CLI Guide
Page 12
... mode. All rights reserved. Use the end command in any key to login... 16 2000-01-22 01:20:37 INFO(6) Logout through Console (Username: admin) DXS-3600-32S TenGigabit Ethernet Switch Command Line Interface Firmware: Build 1.10.023 Copyright(C) 2012 D-Link Corporation. if there is another session running, it will logout. Switch con0 is...
... mode. All rights reserved. Use the end command in any key to login... 16 2000-01-22 01:20:37 INFO(6) Logout through Console (Username: admin) DXS-3600-32S TenGigabit Ethernet Switch Command Line Interface Firmware: Build 1.10.023 Copyright(C) 2012 D-Link Corporation. if there is another session running, it will logout. Switch con0 is...
CLI Guide
Page 20
...learned via 802.1X authentication on a port is 16. In addition to configure the maximum numbers of users allowed on port 1. DXS-3600-32S#configure terminal DXS-3600-32S(config)#interface tenGigabitEthernet 1/0/1 DXS-3600-32S(config-if)#dot1x port-max-user 32 DXS-3600-32S(config-if)# 2-13 dot1x system-fwd-pdu This... Command Default Level Usage Guideline None. 802.1X can not forward EAPOL PDUs by default. DXS-3600-32S#configure terminal DXS-3600-32S(config)#dot1x system-max-user 128 DXS-3600-32S(config)# 2-12 dot1x port-max-user This command is used to globally control the forwarding of...
...learned via 802.1X authentication on a port is 16. In addition to configure the maximum numbers of users allowed on port 1. DXS-3600-32S#configure terminal DXS-3600-32S(config)#interface tenGigabitEthernet 1/0/1 DXS-3600-32S(config-if)#dot1x port-max-user 32 DXS-3600-32S(config-if)# 2-13 dot1x system-fwd-pdu This... Command Default Level Usage Guideline None. 802.1X can not forward EAPOL PDUs by default. DXS-3600-32S#configure terminal DXS-3600-32S(config)#dot1x system-max-user 128 DXS-3600-32S(config)# 2-12 dot1x port-max-user This command is used to globally control the forwarding of...
CLI Guide
Page 22
... : 30 sec SuppTimeout : 30 sec ServerTimeout : 30 sec MaxReq : 2 times ReAuthPeriod : 3600 sec ReAuthenticate : Disabled Forward EAPOL PDU On Port : Disabled Max User On Port : 16 DXS-3600-32S# Example This example shows how to display the 802.1X configuration for the interface TenGigabitEthernet1/0/1. DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide Default Command Mode Command...
... : 30 sec SuppTimeout : 30 sec ServerTimeout : 30 sec MaxReq : 2 times ReAuthPeriod : 3600 sec ReAuthenticate : Disabled Forward EAPOL PDU On Port : Disabled Max User On Port : 16 DXS-3600-32S# Example This example shows how to display the 802.1X configuration for the interface TenGigabitEthernet1/0/1. DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide Default Command Mode Command...
CLI Guide
Page 24
DXS-3600-32S#show dot1x interface tenGigabitEthernet 1/0/1 session-statistics MAC Address : 00-00-00-00-00-02 Interface : TenGigabitEthernet1/0/1 SessionOctetsRx SessionOctetsTx SessionFramesRx SessionFramesTx SessionId SessionAuthenticMethod SessionTime SessionTerminateCause SessionUserName 0 0 0 0 ether1_1-1 Remote Authentication Server 3 NotTerminatedYet user_test DXS-3600-32S# 16 DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide Example This example shows how to display the 802.1X session statistics for the interface TenGigabitEthernet1/0/1.
DXS-3600-32S#show dot1x interface tenGigabitEthernet 1/0/1 session-statistics MAC Address : 00-00-00-00-00-02 Interface : TenGigabitEthernet1/0/1 SessionOctetsRx SessionOctetsTx SessionFramesRx SessionFramesTx SessionId SessionAuthenticMethod SessionTime SessionTerminateCause SessionUserName 0 0 0 0 ether1_1-1 Remote Authentication Server 3 NotTerminatedYet user_test DXS-3600-32S# 16 DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide Example This example shows how to display the 802.1X session statistics for the interface TenGigabitEthernet1/0/1.
CLI Guide
Page 26
.... Means any (Optional) Specifies the ACE sequence number used to 32 characters. DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip access-list standard Std-acl DXS-3600-32S(config-std-nacl)#permit 10.20.0.0 0.0.255.255 DXS-3600-32S(config-std-nacl)#end DXS-3600-32S#show access-list Standard IP access list 1998 Std-acl 10 permit... user does not assign it manually. Masks, in processing the traffic. Example This example shows how to the source network 10.20.0.0/16. Use the no ip access-list extended {id | name} Parameters id name Specifies the ID number of the IP ACL can...
.... Means any (Optional) Specifies the ACE sequence number used to 32 characters. DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip access-list standard Std-acl DXS-3600-32S(config-std-nacl)#permit 10.20.0.0 0.0.255.255 DXS-3600-32S(config-std-nacl)#end DXS-3600-32S#show access-list Standard IP access list 1998 Std-acl 10 permit... user does not assign it manually. Masks, in processing the traffic. Example This example shows how to the source network 10.20.0.0/16. Use the no ip access-list extended {id | name} Parameters id name Specifies the ID number of the IP ACL can...
CLI Guide
Page 31
... others. The purpose is used . Level: 12 23 DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip access-list extended ext_ipv6 DXS-3600-32S(config-ext-nacl)#deny tcp host 19:18:43::12 120:16:10::/48 eq ftp DXS-3600-32S(config-ext-nacl)#permit any any DXS-3600-32S(config-ext-nacl)#end DXS-3600-32S#show access-lists Extended IPv6 access list ext_ipv6 10...
... others. The purpose is used . Level: 12 23 DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip access-list extended ext_ipv6 DXS-3600-32S(config-ext-nacl)#deny tcp host 19:18:43::12 120:16:10::/48 eq ftp DXS-3600-32S(config-ext-nacl)#permit any any DXS-3600-32S(config-ext-nacl)#end DXS-3600-32S#show access-lists Extended IPv6 access list ext_ipv6 10...
CLI Guide
Page 40
.... Example This example shows how to apply a MAC ACL to cancel the application. DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide 3-16 mac access-group This command is used to apply a specific expert ACL to an ... there is any criteria statements that are not supported. DXS-3600-32S#configure terminal DXS-3600-32S(config)#interface range tenGigabitEthernet 1/0/1-1/0/3 DXS-3600-32S(config-if-range)#mac access-group ext_mac out DXS-3600-32S(config-if-range)# end DXS-3600-32S# show access-group interface tenGigabitEthernet 1/0/1-1/0/3 Interface tenGigabitEthernet 1/0/1: ...
.... Example This example shows how to apply a MAC ACL to cancel the application. DXS-3600 Series 10GbE Layer 2/3 Switch CLI Reference Guide 3-16 mac access-group This command is used to apply a specific expert ACL to an ... there is any criteria statements that are not supported. DXS-3600-32S#configure terminal DXS-3600-32S(config)#interface range tenGigabitEthernet 1/0/1-1/0/3 DXS-3600-32S(config-if-range)#mac access-group ext_mac out DXS-3600-32S(config-if-range)# end DXS-3600-32S# show access-group interface tenGigabitEthernet 1/0/1-1/0/3 Interface tenGigabitEthernet 1/0/1: ...
CLI Guide
Page 66
... The no server ip-addr 58 "group radius" means to delete a server. Specifies to configure the AAA server group. DXS-3600-32S#configure terminal DXS-3600-32S(config)#aaa accounting network default start and the end time of this feature is used to delete the server group. It cannot ... security server. Up to configure an AAA server group named 'group-1'. Global Configuration Mode. Use the keyword start-stop group radius DXS-3600-32S(config)# 6-16 aaa group server This command is disabled. server ip-addr no form is used to use the RADIUS group for accounting. "group...
... The no server ip-addr 58 "group radius" means to delete a server. Specifies to configure the AAA server group. DXS-3600-32S#configure terminal DXS-3600-32S(config)#aaa accounting network default start and the end time of this feature is used to delete the server group. It cannot ... security server. Up to configure an AAA server group named 'group-1'. Global Configuration Mode. Use the keyword start-stop group radius DXS-3600-32S(config)# 6-16 aaa group server This command is disabled. server ip-addr no form is used to use the RADIUS group for accounting. "group...
CLI Guide
Page 72
...: 15 Use this command in a different VRF server group: DXS-3600-32S#configure terminal DXS-3600-32S(config)#aaa group server radius sg_global DXS-3600-32S(config-aaa-groug-server)#server-private 172.16.010.0254 timeout 5 retransmit 3 DXS-3600-32S(config-aaa-groug-server)#exit DXS-3600-32S(config)# DXS-3600-32S(config)#aaa group server radius sg_water DXS-3600-32S(config-aaa-group-server)#server-private 10.10.0.01 timeout...
...: 15 Use this command in a different VRF server group: DXS-3600-32S#configure terminal DXS-3600-32S(config)#aaa group server radius sg_global DXS-3600-32S(config-aaa-groug-server)#server-private 172.16.010.0254 timeout 5 retransmit 3 DXS-3600-32S(config-aaa-groug-server)#exit DXS-3600-32S(config)# DXS-3600-32S(config)#aaa group server radius sg_water DXS-3600-32S(config-aaa-group-server)#server-private 10.10.0.01 timeout...
CLI Guide
Page 80
...in the IPv4 address format, for the client. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 172.18.0.16 route-reflector-client DXS-3600-32S(config-router)#bgp cluster-id 10.0.0.2 DXS-3600-32S(config-router)# 72 This command is configured with the...13 bgp cluster-id This command is only required for the reflector and not for the router reflector. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp client-to a route reflector. Use the show ip bgp reflection command to verify ...
...in the IPv4 address format, for the client. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 172.18.0.16 route-reflector-client DXS-3600-32S(config-router)#bgp cluster-id 10.0.0.2 DXS-3600-32S(config-router)# 72 This command is configured with the...13 bgp cluster-id This command is only required for the reflector and not for the router reflector. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp client-to a route reflector. Use the show ip bgp reflection command to verify ...
CLI Guide
Page 82
Use the no bgp confederation peers 21,22 DXS-3600-32S(config-router)# 7-16 bgp dampening This command is disabled by default. The maximum length is fully meshed within itself or configures a route reflector. Reuse: ...Reference Guide The command is suppressed when its penalty exceeds this limit. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp confederation identifier 10 DXS-3600-32S(config-router)#bgp confederation peers 21,22,23,24,25 DXS-3600-32S(config-router)# Example This example shows how to change the BGP route...
Use the no bgp confederation peers 21,22 DXS-3600-32S(config-router)# 7-16 bgp dampening This command is disabled by default. The maximum length is fully meshed within itself or configures a route reflector. Reuse: ...Reference Guide The command is suppressed when its penalty exceeds this limit. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp confederation identifier 10 DXS-3600-32S(config-router)#bgp confederation peers 21,22,23,24,25 DXS-3600-32S(config-router)# Example This example shows how to change the BGP route...
CLI Guide
Page 83
...DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip prefix-list pp1 permit 100.2.0.0/16 DXS-3600-32S(config)#route-map mymap1 DXS-3600-32S(config-route-map)#match ip address prefix-list pp1 DXS-3600-32S(config-route-map)#exit DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp dampening route-map mymap1 DXS-3600-32S... as the default address family for this status change. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp dampening 20 100 6000 120 20 DXS-3600-32S(config-router)# Example This example shows how to apply ...
...DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip prefix-list pp1 permit 100.2.0.0/16 DXS-3600-32S(config)#route-map mymap1 DXS-3600-32S(config-route-map)#match ip address prefix-list pp1 DXS-3600-32S(config-route-map)#exit DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp dampening route-map mymap1 DXS-3600-32S... as the default address family for this status change. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#bgp dampening 20 100 6000 120 20 DXS-3600-32S(config-router)# Example This example shows how to apply ...
CLI Guide
Page 87
...the prefix filter. The existing outbound route filter (ORF) prefix list from the peer 172.16.10.2 is disabled, then the local router will be rebuilt. Privileged Mode. DXS-3600-32S#clear ip bgp 172.16.10.2 soft in the autonomous system numbered 35700. Level: 8. (EI Mode Only Command...) This command can be torn down the session. clear ip bgp vrf VRF-NAME {all routers in prefix-filter DXS-3600-32S# Example In the following...
...the prefix filter. The existing outbound route filter (ORF) prefix list from the peer 172.16.10.2 is disabled, then the local router will be rebuilt. Privileged Mode. DXS-3600-32S#clear ip bgp 172.16.10.2 soft in the autonomous system numbered 35700. Level: 8. (EI Mode Only Command...) This command can be torn down the session. clear ip bgp vrf VRF-NAME {all routers in prefix-filter DXS-3600-32S# Example In the following...
CLI Guide
Page 91
... an IPv4 network to clear the dampening flap statistics. Example The following example, a soft reconfiguration is enabled in DXS-3600-32S# Example This example shows how to send a prefix filter to the prefix filter. clear ip bgp flap-statistics ...DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 172.16.10.1 remote-as 200 DXS-3600-32S(config-router)#neighbor 172.16.10.1 capability orf prefix-list send DXS-3600-32S(config-router)#neighbor 172.16.10.1 filter-list myacl in DXS-3600-32S(config-router)#end DXS-3600-32S...
... an IPv4 network to clear the dampening flap statistics. Example The following example, a soft reconfiguration is enabled in DXS-3600-32S# Example This example shows how to send a prefix filter to the prefix filter. clear ip bgp flap-statistics ...DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 172.16.10.1 remote-as 200 DXS-3600-32S(config-router)#neighbor 172.16.10.1 capability orf prefix-list send DXS-3600-32S(config-router)#neighbor 172.16.10.1 filter-list myacl in DXS-3600-32S(config-router)#end DXS-3600-32S...
CLI Guide
Page 92
... If the soft keyword is 16 characters. (Optional) Specifies to clear BGP route dampening flap statistics of the BGP peer group. The maximum length is not specified, all routes. Privileged Mode. DXS-3600-32S#clear ip bgp flap-statistics vrf VPN-A 192.168.1.0/24 DXS-3600-32S# 7-30 clear ip bgp ...received on a router which has BGP dampening enabled of all the members of IPv4 VRF address family sessions. DXS-3600-32S#clear ip bgp flap-statistics 192.168.1.0/24 DXS-3600-32S# 7-29 clear ip bgp flap-statistics vrf This command is used to clear the accumulated penalties for all ...
... If the soft keyword is 16 characters. (Optional) Specifies to clear BGP route dampening flap statistics of the BGP peer group. The maximum length is not specified, all routes. Privileged Mode. DXS-3600-32S#clear ip bgp flap-statistics vrf VPN-A 192.168.1.0/24 DXS-3600-32S# 7-30 clear ip bgp ...received on a router which has BGP dampening enabled of all the members of IPv4 VRF address family sessions. DXS-3600-32S#clear ip bgp flap-statistics 192.168.1.0/24 DXS-3600-32S# 7-29 clear ip bgp flap-statistics vrf This command is used to clear the accumulated penalties for all ...
CLI Guide
Page 94
... length is 16 characters. An Autonomous System path access list can be applied to inbound, outbound or both routes exchanged in a BGP peer session. Use the show how to exit from the address family configuration mode and enter the router configuration mode. Level: 8. (EI Mode Only Command) None. DXS-3600-32S#configure terminal DXS-3600-32S(config...
... length is 16 characters. An Autonomous System path access list can be applied to inbound, outbound or both routes exchanged in a BGP peer session. Use the show how to exit from the address family configuration mode and enter the router configuration mode. Level: 8. (EI Mode Only Command) None. DXS-3600-32S#configure terminal DXS-3600-32S(config...
CLI Guide
Page 95
...general string that routes not to be used only with this command to match against an input string. no ip as -path access-list mylist DXS-3600-32S(config)# 7-33 ip community-list This command is configured with expanded community lists. Regular expressions can also be a user-specified number represented by ...(EI Mode Only Command) 87 It can accept up to delete an AS path access list, no form of the following example show how to 16 characters. DXS-3600-32S#configure terminal DXS-3600-32S(config)#no -export - The following reserved community values: internet -
...general string that routes not to be used only with this command to match against an input string. no ip as -path access-list mylist DXS-3600-32S(config)# 7-33 ip community-list This command is configured with expanded community lists. Regular expressions can also be a user-specified number represented by ...(EI Mode Only Command) 87 It can accept up to delete an AS path access list, no form of the following example show how to 16 characters. DXS-3600-32S#configure terminal DXS-3600-32S(config)#no -export - The following reserved community values: internet -
CLI Guide
Page 96
...configured in a community list, earlier configured. Use the show ip community-list command to specify BGP community attributes. DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip community-list standard mycom deny no rules or only deny rules to create an expanded community list named...the community list 'mycom' will be denied. Example This example shows how to 16 characters. DXS-3600-32S#configure terminal DXS-3600-32S(config)#no ip community-list standard mycom deny no-export 20:30 DXS-3600-32S(config)# Example After that does not match any rule in the list will be...
...configured in a community list, earlier configured. Use the show ip community-list command to specify BGP community attributes. DXS-3600-32S#configure terminal DXS-3600-32S(config)#ip community-list standard mycom deny no rules or only deny rules to create an expanded community list named...the community list 'mycom' will be denied. Example This example shows how to 16 characters. DXS-3600-32S#configure terminal DXS-3600-32S(config)#no ip community-list standard mycom deny no-export 20:30 DXS-3600-32S(config)# Example After that does not match any rule in the list will be...
CLI Guide
Page 98
... shows how to disable address exchange for neighbor 10.4.4.4 DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 10.4.4.4 remote-as 65101 DXS-3600-32S(config-router)#no neighbor {IP-ADDRESS | PEER-GROUP-NAME...} activate Parameters IP-ADDRESS PEER-GROUP-NAME Specifies the IP address of information with a Border Gateway Protocol (BGP) neighbor. The maximum length is 16...
... shows how to disable address exchange for neighbor 10.4.4.4 DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 10.4.4.4 remote-as 65101 DXS-3600-32S(config-router)#no neighbor {IP-ADDRESS | PEER-GROUP-NAME...} activate Parameters IP-ADDRESS PEER-GROUP-NAME Specifies the IP address of information with a Border Gateway Protocol (BGP) neighbor. The maximum length is 16...
CLI Guide
Page 99
... 5 DXS-3600-32S(config-router)# 91 DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 10.4.4.4 remote-as 65101 DXS-3600-32S(config-router)#neighbor 100.16.5.4 allowas-in Parameters IP-ADDRESS PEER-GROUP-NAME NUMBER Specifies the IP address of this command. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 100.16.5.4 remote-as 65101 DXS-3600-32S(config...
... 5 DXS-3600-32S(config-router)# 91 DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 10.4.4.4 remote-as 65101 DXS-3600-32S(config-router)#neighbor 100.16.5.4 allowas-in Parameters IP-ADDRESS PEER-GROUP-NAME NUMBER Specifies the IP address of this command. DXS-3600-32S#configure terminal DXS-3600-32S(config)#router bgp 100 DXS-3600-32S(config-router)#neighbor 100.16.5.4 remote-as 65101 DXS-3600-32S(config...