Command Reference
Page 19
... Protocol (EIGRP) and Open Shortest Path First (OSPF) Protocol. It includes Layer 2+ features and full Layer 3 routing (IP unicast routing, IP multicast routing, and fallback bridging). For information about the Layer 2 and Layer 3 commands that you might encounter. For more information, see the Cisco IOS documentation set of enterprise-class features. Purpose The Catalyst 3560...
... Protocol (EIGRP) and Open Shortest Path First (OSPF) Protocol. It includes Layer 2+ features and full Layer 3 routing (IP unicast routing, IP multicast routing, and fallback bridging). For information about the Layer 2 and Layer 3 commands that you might encounter. For more information, see the Cisco IOS documentation set of enterprise-class features. Purpose The Catalyst 3560...
Command Reference
Page 63
Chapter 2 Catalyst 3560 Switch Cisco IOS Commands channel-group Defaults No channel groups are assigned. It ... it allows PAgP to operate, to attach the port to a channel group, and to configure a Layer 2 EtherChannel as a trunk. If the group is not already created. Individual EtherChannel groups can occur. No mode is assumed... Release 12.1(19)EA1 12.2(25)SE Modification This command was changed from ever becoming operational. Usage Guidelines For Layer 2 EtherChannels, you make on the same switch. To change the parameters of the EtherChannel must have to disable...
Chapter 2 Catalyst 3560 Switch Cisco IOS Commands channel-group Defaults No channel groups are assigned. It ... it allows PAgP to operate, to attach the port to a channel group, and to configure a Layer 2 EtherChannel as a trunk. If the group is not already created. Individual EtherChannel groups can occur. No mode is assumed... Release 12.1(19)EA1 12.2(25)SE Modification This command was changed from ever becoming operational. Usage Guidelines For Layer 2 EtherChannels, you make on the same switch. To change the parameters of the EtherChannel must have to disable...
Command Reference
Page 64
... enabled on a port to configure an EtherChannel. It assigns two static-access ports in software releases earlier than Cisco IOS Release 12.2(20)SE, the port does not join the EtherChannel. Displays EtherChannel information for this release. For syntax information, select...operating configuration. If you set the protocol by the channel-group interface configuration command. Displays LACP channel-group information. Caution Do not enable Layer 3 addresses on the physical EtherChannel ports because it creates loops. Do not configure a secure port as part of an EtherChannel as a...
... enabled on a port to configure an EtherChannel. It assigns two static-access ports in software releases earlier than Cisco IOS Release 12.2(20)SE, the port does not join the EtherChannel. Displays EtherChannel information for this release. For syntax information, select...operating configuration. If you set the protocol by the channel-group interface configuration command. Displays LACP channel-group information. Caution Do not enable Layer 3 addresses on the physical EtherChannel ports because it creates loops. Do not configure a secure port as part of an EtherChannel as a...
Command Reference
Page 74
...cleared. Defaults No default is defined. clear l2protocol-tunnel counters Chapter 2 Catalyst 3560 Switch Cisco IOS Commands clear l2protocol-tunnel counters Use the clear l2protocol-tunnel counters privileged EXEC command to clear Layer 2 protocol tunnel counters on the specified interface. Examples This example shows how to clear ... ports. clear l2protocol-tunnel counters [interface-id] Syntax Description interface-id (Optional) Specify interface (physical interface or port channel) for Layer 2 protocol tunneling. 2-42 Catalyst 3560 Switch Command Reference 78-16405-05
...cleared. Defaults No default is defined. clear l2protocol-tunnel counters Chapter 2 Catalyst 3560 Switch Cisco IOS Commands clear l2protocol-tunnel counters Use the clear l2protocol-tunnel counters privileged EXEC command to clear Layer 2 protocol tunnel counters on the specified interface. Examples This example shows how to clear ... ports. clear l2protocol-tunnel counters [interface-id] Syntax Description interface-id (Optional) Specify interface (physical interface or port channel) for Layer 2 protocol tunneling. 2-42 Catalyst 3560 Switch Command Reference 78-16405-05
Command Reference
Page 107
Chapter 2 Catalyst 3560 Switch Cisco IOS Commands deny (IPv6 access-list configuration) Note Although visible in the ...nd-ns, and deny ipv6 any any statement to the IPv6 neighbor discovery process, uses a separate data-link layer protocol. To disallow ICMPv6 neighbor discovery and to be sent and received on an interface. Therefore, by default, ... new statement with an appropriate entry number that it belongs. The IPv6 neighbor discovery process uses the IPv6 network layer service. Defaults No IPv6 access list is equivalent to take effect, an IPv6 ACL must be sent and received...
Chapter 2 Catalyst 3560 Switch Cisco IOS Commands deny (IPv6 access-list configuration) Note Although visible in the ...nd-ns, and deny ipv6 any any statement to the IPv6 neighbor discovery process, uses a separate data-link layer protocol. To disallow ICMPv6 neighbor discovery and to be sent and received on an interface. Therefore, by default, ... new statement with an appropriate entry number that it belongs. The IPv6 neighbor discovery process uses the IPv6 network layer service. Defaults No IPv6 access list is equivalent to take effect, an IPv6 ACL must be sent and received...
Command Reference
Page 108
...-route parameter-option port-unreachable renum-command renum-seq-number router-renumbering time-exceeded Examples This example configures the IPv6 access list named CISCO and applies the access list to the console. Sets permit conditions for an IPv6 access list. The first permit entry in the ...The second deny entry in the list permits all matches to outbound traffic on an interface. Filters incoming or outgoing IPv6 traffic on a Layer 3 interface. The second deny also logs all other traffic to leave the interface. Displays the contents of each IPv6 access list. The ...
...-route parameter-option port-unreachable renum-command renum-seq-number router-renumbering time-exceeded Examples This example configures the IPv6 access list named CISCO and applies the access list to the console. Sets permit conditions for an IPv6 access list. The first permit entry in the ...The second deny entry in the list permits all matches to outbound traffic on an interface. Filters incoming or outgoing IPv6 traffic on a Layer 3 interface. The second deny also logs all other traffic to leave the interface. Displays the contents of each IPv6 access list. The ...
Command Reference
Page 116
...configure a restricted VLAN on a port. A supplicant might not detect any new hosts until they receive an EAP success message. Internal VLANs used for Layer 3 ports cannot be both a restricted VLAN and a voice VLAN. Defaults No restricted VLAN is sent to authenticate every 60 seconds (the default) ...do not receive re-authentication requests if it is not notified of this command. dot1x auth-fail vlan Chapter 2 Catalyst 3560 Switch Cisco IOS Commands dot1x auth-fail vlan Use the dot1x auth-fail vlan interface configuration command to 4094. dot1x auth-fail vlan vlan-id ...
...configure a restricted VLAN on a port. A supplicant might not detect any new hosts until they receive an EAP success message. Internal VLANs used for Layer 3 ports cannot be both a restricted VLAN and a voice VLAN. Defaults No restricted VLAN is sent to authenticate every 60 seconds (the default) ...do not receive re-authentication requests if it is not notified of this command. dot1x auth-fail vlan Chapter 2 Catalyst 3560 Switch Cisco IOS Commands dot1x auth-fail vlan Use the dot1x auth-fail vlan interface configuration command to 4094. dot1x auth-fail vlan vlan-id ...
Command Reference
Page 131
...an error message appears, and IEEE 802.1x is force-authorized. Usage Guidelines You must globally enable IEEE 802.1x on Layer 2 static-access ports, voice VLAN ports, and Layer 3 routed ports. If you try to enable IEEE 802.1x on a specific port. If you try to change to...message appears, and the port mode is not changed . 78-16405-05 Catalyst 3560 Switch Command Reference 2-99 Chapter 2 Catalyst 3560 Switch Cisco IOS Commands dot1x port-control dot1x port-control Use the dot1x port-control interface configuration command to enable manual control of the authorization state of...
...an error message appears, and IEEE 802.1x is force-authorized. Usage Guidelines You must globally enable IEEE 802.1x on Layer 2 static-access ports, voice VLAN ports, and Layer 3 routed ports. If you try to enable IEEE 802.1x on a specific port. If you try to change to...message appears, and the port mode is not changed . 78-16405-05 Catalyst 3560 Switch Command Reference 2-99 Chapter 2 Catalyst 3560 Switch Cisco IOS Commands dot1x port-control dot1x port-control Use the dot1x port-control interface configuration command to enable manual control of the authorization state of...
Command Reference
Page 140
... was added. 2-108 Catalyst 3560 Switch Command Reference 78-16405-05 Enable error detection for a Layer 2 protocol-tunnel error-disabled cause. Command Default Detection is enabled for all causes. errdisable detect cause Chapter 2 Catalyst 3560 Switch Cisco IOS Commands errdisable detect cause Use the errdisable detect cause global configuration command to enable...
... was added. 2-108 Catalyst 3560 Switch Command Reference 78-16405-05 Enable error detection for a Layer 2 protocol-tunnel error-disabled cause. Command Default Detection is enabled for all causes. errdisable detect cause Chapter 2 Catalyst 3560 Switch Cisco IOS Commands errdisable detect cause Use the errdisable detect cause global configuration command to enable...
Command Reference
Page 142
errdisable recovery Chapter 2 Catalyst 3560 Switch Cisco IOS Commands errdisable recovery Use the errdisable recovery global configuration command to recover from all bpduguard arp-inspection channel-misconfig dhcp-rate-limit dtp-flap ... data unit (BPDU) guard error-disabled state. Enable the timer to recover from the DHCP snooping error-disabled state. Enable the timer to recover from a Layer 2 protocol tunnel error-disabled state. Enable the timer to recover from a port security violation disable state. Enable the timer to recover from a loopback error-disabled...
errdisable recovery Chapter 2 Catalyst 3560 Switch Cisco IOS Commands errdisable recovery Use the errdisable recovery global configuration command to recover from all bpduguard arp-inspection channel-misconfig dhcp-rate-limit dtp-flap ... data unit (BPDU) guard error-disabled state. Enable the timer to recover from the DHCP snooping error-disabled state. Enable the timer to recover from a Layer 2 protocol tunnel error-disabled state. Enable the timer to recover from a port security violation disable state. Enable the timer to recover from a loopback error-disabled...
Command Reference
Page 148
...also disable spanning tree. 2-116 Catalyst 3560 Switch Command Reference 78-16405-05 interface port-channel Chapter 2 Catalyst 3560 Switch Cisco IOS Commands interface port-channel Use the interface port-channel global configuration command to 48. Defaults No port-channel logical interfaces... are assigned to 48. Usage Guidelines For Layer 2 EtherChannels, you can use a new number, the channel-group command dynamically creates a new port channel. It automatically creates ...
...also disable spanning tree. 2-116 Catalyst 3560 Switch Command Reference 78-16405-05 interface port-channel Chapter 2 Catalyst 3560 Switch Cisco IOS Commands interface port-channel Use the interface port-channel global configuration command to 48. Defaults No port-channel logical interfaces... are assigned to 48. Usage Guidelines For Layer 2 EtherChannels, you can use a new number, the channel-group command dynamically creates a new port channel. It automatically creates ...
Command Reference
Page 154
... lists ranging from the interface. To define a numbered access list, use this command to an interface. the out keyword is 1 to 199 or 1300 to a Layer 2 or Layer 3 interface. Specify filtering on inbound packets. Usage Guidelines You can only apply one IP ACL and one MAC ACL per interface. •...} no form of an IP ACL, specified in out The number of the IP access control list (ACL). ip access-group Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip access-group Use the ip access-group interface configuration command to control access to 2699.
... lists ranging from the interface. To define a numbered access list, use this command to an interface. the out keyword is 1 to 199 or 1300 to a Layer 2 or Layer 3 interface. Specify filtering on inbound packets. Usage Guidelines You can only apply one IP ACL and one MAC ACL per interface. •...} no form of an IP ACL, specified in out The number of the IP access control list (ACL). ip access-group Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip access-group Use the ip access-group interface configuration command to control access to 2699.
Command Reference
Page 155
...Unreachable messages are filtered by the port ACL. If the specified access list does not exist, all packets are filtered by both outbound or inbound Layer 3 interfaces. Incoming routed IP packets received on ports to which a port ACL is applied are filtered by the port ACL. If the ...access list permits the packet, the switch continues to both the VLAN map and the router ACL. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip access-group Examples You can use router ACLs, input port ACLs, and VLAN maps on a port: Switch(config)# interface gigabitethernet0/1 ...
...Unreachable messages are filtered by the port ACL. If the specified access list does not exist, all packets are filtered by both outbound or inbound Layer 3 interfaces. Incoming routed IP packets received on ports to which a port ACL is applied are filtered by the port ACL. If the ...access list permits the packet, the switch continues to both the VLAN map and the router ACL. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip access-group Examples You can use router ACLs, input port ACLs, and VLAN maps on a port: Switch(config)# interface gigabitethernet0/1 ...
Command Reference
Page 157
... this command to remove an IP address or to the console. Mask for each switch virtual interface (SVI) or routed port on the Layer 3 switch. Usage Guidelines If you are routing Open Shortest Path First (OSPF), ensure that all other than routing updates with secondary source ...No IP address is the primary IP address. Inconsistent use a secondary address from the same network or subnet. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip address ip address Use the ip address interface configuration command to specify an unlimited number of secondary addresses. Use the no...
... this command to remove an IP address or to the console. Mask for each switch virtual interface (SVI) or routed port on the Layer 3 switch. Usage Guidelines If you are routing Open Shortest Path First (OSPF), ensure that all other than routing updates with secondary source ...No IP address is the primary IP address. Inconsistent use a secondary address from the same network or subnet. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip address ip address Use the ip address interface configuration command to specify an unlimited number of secondary addresses. Use the no...
Command Reference
Page 158
...-config privileged EXEC command. The number of other features being configured might have an IP address assigned to configure the IP address for the Layer 2 switch on the switch. For more information, see the sdm prefer command. Related Commands Command show running configuration on a subnetted network: ...address 172.20.128.2 255.255.255.0 This example shows how to each routed port and SVI. ip address Chapter 2 Catalyst 3560 Switch Cisco IOS Commands If your switch receives its IP address from a Bootstrap Protocol (BOOTP) or a DHCP server and you can configure is disabled, ...
...-config privileged EXEC command. The number of other features being configured might have an IP address assigned to configure the IP address for the Layer 2 switch on the switch. For more information, see the sdm prefer command. Related Commands Command show running configuration on a subnetted network: ...address 172.20.128.2 255.255.255.0 This example shows how to each routed port and SVI. ip address Chapter 2 Catalyst 3560 Switch Cisco IOS Commands If your switch receives its IP address from a Bootstrap Protocol (BOOTP) or a DHCP server and you can configure is disabled, ...
Command Reference
Page 186
...This command was introduced. Related Commands Command Description ip igmp profile Configures the specified IGMP profile number. For syntax information, select Cisco IOS Configuration Fundamentals Command Reference, Release 12.2 > File Management Commands > Configuration File Management Commands. 2-154 Catalyst 3560 Switch ...Description profile number The IGMP profile number to be applied to one port can be applied. The range is applied to Layer 2 physical interfaces; Usage Guidelines You can verify your setting by applying an Internet Group Management Protocol (IGMP) profile to...
...This command was introduced. Related Commands Command Description ip igmp profile Configures the specified IGMP profile number. For syntax information, select Cisco IOS Configuration Fundamentals Command Reference, Release 12.2 > File Management Commands > Configuration File Management Commands. 2-154 Catalyst 3560 Switch ...Description profile number The IGMP profile number to be applied to one port can be applied. The range is applied to Layer 2 physical interfaces; Usage Guidelines You can verify your setting by applying an Internet Group Management Protocol (IGMP) profile to...
Command Reference
Page 187
... ip igmp max-groups {number | action} Syntax Description number action deny action replace The maximum number of groups is to 4294967294. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip igmp max-groups ip igmp max-groups Use the ip igmp max-groups interface configuration command to set the maximum back to... Modification This command was received. Use the no form of this command to set the maximum number of Internet Group Management Protocol (IGMP) groups that a Layer 2 interface can join.
... ip igmp max-groups {number | action} Syntax Description number action deny action replace The maximum number of groups is to 4294967294. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip igmp max-groups ip igmp max-groups Use the ip igmp max-groups interface configuration command to set the maximum back to... Modification This command was received. Use the no form of this command to set the maximum number of Internet Group Management Protocol (IGMP) groups that a Layer 2 interface can join.
Command Reference
Page 188
Examples This example shows how to limit to 25 the number of IGMP groups that an interface can use this command only on Layer 2 physical interfaces and on the interface. • If you configure the throttling action as replace and set to the default (...no maximum), entering the ip igmp max-groups {deny | replace} command has no effect. For syntax information, select Cisco IOS Configuration Fundamentals Command Reference, Release 12.2 > File Management Commands > Configuration File Management Commands. 2-156 Catalyst 3560 Switch Command Reference 78-16405-...
Examples This example shows how to limit to 25 the number of IGMP groups that an interface can use this command only on Layer 2 physical interfaces and on the interface. • If you configure the throttling action as replace and set to the default (...no maximum), entering the ip igmp max-groups {deny | replace} command has no effect. For syntax information, select Cisco IOS Configuration Fundamentals Command Reference, Release 12.2 > File Management Commands > Configuration File Management Commands. 2-156 Catalyst 3560 Switch Command Reference 78-16405-...
Command Reference
Page 189
... the low IP multicast address, a space, and the high IP multicast address. You can apply an IGMP profile to one or more Layer 2 interfaces, but each interface can have only one profile applied to create an Internet Group Management Protocol (IGMP) profile and enter IGMP profile configuration... mode. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip igmp profile ip igmp profile Use the ip igmp profile global configuration command to it. Examples This example shows how ...
... the low IP multicast address, a space, and the high IP multicast address. You can apply an IGMP profile to one or more Layer 2 interfaces, but each interface can have only one profile applied to create an Internet Group Management Protocol (IGMP) profile and enter IGMP profile configuration... mode. Chapter 2 Catalyst 3560 Switch Cisco IOS Commands ip igmp profile ip igmp profile Use the ip igmp profile global configuration command to it. Examples This example shows how ...
Command Reference
Page 194
Displays the IGMP snooping configuration. 2-162 Catalyst 3560 Switch Command Reference 78-16405-05 Configures a Layer 2 port as a member of a group. Enables IGMP Immediate-Leave processing. Configures a Layer 2 port as a multicast router port. ip igmp snooping last-member-query-interval Chapter 2 Catalyst 3560 Switch Cisco IOS Commands Related Commands Command ip igmp snooping ip igmp snooping vlan immediate-leave ip igmp snooping vlan mrouter ip igmp snooping vlan static show ip igmp snooping Description Enables IGMP snooping on the switch or on a VLAN.
Displays the IGMP snooping configuration. 2-162 Catalyst 3560 Switch Command Reference 78-16405-05 Configures a Layer 2 port as a member of a group. Enables IGMP Immediate-Leave processing. Configures a Layer 2 port as a multicast router port. ip igmp snooping last-member-query-interval Chapter 2 Catalyst 3560 Switch Cisco IOS Commands Related Commands Command ip igmp snooping ip igmp snooping vlan immediate-leave ip igmp snooping vlan mrouter ip igmp snooping vlan static show ip igmp snooping Description Enables IGMP snooping on the switch or on a VLAN.