- Quick Links to Catalyst 4500 Series Switch Cisco IOS Commands
- Index file
- Preface
- Command-Line Interface
- aaa accounting dot1x default start-stop group radius through instance
- interface port-channel through shape
- show access-group mode interface through show vtp
- snmp ifindex clear through vtp v2-mode
- Acronyms and Abbreviations
Index
Symbols
$ matches the end of a string 1-7
( ) in commands 1-11
* matches 0 or more sequences of a pattern 1-7
+ matches 1 or more sequences of a pattern 1-7
. matches any single character 1-7
? command 1-1
? matches 0 or 1 occurrence of a pattern 1-7
^ matches the beginning of a string 1-7
_ matches a comma (,), left brace ({), left parenthesis 1-7
" 1-10
Numerics
10-Gigabit Ethernet uplink
selecting 2-233
802.1Q trunk ports and native VLANs 2-1024
802.1Q tunnel ports
configuring 2-956
802.1S Multiple Spanning Tree
802.1X
configuring for multiple hosts 2-182
configuring for single host 2-182
configuring multiple domains 2-182
disabling port control 2-174
enabling port control 2-174
802.1X Critical Authentication
disabling on a port 2-176
disabling on a VLAN 2-179
EAPOL
disabling send success packets 2-177
enabling send success packets 2-177
enabling on a port 2-176
enabling on a VLAN 2-179
returning delay time to default setting 2-178
setting delay time on a port 2-178
802.1X critical authentication
configure parameters 2-25
802.1X critical recovery delay, configuring 2-25
802.1X Port Based Authentication
debugging 802.1X Port Based Authentication 2-122
displaying port based authentication 2-621
enabling accounting for authentication sessions 2-4
enabling authentication on the system 2-193
enabling guest VLAN 2-180
enabling guest VLAN supplicant 2-172, 2-181
enabling manual control of auth state 2-189
enabling periodic re-authentication of the client 2-192
initializing re-authentication of dot1x ports 2-191
initializing state machines 2-184
receive session termination message upon reboot 2-5
setting maximum number for EAP requests 2-187
setting the reauthentication timer 2-194
A
aaa authorization network command 2-175
abbreviating commands
context-sensitive help 1-1
Access Gateway Module
connecting to a module 2-22
connecting to a remote module 2-533
connecting to a specific remote module 2-562
access-group
displaying mac interface 2-756
show mode interface 2-475, 2-583, 2-823
access groups
access lists
clearing an access template 2-79
defining ARP 2-21
displaying ARP information 2-587
See also ACLs, MAC ACLs, and VACLs
access maps
applying with VLAN filter 2-1026
access-node-identifier, setting for the switch 2-478
access-policies, applying using host-mode 2-30
ACLs
access-group mode 2-6
balancing hardware regions 2-12
capturing control packets 2-8
determining ACL hardware programming 2-10
disabling hardware statistics 2-227
displaying mac access-group interface 2-756
enabling hardware statisctics 2-227
using ACL naming conventions for MAC ACLs 2-358
action clause
specifying drop or forward action in a VACL 2-13
addresses, configuring a maximum 2-461
adjacency
debugging the adjacency table 2-115
disabling the debug facility 2-115
displaying information about the adjacency table 2-584
displaying IPC table entries 2-115
aggregate policer
displaying information 2-824
aging time
displaying MAC address aging time 2-759
MAC address table 2-361
alarms
displaying operational status 2-629
alternation
description 1-10
anchoring
description 1-10
ancp, show multicast 2-586
ANCP client
port identifier 2-16
remote server 2-17
set router to become 2-18
ARP
access list, displaying detailed information 2-587
defining access-lists 2-21
ARP inspection
enforce certain types of checking 2-251
ARP packet
deny based on DHCP bindings 2-157
permit based on DHCP bindings 2-439
changing the control-direction 2-23
configure actions for events
configuring the actions 2-26
configuring port-control 2-36
enabling reauthentication 2-35
enabling Webauth fallback 2-29
host-mode configuration 2-30
setting priority of methods 2-38
setting the timer 2-40
setting username 2-1011
specifying the order of methods 2-33
using an MD5-type encryption method 2-1011
verifying MD5 signature 2-1013
verifying the checksum for Flash memory 2-1013
authentication control-direction command 2-23
authentication critical recovery delay command 2-25
authentication event command 2-26
authentication fallback command 2-29
authentication host-mode 2-30
authentication methods, setting priority 2-38
authentication methods, specifying the order of attempts 2-33
authentication open command 2-32
authentication order command 2-33
authentication periodic command 2-35
authentication port-control command 2-36
authentication priority command 2-38
authentication timer, setting 2-40
authentication timer command 2-40
authentication violation command 2-42
auth fail VLAN
enable on a port 2-173
set max number of attempts 2-172
Auth Manager
configuring
authentication timer 2-40
authorization state
enabling manual control 2-189
authorization state of a controlled port 2-189
automatic installation
displaying status 2-592
automatic medium-dependent interface crossover
Auto-MDIX
disabling 2-406
enabling 2-406
auto-negotiate interface speed
example 2-933
auto-QoS
configuring for VoIP 2-44
displaying configuration 2-593
average-packet-size (netflow-lite monitor submode) command 2-48
B
baby giants
displaying the system MTU setting 2-858
setting the maximum Layer 2 payload size 2-983
BackboneFast
displaying debugging messages 2-144
displaying spanning tree status 2-847
enabling debugging 2-144
bandwidth command 2-50
bindings
store for DHCP snooping 2-263
BOOT environment variable
displaying information 2-596
bootflash
displaying information 2-594
BPDUs
debugging spanning tree activities 2-142
bridge protocol data units
broadcast suppression level
C
cable diagnostics
TDR
displaying test results 2-597
testing conditions of copper cables 2-987
call home
displaying information 2-599
e-mailing output 2-58
entering configuration submode 2-53
executing 2-58
manually send test message 2-61
receiving information 2-56
sending alert group message 2-59
submitting information 2-56
call home destination profiles
displaying 2-601
Catalyst 4507R 2-459
CDP
configuring tunneling encapsulation rate 2-345
displaying
neighbor information 2-604
enabling protocol tunneling for 2-340
set drop threshold for 2-343
CEF
displaying next-hop information 2-678
displaying VLAN configuration information 2-678
chassis
displaying
chassis MAC address ranges 2-753
current and peak traffic meter readings 2-753
percentage of backplane utilization 2-753
switching clock failure recovery mode 2-753
circuit-id
setting for an interface 2-480
circuit-id, setting for an interface VLAN range 2-481
cisco-desktop
macro apply 2-370
Cisco Express Forwarding
cisco-phone
macro apply 2-372
cisco-router
macro apply 2-374
cisco-switch
macro apply 2-376
CISP
See Client Information Signalling Protocol
cisp enable command 2-66
class maps
creating 2-70
defining the match criteria 2-399
clear commands
clearing Gigabit Ethernet interfaces 2-77
clearing IGMP group cache entries 2-86
clearing interface counters 2-72
clearing IP access lists 2-79, 2-80
clearing IP ARP inspection statistics VLAN 2-81
clearing IP DHCP snooping database statistics 2-85
clearing MFIB counters and routes 2-89
clearing MFIB fastdrop entries 2-90
clearing PAgP channel information 2-99
clearing QoS aggregate counters 2-103
clearing VLAN interfaces 2-78
clear energywise neighbors command 2-74
clear ip wccp command 2-91
clear netflow-lite exporter statistics command 2-96
clear netflow-lite monitor statistics interface command 2-97
clear nmsp statistics command 2-98
Client Information Signalling Protocol 2-175
Client Information Signalling Protocol, enabling 2-66
CLI string search
anchoring 1-10
expressions 1-7
filtering 1-6
multiple-character patterns 1-8
multipliers 1-9
parentheses for recall 1-11
searching outputs 1-6
single-character patterns 1-7
using 1-6
command modes
accessing privileged EXEC mode 1-5
exiting 1-5
understanding user EXEC and configuration modes 1-5
condition interface
debugging interface-related activities 2-117
condition vlan
debugging VLAN output 2-120
configuration, saving 1-11
configuring
root as secondary 2-917
configuring a SPAN session to monitor
limit SPAN source traffic 2-411
configuring critical recovery 2-25
configuring forward delay 2-913
configuring root as primary 2-917
CoPP
attaching
policy map to control plane 2-560
displaying
policy-map class information 2-797
entering configuration mode 2-107
removing
service policy from control plane 2-560
CoS
assigning to Layer 2 protocol packets 2-342
cos (netflow-lite exporter submode) command 2-109
CoS QoS default
defining value on an interface 2-509
Cost of Service
counter command 2-111
counters
clearing interface counters 2-72
critical authentication, configure 802.1X parameters 2-25
critical recovery, configuring 802.1X parameter 2-25
D
DAI
clear statistics 2-81
DBL
displaying qos dbl 2-825
enabling DBL globally on the switch 2-510
debug commands
debugging backup events 2-116
debugging DHCP snooping events 2-127
debugging DHCP snooping messages 2-128
debugging EtherChannel/PAgP/shim 2-123
debugging IPC activity 2-126
debugging IP DHCP snooping security messages 2-129
debugging NVRAM activities 2-133
debugging PAgP activities 2-134
debugging port manager activities 2-137
debugging spanning tree activities 2-142
debugging spanning tree backbonefast 2-144
debugging spanning tree UplinkFast 2-147
debugging supervisor redundancy 2-141
debugging VLAN manager activities 2-148
displaying monitor activity 2-131
displaying the adjacency table 2-115
enabling debug dot1x 2-122
enabling debugging messages for ISL VLAN IDs 2-151
enabling debugging messages for VTP 2-152
enabling debugging of UDLD activity 2-153
enabling switch shim debugging 2-145
enabling VLAN manager file system error tests 2-149
limiting debugging output for VLANs 2-120
limiting interface debugging output 2-117
limiting output for debugging standby state changes 2-118
shortcut to the debug condition interface 2-125
debugging
activity monitoring 2-131
DHCP snooping events 2-127
DHCP snooping packets 2-128
IPC activities 2-126
IP DHCP snooping security packets 2-129
NVRAM activities 2-133
PAgP activities 2-134
PAgP shim 2-123
PM activities 2-137
PPPoE Intermediate Agent 2-139
spanning tree BackboneFast events 2-144
spanning tree switch shim 2-145
spanning tree UplinkFast events 2-147
VLAN manager activities 2-148
VLAN manager IOS file system error tests 2-149
VTP protocol debug messages 2-152
debug nmsp command 2-132
debug spanning tree switch 2-145
debug sw-vlan vtp 2-152
default CoS value 2-509
default form of a command, using 1-6
defining egress DSCP-to-CoS mapping 2-516
destination (netflow-lite exporter submode) command 2-159
DHCP
clearing database statistics 2-85
DHCP bindings
configuring bindings 2-261
deny ARP packet based on matches 2-157
permit ARP packet based on matches 2-439
DHCP snooping
clearing binding entries 2-82
clearing database 2-84
displaying binding table 2-681
displaying configuration information 2-679
displaying status of DHCP database 2-684
displaying status of error detection 2-632
enabling DHCP globally 2-260
enabling IP source guard 2-302
enabling on a VLAN 2-270
enabling option 82 2-265, 2-267
enabling option-82 2-272
enabling rate limiting on an interface 2-268
enabling trust on an interface 2-269
establishing binding configuration 2-261
renew binding database 2-535
store generated bindings 2-263
diagnostic fpga soft-error recover command 2-169
diagnostic test
bootup packet memory 2-615
displaying attributes 2-609
display module-based results 2-611
running 2-171
show results for TDR 2-597
testing conditions of copper cables 2-987
displaying error disable recovery 2-633
displaying inline power status 2-812
displaying monitoring activity 2-131
displaying PoE policing and monitoring status 2-820
displaying SEEPROM information
GBIC 2-643
displaying SPAN session information 2-858, 2-936
document conventions 1-xxii
document organization 1-xxi
DoS
CoPP
attaching policy map to control plane 2-560
displaying policy-map class information 2-797
entering configuration mode 2-107
removing service policy from control plane 2-560
entering
CoPP configuration mode 2-107
DOS attack
protecting system's resources 2-246
dot1x credentials (global configuration) command 2-175
drop threshold, Layer 2 protocol tunneling 2-343
dscp (netflow-lite exporter submode command 2-196
DSCP rewrite for IP packets
enable 2-520
dual-capable port
selecting a connector 2-408
duplex mode
configuring autonegotiation on an interface 2-198
configuring full duplex on an interface 2-198
configuring half duplex on an interface 2-198
dynamic ARP inspection
preventing 2-246
Dynamic Buffer Limiting
Dynamic Host Configuration Protocol
E
EAP
restarting authentication process 2-187
EIGRP (Enhanced IGRP)
filters
routing updates, preventing 2-436
enabling
debugging for UDLD 2-153
voice VLANs 2-949
enabling open access 2-32
EnergyWise
display power information through queries 2-207
display setting, status of entity and PoE ports 2-625
on an entity
enable, assign to domain, and set password 2-205
on an entity, enable and configure 2-200
on a PoE port
configuring on PoE port 2-202
energywise (global configuration) command 2-200, 2-202
energywise domain command 2-205
EnergyWise neighbor table, deleting 2-74
energywise query command 2-207
environmental
alarms 2-629
displaying information 2-629
status 2-629
temperature 2-629
epm access control command 2-211
erase a file 2-212
error disable detection
clearing error disable on an interface 2-75
enabling error disable detection 2-75, 2-215
enabling per-VLAN on BPDU guard 2-215
error-disabled state
displaying 2-662
error disable recovery
configuring recovery mechanism variables 2-217
displaying recovery timer information 2-633
enabling ARP inspection timeout 2-217
specifying recovery cause 2-217
EtherChannel
assigning interfaces to EtherChannel groups 2-62
debugging EtherChannel 2-123
debugging PAgP shim 2-123
debugging spanning tree activities 2-142
displaying information for a channel 2-635
removing interfaces from EtherChannel groups 2-62
EtherChannel guard
detecting STP misconfiguration 2-903
Explicit Host Tracking
clearing the database 2-88
enabling per-VLAN 2-284
exporter (netflow-lite monitor submode) command 2-222
expressions
matching multiple expression occurrences 1-9
multiple-character patterns 1-8
multiplying pattern occurrence 1-11
single-character patterns 1-7
Extensible Authentication Protocol
F
fallback profile, specifying 2-29
field replaceable unit (FRU)
displaying status information 2-629
filters
EIGRP
routing updates, preventing 2-436
Flash memory file system
displaying file system information 2-594
verifying checksum 2-1013
flow control
configuring a gigabit interface for pause frames 2-224
displaying per-interface statistics for flow control 2-639
G
GBIC
displaying SEEPROM information 2-643
generic-error-message, setting for the switch 2-478
Gigabit Ethernet interface
clearing the hardware logic 2-77
Gigabit Ethernet uplink
selecting 2-233
global configuration mode
using 1-5
H
hardware module
resetting a module by toggling the power 2-229
hardware statistics
disabling 2-227
enabling 2-227
hardware uplink
selecting the mode 2-233
helper addresses, IP 2-699
hot standby protocol
debugging 2-118
disabling debugging 2-118
limiting output 2-118
hw-module system max-queue-limit command 2-230
hw-module uplink mode shared-backplane command 2-231
I
identifier-string, setting for the switch 2-478
ID mapping, creating an ANCP client 2-16
IDPROMs
displaying SEEPROM information
chassis 2-643
clock module 2-643
fan trays 2-643
module 2-643
mux buffer 2-643
power supplies 2-643
supervisor engine 2-643
ifIndex persistence
clearing SNMP ifIndex commands 2-885
compress SNMP ifIndex table format 2-892
disabling globally 2-891
disabling on an interface 2-887
enabling globally 2-891
enabling on an interface 2-887
IGMP
applying filters for host joining on Layer 2 interfaces 2-274
clearing IGMP group cache entries 2-86
configuring frequency for IGMP host-query messages 2-277
creating an IGMP profile 2-276
displaying IGMP interface configuration information 2-686
displaying profiles 2-688
setting maximum group numbers 2-275
IGMP profiles
displaying 2-688
IGMP snooping
clearing the EHT database 2-88
configuring a Layer 2 interface as a group member 2-290
configuring a Layer 2 interface as a multicast router 2-288
configuring a static VLAN interface 2-290
displaying multicast information 2-695
displaying VLAN information 2-689, 2-693, 2-696
enabling 2-279
enabling immediate-leave processing 2-286
enabling on a VLAN 2-283
enabling per-VLAN Explicit Host Tracking 2-284
informs
enabling 2-889
inline power
displaying inline power status 2-812
In Service Software Upgrade
inspection log
clearing log buffer 2-80
interface
displaying suppressed multicast bytes 2-656
interface capabilities
displaying 2-652
interface configuration mode
summary 1-5
interface link
display cable disconnect time 2-659
interfaces
configuring dot1q tunnel ports 2-956
creating an interface-range macro 2-156
debugging output of interface related activities 2-117
displaying description 2-658
displaying error-disabled state 2-662
displaying information when tunneling is enabled 2-747
displaying status 2-658
displaying traffic for a specific interface 2-649
entering interface configuration mode 2-237
executing a command on multiple ports in a range 2-240
selecting an interface to configure 2-237
setting a CoS value for Layer 2 packets 2-342
setting drop threshold for Layer 2 packets 2-343
setting the interface type 2-956
interface speed
configuring interface speed 2-931
interface transceiver
displaying diagnostic data 2-666
internal VLAN allocation
configuring 2-1029
default setting 2-1029
displaying allocation information 2-872
Internet Group Management Protocol
IP address of remote ANCP server, setting 2-17
IP ARP
applying ARP ACL to VLAN 2-244
clearing inspection statistics 2-81
clearing status of log buffer 2-80
controlling packet logging 2-255
enabling dynamic inspection 2-253
limit rate of incoming requests 2-246
set per-port config trust state 2-250
showing status of dynamic ARP inspection 2-673
showing status of log buffer 2-676
IPC
debugging IPC activities 2-126
IP DHCP Snooping
IP header validation
disabling 2-301
enabling 2-301
IP interfaces
displaying usability status 2-698
IP multicast
displaying multicast routing table information 2-704
ip multicast multipath command 2-294
IP packets
enable DSCP rewrite 2-520
IP phone and standard desktop
enabling Cisco-recommended features 2-372
IP Port Security
enabling 2-302
IP source binding
adding or deleting 2-298
displaying bindingstagging 2-709
IP source guard
debugging messages 2-129
displaying configuration and filters 2-710
enabling on DHCP snooping 2-302
IPv4 statistics, enabling collection 2-111
IPv6 MLD
configuring queries 2-319, 2-321
configuring snooping last-listener-query-intervals 2-321
configuring snooping listener-message-suppression 2-323
configuring snooping robustness-variables 2-324
configuring tcn topology change notifications 2-326
counting snooping last-listener-queries 2-319
displaying information 2-722
displaying ports for a switch or VLAN 2-724
displaying querier information 2-725
enabling snooping 2-317
enabling snooping on a VLAN 2-327
IPv6 statistics, enabling collection 2-111
ip wccp check services all command 2-309
ip wccp command 2-306
ip wccp group-address command 2-306
ip wccp group-list command 2-306
ip wccp group-listen command 2-311
ip wccp password command 2-306, 2-308
ip wccp redirect command 2-313
ip wccp redirect exclude in command 2-315
ip wccp redirect-list command 2-306
ISSU
canceling process 2-329
configuring rollback timer 2-339
displaying capability 2-728
displaying client information 2-730
displaying compatibility matrix 2-732
displaying endpoint information 2-737
displaying entities 2-738
displaying FSM session 2-739
displaying messages 2-740
displaying negotiated 2-742
displaying rollback-timer 2-743
displaying session information 2-744
displaying software version 2-745
displaying state 2-745
forcing switchover to standby supervisor engine 2-337
loading new image 2-333
starting process 2-335
stopping rollback timer 2-331
J
Jumbo frames
enabling jumbo frames 2-417
L
LACP
deselecting channeling protocol 2-64
enabling LACP on an interface 2-64
setting channeling protocol 2-64
lacp system-priority command 2-348
Layer 2
displaying ACL configuration 2-756
Layer 2 interface type
specifying a nontrunking, nontagged single VLAN interface 2-956
specifying a trunking VLAN interface 2-956
Layer 2 protocol ports
displaying 2-747
Layer 2 protocol tunneling error recovery 2-345
Layer 2 switching
enabling voice VLANs 2-949
modifying switching characteristics 2-949
Layer 2 traceroute
IP addresses 2-992
Layer 3 interface, assign counters 2-111
Layer 3 switching
displaying information about an adjacency table 2-584
displaying port status 2-664
displaying status of native VLAN tagging 2-664
link-status event messages
disabling
enabling
LLDP
enabling power negotiation 2-349
lldp tlv-select power-management command 2-349
log buffer
show status 2-676
logging
controlling IP ARP packets 2-255
M
MAB, display information 2-753
MAB, enable and configure 2-356
mab command 2-356
MAC Access Control Lists
MAC ACLs
defining extended MAC access list 2-358
displaying MAC ACL information 2-868
naming an ACL 2-358
MAC addresses
disabling MAC address learning per VLAN 2-365
displaying
notification settings 2-211, 2-727, 2-767
MAC address filtering
configuring 2-369
disabling 2-369
enabling 2-369
MAC address learning on a VLAN, enabling 2-365
MAC address table
adding static entries 2-396
clearing dynamic entries 2-93, 2-95
configuring aging time 2-361
displaying dynamic table entry information 2-763
displaying entry count 2-761
displaying information 2-757
displaying interface-based information 2-765
displaying multicast information 2-768
displaying notification information 2-770
displaying protocol-based information 2-772
displaying static table entry information 2-774
displaying the MAC address aging time 2-759
displaying VLAN-based information 2-777
enabling authentication bypass 2-185
enabling notifications 2-367
learning in the protocol buckets 2-362
removing static entries 2-396
mac address-table learning vlan command 2-365
MAC address tables
adding static entries 2-369
deleting secure or specific addresses 2-100
disabling IGMP snooping on static MAC addresses 2-369
removing static entries 2-369
mac-address-table static 2-369
MAC address unicast filtering
dropping unicast traffic 2-369
MAC authentication bypass (MAB), display information 2-753
MAC authorization bypass(MAB), enable and configure 2-356
macro
displaying descriptions 2-395
macro auto global processing command 2-378, 2-380, 2-383, 2-385, 2-387, 2-389, 2-390, 2-392, 2-779
macro keywords
help strings 2-2
macros
adding a global description 2-395
cisco global 2-393
system-cpp 2-394
mapping secondary VLANs to MST instance 2-494
mapping VLAN(s) to an MST instance 2-235
match (class-map configuration) command 2-14, 2-161, 2-163, 2-165, 2-167, 2-399, 2-937, 2-939, 2-941, 2-943, 2-947
maximum transmission unit (MTU)
displaying the system MTU setting 2-858
setting the maximum Layer 2 payload size 2-983
MD5
verifying MD5 signature 2-1013
message digest 5
MFIB
clearing ip mfib counters 2-89
clearing ip mfib fastdrop 2-90
displaying all active MFIB routes 2-701
displaying MFIB fastdrop table entries 2-703
enabling IP MFIB fastdrops 2-293
MLD
configuring snooping last-listener-query-intervals 2-321
configuring snooping listener-message-suppression 2-323
configuring snooping robustness-variables 2-324
configuring topology change notifications 2-326
counting snooping last-listener-queries 2-319
enabling snooping 2-317
enabling snooping on a VLAN 2-327
MLD snooping
displaying 2-725
modes
access-group 2-6
show access-group interface 2-475, 2-583, 2-823
switching between PVST+, MST, and Rapid PVST 2-908
module password clearing 2-76
module reset
resetting a module by toggling the power 2-229
--More-- prompt
filter 1-6
search 1-7
MST
designating the primary and secondary root 2-917
displaying MST protocol information 2-852
displaying region configuration information 2-852
displaying spanning tree information 2-852
entering MST configuration submode 2-911
setting configuration revision number 2-552
setting path cost and port priority for instances 2-909
setting the forward delay timer for all instances 2-913
setting the hello-time delay timer for all instances 2-914
setting the max-age timer for all instances 2-915
setting the MST region name 2-418
specifying the maximum number of hops 2-916
switching between PVST+ and Rapid PVST 2-908
using the MST configuration submode revision command 2-552
using the submode name command 2-418
MTU
displaying global MTU settings 2-858
multi-auth, setting 2-30
Multicase Listener Discovery
multicast
enabling storm control 2-936
show ancp 2-586
multicast/unicast packets
prevent forwarding 2-955
Multicast Forwarding Information Base
multi-domain, setting 2-30
multiple-character patterns 1-8
Multiple Spanning Tree
N
native VLAN
controlling tagging of traffic 2-976
displaying ports eligible for native tagging 2-870
displaying ports eligible for tagging 2-870
enabling tagging on 802.1Q trunk ports 2-1024
specifing the tagging of traffic 2-977
NetFlow
enabling NetFlow statistics 2-296
including infer fields in routing statistics 2-296
netflow-lite exporter command 2-419
netflow-lite monitor command 2-421
netflow-lite sampler command 2-423
next-hop
displaying CEF VLAN information 2-678
nmsp attachment suppress command 2-426
nmsp command 2-425
no form of a command, using 1-6
NVRAM
debugging NVRAM activities 2-133
O
open access on a port, enabling 2-32
options timeout (netflow-lite exporter submode) command 2-220, 2-427
output
pattern searches 1-7
P
packet counters (statistics)
clear for PPPoE Intermediate Agent 2-102
packet counters, display for PPPoE Intermediate Agent 2-821
packet forwarding
prevent unknown packets 2-955
packet memory failure
direct switch action upon detection 2-170
packet memory test
bootup, displaying results 2-615, 2-617
ongoing, displaying results 2-619
packet-offset (netflow-lite sampler submode) command 2-429
packet rate (netflow-lite sampler submode) command 2-430
packet-section size (netflow-lite sampler submode command 2-432
PACL
access-group mode 2-6
paging prompt
PAgP
clearing port channel information 2-99
debugging PAgP activity 2-134
deselecting channeling protocol 2-64
displaying port channel information 2-794
hot standby mode
returning to defaults 2-435
selecting ports 2-435
input interface of incoming packets
learning 2-434
returning to defaults 2-434
setting channeling protocol 2-64
parentheses 1-11
password
clearing on an intelligent line module 2-76
establishing enhanced password security 2-1011
setting username 2-1011
PBR
redistributing route maps 1-xxii
PM activities
debugging 2-137
disabling debugging 2-137
PoE policing
configure on an interface 2-470
PoE policing and monitoring
displaying status 2-820
police (percent) command 2-446
police (two rates) command 2-448, 2-450
police command 2-441
policing, configure PoE 2-470
policing and monitoring status
displaying PoE 2-820
Policy Based Routing
policy maps
creating 2-454
marking 2-564
See also QoS, hierarchical policies
traffic classification
defining trust states 2-999
port, dual-capable
selecting the connector 2-408
Port Aggregation Protocol
port-based authentication
displaying debug messages 2-122
displaying statistics and status 2-621
enabling 802.1X 2-189
host modes 2-182
manual control of authorization state 2-189
periodic re-authentication
enabling 2-192
re-authenticating 802.1X-enabled ports 2-191
switch-to-client frame-retransmission number 2-187
port channel
accessing 2-239
creating 2-239
displaying information 2-794
load distribution method
resetting to defaults 2-456
setting 2-456
port-channel standalone-disable command 2-458
port control, changing from unidirectional or bidirectional 2-23
port-control value, configuring 2-36
port range
executing 2-240
port security
debugging ports security 2-138
deleting secure or specific addresses 2-100
displaying settings for an interface or switch 2-805
enabling 2-961
filter source IP and MAC addresses 2-302
setting action upon security violation 2-961
setting the rate limit for bad packets 2-961
sticky port 2-961
Port Trust Device
displaying 2-826
power efficient-ethernet auto command 2-464
power inline logging global command 2-469
power negotiation through LLDP, enabling 2-349
power status
displaying inline power 2-812
displaying power status 2-812
power supply
configuring combined and redundant power on the Catalyst 4507R 2-459
configuring inline power 2-465
configuring power consumption 2-459
displaying the SEEPROM 2-643
setting inline power state 2-463
PPPoE Discovery
enable vendor-tag stripping on packetsPPPoE Server
enable vendor-tag stripping on Discovery packets 2-484
PPPoE Discovery packets, limit rate arriving on an interfsce 2-482
PPPoE Intermediate Agent
clear statistics (packet counters) 2-102
debugging 2-139
pppoe intermediate-agent
enable intermediate agent on a switch 2-474
enable on an interface VLAN range 2-477
enable PPPoE Intermediate Agent on an interface 2-475
enable vendor-tag stripping of Discovery packets 2-484
format-type (global) 2-478
limit rate of PPPoE Discovery packets 2-482
set circuit-id or remote-id for an interface 2-480
set circuit-id or remote-id for an interface VLAN range 2-481
set trust configuration on an interface 2-482, 2-483
PPPoE Intermediate Agent, display configuration and statistics (packet counters) 2-821
priority command 2-485
priority-queue command 2-113
Private VLAN
privileged EXEC mode, summary 1-5
prompts
system 1-5
protocol tunneling
configuring encapsulation rate 2-345
disabling 2-340
displaying port information 2-747
enabling 2-340
setting a CoS value for Layer 2 packets 2-342
setting a drop threshold for Layer 2 packets 2-343
PVLANs
configuring isolated, primary, and community PVLANs 2-487
controlling tagging of native VLAN traffic 2-976
disabling sticky-ARP 2-299
displaying map information for VLAN SVIs 2-661
displaying PVLAN information 2-876
enabling interface configuration mode 2-956
enabling sticky-ARP 2-299
mapping VLANs to the same SVI 2-491
specifying host ports 2-956
specifying promiscuous ports 2-956
PVST+
switching between PVST and MST 2-908
Q
QoS
account Layer 2 encapsulation 2-501
attaching a policy-map to an interface 2-555
automatic configuration 2-44
class maps
creating 2-70
defining the match criteria 2-399
clearing aggregate counters 2-103
configuring auto 2-44
defining a named aggregate policer 2-503
defining default CoS value 2-509
defining ingress CoS-to-DSCP mapping 2-514
displaying aggregate policer information 2-824
displaying auto configuration 2-593
displaying class maps information 2-607
displaying configuration information 2-593
displaying configurations of policies 2-800
displaying policy map information 2-796, 2-803
displaying QoS information 2-823
displaying QoS map information 2-828
egress queue-sets
enabling the priority queue 2-113
enabling global configuration mode 2-497
enabling on control packets 2-506
enabling per-VLAN QoS for a Layer 2 interface 2-523
enabling QoS on an interface 2-498
hierarchical policies
average-rate traffic shaping on a class 2-577
bandwidth allocation for a class 2-50, 2-69
creating a service policy 2-558
marking 2-564
strict priority queueing (LLQ) 2-485
mapping DSCP values to transmit queues 2-516
mapping egress DSCP-to-CoS 2-516
mapping the DSCP-to-CoS value 2-516
policy maps
creating 2-454
marking 2-564
trust states 2-999
setting the mapping of policed DSCP values 2-518
setting the trust state 2-521
specifying flow-based match criteria 2-402
Supervisor Engine 6-E
setting CoS 2-566
setting DSCP 2-569
setting precedence values 2-572
setting QoS group identifiers 2-575
QoS CoS
configuring for tunneled Layer 2 protocol packets 2-342
defining default CoS value 2-509
qos dbl 2-510
quality of service
question command 1-1
queueing information
displaying 2-826
queue limiting
configuring packet limits 2-525
R
Rapid PVST
switching between PVST and MST 2-908
re-authenticating 802.1X-enabled ports 2-191
re-authentication
periodic 2-192
set the time 2-194
reauthentication, enabling 2-35
reboots
restoring bindings across 2-261
redundancy
accessing the main CPU 2-527
changing from active to standby supervisor engine 2-531
displaying information 2-830
displaying ISSU config-sync failure information 2-834
displaying redundancy facility information 2-830
displaying RF client list 2-830
displaying RF operational counters 2-830
displaying RF states 2-830
enabling automatic synchronization 2-47
forcing switchover to standby supervisor engine 2-531
mismatched command listing 2-529
set the mode 2-409
synchronizing the route processor configurations 2-396
related documentation 1-xxi
remote-id, setting for an interface 2-480
remote-id, setting for an interface VLAN range 2-481
remote SPAN
renew commands
ip dhcp snooping database 2-535
rep admin vlan command 2-536
rep block port command 2-537
rep lsl-age-timer command 2-541
rep preempt delay command 2-543
rep preempt segment command 2-545
rep segment command 2-546
rep stcn command 2-549
resetting PVLAN trunk
setting switchport to trunk 2-956
retry failed authentiation, configuring 2-26
rj45 connector, selecting the connector 2-408
ROM monitor mode
summary 1-6
Route Processor Redundancy
router, set to become ANCP client 2-18
RPF
disabling IPv4 exists-only checks 2-304
enabling IPv4 exists-only checks 2-304
RPR
set the redundancy mode 2-409
RSPAN
converting VLAN to RSPAN VLAN 2-534
displaying list 2-878
S
sampler (netflow-lite monitor submode) command 2-553
saving configuration changes 1-11
secure address, configuring 2-459
secure ports, limitations 2-962
server (AAA) alive actions, configuring 2-26
server (AAA) dead actions, configuring 2-26
service-policy command (policy-map class) 2-558
session classification, defining 2-30
set the redundancy mode 2-409
sfp connector, selecting the connector 2-408
shape command 2-577
shell trigger command 2-581, 2-840
show ancp multicast 2-586
show authentication interface command 2-588
show authentication registration command 2-588
show authentication sessions command 2-588
show commands
filtering parameters 1-7
searching and filtering 1-6
show platform commands 1-11
show energywise command 2-625
show ipv6 snooping counters command 2-727
show ip wccp command 2-713
show ip wccp detail command 2-713
show ip wccp view command 2-713
show mab command 2-753
show mac address-table learning command 2-211, 2-767
show netflow-lite exporter command 2-786
show netflow-lite monitor command 2-788
show netflow-lite sampler command 2-790
show nmsp command 2-791
show vlan group command 2-871
show vlan mapping command 2-873
Simple Network Management Protocol
single-character patterns
special characters 1-7
single-host, setting 2-30
slaveslot0
displaying information on the standby supervisor 2-843
slot0
displaying information about the system 2-845
SNMP
debugging spanning tree activities 2-142
ifIndex persistence
clearing SNMP ifIndex commands 2-885
compress SNMP ifIndex table format 2-892
disabling globally 2-891
disabling on an interface 2-887
enabling globally 2-891
enabling on an interface 2-887
informs
disabling 2-889
enabling 2-889
traps
configuring to send when storm occurs 2-934
disabling 2-889
enabling 2-889
mac-notification
adding 1
removing 1
source (netflow-lite exporter submode) command 2-894
SPAN commands
configuring a SPAN session to monitor 2-411
displaying SPAN session information 2-858, 2-936
SPAN enhancements
displaying status 2-784
Spanning Tree Protocol
SPAN session
displaying session information 2-784
filter ACLs 2-411
specify encap type 2-411
turn off host learning based on ingress packets 2-411
special characters
anchoring, table 1-10
SSO 2-409
standard desktop
enabling Cisco-recommended features 2-370
standard desktop and Cisco IP phone
enabling Cisco-recommended features 2-372
sticky address, configuring 2-460
sticky-ARP
disabling on PVLANs 2-299
enabling on PVLANs 2-299
sticky port
deleting 2-100
enabling security 2-961
storm control
configuring for action when storm occurs 2-934
disabling suppression mode 2-632
displaying settings 2-855
enabling 2-934
enabling broadcast 2-934, 2-936
enabling multicast 2-934, 2-936
enabling suppression mode 2-632
enabling timer to recover from error disable 2-217
multicast, enabling 2-936
setting high and low levels 2-934
setting suppression level 2-632
STP
configuring link type for a port 2-906
configuring tunneling encapsulation rate 2-345
debugging all activities 2-142
debugging spanning tree activities 2-142
debugging spanning tree BackboneFast events 2-144
debugging spanning tree UplinkFast 2-147
detecting misconfiguration 2-903
displaying active interfaces only 2-847
displaying BackboneFast status 2-847
displaying bridge status and configuration 2-847
displaying spanning tree debug messages 2-142
displaying summary of interface information 2-847
enabling BPDU filtering by default on all PortFast ports 2-922
enabling BPDU filtering on an interface 2-899
enabling BPDU guard by default on all PortFast ports 2-924
enabling BPDU guard on an interface 2-901
enabling extended system ID 2-904
enabling loop guard as a default on all ports 2-907
enabling PortFast by default on all access ports 2-925
enabling PortFast mode 2-920
enabling protocol tunneling for 2-340
enabling root guard 2-905
enabling spanning tree BackboneFast 2-898
enabling spanning tree on a per VLAN basis 2-929
enabling spanning tree UplinkFast 2-927
setting an interface priority 2-926
setting drop threshold for 2-343
setting pathcost 2-902
setting the default pathcost calculation method 2-919
subinterface configuration mode, summary 1-6
SVI
creating a Layer 3 interface on a VLAN 2-242
switching characteristics
excluding from link-up calculation 2-953
modifying 2-953
returning to interfaces
capture function 2-953
switchport 2-977
switchport interfaces
displaying status of Layer 3 port 2-664
displaying status of native VLAN tagging 2-664
switchport vlan mapping command 2-981
switch shim
debugging 2-145
disabling debugging 2-145
switch to router connection
enabling Cisco-recommended features 2-374
switch to switch connection
enabling Cisco-recommended features 2-376
switch virtual interface
sw-vlan 2-148
system prompts 1-5
T
Tab key
command completion 1-1
tables
characters with special meaning 1-7
mac access-list extended subcommands 2-358
multipliers 1-9
relationship between duplex and speed commands 2-932
show cable-diagnostics tdr command output fields 2-598
show cdp neighbors detail field descriptions 2-606
show cdp neighbors field descriptions 2-605
show ip dhcp snooping command output 2-589, 2-753
show ip interface field descriptions 2-699
show policy-map control-plane field descriptions 2-799
show vlan command output fields 2-877
show vtp command output fields 2-882
special characters 1-9
special characters used for anchoring 1-10
speed command options 2-402, 2-932
valid interface types 2-237
TAC
displaying information useful to TAC 2-859
TCAM
debugging spanning tree activities 2-142
TDR
displaying cable diagnostic test results 2-597
test condition of copper cables 2-987
temperature readings
displaying information 2-629
template data timeout (netflow-lite exporter submode) command 2-985
timer information 2-633
traffic monitor
display status 2-753
traffic shaping
enable on an interface 2-579
transport udp (netflow-lite exporter submode) command 2-995
transport udp load-share (netflow-lite exporter submode) command 2-997
traps, enabling 2-889
trunk encapsulation
setting format 2-977
trunk interfaces
displaying trunk interfaces information 2-671
trunk port, configuring VLAN mapping 2-981
trunk ports, display VLAN mapping information 2-873
trust configuration, setting on an interface 2-482, 2-483
trust state
setting 2-250
ttl (netflow-lite exporter submode) command 2-1001
tunnel ports
displaying information about Layer 2 protocol 2-747
TX queues
allocating bandwidth 2-1003
returning to default values 2-1003
setting priority to high 2-1003
specifying burst size 2-1003
specifying traffic rate 2-1003
U
UDLD
displaying administrative and operational status 2-861
enabling by default on all fiber interfaces 2-1005
enabling on an individual interface 2-1007
preventing a fiber interface from being enabled 2-1007
resetting all shutdown ports 2-1009
setting the message timer 2-1005
Unidirectional Link Detection
unidirection port control, changing from bidirectional 2-23
unknown multicast traffic, preventing 2-955
unknown unicast traffic, preventing 2-955
user EXEC mode, summary 1-5
username
setting password and privilege level 2-1011
V
VACLs
access-group mode 2-6
applying VLAN access maps 2-1026
displaying VLAN access map information 2-868
specifying an action in a VLAN access map 2-13
specifying the match clause for a VLAN access-map sequence 2-397
using a VLAN filter 2-1026
VLAN
applying an ARP ACL 2-244
configuring 2-1015
configuring service policies 2-1020
converting to RSPAN VLAN 2-534
displaying CEF information 2-678
displaying CEF next-hop information 2-678
displaying information on switch interfaces 2-689, 2-693
displaying information on VLAN switch interfaces 2-696
displaying information sorted by group IP address 2-689, 2-693
displaying IP address and version information 2-689, 2-693
displaying Layer 2 VLAN information 2-864
displaying statistical information 2-782
displaying VLAN information 2-866
enabling dynamic ARP inspection 2-253
enabling Explicit Host Tracking 2-284
enabling guest per-port 2-180
enabling guest VLAN supplicant 2-172, 2-181
entering VLAN configuration mode 2-1020, 2-1022
native frames
enabling tagging on all 802.1Q trunk ports 2-1024
pruning the list for VTP 2-977
setting the list of allowed 2-977
VLAN, create or modify a group 2-1027
VLAN Access Control Lists
VLAN access map
VLAN database
resetting 2-551
VLAN debugging
limiting output 2-120
vlan group command 2-1027
VLAN groups, display VLANs mapped 2-871
VLAN link-up calculation
excluding a switch port 2-953
including a switch port 2-953
VLAN manager
debugging 2-148
disabling debugging 2-148
IOS file system error tests
debugging 2-149
disabling debugging 2-149
VLAN mapping
configuring 2-981
displaying 2-873
VLAN mapping, configure on trunk port 2-981
VLAN mapping on trunk ports, display information 2-873
VLAN Query Protocol
VLAN query protocol (VQPC)
debugging 2-155
VLANs
clearing
counters 2-105
clearing hardware logic 2-78
configuring
internal allocation scheme 2-1029
displaying
internal VLAN allocation information 2-872
RSPAN VLANs 2-878
entering VLAN configuration mode 2-1022
VMPS
configuring servers 2-1033
reconfirming dynamic VLAN assignments 2-155, 2-1031
voice VLANs
enabling 2-949
VoIP
configuring auto-QoS 2-44
VQP
per-server retry count 2-1032
reconfirming dynamic VLAN assignments 2-155, 2-1031
vrf (netflow-lite exporter submode) command 2-1035
VTP
configuring the administrative domain name 2-1039
configuring the device in VTP client mode 2-1038
configuring the device in VTP server mode 2-1042
configuring the device in VTP transparent mode 2-1043
configuring tunnel encapsulation rate 2-345
creating a VTP domain password 2-1040
displaying domain information 2-881
displaying statistics information 2-881
enabling protocol tunneling for 2-340
enabling pruning in the VLAN database 2-1041
enabling VTP version 2 mode 2-1044
modifying the VTP configuration storage file name 2-1037
set drop threshold for 2-343
VTP protocol code
activating debug messages 2-152
deactivating debug messages 2-152
W
Webauth fallback, enabling 2-29