1.00.001This command was introduced

switchport ingress-filter

To filter all ingress packets which do not carry the same VLAN tag with the VLAN membership of the port.
Commandswitchport ingress-filter
no switchport ingress-filter
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to disable the ingress filtering of the port
Exampleswitch(config-if)# switchport ingress-filter
Command HistoryVersionHistory
1.00.001This command was introduced

switchport pvid

To set the port VLAN ID of the port, all ingress untagged or priority tagged packet from this port will be assign to this VLAN.
Commandswitchport pvid
no switchport pvid
Syntax Descriptionvlan-id(1-4094) Specify the PVID of the port.
Default Settings1
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# switchport pvid 100
Command HistoryVersion History
1.00.001 This command was introduced
ports
CommandTo apply the VLAN membership to ports or port-channels.
ports ([] <0/a-b,0/c,...>)[<0/a-b,0/c,...>] [port-channel]) [untagged(<0/a-b,0/c,...>][<0/a-b,0/c,...>][[port-channel] [all]] [forbidden<0/a-b,0/c,...>][[port-channel]] [name]
Syntax Descriptioninterface-type 0/a-b,0/c,...Specify the ports to apply the VLAN membership. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
port-channel a,b,c-dSpecify the port-channels to apply the VLAN membership.
untaggedApply untagged membership to interfaces.
allApply untagged membership to all interfaces.
forbiddenApply forbidden membership to interfaces.
name vlan-nameSpecify the name of this VLAN.
Default SettingsThe default port membership is tagged.
Command ModesConfig-vlan Mode
User GuidelinesThe untagged port must be the subset of member port.
Exampleswitch(config-vlan)# ports fa 0/1-5 untagged fa 0/5 forbidden fa 0/7 name trendnet
Command HistoryVersion History
1.00.001 This command was introduced

debug vlan

CommandTo enable the debug mode for VLAN.
debug vlan { global | [{fwd | priority | redundancy} [initsh [mgmt] [data] [ctpl] [dump] [os] [failall] [buffer] [all]]}
no debug vlan { global | [{fwd | priority | redundancy} [initshut] [mgmt] [data] [ctpl] [dump] [os] [failall] [buffer [all]]}
Syntax DescriptionglobalDisplays the global debug messages for multiple instances.
fwdDisplays the forwarding debug messages.
priorityDisplays the VLAN priority debug messages.
redundancyDisplays the redundancy related debug messages.
initshutDisplays the initial and shutdown debug messages.
mgmtDisplays the management related debug messages.
dataDisplays the data path debug messages.
ctplDisplays the control plan debug messages.
dumpDisplays the packet dump debug messages.
osDisplays the debug messages for all resources except buffer.
failallDisplays the all failure messages.
bufferDisplays the buffer debug messages.
allDisplays all debug messages.
Default SettingsDisable
Command ModesPrivileged EXEC Mode
User GuidelinesUsing no form the disable debug mode.
Exampleswitch# debug vlan all
Command HistoryVersionHistory
1.00.001This command was introduced
show vlan

To display the VLAN member port information and VLAN number.

Command
show vlan [brief | id | summary]

Syntax DescriptionbriefDisplay the brief of VLAN information.
idLimited a range of VLAN to display the information.The vlan-range format is a-b, b should be larger than a.
summaryDisplay the number of VLAN.

Command Modes
Privileged EXEC Mode
User Guidelines
System will display all the VLAN brief information when executing the command without any parameter.

Example

Single Instance:

switch# show vlan brief

Vlan database

Vlan ID : 1

Member Ports : Fa0/1, Fa0/2, Fa0/3, Fa0/4, Fa0/5, Fa0/Fa0/7, Fa0/8, Fa0/9, Fa0/10, Fa0/11, FaFa0/13, Fa0/14, Fa0/15, Fa0/16, Fa0/17,Fa0/18, Fa0/19, Fa0/20, Fa0/21, Fa0/22,Fa0/23, Fa0/24Gi0/1, Gi0/2, Gi0/3, Gi0/4

Untagged Ports : Fa0/1, Fa0/2, Fa0/3, Fa0/4, Fa0/5, Fa0/Fa0/7, Fa0/8, Fa0/9, Fa0/10, Fa0/11, FaFa0/13, Fa0/14, Fa0/15, Fa0/16, Fa0/17,Fa0/18, Fa0/19, Fa0/20, Fa0/21, Fa0/22,Fa0/23, Fa0/24Gi0/1, Gi0/2, Gi0/3, Gi0/4

Forbidden Ports : None

Name :

Status : Permanent

switch# show vlan summary

Number of vlans : 1

Multiple Instance:

switch# show vlan

Switch - default

Vlan database

Vlan ID : 1

Member Ports : Gi0/1

Untagged Ports : Gi0/1

Forbidden Ports : None

Name :

Status : Permanent

Switch - cust1

Vlan database

Vlan ID : 1

Member Ports : Fa0/1, Fa0/2, Fa0/3, Fa0/4, Fa0/5

Untagged Ports : Fa0/1, Fa0/2, Fa0/3, Fa0/4, Fa0/5

Forbidden Ports : None

Name :

Status : Permanent

Vlan ID : 2

Member Ports : Gi0/1

Untagged Ports : None

Forbidden Ports : None

Name :

Status : Dynamic Gvrp

Command History

Version

History

1.00.001

This command was introduced

show vlan device info

To display the VLAN settings and detailed information of the device.
Commandshow vlan device info
Command ModesPrivileged EXEC Mode

Example

Single Instance:

switch# show vlan device info

Vlan device configurations

Vlan Status: Enabled
Vlan Oper status: Enabled
Gvrp status: Disabled
Gvrp Oper status: Disabled
Bridge Mode: Customer Bridge
Traffic Classes: Enabled
Vlan Operational Learning Mode: IVL
Version number: 1
Max Vlan id: 4095
Max supported vlans: 256

Multiple Instance:

switch# show vlan device info

Switch default

Vlan device configurations

Vlan Status : Enabled

Vlan Oper status : Enabled

Gvrp status : Enabled

Gmrp status : Disabled

Gvrp Oper status : Enabled

Gmrp Oper status : Disabled

Mac-Vlan Status : Disabled

Protocol-Vlan Status : Enabled

Bridge Mode : Provider Edge

Bridge

Traffic Classes : Enabled

Vlan Operational Learning Mode : IVL

Version number : 1

Max Vlan id : 4094

Max supported vlans : 1024

Command History

Version

History

1.00.001

This command was introduced

show vlan port config

To display the VLAN configurations of ports.

Command

show vlan port config [{port }]

Syntax Description

port interface-type

interface-id

Specify which port to show VLAN configurations.

Interface-type including Fa (Fast Ethernet) or Gi

(Gigabit Ethernet).

Interface-id is slot/port number.

Command Modes

Privileged EXEC Mode

User Guidelines

System will display VLAN configurations for all port when executing the command without a port parameter.

Example

Single Instance:

switch# show vlan port config port fa 0/1

Vlan Port configuration table

Port Fa0/1

Port Vlan ID : 1
Port Acceptable Frame Type : Admit All
Port Ingress Filtering : Enabled
Port Mode : Hybrid
Port Gvrp Status : Enabled
Port Gvrp Failed Registrations : 0
Gvrp last pdu origin : 00:00:00:00:00:00
Port Restricted Vlan Registration : Disabled
Default Priority : 0 

Multiple Instance:

switch# show vlan port config

Switch - default

Vlan Port configuration table

Port Fa0/1

Port Vlan ID : 1

Port Acceptable Frame Type : Admit All

Port Ingress Filtering : Disabled

Port Mode : Hybrid

Port Gvrp Status : Enabled

Port Gmrp Status : Enabled

Port Gvrp Failed Registrations : 0

Gvrp last pdu origin : 00:00:00:00:00:00

Port Restricted Vlan Registration : Disabled

Port Restricted Group Registration : Disabled

Mac Based Support : Disabled

Port-and-Protocol Based Support : Enabled

Default Priority : 0

Switch - cust1

Vlan Port configuration table

Port Fa0/2

Port Vlan ID : 20

Port Acceptable Frame Type : Admit All

Port Ingress Filtering : Disabled

Port Mode : Hybrid

Port Gvrp Status : Enabled

Port Gmrp Status : Enabled

Port Gvrp Failed Registrations : 0

Gvrp last pdu origin : 00:00:00:00:00:00

Port Restricted Vlan Registration : Disabled

Port Restricted Group Registration : Disabled

Mac Based Support : Disabled

Port-and-Protocol Based Support : Enabled

Default Priority : 0

Port Fa0/3
Port Vlan ID : 1
Port Acceptable Frame Type : Admit All
Port Ingress Filtering : Disabled
Port Mode : Hybrid
Port Gvrp Status : Enabled
Port Gmrp Status : Enabled
Port Gvrp Failed Registrations : 0
Gvrp last pdu origin : 00:25:64:93:1c:35
Port Restricted Vlan Registration : Disabled
Port Restricted Group Registration : Disabled
Mac Based Support : Disabled
Port-and-Protocol Based Support : Enabled
Default Priority : 0 

Command History

VersionHistory
1.00.001This command was introduced

Chapter 27

Dynamic VLAN Command

Dynamic VLAN Command List

set gvrpset port gvrpset garp timervlan restrictedshutdown garpdebug garpshow garp timer
set gvrp
CommandTo global enable/disable GVRP function.
set gvrp { enable | disable }
Syntax DescriptionenableEnables GVRP globally.
disableDisable GVRP globally.
Default SettingsEnable
Command ModesGlobal Configuration Mode
Exampleswitch(config)# set gvrp disable
Command HistoryVersionHistory
1.00.001This command was introduced
set port gvrp
CommandTo enable/disable gvrp on specific ports.
set port gvrp{ enable | disable }
Syntax Descriptioninterface-type interface-idSpecify which port to enable GVRP function. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
enableEnables GVRP on the port.
disableDisables GVRP on the port.
Default SettingsEnable
Command ModesGlobal Configuration Mode
User GuidelinesIf port GVRP is disabled, but global GVRP is enabled, any GVRP packet received by this port will be discarded and no GVRP registrations will be propagated from other ports
Exampleswitch(config)# set port gvrp fa 0/1 disable
Command HistoryVersionHistory
1.00.001This command was introduced
set garp timer
CommandTo set the GARP timers on an interface.
set garp timer {join|leave| leaveall}
Syntax Descriptionjoinspecify the join time of GARP seconds(10-1073741810)
leaveSpecify the leave time of GARP seconds(30-2147483630)
leaveallSpecify the leaveall time of GARP seconds(40-2147483640)
Default SettingsJoin - 20 Leave - 60 Leaveall - 100
Command ModesInterface Configuration Mode
User Guidelines1. Leave timer must be greater than 2 times join time. 2. Leaveall time must be greater than Leave time
Exampleswitch(config-if)# set garp timer join 50
Command HistoryVersionHistory
1.00.001This command was introduced

vlan restricted

CommandTo enable/disable the restricted VLAN on an interface.
vlan restricted {enable | disable}
Syntax DescriptionenableEnalbes VLAN restriction.
disableDisables VLAN restriction.
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesWhen a port enables VLAN restriction, only static configured VLAN can be learnt from this interface.
Exampleswitch (config-if) # vlan restricted enable
Command HistoryVersionHistory
1.00.001This command was introduced
shutdown garp
CommandTo shutdown GARP function.
shutdown garp
no shutdown garp
Default SettingsEnable
Command ModesGlobal Configuration Mode
User Guidelines1. GARP cannot be activated if VLAN is shutdown.2. GARP cannot be shutdown if GVRP or GMRP is activated.
Exampleswitch (config) # shutdown garp
Command HistoryVersionHistory
1.00.001This command was introduced

debug garp

CommandTo enable the debug mode of GARP function.
debug garp { global | [{protocol | gvrp | redundancy} [inits [mgmt] [data] [ctl] [dump] [os] [failall] [buffer] [all]]}
no debug garp { global | [{protocol | garp | redundancy} [initshut] [mgmt] [data] [ctl] [dump] [os] [failall] [buffer] [all]]
Syntax DescriptionglobalDisplays the global GARP debug messages for multiple instances.
protocolDisplays the protocol related debug messages.
GvrpDisplays the GVRP related debug messages.
RedundancyDisplays the redundancy related debug messages.
InitshutDisplays the initial and shutdown debug messages.
MgmtDisplays the management related debug messages.
DataDisplays the data path debug messages.
CtplDisplays the control plane debug messages.
dumpDisplays the packet dump debug messages.
OsDisplays the debug messages for all resources except buffer.
FailallDisplays the all failure messages.
BufferDisplays the buffer debug messages.
allDisplays all debug messages.
Default SettingsDisable
Command ModesPrivileged EXEC Mode
Exampleswitch#
Command HistoryVersionHistory
1.00.001This command was introduced
show garp timer
CommandTo display the port timer settings.
show garp timer [{ port}]
Syntax Descriptionportinterface-typeinterface-idSpecify which port to show GVRP timer setting.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display timer settings for all port when executing the command without a port parameter.
Exampleswitch# show garp timer port fa 0/1
Garp Port Timer Info (in milli seconds)
PortJoin-timeLeave-timeLeave-all-time
Fa0/120060010000
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 28

RSTP Command

RSTP Command List

▪ spanning-tree▪ spanning-tree compatibility▪ spanning-tree mode▪ spanning-tree pathcost dynamic▪ spanning-tree transmit hold-count▪ spanning-tree timers▪ spanning-tree auto-edge▪ spanning-tree restricted-role▪ spanning-tree restricted-tcn▪ spanning-tree interface attributes▪ shutdown spanning-tree▪ clear spanning-tree counters▪ debug spanning-tree▪ show spanning-tree▪ show spanning-tree active▪ show spanning-tree bridge▪ show spanning-tree interface▪ show spanning-tree root
spanning-tree
CommandTo enable spanning tree function.
spanning-tree
no spanning-tree
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to disable STP.
Exampleswitch (config)# spanning-tree
Command HistoryVersion History
1.00.001 This command was introduced
spanning-tree compatibility

To set the spanning tree compatibility version.

Commandspanning-tree compatibility {stp|rst|mst}
no spanning-tree compatibility
Syntax DescriptionstpCompatible with STP.
rstCompatible with RSTP.
mstCompatible with MSTP.
Default Settingsrst
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the STP compatibility to default.
Exampleswitch(config)# spanning-tree compatibility stp
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree mode

CommandTo choose the spanning tree opreation mode.
spanning-tree mode {mst|rst}
Syntax DescriptionmstOperates with MSTP mode.
rstOperates with RSTP mode
Default Settingsrst
Command ModesGlobal Configuration Mode
User GuidelinesIf the configured mode is not the same with current running mode, spanning tree will be shutdown and restart.
Exampleswitch(config)# spanning-tree mode mst
switch(config)# spanning-tree mode rst
Spanning Tree protocol enabled is MST. Now MST is being shut and RST is being enabled
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree pathcost dynamic

CommandTo enable the dynamic pathcost according to the port speed.. spanning-tree pathcost dynamic no spanning-tree pathcost dynamic
Default SettingsDisable
Command ModesGlobal Configuration Mode
User Guidelines1. If the cost has been configured on a CIST or a RSTP interface, then this command won't take effect on those interfaces. 2. If the cost has been configured on a port of MST instance, then this command won't take effect on that instance. However, the pathcost of all the other instances on the same port will still be calculated dynamically. 3. Using no form to disable the dynamic pathcost function.
Exampleswitch(config)# spanning-tree pathcost dynamic
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree transmit hold-count

CommandTo set a hold counter to limit maximum transmission rate of the Switch. spanning-tree transmit hold-countno spanning-tree transmit hold-count
Syntax Descriptionvalue (1-10)Specify the value of hold counter.
Default Settings3
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the hold count to default.
Exampleswitch(config)# spanning-tree transmit hold-count 10
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree timers

CommandTo set the timer of spanning tree.
spanning-tree {forward-time <seconds(4-30)> | hello-time<seconds(1-2)> | max-age <seconds(6-40)>}
no spanning-tree { forward-time | hello-time | max-age }
Syntax Descriptionforward-timeseconds (4-30)The time period that a port changes the STP state from blocking to forwarding.
hello-timeseconds (1-2)Time interval for a root bridge broadcasts the hello packets to other switches.
max-ageseconds (6-40)The maximum age for STP information learned from the network on any port before it is discarded
Default SettingsForward-time - 15 secondsHello-time - 2 secondsMax-age - 20 seconds
Command ModesGlobal Configuration Mode
User Guidelines1. The relationship between these timer must follow this formula:2 x (Forward-time - 1) >= Max-ageMax-Age >= 2 x (Hello-time +1)2. Using no form to reset the timer to default.
Exampleswitch(config)# spanning-tree forward-time 10
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree auto-edge

To enable the auto-detection of a port.
Commandspanning-tree auto-edge
no spanning-tree auto-edge
Default SettingsEnable
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to disable the auto-edge function.
Exampleswitch(config-if)# spanning-tree auto-edge
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree restricted-role

CommandTo enable the root guard function to prevent the port becoming a root port.
spanning-tree restricted-role
no spanning-tree restricted-role
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to disable the root guard function.
Exampleswitch(config-if)# spanning-tree restricted-role
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree restricted-tcn

To enable the topology change guard function to prevent the topology change caused by this port.
Commandspanning-tree restricted-tcn
no spanning-tree restricted-tcn
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to disable the topology change guard function.
Exampleswitch(config-if)# spanning-tree restricted-tcn
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree interface attributes

CommandTo set detailed spanning attributes to ports.
spanning-tree {cost| disable | link-type{point-to-point | shared} | portfast | port-priority}
no spanning-tree {cost | disable | link-type | portfaport-priority}
Syntax Descriptioncostvalue(0-200000000)Specify the pathcost of this port.
disableDisbles spanning tree on this port.
link-typepoint-to-pointSpecify the port link type is point to point.
link-type sharedSpecify the port connects to a LAN which hasanother bridge.
portfastSpecify the port connects to host
port-priorityvalue(0-240)Speficy the port STP priority.
Default SettingsCost - 2000000Portfast - Not in portfastLink-type - SharedPort-priority - 128
Command ModesInterface Configuration Mode
User Guidelines1. A portfast port will change to forwarding quickly during STP convergence, sothat it can speed up the STP convergence.2. Using no form to reset the port attributes to default.
Exampleswitch(config-if)# spanning-tree cost 100
Command HistoryVersion History
1.00.001 This command was introduced

shutdown spanning-tree

To shutdown the spanning tree function.
Commandshutdown spanning-tree
Command ModesGlobal Configuration Mode
User GuidelinesMSTP and RSTP are exclusive to each other, so that spanning tree function must be shutdown when changing the STP operation mode.
Exampleswitch(config)# shutdown spanning-tree
Command HistoryVersionHistory
1.00.001This command was introduced

clear spanning-tree counters

To clear the spanning tree counters.
Commandclear spanning-tree counters
Command ModesGlobal Configuration Mode
Exampleswitch(config)# clear spanning-tree counters
Command HistoryVersionHistory
1.00.001This command was introduced

debug spanning-tree

CommandTo enable the debug mode for spanning tree function.
debug spanning-tree { global | { all | errors | init-shut | management | memory | bpdu | events | timer | state-machine { port-info | port-rcieve | port-role-selection | role-transition | state-transition | protocol-migration | topology-change | port-transmit | bridge-detection } redundancy | sem-variables}
no debug spanning-tree {global | {all | errors | init-shut | management | memory | bpdu |events | timer | state-machine {port-info | port-rcieve | port-role-selection | role-transition | state-transition | protocol-migration | topology-change | port-transmit | bridge-detection } redundancy | sem-variables}

Syntax Description

globalDisplays the MSTP global debug messages.
allDisplays all RSTP/MSTP debug messages.
errorsDisplays the error code debug messages.
init-shutDisplays the initial and shutdown debug messages.
managementDisplays the management related debug messages.
memoryDisplays the memory related debug messages.
bpduDisplays the BPDU related debug messages.
eventsDisplays the events related debug messages.
timerDisplays the timer related debug messages.
state-machineDisplays the state-machine related debug messages.
port-infoDisplays the port information messages.
port-recieveDisplays the port received messages.
port-role-selectionDisplays the port role selection messages.
role-transitionDisplays the role transition messages.
state-transitionDisplays the state transition messages.
protocol-migrationDisplays the protocol migration messages.
topology-changeDisplays the topology change messages.
port-transmitDisplays the port transmission messages.
bridge-detectionDisplays the bridge detection messages.
redundancyDisplays the redundancy related messages.
sem-variablesDisplays the state-mechine variable's debug messages.

Default Settings

Disable

Command Modes

Privileged EXEC Mode

User Guidelines

Using no form to disable the debug mode.

Example

switch# debug spanning-tree all

Command History

VersionHistory
1.00.001This command was introduced

show spanning-tree

CommandTo display the spanning port states, statistics, settings and detailed information.
show spanning-tree [{ summary | blockedports | pathcos method }]
Syntax DescriptionsummaryDisplay the summary of port states.
blockedportsDisplay current block port number.
pathcost methodDisplay the pathcost method setting.
Command ModesPrivileged EXEC Mode

Example

Single Instance:

switch# show spanning-tree
Root IdPriority 32768
Address 00:18:8b:bf:75:30
Cost 0
Port 0 [0]
This bridge is the root
Max age 20 Sec, forward delay 15 Sec
Spanning tree Protocol Enabled
Bridge IdPriority 32768
Address 00:18:8b:bf:75:30
Hello Time 2 sec, Max Age 20 sec, Forward Del
15 sec
Dynamic Path Cost is Enabled
NameRoleStateCostPrioType
------------------------
Fa0/1DesignatedForwarding200000128SharedLan
Fa0/2DesignatedForwarding200000128SharedLan
Fa0/3DesignatedForwarding200000128SharedLan
Fa0/4DisabledDiscarding200000128SharedLan

switch# show spanning-tree summary

Spanning Tree port pathcost method is Long

Spanning tree enabled protocol is RSTP

RSTP Port Roles and States

Port-IndexPort-RolePort-StatePort-Status
1DisabledDiscardingEnabled
2DisabledDiscardingEnabled
3DisabledDiscardingEnabled
4RootForwardingEnabled

switch# show spanning-tree blockedports

Blocked Interfaces List:

The Number of Blocked Ports in the system is :1

switch# show spanning-tree pathcost method

Spanning Tree port pathcost method is Long

Multiple Instance:

switch# show spanning-tree

Root IdPriority32768
Address00:18:8b:bf:75:30
Cost 0
Port 0 [0]
This bridge is the root

Max age 20 Sec, forward delay 15 Sec

MST00

Spanning tree Protocol Enabled

S-VLAN Component: MST00 is executing the mstp compatib Multiple Spanning Tree Protocol Bridge Id Priority 32768 Address 00:18:8b:bf:75:30 Hello Time 2 sec, Max Age 20 sec, Forward Del 15 sec

Dynamic Path Cost is Enabled
NameRoleStateCostPrioType
Fa0/1DesignatedForwarding200000128SharedLan
Fa0/2DesignatedForwarding200000128SharedLan
Fa0/3DesignatedForwarding200000128SharedLan
Fa0/4DisabledDiscarding200000128SharedLan

switch# show spanning-tree summary

Switch - default

Spanning Tree port pathcost method is Long Spanning tree enabled protocol is MSTP

MST00 Port Roles and States Port-Index Port-Role Port-State Port-Status 49 Disabled Forwarding Disabled

Switch - cust1

Spanning Tree port pathcost method is Long Spanning tree enabled protocol is MSTP

MST00 Port Roles and States
Port-IndexPort-RolePort-StatePort-Status
1DesignatedForwardingEnabled
2RootForwardingEnabled
3DesignatedForwardingEnabled
4DisabledDiscardingEnabled

Switch - cust2

Spanning Tree port pathcost method is Long Spanning tree enabled protocol is MSTP MST00 Port Roles and States Port-Index Port-Role Port-State Port-Status 5 Designated Forwarding Enabled 6 Root Forwarding Enabled 7 Alternate Discarding Enabled 8 Disabled Discarding Enabled

Command History

VersionHistory
1.00.001This command was introduced

show spanning-tree active

CommandTo display the spanning tree information on active ports.show spanning-tree active [detail]
Syntax DescriptiondetailDisplay the details of spanning tree bridge.
Command ModesPrivileged EXEC Mode

Example

Single Instance:

switch# show spanning-tree active
Root Id Priority 8192
Address 00:74:24:00:01:00
Cost 2000000
Port Fa0/1
Hello Time 2 Sec, Max Age 20 Sec, Forward Delay 15 Sec
Spanning Tree Enabled Protocol RSTP
Bridge Id Priority 32768
Address 00:18:8b:bf:75:30
Hello Time 2 sec, Max Age 20 sec, Forward Delay 15
Name Role State Cost Prio Type
---- ---- ---- ---- ----
Fa0/1 Root Forwarding 2000000 128 SharedLan 

switch# show spanning-tree active detail

Spanning tree Protocol has been disabled
Bridge Identifier has priority 32768, Address 00:74:24:00:01:
Configured Hello time 2 sec, Max Age 20 sec, Forward Delay 15 sec
Dynamic Path Cost Enabled
Number of Topology Changes 0
Time since topology Change 0 seconds ago
Transmit Hold-Count 6
Max Age 20 Sec, Forward Delay 15 Sec
Hello Time 2 Sec 

Multiple Instance:

switch# show spanning-tree active switch default

Switch default

Root Id Priority 32768
Address 00:51:02:03:04:05
Cost 0
Port 0 [0] 

This bridge is the root Max age 20 Sec, forward delay 15 Sec

MST00

MST00 is executing the mstp compatible Multiple Spanning Tree Protocol
Bridge Id Priority 32768
Address 00:51:02:03:04:05
Max age is 20 sec, forward delay is 15 sec
Name Role State Cost Prio Type
---- ---- ---- ---- ----
Fa0/1 Root Forwarding 2000000 128 SharedLan 

Command History

Version History

1.00.001 This command was introduced

show spanning-tree bridge

CommandTo display the spanning tree bridge settings.
show spanning-tree bridge [{ address | forward-time | hello-t | id |max-age | protocol | priority | detail }]
Syntax DescriptionaddressDisplay the MAC address of spanning tree bridge.
forward-timeDisplay the current setting of spanning tree forward time.
hello-timeDisplay the current setting of spanning tree hello time.
idDisplay the spanning tree bridge ID.
max-ageDisplay the current setting of spanning tree max-age.
protocolDisplay the current setting of spanning tree protocol.
priorityDisplay the current setting of spanning tree bridge priority.
detailDisplay the spanning tree bridge details.

Command Modes

Privileged EXEC Mode

Example

Single Instance:

switch# show spanning-tree bridge

Bridge IDHelloTimeMaxAgeFwdDlyProtocol
80:00:00:74:24:00:01:0020200015rstp

switch# show spanning-tree bridge address

Bridge Address is 00:74:24:00:01:00

switch# show spanning-tree bridge forward-time

Bridge Forward delay is 15 sec

switch# show spanning-tree bridge hello-time

Bridge Hello Time is 2 sec

switch# show spanning-tree bridge id

Bridge ID is 80:00:00:74:24:00:01:00

switch# show spanning-tree bridge max-age

Bridge Max Age is 20 sec

switch# show spanning-tree bridge protocol

Bridge Protocol Running is RSTP

switch# show spanning-tree bridge priority

Bridge Priority is 32768

switch# show spanning-tree bridge detail

Bridge IdPriority 32768,Address 00:74:24:00:01:00Hello Time 2 sec, Max Age 20 sec, Forward Delay15 sec

Multiple Instance:

switch# show spanning-tree bridge

Switch - default
MST Instance Bridge IDMaxAge FwdDly Protocol
MST0080:00:00:74:24:00:01:002015 mstp
Switch - cust1
MST Instance Bridge IDMaxAge FwdDly Protocol
MST0080:00:00:74:24:00:01:022015 mstp

switch# show spanning-tree bridge address

Switch - default

MST00 00:74:24:00:01:00

Switch - cust1

MST00 00:74:24:00:01:02

Command History

VersionHistory
1.00.001This command was introduced

show spanning-tree interface

CommandTo display the spanning tree states, statistics, settings information on a port.
show spanning-tree interface{{ cost | priority | portfast | rootcost | restricted-role | restricted-tcn | state | stats | detail }}
Syntax Descriptioninterface-type interface-idSpecify the information of which interface to display. Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel. Interface-id is slot/port number or port channel ID.
costDisplay the port cost.
priorityDisplay the port priority.
portfastDisplay the portfast state.
rootcostDisplay the rootcost.
restricted-roleDisplay the setting of restricted-role function.
restricted-tcnDisplay the setting of restricted-tcn function.
stateDisplay the spanning tree state
statsDisplay the spanning tree statistics
detailDisplay the detailed information of port and root bridge.

Command Modes

Privileged EXEC Mode

User Guidelines

Example

Single Instance:

switch# show spanning-tree interface fa 0/1

Role State Cost Prio Type


Root Forwarding 2000000 128 SharedLan

switch# show spanning-tree interface fa 0/1 cost

Port cost is 2000000

switch# show spanning-tree interface fa 0/1 priority

Port Priority is 128

switch# show spanning-tree interface fa 0/1 portfast

PortFast is enabled

switch# show spanning-tree interface fa 0/1 rootcost

Root Cost is 2000000

switch# show spanning-tree interface fa 0/1 restricted-role

Restricted Role is Enabled

swtich# show spanning-tree interface fa 0/1 restricted-tcn

Restricted TCN is Enabled

switch# show spanning-tree interface fa 0/1 state

Forwarding

switch# show spanning-tree interface fa 0/1 stats

Statistics for Port Fa0/1

Number of Transitions to forwarding State : 2

Number of RSTP BPDU Count received : 3384

Number of Config BPDU Count received : 18

Number of TCN BPDU Count received : 1

Number of RSTP BPDU Count Transmitted : 1470

Number of Config BPDU Count Transmitted : 22

Number of TCN BPDU Count Transmitted : 0

Number of Invalid BPDU Count Transmitted : 0

Port Protocol Migration Count : 1

switch# show spanning-tree interface fa 0/1 detail

Port 1 [Fa0/1] is Root, Forwarding

Port PathCost 2000000, Port Priority 128, Port Identifier 128

Designated Root has priority 8192, address 00:18:8b:bf:75:30

Designated Bridge has priority 8192, address 00:18:8b:bf:75:30

Designated Port Id is 128.1, Designated PathCost 0

No of Transitions to forwarding State :1

PortFast is disabled

Link Type is Shared

BPDUs : sent 1479 , recieved 3458

Multiple Instance:

switch# show spanning-tree interface fa 0/1

Switch - default

Role State Cost Prio Type


Root Forwarding 2000000 128 SharedLan

switch# show spanning-tree interface fa 0/1 cost

Port cost is 2000000

Switch - default

switch# show spanning-tree interface fa 0/1 priority

Switch - default

Port Priority is 128

switch# show spanning-tree interface fa 0/1 portfast

Switch - default

PortFast is enabled

switch# show spanning-tree interface fa 0/1 rootcost

Switch - default

Root Cost is 2000000

switch# show spanning-tree interface fast 0/1 restricted-role

Switch - default

Restricted Role is Enabled

switch# show spanning-tree interface fast 0/1 restricted-tcn

Switch - default

Restricted TCN is Enabled

switch# show spanning-tree interface fa 0/1 state

Switch - default

Forwarding

switch# show spanning-tree interface fa 0/1 stats

Switch - default

Statistics for Port Fa0/1

Number of Transitions to forwarding State : 2

Number of RSTP BPDU Count received : 3384

Number of Config BPDU Count received : 18

Number of TCN BPDU Count received : 1

Number of RSTP BPDU Count Transmitted : 1470

Number of Config BPDU Count Transmitted : 22

Number of TCN BPDU Count Transmitted : 0

Number of Invalid BPDU Count Transmitted : 0

Port Protocol Migration Count : 1

switch# show spanning-tree interface fa 0/1 detail
Switch - defaultPort 1 [Fa0/1] is Root, ForwardingPort PathCost 2000000, Port Priority 128, Port Identifier 128Designated Root has priority 8192, address 00:18:8b:bf:75:30Designated Bridge has priority 8192, address 00:18:8b:bf:75:30Designated Port Id is 128.1, Designated PathCost 0No of Transitions to forwarding State :1PortFast is disabledLink Type is SharedBPDUs : sent 1470 , recieved 3458
Command HistoryVersionHistory
1.00.001This command was introduced

show spanning-tree root

CommandTo display the information of the spanning root bridge.
show spanning-tree root [{ address | cost | forward-time | hello-time | id | max-age | port | priority | detail }]
Syntax DescriptionaddressDisplay the MAC address of root bridge.
forward-timeDisplay the root cost value.
hello-timeDisplay the hello time setting.
idDisplay the root bridge ID.
max-ageDisply the max age of root bridge.
portDisplay the root port.
priorityDisplay the root priority.
detailDisplay the detailed information of bridge.

Command Modes
Privileged EXEC Mode

Example

switch# show spanning-tree root

Root IDRootCostMaxAgeFwdDlyRootPort
80:00:08:00:1f:3f:73:26020150

switch# show spanning-tree root address

Root Bridge Address is 08:00:1f:3f:73:26

switch# show spanning-tree root cost

Root Cost is 2000000

switch# show spanning-tree root forward-time

Forward delay is 15 sec

switch# show spanning-tree root hello-time

Hello Time is 2 sec

switch# show spanning-tree root id

Root Bridge Id is 80:00:08:00:1f:3f:73:26

switch# show spanning-tree root max-age

Root MaxAge is 20

switch# show spanning-tree root port

Root Port is 1

switch# show spanning-tree root priority

Root Priority is 32768

switch# show spanning-tree root detail

We are the root of the Spanning Tree

Root Id Priority 32768

Address 08:00:1f:3f:73:26

Cost 0

Port 0

Hello Time 2 Sec, Max Age 20 Sec, Forward Delay 15 Sec

Command History

Version

History

1.00.001

This command was introduced

Chapter 29

MSTP Command

MSTP Command List

spanning-tree priority
spanning-tree mst configuration
spanning-tree mst max-hops
spanning-tree mst max-instance
instance
name
revision
spanning-tree mst hello-time
show spanning-tree mst
show spanning-tree mst interface
show spanning-tree mst configuration

spanning-tree priority

CommandTo set the bridge priority of spanning tree.
spanning-tree [mst] priorityno spanning-tree [mst] priority
Syntax Descriptionmst instance-idSpecify the priority of which MST instance to configure.
priorityvalue(0-61440)Specify the bridge priority of spanning tree.
Default Settings32768
Command ModesGlobal Configuration Mode
User GuidelinesMST instance configuration is only available when MSTP is running.
Exampleswitch(config)# spanning-tree mst 10 priority 1
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree mst configuration

To enter MSTP Configuration Mode

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Commandspanning-tree mst configuration
Command ModesGlobal Configuration Mode
User GuidelinesSpanning tree mode must be MST before entering the MSTP Configuration Mode.
Exampleswitch(config)# spanning-tree mst configuration switch(config-mst)#
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree mst max-hops

CommandTo set the maximum hops permitted in MST spanning-tree mst max-hops
no spanning-tree mst max-hops
Syntax Descriptionvalue(6-40)Specify the maximum hop number.
Default Settings20
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the maximum hop number to default.
Exampleswitch(config)# spanning-tree mst max-hops 6
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree mst max-instance

CommandTo set the maximum MST instance of the Switch.
spanning-tree mst max-instance
no spanning-tree mst max-instance
Syntax Descriptionshort (1-64)Specify the max instance number of the Switch.
Default Settings64
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the max instance number to default.
Exampleswitch(config)# spanning-tree mst max-instance 16
Command HistoryVersionHistory
1.00.001This command was introduced
instance
CommandTo assign VLAN range to a MST instance.
instancevlan
no instance[vlan]
Syntax Descriptioninstance-id(1-64)Specify which instance to configure.
vlan vlan-rangeSpecify which VLAN to map.
Default SettingsInstance 0 – VLAN 1~4094
Command ModesMSTP Configuration Mode
User GuidelinesUse no form to reset the VLAN mapping to default.
Exampleswitch(config-mst)# instance 1 vlan 1-100
Command HistoryVersionHistory
1.00.001This command was introduced
name
CommandTo set the name for the MST reigon.
name
no name
Syntax Descriptionstring(optional max Length)Specify the name of MST reigon.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Default Settings00: 00: 00: 00: 00: 00
Command ModesMSTP Configuration Mode
User GuidelinesUsing no form the reset the name to default.
Exampleswitch(config-mst)# name trendnet
Command HistoryVersionHistory
1.00.001This command was introduced
revision
CommandTo set the revision number for the MST reigon.revision
no revision
Syntax Descriptionvalue(0-65535)Specify the number of revision.
Default Settings0
Command ModesMSTP Configuration Mode
User GuidelinesUsing no form to reset the revision number to default.
Exampleswitch(config-mst)# revision 1
Command HistoryVersionHistory
1.00.001This command was introduced

spanning-tree mst hello-time

CommandTo set the MST hello time to a port.
spanning-tree mst hello-time
no spanning-tree mst hello-time
Syntax Descriptionvalue(1-2)Specify the hello time value of the port.
Default Settings2 seconds
Command ModesInterface Configuration Mode
User GuidelinesUse no form to reset the hello time value to default.
Exampleswitch (config-if) # spanning-tree mst hello-time 1
Command HistoryVersionHistory
1.00.001This command was introduced

show spanning-tree mst

CommandTo display the information of MST instances.show spanning-tree mst [<instance-id(1-64)>] [detail]
Syntax Descriptioninstance-id(1-64)Specify information of which MST instance to show.
detailDisplay more details of MST instance information.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display MST information for all instances when executing the command without instance-id parameter.
Exampleswitch# show spanning-tree mst 1## MST01Vlans mapped: 2Bridge Address 00:50:ba:fd:51:49 Priority 32768Root Address 00:50:ba:fd:51:49 Priority 32768Root this switch for MST01Interface Role Sts Cost Prio.Nbr Type---- ---- ---- ---- ----Fa0/1 Master Forwarding 2000000 128.1 SharedLanswitch# show spanning-tree mst 1 detail## MST01Vlans mapped: 2Bridge Address 00:50:ba:fd:51:49 Priority 32768Root Address 00:50:ba:fd:51:49 Priority 32768Root this switch for MST01Fa0/1 of MST01 is Master , ForwardingPort info port id 128.1 priority 128 cost 2000000Designated root address 00:50:ba:fd:51:49 priority 32768 cost 0Designated bridge address 00:50:ba:fd:51:49 priority 32768 port id 128.1
Command HistoryVersionHistory
1.00.001This command was introduced
show spanning-tree mst interface
CommandTo display the MSTP status, statistics and current setting on interfaces.show spanning-tree mst [<instance-id(1-64)>] interface<interface-type> <interface-id> [{ stats | hello-time | detail }]
Syntax Descriptioninstance-id(1-64)
interfaceinterface-typeinterface-idSpecify which interface to show the multiple spanning tree information.Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel.Interface-id is slot/port number or port-channel ID.
statsDisplay the BPDU statistic on this interface.
hello-timeDisplay the hello-time setting on the interface.
detailDisplay details multiple spanning tree on the interface.
Command ModesPrivileged EXEC Mode
Exampleswitch# show spanning-tree mst 1 interface fa 0/1
Instance Role Sts Cost Prio.Nbr---- ---- ----
1 Master Forwarding 2000000 128.1
switch# show spanning-tree mst 1 interface fa 0/1 statsMST01 Bpdus sent 2, Received 0
switch# show spanning-tree mst 1 interface fa 0/1 hello-timeMST01 2
switch# show spanning-tree mst 1 interface fa 0/1 detailFa0/1 of MST01 is Master , ForwardingPort info port id 128.1 priority 128 cost 2000000Designated root address 00:50:ba:fd:51:49 priority 32768 cost 0Designated bridge address 00:50:ba:fd:51:49 priority 32768 port id 128.1
Command HistoryVersionHistory
1.00.001This command was introduced

show spanning-tree mst configuration

CommandTo display current multiple spanning tree settings.show spanning-tree mst configuration
Command ModesPrivileged EXEC Mode
ExampleSingle Instance:switch# show spanning-tree mst configurationName [trendnet]Revision 2Instance Vlans mapped0 1,3-1024,1025-2048,2049-3072,3073-40941 2
Multiple Instance:switch# show spanning-tree mst configurationSwitch - defaultName [trendnet1]Revision 0Instance Vlans mapped0 1-1024,1025-2048,2049-3072,3073-4094
Switch - cust1Name [trendnet2]Revision 0Instance Vlans mapped0 1-1024,1025-2048,2049-3072,3073-4094
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 30

Link Aggregation Command List

set port-channel
lacp system-priority
port-channel load-balance
channel-group
lacp port-priority
lacp timeout
lacp wait-time
shutdown port-channel
show etherchannel
show lacp
show interfaces etherchannel

set port-channel

CommandTo enable or disable port channel function of the Switch.
set port-channel { enable | disable }
Syntax DescriptionenableEnables the port channel.
disableDisables the port channel.
Default SettingsDisable
Command ModesGlobal Configuration Mode
Exampleswitch(config)# set port-channel enable
Command HistoryVersionHistory
1.00.001This command was introduced

Iacp system-priority

To set the LACP priority of the Switch.
Commandlacp system-priority <0-65535>
no lacp system-priority
Syntax Description0-65535Specify the value of LACP system priority.
Default Settings32768
Command ModesGlobal Configuration Mode
User GuidelinesThe system priority decides the standby or active links in a aggregation when the number of member port exceeds the maximum number of the etherchannel that Switch supported.
Exampleswitch(config)# lacp system-priority 1
Command HistoryVersionHistory
1.00.001This command was introduced

port-channel load-balance

CommandTo choose the load balance algorithm of the port-channel.
port-channel load-balance {src-mac | dest-mac | src-dest-mac| src-ip | dest-ip | src-dest-ip}[ ]
no port-channel load-balance [ ]
Syntax Descriptionsrc-macHashing according to the source MAC address of the packets.
dest-macHashing according to the destication MAC address of the packets.
src-dest-macHashing according to the source and destication MAC address of the packets.
src-ipHashing according to the source IP address of the packets.
dest-ipHashing according to the destication IP address of the packets.
src-dest-ipHashing according to the source and destication IP address of the packets.
port-channel-index (1-65535)Specify which port channel to set the load balance algorithm.
Default Settingssrc-dest-mac
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the load balance algorithm to default.
Exampleswitch(config)# port-channel load-balance src-dest-ip 1
Command HistoryVersionHistory
1.00.001This command was introduced
channel-group
CommandTo join a port to a channel group.
channel-groupmode {active | passive | on}
no channel-group
Syntax Descriptionchannel-group-number(1-65535)Specify which channel group to configure.
mode activeActivates the LACP negotiation.
mode passiveLACP negotiation starts only when LACP packet is received.
mode onDisables the LACP negotiation, using manual aggregation.
Command ModesInterface Configuration Mode
User Guidelines1. Port-channel group must be crested before assign port to a channel group.2. The MTU of the port and channel group must be the same.
Exampleswitch(config-if)# channel-group 1 mode active
Command HistoryVersionHistory
1.00.001This command was introduced
Iacp port-priority
CommandTo set the LACP port priority of a port.
lacp port-priority <0-65535>
no lacp port-priority
Syntax Description0-65535Specify the port priority of the port.
Default Settings128
Command ModesInterface Configuration Mode
User GuidelinesThe port priority decides the standby or active links in a aggregation when the number of member port exceeds the maximum number of the etherchannel that Switch supported.
Exampleswitch(config-if)# lacp port-priority 1
Command HistoryVersionHistory
1.00.001This command was introduced
Iacp timeout
CommandTo choose the LACP timeout period when no packet receive from peer..
lacp timeout {long | short}
no lacp timeout
Syntax DescriptionlongSpecify a long time out value. LACP PDU will be sent every 30 seconds and LACP timeout value is 90 seconds
shortSpecify a short time out value. LACP PDU will be sent every 1 seconds and LACP timeout value is 3 seconds
Default SettingsLong
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# lacp timeout short
Command HistoryVersionHistory
1.00.001This command was introduced
Iacp wait-time
CommandThe period that ports get aggregated after receiving LACP PDU.
lacp wait-time <0-10>
no lacp wait-time
Syntax Description0-10Specify the wait time in seconds.
Default Settings2 seconds
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# lacp wait-time 0
Command HistoryVersionHistory
1.00.001This command was introduced

shutdown port-channel

CommandTo shutdown the port channel group.
shutdown port-channel
no shutdown port-channel
Default SettingsActive
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reactivate the port channel group.
Exampleswitch(config)# shutdown port-channel
Command HistoryVersionHistory
1.00.001This command was introduced

show etherchannel

CommandTo display the information of port channel groups.
show etherchannel [{ detail | load-balance | port | port-channel | summary | protocol}]
Syntax Descriptionchannel-group-numberSpecify the information of which port channel group to display.
detailDisplays the detailed information of the etherchannel.
load-balanceDisplays the load-balance or frame-distribution scheme among ports in the port channel of the etherchannel.
portDisplays the port information of the etherchannel.
port-channelDisplays the port-channel of the etherchannel.
summaryDisplays summary of the etherchannel.
protocolDisplays protocol used in the etherchannel.

Command Modes

Privileged EXEC Mode

User Guidelines

System will display the global information and the summary of all port channel groups when executing this command without any keyword.

Example

switch# show etherchannel

Port-channel Module Admin Status is enabled Port-channel Module Oper Status is enabled Port-channel System Identifier is 00:74:24:00:01:00

Maximum ports per Port Channel is 8 with maximum 8 active port

Channel Group Listing

switch# show etherchannel 1 detail Port-channel Module Admin Status is enabled Port-channel Module Oper Status is enabled Port-channel System Identifier is 00:74:24:00:01:00

Maximum ports per Port Channel is 8 with maximum 8 active port LACP System Priority: 32768

Channel Group Listing

Group: 1 Protocol :LACP

Ports in the Group

Port : Gi0/1

Port State = Down, Not in Bundle Channel Group : 1 Mode : Active Pseudo port-channel = Pol LACP port-priority = 128 LACP Wait-time = 2 secs LACP Port Identifier = 25 LACP Activity : Active LACP Timeout : Long

Aggregation State : Aggregation, Defaulted

PortStateLACP Port PriorityAdmin KeyOper KeyPort NumberPort State
Gi0/1Down128110x190xa2

Port-channel : Pol

Number of Ports = 1 HotStandBy port = null Port state = Port-channel Ag-Not-Inuse Protocol = LACP MAC selection = Dynamic

Default Port = None

switch# show etherchannel 1 load-balance
    Channel Group Listing
----
Group : 1
----
Source & Destination MAC Address

switch# show etherchannel 1 port
    Channel Group Listing
----
Group: 1
----
Protocol :LACP
    Ports in the Group
----
Port : Gi0/1
----
Port State = Down, Not in Bundle
Channel Group : 1
Mode : Active
Pseudo port-channel = Pol
LACP port-priority = 128
LACP Wait-time = 2 secs
LACP Port Identifier = 25
LACP Activity : Active
LACP Timeout : Long 

Aggregation State : Aggregation, Defaulted

PortStateLACP Port PriorityAdmin KeyOper KeyPort NumberPort State
Gi0/1Down128110x190xa2

switch# show etherchannel 1 port-channel

Port-channel Module Admin Status is enabled Port-channel Module Oper Status is enabled Port-channel System Identifier is 00:74:24:00:01:00

Maximum ports per Port Channel is 8 with maximum 8 active port

Channel Group Listing

Port-channels in the group:

Group : 1

Port-channel : Pol

Number of Ports = 1
HotStandBy port = null
Port state = Port-channel Ag-Not-Inuse
Protocol = LACP
MAC selection = Dynamic
Default Port = None

switch# show etherchannel 1 summary

Port-channel Module Admin Status is enabled
Port-channel Module Oper Status is enabled
Port-channel System Identifier is 00:74:24:00:01:00

Maximum ports per Port Channel is 8 with maximum 8 active port
Flags:
D - down    P - in port-channel
I - stand-alone   S - suspended
H - Hot-standby (LACP only)

Number of channel-groups in use: 1
Number of aggregators: 1

Group    Port-channel    Protocol    Ports

1    Pol(D)    LACP    Gi0/1(D)

switch# show etherchannel 1 protocol

Channel Group Listing

Group : 1

Protocol : LACP

Command History Version History

1.00.001 This command was introduced 

show lacp

CommandTo display the LACP port channel counters or neighbors information.
show lacp [] { counters | neighbor [detail] }
Syntax Descriptionport-channel (1-65535)Specify the information of which port channel to display.
countersDisplays the traffic statistics.
neighborDisplays the neighbor information.
detailDisplays the detailed neighbor information.

Command Modes

Example

Privileged EXEC Mode

switch# show lacp 1 counters

PortLACPDUsLACPDUs
SentRecvPktsErr
Channel group: 1
Gi0/178870400
Gi0/263659600

switch# show lacp 1 neighbor

Flags:

A - Device is in Active mode P - Device is in Passive mod

Channel group 1 neighbors

Port Gi0/1

Partner System ID : 08:01:02:03:04:05

Flags : P

LACP Partner Port Priority : 128

LACP Partner Oper Key : 2

LACP Partner Port State : 0x3c

Port State Flags Decode

Activity : Passive

LACP Timeout : Long

Aggregation State : Aggregation, Sync, Collecting, Distributing

Port Gi0/2

Partner System ID : 06:01:02:03:04:05

Flags : P

LACP Partner Port Priority : 128

LACP Partner Oper Key : 2

LACP Partner Port State : 0x3c

Port State Flags Decode

Activity : Passive

LACP Timeout : Long

Aggregation State : Aggregation, Sync, Collecting, Distributing

Command History

Version

History

1.00.001

This command was introduced

show interfaces etherchannel

To display the etherchannel information of a port.

Commandshow interfaces [etherchannel]
Syntax Descriptioninterface-type interface-idSpecify the information of which port to show. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display the etherchannel information for all ports and also the etherchannel global information when executing this command without a interface parameter.

Example

switch# show interface gi 0/1 etherchannel

Port : Gi0/1

Port State = Down, Not in Bundle

Channel Group : 1

Mode : Active

Pseudo port-channel = Pol

LACP port-priority = 128

LACP Wait-time = 2 secs

LACP Admin Port = 25

LACP Activity : Active

LACP Timeout : Long

Aggregation State : Aggregation, Defaulted

PortStateLACP Port PriorityAdmin KeyOper KeyPort NumberPort State
Gi0/1Down128110x190xa2

switch# show interface etherchannel

Port : Gi0/1

Port State = Down, Not in Bundle

Channel Group : 1

Mode : Active

Pseudo port-channel = Pol

LACP port-priority = 128

LACP Wait-time = 2 secs

LACP Port Identifier = 25

LACP Activity : Active

LACP Timeout : Long

Aggregation State : Aggregation, Defaulted

PortStateLACP Port PriorityAdmin KeyOper KeyPort NumberPort State
Gi0/1Down128110x190xa2

Port-channel : Pol

Number of Ports = 1

HotStandBy port = null

Port state = Port-channel Ag-Not-Inuse

Protocol = LACP

MAC selection = Dynamic

Default Port = None

Command History

Version

History

1.00.001

This command was introduced

Chapter 31

802.1X Command

802.1X Command List

· dot1x re-authenticate
· dot1x system-auth-control
· aaa authentication dot1x default
· dot1x local-database
· radius-server host
· dot1x control-direction
· dot1x default
· dot1x max-req
· dot1x max-start
· dot1x port-control
· dot1x reauthenitcation
· dot1x timeout
· shutdown dot1x
· debug dot1x
· debug radius
· show dot1x
· show radius server
· show radius statistics

dot1x re-authenticate

CommandTo initial a re-authentication request immediately on 802.1X enable ports.
dot1x re-authenticate [interface]
Syntax Descriptioninterface interface-type interface-idSpecify the interface to send re-authentication request. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will initial the re-authentication to all 802.1X enable ports when executing this command without a port parameter.
Exampleswitch# dot1x re-authenticate int fa 0/1
Command HistoryVersionHistory
1.00.001This command was introduced

dot1x system-auth-control

CommandTo enable 802.1X authentication on the Switch.
dot1x system-auth-control
no dot1x system-auth-control
Default SettingsDisable
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to disable the 802.1X authentication.
Exampleswitch(config)# dot1x system-auth-control
Command HistoryVersionHistory
1.00.001This command was introduced

aaa authentication dot1x default

CommandTo choose local or RADIUS database for 802.1X authentication.aaa authentication dot1x default { group radius | local}
Syntax Descriptiongroup radiusUsing the database on RADIUS server.
localUsing the local database.
Default SettingsLocal
Command ModesGlobal Configuration Mode
Exampleswitch(config)# aaa authentication dot1x default group radius
Command HistoryVersionHistory
1.00.001This command was introduced

dot1x local-database

To create user information in local database.

Commanddot1x local-databasepasswordpermission{allow | deny}[interface]
no dot1x local-database
Syntax DescriptionusernameSpecify the user name of a local database entry.
passwordSpecify the password of a local database entry.
permission allowSpecify the user is allowed to access ports configured.
permission denySpecify the user is not allowed to access ports configured.
auth-timeout(value(0-7200))Time interval between authentication attempts.
interfaceinterface-typeinterface-listPort list the 802.1X authentication can be applied.
Default SettingsPermission - allowAuth-timeout - 0Interface - All ports
Command ModesGlobal Configuration Mode
User Guidelines1. When the timeout value is 0, the authenticator will use the re-authentication period of the authenticator port2. When create a user account without permission, auth-timeout and interface values, system will assign default value to this account.
Exampleswitch(config)# dot1x local-databestrendnet password trendnet123 permission deny
Command HistoryVersionHistory
1.00.001This command was introduced

radius-server host

Command

To configure the details of RADIUS server.

radius-server host [timeout <1-120>] [retransmit <1-254>] key

no radius-server host

Syntax Descriptionip-addressSpecify the IP address of RADIUS server.
timeout 1-120Specify the time period that a client waits for the response from the RADIUS server before re-sending the request.
retransmit 1-254The maximum number that a client re-sends the request when there is no response from RADIUS server.
key secret-key-stringThe encryption key for the communication of RADIUS server.
Default Settingstimeout - 3 seconds retransmit - 3 times
Command ModesGlobal Configuration Mode
User GuidelinesWhen configure a RADIUS server without timeout and retransmit parameter, system will apply the default values.
Exampleswitch(config)# radius-server host 172.17.5.111 key trendnet
Command HistoryVersionHistory
1.00.001This command was introduced

dot1x control-direction

CommandTo choose the authentication control direction on ports.dot1x control-direction {in | both}no dot1x control-direction
Syntax DescriptioninSpecify the the authentication control is only for ingress packets.
bothSpecify the the authentication control is for both ingress and egress packets.
Default Settingsboth
Command ModesInterface Configuration Mode
User GuidelinesUsing no form the reset the control direction to default.
Exampleswitch(config-if)# dot1x control-direction in
Command HistoryVersionHistory
1.00.001This command was introduced

dot1x default

CommandTo configure 802.1X with default values on the port.dot1x default
Default SettingsPer-interface 802.1X protocol enable state - Enabled (force-authorized)Periodic reauthentication - DisabledNumber of seconds between reauthentication attempts - 3600 secondsQuiet period - 60 secondsRetransmission time - 30 secondsMaximum retransmission number - 2 timesClient timeout period - 30 secondsTX period - 30 secondsDefaults authentication server timeout period - 30 seconds
Command ModesInterface Configuration Mode
Exampleswitch(config-if)# dot1x default
Command HistoryVersion History1.00.001 This command was introduced
dot1x max-req
CommandTo set the maximum 802.1X Extensible Authentication Protocol (EAP) retries of the client before restarting authentication process.dot1x max-reqno dot1x max-req
Syntax Descriptioncount(1-10) Specify the maximum number of retry.
Default Settings2 retries
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to reset the number of retry to default.
Exampleswitch(config-if)# dot1x max-req 10
Command HistoryVersionHistory
1.00.001This command was introduced
dot1x max-start
CommandTo set the maximum EAPOL retries of the authenticator.
dot1x max-start
no dot1x max-start
Syntax Descriptioncount(1-65535)Specify the number of retry.
Default Settings3 retries
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to reset the number of retry to default.
Exampleswitch(config-if)# dot1x max-start 10
Command HistoryVersionHistory
1.00.001This command was introduced
dot1x port-control
CommandTo set the authenticator control on ports.
dot1x port-control {auto | force-authorized | force-unauthorized}
no dot1x port-control
Syntax DescriptionautoEnable the 802.1X authentication on this port, and the port authorized or unauthorized will based on the 802.1X authentication result.
force-authorizedAll traffic is transparent to the port.
force-unauthorizedAll traffic is blocked to the port.
Default SettingsForce-authorized
Command ModesInterface Configuration Mode
Exampleswitch (config-if) # dot1x port-control auto
Command HistoryVersionHistory
1.00.001This command was introduced

dot1x reauthenitcation

To enable the periodic re-authentication on ports.
Commanddot1x reauthenitcation
no dot1x reauthenitcation
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesUJsing no form to disable the 802.1X re-authentication.
Exampleswitch(config-if)# dot1x reauthenitcation
Command HistoryVersionHistory
1.00.001This command was introduced

dot1x timeout

CommandTo configure the 802.1X timers.dot1x timeout {quiet-period <value (0-65535)> | {reauth-period| server-timeout | supp-timeout | tx-period }<value (1-65535) >}no dot1x timeout {quiet-period | reauth-period | server-timec| supp-timeout | tx-period }
Syntax Descriptionquiet-period value (0-65535)The period that Switch will not do anything after a failed authentication.
reauth-period value (1-65535)The period between re-authentication attempts.
server-timeout value (1-65535)The period that Switch waits for the re-transmission to the RADIUS server.
supp-timeout value (1-65535)The period that Switch waits for the re-transmission to the client.
tx-period value (1-65535)The period that Switch waits for a response to an EAP-request/identity frame from the client before retransmitting the request.
Default Settingsquiet-period - 60 secondsreauth-period - 3600 secondsserver-timeout - 30 secondssupp-timeout - 30 secondstx-period - 30 seconds
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to reset the timers to default.
Exampleswitch(config-if)# dot1x timeout quiet-period 120
Command HistoryVersionHistory
1.00.001This command was introduced
shutdown dot1x
CommandTo shutdown the 802.1X authentication.
shutdown dot1x
no shutdown dot1x
Default SettingsEnable
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reactivate the 802.1X authentication.
Exampleswitch(config)# shutdown dot1x
Command HistoryVersionHistory
1.00.001This command was introduced

debug dot1x

CommandTo enable the debug mode of 802.1X authentication.
debug dot1x {all | errors | events | packets | state-machine | redundancy}
no debug dot1x {all | errors | events | packets | state-machi | redundancy}
Syntax DescriptionallDisplays all 802.1X debug messages.
errorsDisplays error code debug messages
eventsDisplays event debug messages
packetsDisplays packet debug messages
state-machineDisplays state-machine related debug messages
redundancyDisplays redundancy related debug messages.
Default SettingsDisable
Command ModesPrivileged EXEC Mode
User GuidelinesUsing no form to disable the debug mode.
Exampleswitch# debug dot1x all
Command HistoryVersionHistory
1.00.001This command was introduced

debug radius

To enable debug mode for RADIUS.
Commanddebug radius {all | errors | events | packets | responses | timers}
no debug radius
Syntax DescriptionallDisplays all RADIUS debug messages.
errorsDisplays the error code debug messages.
eventsDisplays the event related debug messages.
packetsDisplays the packet related debug messages.
responsesDisplays the server response related debug messages.
timersDisplays the timer related debug messages.
Default SettingsDisable
Command ModesPrivileged EXEC Mode
User GuidelinesUsing no form to disable the debug mode.
Exampleswitch# debug radius all
Command HistoryVersionHistory
1.00.001This command was introduced
show dot1x
CommandTo display the status, settings and information of 802.1X function.show dot1x [{interfacestatisticsinterface| all }]
Syntax Descriptioninterfaceinterface-typeinterface-idSpecify which interface to show 802.1X status and settings.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
statisticsDisplay 802.1X statistics of a specific interface.
interfaceinterface-typeinterface-idSpecify which interface to show 802.1X statistics.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
local-databaseDisplay 802.1X local user database information
allDisplay 802.1X status and settings for all interfaces.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display global 802.1X global status when executing the command without any parameter.

Example

switch# show dot1x

Sysauthcontrol = Disabled
Module Oper Status = Disabled
Dot1x Protocol Version = 2
Dot1x Authentication Method = Local
Nas ID = fsNas1 

switch# show dot1x interface fa 0/1

Dot1x Info for Fa0/1

AuthMode = PORT-BASED
PortStatus = AUTHORIZED
AuthSM State = INITIALIZE
BendSM State = INITIALIZE
AuthPortStatus = AUTHORIZED
AdminControlDirection = BOTH
OperControlDirection = BOTH
MaxReq = 2
Port Control = Force Authorized
QuietPeriod = 60 Seconds
Re-authentication = Disabled
ReAuthPeriod = 3600 Seconds
ServerTimeout = 30 Seconds
SuppTimeout = 30 Seconds
Tx Period = 30 Seconds 

switch# show dot1x statistics interface fa 0/1

PortStatistics Parameters for Dot1x

TxReqId = 0
TxReq = 0
TxTotal = 0
RxStart = 0
RxLogoff = 0
RxRespId = 0
RxResp = 0
RxInvalid = 0
RxLenErr = 0
RxTotal = 0
RxVersion = 0
LastRxSrcMac = 0 

switch# show dot1x local-database

Pnac Authentication Users Database

User name : trendnet

Protocol : 4

Timeout : 0 seconds

Ports : Fa0/1, Fa0/2, Fa0/3, Fa 0/4, Fa 0/5, Fa 0/6, Fa 0/7, Fa 0/8, Fa 0/9, Fa 0/10, Fa 0/11, Fa 0/12, Fa 0/13, Fa 0/14, Fa 0/15, Fa 0/16, Fa 0/17, Fa 0/18, Fa 0/19, Fa 0/20, Fa 0/21, 
Fa 0/22, Fa 0/23, Fa 0/24Permission : Allow
Command HistoryVersionHistory
1.00.001This command was introduced

show radius server

CommandTo display current status and settings of RADIUS servers show radius server
Command ModesPrivileged EXEC Mode
Exampleswitch# show radius server
Radius Server Host Information
Index: 1
Server address: 172.17.5.135
Shared secret: password
Radius Server Status: Enabled
Response Time: 20
Maximum Retransmission: 10
Command HistoryVersionHistory
1.00.001This command was introduced

show radius statistics

To display the RADIUS traffic statistics of the Switch.
Commandshow radius statistics
Command ModesPrivileged EXEC Mode

Example

switch# show radius statistics

Radius Server Statistics

Index : 1

Radius Server Address : 172.17.5.135

UDP port number : 1812

Round trip time : 0

No of request packets : 7

No of retransmitted packets : 72

No of access-accept packets : 0

No of access-reject packets : 0

No of access-challenge packets : 0

No of malformed access responses : 0

No of bad authenticators : 0

No of pending requests : 94

No of time outs : 81

No of unknown types : 0

Command History

Version

History

1.00.001

This command was introduced

Chapter 32

IGMP Snooping Command

IGMP Command List

ip igmp snoopingip igmp snooping clear countersip igmp snooping group-query-intervalip igmp snooping mrouterip igmp snooping mrouter-time-outip igmp snooping port-purge-intervalip igmp snooping querier-query-intervalip igmp snooping report-forwardip igmp snooping report-suppression-intervalip igmp snooping retry-countip igmp snooping send-queryip igmp snooping fast-leaveip igmp snooping queriershutdown snoopingdebug ip igmp snoopingshow ip igmp snoopingshow ip igmp snooping forwarding-databaseshow ip igmp snooping globalsshow ip igmp snooping groupsshow ip igmp snooping mroutershow ip igmp snooping statistics
ip igmp snooping
CommandTo enable IGMP snooping globally or on a specific VLAN.ip igmp snoopingno ip igmp snooping
Default SettingsDisable
Command ModesGlobal Configuration ModeConfig-vlan Mode
User GuidelinesUsing no form to disable IGMP snooping.
Exampleswitch (config)# ip igmp snoopingswitch (config-vlan)# ip igmp snooping
Command HistoryVersion History1.00.001 This command was introduced

ip igmp snooping clear counters

CommandTo clear the IGMP snooping. countersip igmp snooping clear counters [Vlan]
Syntax DescriptionVlan vlanid (1-4094)Specify the counters of which VLAN to clear.
Command ModesGlobal Configuration Mode
User GuidelinesSystem will clear all IGMP counters when executing this command without a VLAN parameter.
Exampleswitch(config)# ip igmp snooping clear counters vlan 1
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping group-query-interval

CommandTo set up the time interval to send the group specific query.ip igmp snooping group-query-interval < (1-5) seconds>no ip igmp snooping group-query-interval
Syntax Description(1-5) secondsSpecify the time interval to send IGMP query.
Default Settings2 seconds
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the time interval to default.
Exampleswitch(config)# ip igmp snooping group-query-interval 5
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping mrouter

To configure static IGMP multicast router ports on a specific VLAN.

Commandip igmp snooping mrouter <0/a-b, 0/c, ...>
no ip igmp snooping mrouter <0/a-b, 0/c, ...>
Syntax Descriptioninterface-type 0/a-b, 0/c, ...Specify the type and ID of the static multicast router port. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
Command ModesConfig-vlan Mode
User GuidelinesUsing no form to delete a static IGMP multicast router port.
Exampleswitch(config-vlan)# ip igmp snooping mrouter int fa 0/1
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping mrouter-time-out

CommandTo set the time-out period that an IGMP multicast router port hasn't receive IGMP router control packet, it will be deleted.ip igmp snooping mrouter-time-out < (60 - 600) seconds>no ip igmp snooping mrouter-time-out
Syntax Description(60-600) secondsSpecify the time out period of IGMP multicast router ports.
Default Settings125 seconds
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the time out period to default.
Exampleswitch(config)# ip igmp snooping mrouter-time-out 60
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping port-purge-interval

To set the purge interval that an IGMP member port hasn't received IGMP report packet, it will be deleted.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Commandip igmp snooping port-purge-interval < (130 - 1225) seconds>
no ip igmp snooping port-purge-interval
Syntax Description(130-1225)Specify the port purge interval.
seconds
Default Settings260 seconds
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the port purge interval to default.
Exampleswitch(config)# ip igmp snooping port-purge-interval 150
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping querier-query-interval

CommandTo set up the time interval to send the IGMP general query.ip igmp snooping querier-query-interval < (60 - 600) seconds>no ip igmp snooping querier-query-interval
Syntax Description(60-600) secondsSpecify the time interval of general query.
Default Settings125 seconds
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the query interval to default.
Exampleswitch(config)# ip igmp snooping querier-query-interval 150
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping report-forward

To configure which kind of ports that IGMP snooping reports should be forwarded.

Commandip igmp snooping report-forward {all-ports | router-ports}
no ip igmp snooping report-forward
Syntax Descriptionall-portsTo forward IGMP reports to all ports.
router-portsTo forward IGMP reports to router ports.
Default SettingsRouter ports
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the forwarding port to default.
Exampleswitch(config)# ip igmp snooping report-forward all-ports
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping report-suppression-interval

CommandTo set the time interval that IGMPv2 report of the same group will not be forwarded to the router portsip igmp snooping report-suppression-interval < (1 - 25) seconds>no ip igmp snooping report-suppression-interval
Syntax Description(1-25) secondsSpecify the report suppression time interval.
Default Settings5 seconds
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the time interval to default.
Exampleswitch(config)# ip igmp snooping report-suppression-interval 10
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping retry-count

To set the maximum retries for group specific queries which sent to a port

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Commandreceived a IGMPv2 leave message.ip igmp snooping retry-count <1 - 5>no ip igmp snooping retry-count
Syntax Description1 - 5Specify the maximum retries for group specific queries.
Default Settings2
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to reset the retry counter to default.
Exampleswitch(config)# ip igmp snooping retry-count 5
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping send-query

CommandTo configure if the Switch sends IGMP queries.ip igmp snooping send-query { enable | disable }
Syntax DescriptionenableSwitch sends IGMP queries.
disableSwitch does not send IGMP queries.
Default SettingsEnable
Command ModesGlobal Configuration Mode
Exampleswitch(config)# ip igmp snooping send-query disable
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping fast-leave

Enable or disable the IGMP snooping fast leave function on a VLAN.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Commandip igmp snooping fast-leave
no ip igmp snooping fast-leave
Default SettingsDisable
Command ModesConfig-vlan Mode
Exampleswitch (config-vlan) # ip igmp snooping fast-leave
Command HistoryVersionHistory
1.00.001This command was introduced

ip igmp snooping querier

To configure the switch as the IGMP querier in a VLAN.
Commandip igmp snooping querier
no ip igmp snooping querier
Default SettingsNon-querier
Command ModesConfig-vlan Mode
User GuidelinesUsing no form to reset the switch to non-querier.
Exampleswitch(config-vlan)# ip igmp snooping querier
Command HistoryVersionHistory
1.00.001This command was introduced

shutdown snooping

To shutdown the snooping of the Switch.
Commandshutdown snooping
no shutdown snooping
Default SettingsNo shutdown
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form the restart the snooping.
Exampleswitch(config)# shutdown snooping
Command HistoryVersionHistory
1.00.001This command was introduced

debug ip igmp snooping

CommandTo enable the debug mode of IGMP snooping.
debug ip igmp snooping { [init] [resources] [tmr] [src] [grp] [qry] [vlan] [pkt] [fwd] [mgmt] [redundancy] | all }
no debug ip igmp snooping { [init] [resources] [tmr] [src] [grp] [qry] [vlan] [pkt] [fwd] [mgmt] [redundancy] | all }
Syntax DescriptioninitDisplays the initial and shutdown debug message.
resourcesDisplays the system resources management debug messages.
tmrDisplays the timer debug messages.
srcDisplays the source debug messages.
grpDisplays the group debug messages.
qryDisplays the query related debug messages.
vlanDisplays the vlan debug messages.
pktDisplays the packet dump debug messages.
fwdDisplays the L2 FDB related debug messages.
mgmtDisplays the management related debug messages.
redundancyDisplays the redundancy related debug messages.
allDisplays all debug messages.

Default Settings

Command Modes

User Guidelines

Example

Disable

Privileged EXEC Mode

Usin no form to disable the debug mode.

switch# debug ip igmp snooping all

Command HistoryVersionHistory
1.00.001This command was introduced
show ip igmp snooping
CommandTo display current settings of IGMP snooping function.
show ip igmp snooping [Vlan]
Syntax DescriptionVlan vlan id
Command ModesPrivileged EXEC Mode
Exampleswitch# show ip igmp snooping
Snooping VLAN Configuration for the VLAN 1IGMP Snooping enabledIGMP configured version is V2IGMP Operating version is V2Fast leave is disabledSnooping switch is configured as Non-QuerierSnooping switch is acting as Non-QuerierQuery interval is 125 seconds
Command HistoryVersionHistory
1.00.001This command was introduced

show ip igmp snooping forwarding-database

CommandTo display the addresses information in IGMP forwarding database.show ip igmp snooping forwarding-database [Vlan]
Syntax DescriptionVlan vlan id
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display multicast addresses in FDB when executing the command without a given VLAN parameter.
Exampleswitch# show ip igmp snooping forwarding-database vlan 1
Vlan MAC-Address Ports---- ----1 01:00:5e:7f:ff:64 Fa0/9
Command HistoryVersionHistory
1.00.001This command was introduced

show ip igmp snooping globals

To display the current global settings of IGMP snooping function.
Commandshow ip igmp snooping globals
Command ModesPrivileged EXEC Mode
Exampleswitch# sh ip igmp snooping globals
Snooping Configuration
IGMP Snooping globally enabled
IGMP Snooping is operationally enabled
Transmit Query on Topology Change globally disabled
Multicast forwarding mode is MAC based
Proxy reporting globally disabled
Router port purge interval is 125 seconds
Port purge interval is 260 seconds
Report forward interval is 5 seconds
Group specific query interval is 1 seconds
Querier query interval is 125 seconds
Reports are forwarded on router ports
Group specific query retry count is 2
Command HistoryVersionHistory
1.00.001This command was introduced

show ip igmp snooping groups

CommandTo display the IGMP snooping group informationshow ip igmp snooping groups [Vlan <vlan id> [Group <Address>]]
Syntax DescriptionVlan vlan id
Group Address
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all the IGMP group information snooped by the Switch when executing the command without given VLAN and group address parameters.
Exampleswitch# sh ip igmp snooping groups vlan 1 Group 239.255.255.2
Snooping Group information
Index: 1
Index: 2
Index: 3
VLAN ID:1 Group Address: 239.255.255.250
Filter Mode: EXCLUDE
Exclude sources: None
Receiver Ports:
Fa0/9
Command HistoryVersionHistory
1.00.001This command was introduced

show ip igmp snooping mrouter

CommandTo display the IGMP multicast router learned or configured on the Switch.show ip igmp snooping mrouter [Vlan]
Syntax DescriptionVlan vlan index Specify the information in which VLAN to display.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display the IGMP multicast router information for all VLANs when executing the command without a given VLAN parameter.

Example

Single Instance: switch# show ip igmp snooping mrouter

Vlan Ports


1 Gi0/1(dynamic), Gi0/2(static) 2 Gi0/3(static), Gi0/4(dynamic)

Multiple Instance:

switch# show ip igmp snooping mrouter

Switch cust1

Vlan Ports

1 Gi0/1(static) 2 Gi0/2(static)

Switch cust2

Vlan Ports

1 Gi0/3(static) 2 Gi0/3(static)

Command History

Version

History

1.00.001

This command was introduced

show ip igmp snooping statistics

CommandTo display the IGMP snooping statistics.show ip igmp snooping statistics [Vlan]
Syntax DescriptionVlan vlan id Specify the statistic in which VLAN to display.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display IGMP Snooping statistics for all VLANs when executing the command without a given VLAN parameter.

Example

switch# show ip igmp snooping statistics vlan 1

Snooping Statistics for VLAN 1
General queries received : 0
Group specific queries received : 0
Group and source specific queries receive:
ASM reports received : 477
SSM reports received : 0
IS_INCLUDE messages received : 0
IS_EXCLUDE messages received : 0
TO_INCLUDE messages received : 0
TO_EXCLUDE messages received : 0
ALLOW messages received : 0
Block messages received : 0
Leave messages received : 25
General queries transmitted : 0
Group specific queries transmitted : 0
ASM reports transmitted : 0
SSM reports transmitted : 0
Leaves transmitted : 2
Packets dropped : 0 

Command History

Version

History

1.00.001

This command was introduced

Chapter 33

Static MAC Entries Command

Static MAC Entries Command List

mac-address-table aging-time
mac-address-table static multicast
mac-address-table static unicast
show mac-address-table
show mac-address-table aging-time
show mac-address-table count
show mac-address-table dynamic multicast
show mac-address-table dynamic unicast
show mac-address-table static multicast
show mac-address-table static unicast

mac-address-table aging-time

CommandTo set the aging time of L2 Forwarding Database (FDB).
mac-address-table aging-time <10-1000000 seconds>
no mac-address-table aging-time
Syntax Description10-1000000Specify the aging time if L2 FDB.
seconds
Default Settings300
Command ModesGlobal Configuration Mode
Exampleswitch(config)# mac-address-table aging-time 100
Command HistoryVersionHistory
1.00.001This command was introduced

mac-address-table static multicast

To create a static multicast entry in L2 FBD.

Command

mac-address-table static multicast <aa:aa:aa:aa:aa:aa> vlan
[vlan-id(1-4094)] [recv-port <interface-type><interface-id>]
interface ( [<interface-type> <0/a-b,0/c,...> ]
[<interface-type> <0/a-b,0/c,...> ] [port-channel <a,b,c-d>])
[forbidden-ports ( [<interface-type> <0/a-b,0/c,...> ]
[<interface-type> <0/a-b,0/c,...> ] [port-channel <a,b,c-d>])
[status { permanent | deleteOnReset | deleteOnTimeout }]
no mac-address-table static multicast <aa:aa:aa:aa:aa:aa> vlan
[vlan-id(1-4094)] [recv-port <interface-type><interface-id>]

Syntax Description

aa:aa:aa:aa:aa:aaMAC address of the static multicast.
vlan vlan-id(1-4094)VLAN of the static multicast.
recv-portinterface-typeinterface-idThe received port of the static multicast.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
interfaceThe member interfaces of the static multicast.
interface-type0/a-b,0/c,...Specify the member port type and ID.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
port-channel a,b,c-dSpecify the member port channel ID.
forbidden-portsThe forbidden interface of this static multicast.
interface-type0/a-b,0/c,...Specify the forbidden port type and ID.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
port-channel a,b,c-dSpecify the forbidden port channel ID.
statusSpecify the status of this static multicast.
permanentThe static multicast will keep alive.
deleteOnResetThe static multicast will be deleted after switch reset.
deleteOnTimeoutThe static multicast will be deleted when aging time out.

Default Settings

Default Status – Permanent

Command Modes

Global Configuration Mode

User Guidelines

1. Using no form to delete a configured entry.
2. Multiple member port is allowed.

Example

switch(config)#mac-address-tablestaticmulticast
01:00:5e:11:22:33vlan 1 interfacefa 0/1fa 0/2 stat
permanent

Command History

VersionHistory
1.00.001This command was introduced

mac-address-table static unicast

CommandTo create a static unicast entry in L2 FBD.mac-address-table static unicast <aa:aa:aa:aa:aa:aa> vlan[vlan-id(1-4094) > [recv-port <interface-type] interface ([<interface-type> <0/a-b,0/c,...>][<interface-type> <0/a-b,0/c,...>] [port-channel <a,b,c-d>])[status { permanent | deleteOnReset | deleteOnTimeout }]no mac-address-table static unicast <aa:aa:aa:aa:aa:aa> vlan[vlan-id(1-4094)> [recv-port <interface-type> <interface-id>]
Syntax Descriptionaa:aa:aa:aa:aa:aaMAC address of the static unicast.
vlan vlan-id(1-4094)VLAN of the static unicast.
recv-portinterface-typeinterface-idThe reveived port of the static unicast.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
interfaceThe interface to forward the static unicast.
interface-type0/a,0/b,...Specify the port type and ID to forward.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
port-channel a,b,...Specify the port channel ID to forward.
statusSpecify the status of this static unicast.
permanentThe static multicast will keep alive.
deleteOnResetThe static multicast will be deleted after switch reset.
deleteOnTimeoutThe static multicast will be deleted when aging time out.
Default SettingsStatus - Permanent
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to delete a configured entry.
Exampleswitch(config)# mac-address-table static unicastaa:bb:cc:dd:ee:ff vlan 1 int fa 0/1 status deleteonreset
Command HistoryVersion History
1.00.001 This command was introduced

show mac-address-table

CommandTo display the MAC address data learned or configured in MAC address table.
show mac-address-table [vlan] [addressaa:aa:aa:aa:aa:aa>] [{interface}]
Syntax Descriptionvlan vlan-rangeTo display MAC addresses belong to a specific VLAN range.
addressaa:aa:aa:aa:aa:aaSpecify a specific MAC address to display.
interfaceinterface-typeinterface-idTo display MAC addresses under a specific port.Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel.Interface-id is slot/port number or port channel ID.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all MAC addresses when executing the command without given VLAN, address and interface parameters.
Exampleswitch# show mac-address-table int fa 0/9
Vlan Mac Address Type Ports---- ----Type ----Ports ----
1 00:00:48:bf:f3:01LearntFa0/9
1 00:03:64:00:01:23LearntFa0/9
1 00:0d:60:cc:2f:feLearntFa0/9
1 00:0d:60:fb:52:c6LearntFa0/9
1 00:0e:7b:a0:12:97LearntFa0/9
1 00:0f:3d:2a:f0:1fLearntFa0/9
1 00:0f:3d:a8:88:9bLearntFa0/9
1 00:0f:ea:f0:0e:1eLearntFa0/9
1 00:0f:ea:f0:22:4fLearntFa0/9
1 00:10:c6:d0:ff:4fLearntFa0/9
1 00:11:25:43:38:83LearntFa0/9
1 00:11:25:87:1d:30LearntFa0/9
1 00:11:2f:2a:4f:eeLearntFa0/9
1 00:11:2f:8a:73:59LearntFa0/9
1 00:11:95:10:b3:7bLearntFa0/9
1 00:12:28:00:08:00LearntFa0/9
1 00:13:46:da:92:e9LearntFa0/9
1 00:13:46:f1:1a:92LearntFa0/9
1 00:14:85:13:cc:c6LearntFa0/9
Total Mac Addresses displayed: 19
Command HistoryVersion History
1.00.001 This command was introduced

show mac-address-table aging-time

To display the current setting of MAC table aging time.

Commandshow mac-address-table aging-time
Command ModesPrivileged EXEC Mode
Exampleswitch# show mac-address-table aging-time
Mac Address Aging Time: 300
Command HistoryVersionHistory
1.00.001This command was introduced

show mac-address-table count

CommandTo display the statistics for each kind of MAC address in MAC address table.show mac-address-table count [vlan]
Syntax DescriptionvlanSpecify information of which VLAN to display.
vlan-id(1-4094)
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all statistics when executing the command without a given VLAN parameter.
Exampleswitch# show mac-address-table count vlan 1
Mac Entries for Vlan 1:
Dynamic Unicast Address Count : 2
Dynamic Multicast Address Count : 1
Static Unicast Address Count : 2
Static Multicast Address Count : 2
Command HistoryVersionHistory
1.00.001This command was introduced

show mac-address-table dynamic multicast

CommandTo display the multicast MAC address dynamic learned in MAC address table. show mac-address-table dynamic multicast [vlan <vlan-range>][address <aa:aa:aa:aa:aa:aa>] [{interface <interface-type><interface-id>}
Syntax Descriptionvlan vlan-rangeTo display MAC addresses belong to a specific VLAN range.
addressaa:aa:aa:aa:aa:aaSpecify a specific MAC address to display.
interfaceinterface-typeinterface-idTo display MAC addresses under a specific port.Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel.Interface-id is slot/port number or port channel ID.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all multicast MAC addresses dynamic learned when executing the command without given VLAN, address and interface parameters.
Exampleswitch# show mac-address-table dynamic multicast vlan 1
Vlan Mac Address Type Ports---- ---- 1 01:00:5e:7f:ff:fa Learnt Fa0/3, Fa0/11Total Mac Addresses displayed: 1
Command HistoryVersion History
1.00.001 This command was introduced

show mac-address-table dynamic unicast

CommandTo display the unicast MAC address dynamic learned in MAC address table.show mac-address-table dynamic unicast [vlan[] [address ] [{interface}]
Syntax Descriptionvlan vlan-rangeTo display MAC addresses belong to a specific VLAN range.
addressaa:aa:aa:aa:aa:aaSpecify a specific MAC address to display.
interfaceinterface-typeinterface-idTo display MAC addresses under a specific port.Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel.Interface-id is slot/port number or port channel ID.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all unicast MAC addresses dynamic learned when executing the command without given VLAN, address and interface parameters.

Example
switch# show mac-address-table dynamic unicast vlan 1

VlanMac AddressTypePorts
100:18:8b:bf:75:30LearntFa0/3
100:19:cb:d2:f2:75LearntFa0/11
100:22:15:0c:85:6cLearntFa0/11

Total Mac Addresses displayed: 3
Command History

VersionHistory
1.00.001This command was introduced

show mac-address-table static multicast

CommandTo display the static multicast MAC address in MAC address table.show mac-address-table static multicast [vlan[][address] [{interface}]
Syntax Descriptionvlan vlan-rangeTo display MAC addresses belong to a specific VLAN range.
addressaa:aa:aa:aa:aa:aaSpecify a specific MAC address to display.
interfaceinterface-typeinterface-idTo display MAC addresses under a specific port.Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel.Interface-id is slot/port number or port channel ID.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all static multicast MAC addresses when executing the command without given VLAN, address and interface parameters.
Exampleswitch# show mac-address-table static multicast vlan 1
Static Multicast Table----
Vlan : 1Mac Address : 11:22:33:44:55:66Member Ports : Fa0/5Status : Permanent----
Vlan : 1Mac Address : 11:33:55:77:99:bbMember Ports : Fa0/7Status : Permanent----
Total Mac Addresses displayed: 2
Command HistoryVersionHistory
1.00.001This command was introduced

show mac-address-table static unicast

CommandTo display the static unicast MAC address in MAC address table.show mac-address-table static unicast [vlan[][address] [{interface}]
Syntax Descriptionvlan vlan-rangeTo display MAC addresses belong to a specific VLAN range.
addressaa:aa:aa:aa:aa:aaSpecify a specific MAC address to display.
interfaceinterface-typeinterface-idTo display MAC addresses under a specific port.Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel.Interface-id is slot/port number or port channel ID.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all static unicast MAC addresses when executing the command without given VLAN, address and interface parameters.
Exampleswitch# show mac-address-table static unicast vlan 1
Vlan Mac Address RecvPort Status Ports---- -------- -------- ----
1 00:11:22:33:44:55 Permanent Fa0/21 00:22:33:44:55:66 Permanent Fa0/1
Total Mac Addresses displayed: 2
Command HistoryVersion History
1.00.001 This command was introduced

Chapter 34

Port Security Command

Port Security Command List

max learning address
show max-learning-address

max learning address

CommandTo limits the number of MAC address learned from a port.
max learning addressno max learning address
Syntax Descriptionaddress number (0-64)Specify the number of MAC can be learned of the port.
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to disable the MAC learning limitation.
Exampleswitch(config-if)# max learning address 64
Command HistoryVersionHistory
1.00.001This command was introduced

show max-learning-address

To display the current port security setting on each port.
Commandshow max-learning-address
Command ModesPrivileged EXEC Mode

Example
switch# show max-learning-address

PortPort Security StatusMax Learning Address
Fa0/1Enabled64
Fa0/2Disabled0
Fa0/3Enabled16
Fa0/4Disabled0
Fa0/5Enabled32
Fa0/6Disabled0
Fa0/7Enabled8
Fa0/8Disabled0
Fa0/9Disabled0
Fa0/10Disabled0
Fa0/11Disabled0
Fa0/12Disabled0
Fa0/13Disabled0
Fa0/14Disabled0
Fa0/15Disabled0
Fa0/16Disabled0
Fa0/17Disabled0
Fa0/18Disabled0
Fa0/19Disabled0
Fa0/20Disabled0
Fa0/21Disabled0
Fa0/22Disabled0
Fa0/23Disabled0
Fa0/24Disabled0
Gi0/1Disabled0
Gi0/2Disabled0
Gi0/3Disabled0
Gi0/4Disabled0

Command History

VersionHistory
1.00.001This command was introduced

Chapter 35

ACL Command

ACL Command List

  • mac access-list extended
  • ip access-list
  • deny (MAC Access List Configuration)
  • permit (MAC Access List Configuration)
  • deny (Standard IP Access List Configuration)
  • permit (Standard IP Access List Configuration)
    ■ deny (Extended IP Access List Configuration)
    ■ permit (Extended IP Access List Configuration)
    ■ deny icmp (Extended IP Access List Configuration)
    ■ permit icmp (Extended IP Access List Configuration)
  • mac access-group
    ip access-group
    ■ show access-lists

mac access-list extended

CommandTo create and enter a MAC access control list.mac access-list extendedno mac access-list extended
Syntax Descriptionaccess-list-number(1-65535)Specify the ID of access control list.
short (1-65535)Specify the ID of access control list.
Command ModesGlobal Configuration Mode
User Guidelines1. Using no form to delete the access control list.2. The ID cannot be duplicated for all access control list.
Exampleswitch(config)# mac access-list extended 1switch(config-ext-macl)#
Command HistoryVersionHistory
1.00.001This command was introduced
ip access-list

To create and enter an IP access control list.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Commandip access-list { standard| extended} no ip access-list { standard| extended}
Syntax DescriptionstandardSpecify the ID to a standard IP access control list.
access-list-number(1-1000)
extendedSpecify the ID to a extended IP access control list.
access-list-number(1001-65535)
Command ModesGlobal Configuration Mode
User Guidelines1. Using no form to delete the access control list.2. The ID cannot be duplicated for all access control list.
Exampleswitch(config)# ip access-list standard 200 switch(config-std-nacl)#
Command HistoryVersionHistory
1.00.001This command was introduced

deny (MAC Access List Configuration)

CommandTo configure a rule that packets matched will be filtered.
deny { any | host <mac-address>} { any | host <mac-address> } [aarp | amber | dec-spanning | decnet-iv | diagnostic | dsm | etype-6000 | etype-8042 | lat | lavc-sca | mop-console | mop-dump | msdos | mumps | netbios | vines-echo | vines-ip | xns-id | <protocol (0-65535)>] [ Vlan ]

Syntax Description

anyMatching packets with any source MAC address.
host mac-addressMatching packets with a specific source MAC address.
anyMatching packets with any destination MAC address.
host mac-addressMatching packets with a specific destination MAC address.
aarpMatching packets with ether type aarp, 0x80F3(33011).
amberMatching packets with ether type amber, 0x6008(24584).
dec-spanningMatching packets with ether type dec-spanning, 0x8138 (33080).
decnet-ivMatching packets with ether type decnet_iv, 0x6003 (24579).
diagnosticMatching packets with ether type diagnostic, 0x6005(24581).
dsmMatching packets with ether type dsm, 0x8309(32825).
etype-6000Matching packets with ether type etype-6000, 0x6000(24576).
etype-8042Matching packets with ether type etype-8042, 0x8042(32834).
latMatching packets with ether type lat, 0x6004(24580).
lavc-scaMatching packets with ether type lavc-sca, 0x6007(24583).
mop-consoleMatching packets with ether type mop-consol, 0x6002(24578).
mop-dumpMatching packets with ether type mop_dump, 0x6001(24577).
msdosMatching packets with ether type msdos, 0x8041(32833).
mumpsMatching packets with ether type mumps, 0x6009(24585).
netbiosMatching packets with ether type netbios, 0x8040(32832).
vines-echoMatching packets with ether type vines-echo, 0x0BAF(2991).
vines-ipMatching packets with ether type vines-ip, 0x0BAD(2989).
xns-idMatching packets with ether type xns-id, 0x0807(2055).
protocol (0-65535)Matching packets with a specific ether type value.
Vlan vlan-id (1-4094)Matching packets with a specific VLAN ID.

Command Modes
MAC Access List Configuration Mode

Example
switch(config-ext-macl)# deny any host 11-22-33-44-55-66 netbios
Command History

VersionHistory
1.00.001This command was introduced

permit (MAC Access List Configuration)

CommandTo configure a rule that packets matched will be processed permit { any | host}{ any | host{ [aarp | amber | dec-spanning | decnet-iv | diagnostic | dsm | etype-6000 | etype-8042 | lat | lavc-sca | mop-console | mop-dump | msdos | mumps | netbios | vines-echo | vines-ip | xns-id | ] [ Vlan]
Syntax DescriptionanyMatching packets with any source MAC address.
host mac-addressMatching packets with a specific source MAC address.
anyMatching packets with any destination MAC address.
host mac-addressMatching packets with a specific destination MAC address.
aarpMatching packets with ether type aarp, 0x80F3(33011).
amberMatching packets with ether type amber, 0x6008(24584).
dec-spanningMatching packets with ether type dec-spanning, 0x8138 (33080).
decnet-ivMatching packets with ether type decnet_iv, 0x6003 (24579).
diagnosticMatching packets with ether type diagnostic, 0x6005(24581).
dsmMatching packets with ether type dsm, 0x8309(32825).
etype-6000Matching packets with ether type etype-6000, 0x6000(24576).
etype-8042Matching packets with ether type etype-8042, 0x8042(32834).
latMatching packets with ether type lat, 0x6004(24580).
lavc-scaMatching packets with ether type lavc-sca, 0x6007(24583).
mop-consoleMatching packets with ether type mop-consol, 0x6002(24578).
mop-dumpMatching packets with ether type mop_dump, 0x6001(24577).
msdosMatching packets with ether type msdos, 0x8041(32833).
mumpsMatching packets with ether type mumps, 0x6009(24585).
netbiosMatching packets with ether type netbios, 0x8040(32832).
vines-echoMatching packets with ether type vines-echo, 0x0BAF( 2991).
vines-ipMatching packets with ether type vines-ip, 0x0BAD( 2989).
xns-idMatching packets with ether type xns-id, 0x0807( 2055).
protocol (0-65535)Matching packets with a specific ether type value.
Vlan vlan-id (1-4094)Matching packets with a specific VLAN ID.
Command ModesMAC Access List Configuration Mode
Exampleswitch(config-ext-macl)# permit host 11-22-33-44-55-66 any msdos
Command HistoryVersionHistory
1.00.001This command was introduced

deny (Standard IP Access List Configuration)

CommandTo configure a rule that packets matched will be filtered.
deny { any | host|}[ { any | host|]
Syntax DescriptionanyMatching packet with any source IP address.
hostsrc-ip-addressMatching packet with a specific source IP address.
src-ip-addressmaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
anyMatching packet with any destination IP address.
hostdest-ip-addressMatching packet with a specific destination IP address.
dest-ip-addressmaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Command ModesStandard IP Access List Configuration Mode
Exampleswitch(config-std-nacl)# deny any 172.17.5.100 255.255.255.0
Command HistoryVersionHistory
1.00.001This command was introduced

permit (Standard IP Access List Configuration)

CommandTo configure a rule that packets matched will be processed permit { any | host <src-ip-address> | <src-ip-address><mask>} [ { any | host <dest-ip-address> | <dest-ip-address><mask>} ]
Syntax DescriptionanyMatching packet with any source IP address.
hostsrc-ip-addressMatching packet with a specific source IP address.
src-ip-addressmaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
anyMatching packet with any destination IP address.
hostdest-ip-addressMatching packet with a specific destination IP address.
dest-ip-addressmaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
Command ModesStandard IP Access List Configuration Mode
Exampleswitch(config-std-nacl)# permit host 172.17.6.1 172.17.5.100 255.255.255.0
Command HistoryVersionHistory
1.00.001This command was introduced

deny (Extended IP Access List Configuration)

CommandDeny { ip | ospf | pim | <protocol-type (1-255)>} { any | host
<src-ip-address> | <src-ip-address> <mask> } { any | host
<dest-ip-address> | <dest-ip-address> <mask> } [ {tos
(0-7) > | dscp <value (0-63)> } ]
deny {tcp | udp} {any | host <src-ip-address> | <src-ip-address>
<src-ip-mask> } {anyport | <src-port (1-65535)> <x8000> | xC000
| xE000 | xF000 | xF800 | xFC00 | xFE00 | xFF00 | xFF80 | xFFC0
| xFFE0 | xFFF0 | xFFF8 | xFFFC | xFFFE | xFFFF> } {any | host
<dest-ip-address> | <dest-ip-address> <dest-ip-mask> }
{anyport | <dest-port (1-65535)> <x8000 | xC000 | xE000 | xF000
| xF800 | xFC00 | xFE00 | xFF00 | xFF80 | xFFC0 | xFFE0 | xFFF0
| xFFF8 | xFFFC | xFFFE | xFFFF> } [ {tos <value (0-7)> | dscp
<value (0-63)> } ] [{ ack | ack-not }][{ rst | rst-not }}

Syntax Description

ipMatching all IP packets.
ospfMatching all OSPF packets.
pimMatching all PIM packets.
protocol-type(1-255)Matching packets with specific protocol type.
anyMatching packet with any source IP address.
hostsrc-ip-addressMatching packet with a specific source IP address.
src-ip-addressmaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
anyMatching packet with any destination IP address.
hostdest-ip-addressMatching packet with a specific destination IP address.
dest-ip-addressmaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
tos value (0-7)Matching packets with specific ToS value.
dscp value(0-63)Matching packets with specific DSCP type.
tcpMatching all TCP packets.
udpMatching all UDP packets.
anyportMatching packets with any L4 source port.
src-port(1-65535)x8000 ~ xFFFFMatching packets with a specific L4 source port.
dest-port(1-65535)x8000 ~ xFFFFMatching packets with a specific L4 destination port.
ackMacthing packets with a TCP acknowledge flag
ack-notMacthing packets with a TCP acknowledge-not flag
rstMacthing packets with a TCP reset flag
rst-notMacthing packets with a TCP reset not flag

Command Modes

Extended IP Access List Configuration Mode

Example

switch(config-ext-nacl)# deny ip any any tos 7

Command History

VersionHistory
1.00.001This command was introduced

permit (Extended IP Access List Configuration)

To configure a rule that packets matched will be processed.

Command

permit { ip | ospf | pim | <protocol-type (1-255)> } { any | host <src-ip-address> | <src-ip-address> <mask> } { any | host <dest-ip-address> | <dest-ip-address> <mask> } [ {tos <value (0-7) > | dscp <value (0-63)> } ] 
permit {tcp | udp} {any | host <src-ip-address> |
<src-ip-address> <src-ip-mask>} {anyport | <src-port (1-65535)> <x8000 | xC000 | xE000 | xF000 | xF800 | xFC00 | xFE00 | xFF00 | xFF80 | xFFC0 | xFFE0 | xFFF0 | xFFF8 | xFFE1  | xFFF0 | xFFF8 | xFFF8 | xFFF8 | xFFF9 | xFFFE | xFFFF>} {any | host <dest-ip-address> | <dest-ip-address>
<dest-ip-mask>} {anyport | <dest-port (1-65535)> <x8000 | xC000 | xE000 | xF000 | xF800 | xF800 | xFE00 | xFF00 | xFF80 | xFFC0 | xFFE0 | xFFF0 | xFFF8 | xFFF8 | xFFFE | xFFFF>} [ {tos <value (0-7)> | dscp <value (0-63)>]} [{ ack | ack-not }][ { rst | rst-not }] 

Syntax Description

ipMatching all IP packets.
ospfMatching all OSPF packets.
pimMatching all PIM packets.
protocol-type(1-255)Matching packets with specific protocol type.
anyMatching packet with any source IP address.
hostsrc-ip-addressMatching packet with a specific source IP address.
src-ip-addressmaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
anyMatching packet with any destination IP address.
hostdest-ip-addressMatching packet with a specific destination IP address.
dest-ip-addressmaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
tos value (0-7)Matching packets with specific ToS value.
dscp value(0-63)Matching packets with specific DSCP type.
tcpMatching all TCP packets.
udpMatching all UDP packets.
anyportMatching packets with any L4 source port.
src-port(1-65535)x8000 ~ xFFFFMatching packets with a specific L4 source port.
dest-port(1-65535)x8000 ~ xFFFFMatching packets with a specific L4 destination port.
ackMacthing packets with a TCP acknowledge flag
ack-notMacthing packets with a TCP acknowledge-not flag
rstMacthing packets with a TCP reset flag
rst-notMacthing packets with a TCP reset not flag

Command Modes

Extended IP Access List Configuration Mode

Example

switch(config-ext-nacl)# deny ip any any tos 7

Command History

VersionHistory
1.00.001This command was introduced

deny icmp (Extended IP Access List Configuration)

CommandTo configure a rule that packets matched will be filtered.
deny icmp {any |host|{any | host | {message-type < (0-255)>}{message-code < (0-255)>}
Syntax DescriptionanyMatching packet with any source IP address.
hostsrc-ip-addressMatching packet with a specific source IP address.
src-ip-addressmaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
anyMatching packet with any destination IP address.
hostdest-ip-addressMatching packet with a specific destination IP address.
dest-ip-addressmaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
message-type(0-255)Matching ICMP packets with specific message type.
message-code(0-255)Matching ICMP packets with specific message code.
Command ModesExtended IP Access List Configuration Mode
Exampleswitch(config-ext-nacl)#deny icmp any any message-type 10message-code 10
Command HistoryVersionHistory
1.00.001This command was introduced

permit icmp (Extended IP Access List Configuration)

CommandTo configure a rule that packets matched will be processed permit icmp {any |host <src-ip-address>|<src-ip-address><mask>} {any | host <dest-ip-address> | <dest-ip-address><mask>} {message-type < (0-255)>} {message-code < (0-255)>}
Syntax DescriptionanyMatching packet with any source IP address.
hostsrc-ip-addressMatching packet with a specific source IP address.
src-ip-addressmaskMatching packet with a range of source IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
anyMatching packet with any destination IP address.
hostdest-ip-addressMatching packet with a specific destination IP address.
dest-ip-addressmaskMatching packet with a range of destination IP address. For example 172.17.5.1 with mask 255.255.255.0 means 172.15.5.0~255.
message-type(0-255)Matching ICMP packets with specific message type.
message-code(0-255)Matching ICMP packets with specific message code.
Command ModesExtended IP Access List Configuration Mode
Exampleswitch(config-ext-nacl)# permit icmp any any message-type 10message-code 10
Command HistoryVersionHistory
1.00.001This command was introduced
mac access-group
CommandTo apply a MAC access control list to the port.mac access-groupno mac access-group[]
Syntax Descriptionaccess-list-number(1-65535)Specify which access control list to associate.
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to dissociate ACL from the port.
Exampleswitch(config-if)# mac access-group 1
Command HistoryVersionHistory
1.00.001This command was introduced

ip access-group

CommandTo apply an IP access control list from the port.ip access-groupno ip access-group []
Syntax Descriptionaccess-list-number(1-65535)
Command ModesInterface Configuration Mode
User GuidelinesUsing no form to dissociate ACL from the port.
Exampleswitch(config-if)# ip access-group 1001
Command HistoryVersionHistory
1.00.001This command was introduced

show access-lists

CommandTo display the details of configured access lists.
show access-lists [{{ip | mac}] (1-65535)>]
Syntax DescriptionipTo display IP access control list.
macTo display MAC access control list.
access-list-number (1-65535)Specify the ID of access control list.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display all access list information without a given IP or MAC access list number.
Exampleswitch# show access-lists mac 1
Extended MAC Access List 1
EtherType : 0Vlan Id : 0Destination MAC Address : 00:00:00:00:00:00Source MAC Address : 00:00:00:00:00:00In Port List : NILFilter Action : PermitStatus : InActive
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 36

Classmap Command

Classmap Command List

▪ class-map▪ match access-group▪ show class-map
class-map
CommandTo create or enter a class map.class-mapno class-map
Syntax Descriptionclass-map-number(1-65535)Specify the class map ID.
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to delete a class map.
Exampleswitch(config)# class-map 1
Command HistoryVersionHistory
1.00.001This command was introduced

match access-group

CommandTo associate a access control rule.
match access-group { mac-access-list | ip-access-list }
Syntax Descriptionmac-access-listSpecify the rule of MAC access list to associate.
ip-access-listSpecify the rule of standard or extended IP access list to associate.
acl-index-num (1-65535)Specify the access control list ID.
Command ModesClass-map Configuration Mode
User GuidelinesThe access control list rule must be created before associating.
Exampleswitch(config-cmap)# match access-group mac-access-list 1
Command HistoryVersionHistory
1.00.001This command was introduced
show class-map
CommandTo display the settings of class maps.show class-map [<class-map-num(1-65535)>]
Syntax Descriptionclass-map-num (1-65535)Specify which class map to display.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will show all the class map information when executing the command without a given class map number.
Exampleswitch# show class-mapDiffServ Configurations:----Class map 1----Filter ID : 1Filter Type : MAC-FILTERDiffServ Configurations:----Class map 2----Filter ID : 1Filter Type : MAC-FILTER
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 37

Policymap Command

Policymap Command List

policy-mapclasssetpoliceshow policy-map
policy-map
CommandTo create or enter a policy map.
policy-mapno policy-map
Syntax Descriptionpolicy-map-number (1-65535)Specify the policy map ID.
Command ModesGlobal Configuration Mode
User GuidelinesUsing no form to delete a policy map.
Exampleswitch(config)# policy-map 1
Command HistoryVersionHistory
1.00.001This command was introduced
class
CommandTo associate a class map in policy map and enter the Policy-map Class Configuration Mode.
classno class
Syntax Descriptionclass-map-number (1-65535)Specify the class map IP to associate.
Command ModesPolicy-map Configuration Mode
User GuidelinesClass map must be created before associating.
Exampleswitch(config-pmap)# class 1
Existing Policy-map configurations have been deleted. Please apply the policy-map to make it active.switch(config-pmap-c)#
Command HistoryVersionHistory
1.00.001This command was introduced
set
CommandTo set the new 802.1p priority or DSCP type of packets match the associated ACL rule.
set {cos| ip dscp}
no set {cos| ip dscp}
Syntax Descriptioncos new-cos (0-7)Specify the new 802.1p priority of the packet.
ip dscp new-dscp(0-63)Specify the new DSCP type of the packet.
Command ModesPolicy-map Class Configuration Mode
Exampleswitch(config-pmap-c)# set cos 1
Command HistoryVersionHistory
1.00.001This command was introduced
police
CommandTo set up the actions of packets match the associated ACL rule.
policeexceed-action {drop | policed-dscp-transmit}
Syntax Descriptionrate-KbpsSet the traffic rate threshold in Kbps for the class map.
exceed-action dropDrop packets if traffic rate exceeds the threshold.
exceed-actionpoliced-dscp-transmitnew-dscp (0-63)Modifying the DSCP type value for packets if traffic rate exceeds the threshold.
Command ModesPolicy-map Class Configuration Mode
Exampleswitch(config-pmap-c)# police 64 exceed-action drop
Command HistoryVersionHistory
1.00.001This command was introduced
show policy-map
CommandTo display the settings of a policy map.show policy-map [<policy-map-num(1-65535)> [class]
Syntax Descriptionpolicy-map-num(1-65535)
classclass-map-num(1-65535)
Command ModesPrivileged EXEC Mode
User Guidelines
Exampleswitch# show policy-mapDiffServ Configurations: Quality of Service has been enabledPolicy Map 1 is activeClass Map: 1In Profile EntryIn profile action : policed-dscp 2Out Profile EntryMetering onOut profile action : none
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 38

Rate Limiting Command

Rate Limiting Command List

rate-limit egress· rate-limit egress· rate-limit ingress· show rate-limit
CommandTo enable and setup the egress packet rate limiting on a port.
rate-limit egress []
no rate-limit egress
Syntax Descriptionrate-value (64~1000000)Specify the traffic Kbit per second is allowed to be transmitted for an egress port..
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesThe no form is to disable the rate limiting on a port.
Exampleswitch(config-if)# rate-limit egress 64
Command HistoryVersionHistory
1.00.001This command was introduced
rate-limit ingress
CommandTo enable and setup the ingress packet rate limiting on a port.
rate-limit ingress []
no rate-limit ingress
Syntax Descriptionrate-value (64~1000000)Specify the traffic Kbit per second is allowed to be received for an ingress port.
Default SettingsDisable
Command ModesInterface Configuration Mode
User GuidelinesThe no form is to disable the rate limiting on a port.
Exampleswitch(config-if)# rate-limit ingress 64
Command HistoryVersionHistory
1.00.001This command was introduced
show rate-limit
CommandTo display the current rate-limit setting of interfaces
show rate-limit [interface]
Syntax Descriptioninterface interface-type interface-idSpecifying which interface to show rate limiting information. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will show the information for all ports when executing the command without a given interface parameter.
Exampleswitch# show rate-limit int fa 0/1
Fa0/1 Ingress Rate Limit Control : Disabled Egress Rate Limit Control : Enabled Egress Rate Limit Control : 64
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 39

Storm Control Command

Storm Control Command List
■ storm-control pkt-type
storm-control pkt-type

CommandTo enable and configure the details of the storm control function.storm-control pkt-type { broadcast-only | multicast-broadcast| dlf-multicast-broadcast } rate-level(64-1024000)>no storm-control
Syntax Descriptionbroadcast-onlyOnly controls the broadcast packets.
multicast-broadcastControls both broadcast and multicast packets.
dlf-multicast-broadcastControls broadcast, multicast and Destination Lookup Failed (DLF) unicast packets.
rate-levelrate-level (64-1024000)Specify the packet number all types above is allowed to be forwarded per second.
Default SettingsDisable
Command ModesGlobal Configuration Mode
User GuidelinesThe no form disables the storm control.
Exampleswitch(config)# storm-control broadcast level 500
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 40

QoS Command

QoS Command List

set dscpvlan map-prioritydscp map-typecosq scheduling algorithmswitchport priority defaultshow vlan traffic-classesshow vlan port configshow dscpshow cosq algorithm
set dscp
CommandTo configure the priority and switch queue mapping
set dscp { enable | disable }
Syntax DescriptionenableEnables DSCP and queue mapping.
disableDisables DSCP and queue mapping.
Default SettingsDisable
Command ModesGlobal Configuration Mode
User GuidelinesWhen DSCP is disabled, Switch map queue with 802.1p priority.
Exampleswitch(config)# set dscp enable
Command HistoryVersionHistory
1.00.001This command was introduced
vlan map-priority
CommandTo set the 802.1p priority and queue mapping.vlan map-prioritytraffic-class
Syntax Descriptionpriority value(0-7)Specify which priority to map.
traffic-classSpecify which switch queue to map.
Traffic classvalue(0-3)
Default SettingsPriorityDefault traffic class
00
10
21
31
42
52
63
73
Command ModesGlobal Configuration Mode
Exampleswitch(config)# vlan map-priority 0 traffic-class 1
Command HistoryVersionHistory
1.00.001This command was introduced
dscp map-type
CommandTo set the dscp type and queue mapping.
dscp map-type<integer(0-63)>traffic-class
Syntax Descriptioninteger(0-63)Specify which DSCP type to map.
traffic-classinteger(0-3)Specify which switch queue to map.
Command ModesGlobal Configuration Mode
User GuidelinesDSCP must be enabled before configuring this command.
Exampleswitch(config)# dscp map-type 63 traffic-class 0
Command HistoryVersionHistory
1.00.001This command was introduced
cosq scheduling algorithm

To choose the scheduling algorithm for switch queues.

Commandcosq scheduling algorithm { strict | wrr }
Syntax DescriptionstrictThe traffic in highest queue always process first.
wrrUsing weighted round-robin algorithm to handle packets in priority queues.
Default SettingsStrict
Command ModesGlobal Configuration Mode
Exampleswitch(config)# cosq scheduling algorithm wrr
Command HistoryVersionHistory
1.00.001This command was introduced

switchport priority default

CommandTo setup the 802.1p priority for untagged packets.switchport priority defaultno switchport priority default
Syntax Descriptionpriority value(0-7)Specify which priority to set.
Default Settings0
Command ModesInterface Configuration Mode
User GuidelinesThe no form resets the priority to default value.
Exampleswitch(config-if)#
Command HistoryVersionHistory
1.00.001This command was introduced

show vlan traffic-classes

To display the current setting of 802.1p priority and traffic class mapping.
Commandshow vlan traffic-classes
Command ModesPrivileged EXEC Mode
Exampleswitch# show vlan traffic-classes
Traffic Class table
PriorityTraffic Class
00
10
21
31
42
52
63
73
Command HistoryVersionHistory
1.00.001This command was introduced

show vlan port config

CommandTo display the VLAN settings of portsshow vlan port config [{port}
Syntax Descriptionportinterface-typeinterface-idSpecified which interface to display vlan configurations.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display the information of all ports when executing the command without a given port parameter.
Exampleswitch# show vlan port config port fa 0/1Vlan Port configuration table----Port Fa0/1Port Vlan ID : 1Port Acceptable Frame Type : Admit AllPort Ingress Filtering : EnabledPort Mode : HybridPort Gvrp Status : EnabledPort Gvrp Failed Registrations : 0Gvrp last pdu origin : 00:00:00:00:00:00Port Restricted Vlan Registration : DisabledDefault Priority : 0
Command HistoryVersionHistory
1.00.001This command was introduced
show dscp
CommandTo display the current dscp setting.
show dscp
Command ModesPrivileged EXEC Mode
Exampleswitch# show dscp
DSCP is disabled
Command HistoryVersionHistory
1.00.001This command was introduced
show cosq algorithm
CommandTo display the current setting of CoS scheduling algorithm.
show cosq algorithm
Command ModesPrivileged EXEC Mode
Exampleswitch# show cosq algorithm
CoSq Algorithm is StrictPriority
Command HistoryVersionHistory
1.00.001This command was introduced

Chapter 41

RMON Command

RMON Command List

set rmon
CommandTo enable or disable RMON function.
set rmon { enable | disable }
Syntax DescriptionenableEnable RMON.
disableDisable RMON.
Default SettingsDisable
Command ModesGlobal Configuration Mode
Exampleswitch(config)# set rmon enable
Command HistoryVersionHistory
1.00.001This command was introduced
rmon alarm
CommandTo set a RMON alarm on a MIB object.
rmon alarm < number (1-65535)>
< sample-interval-time (1-2147482647)> {absolute | delta}
rising-threshold < value (0-2147483647)>
(1-65535)> falling-threshold < value (0-2147483647)>
< falling-event-number (1-65535)> [owner]
no rmon alarm
Syntax Descriptionnumber (1-65535)Specify the alarm number.
mib-object-id (255)The MIB OID to set alarm.
sample-interval-time (1-2147482647)The time interval in seconds that alarm monitors the MIB variable.
absoluteTo test the MIB variable directly.
deltaTo test the change between samples of a MIB variable.
rising-threshold value (0-2147483647)The threshold value to trigger alarm when the number of sample exceeds.
rising-event-number (1-65535)The number of event to trigger when rising threshold is exceeded.
falling-threshold value (0-2147483647)The threshold value to reset alarm when the number of sample exceeds.
falling-event-number (1-65535)The number of event to trigger when falling threshold is exceeded.
owner ownername (127)Specify the owner of the alarm.
Command ModesGlobal Configuration Mode
User Guidelines1. RMON function must be enabled and RMON event must be configured before configuring alarms.2. Using no form to delete a RMON alarm on a MIB object.
Exampleswitch(config)# rmon alarm 11.3.6.1.2.1.17.7.1.3.1.1.3.141.0.0.0.0.0.22.0 10 delta rising-threshold 15 1 falling-threshold 10 1
Command HistoryVersion History
1.00.001 This command was introduced
rmon event
CommandTo add an event to RMON event table.rmon event <number (1-65535)> [description <event-description (127)>] [log] [owner <ownername (127)>] [trap <community (127)>]no rmon event <number (1-65535)>
Syntax Descriptionnumber (1-65535)Specify the event number.
description event-description (127)Setting the description of the event.
logGenerating syslog when event is triggered.
owner ownername (127)Specify the owner of the event.
trap community (127)Generating a trap message when event is triggered.
Command ModesGlobal Configuration Mode
User Guidelines1. RMON function must be enabled and RMON event must be configured before configuring alarms.2. Using no form to delete events from RMON event table.
Exampleswitch (config) # rmon event 1 description broadcast-too-high log owner trendnet trap redalert
Command HistoryVersionHistory
1.00.001This command was introduced

rmon collection history

CommandTo enable and setup the RMON collection history on a port.
rmon collection history [buckets] [interval] [owner]
no rmon collection history
Syntax Descriptionindex (1-65535)Specify the index of history table.
buckets bucket-number (1-50)The maximum number of RMON history collection.
interval seconds (1-3600)The time interval for the history collection.
owner ownername (127)Specify the owner of the history group.
Command ModesInterface Configuration Mode
User Guidelines1. RMON function must be enabled and RMON event must be configured before configuring alarms.2. Using no form to disable the history collection..
Exampleswitch(config-if)# rmon collection history 1 buckets 50 interval 10 owner trendnet
Command HistoryVersionHistory
1.00.001This command was introduced

rmon collection stats

To enable and setup the RMON statistics collection on a port.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Commandrmon collection stats <index (1-65535)> [owner <ownername(127)>]
no rmon collection stats <index (1-65535)>
Syntax Descriptionindex (1-65535)Specify the index of the RMON statistics collection.
owner ownername (127)Specify the owner of the statistics
Command ModesInterface Configuration Mode
User Guidelines1. RMON function must be enabled and RMON event must be configured before configuring alarms.2. Using no form to disable the statistics collection..
Exampleswitch(config-if)# rmon collection stats 1 owner trendnet
Command HistoryVersionHistory
1.00.001This command was introduced
show rmon
CommandTo display the RMON statistics, alarms, events, and history configured on the interface
show rmon [statistics [<stats-index (1-65535)>]] [alarms][events] [history <history-index (1-65535)> [overview]]
Syntax Descriptionstatistics stats-index(1-65535)To display the RMON collection stats data configured
alarmsTo display the RMON alarms data configured
eventsTo display the RMON events data configured
history history-index(1-65535)To display the RMON collection history data configured
overviewTo display the overview of RMON entries
Command ModesPrivileged EXEC Mode

Example

switch# show rmon

RMON is enabled

switch# show rmon statistics 1 alarms events history overview

RMON is enabled

Collection 1 on Fa0/5 is active, and owned by trendnet, Monitors ifEntry.1.5 which has Received 0 octets, 0 packets, 0 broadcast and 0 multicast packets, 0 undersized and 0 oversized packets, 0 fragments and 0 jabbers, 0 CRC alignment errors and 0 collisions.

of packets received of length (in octets):

64: 0, 65-127: 0, 128-255: 0, 256-511: 0, 512-1023: 0, 1024-1518: 0 Alarm table is empty

Event 1 is active, owned by trendnet

Description is trendnet

Event firing causes log,

Time last sent is Jan 1 00:07:41 2009

Entry 1 is active, and owned by trendnet

Monitors ifEntry.1.5 every 1 second(s)

Requested # of time intervals, ie buckets, is 1,

Granted # of time intervals, ie buckets, is 1,

Command History

Version

History

1.00.001

This command was introduced

Chapter 42

Statistics Command

Statistics Command List

clear interfaces
CommandTo clear counters of interfaces.
clear interfaces [ ] counters
Syntax Descriptioninterface-type specify which counters of which interface to clear. interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel. Interface-id is slot/port number or port channel ID.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will clear all interface counters when executing the command without a interface type and ID.
Exampleswitch# clear interfaces counters
switch# clear interfaces fa 0/1 counters
Command HistoryVersionHistory
1.00.001This command was introduced
show ip traffic
CommandTo display the statistic of IP traffic and ICMP traffic
show ip traffic
Command ModesPrivileged EXEC Mode

Example

switch# show ip traffic

IP Statistics:

Rcvd: 1817 total, 0 header error discards 0 bad ip address discards, 12 unsupported prot discards

Frags: 0 reassembled, 30 timeouts, 0 needs reassembly 0 fragmented, 0 couldn't fragment

Bcast: Sent: 0 forwarded, 2845 generated requests Drop:

ICMP Statistics:

Rcvd: 4 total, 0 checksum errors, 0 unreachable, 0 redirected 0 time exceeded, 0 param problems, 0 quench 4 echo, 0 echo reply, 0 mask requests, 0 mask replie 0 timestamp, 0 time stamp reply,

Sent: 4 total, 0 checksum errors, 0 unreachable, 0 redirected 0 time exceeded, 0 param problems, 0 quench 0 echo, 4 echo reply, 0 mask requests, 0 mask replied 0 timestamp, 0 time stamp reply,

Command History

Version

History

1.00.001

This command was introduced

Chapter 43

System Operation Command

System Operation Command List

watchdog
copy
ping
help
clear screen
lock
logout
cmdbuffs
show history
dir flash:
space flash:
space memory:
?

watchdog

CommandTo auto-recover the Switch if Switch was found hanging up.
watchdog { enable | disable}
Syntax DescriptionenableEnables the watchdog.
disableDisables the watchdog.
Default SettingsDisable
Command ModesPrivileged EXEC Mode
Exampleswitch# watchdog
Command HistoryVersionHistory
1.00.001This command was introduced
copy

To download a file from TFTP server to local flash or upload a local file to TFTP server.

Commandcopy { tftp://ip-address/filename | flash: filename}{ tftp://ip-address/filename | flash: filename}
Syntax Descriptiontftp://ip-address/filenameThe IP address the remote tftp server and the filename you would like to copy from.
flash: filenameThe path and filename of the local file you would like to copy from.
tftp://ip-address/filenameThe IP address the remote tftp server and the file name to be saved.
flash: filenameThe path and filename you would like to saved in local flash
Command ModesPrivileged EXEC Mode
Exampleswitch# copy tftp://172.17.0.100/syslog1 flash:backuplog
Command HistoryVersion History
1.00.001 This command was introduced
ping
CommandSending out ICMP echo request to verify a specific IP address is available.
ping [ ip ][size] [count] [timeout]
Syntax Descriptionip destination-addressSpecify which IP address to send echo request.
size packet_size (0-2080)Specify the size of ping packet to send.
count packet_count (1-10)Specify how mand echo request to send.
timeout time_out (1-100)Specify the timeout in seconds to wait each ICMP echo reply.
Default SettingsPacket count: 3Timeout: 5
Command ModesPrivileged EXEC Mode
Exampleswitch# ping ip 192.168.0.2 size 2080Reply Received From :192.168.0.2, TimeTaken : 10 msecsReply Received From :192.168.0.2, TimeTaken : 20 msecsReply Received From :192.168.0.2, TimeTaken : 20 msecs--- 192.168.0.2 Ping Statistics ---3 Packets Transmitted, 3 Packets Received, 0% Packets Loss
Command HistoryVersion History
1.00.001 This command was introduced

help

CommandTo list all the command starting with the given keyword and also display th description of the command.help
Syntax DescriptioncommandSpecify which command you would like to get the help.
Command ModesAll Modes
User GuidelinesSystem will display all commands under the command mode without descriptions when executing the command without a keyword.
Exampleswitch(config)# help sys
CONFIGURE commands :system cli-timeout <1-18000 seconds>[Desc]: Sets Cli auto timeout interval system contact[Desc]: Sets the system contact information system location[Desc]: Sets the system location system name[Desc]: Sets the system name system web-timeout <180-3600 seconds>[Desc]: Sets Web auto timeout interval
switch(config-cmap)# help
CLASSMAP commands :clear screenendexithelp [ command ]match access-group { mac-access-list | ip-access-list
Command HistoryVersionHistory
1.00.001This command was introduced
clear screen
CommandTo clear the screen.
clear screen
Command ModesAll Modes
Exampleswitch# clear screen
Command HistoryVersionHistory
1.00.001This command was introduced
lock
Command ModesTo lock the command line interface to prevent unauthorized user accessing the Switch.
lock
Command GuidelinesPrivileged EXEC Mode
Entering the password of any privilege 15 user to unlock.
Exampleswitch# lockCLI console lockedEnter Password to unlock the console:
Command HistoryVersionHistory
1.00.001This command was introduced
logout
Command ModesTo logout the Switch.
logout
Command HistoryPrivileged EXEC Mode
switch# logout
Command HistoryVersionHistory
1.00.001This command was introduced
cmdbuffs
CommandTo configure the syslog buffer size for a particular user.
cmdbuffs
Syntax Descriptionuser nameSpecify which user to configure the buffer size.
no.of buffers (1-200)Specify the number of buffer size.
Command ModesGlobal Configuration Model
Exampleswitch(config)# cmdbuffs root 200
Command HistoryVersionHistory
1.00.001This command was introduced
show history
CommandTo display the command history had been executed.
show history
Command ModesPrivileged EXEC Mode
User GuidelinesThe command history is listed form the first executed command to the latest one.
Exampleswitch#
Command HistoryVersionHistory
1.00.001This command was introduced
dir flash:
CommandTo display the files stored in NV-RAM.
dir flash:
Command ModesPrivileged EXEC Mode
Exampleswitch# dir flash:
Command HistoryVersionHistory
1.00.001This command was introduced
space flash:

To display the space of NV-RAM remained

Commandspace flash:
Command ModesPrivileged EXEC Mode
Exampleswitch# space flash:
Command HistoryVersionHistory
1.00.001This command was introduced
space memory:
CommandTo display the space of DRAM remained
space memory:
Command ModesPrivileged EXEC Mode
Exampleswitch# space memory:
Command HistoryVersionHistory
1.00.001This command was introduced
?
CommandTo display the next possible keyword or parameter of the command
?
Command ModesAll Modes
Exampleswitch# space ?EXEC commands :space flash:space memory:
Command HistoryVersionHistory
1.00.0010This command was introduced

Chapter 44

Interface Command

Interface Command List

interfaceshutdownmtushow interfacesshow interface mtushow interfaces counters
interface
CommandTo create or enter a physical or logical network interface.
interface { vlanMgmt | Port-Channel|no interface { vlanMgmt | Port-Channel(1-65535) |}
Syntax DescriptionvlanMgmtTo enter the management VLAN of the Switch.
Port-Channelport-channel-id(1-65535)To enter a port channel interface. If the channel ID specified doesn't exist, system will create a new port channel.
interface-typeinterface idTo enter a physical port.Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet).Interface-id is slot/port number.
Command ModesGlobal Configuration Mode
User GuidelinesTo create or entering a port channel, port-channel function must be enabled first.
Exampleswitch(config)#interface fa 0/1switch(config-if)#
Command HistoryVersionHistory
1.00.001This command was introduced.
shutdown

Shutting down the network interface.

24-Port 10/100Mbps Layer 2 Switch w/ 4 Gigabit Ports and 2 Shared Mini-GBIC Slots

Commandshutdown
no shutdown
Default SettingsInterfaces had been created are active by default.
Command ModesInterface Configuration Mode
User GuidelinesThe no form reactivates the interface.
Exampleswitch(config-if)# shut down
Command HistoryVersionHistory
1.00.001This command was introduced.
mtu
CommandTo setup the Maximum Transmission Unit (MTU) frame size of the interface.
mtu
Syntax Descriptionframe-size(90-1522)
Default Settings1500
Command ModesInterface Configuration Mode
User GuidelinesInterface must be shutdown before configuring MTU size.
Exampleswitch(config-if)# mtu 90
Command HistoryVersionHistory
1.00.001This command was introduced.
show interfaces
CommandTo display the status, configurations or statistics of the interface
show interfaces [{ [][ { description | flowcontrol | capabilities | status port-channel}]
Syntax Descriptioninterface-type interface-idSpecify the information of which interface to display. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
descriptionDisplay the link status and protocol status of the interface
flowcontrolDisplay the flow control setting and pause frame statistic of the interface
capabilitiesDisplay the capabilities of the interface
statusDisplay the current status of the interface
port-channel port-channel-id (1-65535)Port channel ID
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display information of all interfaces when executing the command without given parameters.
Exampleswitch# show interface fa 0/5 description
Interface Status Protocol
Fa0/5 up up
switch# show interface fa 0/5 flowcontrol
Port Tx FlowControl Rx FlowControl Tx Pause Rx Paus
Fa0/5 off off 0 0
switch# show interface fa 0/5 capabilities
Fa0/5 Type : 10/100/1000 Base TX Speed : 10, 100, 1000, Auto Duplex : Half, Full FlowControl : Send, Receive
switch# show interface fa 0/5 status
Port Status Duplex Speed Negotiation
Fa0/5 connected Full 100 Mbps Auto Copper
Command HistoryVersion History
1.00.001 This command was introduced.

show interface mtu

To display the MTU setting of the interface.

Commandshow interface mtu [{ Vlan| port-channelid(1-65535) |}
Syntax DescriptionVlan vlan-id (1-4094)VLAN ID
port-channel port-channel-id (1-65535)Port channel ID
interface-type interface-idSpecify which interface to show the mtu setting. Interface-type including Fa (Fast Ethernet) or Gi (Gigabit Ethernet). Interface-id is slot/port number.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display MTU settings for all interface when executing the command without given parameters.
Exampleswitch# show interface mtu fa 0/1
Fa0/1 MTU size is 1522
Command HistoryVersionHistory
1.00.001This command was introduced.

show interfaces counters

CommandTo display the statistics of interfaces.show interfaces [{<interface-type><interface-id>}] counters
Syntax Descriptioninterface-type interface-idSpecify the counter information of which interface to display.Interface-type including Fa (Fast Ethernet), Gi (Gigabit Ethernet) or port-channel.Interface-id is slot/port number or port-channel ID.
Command ModesPrivileged EXEC Mode
User GuidelinesSystem will display statistics for all interfaces when executing the command without interface-type and interface-id.

Example
switch# show interface fa 0/12 counters

PortInHCOctetInOctetInUcastInDiscardInErrs
--------------------
Fa0/123015962630159626876300
PortOutHCOctetOutOctetOutUcastOutDiscardOutErrs
--------------------
Fa0/12226671285800

Command History

VersionHistory
1.00.001This command was introduced

Technical Specifications

Hardware
StandardsIEEE 802.3 10BASE-TIEEE 802.3u 100BASE-TXIEEE 802.3ab 1000BASE-TIEEE 802.3z 1000BASE-X SX/LXIEEE 802.3x Flow Control and Back PressureIEEE 802.3ad Link Aggregaon/Port Trunking (LACP)IEEE 802.1d Spanning Tree (STP)IEEE 802.1w Rapid Spanning Tree (RSTP)IEEE 802.1s Mulple Spanning Tree (MSTP)IEEE 802.1p Quality of Service/Class of Service (QoS/CoS)IEEE 802.1Q VLAN Tagging and GVRPIEEE 802.1X Port-Based Network Access Control
Interface24 x 10/100Mbps Auto-MDIX Fast Ethernet ports4 x 10/100/1000Mbps Auto-MDIX Gigabit ports2 x shared SFP (Mini-GBIC) slots1 x RS-232 console port for switch management
CablingNetwork:10Base-T: UTP/STP Cat. 5 cable (100m)100Base-TX: UTP/STP Cat. 5, 5e cable (100m)1000Base-T: UTP/STP Cat 5e, 6 cable (100m)Mini-GBIC:LC (Mul-Mode): 50/125um~62.5/125umLC (Single Mode): 9/125um~10/125um
Switching MethodStore-and-Forward
Protocol/Topology(CSMA/CD) / Star
Buer Memory256KByte data buer
Filtering Address Table8K MAC address entries
Switch Fabric/CapacityUp to 12.8Gbps
LED DisplayPWR (Green): Power, SYS (Green): System10M Link/ACT (Amber): 10Mbps Link/Acvity (per Ethernet port)100M Link/ACT (Green): 100Mbps Link/Acvity (per Ethernet port)10/100M Link/ACT (Amber): 10/100Mbps Link/Acvity (per Gigabit port)1000M Link/ACT (Green): 1000Mbps Link/Acvity (per Gigabit port)
PowerInput: 100~240VAC, 50/60Hz internal power supply
Power Consumpon16.8 W
Dimensions440 x 140 x 44 mm (17.3 x 5.5 x 1.7 in.)
Weight2 kg (4.5 lbs.)
TemperatureOperang: 0° ~ 40° C (32° ~ 104° F)Storage: -10° ~ 70° C (14° ~ 158° F)
HumidityMax. 90% (non-condensing)
CercaonsCE, FCC
Soware
ManagementSNMP v1, v2c, v3, HTTP/HTTPS Web, Telnet, SSH, console
Spanning Tree802.1d STP (Spanning Tree Protocol)802.1w RSTP (Rapid Spanning Tree Protocol)802.1s MSTP (Mulple Spanning Tree Protocol)
Link AggregaonStac Link Aggregaon802.3ad Dynamic LACP
Quality of Service802.1p Class of ServicePort Based QoSDSCP (Dierenated Services Code Point)
VLANAsymmetric VLAN802.1Q Tagged VLAN & Dynamic GVRPUp to 256 stac/dynamic groups
IGMPSupport IGMP Snooping v1/2Up to 64 mulcast entries
Port MirrorRX, TX, or both
SecurityMAC Address learning, ACL L2/L3/L4User Authencaon: 802.1X Port-Based Network Access Control, Local User Database
Frame Size1522 bytes (max.)
Bandwidth ControlBandwidth control per port
Flow Control802.3x Flow Control for Full-Duplex and back pressure for Half-Duplex
Firmware UpdateSupport TFTP rmware update, TFTP backup and restore, via Web Browser

Limited Warranty

TRENDnet warrants its products against defects in material and workmanship, under normal use and service, for the following lengths of me from the date of purchase.

AC/DC Power Adapter, Cooling Fan, and Power Supply carry 1 year warranty.

If a product does not operate as warranted during the applicable warranty period, TRENDnet shall reserve the right, at its expense, to repair or replace the defective product or part and deliver an equivalent product or part to the customer. The repair/replacement unit's warranty connues from the original date of purchase. All products that are replaced become the property of TRENDnet. Replacement products may be new or reconditioned. TRENDnet does not issue refunds or credit. Please contact the point-of-purchase for their return policies.

TRENDnet shall not be responsible for any soware, rmware, informaon, or memory data of customer contained in, stored on, or integrated with any products returned to TRENDnet pursuant to any warranty.

There are no user serviceable parts inside the product. Do not remove or aempt to service the product by any unauthorized service center. This warranty is voided if (i) the product has been modified or repaired by any unauthorized service center, (ii) the product was subject to accident, abuse, or improper use (iii) the product was subject to conditions more severe than those specified in the manual.

Warranty service may be obtained by contacng TRENDnet within the applicable warranty period and providing a copy of the dated proof of the purchase. Upon proper submission of required documentaon a Return Material Authorizaon (RMA) number will be issued. An RMA number is required in order to initiate warranty service support for all TRENDnet products. Products that are sent to TRENDnet for RMA service must have the RMA number marked on the outside of return packages and sent to TRENDnet prepaid, insured and packaged appropriately for safe shipment. Customers shipping from outside of the USA and Canada are responsible for return shipping fees. Customers shipping from outside of the USA are responsible for custom charges, including but not limited to, duty, tax, and other fees.

WARRANTIES EXCLUSIVE: IF THE TRENDNET PRODUCT DOES NOT OPERATE AS WARRANTED ABOVE, THE CUSTOMER'S SOLE REMEDY SHALL BE, AT TRENDNET'S OPTION, REPAIR OR REPLACE. THE FOREGOING WARRANTIES AND REMEDIES ARE EXCLUSIVE AND ARE IN LIEU OF ALL OTHER WARRANTIES, EXPRESSED OR IMPLIED, EITHER IN FACT OR BY OPERATION OF LAW, STATUTORY OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. TRENDNET NEITHER ASSUMES NOR AUTHORIZES ANY OTHER PERSON TO ASSUME FOR IT ANY OTHER LIABILITY IN CONNECTION WITH THE SALE, INSTALLATION MAINTENANCE OR USE OF TRENDNET'S PRODUCTS.

TRENDNET SHALL NOT BE LIABLE UNDER THIS WARRANTY IF ITS TESTING AND EXAMINATION DISCLOSE THAT THE ALLEGED DEFECT IN THE PRODUCT DOES NOT EXIST OR WAS CAUSED BY CUSTOMER'S OR ANY THIRD PERSON'S MISUSE, NEGLECT, IMPROPER INSTALLATION OR TESTING, UNAUTHORIZED ATTEMPTS TO REPAIR OR MODIFY, OR ANY OTHER CAUSE BEYOND THE RANGE OF THE INTENDED USE, OR BY ACCIDENT, FIRE, LIGHTNING, OR OTHER HAZARD.

LIMITATION OF LIABILITY: TO THE FULL EXTENT ALLOWED BY LAW TRENDNET ALSO EXCLUDES FOR ITSELF AND ITS SUPPLIERS ANY LIABILITY, WHETHER BASED IN CONTRACT OR TORT (INCLUDING NEGLIGENCE), FOR INCIDENTAL, CONSEQUENTIAL, INDIRECT, SPECIAL, OR PUNITIVE DAMAGES OF ANY KIND, OR FOR LOSS OF REVENUE OR PROFITS, LOSS OF BUSINESS, LOSS OF INFORMATION OR DATE, OR OTHER FINANCIAL LOSS ARISING OUT OF OR IN CONNECTION WITH THE SALE, INSTALLATION, MAINTENANCE, USE, PERFORMANCE, FAILURE, OR INTERRUPTION OF THE POSSIBILITY OF SUCH DAMAGES, AND LIMITS ITS LIABILITY TO REPAIR, REPLACEMENT, OR REFUND OF THE PURCHASE PRICE PAID, AT TRENDNET'S OPTION. THIS DISCLAIMER OF LIABILITY FOR DAMAGES WILL NOT BE AFFECTED IF ANY REMEDY PROVIDED HEREIN SHALL FAIL OF ITS ESSENTIAL PURPOSE.

Governing Law: This Limited Warranty shall be governed by the laws of the state of California.

Some TRENDnet products include soware code written by third party developers. These codes are subject to the GNU General Public License ("GPL") or GNU Lesser General Public License ("LGPL").

Go to hp://www.trendnet.com/gpl_or hp://www.trendnet.com_Download secon and look for the desired TRENDnet product to access to the GPL Code or LGPL Code. These codes are distributed WITHOUT WARRANTY and are subject to the copyrights of the developers. TRENDnet does not provide technical support for these codes. Please go to hp://www.gnu.org/licenses/gpl.txt or hp://www.gnu.org/licenses/lgpl.txt for specific terms of each license.

PWP05202009v2

TRENDNET TL2-E284 - Limited Warranty - 1

TRENDNET®

Product Warranty Registration

Please take a moment to register your product online. Go to TRENDnet's website at http://www.trendnet.com/register

Table of contents Click a title to access it
Manual assistant
Powered by Anthropic
Waiting for your message
Product information

Brand : TRENDNET

Model : TL2-E284

Category : Switch