Command Line Interface Guide
Page 28
... is connected to the device prior to enter the QoS services configuration mode. Starting the CLI The switch can be managed over a direct connection to manually specify other device SSH public keys. Contains commands related to modify specific interface operations. The Global Configuration mode command crypto key pubkey-chain ssh is...
... is connected to the device prior to enter the QoS services configuration mode. Starting the CLI The switch can be managed over a direct connection to manually specify other device SSH public keys. Contains commands related to modify specific interface operations. The Global Configuration mode command crypto key pubkey-chain ssh is...
Command Line Interface Guide
Page 29
... not displayed. To start using the CLI, there is an assortment of editing features. The User Exec mode is entered, and the prompt "Console>" is manually entered.
... not displayed. To start using the CLI, there is an assortment of editing features. The User Exec mode is entered, and the prompt "Console>" is manually entered.
Command Line Interface Guide
Page 37
... at a Privileged User specific VLAN. EXEC Displays statically created entries in locked ports. Privileged User EXEC Clock Commands Command Group Description Access Mode clock set Manually sets the system clock. Configuration sntp authenticate Grants authentication for received Network Time Global Protocol (NTP) traffic from servers. Global Configuration sntp client enable (interface...
... at a Privileged User specific VLAN. EXEC Displays statically created entries in locked ports. Privileged User EXEC Clock Commands Command Group Description Access Mode clock set Manually sets the system clock. Configuration sntp authenticate Grants authentication for received Network Time Global Protocol (NTP) traffic from servers. Global Configuration sntp client enable (interface...
Command Line Interface Guide
Page 53
Global Configuration Specifies which SSH public key is manually configured and enters the SSH public key-string configuration command. SSH Public Key Displays the SSH server configuration. Privileged User EXEC... Global Configuration Global Configuration Global Configuration Global Configuration Command Groups 53 Global Configuration Enables public key authentication for incoming SSH sessions. SSH Public Key Manually specifies a SSH public key. Limits messages logged to a syslog server. Global Configuration Generates DSA key pairs. Privileged User EXEC Syslog Commands ...
Global Configuration Specifies which SSH public key is manually configured and enters the SSH public key-string configuration command. SSH Public Key Displays the SSH server configuration. Privileged User EXEC... Global Configuration Global Configuration Global Configuration Global Configuration Command Groups 53 Global Configuration Enables public key authentication for incoming SSH sessions. SSH Public Key Manually specifies a SSH public key. Limits messages logged to a syslog server. Global Configuration Generates DSA key pairs. Privileged User EXEC Syslog Commands ...
Command Line Interface Guide
Page 60
... and the RSA keys within a pkcs12 PKCS12 file Privileged User EXEC show crypto certificate Displays the SSL certificates of the client. dot1x port-control Enables manual control of the authorization state of the port dot1x re-authentication Enables periodic re-authentication of the device mycertificate Privileged User EXEC show ip https...
... and the RSA keys within a pkcs12 PKCS12 file Privileged User EXEC show crypto certificate Displays the SSL certificates of the client. dot1x port-control Enables manual control of the authorization state of the port dot1x re-authentication Enables periodic re-authentication of the device mycertificate Privileged User EXEC show ip https...
Command Line Interface Guide
Page 61
...- dot1x timeout reauthperiod Sets the number of all 802.1X-enabled Privileged User ports or the specified 802.1X-enabled port. Configuration dot1x re-authenticate Manually initiates a re-authentication of seconds between re-authentica- request/identity frame to the Interface authentication server. Configuration show dot1x statistics Displays 802.1X statistics for...
...- dot1x timeout reauthperiod Sets the number of all 802.1X-enabled Privileged User ports or the specified 802.1X-enabled port. Configuration dot1x re-authenticate Manually initiates a re-authentication of seconds between re-authentica- request/identity frame to the Interface authentication server. Configuration show dot1x statistics Displays 802.1X statistics for...
Command Line Interface Guide
Page 67
... router solicitations messages (when there is known) for the communication with a Port-channel. Associates a port with TACACS servers. Enables authentication based on a given interface. Enables manual control of the authorization state of the port Enables periodic re-authentication of the 802.1X MAC authentication access control. Establishes a username-based authentication system...
... router solicitations messages (when there is known) for the communication with a Port-channel. Associates a port with TACACS servers. Enables authentication based on a given interface. Enables manual control of the authorization state of the port Enables periodic re-authentication of the 802.1X MAC authentication access control. Establishes a username-based authentication system...
Command Line Interface Guide
Page 71
clock set interface active Reactivates an interface that was suspended by the system. set Manually sets the system clock. set to auto. show dot1x advanced Displays 802.1X enhanced features for the switch or for the specified interface. show bridge... or on the device. Restarts the protocol migration process on all 802.1X-enabled ports or the specified 802.1X-enabled port. dot1x re-authenticate Manually initiates a re-authentication of addresses present in all VLANs or at startup show copper-ports cable-length Displays the estimated copper cable length attached to...
clock set interface active Reactivates an interface that was suspended by the system. set Manually sets the system clock. set to auto. show dot1x advanced Displays 802.1X enhanced features for the switch or for the specified interface. show bridge... or on the device. Restarts the protocol migration process on all 802.1X-enabled ports or the specified 802.1X-enabled port. dot1x re-authenticate Manually initiates a re-authentication of addresses present in all VLANs or at startup show copper-ports cable-length Displays the estimated copper cable length attached to...
Command Line Interface Guide
Page 72
... diagnostics. show ip ssh Displays the SSH server configuration. SP (SSH Public Key) Mode Command key-string user-key Description Manually specifies a SSH public key. show users accounts Displays information about the local user database. show management access-list Displays management ... the active management Access-List. show ipv6 neighbors Displays IPv6 neighbor discovery cache information. Specifies which SSH public key is manually configured and enters the SSH public key-string configuration command 72 Command Modes show ports security Displays the port-lock status....
... diagnostics. show ip ssh Displays the SSH server configuration. SP (SSH Public Key) Mode Command key-string user-key Description Manually specifies a SSH public key. show users accounts Displays information about the local user database. show management access-list Displays management ... the active management Access-List. show ipv6 neighbors Displays IPv6 neighbor discovery cache information. Specifies which SSH public key is manually configured and enters the SSH public key-string configuration command 72 Command Modes show ports security Displays the port-lock status....
Command Line Interface Guide
Page 123
..., mm: 0 59, ss: 0 - 59) • day - Command Mode Privileged EXEC mode. Current year. (2000 - 2097) Default Configuration The default time set Privileged EXEC mode command manually sets the system clock. Current time in the month. (1 - 31) • month - Current day (by name. (Jan, ..., Dec) • year - User Guidelines • There are...
..., mm: 0 59, ss: 0 - 59) • day - Command Mode Privileged EXEC mode. Current year. (2000 - 2097) Default Configuration The default time set Privileged EXEC mode command manually sets the system clock. Current time in the month. (1 - 31) • month - Current day (by name. (Jan, ..., Dec) • year - User Guidelines • There are...
Command Line Interface Guide
Page 124
... UTC. (Range: 0 - 59) • zone acronym - Command Mode Global Configuration mode. User Guidelines • The system internally keeps time in UTC, so this command is manually set the time to 4 characters) Default Configuration UTC. Syntax • clock source {sntp} • no clock timezone • hours-offset - Console# clock source sntp clock...
... UTC. (Range: 0 - 59) • zone acronym - Command Mode Global Configuration mode. User Guidelines • The system internally keeps time in UTC, so this command is manually set the time to 4 characters) Default Configuration UTC. Syntax • clock source {sntp} • no clock timezone • hours-offset - Console# clock source sntp clock...
Command Line Interface Guide
Page 157
...)# interface ethernet 1/4 Console(config-if)# system flowcontrol mdix The mdix Interface Configuration mode command enables automatic crossover on cascade ports. Command Mode Interface Configuration mode. Manual mdix • auto - Syntax system flowcontrol no mdix • on port 1/4. Command Mode Interface Configuration (Ethernet) mode. To disable flow control, use the no form...
...)# interface ethernet 1/4 Console(config-if)# system flowcontrol mdix The mdix Interface Configuration mode command enables automatic crossover on cascade ports. Command Mode Interface Configuration mode. Manual mdix • auto - Syntax system flowcontrol no mdix • on port 1/4. Command Mode Interface Configuration (Ethernet) mode. To disable flow control, use the no form...
Command Line Interface Guide
Page 187
... disabled. The gvrp enable Global Configuration mode command enables GVRP globally. Command Mode Global Configuration mode. Use the no gvrp enable Default Configuration GVRP is manually configured with all desired VLANs for this command to disable GVRP globally on the switch. Syntax • gvrp enable • no form of this command...
... disabled. The gvrp enable Global Configuration mode command enables GVRP globally. Command Mode Global Configuration mode. Use the no gvrp enable Default Configuration GVRP is manually configured with all desired VLANs for this command to disable GVRP globally on the switch. Syntax • gvrp enable • no form of this command...
Command Line Interface Guide
Page 220
... on the interface MAC address. • anycast - The IPv6 network assigned to remove the address from an interface, including link local manually configured addresses. 220 IP Addressing Commands User Guidelines • If the value specified for a range of the address). Default Configuration No ... Syntax • ipv6 address ipv6-address/prefix-length [eui-64] [anycast] • no ipv6 address command without arguments removes all manually configured IPv6 addresses from the interface. Console> show ipv6 icmp error-interval Rate limit interval: 100 ms Bucket size: 10 tokens ipv6 ...
... on the interface MAC address. • anycast - The IPv6 network assigned to remove the address from an interface, including link local manually configured addresses. 220 IP Addressing Commands User Guidelines • If the value specified for a range of the address). Default Configuration No ... Syntax • ipv6 address ipv6-address/prefix-length [eui-64] [anycast] • no ipv6 address command without arguments removes all manually configured IPv6 addresses from the interface. Console> show ipv6 icmp error-interval Rate limit interval: 100 ms Bucket size: 10 tokens ipv6 ...
Command Line Interface Guide
Page 221
...is enabled on the interface. The address is FE80::EUI64 (interface MAC address). Command Mode Interface configuration (Ethernet, VLAN, Port-channel). To manually specify a link-local address to be configured per interface, but only one linklocal address. Console# Console (config)# interface g1 Console (config-if... an IPv6 link-local address for a range of interfaces (range context). When the no ipv6 link-local address command removes the manually configured link local IPv6 address from an interface. User Guidelines • Using the no ipv6 link-local address command is used, ...
...is enabled on the interface. The address is FE80::EUI64 (interface MAC address). Command Mode Interface configuration (Ethernet, VLAN, Port-channel). To manually specify a link-local address to be configured per interface, but only one linklocal address. Console# Console (config)# interface g1 Console (config-if... an IPv6 link-local address for a range of interfaces (range context). When the no ipv6 link-local address command removes the manually configured link local IPv6 address from an interface. User Guidelines • Using the no ipv6 link-local address command is used, ...
Command Line Interface Guide
Page 225
g2 7001::5668/64 [ANY] g2 6001::1234/64 g2 fe80::22/64 g2 ff02::1 g2 ff02::78 Type ----manual manual manual linklayer manual IP Addressing Commands 225 Port channel number Default Configuration Displays all IPv6 interfaces. Console# show ipv6 neighbors command in the privileged EXEC mode. Console(config-...
g2 7001::5668/64 [ANY] g2 6001::1234/64 g2 fe80::22/64 g2 ff02::1 g2 ff02::78 Type ----manual manual manual linklayer manual IP Addressing Commands 225 Port channel number Default Configuration Displays all IPv6 interfaces. Console# show ipv6 neighbors command in the privileged EXEC mode. Console(config-...
Command Line Interface Guide
Page 226
... 1 VLAN 1 VLAN 1 VLAN 1 VLAN 1 VLAN 1 ff02::1:ff00:22 manual ff02::1:ff00:1234 manual ff02::1:ff00:5668 manual 2002:1:1:1:200:b0ff:fe00:: other 3001::1/64 manual 4004::55/64 [ANY] manual fe80::200:b0ff:fe00:0 linklayer ff02::1 linklayer ff02::77 manual ff02::1:ff00:0 manual ff02::1:ff00:1 manual ff02::1:ff00:55 manual Default Gateway IP address fe80::77 fe80::200:cff...
... 1 VLAN 1 VLAN 1 VLAN 1 VLAN 1 VLAN 1 ff02::1:ff00:22 manual ff02::1:ff00:1234 manual ff02::1:ff00:5668 manual 2002:1:1:1:200:b0ff:fe00:: other 3001::1/64 manual 4004::55/64 [ANY] manual fe80::200:b0ff:fe00:0 linklayer ff02::1 linklayer ff02::77 manual ff02::1:ff00:0 manual ff02::1:ff00:1 manual ff02::1:ff00:55 manual Default Gateway IP address fe80::77 fe80::200:cff...
Command Line Interface Guide
Page 227
...; There are no default setting. IP addresses Type ------ 2002:1:1:1:200:b0ff:fe00 other :: 3001::1/64 manual 4004::55/64 [ANY] manual fe80::200:b0ff:fe00:0 linklayer ff02::1 linklayer ff02::77 manual ff02::1:ff00:0 manual ff02::1:ff00:1 manual ff02::1:ff00:55 manual DAD State --------Active Active Active Active Active show ipv6 route The show ipv6 route Default...
...; There are no default setting. IP addresses Type ------ 2002:1:1:1:200:b0ff:fe00 other :: 3001::1/64 manual 4004::55/64 [ANY] manual fe80::200:b0ff:fe00:0 linklayer ff02::1 linklayer ff02::77 manual ff02::1:ff00:0 manual ff02::1:ff00:1 manual ff02::1:ff00:55 manual DAD State --------Active Active Active Active Active show ipv6 route The show ipv6 route Default...
Command Line Interface Guide
Page 380
...Configuration mode command specifies which SSH public key is used when you need to remove a SSH public key. 380 SSH Commands The mode is manually configured and enters the SSH Public Key-chain Configuration mode command. Syntax • crypto key pubkey-chain ssh Default Configuration By default, there .... Use the no form of this command to enter Public Key-chain Configuration mode. • This command can also be used to manually specify other device public keys such as SSH client public keys. Command Mode Global Configuration mode. User Guidelines • Use this command to...
...Configuration mode command specifies which SSH public key is used when you need to remove a SSH public key. 380 SSH Commands The mode is manually configured and enters the SSH Public Key-chain Configuration mode command. Syntax • crypto key pubkey-chain ssh Default Configuration By default, there .... Use the no form of this command to enter Public Key-chain Configuration mode. • This command can also be used to manually specify other device public keys such as SSH client public keys. Command Mode Global Configuration mode. User Guidelines • Use this command to...
Command Line Interface Guide
Page 381
...long. • rsa - Syntax • key-string row key-string • row - SSH Commands 381 Specifies the remote SSH client username, which can be manually configured for the SSH public key chain called "bob". UU-encoded DER format is the same format in authorized_keys file used by row • key... rsa Console(config-pubkey-key)# key-string row key-string AAAAB3NzaC1yc2EAAAADAQABAAABAQCvTnRwPWl key-string The key-string SSH Public Key-String Configuration mode command manually specifies a SSH public key. RSA key. • dsa - Command Mode SSH Public Key Chain Configuration mode.
...long. • rsa - Syntax • key-string row key-string • row - SSH Commands 381 Specifies the remote SSH client username, which can be manually configured for the SSH public key chain called "bob". UU-encoded DER format is the same format in authorized_keys file used by row • key... rsa Console(config-pubkey-key)# key-string row key-string AAAAB3NzaC1yc2EAAAADAQABAAABAQCvTnRwPWl key-string The key-string SSH Public Key-String Configuration mode command manually specifies a SSH public key. RSA key. • dsa - Command Mode SSH Public Key Chain Configuration mode.