Page 1
ProCurve 5400zl Switches HP ProCurve Switch Software Installation and Getting Started Guide Command Line Interface Reference Guide 3500yl switches 5400zl switches 6200yl switches 8200zl switches Software version K.14.09 April 2009...
Page 3
HP ProCurve 3500yl Switches 5400zl Switches 6200yl Switch 8200zl Switches April 2009 K.14.09 Command Line Interface Reference Guide...
Page 4
The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty.
Contents Introduction ........................... 14 Introduction ........................... 15 Conventions ........................15 Getting Documentation From the Web ................16 CLI Online Help ......................16 Related Publications ...................... 17 How to Navigate This Guide ..................18 Commands ............................ 20 aaa ............................21 Overview ........................21 Command Structure ......................
Command Line Interface Reference Guide Introduction Example Commands Example commands and their output appear in the Courier type face. For example: ProCurve(config)# clear public-key ProCurve(config)# show ip client-public-key show_client_public_key: cannot stat keyfile Port Numbering Conventions ProCurve chassis switches designate individual ports with a letter/number combination to show the slot in which the port is found and the sequential number the port has in that slot (A1, A2, B1, B2, etc.) GETTING DOCUMENTATION FROM THE WEB...
Command Line Interface Reference Guide Introduction This option displays help for any command available at the current context level. RELATED PUBLICATIONS The following documents (available on the ProCurve website) provide additional information on the CLI commands. Software Release Notes Release notes provide information on new software updates: ■...
Command Line Interface Reference Guide Introduction ■ KMS (Key Management System) Advanced Traffic Management Guide Use the Advanced Traffic Management Guide for information on: ■ VLANs: Static port-based and protocol VLANs, and dynamic GVRP VLANs ■ Spanning-Tree: 802.1D (STP), 802.1w (RSTP), and 802.1s (MSTP) ■...
OVERVIEW Category: 802.1X, Accounting, Switch Security Primary context: config Related Commands show (page 511) show (page 511) show (page 511) show (page 511) show (page 511) radius-server (page 456) tacacs-server (page 678) Usage: aaa <...> Description: Configure the switch Authentication, Authorization, and Accounting features.
Page 24
Command Line Interface Reference Guide primary < local | tacacs | radius > -- Specify the primary authentication method for access ■ control. (p. 44) secondary < local | none | authorized > -- Specify the backup authentication method ■ for access control.
Page 25
Command Line Interface Reference Guide secondary < local | none | authorized > -- Specify the backup authentication method ■ for access control. (p. 48) web-based -- Configure authentication mechanism used to control web-based port access to ■ the switch (p.
Page 26
Command Line Interface Reference Guide mac-list1 -- Manage MAC address based network authentication on the device port(s). ■ ([ethernet] PORT-LIST) (p. 39) addr-limit < 1 to 32 > -- Set the port's maximum number of authenticated MAC addresses ■ (default 1). (NUMBER) (p.
Command Line Interface Reference Guide ip-addr -- IP address of the enahced web auth server. (IP-ADDR) (p. 35) ■ page-path -- Sets the path of the login pages to be found on the ewa server. ■ (ASCII-STR) (p. 42) web-list1 -- Manage web authentication based network authentication on the device port(s).
Page 29
Command Line Interface Reference Guide active ■ [no] aaa port-access authenticator active Activate/deactivate 802.1X authenticator. addr-format ■ aaa port-access mac-based addr-format < no-delimiter | single-dash | multi-dash | ... > Set the MAC address format to be used in the RADIUS request message (default no-delimiter).
Page 30
Command Line Interface Reference Guide web-based -- Configure authentication mechanism used to control web-based port access to ■ switch(p. 55) mac-based -- Configure authentication mechanism used to control mac-based port access to ■ switch(p. 37) num-attempts < 1 to 10 > -- Specify the maximum number of login attempts allowed(p.
Page 31
Command Line Interface Reference Guide switch does not try to acquire a supplicant after a failed authentication attempt(default 60 seconds). o 'tx-period' sets the period of time the switch waits to retransmit the next EAPOL PDU during an authentication session (default 30 seconds). o 'server-timeout' sets the period of time after which the switch assumes that authentication has timed out (default 30 seconds).
Page 32
Command Line Interface Reference Guide no specific MAC address filter on the port. The default is no client limit. o 'initialize' re-initialize authentication on the specified ports. That is, 'initialize' blocks inbound and outbound traffic and restarts the authentication process on the specified ports that are configured with 'control auto' (see the 'control' parameter, described above) and actively operating as authenticators.
Page 33
Command Line Interface Reference Guide Next Available Option: VLAN-ID -- Configures VLAN where to move port after successful authentication (not configured ■ by default). (VLAN-ID) (p. 54) ■ [no] aaa port-access web-based [ETHERNET] PORT-LIST auth-vid Configures VLAN where to move port after successful authentication (not configured by default).
Page 34
Command Line Interface Reference Guide Next Available Option: mode < stop-only > -- Specify how to initiate and terminate an accounting session. (p. 40) ■ ■ [no] aaa authorization commands Configure exec (shell) commands authorization. Next Available Option: primary_method < radius | none > -- (p.
Page 35
Command Line Interface Reference Guide Configure how traffic is controlled on non-authenticated ports; in BOTH directions (ingress+egress) or IN only (ingress). Supported Values: ■ both -- Exert control in both directions. ■ in -- Exert control on incoming packets. dhcp-addr ■...
Page 36
Command Line Interface Reference Guide ewa-server ■ [no] aaa port-access web-based ewa-server IP address or hostname of the enhanced web authentication server on the device. Next Available Options: ip-addr -- IP address of the enahced web auth server. (IP-ADDR) (p. 35) ■...
Page 37
Command Line Interface Reference Guide -Disable the port from sending advertisements of existing GVRP-created VLANs on the switch. -Drop all GVRP advertisements received on the port. 3. If you disable the use of dynamic VLANs in an authentication session using the no aaa port-access gvrp-vlans command, client sessions that were authenticated with a dynamic VLAN continue and are not deauthenticated.
Page 38
Command Line Interface Reference Guide Next Available Option: page-path -- Sets the path of the login pages to be found on the ewa server. (ASCII-STR) ■ login ■ aaa authentication console login Configure login access to the switch. Next Available Option: primary <...
Page 39
Command Line Interface Reference Guide Set period of time after which a client will be considered removed from the port for a lack of activity. Range: < 1 to 999999999 > ■ aaa port-access mac-based [ETHERNET] PORT-LIST logoff-period < 1 to 9999999 > Set the period of time of inactivity that the switch considers an implicit logoff (default 300 seconds).
Page 40
Command Line Interface Reference Guide The first form of the command sets the MAC address format which is common to all ports The second form of the command enables, disables, or configures authentication on the device's individual ports. o 'addr-format' sets the MAC address format to be used in the RADIUS request message (default no-delimiter).
Page 41
Command Line Interface Reference Guide addr-format < no-delimiter | single-dash | multi-dash | ... > -- Set the MAC address format to ■ be used in the RADIUS request message (default no-delimiter).(p. 27) mac-list1 ■ [no] aaa port-access mac-based [ETHERNET] PORT-LIST Manage MAC address based network authentication on the device port(s).
Page 42
Command Line Interface Reference Guide Set number of times a client can enter their credentials before authentication is considered to have failed (default 3). Range: < 1 to 10 > max-start ■ aaa port-access supplicant [ETHERNET] PORT-LIST max-start < 1 to 10 > Define the maximum number of attempts taken to start authentication (default 3).
Page 43
Command Line Interface Reference Guide Next Available Option: method < radius > -- Specify which accounting method to use (radius) (p. 40) ■ ■ aaa accounting network < start-stop | stop-only > Specify how to initiate and terminate an accounting session. Supported Values: ■...
Page 44
Command Line Interface Reference Guide num-attempts ■ aaa authentication num-attempts < 1 to 10 > Usage: aaa authentication num-attempts <1-10> Description: Specify the maximum number of login attempts allowed. The default value is 3. Range: < 1 to 10 > NUMBER-OF-CLIENTS ■...
Page 45
Command Line Interface Reference Guide Usage: [no] aaa port-access <authenticator ... | supplicant ... web-based ... | mac-based ...> Description: Configure 802.1X (Port Based Network Access), MAC address based network access, or web authentication based network access on the device. You can configure authenticator, supplicant, MAC address based, or web authentication based network access on the device or device ports by specifying...
Page 46
Command Line Interface Reference Guide logoff-period < 1 to 999999999 > -- Set period of time after which a client will be considered ■ removed from the port for a lack of activity. (NUMBER) (p. 36) client-limit -- Set the maximum number of clients to allow on the port.(p.
Page 47
Command Line Interface Reference Guide Next Available Option: secondary < local | none | authorized > -- Specify the backup authentication method for access ■ control.(p. 48) ■ aaa authentication telnet login < local | tacacs | radius > Specify the primary authentication method for access control. Supported Values: ■...
Page 48
Command Line Interface Reference Guide Next Available Option: secondary < local | none | authorized > -- Specify the backup authentication method for access ■ control.(p. 48) ■ aaa authentication ssh login < local | tacacs | radius | ... > Specify the primary authentication method for access control.
Page 49
Command Line Interface Reference Guide Next Available Option: secondary < none | authorized > -- Specify the backup authentication method for access ■ control.(p. 48) primary_method ■ aaa authorization commands < radius | none > Supported Values: ■ radius -- Use RADIUS protocol as the authorization method. ■...
Page 50
Command Line Interface Reference Guide Range: < 0 to 9999999 > ■ aaa port-access mac-based [ETHERNET] PORT-LIST reauth-period < 0 to 9999999 > Set the re-authentication timeout in seconds; set to '0' to disable re-authentication (default 0). Range: < 0 to 9999999 > ■...
Page 51
Command Line Interface Reference Guide ■ none -- Do not use backup authentication methods. ■ authorized -- Allow access without authentication. ■ aaa authentication web enable < local | radius > < local | none | authorized > Specify the backup authentication method for access control. Supported Values: ■...
Page 52
Command Line Interface Reference Guide secret ■ aaa port-access supplicant [ETHERNET] PORT-LIST identity IDENTITY secret ■ aaa port-access supplicant [ETHERNET] PORT-LIST secret Trigger the command to ask user for a password for the supplicant to use. server-timeout ■ aaa port-access authenticator [ETHERNET] PORT-LIST server-timeout < 1 to 300 > Set the authentication server response timeout (default 30sec.).
Page 53
Command Line Interface Reference Guide start-period ■ aaa port-access supplicant [ETHERNET] PORT-LIST start-period < 1 to 300 > Set a period of time between EAPOL-Start packet retransmission (default 30sec.). Range: < 1 to 300 > supplicant ■ [no] aaa port-access supplicant [ETHERNET] PORT-LIST Usage: [no] aaa port-access supplicant [ethernet] PORT-LIST [auth-timeout <1-300>...
Page 54
Command Line Interface Reference Guide supplicant-timeout ■ aaa port-access authenticator [ETHERNET] PORT-LIST supplicant-timeout < 1 to 300 > Set the supplicant response timeout on an EAP request (default 30 sec.). Range: < 1 to 300 > suppress ■ [no] aaa accounting suppress Do not generate accounting records for a specific type of user.
Page 55
Command Line Interface Reference Guide o <backup-method> - Specifies an authentication method to use, if the primary authentication method is not able to check user's credentials. Use <TAB> or <?> after you specify the primary authentication method to get a list of all available backup methods.
Page 56
Command Line Interface Reference Guide Next Available Option: web-unauthvid -- Configures VLAN where to keep port while there is an unauthorized client ■ connected (not configured by default). (VLAN-ID) (p. 58) update ■ [no] aaa accounting update Usage: [no] aaa accounting update periodic <number> Description: Configure update accounting records mechanism.
Page 57
Command Line Interface Reference Guide to use, if the primary authentication method is not able to check user's credentials. Use <TAB> or <?> after you specify the primary authentication method to get a list of all available backup methods. Next Available Options: enable -- Configure access to the privileged mode commands.(p.
Page 58
Command Line Interface Reference Guide Description: Configure web authentication based network authentication on the device or the device's port(s). The first form of the command sets the dhcp address, dhcp lease, or ewa server parameters which are common to all ports The second form of the command enables, disables, or configures authentication on the device's individual ports.
Page 59
Command Line Interface Reference Guide the switch considers an implicit logoff (default 300) o 'reauth-period' sets the period of time after which connected clients must be re-authenticated. When the timeout is set to 0 the re-authentication is disabled (default 0). o 'auth-vid' configures the VLAN to which to move a port after successful authentication.
Page 60
Command Line Interface Reference Guide max-requests < 1 to 10 > -- Set maximum number of times the switch retransmits authentication ■ requests (default 3). (NUMBER) (p. 39) reauth-period < 0 to 9999999 > -- Set the re-authentication timeout in seconds; set to '0' to ■...
access-list OVERVIEW FOR IPV4 ACLS Category: Primary context: config Related Commands Note: This information is preliminary; the final detailed command list is coming soon. Usage for commands: access-list <number> remark <remark> access-list <1-99> permit <ACL-IP-SPEC-SRC> access-list <1-99> deny <ACL-IP-SPEC-SRC> [log] access-list <100-199>...
Command Line Interface Reference Guide access-list o <ACL-IP-SPEC> - specify the source or destination IP addresses to match. The following formats may be used to specify IP addresses: * IP-ADDR MASK - match addresses defined by IP-ADDR using the bits set to zero in MASK.
Page 63
Command Line Interface Reference Guide access-list <any|host <DA>|DA/<prefix-length>> [comparison-operator <value>] [established] [ack][fin][rst][syn] <icmp> <any|host <SA>|SA/<prefix-length>> <any|host <DA>|DA/<prefix-length>> [0-255 [0-255]|icmp-message] [dscp <precedence|codepoint>] [log] Insert an ACE or a remark by assigning a sequence number: ProCurve(config)# ipv6 access-list <name-str> ProCurve(config-ipv6-acl)# <seq-#> <deny|permit|remark> Note: The deny and permit keywords use the options show above for "Create and IPv6 ACL".
alias OVERVIEW Category: Primary context: config Related Commands Usage: [no] alias <NAME> <COMMAND> [COMMAND-OPTIONS] Description: Configure/remove a NAME for the specified alias command and options. COMMAND STRUCTURE ■ [no] alias name -- Name of alias. (ASCII-STR) (p. 63) command -- Command to execute. (ASCII-STR) (p.
arp-protect OVERVIEW Category: Primary context: config Related Commands Usage: [no] arp-protect [trust [ethernet] PORT-LIST| validate <ip|destination-mac|src-mac>| vlan VLAN-ID-RANGE] Description: Configure Dynamic ARP Protection. To Enable/disable ARP Protection on the switch execute the [no] arp-protect command. Dynamic ARP Protection will not be enabled on any VLAN if it is not enabled on the switch.
Command Line Interface Reference Guide arp-protect src-mac -- Drop any ARP request or response packet in which the source MAC in the ethernet ■ header does not match the sender MAC address in the body of the packet. (p. 66) ■...
autorun OVERVIEW Category: Primary context: config Related Commands copy usb (page 133) Usage: [no] autorun ... Description: Enable/Disable/Configure Autorun. Use the 'secure-mode' keyword to enable/disable secure mode for autorun. Use the 'encryption-key' keyword to configure or remove an encryption key (a base-64 encoded string).
auto-tftp OVERVIEW Category: File Transfer Primary context: config Related Commands the section called client” (page 685) Usage: [no] auto-tftp [<IPV4-ADDR | IPV6-ADDR> <FILENAME-STR>] Description: Enable/disable automatic software image download via TFTP during boot. The software image will be downloaded if it has a different version from the software running on the switch.
Page 73
Command Line Interface Reference Guide auto-tftp IPv4 address of the TFTP server to download a software image from. Next Available Option: filename -- The software image file-name. (ASCII-STR) (p. 70) ■ server-ipv6 ■ auto-tftp IPV6-ADDR IPv6 address of the TFTP server to download a software image from. Next Available Option: filename -- The software image file-name.
banner OVERVIEW Category: Switch Management Primary context: config Related Commands show (page 511) Usage: [no] banner motd ASCII-STR Description: Define a login banner. The banner will be displayed before login on the console, telnet, ssh, and Web-UI sessions. The banner can be a multi-line text up to 320 characters. The banner text can contain any printable character except the delimiting character and the ~ character.
boot OVERVIEW Category: Switch Management Primary context: manager Related Commands reload (page 467) Usage: boot [system [flash <primary|secondary>] [config FILENAME]] boot set-default flash <primary|secondary> boot active boot standby Description: Reboot the device. The primary or secondary software image can be specified to be used during the boot process. Optionally, a configuration file can be set for this boot.
Page 76
Command Line Interface Reference Guide boot module. If a second management module is not present in the switch, the system is rebooted. config ■ boot system flash < primary | secondary > config < config | config1 > Specify configuration file to use on boot. Supported Values: ■...
OVERVIEW Category: Routing Primary context: config Related Commands the section called cdp” (page 537) Usage: [no] cdp ... Description: Set various CDP (Cisco Discovery Protocol) parameters. Use 'cdp ?' to get a list of all possible options. COMMAND STRUCTURE ■ [no] cdp enable -- Enable/disable CDP on particular device ports ([ethernet] PORT-LIST) (p.
chassislocate OVERVIEW Category: Primary context: operator Related Commands Usage: chassislocate <on|blink> [<1-1440>] chassislocate off Description: Control the chassis locate led. Parameters: o on - Turn the led on. o off - Turn the led off. o blink - Make the led blink. o [<1-1440>] - Number of minutes the led is to blink or be turned on (default is 30).
Page 80
Command Line Interface Reference Guide chassislocate ■ chassislocate off Turn the chassis locate led off. ■ chassislocate on Turn the chassis locate led on (default 30 minutes). Next Available Option: duration < 1 to 1440 > -- Number of minutes duration (default 30). (NUMBER) (p.
class OVERVIEW Category: Primary context: config Related Commands policy (page 398) Usage: [no] class <address-family> <name> Description: Create a classifier class and enter the class context. Parameters are address family(ipv4 or ipv6) and class name. COMMAND STRUCTURE ■ [no] class ipv4 -- Enter ipv4 class name (ASCII-STR) (p.
Page 82
Command Line Interface Reference Guide class incr-num ■ class resequence ipv4 IPV4 < 1 to 2147483647 > < 1 to 2147483646 > Specify the increment. Range: < 1 to 2147483646 > ■ class resequence ipv6 IPV6 < 1 to 2147483647 > < 1 to 2147483646 > Specify the increment.
Page 83
Command Line Interface Reference Guide class Next Available Option: incr-num < 1 to 2147483646 > -- Specify the increment. (p. 80) ■ ■ class resequence ipv6 IPV6 < 1 to 2147483647 > Specify the starting sequence number. Range: < 1 to 2147483647 > Next Available Option: incr-num <...
clear OVERVIEW Category: Primary context: manager Related Commands Usage: clear <arp|intrusion-log|logging|public-key|statistics [ethernet] PORT-LIST |link-keepalive statistics> Description: Clear table/statistics or authorized client public keys. Parameters: o arp - Flushes all non-permanent entries in the ARP cache. o intrusion-log - Resets the Alert Flags and prepares the switch to detect and log the next security intrusion.
Page 86
Command Line Interface Reference Guide clear ipv6 ■ clear ipv6 Clear all IPv6 information. Next Available Option: neighbors -- Delete all the neighbour discovery cache entries, except static entries.(p. 84) ■ keyfile ■ clear crypto client-public-key < manager | operator > Remove client public keys from active configuration.
Page 87
Command Line Interface Reference Guide clear [<ip-address>] specified clears statistics for a given interface if the interface is OSPF enabled. Next Available Option: if-ip -- specify ip-address whose statistics is to be cleared. (IP-ADDR) (p. 83) ■ statistics ■ clear statistics [ETHERNET] PORT-LIST Reset all counters for the specified ports.
clock OVERVIEW Category: Switch Management Primary context: config Related Commands ip (page 290) sntp (page 634) time (page 686) Usage: [no] clock [...] Description: Display/set current time, date, and local time parameters. Called without any parameters displays the information mentioned above. Use 'clock ?' to see a list of all possible configuration options.
Page 90
Command Line Interface Reference Guide clock time ■ clock set [TIME] Current time to set. timezone ■ clock timezone Usage: clock timezone [gmt <-12:00 - +14:00>] | <none|alaska|aleutian|arizona|central| east-indiana|eastern|hawaii|michigan|mountain| pacific|samoa>] Description: Set the number of hours your location is to the West(-) or East(+) of GMT.
connection-rate-filter OVERVIEW Category: Troubleshooting Primary context: config Related Commands filter (page 185) ip (page 290) vlan (page 706) show (page 511) Usage: connection-rate-filter unblock < host SRC-IP-ADDR | SRC-IP-ADDRESS/MASK > [no] connection-rate-filter sensitivity <low|medium|high|aggressive> Description: Re-enables access to a host or set of hosts that has been previously blocked by the connection rate filter.
Page 93
Command Line Interface Reference Guide connection-rate-filter sensitivity ■ connection-rate-filter sensitivity Sets the level of filtering required Next Available Option: sensitive < low | medium | high | ... > -- (p. 90) ■ src-ip ■ connection-rate-filter unblock IP-ADDR/MASK-LENGTH Match packets from the specified subnet. unblock ■...
console OVERVIEW Category: Switch Management Primary context: config Related Commands show (page 511) repeat (page 470) Usage: console ... Description: Set various console parameters. Use 'console ?' to get a list of all configurable parameters. The non-configurable parameters and their default values are: Data bits = 8;...
Page 96
Command Line Interface Reference Guide console ■ XON/XOFF ■ None inactivity-timer ■ console inactivity-timer < 0 | 1 | 5 | ... > Usage: console inactivity-timer <0|1|5|10|15|20|30|60|120> Description: Set the number of minutes of no activity detected on the Console port before the switch terminates a communication session.
Page 97
Command Line Interface Reference Guide console ■ 3 ■ 5 ■ 10 ■ 20 ■ 30 ■ 45 ■ 60 terminal ■ console terminal < VT100 | NONE | ANSI > Usage: console terminal <vt100|ansi|none> Description: Set type of terminal being used for all console and telnet sessions (default is vt100).
copy OVERVIEW Category: Primary context: manager Related Commands Usage: copy <source> <destination> [options] Description: Copy datafiles to/from the switch. <source> - specify source of data. It can be 'tftp', 'xmodem', 'command', 'flash', 'usb' or any of the following switch data files: o config o running-config o startup-config...
Page 99
Command Line Interface Reference Guide copy tftp-ip -- Specify TFTP server IPv4 address. (IP-ADDR) (p. 126) ■ filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p. 109) ■ -- Change CR/LF to PC style. (p. 120) ■ unix -- Change CR/LF to unix style. (p.
Page 100
Command Line Interface Reference Guide copy xmodem -- Use xmodem on the terminal as the data destination. (p. 135) ■ ■ copy crash-log -- Copy the switch log file. (p. 107) card -- Enter single slot identifier. (SLOT-ID-RANGE) (p. 105) ■...
Page 101
Command Line Interface Reference Guide copy filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p. 109) ■ cv_out_flash < primary | secondary > -- Copy from primary/secondary flash. (p. 108) ■ xmodem -- Use xmodem on the terminal as the data destination. (p.
Page 102
Command Line Interface Reference Guide copy append -- Add the key(s) for access. (p. 102) ■ autorun-key-file -- Copy autorun key file to the switch. (p. 105) ■ tftp-ip -- Specify TFTP server IPv4 address. (IP-ADDR) (p. 126) ■ filename -- Specify filename for the TFTP transfer.
Page 103
Command Line Interface Reference Guide copy operator -- Replace the key(s) for operator access (default); follow with the 'append' ■ option to add the key(s). (p. 119) append -- Add the key(s) for access. (p. 102) ■ tftp-ipv6 -- Specify TFTP server IPv6 address. (IPV6-ADDR) (p.
Command Line Interface Reference Guide copy flash -- Copy data to the switch system image file. (p. 116) ■ image-name -- Specify filename for the USB transfer. (ASCII-STR) (p. 117) ■ cv_flash < primary | secondary > -- Copy to primary/secondary flash. (p.
Page 105
Command Line Interface Reference Guide copy ■ copy tftp pub-key-file IPV6-ADDR FILENAME append Add the key(s) for operator access. ■ copy tftp pub-key-file IPV6-ADDR FILENAME operator append Add the key(s) for access. ■ copy tftp pub-key-file IPV6-ADDR FILENAME manager append Add the key(s) for access.
Page 106
Command Line Interface Reference Guide copy ■ copy tftp autorun-key-file IPV6-ADDR FILENAME append Add the key(s) for operator access. ■ copy tftp autorun-key-file IPV6-ADDR FILENAME operator append Add the key(s) for access. ■ copy tftp autorun-key-file IPV6-ADDR FILENAME manager append Add the key(s) for access.
Page 107
Command Line Interface Reference Guide copy autorun-cert-file ■ copy tftp autorun-cert-file Copy autorun trusted certificate to the switch. Next Available Options: tftp-ip -- Specify TFTP server IPv4 address. (IP-ADDR) (p. 126) ■ tftp-ipv6 -- Specify TFTP server IPv6 address. (IPV6-ADDR) (p.
Page 108
Command Line Interface Reference Guide copy xmodem -- Use xmodem on the terminal as the data destination.(p. 135) ■ -- Copy data to a USB flash drive.(p. 133) ■ command-file ■ copy tftp command-file Copy command script to switch and execute. Next Available Options: tftp-ip -- Specify TFTP server IPv4 address.
Page 109
Command Line Interface Reference Guide copy Copy data to specified configuration file. Next Available Options: unix -- Change CR/LF to unix style.(p. 131) ■ -- Change CR/LF to PC style.(p. 120) ■ ■ copy config < config1 | config2 | config3 > Copy named configuration file.
Page 110
Command Line Interface Reference Guide copy Copy to primary/secondary flash. Supported Values: ■ primary -- Copy to primary flash. ■ secondary -- Copy to secondary flash. ■ copy tftp flash IPV6-ADDR FILENAME < primary | secondary > Copy to primary/secondary flash. Supported Values: ■...
Page 112
Command Line Interface Reference Guide copy Next Available Option: cv_flash < primary | secondary > -- Copy to primary/secondary flash.(p. 107) ■ ■ copy tftp pub-key-file IP-ADDR FILENAME Specify filename for the TFTP transfer. Next Available Options: append -- Add the key(s) for operator access.(p.
Page 113
Command Line Interface Reference Guide copy Specify filename for the TFTP transfer. Next Available Options: unix -- Change CR/LF to unix style.(p. 131) ■ -- Change CR/LF to PC style.(p. 120) ■ ■ copy tftp autorun-cert-file IP-ADDR FILENAME Specify filename for the TFTP transfer. Next Available Options: append -- Add the key(s) for operator...
Page 114
Command Line Interface Reference Guide copy Specify filename for the TFTP transfer. Next Available Options: unix -- Change CR/LF to unix style.(p. 131) ■ -- Change CR/LF to PC style.(p. 120) ■ ■ copy tftp show-tech IPV6-ADDR FILENAME Specify filename for the TFTP transfer. Next Available Options: unix -- Change CR/LF to unix...
Page 115
Command Line Interface Reference Guide copy Next Available Options: append -- Add the key(s) for operator access.(p. 102) ■ operator -- Replace the key(s) for operator access (default); follow with the 'append' option to ■ add the key(s).(p. 119) manager -- Replace the key(s) for manager access;...
Page 116
Command Line Interface Reference Guide copy ■ copy crash-data SLOT-ID-RANGE usb FILENAME Specify filename for the USB transfer. ■ copy crash-data mm tftp IP-ADDR FILENAME Specify filename for the TFTP transfer. ■ copy crash-data mm tftp IPV6-ADDR FILENAME Specify filename for the TFTP transfer. ■...
Page 117
Command Line Interface Reference Guide copy Specify filename for the TFTP transfer. ■ copy crash-log tftp IPV6-ADDR FILENAME Specify filename for the TFTP transfer. ■ copy crash-log usb FILENAME Specify filename for the USB transfer. ■ copy flash tftp IP-ADDR FILENAME Specify filename for the TFTP transfer.
Page 118
Command Line Interface Reference Guide copy Specify filename for the TFTP transfer. Next Available Options: unix -- Change CR/LF to unix style.(p. 131) ■ -- Change CR/LF to PC style.(p. 120) ■ ■ copy startup-config tftp IPV6-ADDR FILENAME Specify filename for the TFTP transfer. Next Available Options: unix -- Change CR/LF to unix...
Page 119
Command Line Interface Reference Guide copy Next Available Option: cv_flash < primary | secondary > -- Copy to primary/secondary flash.(p. 107) ■ ■ copy usb flash Copy data to the switch system image file. Next Available Option: image-name -- Specify filename for the USB transfer. (ASCII-STR) (p.
Page 120
Command Line Interface Reference Guide copy ■ copy tftp autorun-cert-file IP-ADDR FILENAME manager Replace the key(s) for manager access; follow with the 'append' option to add the key(s). Next Available Option: append -- Add the key(s) for access.(p. 102) ■ ■...
Page 121
Command Line Interface Reference Guide copy Next Available Option: append -- Add the key(s) for access.(p. 102) ■ ■ copy crash-data mm Copy from the management card. Next Available Options: tftp -- Copy data to a TFTP server.(p. 124) ■ xmodem -- Use xmodem on the terminal as the data destination.(p.
Page 122
Command Line Interface Reference Guide copy Replace the key(s) for operator access (default); follow with the 'append' option to add the key(s). Next Available Option: append -- Add the key(s) for access.(p. 102) ■ ■ copy tftp autorun-key-file IP-ADDR FILENAME operator Replace the key(s) for operator access (default);...
Page 123
Command Line Interface Reference Guide copy ■ copy tftp command-file IPV6-ADDR FILENAME pc Change CR/LF to PC style. ■ copy tftp startup-config IP-ADDR FILENAME pc Change CR/LF to PC style. ■ copy tftp startup-config IPV6-ADDR FILENAME pc Change CR/LF to PC style. ■...
Page 124
Command Line Interface Reference Guide copy ■ copy config < config1 | config2 | config3 > xmodem pc Change CR/LF to PC style. ■ copy running-config tftp IP-ADDR FILENAME pc Change CR/LF to PC style. ■ copy running-config tftp IPV6-ADDR FILENAME pc Change CR/LF to PC style.
Page 125
Command Line Interface Reference Guide copy running-config ■ copy running-config Copy running configuration file. Next Available Options: tftp -- Copy data to a TFTP server.(p. 124) ■ xmodem -- Use xmodem on the terminal as the data destination.(p. 135) ■ -- Copy data to a USB flash drive.(p.
Page 126
Command Line Interface Reference Guide copy -- Copy data to a USB flash drive.(p. 133) ■ tftp ■ copy tftp Copy data from a TFTP server. Next Available Options: command-file -- Copy command script to switch and execute.(p. 106) ■ flash -- Copy data to the switch system image file.(p.
Page 127
Command Line Interface Reference Guide copy Copy data to a TFTP server. Next Available Options: tftp-ip -- Specify TFTP server IPv4 address. (IP-ADDR) (p. 126) ■ tftp-ipv6 -- Specify TFTP server IPv6 address. (IPV6-ADDR) (p. 129) ■ ■ copy crash-log SLOT-ID-RANGE tftp Copy data to a TFTP server.
Page 128
Command Line Interface Reference Guide copy tftp-ipv6 -- Specify TFTP server IPv6 address. (IPV6-ADDR) (p. 129) ■ ■ copy event-log tftp Copy data to a TFTP server. Next Available Options: tftp-ip -- Specify TFTP server IPv4 address. (IP-ADDR) (p. 126) ■...
Page 129
Command Line Interface Reference Guide copy Next Available Option: filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p. 109) ■ ■ copy tftp autorun-key-file IP-ADDR Specify TFTP server IPv4 address. Next Available Option: filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p.
Page 130
Command Line Interface Reference Guide copy ■ copy crash-log SLOT-ID-RANGE tftp IP-ADDR Specify TFTP server IPv4 address. Next Available Option: filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p. 109) ■ ■ copy crash-log mm tftp IP-ADDR Specify TFTP server IPv4 address. Next Available Option: filename -- Specify filename for the TFTP transfer.
Page 131
Command Line Interface Reference Guide copy tftp-ipv6 ■ copy tftp command-file IPV6-ADDR Specify TFTP server IPv6 address. Next Available Option: filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p. 109) ■ ■ copy tftp flash IPV6-ADDR Specify TFTP server IPv6 address. Next Available Option: filename -- Specify filename for the TFTP transfer.
Page 132
Command Line Interface Reference Guide copy Specify TFTP server IPv6 address. Next Available Option: filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p. 109) ■ ■ copy command-output COMMAND-OUTPUT tftp IPV6-ADDR Specify TFTP server IPv6 address. Next Available Option: filename -- Specify filename for the TFTP transfer.
Page 133
Command Line Interface Reference Guide copy Next Available Option: filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p. 109) ■ ■ copy crash-log tftp IPV6-ADDR Specify TFTP server IPv6 address. Next Available Option: filename -- Specify filename for the TFTP transfer. (ASCII-STR) (p.
Page 135
Command Line Interface Reference Guide copy Change CR/LF to unix style. ■ copy running-config xmodem unix Change CR/LF to unix style. ■ copy startup-config tftp IP-ADDR FILENAME unix Change CR/LF to unix style. ■ copy startup-config tftp IPV6-ADDR FILENAME unix Change CR/LF to unix style.
Page 136
Command Line Interface Reference Guide copy ■ copy crash-data mm usb Copy data to a USB flash drive. Next Available Option: filename -- Specify filename for the USB transfer. (ASCII-STR) (p. 109) ■ ■ copy crash-data usb Copy data to a USB flash drive. Next Available Option: filename -- Specify filename for the USB transfer.
Page 137
Command Line Interface Reference Guide copy Copy data to a USB flash drive. Next Available Option: filename -- Specify filename for the USB transfer. (ASCII-STR) (p. 109) ■ ■ copy event-log usb Copy data to a USB flash drive. Next Available Option: filename -- Specify filename for the USB transfer.
Page 138
Command Line Interface Reference Guide copy ■ copy crash-log SLOT-ID-RANGE xmodem Use xmodem on the terminal as the data destination. ■ copy crash-log mm xmodem Use xmodem on the terminal as the data destination. ■ copy crash-log xmodem Use xmodem on the terminal as the data destination. ■...
Page 143
Command Line Interface Reference Guide crypto Common name [e.g., IP address of device]. Next Available Option: org-unit -- Organizational unit [Department]. (ASCII-STR) (p. 147) ■ country ■ crypto host-cert generate self-signed [DATE: START-DATE] [DATE: END-DATE] CNAME ORG-UNIT ORGANIZATION CITY STATE < AD | AE | AF | ... > Country code (2 character ISO code).
Page 144
Command Line Interface Reference Guide crypto ■ CG -- Congo ■ CH -- Switzerland ■ CI -- Cote D'Ivoire (Ivory Coast) ■ CK -- Cook Islands ■ CL -- Chile ■ CM -- Cameroon ■ CN -- China ■ CO -- Colombia ■...
Page 145
Command Line Interface Reference Guide crypto ■ GW -- Guinea-Bissau ■ GY -- Guyanav ■ HK -- Hong Kong ■ HM -- Heard and McDonald Islands ■ HN -- Honduras ■ HR -- Croatia (Hrvatska) ■ HT -- Haiti ■ HU -- Hungary ■...
Page 146
Command Line Interface Reference Guide crypto ■ MM -- Myanmar ■ MN -- Mongolia ■ MO -- Macau ■ MP -- Northern Mariana Islands ■ MQ -- Martinique ■ MR -- Mauritania ■ MS -- Montserrat ■ MT -- Malta ■...
Page 147
Command Line Interface Reference Guide crypto ■ SE -- Sweden ■ SG -- Singapore ■ SH -- St. Helena ■ SI -- Slovenia ■ SJ -- Svalbard and Jan Mayen Islands ■ SK -- Slovak Republic ■ SL -- Sierra Leone ■...
debug OVERVIEW Category: Primary context: manager Related Commands log (page 361) show logging (page 567) show debug (page 545) Usage: [no] debug destination <logging|session|buffer> [no] debug <all|DEBUG_TYPE> Description: Enable/disable debug logging. Parameters: o destination - Enable or disable a debug destination. (Multiple destinations can be configured) o logging - Send the debug messages to a remote device via the syslog facility.
Command Line Interface Reference Guide dhcp-relay -- Sets the remote id to be the IP address of the VLAN on which the client request was ■ received. (p. 162) -- Sets the remote id to be the MAC address of the switch. This is the default value. ■...
Page 163
Command Line Interface Reference Guide dhcp-relay ■ [no] dhcp-relay option 82 Optional argument to dhcp-agent used to specify the operational status for option 82. Next Available Options: append -- Specifies that the option 82 field should be appended to client DHCP packet.(p.
Page 164
Command Line Interface Reference Guide dhcp-relay mgmt-vlan -- Sets the remote id to be the IP address of the Management VLAN.(p. 163) ■ ■ dhcp-relay option 82 validate drop Specifies that the DHCP packet will be dropped unconditionally, if option 82 field(s) already exists in the client DHCP packet. Next Available Options: -- Sets the remote id to be the MAC address of the switch.
Page 165
Command Line Interface Reference Guide dhcp-relay keep ■ dhcp-relay option 82 keep Specifies that no option 82 field will be added or replaced, if option 82 field(s) already exists in the client DHCP packet. Next Available Options: -- Sets the remote id to be the MAC address of the switch. This is the default value.(p.
Page 166
Command Line Interface Reference Guide dhcp-relay ■ dhcp-relay option 82 keep mgmt-vlan Sets the remote id to be the IP address of the Management VLAN. ■ dhcp-relay option 82 drop mgmt-vlan Sets the remote id to be the IP address of the Management VLAN. ■...
Page 167
Command Line Interface Reference Guide dhcp-relay validate ■ dhcp-relay option 82 append validate Specifies the validation for server response. ■ dhcp-relay option 82 replace validate Specifies the validation for server response. ■ dhcp-relay option 82 drop validate Specifies the validation for server response. ■...
dhcp-snooping OVERVIEW Category: Primary context: config Related Commands Usage: [no] dhcp-snooping Description: Enable/Disable the global administrative status of DHCP snooping. No snooping will be performed on any VLAN if the global administrative status is disabled. The default state is disabled. COMMAND STRUCTURE ■...
Page 169
Command Line Interface Reference Guide dhcp-snooping remote-id < mac | subnet-ip | mgmt-ip > -- Set relay information option remote-id value to use. ■ (NUMBER) (p. 169) authorized-server ■ [no] dhcp-snooping authorized-server Usage: [no] dhcp-snooping authorized-server <IP-ADDR> Description: Configure valid DHCP Servers. For DHCP Snooping to allow a server to client packet to be forwarded, it must be received on a trusted port from a valid server.
Page 170
Command Line Interface Reference Guide dhcp-snooping delay ■ dhcp-snooping database delay < 15 to 86400 > Seconds to delay writing to the lease database file. Range: < 15 to 86400 > file ■ dhcp-snooping database file FILE URL Format: "tftp://<ip-address>/<filename>". ■...
Page 171
Command Line Interface Reference Guide dhcp-snooping Next Available Option: (p. 166) ■ port-list ■ [no] dhcp-snooping trust [ETHERNET] PORT-LIST remote-id ■ dhcp-snooping option 82 remote-id < mac | subnet-ip | mgmt-ip > Set relay information option remote-id value to use. Supported Values: ■...
Page 172
Command Line Interface Reference Guide dhcp-snooping Usage: [no] dhcp-snooping verify <mac> Description: Enable/Disable DHCP packet validation. Parameters: o <mac> - Verify DHCP header client hardware address field and the source mac address match for packets received on untrusted ports. If 'no' is specified this check is omitted.
OVERVIEW Category: Primary context: operator Related Commands Usage: dir [<pathname>] Description: Display a list of the files and subdirectories in a directory on a USB device. COMMAND STRUCTURE ■ dir pathname -- Display a list of the files and subdirectories in a directory on a USB device (ASCII-STR) (p.
enable OVERVIEW Category: Switch Management Primary context: operator Related Commands exit (page 176) end (page 173) Usage: enable Description: Enter the Manager Exec context. COMMAND STRUCTURE EXAMPLES Example: enable Enter the Manager user name and password to access the Manager Exec context of the CLI: ProCurve>...
exit OVERVIEW Category: Switch Management Primary context: operator Related Commands end (page 173) enable (page 172) Usage: exit Description: Return to the previous context or terminate current console/telnet session if you are in the Operator context level. COMMAND STRUCTURE EXAMPLES Example: exit Exit from the interface configuration context to the global configuration context: ProCurve(eth-A4)# exit...
feature-coordinator OVERVIEW Category: Primary context: config Related Commands Usage: [no] feature-coordinator name <'name'> block policy interface <port-list>|vlan <vid-list> message <'msg-text'> [expires expiration-policy]. 'policy' can be 'ip-address','vlan_deletion' for vlans and 'port-security' for interfaces' A list of vlan(s) of the form 3-5,10 can be specified for vid-list A list of port(s) of the form A12,A15-A25 can be specified for port-list.
Command Line Interface Reference Guide feature-coordinator message -- Friendly error message to be displayed when overriding a restriction ■ (ASCII-STR) (p. 182) expires -- Expiration policy for the features Press <tab> for options (p. 181) ■ app-down -- Expire on application failure Mention a valid application name ■...
Page 184
Command Line Interface Reference Guide feature-coordinator app-down -- Expire on application failure Mention a valid application name (ASCII-STR) (p. 181) ■ reboot -- Expire on reboot (p. 183) ■ ■ feature-coordinator name NAME block vlan-deletion vlan [VLAN]VLAN-ID-LIST message MESSAGE expires Expiration policy for the features Press <tab>...
Page 185
Command Line Interface Reference Guide feature-coordinator Next Available Option: expires -- Expiration policy for the features Press <tab> for options (p. 181) ■ ■ feature-coordinator name NAME block vlan-deletion vlan [VLAN]VLAN-ID-LIST message MESSAGE Friendly error message to be displayed when overriding a restriction Next Available Option: expires...
Page 186
Command Line Interface Reference Guide feature-coordinator Expire on reboot slot-down ■ feature-coordinator name NAME block ip-address vlan [VLAN]VLAN-ID-LIST message MESSAGE expires slot-down SLOT-ID Expire on slot-down.Mention slot. ■ feature-coordinator name NAME block vlan-deletion vlan [VLAN]VLAN-ID-LIST message MESSAGE expires slot-down SLOT-ID Expire on slot-down.Mention slot.
filter OVERVIEW Category: Troubleshooting Primary context: config Related Commands connection-rate-filter (page 90) ip (page 290) show (page 511) show (page 511) Usage: [no] filter ... Description: Set or edit traffic/security filters. The command allows you to set conditional filters and correspondent actions to apply to the incoming traffic satisfying to the specified conditions.
Page 189
Command Line Interface Reference Guide filter Next Available Option: forward -- Set a list of ports to which forwarding of filtered packets is permitted. ([ethernet] ■ PORT-LIST) (p. 187) ■ filter multicast MAC-ADDR drop [ETHERNET] PORT-LIST Set a list of ports to which forwarding of filtered packets is not permitted. ■...
Page 190
Command Line Interface Reference Guide filter packets satisfying to the filter condition can be set. The packets satisfying to the filter condition are all packets destined to the MAC-ADDR specified. Use 'filter source-port [ethernet] PORT-NUM ?' to get a list of all possible actions that could be applied to the packets.
Page 191
Command Line Interface Reference Guide filter ■ ip ■ ipx ■ arp ■ appletalk ■ sna ■ netbeui Next Available Options: forward -- Set a list of ports to which forwarding of filtered packets is permitted. ([ethernet] ■ PORT-LIST) (p. 187) drop -- Set a list of ports to which forwarding of filtered packets is not permitted.
With 'password-recovery' enabled (and the front panel buttons disabled), a lost password can be recovered by contacting HP customer support. With 'password- recovery' disabled, there is no way to access a device after losing a password with the front panel buttons disabled.
Page 193
Command Line Interface Reference Guide front-panel-security password-clear ■ [no] front-panel-security password-clear Enable/Disable password clear Next Available Option: reset-on-clear -- Reset switch on password clear (p. 191) ■ password-recovery ■ [no] front-panel-security password-recovery Usage: [no] front-panel-security password-recovery Description: Enable/Disable password recovery. To disable 'password-recovery' physical access to the front-pannel is required, and within 60 secs of pressing the clear button, execute the 'no' form of the command.
getMIB OVERVIEW Category: manager Primary context: manager Related Commands walkMIB (page 754) setMIB (page 504) Usage: getmib OBJECT-STR [OBJECT-STR ...] Description: Retrieve and display the value of the MIB objects specified. COMMAND STRUCTURE ■ getMIB object -- Name and instance of the MIB variable to retrieve. (ASCII-STR) (p.
hostname OVERVIEW Category: config Primary context: config Related Commands snmp-server (page 612) Usage: hostname ASCII-STR Description: Specify the device name for administrative purposes. The ASCII-STR defines the device name. It can be up to 30 characters. Use quotes if your device name contains spaces.
igmp OVERVIEW Category: IGMP Primary context: config Related Commands the section called igmp” (page 556) Usage: igmp ... Description: Configure various global IGMP parameters for the switch. The 'igmp' command must be followed by a feature-specific keyword. Use 'igmp ?' to get a list of all possible options. COMMAND STRUCTURE ■...
igmp-proxy-domain OVERVIEW Category: IGMP Primary context: config Related Commands show (page 511) vlan (page 706) Usage: [no] igmp-proxy-domain DOMAIN-NAME [BORDER-ROUTER-IP-ADDR <MCAST-LOW-IP-ADDR MCAST-HIGH-IP-ADDR|all>] Description: Configure an IGMP proxy domain. If the 'no' keyword is used: The DOMAIN-NAME must be specified, All other parameters are optional (they will be verified if they are specified).
Page 199
Command Line Interface Reference Guide igmp-proxy-domain border-ip ■ [no] igmp-proxy-domain DOMAIN-NAME IP-ADDR Specify the igmp proxy border ip address. Next Available Options: mcast-low-ip -- Specify the igmp proxy multicast low bound (inclusive) ip address. (IP-ADDR) ■ (p. 197) -- Specify ALL if the multicast range 224.0.1.0-239.255.255.255 is desired. (p.
include-credentials OVERVIEW Category: Primary context: config Related Commands Usage: [no] include-credentials Description: Enable/disable including passwords and credentials in config. NOTES Benefits After making changes to security parameters in the running configuration, you can experiment with the new configuration and, if necessary, view the new security settings during the session. After verifying the configuration, you can then save it permanently by writing the settings to the startup-config file.
Command Line Interface Reference Guide instrumentation o high - Preconfigured high threshold value. o limitValue - User configured threshold value. COMMAND STRUCTURE ■ [no] instrumentation collection (p. 200) ■ instrumentation memory -- Sets the maximum size in MB which may be used by instrumentation (p.
Page 203
Command Line Interface Reference Guide instrumentation monitor ■ [no] instrumentation monitor Usage: [no] instrumentation monitor [ [<all|arp-requests|ip-address-count| learn-discards|login-failures|mac-moves| mac-address-count|pkts-to-closed-ports| port-auth-failures|system-resource-usage| system-delay> [<low|med|high|limitValue>]] ] [no] instrumentation monitor [trap] [no] instrumentation monitor [log] Description: Enables/Disables instrumentation monitoring. The first version of the command enables/disables instrumentation monitoring and sets threshold value.
Page 204
Command Line Interface Reference Guide instrumentation ■ [no] instrumentation monitor < all | arp-requests | ip-address-count | ... > Usage: [no] instrumentation monitor [ [<all|arp-requests|ip-address-count| learn-discards|login-failures|mac-moves| mac-address-count|pkts-to-closed-ports| port-auth-failures|system-resource-usage| system-delay> [<low|med|high|limitValue>]] ] [no] instrumentation monitor [trap] [no] instrumentation monitor [log] Description: Enables/Disables instrumentation monitoring. The first version of the command enables/disables instrumentation monitoring and sets threshold value.
Page 205
Command Line Interface Reference Guide instrumentation ■ mac-address-count -- Mac address count. ■ mac-moves -- MAC Moves. ■ pkts-to-closed-ports -- Packets to closed TCP/UDP ports. ■ port-auth-failures -- Port authentication failures. ■ system-resource-usage -- System resource usage. ■ system-delay -- System Delay. Next Available Options: threshold-value <...
interface OVERVIEW Category: Primary context: config Related Commands show interfaces (page 560) Usage: [no] interface < [ethernet] PORT-LIST [...] | loopback <num> > Description: Enter the Interface Configuration Level, or execute one command for that level. Without optional parameters specified, the 'interface' command changes the context to the Interface Configuration Context Level for execution of configuration changes to the port or ports in the PORT-LIST or with loopback keywork it will change context to loopback...
Page 207
Command Line Interface Reference Guide interface queue4 < 0 to 100 > -- Specify min. bandwidth percentage for queue four ■ outgoing traffic. (p. 270) queue5 < 0 to 100 > -- Specify min. bandwidth percentage for queue five ■ outgoing traffic.
Page 208
Command Line Interface Reference Guide interface provider-network -- Configure qinq port-type as provider-network (p. 267) ■ -- Set port-based priority (p. 268) ■ dscp -- Specify DSCP policy to use. (p. 231) ■ binary-range < 0 to 63 > -- Specify the DSCP code-point in binary. (BINARY) (p.
Page 209
Command Line Interface Reference Guide interface access-group -- Apply the specified access control list on this VLAN interface (ASCII-STR) ■ (p. 214) direction < in | out | connection-rate-filter | ... > -- (p. 231) ■ address -- Set IP parameters for communication within an IP network (p.
Page 210
Command Line Interface Reference Guide interface -- Resets all previously blocked by the connection rate filter (p. 219) ■ host -- Match packets from the specified IP address. (IP-ADDR) (p. 237) ■ src-ip -- Match packets from the specified subnet. (IP-ADDR/mask-LENGTH) (p.
Page 211
Command Line Interface Reference Guide interface no-default -- Indicates that the router should never be used as a default by its ■ neighbors. (p. 255) number < -2147483647 to 2147483647 > -- The router preferability number. Higher ■ values are more preferable. (p.
Page 212
Command Line Interface Reference Guide interface chain-name -- Specify key chain to use for MD5 authentication. (ASCII-STR) ■ 228) passive -- Configures an ospf interface as passive. (p. 258) ■ priority < 0 to 255 > -- Set priority of this router as a designated router. (p.
Page 213
Command Line Interface Reference Guide interface -- Enable/disable/configure Routing Internet Protocol (RIP) on the VLAN interface (p. 274) ■ -- Process the request for all IP addresses. (p. 219) ■ authentication-key -- Set RIP authentication key (maximum 16 characters). (p. 223) ■...
Page 214
Command Line Interface Reference Guide interface rapid-commit -- Obtain IPv6 address quickly from DHCPv6 server. (p. 271) ■ ipv6-addr -- Configure a link-local IPv6 address. (IPV6-ADDR) (p. 245) ■ link-local -- Configure a link-local IPv6 address. (p. 248) ■ ipv6-addr/mask -- Configure IPv6 address represented in CIDR notation.
Page 217
Command Line Interface Reference Guide interface Usage: [no] ip access-group <ACL-ID> in Description: Apply the specified access control list to inbound packets on this INTERFACE list. The access control list ACL-ID must be defined before it can be applied. Connection rate filter ACLs cannot be applied on this INTERFACE list.
Page 218
Command Line Interface Reference Guide interface Usage: [no] ip access-group <ACL-ID> <in|out> Match packets this device will route to another VLAN Match packets this device will route onto this VLAN vlan Match packets that originate within this VLAN connection-rate-filter Manage new conection rates originating in this VLAN Description: Apply the specified access control list on this VLAN interface.
Page 219
Command Line Interface Reference Guide interface DHCP/Bootp server. o IP-ADDR/mask-LENGTH - Assign an IP address to the switch or VLAN. The IP-ADDR/mask-LENGTH may be specified in two ways using the following syntax: ip address 192.32.36.87/24 ip address 192.32.36.87 255.255.255.0 Both of the statements above would have the same effect. Multiple addresses may be configured on a single VLAN.
Page 220
Command Line Interface Reference Guide interface configuration. The VLAN for which the configuration is applied can be specified implicitly by preceding the phrase 'ip address' with the 'vlan VLAN-ID' keyword and argument. It can also be called explicitly when called directly from a VLAN context.
Page 221
Command Line Interface Reference Guide interface ipv6-addr/mask -- Configure IPv6 address represented in CIDR notation. ■ (IPV6-ADDR/PREFIX-LEN) (p. 245) advert-address ■ interface vlan VLAN-ID ip irdp < multicast | broadcast > Usage: [no] ip irdp <multicast|broadcast> Description: Specify the destination address to be used for router advertisements.
Page 222
Command Line Interface Reference Guide interface Process the request for all IP addresses. Next Available Options: area -- Specify an OSPF area.(p. 221) ■ cost < 1 to 65535 > -- Set metric of this interface.(p. 229) ■ ■ [no] interface vlan VLAN-ID ip ospf all Process the request for all IP addresses.
Page 223
Command Line Interface Reference Guide interface ■ interface svlan VLAN-ID connection-rate-filter unblock all Resets all previously blocked by the connection rate filter ■ interface svlan VLAN-ID monitor all < In | Out | Both > Monitor all traffic. Supported Values: ■...
Page 224
Command Line Interface Reference Guide interface Specify an OSPF area. Next Available Options: area-id -- Single integer or IP address style dotted decimal. (OSPF-AREA-ID) (p. 222) ■ backbone -- The backbone area (the same as 0.0.0.0).(p. 226) ■ ■ interface loopback < 0 to 7 > ip ospf all area Specify an OSPF area.
Page 225
Command Line Interface Reference Guide interface Single integer or IP address style dotted decimal. ■ interface vlan VLAN-ID ip ospf all area OSPF-AREA-ID Single integer or IP address style dotted decimal. arp-protect ■ interface [ETHERNET] PORT-LIST arp-protect Usage: [no] arp-protect trust Description: Configure the port as trusted or untrusted.
Page 226
Command Line Interface Reference Guide interface OSPF authentication key (maximum 8 characters). ■ interface vlan VLAN-ID ip ospf all authentication-key Set simple authentication method and key. Next Available Option: authentication-key -- OSPF authentication key (maximum 8 characters). (OCTET-STR) (p. 223) ■...
Page 227
Command Line Interface Reference Guide interface ■ none -- Do not use authentication. ■ text -- Use simple password. auth-key-text ■ interface vlan VLAN-ID ip rip authentication-key OCTET-STR Set RIP authentication key (maximum 16 characters). ■ interface vlan VLAN-ID ip rip IP-ADDR authentication-key OCTET-STR Set RIP authentication key (maximum 16 characters).
Page 228
Command Line Interface Reference Guide interface Automatic address configuration. ■ [no] interface svlan VLAN-ID ipv6 address autoconfig Automatic address configuration. backbone ■ interface loopback < 0 to 7 > ip ospf IP-ADDR area backbone The backbone area (the same as 0.0.0.0). ■...
Page 229
Command Line Interface Reference Guide interface priority. If no guaranteed minimum bandwidth is configured (i.e., the settings for all queues are 0), the traffic is serviced strictly by priority. In practice, this may cause complete starvation of some or all lower-priority queues during any periods where the output port traffic is over-subscribed.
Page 230
Command Line Interface Reference Guide interface bootp-gateway ■ [no] interface vlan VLAN-ID ip bootp-gateway Usage: [no] ip bootp-gateway [IP-ADDR] Description: Add or remove the gateway address to be used for stamping incoming DHCP requests. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 231
Command Line Interface Reference Guide interface may have improved performance after rebooting the switch Next Available Option: unblock -- Resets a host previously blocked by the connection rate filter (p. 281) ■ ■ interface svlan VLAN-ID connection-rate-filter Usage: connection-rate-filter unblock < host SRC-IP-ADDR | SRC-IP-ADDRESS/mask >...
Page 232
Command Line Interface Reference Guide interface Set dead interval in seconds; the default is 40. Range: < 1 to 65535 > ■ interface vlan VLAN-ID ip ospf IP-ADDR dead-interval < 1 to 65535 > Set dead interval in seconds; the default is 40. Range: <...
Page 233
Command Line Interface Reference Guide interface direction ■ [no] interface [ETHERNET] PORT-LIST ip access-group ACCESS-GROUP < in > Supported Values: ■ in -- Match inbound packets ■ [no] interface vlan VLAN-ID ip access-group ACCESS-GROUP < in | out | connection-rate-filter | ...
Page 234
Command Line Interface Reference Guide interface Next Available Options: integer-range < 0 to 63 > -- Specify the DSCP code-point in decimal. (p. 239) ■ binary-range < 0 to 63 > -- Specify the DSCP code-point in binary. (BINARY) (p. 227) ■...
Page 235
Command Line Interface Reference Guide interface An IPv6 EUI-64 address that can be automatically configured on any interface ■ [no] interface svlan VLAN-ID ipv6 address IPV6-ADDR/PREFIX-LEN eui-64 An IPv6 EUI-64 address that can be automatically configured on any interface failback ■...
Page 236
Command Line Interface Reference Guide interface flow control is disabled. Flow Control is enabled on both transmit and receive or auto negotiated if port Mode is set to Auto. This is an Interface context command. It can be called directly from the interface context or follow the 'interface [ethernet] PORT-LIST' command.
Page 237
Command Line Interface Reference Guide interface Usage: vlan < vid > ipv6 mld forward < port-list > Description: Instruct the device to forward incoming multicast packets received on the specified ports. This feature is configured on a per-VLAN basis. forward-protocol ■...
Page 238
Command Line Interface Reference Guide interface The timers must follow the constraints 2 * join-timer <= leave-timer < leaveall-timer Next Available Options: join-timer < 20 to 75 > -- Set join timer value (centiseconds; default 20).(p. 246) ■ leave-timer < 40 to 300 > -- Set leave timer value (centiseconds; default 300).(p.
Page 239
Command Line Interface Reference Guide interface Range: < 5 to 300 > helper-address ■ [no] interface vlan VLAN-ID ip helper-address IP-ADDR Usage: [no] ip helper-address IP-ADDR Description: Add or remove a DHCP server IP address for the VLAN. The DHCP requests received by the switch on this VLAN are to be relayed to the specified DHCP server.
Page 240
Command Line Interface Reference Guide interface igmp ■ [no] interface vlan VLAN-ID ip igmp Usage: [no] ip igmp [...] Description: Enable/disable/configure IP Multicast Group Protocol (IGMP) feature on a VLAN. This command enables, disables or configures the IGMP feature for IGMP communication between Multicast Routers, Multicast Servers, and Multicast Clients connected to the device.
Page 241
Command Line Interface Reference Guide interface Set limits for all inbound traffic. Next Available Options: percent < 0 to 100 > -- Specify limit as percent of inbound or outbound traffic.(p. 258) ■ kbps < 0 to 10000000 > -- Specify limit of allowed inbound or outbound traffic in ■...
Page 242
Command Line Interface Reference Guide interface Usage: [no] vrrp vrid <VRID> track interface <LPORT-LIST> Description: Enable/disable tracking of logical ports for VR. Next Available Option: lport-list -- Enable/disable tracking of specified logical ports for VR ([ethernet] PORT-LIST) ■ 249) interval ■...
Page 243
Command Line Interface Reference Guide interface ■ interface vlan VLAN-ID ip Usage: [no] ip ... Description: Configure various IP parameters for the VLAN. The 'ip' command must be followed by a feature-specific keyword. Use 'ip ?' to get a list of all possible options. This is a VLAN context command.
Page 244
Command Line Interface Reference Guide interface Specify the IP address the request is for. Next Available Options: area -- Specify an OSPF area.(p. 221) ■ cost < 1 to 65535 > -- Set metric of this interface.(p. 229) ■ ■ [no] interface vlan VLAN-ID ip address IP-ADDR/mask-LENGTH Interface IP address/mask.
Page 245
Command Line Interface Reference Guide interface ■ interface vlan VLAN-ID ip pim-dense ip-addr Usage: ip pim-dense [ip-addr IP-ADDR|any] Description: Set the source IP address for the PIM-DM packets sent out on this interface. You can either explicitly specify one of the existing VLAN's IP addresses or use 'any' option to dynamically determine it from the VLAN's current IP configuration.
Page 246
Command Line Interface Reference Guide interface To associate L3-Mac-Address with a VLAN with default timeout interval of 60s. ip-recv-mac-address <mac-address> To disassociate L3-Mac_address with a VLAN. no ip-recv-mac-address Parameters: <mac-address> The L3-mac-address to be associated with a VLAN. interval Specify L3-Mac-Address timeout interval. <1-255>...
Page 247
Command Line Interface Reference Guide interface Usage: [no] ipv6 ... Description: Configure various IP parameters for the VLAN. The 'ipv6' command must be followed by a feature-specific keyword. Use 'ipv6 ?' to get a list of all possible options. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 248
Command Line Interface Reference Guide interface irdp ■ [no] interface vlan VLAN-ID ip irdp Usage: [no] ip irdp [...] Description: Configure ICMP Router Discovery Protocol (IRDP). This is a VLAN context command. It can be called directly from the VLAN context or may follow the 'vlan VLAN-ID' command prefix.
Page 249
Command Line Interface Reference Guide interface Specify kilobits-per-second limit of allowed ICMP traffic (values should be at least 13Kbps, or max-length ICMP packets will fail.) Range: < 0 to 10000000 > ■ interface [ETHERNET] PORT-LIST rate-limit all in kbps < 0 to 10000000 > Specify limit of allowed inbound or outbound traffic in kilobits-per-second on the specified port(s).
Page 250
Command Line Interface Reference Guide interface leaveall-timer ■ interface [ETHERNET] PORT-LIST gvrp leaveall-timer < 500 to 3000 > Set leaveall timer value (centiseconds; default 1000). Range: < 500 to 3000 > leave-timer ■ interface [ETHERNET] PORT-LIST gvrp leave-timer < 40 to 300 > Set leave timer value (centiseconds;...
Page 251
Command Line Interface Reference Guide interface Next Available Option: -- Configure various IP parameters for the Loopback(p. 240) ■ lowest ■ interface vlan VLAN-ID vrrp vrid < 1 to 255 > primary-ip-address lowest Dynamically determine lowest IP address. lport-list ■ [no] interface vlan VLAN-ID vrrp vrid < 1 to 255 > track interface [ETHERNET] PORT-LIST Usage: [no] vrrp vrid <VRID>...
Page 252
Command Line Interface Reference Guide interface md5-auth-key-chain ■ interface vlan VLAN-ID ip ospf md5-auth-key-chain Set MD5 authentication method and key chain. Next Available Option: chain-name -- Specify key chain to use for MD5 authentication. (ASCII-STR) (p. 228) ■ ■ interface vlan VLAN-ID ip ospf IP-ADDR md5-auth-key-chain Set MD5 authentication method and key chain.
Page 253
Command Line Interface Reference Guide interface Description: Set the minimum time (in seconds) allowed between sending unsolicited router advertisements. Must be no greater than the maximum time between sending unsolicited router advertisements. Range: < 3 to 1800 > mirror ■ interface [ETHERNET] PORT-LIST monitor all < In | Out | Both > mirror Mirror destination.
Page 254
Command Line Interface Reference Guide interface If not preceded by 'no', the command accepts a variety of configuration parameters. To get a list of all available parameters use 'ipv6 mld ?'. To get detailed help for a parameter follow it with 'help' keyword.
Page 255
Command Line Interface Reference Guide interface some frames may not be copied to the mirroring port. This is an Interface context command. It can be called directly from the interface context or follow the 'interface [ethernet] PORT-LIST' command. Parameters: o 1-4 - Mirror destination number o NAME-STR - Friendly name associated with the mirror destination number.
Page 256
Command Line Interface Reference Guide interface destination number. o ACL-NAME - Standard or Extended Access Control List number. o <in|out|both> direction of the traffic to be monitored. Next Available Option: < In | Out | Both > -- Monitor all traffic.(p.
Page 257
Command Line Interface Reference Guide interface Next Available Option: port-name -- Specify a port name up to 64 characters length. (ASCII-STR) (p. 263) ■ ■ interface vlan VLAN-ID name NAME Usage: name ASCII-STR Description: Set the VLAN's name. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 258
Command Line Interface Reference Guide interface Indicates that the router should never be used as a default by its neighbors. no-tag-added ■ [no] interface [ETHERNET] PORT-LIST monitor all < In | Out | Both > mirror < 1 to 4 > no-tag-added Don't add VLAN tag for this untagged-port ns-interval...
Page 259
Command Line Interface Reference Guide interface Usage: [no] ip ospf [...] Description: configure Open Shortest Path First (OSPF) protocol parameters on the interface. Called without 'no', the command configures OSPF parameter on interface. Otherwise ('no' is specified), the command remove specified ospf parameter on the interface.
Page 260
Command Line Interface Reference Guide interface output ■ [no] interface [ETHERNET] PORT-LIST bandwidth-min output Enable/disable and configure guaranteed minimum bandwidth for outgoing traffic. Next Available Option: queue1 < 0 to 100 > -- Specify min. bandwidth percentage for queue one outgoing traffic.(p.
Page 261
Command Line Interface Reference Guide interface Range: < 0 to 100 > ■ interface [ETHERNET] PORT-LIST rate-limit all in percent < 0 to 100 > Specify limit as percent of inbound or outbound traffic. Range: < 0 to 100 > ■...
Page 262
Command Line Interface Reference Guide interface PIM-SM on the interface. Use 'ip pim-sparse ?' to get the list of all configuration options. This command can be used in the VLAN context or in the global context with the 'vlan <VLAN-ID>' prefix.
Page 263
Command Line Interface Reference Guide interface ■ 8 ■ 9 ■ 10 ■ 11 ■ 12 ■ 13 ■ 14 ■ 15 ■ 16 ■ 17 poe-allocate-by ■ interface [ETHERNET] PORT-LIST poe-allocate-by Usage: poe-allocate-by [usage|class|value] Description: Control manual power over ethernet allocation. By default, power-over-ethernet allocation is automatic by usage of the powered device.
Page 264
Command Line Interface Reference Guide interface poison-reverse ■ [no] interface vlan VLAN-ID ip rip poison-reverse Enable/disable poison reverse on this interface. ■ [no] interface vlan VLAN-ID ip rip IP-ADDR poison-reverse Enable/disable poison reverse on this interface. ■ [no] interface vlan VLAN-ID ip rip all poison-reverse Enable/disable poison reverse on this interface.
Page 265
Command Line Interface Reference Guide interface bandwidth-min -- Enable/disable and configure guaranteed minimum bandwidth settings for ■ outgoing traffic on the port(s)(p. 226) rate-limit -- Enable/disable and configure rate-limiting for all traffic (or for incoming ICMP ■ traffic) on the port(s)(p.
Page 266
Command Line Interface Reference Guide interface the event of power over-subscription. Per-port power is enabled by default. The default priority is low. Note: Lower numbered ports have precedence over higher numbered ports of the same priority. Next Available Option: priority <...
Page 267
Command Line Interface Reference Guide interface '0.0.0.0') the virtual router uses numerically lowest IP address of the VLAN. The default value is 'lowest'. Next Available Options: ip-addr -- Specify IP address. (IP-ADDR) (p. 241) ■ lowest -- Dynamically determine lowest IP address.(p.
Page 269
Command Line Interface Reference Guide interface protocol-group -- Enter a list of protocols for the current VLAN delimited by commas. ■ (ASCII-STR) (p. 267) ■ interface svlan VLAN-ID protocol Set a predefined protocol for the current VLAN. Next Available Options: protocols <...
Page 270
Command Line Interface Reference Guide interface proxy-arp ■ [no] interface vlan VLAN-ID ip proxy-arp Usage: [no] ip proxy-arp Description: Enable/disable proxy ARP. This is a VLAN context command. It can be called directly from the VLAN context or may follow the 'vlan VLAN-ID' command prefix.
Page 271
Command Line Interface Reference Guide interface This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command. Next Available Options: dscp -- Specify DSCP policy to use. (p. 231) ■ priority <...
Page 272
Command Line Interface Reference Guide interface queue1 ■ interface [ETHERNET] PORT-LIST bandwidth-min output < 0 to 100 > Specify min. bandwidth percentage for queue one outgoing traffic. Range: < 0 to 100 > Next Available Option: queue2 < 0 to 100 > -- Specify min. bandwidth percentage for queue two outgoing traffic.(p.
Page 273
Command Line Interface Reference Guide interface Range: < 0 to 100 > Next Available Option: queue6 < 0 to 100 > -- Specify min. bandwidth percentage for queue six outgoing traffic.(p. 271) ■ queue6 ■ interface [ETHERNET] PORT-LIST bandwidth-min output < 0 to 100 > < 0 to 100 > < 0 to 100 > <...
Page 274
Command Line Interface Reference Guide interface rate-limit ip access-group <acl-name> in kbps <0-10000000> no rate-limit <icmp | all <in|out> | ip <access-group>> rate-limit bcast in percent <0-100> no rate-limit bcast in rate-limit mcast in percent <0-100> no rate-limit mcast in Description: Enable/disable and configure rate-limiting for all traffic (or for incoming ICMP traffic) on the port(s).
Page 275
Command Line Interface Reference Guide interface reachable-time ■ [no] interface vlan VLAN-ID ipv6 nd reachable-time Usage: [no] ipv6 nd reachable-time <milliseconds> Description: Configures the length of time neighbors are considered reachable after being confirmed as reachable via the neighbor unreachability detection algorithm. This value appears in router advertisements sent on this interface and is also used to manage the neighbor table entries on this node.
Page 276
Command Line Interface Reference Guide interface ■ interface vlan VLAN-ID ip ospf all retransmit-interval < 1 to 3600 > Set retransmit interval in seconds; the default is 5. Range: < 1 to 3600 > ■ [no] interface vlan VLAN-ID ip rip Usage: [no] ip rip [...] Description: Enable/disable/configure Routing Internet Protocol (RIP) on the VLAN interface.
Page 277
Command Line Interface Reference Guide interface Supported Values: ■ V1-only -- Use RIP version 1 only. ■ V2-only -- Use RIP version 2 only. ■ V1-or-V2 -- Use RIP 2 in the RIP 1 compatible mode. send ■ interface vlan VLAN-ID ip rip send < disabled | V1-only | V1-compatible-V2 | ... > Define RIP version for outgoing packets.
Page 278
Command Line Interface Reference Guide interface o <name> - Policy name. o in - Apply the policy in inbound direction. Next Available Option: -- Apply policy on inbound packets. (p. 238) ■ source-lockdown ■ [no] interface [ETHERNET] PORT-LIST ip source-lockdown Usage: [no] ip source-lockdown [ethernet] <port-list>...
Page 279
Command Line Interface Reference Guide interface network speed (100 or 1000 Mbps)and the port wiring operation (MDI-X or MDI) between the switch and another IEEE 802.3ab-compliant device running the 'Auto Negotiation' protocol. - 100-full 100 Mbps, full duplex. - auto-100 Same as 'auto'.
Page 280
Command Line Interface Reference Guide interface Next Available Options: dhcp-snooping (p. 230) ■ -- Configure various IP parameters for the VLAN(p. 240) ■ ipv6 -- Configure various IP parameters for the VLAN(p. 244) ■ auto -- Cause each port identified in the port list to learn its VLAN membership using the GARP ■...
Page 281
Command Line Interface Reference Guide interface Next Available Options: interface -- Enable/disable tracking of logical ports for VR(p. 239) ■ vlan -- Enable/disable tracking of VLANs for VR(p. 282) ■ transit-delay ■ interface vlan VLAN-ID ip ospf transit-delay < 1 to 3600 > Set transit delay in seconds;...
Page 283
Command Line Interface Reference Guide interface Usage: [no] ip forward-protocol udp IP-ADDR PORT-NUM|PORT-NAME Description: Add or remove a UDP server address for the VLAN. The broadcast packets received by the switch on this VLAN are to be forwarded to the specified application server. This is a VLAN context command.
Page 284
Command Line Interface Reference Guide interface untagged ■ [no] interface vlan VLAN-ID untagged [ETHERNET] PORT-LIST Usage: [no] untagged [ethernet] PORT-LIST Description: Assign ports to current VLAN as untagged. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 285
Command Line Interface Reference Guide interface ipv6 -- Configure various IP parameters for the VLAN(p. 244) ■ connection-rate-filter -- Re-enables access to a host or set of hosts that has been previously ■ blocked by the connection rate filter(p. 228) monitor -- Define either the VLAN is to be monitored or not(p.
Page 286
Command Line Interface Reference Guide interface Usage: [no] voice Description: Labels this VLAN as a Voice VLAN, allowing you to separate, prioritize, and authenticate voice traffic moving through your network. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 287
Command Line Interface Reference Guide interface well-defined ■ interface [ETHERNET] PORT-LIST qos dscp < af11 | af12 | af13 | ... > Usage: [no] qos dscp-map <0|1...63|af11|af12|af13|af21|af22|af23|af31|af32| af33|af41|af42|af43|ef|cs0..cs7|000000|000001...111111>| [priority <<0-7>|no-override>] [name <str>] Description: Define mapping between a DSCP (Differentiated-Services Codepoint) value and an 802.1p priority. The mapping is used to assign priority for IPv4 packets if a QoS classifier uses this DSCP policy as the method of traffic prioritization.
Page 290
Command Line Interface Reference Guide interface 'no qos dscp-map <codepoint>' will remove the settings for the specified codepoint from the running configuration. priority is set to no-override and the name is deleted (the priority and name can only be removed if no QoS feature is configured to use this DSCP Policy).
OVERVIEW Category: Primary context: config Related Commands ipv6 (page 313) show ip (page 561) Usage: [no] ip ... Description: Configure various IP parameters for the switch. The 'ip' command must be followed by a feature-specific keyword. Use 'ip ?' to get a list of all possible options. COMMAND STRUCTURE ■...
Page 293
Command Line Interface Reference Guide server-address -- Configure DNS server IP address. (p. 308) ■ priority < 1 to 2 > -- Priority of Server Address. (NUMBER) (p. 305) ■ ip6addr -- DNS server IPv6 address. (IPV6-ADDR) (p. 302) ■ ipaddr -- DNS server IP address.
Command Line Interface Reference Guide ■ [no] ip source-binding -- Add/remove a static IP-to-MAC binding in the DHCP snooping database (p. 308) trap -- Set traps for dynamic ip lockdown (p. 311) ■ OutOfResources -- Set out-of-resources trap. (p. 305) ■...
Page 296
Command Line Interface Reference Guide access-method ■ [no] ip authorized-managers IP-ADDR access-method < all | ssh | telnet | ... > Define an access method desired. Supported Values: ■ all ■ ssh ■ telnet ■ web ■ snmp ■ tftp address ■...
Page 297
Command Line Interface Reference Guide infinite - sets the timeout to 0. A value of 0 indicates an infinite timeout to the switch. (Internally the ARP age timeout is set to 99,999,999 seconds (approximately 3.2 years) Next Available Options: timeout <...
Page 298
Command Line Interface Reference Guide auto ■ ip igmp auto [ETHERNET] PORT-LIST Usage: ip igmp auto [ethernet] PORT-LIST Description: Instruct the device to monitor incoming multicast traffic on the specified ports (this is the default behavior). This feature is configured on a per-VLAN basis. blackhole ■...
Page 299
Command Line Interface Reference Guide ■ 3des-cbc ■ aes192-cbc ■ aes256-cbc ■ rijndael-cbc@lysator.liu.se ■ aes128-ctr ■ aes192-ctr ■ aes256-ctr connection-rate-filter ■ [no] ip access-list connection-rate-filter Configure a connection-rate-filter Access Control List. Next Available Option: name -- Specify name of Access Control List to configure. (ASCII-STR) (p.
Page 300
Command Line Interface Reference Guide directed-broadcast ■ [no] ip directed-broadcast Usage: [no] ip directed-broadcast Description: Enable/disable directed broadcast forwarding. distance ■ ip route IP-ADDR/MASK-LENGTH IP-ADDR distance < 1 to 255 > Set the administrative distance to associate with this static route. Range: <...
Page 301
Command Line Interface Reference Guide Next Available Option: domain-name -- Default domain suffix. (ASCII-STR) (p. 298) ■ ■ ip dns domain-name DOMAIN-NAME Default domain suffix. echo ■ [no] ip icmp echo Usage: [no] ip icmp echo ... Description: Enable/disable echo replies to broadcast echo requests. Next Available Option: broadcast-request <...
Page 302
Command Line Interface Reference Guide Usage: [no] ip igmp forcedfastleave [ethernet] PORT-LIST Description: When enabled, this feature forces IGMP Fast Leaves to occur even when the port is cascaded. See 'ip igmp fastleave' for more information. The default behavior is for IGMP Forced FastLeaves to be disabled.
Page 303
Command Line Interface Reference Guide available parameters use 'ip igmp ?'. To get a detailed help for a parameter, follow it with 'help' keyword. Next Available Options: querier -- Specify querier/non-querier capability for the VLAN(p. 306) ■ high-priority-forward -- Enable/disable the high priority forwarding of traffic for subscribed IP ■...
Page 304
Command Line Interface Reference Guide Specify how often (in minutes) the switch tries to get the current time. Range: < 1 to 9999 > ■ ip source-binding VLAN-ID IP-ADDR Next Available Option: -- (MAC-ADDR) (p. 304) ■ ip6addr ■ [no] ip dns server-address priority < 1 to 2 > IPV6-ADDR DNS server IPv6 address.
Page 305
Command Line Interface Reference Guide IP-PORT ■ ip ssh port TCP/UDP-PORT Specify the TCP port number on which the daemon should listen. IPV4-ADDR ■ ip authorized-managers IP-ADDR Authorized manager IPv4 address. Next Available Options: IPV4-MASK -- IP mask defining a group of adjacent manager IP addresses. (IP-ADDR) (p.
Page 306
Command Line Interface Reference Guide Usage: ip load-sharing <2-4> no ip load-sharing Description: Specify the maximum number of equal cost IP load sharing paths. no ip load-sharing disables IP load sharing. Range: < 2 to 4 > ■ [no] ip ssh mac < hmac-md5 | hmac-sha1 | hmac-sha1-96 | ... > Specify a mac to enable/disable.
Page 307
Command Line Interface Reference Guide Next Available Option: start-seq-num < 1 to 2147483647 > -- Specify the starting sequence number. (p. 310) ■ ■ [no] ip access-list connection-rate-filter NAME Specify name of Access Control List to configure. number ■ [no] ip access-list extended < 100 to 199 > Specify Access Control List to configure by number.
Page 308
Command Line Interface Reference Guide public-key ■ ip ssh public-key < manager | operator > Configure a client public-key. Supported Values: ■ manager -- Select manager public keys. ■ operator -- Select operator public keys. Next Available Option: keystring -- ASCII formatted public-key. (ASCII-STR) (p.
Page 309
Command Line Interface Reference Guide Usage: ip icmp reply-limit Description: Enable/disable ICMP reply rate limiting. resequence ■ ip access-list resequence Renumber the entries in an Access Control List. Next Available Option: name -- Specify name of Access Control List to configure. (ASCII-STR) (p.
Page 310
Command Line Interface Reference Guide Description: Define the device router id. The no form of the command clears the router-id. Next Available Option: ipaddr -- Define the device router id (IP-ADDR) (p. 302) ■ routing ■ [no] ip routing Usage: [no] ip routing Description: Enable/disable IP routing support on the device.
Page 311
Command Line Interface Reference Guide o <VLAN-ID> -- VLAN ID number to bind with the specified IP and MAC address on the specified port in the DHCP snooping binding database. o <MAC-ADDR> -- MAC address to bind with the specified IP address and VLAN on the specified port.
Page 312
Command Line Interface Reference Guide function unless SSH is also enabled. o 'port <<1-65535>|default>' - Set the TCP port on which the daemon should listen for SSH connections. The default is 22. o 'public-key <operator|manager> KEYSTRING' - set a key for public-key authentication.
Page 313
Command Line Interface Reference Guide timeout ■ ip arp-age < 1 to 1440 > Usage: [no] ip arp-age <[0..1440]|infinite> Description: Modify Address Resolution Protocol (ARP) table entry timeout, specified in minutes. The default timeout is 20 minutes. <0..1440> - timeout specified in minutes. infinite - sets the timeout to 0.
Page 314
Command Line Interface Reference Guide Usage: [no] ip source-binding trap OutOfResources Description: Set traps for dynamic ip lockdown. Next Available Option: OutOfResources -- Set out-of-resources trap. (p. 305) ■ ■ ip ttl < 2 to 255 > Usage: ip ttl <2-255> Description: Specify TTL for outgoing IP packets.
ipv6 OVERVIEW Category: Primary context: config Related Commands show ipv6 (page 562) ip (page 290) Usage: [no] ipv6 ... Description: Configure various IP parameters for the VLAN. The 'ipv6' command must be followed by a feature-specific keyword. Use 'ipv6 ?' to get a list of all possible options. This is a VLAN context command.
Page 316
Command Line Interface Reference Guide ipv6 access ■ ipv6 authorized-managers IPV6-ADDR access < Manager | Operator > Define an access level desired. Supported Values: ■ Manager ■ Operator access-list ■ [no] ipv6 access-list Usage: [no] ipv6 access-list <ACL-ID> <resequence> <ACL-ID> <start-seq-no> <increment> Description: Enter the ipv6 acl context for the specified access control list.
Page 317
Command Line Interface Reference Guide ipv6 [access-method <all|ssh|telnet|web|snmp|tftp>] Description: Define the IPV6 addresses allowed to manage the switch. Clients using the specified IPV6 addresses are allowed to access the switch with the specified access method and access level. A maximum of 100 addresses may be configured. Parameters: o IPV6-ADDR - The IPV6 address of an authorized manager.
Page 318
Command Line Interface Reference Guide ipv6 This command is executed at the global config level. It configures the number of neighbor solicitations to send when performing duplicate address detection for a unicast address configured on a VLAN interface. Range: 0-600 (0 = disabled) Default: 3 (enabled) Next Available Option: number...
Page 319
Command Line Interface Reference Guide ipv6 ■ ipv6 icmp error-interval < 0 to 2147483647 > bucket-size < 1 to 200 > Specify bucket size. Range: < 1 to 200 > IPV6-ADDR ■ ipv6 authorized-managers IPV6-ADDR Authorized manager IPv6 address. Next Available Options: IPV6-MASK -- IP mask defining a group of adjacent manager IP addresses.
Page 320
Command Line Interface Reference Guide ipv6 Next Available Option: start-seq-num < 1 to 2147483647 > -- Specify the starting sequence number. (p. 318) ■ start-seq-num ■ ipv6 access-list resequence RESEQUENCE < 1 to 2147483647 > Specify the starting sequence number. Range: <...
jumbo OVERVIEW Category: Primary context: config Related Commands the section called jumbos” (page 564) Usage: jumbo ... Description: Configure Global Jumbos parameters for the switch. NOTES Restriction on Value of max-frame-size The value of max-frame-size must be greater than or equal to 18 bytes more than the value selected for ip-mtu.
Command Line Interface Reference Guide key-chain time -- Key send stop time. (HH:MM[:SS]) (p. 338) ■ duration -- Use current day and time. (NUMBER) (p. 329) ■ infinite -- Set infinite lifetime. (p. 332) ■ -- Use current day and time. (p.
Page 326
Command Line Interface Reference Guide key-chain Key send start date. Next Available Option: time -- Key send start time. (HH:MM[:SS]) (p. 338) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime [DATE] [TIME] [DATE] [TIME] send-lifetime [DATE] [TIME] [DATE] Key send stop date.
Page 327
Command Line Interface Reference Guide key-chain ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime now [DATE] [TIME] send-lifetime [DATE] Key send start date. Next Available Option: time -- Key send start time. (HH:MM[:SS]) (p. 338) ■ ■...
Page 328
Command Line Interface Reference Guide key-chain Key send start date. Next Available Option: time -- Key send start time. (HH:MM[:SS]) (p. 338) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime infinite send-lifetime [DATE] [TIME] [DATE] Key send stop date.
Page 329
Command Line Interface Reference Guide key-chain Key accept stop date. Next Available Option: time -- Key send stop time. (HH:MM[:SS]) (p. 338) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime [DATE] [TIME] [DATE] [TIME] send-lifetime [DATE] Key send start date. Next Available Option: time -- Key send start time.
Page 330
Command Line Interface Reference Guide key-chain ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime now [DATE] Key accept stop date. Next Available Option: time -- Key send stop time. (HH:MM[:SS]) (p. 338) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime now [DATE] [TIME] send-lifetime [DATE] Key send start date.
Page 331
Command Line Interface Reference Guide key-chain Next Available Option: time -- Key send stop time. (HH:MM[:SS]) (p. 338) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime infinite send-lifetime [DATE] Key send start date. Next Available Option: time -- Key send start time.
Page 332
Command Line Interface Reference Guide key-chain Use current day and time. ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime [DATE] [TIME] [DATE] [TIME] send-lifetime now duration NUMBER Use current day and time. ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime [DATE] [TIME] duration NUMBER Use current day and time.
Page 333
Command Line Interface Reference Guide key-chain ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime infinite send-lifetime now duration NUMBER Use current day and time. ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING send-lifetime [DATE] [TIME] duration NUMBER Use current day and time.
Page 334
Command Line Interface Reference Guide key-chain ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime now duration NUMBER send-lifetime [DATE] [TIME] duration NUMBER Use current day and time. ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime now duration NUMBER send-lifetime now duration NUMBER Use current day and time.
Page 335
Command Line Interface Reference Guide key-chain ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING send-lifetime infinite Set infinite lifetime. ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime [DATE] [TIME] [DATE] [TIME] send-lifetime infinite Set infinite lifetime. ■...
Page 336
Command Line Interface Reference Guide key-chain Next Available Options: accept-lifetime -- Set key accept lifetime.(p. 323) ■ send-lifetime -- Set key send lifetime.(p. 336) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime [DATE] [TIME] [DATE] [TIME] send-lifetime now Use current day and time.
Page 337
Command Line Interface Reference Guide key-chain ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime infinite send-lifetime Use current day and time. Next Available Options: date -- Key send stop date. (MM/DD[/[YY]YY]) (p. 323) ■ duration -- Use current day and time. (NUMBER) (p.
Page 338
Command Line Interface Reference Guide key-chain ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime now duration NUMBER send-lifetime now Use current day and time. Next Available Options: date -- Key send stop date. (MM/DD[/[YY]YY]) (p. 323) ■ duration -- Use current day and time.
Page 339
Command Line Interface Reference Guide key-chain Next Available Options: date -- Key send start date. (MM/DD[/[YY]YY]) (p. 323) ■ -- Use current day and time.(p. 334) ■ infinite -- Set infinite lifetime.(p. 332) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime now duration NUMBER send-lifetime Set key send lifetime.
Page 340
Command Line Interface Reference Guide key-chain infinite -- Set infinite lifetime.(p. 332) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime now [DATE] [TIME] send-lifetime Set key send lifetime. Next Available Options: date -- Key send start date. (MM/DD[/[YY]YY]) (p.
Page 341
Command Line Interface Reference Guide key-chain Key send stop time. Next Available Option: send-lifetime -- Set key send lifetime.(p. 336) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime [DATE] [TIME] [DATE] [TIME] send-lifetime [DATE] [TIME] Key send start time.
Page 342
Command Line Interface Reference Guide key-chain Next Available Options: date -- Key send stop date. (MM/DD[/[YY]YY]) (p. 323) ■ duration -- Use current day and time. (NUMBER) (p. 329) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING accept-lifetime now [DATE] [TIME] send-lifetime [DATE] [TIME] [DATE] [TIME] Key send stop time.
Page 343
Command Line Interface Reference Guide key-chain Next Available Options: date -- Key send stop date. (MM/DD[/[YY]YY]) (p. 323) ■ duration -- Use current day and time. (NUMBER) (p. 329) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > key-string KEY-STRING send-lifetime [DATE] [TIME] [DATE] [TIME] Key send stop time.
Page 344
Command Line Interface Reference Guide key-chain duration -- Use current day and time. (NUMBER) (p. 329) ■ ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime [DATE] [TIME] duration NUMBER send-lifetime [DATE] [TIME] [DATE] [TIME] Key send stop time. ■...
Page 345
Command Line Interface Reference Guide key-chain Key send stop time. ■ key-chain KEY-CHAIN key < 0 to 255 > accept-lifetime infinite send-lifetime [DATE] [TIME] Key send start time. Next Available Options: date -- Key send stop date. (MM/DD[/[YY]YY]) (p. 323) ■...
kill OVERVIEW Category: Switch Management Primary context: manager Related Commands the section called ssh” (page 593) the section called telnet” (page 598) Usage: kill [SESSION_ID] Description: Kill other active console, telnet, or ssh sessions. If no session ID is specified, all other active sessions are terminated.
licenses OVERVIEW Category: Primary context: manager Related Commands show licenses (page 565) Usage: licenses <hardware-id PKG-ID | install PKG-ID PKG-KEY | uninstall PKG-ID> Description: Manage premium features. Parameters: o hardware-id - Display the hardware ID for installing the specified package on this chassis. o install - Install the specified package.
Command Line Interface Reference Guide licenses COMMAND DETAILS hardware-id (p. 347) Network-Services (p. 347) uninstall (p. 348) install (p. 347) premium (p. 347) key (p. 347) Premium (p. 348) hardware-id ■ licenses hardware-id Display hardware ID for installation request. Next Available Options: Premium -- For Premium features(p.
Page 350
Command Line Interface Reference Guide licenses For Premium features Next Available Option: -- Enter key for this feature. (ASCII-STR) (p. 347) ■ Premium ■ licenses hardware-id Premium For Premium features ■ licenses uninstall Premium For Premium features uninstall ■ licenses uninstall Uninstall the specified package.
link-keepalive OVERVIEW Category: Primary context: config Related Commands Usage: link-keepalive interval <10-100> link-keepalive retries <3-10> Description: Configure UDLD on your switch. The first version of the command is used to configure keep-alive interval in seconds. Here 10 is 1 sec, 11 is 1.1 sec, and so on.
Page 352
[timeout <1-256>] - Seconds within which a response is required before the test is considered as failed; the default value is 5. Examples: (1) hp-switch# link-test 0800095F3AD6 COMMAND STRUCTURE ■ link-test -- MAC address of device to which to send link test. (MAC-ADDR) (p.
Command Line Interface Reference Guide link-test COMMAND DETAILS mac (p. 351) timeout (p. 351) repetitions (p. 351) vlan (p. 351) ■ link-test MAC-ADDR MAC address of device to which to send link test. repetitions ■ link-test repetitions < 1 to 999 > Number of test packets to send <1-999>.
Page 354
lldp OVERVIEW Category: Device Discovery Primary context: config Related Commands show lldp (page 566) Usage:lldp ... Description: Configuration for LLDP parameter. Provides a standards-based method for enabling the switches to advertise themselves to adjacent devices and to learn about adjacent LLDP devices. You can also configure the Media Extension Discovery (MED) extension to LLDP for Voice over IP (VoIP) devices.
Command Line Interface Reference Guide lldp ■ [no] lldp enable-notification -- Set the port for which notification should be enabled ([ethernet] PORT-LIST) (p. 356) ■ lldp fast-start-count < 1 to 10 > -- Set MED fast-start count in seconds (NUMBER) (p.
Page 356
Command Line Interface Reference Guide lldp Description: Configure various parameters related to lldp automatic provisioning. Next Available Option: radio-ports -- Configure various parameters related to automatic provisioning for the radio-port ■ application(p. 358) auto-vlan ■ [no] lldp auto-provision radio-ports auto-vlan Create a VLAN, with the specified VLAN id value, to be used as the radio-ports controller auto-generated VLAN.
Page 357
Command Line Interface Reference Guide lldp Specify the ca-value string. civic-addr ■ [no] lldp config [ETHERNET] PORT-LIST medPortLocation civic-addr Usage: lldp config <port-list> medPortLocation civic-str <COUNTRY-STR> <WHAT> <CA-TYPE> <CA-VALUE> Description: Specify the civic location-id information to be advertised. The total length of the TLV is 104. COUNTRY-STR : Set the Country Code of two characters.e.g.
Page 358
Command Line Interface Reference Guide lldp Next Available Options: basicTlvEnable < port_descr | system_name | system_descr | ... > -- Specify the Basic TLV List ■ to be advertised. (NUMBER) (p. 354) ipAddrEnable -- Set IP ADDR to be enabled.(p. 357) ■...
Page 359
Command Line Interface Reference Guide lldp fast-start-count ■ lldp fast-start-count < 1 to 10 > Usage: lldp fast-start-count <1-10> Description: Set MED fast-start count in seconds. Range: < 1 to 10 > holdtime-multiplier ■ lldp holdtime-multiplier < 2 to 10 > Usage: lldp holdtime-multiplier <2-10>...
Page 360
Command Line Interface Reference Guide lldp Specify the MED TLV List to be advertised. Supported Values: ■ capabilities -- Capability TLV ■ network_policy -- Network Policy TLV ■ location_id -- Location Id TLV ■ poe -- Poe TLV omodes ■ lldp admin-status [ETHERNET] PORT-LIST < TxOnly | RxOnly | Tx_Rx | ... > Set the operational mode: transmit | receive | transmit-receive | disable.
Page 361
Command Line Interface Reference Guide lldp Usage:[no] lldp run Description: Start or Stop LLDP on device. top-change-notify ■ [no] lldp top-change-notify [ETHERNET] PORT-LIST Usage:[no] lldp top-change-notify <port-list> Description: Set the port for which LLDP MED topology notification should be enabled. vlan-base ■...
Page 362
Usage: lockout-mac <MAC-ADDR> Description: Lock out a MAC address. Parameter: o MAC-ADDR - MAC address to lock down. Examples: (1) hp-switch# lockout-mac 0800095F3AD6 COMMAND STRUCTURE EXAMPLES Example: lockout-mac Drop all traffic to or from MAC address 0800095F3AD6: ProCurve# lockout-mac 0800095F3AD6...
OVERVIEW Category: Switch Management Primary context: manager Related Commands logging (page 363) the section called logging” (page 567) Usage: log [-a|-r|-m|-p|-w|-i|-d|substring ...] Description: Display log events. -a - Instructs the switch to display all recorded log events, which includes events from previous boot cycles. -r - Instructs the switch to display recorded log events in reverse order (most recent first).
Page 364
Command Line Interface Reference Guide Supported Values: ■ -M -- Major event class. ■ -P -- Performance event class. ■ -W -- Warning event class. ■ -I -- Information event class. ■ -D -- Debug event class. option ■ log OPTION Specify substring to match in log entry.
Page 365
logging OVERVIEW Category: Switch Management Primary context: config Related Commands log (page 361) the section called logging” (page 567) Usage: [no] logging <IP-ADDR> [control-descr <text string>] [no] logging priority-descr <text-string> [no] logging facility <facility> [no] logging severity <severity> [no] logging system-module <module> Description: Add an IP address to the list of receiving syslog servers.
Page 368
Command Line Interface Reference Guide logging severity ■ [no] logging severity < major | error | warning | ... > Usage: [no] logging severity <severity> Description: Event messages of the specified severity or higher will be sent to the syslog server. 'no' sends all severities. Supported Values: ■...
Page 372
loop-protect OVERVIEW Category: Primary context: config Related Commands Usage: [no] loop-protect <...> [[ethernet] PORT-LIST [receiver-action <send-disable|no-disable>]| [transmit-interval <1-10>]| [disable-period <0-604800>]| [trap <loop-detected>] Description: Configure Loop protection on the switch. Parameters: o ethernet PORT-LIST - Port(s) to configure loop protection on. By default loop protection is disabled on a port o receiver-action - Sets the loop detected action per port.
Page 373
Command Line Interface Reference Guide loop-protect disable-timer ■ loop-protect disable-timer < 0 to 604800 > Set time in seconds to wait before attempting to reenable a port. Range: < 0 to 604800 > loop-detected ■ [no] loop-protect trap loop-detected generate trap when a loop is detected port-list ■...
Page 374
mac-age-time OVERVIEW Category: Device Discovery Primary context: config Related Commands Usage: mac-age-time <60-999960> Description: Set the MAC address table's age-out interval. A MAC address that is dynamically learned by the switch, stays in the switch's address table for a certain amount of time - the age-out interval, before being aged out.
Page 375
management-vlan OVERVIEW Category: config Primary context: config Related Commands the section called vlan” (page 603) Usage: [no] management-vlan VLAN-ID Description: Set the VLAN that is to be used as the management VLAN. COMMAND STRUCTURE EXAMPLES Example: management-vlan Set VLAN 100 as the management VLAN and add ports A1 and A2 to it: ProCurve(config)# management-vlan 100 ProCurve(config)# vlan 100 tagged a1 ProCurve(config)# vlan 100 tagged a2...
Page 376
max-vlans OVERVIEW Category: VLANs Primary context: config Related Commands Usage: max-vlans <1-2048> Description: Set the maximum number of VLANs on the switch. The default is 256. COMMAND STRUCTURE EXAMPLES Example: max-vlans NUMBER Reconfigure the switch to allow 10 VLANs: ProCurve(config)# max-vlans 10 Command will take effect after saving configuration and reboot.
Description: Change console user interface to menu system. COMMAND STRUCTURE EXAMPLES menu Enter the menu mode for switch configuration: ProCurve# menu HP ProCurve Switch 5400zl 1-Jan-2006 4:55:06 =======================- TELNET - MANAGER MODE -======================== Main Menu 1. Status and Counters... 2. Switch Configuration...
mesh OVERVIEW Category: Redundant Paths Primary context: config Related Commands the section called mesh” (page 569) Usage: [no] mesh [ethernet] PORT-LIST Description: Configure the specified ports as being members of a mesh group. A mesh group can have up to 24 member ports. - VLAN support must be enabled before configuring a mesh group.
Page 381
Command Line Interface Reference Guide mirror mirror_session_dest_ip ■ mirror < 1 to 4 > name NAME remote ip IP-ADDR < 1 to 65535 > IP-ADDR Remote mirroring UDP encapsulation destination ip addr. ■ mirror < 1 to 4 > remote ip IP-ADDR < 1 to 65535 > IP-ADDR Remote mirroring UDP encapsulation destination ip addr.
Page 382
Command Line Interface Reference Guide mirror ■ mirror < 1 to 4 > remote ip IP-ADDR < 1 to 65535 > Remote mirroring UDP encapsulation port. Range: < 1 to 65535 > Next Available Option: mirror_session_dest_ip -- Remote mirroring UDP encapsulation destination ip addr. (IP-ADDR) ■...
Page 383
mirror-port OVERVIEW Category: config Primary context: config Related Commands vlan (page 706) Usage: [no] mirror-port [[ethernet] PORT-NUM] Description: Define the mirror port for diagnostic purposes. The device ports or VLAN (if VLANs are enabled on the device) that will be monitored are defined through the 'monitor' command in either VLAN or interface context.
Page 385
module OVERVIEW Category: config Primary context: config Related Commands the section called modules” (page 570) Usage: module <MODULE-NUM> type <MODULE-TYPE> Description: Configure type of the module. COMMAND STRUCTURE ■ module < 1 to 12 > type < J8701A | J8702A | J8705A | ... > -- The type of the module. (p.
Page 387
monitor OVERVIEW Category: Primary context: config Related Commands show monitor (page 570) Usage: [no] monitor mac MAC-ADDR <src | dst | both> mirror <1-4 | NAME-STR> Description: Set up traffic monitoring for a given MAC address. Network traffic with this MAC address as the source or destination is copied to the mirror port.
Page 388
Command Line Interface Reference Guide monitor number or (if configured) a name. Depending on how many sessions are configured on the switch, you can use the same command to configure a MAC address as mirroring criteria in up to four sessions. To identify session, you can enter either its name or number;...
Page 390
password OVERVIEW Category: Switch Management Primary context: config Related Commands front-panel-security (page 190) show (page 511) Usage: [no] password <manager|operator|port-access|all> [user-name ASCII-STR] [<plaintext|sha1> ASCII-STR] Description: Set or clear local password/username for a given access level. Invoked without 'no', the command sets or changes existent password(s).
Page 391
Command Line Interface Reference Guide password Usage: [no] password <manager|operator|port-access|all> [user-name ASCII-STR] [<plaintext|sha1> ASCII-STR] Description: Set or clear local password/username for a given access level. Invoked without 'no', the command sets or changes existent password(s). If no password provided in the command, the user will be prompted to enter the new password twice.
Page 392
Command Line Interface Reference Guide password Set password ■ password < operator | manager > plaintext PASSWORD Set password ■ password < operator | manager > sha0 PASSWORD Set password ■ password < operator | manager > sha1 PASSWORD Set password plaintext ■...
Page 393
Command Line Interface Reference Guide password ■ password < operator | manager > sha1 Enter SHA-1 hash of password. Next Available Option: password -- Set password (ASCII-STR) (p. 389) ■ user-name ■ password < operator | manager > user-name USER-NAME Set username for the specified user category.
Page 394
A string upto 1024 characters in length can be specified. The default value is a 0 length string. o [source <IP_ADDR|VLAN-ID>] - The source IPv4 address or VLAN. Examples: (1) hp-switch# ping 1.1.1.1 COMMAND STRUCTURE ■ ping data-fill -- Ping data fill string (size <0-1024>).
Command Line Interface Reference Guide ping EXAMPLES Example: ping IP-ADDR Send an IP Ping request to the device that has IP address 10.10.10.1: ProCurve# ping 10.10.10.1 10.10.10.1 is alive, time = 50 ms COMMAND DETAILS data-fill (p. 393) ip-addr (p. 393) switch-num (p.
Page 396
Command Line Interface Reference Guide ping switch-num ■ ping NUMBER The stack number of the switch to ping. timeout ■ ping timeout < 1 to 60 > Ping timeout in seconds <1-60>. Range: < 1 to 60 > vlan ■ ping source VLAN-ID Source VLAN.
ping6 OVERVIEW Category: Primary context: operator Related Commands ping (page 392) traceroute6 (page 695) Usage: ping6 <IPV6-ADDR|hostname> [repetitions <1-10000>] [timeout <1-60>] [data-size <0-65471>] [data-fill <0-1024>] [source <IPV6-ADDR|VLAN-ID>] Description: Send IPv6 ping request(s) to a device on the network. Parameters: o IPV6-ADDR - IPv6 address of device to ping. o hostname - Hostname of device to which to send IPv6 ping.
Page 399
Command Line Interface Reference Guide ping6 Source address or VLAN. Next Available Options: vlan -- Source VLAN. (VLAN-ID) (p. 397) ■ ip-addr -- Source IPv6 address. (IPV6-ADDR) (p. 396) ■ timeout ■ ping6 timeout < 1 to 60 > Number of seconds within which a response is required from the destination host before the ping test times out.
policy OVERVIEW Category: Primary context: config Related Commands class (page 79) Usage: [no] policy <qos | pbr | mirror> <name> Description: Create a classifier policy and enter the policy context. Parameters are policy type and policy name. COMMAND STRUCTURE ■ [no] policy mirror -- Enter mirror type policy name (ASCII-STR) (p.
Page 401
Command Line Interface Reference Guide policy mirror ■ [no] policy mirror MIRROR Enter mirror type policy name name ■ policy resequence NAME Specify the policy name. Next Available Option: start-seq-num < 1 to 2147483646 > -- Specify the starting sequence number. (p.
port-security OVERVIEW Category: Port Security Primary context: config Related Commands show (page 511) show (page 511) Usage: [no] port-security [ethernet] PORT-LIST [learn-mode <continuous|static|configured| limited-continuous|port-access>] [address-limit <1-32>] [mac-address MAC-ADDR [MAC-ADDR ...]] [action <none|send-alarm|send-disable>] [clear-intrusion-flag] Description: Set the port-security operation(s) for each port in port list. Parameters: o learn-mode <continuous|static|configured|limited-continuous|port-access>...
Command Line Interface Reference Guide port-security o action <none|send-alarm|send-disable> - Indicates the port security action the switch will take if an intruder is detected on the port. o clear-intrusion-flag - clears intrusion indicator for the ports specified in the command PORT-LIST. COMMAND STRUCTURE ■...
Page 404
Command Line Interface Reference Guide port-security ■ port-access -- Learn port-access authorized MAC address only. ■ limited-continuous -- Limited continuous MAC address learn mode. mac-addr ■ port-security [ETHERNET] PORT-LIST mac-address MAC-ADDR Authorized MAC address. mac-address ■ [no] port-security [ETHERNET] PORT-LIST mac-address Configure the address(es) authorized on the port(s).
power-over-ethernet OVERVIEW Category: Primary context: config Related Commands show power-over-ethernet (page 581) Usage: power [slot <SLOT-LIST>] [threshold <1-99>][optional-parameters] Description: Set Power Over Ethernet(poe) configuration parameters. threshold - set the power consumption percentage at which a trap should be sent. optional-parameters - Use <TAB> or <?> after entering power to see a list of all available options.
Command Line Interface Reference Guide power-over-ethernet Example: power-over-ethernet threshold option Executing the following command sets the global notification threshold to 70% of available PoE power: ProCurve(config)# power-over-ethernet threshold 70 COMMAND DETAILS pre-std-detect (p. 404) redundancy_type (p. 404) threshold (p. 405) redundancy (p.
Page 407
Command Line Interface Reference Guide power-over-ethernet ■ full slot ■ power-over-ethernet slot SLOT-ID-RANGE Optional - Specify a valid powered-slot list for power threshold setting or omit to set all powered-slots. Next Available Option: threshold < 1 to 99 > -- Set the power consumption percentage at which a trap should be sent. ■...
primary-vlan OVERVIEW Category: config Primary context: config Related Commands the section called vlan” (page 603) Usage: primary-vlan VLAN-ID Description: Set the VLAN that is to be used as the primary VLAN. The primary VLAN comes into play for features such as stacking, DHCP, and TIMEP.
print OVERVIEW Category: Primary context: manager Related Commands Usage: print COMMAND-STR Description: Execute a command and redirect its output to the device channel for current session. COMMAND STRUCTURE ■ print command -- Command to execute. Use quotes for multiword commands. (ASCII-STR) 407) COMMAND DETAILS command (p.
qinq OVERVIEW Category: Primary context: config Related Commands svlan (page 661) vlan (page 706) show qinq (page 582) Usage: [no] qinq [ <mixedvlan|svlan> [tag-type<tpid>] ] Description: Configure the device qinq mode. The command 'no qinq' disables qinq on the device (no tag-stacking). Changing qinq mode from one to another requires reboot to take effect and the device will boot up with a default configuration for the new qinq mode.
Page 412
Command Line Interface Reference Guide qinq svlan ■ qinq svlan Configure as svlan mode. Globally enables QinQ svlan mode, an S-VLAN only environment that supports port-based or s-tagged interfaces of the standard. Requires a reboot to take effect. Next Available Option: tag-type <...
OVERVIEW Category: Primary context: config Related Commands show (page 511) Usage: [no] qos ... Description: Configure Quality of Service (QoS) on the device. The command must be followed by a keyword defining a subdomain of the QoS parameters to configure. COMMAND STRUCTURE ■...
Page 414
Command Line Interface Reference Guide well-defined < af11 | af12 | af13 | ... > -- Define mapping between a DSCP ■ (Differentiated-Services Codepoint) value and an 802 (p. 434) priority < 0 | 1 | 2 | ... > -- Specify priority to use. (p.
Page 415
Command Line Interface Reference Guide well-defined < af11 | af12 | af13 | ... > -- Define mapping between a DSCP ■ (Differentiated-Services Codepoint) value and an 802 (p. 434) priority < 0 | 1 | 2 | ... > -- Specify priority to use. (p.
Page 418
Command Line Interface Reference Guide priority of the outgoing packets is defined by the Differentiated Services Codepoint mapping (see 'show qos dscp-map'). Using 'no' removes any priority assignment for this TCP/UDP service. If MAX-TCP/UDP-PORT is specified then the priority is applied to all TCP/UDP ports in the range from TCP/UDP-PORT to MAX-TCP/UDP-PORT.
Page 419
Command Line Interface Reference Guide name -- Specify DSCP->priority mapping name. (p. 426) ■ ■ qos < udp-port | tcp-port > TCP/UDP-PORT dscp < 0 to 63 > Specify the DSCP code-point in binary. Range: < 0 to 63 > ■...
Page 420
Command Line Interface Reference Guide Usage: [no] qos device-priority <IP-ADDR[/mask-or-prefix-length] | IPV6_ADDR[/CIDR mask length]> [dscp <0|1...63|af11|af12|af13|af21|af22|af23|af31|af32| af33|af41|af42|af43|ef|cs0..cs7|000000|000001...111111>| priority <0-7>] Description: Configure device-based priority. The priority can be set for IP packets from/to a particular IP Address. The specified priority value will be placed in the 802.1p priority field of outgoing tagged packets.
Page 421
Command Line Interface Reference Guide ■ qos device-priority IP-ADDR/mask-LENGTH dscp Specify DSCP policy to use. Next Available Options: integer-range < 0 to 63 > -- Specify the DSCP code-point in decimal. (p. 423) ■ binary-range < 0 to 63 > -- Specify the DSCP code-point in binary. (BINARY) (p.
Page 422
Command Line Interface Reference Guide Supported Values: Binary formatted value from 000000 to 111111 Next Available Options: integer-range < 0 to 63 > -- Specify the DSCP code-point in decimal. (p. 423) ■ binary-range < 0 to 63 > -- Specify the DSCP code-point in binary. (BINARY) (p.
Page 423
Command Line Interface Reference Guide Next Available Options: integer-range < 0 to 63 > -- Specify the DSCP code-point in decimal. (p. 423) ■ binary-range < 0 to 63 > -- Specify the DSCP code-point in binary. (BINARY) (p. 416) ■...
Page 424
Command Line Interface Reference Guide this DSCP policy as the method of traffic prioritization. The mapping also provides the profile for inbound classification and priority assignment based on an IPv4 packet's received IP ToS byte ONLY IF the user has also configured 'qos type-of-service diff-services' 'no qos dscp-map <codepoint>' will remove the settings for the specified codepoint from the running configuration.
Page 425
Command Line Interface Reference Guide Next Available Option: dscp -- Define Differentiated Services Codepoint to which to map IP ToS.(p. 418) ■ integer-range ■ qos device-priority IP-ADDR dscp < 0 to 63 > Specify the DSCP code-point in decimal. Range: < 0 to 63 > ■...
Page 426
Command Line Interface Reference Guide Specify the DSCP code-point in decimal. Range: < 0 to 63 > ■ qos < udp-port | tcp-port > ip-all TCP/UDP-PORT dscp < 0 to 63 > Specify the DSCP code-point in decimal. Range: < 0 to 63 > ■...
Page 427
Command Line Interface Reference Guide 0 (Normal) 2 (Low) 1 (Lowest) ipv4 ■ qos < udp-port | tcp-port > ipv4 Specify range of TCP/UDP ports from [to] which to prioritize traffic. Next Available Options: port-num -- TCP/UDP port from [to] which to prioritize traffic. (TCP/UDP-PORT) (p.
Page 428
Command Line Interface Reference Guide Next Available Options: dscp < 000000 | 000001 | 000010 | ... > -- Specify DSCP policy to use. (p. 418) ■ priority < 0 | 1 | 2 | ... > -- Specify priority to use. (p.
Page 429
Command Line Interface Reference Guide port-num ■ qos < udp-port | tcp-port > TCP/UDP-PORT TCP/UDP port from [to] which to prioritize traffic. Next Available Options: dscp < 000000 | 000001 | 000010 | ... > -- Specify DSCP policy to use. (p.
Page 434
Command Line Interface Reference Guide placed in the appropriate outbound priority queue. '7' means highest priority. Using 'no' removes any priority assignment for the specified protocol. Supported Values: ■ IP ■ IPX ■ ARP ■ AppleTalk ■ SNA ■ NetBEUI Next Available Option: priority <...
Page 435
Command Line Interface Reference Guide Next Available Option: port-num -- TCP/UDP port from [to] which to prioritize traffic. (TCP/UDP-PORT) (p. 427) ■ Example 1. Example of Port Range ProCurve(config)# qos udp-port range 1001 2000 dscp 000010 type-of-service ■ [no] qos type-of-service Usage: [no] type-of-service <ip-precedence| diff-services [<0|1...63|af11|af12|af13|af21| af22|af23|af31|af32|af33|af41|...
Page 436
Command Line Interface Reference Guide 'no dscp-map <af11..ef|0-63|000000...111111>' function must be used. o diff-services <0|1...63|af11|af12|af13|af21|af22|af23|af31|af32|af33| af41|af42|af43|ef|cs0..cs7|000000|000001...111111> - The value of the upper bits in the ToS field. o dscp <0|1...63|af11|af12|af13|af21|af22|af23|af31|af32|af33|af42|af42| af43|ef|cs0..cs7|000000|000001...111111> - Re-maps a given inbound Differentiated Services codepoint to the specified DSCP Policy and codepoint on outbound.
Page 438
Command Line Interface Reference Guide The mapping also provides the profile for inbound classification and priority assignment based on an IPv4 packet's received IP ToS byte ONLY IF the user has also configured 'qos type-of-service diff-services' 'no qos dscp-map <codepoint>' will remove the settings for the specified codepoint from the running configuration.
Page 441
Command Line Interface Reference Guide and Expedited Forwarding. These are automatically configured as follows: DiffServ 802.1p Codepoint Value IETF Standard Designation --------------------------------------------------- 001010 Assured Forwarding AF11 001100 Assured Forwarding AF12 001110 Assured Forwarding AF13 010010 Assured Forwarding AF21 010100 Assured Forwarding AF22 010110 Assured Forwarding...
Page 442
Command Line Interface Reference Guide Description: Define mapping between a DSCP (Differentiated-Services Codepoint) value and an 802.1p priority. The mapping is used to assign priority for IPv4 packets if a QoS classifier uses this DSCP policy as the method of traffic prioritization. The mapping also provides the profile for inbound classification and priority assignment based on an IPv4 packet's received IP ToS byte ONLY IF the user has also configured...
Page 445
Command Line Interface Reference Guide specified codepoint from the running configuration. priority is set to no-override and the name is deleted (the priority and name can only be removed if no QoS feature is configured to use this DSCP Policy). 'no qos dscp-map <codepoint>...
Page 446
Command Line Interface Reference Guide ■ cs5 ■ cs6 ■ cs7 ■ qos < udp-port | tcp-port > ipv4 TCP/UDP-PORT dscp < af11 | af12 | af13 | ... > Usage: [no] qos dscp-map <0|1...63|af11|af12|af13|af21|af22|af23|af31|af32| af33|af41|af42|af43|ef|cs0..cs7|000000|000001...111111>| [priority <<0-7>|no-override>] [name <str>] Description: Define mapping between a DSCP (Differentiated-Services Codepoint) value and an 802.1p priority.
Page 449
Command Line Interface Reference Guide The mapping also provides the profile for inbound classification and priority assignment based on an IPv4 packet's received IP ToS byte ONLY IF the user has also configured 'qos type-of-service diff-services' 'no qos dscp-map <codepoint>' will remove the settings for the specified codepoint from the running configuration.
Page 452
Command Line Interface Reference Guide and Expedited Forwarding. These are automatically configured as follows: DiffServ 802.1p Codepoint Value IETF Standard Designation --------------------------------------------------- 001010 Assured Forwarding AF11 001100 Assured Forwarding AF12 001110 Assured Forwarding AF13 010010 Assured Forwarding AF21 010100 Assured Forwarding AF22 010110 Assured Forwarding...
Page 453
Command Line Interface Reference Guide Description: Define mapping between a DSCP (Differentiated-Services Codepoint) value and an 802.1p priority. The mapping is used to assign priority for IPv4 packets if a QoS classifier uses this DSCP policy as the method of traffic prioritization. The mapping also provides the profile for inbound classification and priority assignment based on an IPv4 packet's received IP ToS byte ONLY IF the user has also configured...
Page 454
Command Line Interface Reference Guide ■ af32 ■ af33 ■ af41 ■ af42 ■ af43 ■ ef ■ cs0 ■ cs1 ■ cs2 ■ cs3 ■ cs4 ■ cs5 ■ cs6 ■ cs7 ■ qos type-of-service diff-services < 0 to 63 > dscp < af11 | af12 | af13 | ... > Define Differentiated Services Codepoint to which to map IP ToS.
Page 456
Command Line Interface Reference Guide of each packet. Using 'no' type-of-service with just the mode (ip-precedence or diff-services) will disable all ToS QoS for the switch. Modes: -------------- Disabled The switch does NOT prioritize IP packets based on the IP ToS field.
Page 457
Command Line Interface Reference Guide ■ af33 ■ af41 ■ af42 ■ af43 ■ ef ■ cs0 ■ cs1 ■ cs2 ■ cs3 ■ cs4 ■ cs5 ■ cs6 ■ cs7 Next Available Option: dscp -- Define Differentiated Services Codepoint to which to map IP ToS.(p.
Command Line Interface Reference Guide radius-server encryption key to use for authentication with given server (default is NULL). Specifying this key overrides the key set for this server by the 'radius-server key <KEY-STR>' global configuration command. o key <KEY-STR> - specifies the global encryption key, which is used for authentication if encryption key for the server is not configured.
Command Line Interface Reference Guide radius-server acct-port -- Accounting UDP destination port number (default is 1813). (TCP/UDP-PORT) ■ (p. 458) auth-port -- Authentication UDP destination port number (default is 1812). ■ (TCP/UDP-PORT) (p. 459) time-window -- time window (in seconds) within which the received dynamic authorization ■...
Page 461
Command Line Interface Reference Guide radius-server auth-port ■ radius-server host IP-ADDR acct-port TCP/UDP-PORT auth-port TCP/UDP-PORT Authentication UDP destination port number (default is 1812). ■ radius-server host IP-ADDR auth-port Authentication UDP destination port number (default is 1812). Next Available Option: auth-port -- Authentication UDP destination port number (default is 1812).
Page 462
Command Line Interface Reference Guide radius-server dyn-autz-port ■ radius-server dyn-autz-port < 1024 to 49151 > UDP port number to listen for Change-of-Authorization and Disconnect messages (default is 3799). Range: < 1024 to 49151 > host ■ [no] radius-server host IP-ADDR IP address of the RADIUS server to use.
Page 463
Command Line Interface Reference Guide radius-server ■ radius-server key KEY Encryption key to use with the RADIUS server (default is NULL). retransmit ■ radius-server retransmit < 1 to 5 > Number of packet retransmits (default is 3). Range: < 1 to 5 > timeout ■...
redo OVERVIEW Category: Switch Management Primary context: manager Related Commands repeat (page 470) Usage: redo [NUMBER|COMMAND-STR] Description: Re-execute a command from history. By default, it executes the last command. If the 'number' is specified, it executes the n-th command starting from the most recent command in the history.
redundancy OVERVIEW Category: Primary context: config Related Commands Usage: redundancy switchover redundancy active-management < management-module1 | management-module2 | standby> [no]redundancy management-module redundancy fabric-module <<1|2> <enable|disable>> Description: Redundancy configuration for management and fabric modules. The first version of the command causes the switch to immediately switchover to the standby management module.
redundancy OVERVIEW Category: Primary context: manager Related Commands Usage: redundancy switchover redundancy active-management < management-module1 | management-module2 | standby> Description: Redundancy configuration for management modules. The first version of the command causes the switch to immediately switchover to the standby management module. The second version of the command makes the module specified an active management module for next boot.
reload OVERVIEW Category: Switch Management Primary context: manager Related Commands boot (page 73) Usage: [no] reload <after <[[DD:]HH:]MM> HH:MM[:SS] [MM/DD[/[YY]YY]>] > Description: Warm reboot of the switch. If no parameters are entered, an immediate reload is executed. [no] - Causes the removal of any pending reload request. Note: The maximum allowable time is 99 days.
Page 470
Command Line Interface Reference Guide reload ■ reload at Warm reboot at a specified time; If the mm/dd/yy is left blank, the current day is assumed. Next Available Option: time -- Time on given date to do a warm reboot. (HH:MM[:SS]) (p.
rename OVERVIEW Category: Switch Management Primary context: manager Related Commands show (page 511) erase (page 174) Usage: rename config OLDNAME NEWNAME Description: Change the name of the configuration OLDNAME to NEWNAME. No action occurs if there is no configuration named OLDNAME, or if a configuration named NEWNAME already exists.
repeat OVERVIEW Category: Switch Management Primary context: manager Related Commands redo (page 462) Usage: repeat [CMDLIST] [count NUMBER] [delay NUMBER] Description: Repeat execution of a previous command. By default, repeats the last command until a key is pressed. If the 'CMDLIST' is specified, repeats the n-th most recent command where n is the number.
router OVERVIEW Category: Routing Primary context: config Related Commands ip (page 290) vlan (page 706) show (page 511) Usage: [no] router ... Description: Configure the switch routing protocols. You can enter the commands from the global configuration context or the RIP, OSPF, PIM, or VRRP configuration contexts. For example, to enter an OSPF command from the global configuration context, use the "router"...
Page 474
Command Line Interface Reference Guide router retransmit-interval < 1 to 3600 > -- Set retransmit interval in seconds; the default is ■ (p. 486) transit-delay < 1 to 3600 > -- Set transit delay in seconds; the default is 1. (p.
Command Line Interface Reference Guide router bsm-interval < 5 to 300 > -- Specify the interval for sending Bootstrap messages on PIM-SM ■ interfaces. (p. 477) hash-mask-length < 1 to 32 > -- Specify the length (in bits) of the hash mask. (p.
Command Line Interface Reference Guide router ProCurve(config)# router vrrp ProCurve(config)# vlan 10 ProCurve(vlan-10)# vrrp vrid 1 ProCurve(vlan-10-vrid-1)# owner ProCurve(vlan-10-vrid-1)# virtual-ip-address 10.10.10.1 255.255.255.0 ProCurve(vlan-10-vrid-1)# enable ProCurve(vlan-10-vrid-1)# show vrrp vlan 10 vrid 1 config VRRP Virtual Router Configuration Information Vlan ID : 10 Virtual Router ID : 1 Administrative Status [Disabled] : Enabled Mode [Uninitialized] : Owner...
Page 477
Command Line Interface Reference Guide router area <OSPF-AREA-ID|backbone> range IP-ADDR/MASK-LENGTH [no-advertise] area <OSPF-AREA-ID|backbone> virtual-link IP-ADDR [transit-delay <0-3600>] [retransmit-interval <0-3600>] [hello-interval <1-65535>] [dead-interval <0-2147483647>] area <OSPF-AREA-ID|backbone> virtual-link IP-ADDR authentication-key OCTET-STR area <OSPF-AREA-ID|backbone> virtual-link IP-ADDR md5-auth-key-chain CHAIN-NAME-STR no area <OSPF-AREA-ID|backbone> no area <OSPF-AREA-ID|backbone> range IP-ADDR/MASK-LENGTH no area <OSPF-AREA-ID|backbone>...
Page 478
Command Line Interface Reference Guide router backbone -- The backbone area (the same as 0.0.0.0).(p. 477) ■ area-id ■ router ospf area OSPF-AREA-ID Single integer or IP address style dotted decimal. Next Available Options: normal -- Define a "normal" area.(p. 482) ■...
Page 479
Command Line Interface Reference Guide router Description: Enable/disable advertisement of summarized routes. Summarization mechanisms should be disabled when using both version 1 and version 2 of RIP within a single network. backbone ■ router ospf area backbone The backbone area (the same as 0.0.0.0). Next Available Options: normal -- Define a "normal"...
Page 480
Command Line Interface Reference Guide router Next Available Options: source-ip-vlan -- Specify the VLAN to use as a source for Candidate-BSR router IP address ■ (PIM-SM must be enabled on this VLAN). (VLAN-ID) (p. 488) hash-mask-length < 1 to 32 > -- Specify the length (in bits) of the hash mask. (p.
Page 481
Command Line Interface Reference Guide router Description: Set default metric for imported routes. Default value is 1. Range: < 1 to 15 > distance ■ router ospf distance Usage: distance <intra-area|inter-area|external> <1-255> Description: Set administrative distance to associate with intra-area, inter-area and AS-external routes learned by OSPF.
Page 482
Command Line Interface Reference Guide router group-prefix ■ router pim rp-candidate source-ip-vlan VLAN-ID group-prefix Specify the multicast group prefix to associate with the Candidate-RP router. Next Available Option: GROUP-ADDR/GROUP-MASK -- Enter the address and mask to define the multicast group ■...
Page 483
Command Line Interface Reference Guide router Range: < 1 to 255 > ■ router ospf area OSPF-AREA-ID range IP-ADDR/MASK-LENGTH Specify IP address/MASK pair. ■ router ospf area backbone range IP-ADDR/MASK-LENGTH Specify IP address/MASK pair. ip-addr ■ [no] router ospf restrict IP-ADDR/MASK-LENGTH Usage: [no] restrict IP-ADDR/MASK-LEN Description: Prevent redistribution of routes via OSPF.
Page 484
Command Line Interface Reference Guide router Next Available Option: chain-name -- Specify key chain to use for MD5 authentication. (ASCII-STR) (p. 478) ■ metric-type ■ router ospf area OSPF-AREA-ID nssa < 0 to 16777215 > metric-type < type1 | type2 > Metric type of the type-7 default.
Page 485
Command Line Interface Reference Guide router ■ router ospf area backbone nssa < 0 to 16777215 > no-summary Do not send summary LSA into the area. ■ router ospf area backbone stub no-summary Do not send summary LSA into the area. nssa ■...
Page 486
Command Line Interface Reference Guide router trap < virtual-interface-state-change | neighbor-state-change | virtual-neighbor-state-change | ■ ... > -- Enable/disable OSPF traps(p. 489) override ■ [no] router pim rp-address IP-ADDR IP-ADDR/MASK-LENGTH override Specify whether or not static RP configuration precedes the information learned by a BSR.
Page 487
Command Line Interface Reference Guide router Summarize routes matching address/MASK pair. Next Available Options: -- Specify IP address/MASK pair. (IP-ADDR/MASK-LENGTH) (p. 481) ■ no-advertise -- Do not advertise the range outside the area.(p. 482) ■ type < summary | nssa > -- Link state database type to apply the range.(p.
Page 488
Command Line Interface Reference Guide router Usage: [no] restrict IP-ADDR/MASK-LEN Description: Prevent redistribution of routes via OSPF. Next Available Option: ip-addr -- Prevent redistribution of routes via OSPF (IP-ADDR/MASK-LENGTH) (p. 481) ■ ■ router rip restrict Usage: [no] restrict IP-ADDR/MASK-LEN Description: Prevent redistribution of routes via RIP.
Page 489
Command Line Interface Reference Guide router and changes current context to RIP Configuration Context. Otherwise, the command disables RIP. The command can be followed by a RIP configuration command. Use 'router rip ?' to get a list of all possible options. Next Available Options: auto-summary -- Enable/disable advertisement of summarized...
Page 490
Command Line Interface Reference Guide router command to remove specific multicast group or disable the router to be a Candidate-RP. NOTE: It is recommended that the same routing switch is configured as the Candidate-BSR and the Candidate-RP. Parameters: o source-ip-vlan <VLAN-ID> - The VLAN which IP address will be advertised as the Candidate-RP address.
Page 491
Command Line Interface Reference Guide router state-refresh ■ router pim state-refresh < 10 to 300 > Usage: state-refresh <10-300> Description: Set the interval between successive State Refresh messages originated by this router. Default value is 60 seconds. Range: < 10 to 300 > stub ■...
Page 492
Command Line Interface Reference Guide router Dr, or Backup). - 'virtual-interface-state-change' signifies the same change in the state of a virtual OSPF interface. - 'neighbor-state-change' signifies that there has been a change in the state of a non-virtual OSPF neighbor. This trap is generated when the neighbor state regresses (e.g., goes from Attempt or Full to 1-Way or Down) or progresses to a terminal state (e.g., 2-Way or Full).
Page 493
Command Line Interface Reference Guide router Usage: [no] trap <TRAP-NAME|all> Description: Enable/disable PIM traps. The traps defined below are generated as the result of finding an unusual condition or a timer event. Possible trap names are: - 'neighbor-loss' signifies that a neighbor timer expired and the router has no other neighbors on the same interface with a lower IP address than itself.
Page 494
Command Line Interface Reference Guide router virtual-link ■ [no] router ospf area OSPF-AREA-ID virtual-link IP-ADDR Specify a virtual neighbor. Next Available Options: transit-delay < 1 to 3600 > -- Set transit delay in seconds; the default is 1.(p. 489) ■ retransmit-interval <...
savepower OVERVIEW Category: Primary context: config Related Commands Usage: [no] savepower <1|2|3> Description: power on/off of blocks controlling ports. - Power block-1 associated with ports 01-08. - Power block-2 associated with ports 09-16. - Power block-3 associated with ports 17-24. COMMAND STRUCTURE ■...
services OVERVIEW Category: Primary context: config Related Commands Usage: services [<SLOT-ID> <INDEX>|(name <NAME>)| |reload|shutdown] Description: Configure parameters for the services module or change the module's state (reload or shutdown). Parameters: o - Display the applications installed and running. o <SLOT-ID> <INDEX> - Configure parameters for the installed application.
Page 498
Command Line Interface Reference Guide services blink ■ services SLOT-ID locator blink Blink the locate led Next Available Option: duration < 1 to 1440 > -- Number of minutes duration (default 30). (NUMBER) (p. 496) ■ diagnostic-restart ■ services SLOT-ID diagnostic-restart Reboot services module into diagnostic partition.
Page 499
Command Line Interface Reference Guide services ■ services SLOT-ID locator on Turn the locate led on Next Available Option: duration < 1 to 1440 > -- Number of minutes duration (default 30). (NUMBER) (p. 496) ■ reload ■ services SLOT-ID reload Reboot services module.
services OVERVIEW Category: Primary context: manager Related Commands Usage: services [<SLOT-ID> <INDEX>|(name <NAME>)| |reload|shutdown] Description: Display parameters for the services module or change the module's state (reload or shutdown). Parameters: o - Display the applications installed and running. o <SLOT-ID> <INDEX> - Configure parameters for the installed application.
Page 501
Command Line Interface Reference Guide services Blink the locate led Next Available Option: duration < 1 to 1440 > -- Number of minutes duration (default 30). (NUMBER) (p. 499) ■ duration ■ services SLOT-ID locator on < 1 to 1440 > Number of minutes duration (default 30).
Page 502
Command Line Interface Reference Guide services reload ■ services SLOT-ID reload Reboot services module. shutdown ■ services SLOT-ID shutdown Shutdown (halt) the services module. slot-id ■ services SLOT-ID Device slot identifier for the services module. Next Available Options: -- Index of the services CLI to access. (p.
services OVERVIEW Category: Primary context: operator Related Commands Usage: services [<SLOT-ID> <INDEX>|(name <NAME>)] Description: Display parameters for the services module. Parameters: o - Display the applications installed and running. o <SLOT-ID> <INDEX> - Configure parameters for the installed application. o <SLOT-ID> locator - Controls services module locator LED.
Page 504
Command Line Interface Reference Guide services Number of minutes duration (default 30). Range: < 1 to 1440 > ■ services SLOT-ID locator blink < 1 to 1440 > Number of minutes duration (default 30). Range: < 1 to 1440 > ■...
setup OVERVIEW Category: Switch Management Primary context: manager Related Commands Usage: setup [default-logon <CLI|Menu>] Description: Enter the 'Switch Setup' screen for basic switch configuration. The optional parameter 'default-logon' changes the user interface presented after boot without entering full-screen setup. COMMAND STRUCTURE ■...
sflow OVERVIEW Category: Primary context: config Related Commands Usage: sflow <RECEIVER-INSTANCE> destination <IP-ADDRESS> [UDP-PORT] sflow <RECEIVER-INSTANCE> polling [ethernet] PORT-LIST <POLLING-INTERVAL> sflow <RECEIVER-INSTANCE> sampling [ethernet] PORT-LIST <SAMPLING-RATE> [no] sflow <RECEIVER-INSTANCE> Description: Configure or un-claim an sflow sampling receiver. If the [no] option is not used, this command will configure the sflow sampling receiver, polling, and sampling.
Page 512
Command Line Interface Reference Guide sflow sflow-receiver ■ [no] sflow < 1 to 3 > Select one of three possible sFlow receiver tables. Range: < 1 to 3 > Next Available Options: destination -- IP address of sFlow receiver/collector/management station. (IP-ADDR) (p.
show OVERVIEW Category: Primary context: operator Related Commands Usage: show ... Description: Display switch operation information. The 'show' must be followed by a command. Use 'show ?' for the list of all possible command. COMMAND STRUCTURE ■ show access-list -- Show Access Control List information (p.
Page 514
Command Line Interface Reference Guide show ■ show config -- Show the switch startup configuration (p. 540) filename < config | config1 > -- Display specified configuration. (p. 551) ■ files -- List saved configuration files. (p. 551) ■ status -- Check if the running configuration differs from the statup configuration.
Page 515
Command Line Interface Reference Guide show source-port (p. 592) ■ ■ show flash -- Show the version of software stored in the Primary and Secondary image locations (p. 552) ■ show front-panel-security -- Show current security status of the front panel butons (p.
Page 516
Command Line Interface Reference Guide show client-public-key -- Show currently loaded public keys for authorized clients (NUMBER) (p. 537) ■ babble -- Display phonetic hash. (p. 533) ■ fingerprint -- Display hexadecimal hash. (p. 552) ■ -- Show configured DNS server IP addresses on the switch (p.
Page 517
Command Line Interface Reference Guide show type < router | network | summary | ... > -- Show LSAs of the specified type only. ■ 600) neighbor -- Show all OSPF neighbors in the locality of of the device (p. 573) ■...
Page 518
Command Line Interface Reference Guide show ip-addr -- Destination IP address to display the routes to. (IP-ADDR) (p. 561) ■ type < static | connected | rip | ... > -- Specify type of routes to display. (p. 600) ■ source-binding -- Show Dynamic IP Lockdown trap status.
Page 519
Command Line Interface Reference Guide show port-list -- Show remote or local device information for the specified ports. ([ethernet] ■ PORT-LIST) (p. 578) remote-device -- Show LLDP remote device information. (p. 585) ■ port-list -- Show remote or local device information for the specified ports. ([ethernet] ■...
Page 520
Command Line Interface Reference Guide show web-based -- Show Web Authentication statistics and configuration (p. 609) ■ clients -- Show the current web client session statistics. (p. 538) ■ detailed -- Show the current web client session detailed statistics. (p. 546) ■...
Page 521
Command Line Interface Reference Guide show detailed -- Show the detailed configuration of Web Authentication. (p. 546) ■ web-server -- Show the web server-related configuration items. (p. 610) ■ clients -- Show the current web client session statistics. (p. 538) ■...
Page 522
Command Line Interface Reference Guide show mcast -- Show limits for ingress multicast traffic. (p. 569) ■ detailed -- Show Inbound Radius Override details. (p. 546) ■ port-list -- Specify ports for which information will be shown. ([ethernet] PORT-LIST) ■ 578) ■...
Page 523
Command Line Interface Reference Guide show view -- Show views. (p. 602) ■ VIEW-NAME -- Set view name. (ASCII-STR) (p. 603) ■ SUB-TREE -- Set the OID of the tree. (ASCII-STR) (p. 596) ■ ■ show sntp -- Show configured time protocol and servers (p.
Page 524
Command Line Interface Reference Guide show pvst-protection -- Show spanning tree PVST protection status information. (p. 582) ■ port-list -- Limit the port information printed to the set of the specified ports. ([ethernet] ■ PORT-LIST) (p. 578) root-history -- Show spanning tree Root changes history information. (p.
Command Line Interface Reference Guide show transceivers -- Display output of a predefined command sequence used by technical support ■ (p. 599) vrrp -- Display output of a predefined command sequence used by technical support (p. 608) ■ ■ show telnet -- Show active incoming and outgoing sessions (p.
Page 526
Command Line Interface Reference Guide show area-ip (p. 530) INDEX (p. 557) rip (p. 586) arp (p. 530) info (p. 557) rmon (p. 586) arp-protect (p. 530) information (p. 557) root-history (p. 586) authentication (p. 531) instance (p. 557) route (p. 587) authenticator (p.
Page 527
Command Line Interface Reference Guide show details (p. 547) neighbors-port (p. 574) trunks (p. 600) device-priority (p. 548) notify (p. 574) type (p. 600) dhcp-relay (p. 548) NOTIFY-NAME (p. 574) type-of-service (p. 601) dhcp-snooping (p. 548) only (p. 574) uninstalled (p. 601) direction (p.
Page 528
Command Line Interface Reference Guide show ■ show port-access mac-based [ETHERNET] PORT-LIST Specify ports for which MAC Authentication information will be shown. Next Available Options: config -- Show the current configuration of MAC Authentication.(p. 540) ■ clients -- Show the connected MAC address information.(p.
Page 529
Command Line Interface Reference Guide show Description: Show Web/MAC Authentication statistics and configuration. If PORT-LIST parameter is specified then information only for the specified ports is shown. Next Available Options: authenticator -- Show 802(p. 531) ■ mac-based -- Show MAC Authentication statistics and configuration(p.
Page 530
Command Line Interface Reference Guide show Next Available Option: group < ManagerPriv | ManagerAuth | OperatorAuth | ... > -- Show SNMPv3 users. (p. 553) ■ accounting ■ show accounting Usage: show accounting [sessions] Description: Show Accounting configuration parameters. If 'sessions' is specified then show accounting data for all active sessions.
Page 531
Command Line Interface Reference Guide show advertise ■ show ip ospf external-link-state advertise Show each LSA as a stream of bytes in hexadecimal notation. ■ show ip ospf link-state advertise Show each LSA as a stream of bytes in hexadecimal notation. agent ■...
Page 532
Command Line Interface Reference Guide show Usage: show ip ospf area [OSPF-AREA-ID] Description: Show OSPF areas configured on the device. Invoked without parameters displays all OSPF areas configured. If the 'OSPF-AREA-ID' is specified detailed information for the correspondent OSPF area is shown. Next Available Option: area-ip -- (OSPF-AREA-ID)
Page 533
Command Line Interface Reference Guide show authentication ■ show authentication Usage: show authentication Description: Show Authentication configuration parameters. ■ show radius authentication Usage: show radius authentication Description: Show RADIUS authentication statistics. authenticator ■ show port-access authenticator Usage: show port-access authenticator [config|statistics|session-counters] Description: Show 802.1X (Port Based Network Access) authenticator current status, configuration or last session counters.
Page 534
Command Line Interface Reference Guide show authorized-managers ■ show ip authorized-managers Usage: show ip authorized-managers Description: Show IPV4 addresses allowed to manage the switch. ■ show ipv6 authorized-managers Usage: show ipv6 authorized-managers Description: Show IPV6 addresses allowed to manage the switch. auth-server ■...
Page 535
Command Line Interface Reference Guide show autorun ■ show autorun Show Autorun configuration status. autorun-cert ■ show crypto autorun-cert Display trusted certificate. autorun-key ■ show crypto autorun-key Display autorun key. babble ■ show crypto client-public-key babble Display phonetic hash. ■ show crypto client-public-key < manager | operator > babble Display phonetic hash.
Page 536
Command Line Interface Reference Guide show Usage: show banner motd Description: show the configured banner text. Next Available Option: motd -- show the configured banner text(p. 571) ■ bcast ■ show rate-limit bcast Show limits for ingress broadcast traffic. Next Available Options: port-list -- Specify ports for which information will be shown.
Page 537
Command Line Interface Reference Guide show Next Available Option: vlan -- Show the configured BOOTP Gateway for VLAN.(p. 603) ■ bpdu-protection ■ show spanning-tree bpdu-protection Show spanning tree BPDU protection status information. Next Available Option: port-list -- Limit the port information printed to the set of the specified ports. ([ethernet] ■...
Page 538
Command Line Interface Reference Guide show Usage: show debug buffer [-r | -c <count> | substring ...] Description: Show the contents of the debug log buffer. -r - Instructs the switch to display messages in reverse order (most recent first). -c - Instructs the switch to stop after displaying <count>...
Page 539
Command Line Interface Reference Guide show candidates ■ show stack candidates Show the list of devices that are stack candidates. ■ show cdp Usage: show cdp [neighbor [PORT-NUM] [detail]] Description: Show CDP configuration and neighbors discovered. Legend for 'capability' field of the 'show cdp neighbor' command output: R - Performs level 3 routing for at least one network layer protocol.
Page 540
Command Line Interface Reference Guide show ■ show ip client-public-key Usage: show ip client-public-key [babble|fingerprint] Description: Show currently loaded public keys for authorized clients. The 'babble' and 'fingerprint' options produce a phonetic or hexadecimal hash instead of displaying the raw key file. Next Available Options: babble -- Display phonetic...
Page 541
Command Line Interface Reference Guide show Show the current web client session statistics. Next Available Option: ■ -- Specify ports for which Web Authentication information will be shown. ([ethernet] PORT-LIST) (p. 525) ■ show port-access [ETHERNET] PORT-LIST authenticator clients Show the current 802.1X client session statistics. Next Available Option: detailed -- Show the current 802.1X client session detailed statistics.
Page 542
Command Line Interface Reference Guide show config ■ show access-list config Show all configured ACL's on the switch using the CLI syntax used to create them. ■ show access-list ACL-NAME config Show all configured ACL's on the switch using the CLI syntax used to create them. ■...
Page 543
Command Line Interface Reference Guide show Description: Show LLDP configuration information. o [ethernet] PORT-LIST - Show port configuration information. Next Available Option: port-list -- Specify the port or list of ports. ([ethernet] PORT-LIST) (p. 578) ■ ■ show port-access authenticator [ETHERNET] PORT-LIST config Show 802.1X authenticator configuration.
Page 544
Command Line Interface Reference Guide show ■ show port-access [ETHERNET] PORT-LIST mac-based config Show the current configuration of MAC Authentication. Next Available Options: auth-server -- Show the authentication server-related configuration items.(p. 532) ■ detailed -- Show the detailed configuration of MAC Authentication.(p.
Page 545
Command Line Interface Reference Guide show configuration ■ show instrumentation monitor configuration Usage: show instrumentation monitor configuration Description: show configured thresholds for monitored parameters. shows the parameter name and the configured threshold value for all parameters. If instrumenation monitoring for the particular paramter is disabled then threshold for the particular parameter is displayed as 'Not Monitored'.
Page 546
Command Line Interface Reference Guide show Use the 'slot' argument to display CPU utilization for the specified modules, rather than the chassis CPU. Next Available Options: time < 1 to 300 > -- Time (seconds) over which to average CPU utilization. (NUMBER) (p.
Page 547
Command Line Interface Reference Guide show ■ show tech custom Usage: show tech [all|custom|buffers|instrumentation|mesh|route|statistics |transceivers|vrrp] Description: Display output of a predefined command sequence used by technical support. custom-port-list ■ show interfaces custom [ETHERNET] PORT-LIST Usage: show interfaces [ethernet] PORT-LIST Description: Show summary of network traffic handled by the ports. Next Available Option: column-list -- The list of desired FIELD[:WIDTH] (port, type, status, speed, mode, mdi, flow,...
Page 548
Command Line Interface Reference Guide show destination ■ show sflow < 1 to 3 > destination Displays information about the receiver/collector/management-station to which the sampling-polling data is sent. detail ■ show cdp neighbors detail Show neighbor information field-per-line instead of shortened table format. ■...
Page 549
Command Line Interface Reference Guide show ■ show port-access mac-based config [ETHERNET] PORT-LIST detailed Show the detailed configuration of MAC Authentication. ■ show port-access mac-based clients [ETHERNET] PORT-LIST detailed Show the connected MAC address detailed information. ■ show port-access web-based [ETHERNET] PORT-LIST config detailed Show the detailed configuration of Web Authentication.
Page 550
Command Line Interface Reference Guide show Usage: show services details Description: Show services software information ■ show modules details Usage: show modules details Description: Show miniGBIC information device-priority ■ show qos device-priority Usage: show qos device-priority Description: Show the device priority table (priority based on the IP addresses).
Page 551
Command Line Interface Reference Guide show ■ vlan -- VLAN acl ■ [no] show statistics < aclv6 > ACL-NAME vlan VLAN-ID < vlan > Supported Values: ■ vlan -- VLAN acl ■ [no] show statistics < policy > POLICY-NAME vlan VLAN-ID < in > Supported Values: ■...
Page 552
Command Line Interface Reference Guide show elected ■ show ip pim bsr elected Show elected Bootstrap Router information. enable ■ show snmpv3 enable Show SNMPv3 status. endpoint ■ show monitor endpoint Remote mirroring destination configuration. engineid ■ show snmpv3 engineid Show switch's SNMP engineId.
Page 553
Command Line Interface Reference Guide show router-id -- Show LSAs with the specified Router ID only. (IP-ADDR) (p. 587) ■ sequence-number -- Show LSAs with the specified sequence number only.(p. 589) ■ fan-pref-airflow-dir ■ show system fan-pref-airflow-dir Usage: show system fan-pref-airflow-dir Description: Shows the user configured fan preferred airflow direction.
Page 554
Command Line Interface Reference Guide show filter ■ show filter Usage: show filter [INDEX] Description: Show a table of security filters or a filter detailed information, if the filter's INDEX is specified. Next Available Options: INDEX -- Show detailed information for the filter identified by the INDEX. The indices are ■...
Page 555
With 'password-recovery' enabled (and the front panel buttons disabled), a lost password can be recovered by contacting HP customer support. With 'password-recovery' disabled, there is no way to access a device after losing a password with the front panel buttons disabled.
Page 556
Command Line Interface Reference Guide show Supported Values: ■ ManagerPriv -- Require privacy and authentication, can access all objects. ■ ManagerAuth -- Require authentication, can access all objects. ■ OperatorAuth -- Requires authentication, limited access to objects. ■ OperatorNoAuth -- No authentication required, limited access to objects. ■...
Page 557
Command Line Interface Reference Guide show helper-address ■ show ip helper-address Usage: show ip helper-address [vlan <VLAN-ID>] Description: Show DHCP servers where DHCP requests received by the switch are to be forwarded. Next Available Option: vlan -- Specify a vlan for which to show server addresses. (VLAN-ID) (p.
Page 558
Command Line Interface Reference Guide show fingerprint -- Display hexadecimal hash.(p. 552) ■ icmp ■ show ip icmp Usage: show ip icmp Description: Show ICMP Rate Limiting settings. ■ show rate-limit icmp Show only limits for icmp traffic. Next Available Options: port-list -- Specify ports for which information will be shown.
Page 559
Command Line Interface Reference Guide show Next Available Options: vlan -- Show IGMP operational information for the VLAN specified. (VLAN-ID) (p. 603) ■ config -- Show IGMP configuration information.(p. 540) ■ group -- Show ports the specified multicast group address is registered on. (IP-ADDR) (p.
Page 560
Command Line Interface Reference Guide show Show the spanning tree instance information. Next Available Options: -- Show the information for the internal spanning tree (IST) instance.(p. 563) ■ MSTID < 1 to 16 > -- Spanning tree instance ID for which to show the information.(p.
Page 561
Command Line Interface Reference Guide show Range: < 0 to 16 > instrumentation ■ show instrumentation Usage: show instrumentation Description: Show internal version-dependant counters for debugging. This data is for factory troubleshooting purposes. The data displayed is dependent on which version of code is running. Data is maintained for the current 5 minutes, hour, and day.
Page 562
Command Line Interface Reference Guide show ■ show ip rip interface Usage: show ip rip interface [IP-ADDR|vlan VLAN-ID] Description: Show RIP interfaces' information. Invoked without parameters shows all RIP interfaces configured. If the 'IP-ADDR' or the VLAN is specified detailed information for the interface determined through the parameter is shown.
Page 563
Command Line Interface Reference Guide show Next Available Options: port-list -- Show summary of network traffic handled by the ports ([ethernet] PORT-LIST) ■ 578) config -- Show configuration information(p. 540) ■ display -- Show summary of network traffic handled by the ports(p.
Page 564
Command Line Interface Reference Guide show IP-ADDR ■ show ip mroute IP-ADDR Usage: show ip mroute [GRP-ADDR SRC-ADDR] Description: Show detailed information for the specified entry from the IP multicast routing table. GRP-ADDR is the IP multicast group address and SRC-ADDR is the source IP address of the entry. Next Available Option: IP-ADDR -- Specify the source IP address of the MRT entry.
Page 565
Command Line Interface Reference Guide show routers -- Show the IPv6 Router table entries(p. 587) ■ route -- Show the IPv6 routing table(p. 587) ■ -- Show the IPv6 Neighbor Discovery settings(p. 573) ■ -- Invoked without any parameters, shows per-VLAN MLD status, or, if VLANs are disabled ■...
Page 566
Command Line Interface Reference Guide show Show the information for the internal spanning tree (IST) instance. ■ show spanning-tree root-history ist Show IST Regional Root changes history. jumbos ■ show jumbos Usage: show max-frame-size Description: Show the untagged Max frame size for the switch. This value will be effective only when Jumbo is enabled.
Page 567
Command Line Interface Reference Guide show lacp ■ show lacp Usage: show lacp Description: Show status of LACP trunks. Next Available Option: distributed -- Show distributed lacp of local and remote switch(p. 549) ■ learned ■ show ip pim rp-set learned Show RP-Set information learned from the BSR.
Page 568
Command Line Interface Reference Guide show Next Available Options: area-id -- Show LSAs for the specified area only. (OSPF-AREA-ID) (p. 530) ■ advertise -- Show each LSA as a stream of bytes in hexadecimal notation.(p. 529) ■ link-state-id -- Show LSAs with the specified ID only. (IP-ADDR) (p.
Page 569
Command Line Interface Reference Guide show Usage: show lockout-mac Description: Show the MAC addresses that have been locked out of the network. logging ■ show logging Usage: show logging [-a|-r|-m|-p|-w|-i|-d|substring ...] Description: Display log events. -a - Instructs the switch to display all recorded log events, which includes events from previous boot cycles.
Page 570
Command Line Interface Reference Guide show mac-address ■ show mac-address Usage: show mac-address [[ethernet] PORT-LIST|vlan VLAN-ID|MAC-ADDR] Description: Show MAC addresses the switch has learned. You can display addresses learned on a particular port, a PORT-LIST, a VLAN-ID, or a particular MAC address. Next Available Options: address-table-port -- Show MAC addresses learned on the specified ports.
Page 571
Command Line Interface Reference Guide show of MAC Authentication is shown. If 'auth-server' keyword has been specified then the authentication server-related configuration items are shown. If PORT-LIST and 'detail' keyword has been specified then the detailed configuration of MAC Authentication for the specified ports is shown.
Page 572
Command Line Interface Reference Guide show ■ show ipv6 mld Usage: show ipv6 mld [config|group IPV6-ADDR|VLAN-ID [config]] Description: Invoked without any parameters, shows per-VLAN MLD status, or, if VLANs are disabled displays the global MLD status. When followed by the 'config' keyword, shows MLD global configuration information.
Page 573
Command Line Interface Reference Guide show Usage: show monitor Description: Show the switch network monitoring status and configuration, if network monitoring is enabled. Next Available Options: mirror_session_id < 1 to 4 > -- Mirror destination number.(p. 569) ■ name -- Mirror destination name.(p.
Page 574
Command Line Interface Reference Guide show msti ■ show spanning-tree root-history msti < 1 to 16 > Show MSTI Regional Root changes history. Range: < 1 to 16 > MSTID ■ show spanning-tree [ETHERNET] PORT-LIST config instance < 1 to 16 > Spanning tree instance ID for which to show the information.
Page 575
Command Line Interface Reference Guide show ■ show policy NAME Enter policy name. ■ show ipv6 nd Usage: show ipv6 nd Description: Show the IPv6 Neighbor Discovery settings. neighbor ■ show ip ospf neighbor Usage: show ip ospf neighbor [IP-ADDR] Description: Show all OSPF neighbors in the locality of of the device.
Page 576
Command Line Interface Reference Guide show Next Available Option: vlan -- Displays information on the IPv6 neighbor discovery cache(p. 603) ■ neighbors-port ■ show cdp neighbors [ETHERNET] PORT-NUM Show CDP neighbors on specified port only. notify ■ show snmpv3 notify Show SNMPv3 notification table.
Page 577
Command Line Interface Reference Guide show spf-log -- List the OSPF SPF(Shortes Path First Algorithm) run count for all OSPF areas and last ■ ten Reasons for running SPF(p. 593) statistics -- List OSPF packet statistics( OSPF sent,recieved and error packet count) of all OSPF ■...
Page 578
Command Line Interface Reference Guide show peer-ip ■ show ip rip peer IP-ADDR Specify IP address of the RIP peer to show. pending ■ show ip pim pending Show (*,G) and (S,G) Join Pending Information. ■ show spanning-tree pending Usage: show spanning-tree pending ... Description: Show spanning tree pending configuration.
Page 579
Command Line Interface Reference Guide show policy-name ■ show statistics < policy > POLICY-NAME Enter the name of acl/policy. Next Available Options: vlan -- Enter the statistics vlan. (VLAN-ID) (p. 603) ■ port -- Enter the statistics port. ([ethernet] PORT-NUM) (p.
Page 580
Command Line Interface Reference Guide show Next Available Options: authenticator -- Show 802(p. 531) ■ supplicant -- Show 802(p. 596) ■ mac-based -- Show MAC Authentication statistics and configuration(p. 568) ■ web-based -- Show Web Authentication statistics and configuration(p. 609) ■...
Page 581
Command Line Interface Reference Guide show Description: Show names assigned to the ports. If the PORT-LIST is not specified the default is to list all of the ports. ■ show port-security [ETHERNET] PORT-LIST Usage: show port-security [intrusion-log|[ethernet] PORT-LIST] Description: Show a table describing port security settings. o intrusion-log - Show the intrusion log records.
Page 582
Command Line Interface Reference Guide show Limit the port information printed to the set of the specified ports. ■ show spanning-tree pvst-filter [ETHERNET] PORT-LIST Limit the port information printed to the set of the specified ports. ■ show spanning-tree pvst-protection [ETHERNET] PORT-LIST Limit the port information printed to the set of the specified ports.
Page 583
Command Line Interface Reference Guide show Show VLANs that have at least one port from the 'PORT-LIST' as a member. Next Available Option: detail -- Display more info for each port from the 'PORT-LIST' separately.(p. 546) ■ ■ show svlans ports [ETHERNET] PORT-LIST Show VLANs that have at least one port from the 'PORT-LIST' as a member.
Page 584
Command Line Interface Reference Guide show power-supply ■ show system power-supply Usage: show system power-supply Description: Show Chassis Power Supply info and settings. protocol-priority ■ show qos protocol-priority Usage: show qos protocol Description: Show the protocol priority. pvst-filter ■ show spanning-tree pvst-filter Show spanning tree PVST filter status information.
Page 585
Command Line Interface Reference Guide show protocol-priority -- Show the protocol priority(p. 582) ■ tcp-udp-port-priority -- Show TCP/UDP port priorities(p. 598) ■ type-of-service -- Show QoS priorities based on IP Type-of-Service(p. 601) ■ vlan-priority -- Show the VLAN-based priority table(p. 607) ■...
Page 586
Command Line Interface Reference Guide show Next Available Options: authentication -- Show RADIUS authentication statistics(p. 531) ■ accounting -- Show RADIUS accounting statistics(p. 528) ■ dyn-authorization -- Show RADIUS dynamic authorization statistics(p. 549) ■ host -- Show statistics information for the RADIUS host (IP-ADDR) (p.
Page 587
Command Line Interface Reference Guide show Usage: show ip rip redistribute Description: List protocols which are being redistributed into RIP. redundancy ■ show redundancy Usage: show redundancy Description: Display redundant information for Management and Fabric Modules. remote-device ■ show lldp info remote-device Show LLDP remote device information.
Page 588
Command Line Interface Reference Guide show restrict ■ show ip ospf restrict Usage: show ip ospf restrict Description: List routes which will not be redistributed via OSPF. ■ show ip rip restrict Usage: show ip rip restrict Description: List routes which will not be redistributed via RIP. restricted-access ■...
Page 589
Command Line Interface Reference Guide show Next Available Options: -- Show CST Root changes history.(p. 544) ■ -- Show IST Regional Root changes history.(p. 563) ■ msti < 1 to 16 > -- Show MSTI Regional Root changes history. (NUMBER) (p.
Page 590
Command Line Interface Reference Guide show Usage: show ipv6 routers vlan <VLANID> Description: Show the IPv6 Router table entries. Next Available Option: vlan -- Show the IPv6 Router Table Entries for VLAN.(p. 603) ■ rp-candidate ■ show ip pim rp-candidate Usage: show ip pim rp-candidate [config] Description: Show Candidate-RP operational and configuration information.
Page 591
Command Line Interface Reference Guide show sampling-polling ■ show sflow < 1 to 3 > sampling-polling Displays information about sampling and polling. Next Available Option: port-list -- Displays information about sampling and polling. ([ethernet] PORT-LIST) (p. 578) ■ savepower ■ show savepower Usage: show savepower Description: Shows the user configured block power status.
Page 592
Command Line Interface Reference Guide show o <SLOT-ID> - Display summary table for the specified slot. o <SLOT-ID> details - Display application information for the specified slot. Next Available Option: services -- Show services information (SLOT-ID) (p. 589) ■ ■ show services SLOT-ID Usage: show services [<SLOT-ID>...
Page 593
Command Line Interface Reference Guide show receiver-index < 1 to 3 > -- Select one of the three possible sFlow receiver tables. (NUMBER) ■ (p. 584) slave_time ■ show cpu slot SLOT-ID-RANGE < 1 to 90 > Time (seconds) over which to average CPU utilization. Range: <...
Page 594
Command Line Interface Reference Guide show community -- Show SNMPv3 Community table. (p. 539) ■ enable -- Show SNMPv3 status. (p. 550) ■ engineid -- Show switch's SNMP engineId. (p. 550) ■ group -- Show SNMPv3 User to Group mappings. (p.
Page 595
Command Line Interface Reference Guide show [detail] show spanning-tree [mst-config] | [config [instance <ist|INSTANCE-ID>]] | [root-history <cst|ist|msti <INSTANCE-ID>>] | [debug-counters [instance <INSTANCE-ID>] | [ports <PORT_LIST>]] Description: Show spanning tree information. When executed without parameters, the command shows spanning tree status information. If PORT-LIST is specified, the command shows spanning tree status information only for the ports listed.
Page 596
Command Line Interface Reference Guide show Description: Show the stack status of this switch. The 'candidate' and 'view' commands are available on the stack commander only. o candidates - show the list of devices that are stack candidates. o view - show the list of devices that are stack members. o all - show information about all the stacks available on the LAN.
Page 597
Command Line Interface Reference Guide show ■ show link-keepalive statistics show detailed statistics for all link-keepalive enabled ports. ■ show port-access authenticator [ETHERNET] PORT-LIST statistics Show authentication sessions statistics for 802.1X authenticator. ■ show port-access authenticator statistics Show authentication sessions statistics for 802.1X authenticator. ■...
Page 598
Command Line Interface Reference Guide show stats ■ show dhcp-snooping stats Display DHCP snooping events. ■ show lldp stats Usage: show lldp stats [[ethernet] PORT-LIST] Description: Show LLDP statistics. o [ethernet] PORT-LIST - Show statistics for the specified ports . Next Available Option: port-list -- Specify the port or list of ports.
Page 599
Command Line Interface Reference Guide show svlans ■ show svlans Usage: show vlans [VLAN-ID|ports [ethernet] PORT-LIST] Description: Show status information for all VLANs. If a 'VLAN-ID' is specified, shows the ports that are currently members of the VLAN identified by the 'VLAN-ID'. If a 'PORT-LIST' is specified, shows all the VLANs of which at least one port in the 'PORT-LIST' is a member.
Page 600
Command Line Interface Reference Guide show tcp-udp-port-priority ■ show qos tcp-udp-port-priority Usage: show qos tcp-udp-port-priority Description: Show TCP/UDP port priorities. tech ■ show tech Usage: show tech [all|custom|buffers|instrumentation|mesh|route|statistics |transceivers|vrrp] Description: Display output of a predefined command sequence used by technical support. Next Available Options: -- Display output of a predefined command sequence used by technical support(p.
Page 601
Command Line Interface Reference Guide show throttled-hosts ■ show connection-rate-filter throttled-hosts Show throttled IP addresses. time ■ show cpu < 1 to 300 > Time (seconds) over which to average CPU utilization. Range: < 1 to 300 > ■ show time Usage: show time Description: Show current date and time.
Page 602
Command Line Interface Reference Guide show ■ show spanning-tree traps Show spanning tree trap information. trunks ■ show trunks Usage: show trunks [[ethernet] PORT-LIST] Description: Show a list of ports and the trunks to which they belong. If a PORT-LIST is supplied the command shows only the ports specified.
Page 603
Command Line Interface Reference Guide show ■ show statistics < aclv6 > Supported Values: ■ aclv6 -- Ipv6 acl. Next Available Option: acl-name -- Enter the name of acl/policy. (ASCII-STR) (p. 528) ■ ■ show statistics < policy > Supported Values: ■...
Page 604
Command Line Interface Reference Guide show Next Available Option: USER-NAME -- Show a specific user. (ASCII-STR) (p. 602) ■ USER-NAME ■ show snmpv3 user USER-NAME Show a specific user. ver1-2c ■ show snmpv3 access-rights < ManagerPriv | ManagerAuth | OperatorAuth | ... > sec-model < ver1 | ver2c >...
Page 605
Command Line Interface Reference Guide show Show the list of devices that are stack members. VIEW-NAME ■ show snmpv3 view VIEW-NAME Set view name. Next Available Option: SUB-TREE -- Set the OID of the tree. (ASCII-STR) (p. 596) ■ virtual-link ■...
Page 606
Command Line Interface Reference Guide show ■ show dhcp-relay bootp-gateway vlan Show the configured BOOTP Gateway for VLAN. Next Available Option: vlan -- (VLAN-ID) (p. 603) ■ ■ show dhcp-relay bootp-gateway vlan VLAN-ID ■ show instrumentation cam vlan Usage: show instrumentation [<group>] [port|vlan <num>] Description: Show internal version-dependant counters for debugging for thespecified port or vlan number.
Page 607
Command Line Interface Reference Guide show Specify VLAN of the interface for which to show detailed information. ■ show ipv6 vlan Usage: show ipv6 vlan [VLAN-ID] Description: Show IPv6 status information for all VLANs. If a 'VLAN-ID' is specified, shows the ports that are currently members of the VLAN identified by the 'VLAN-ID'.
Page 608
Command Line Interface Reference Guide show Show authorized and unauthorized vlans for 802.1X authenticator. ■ show port-access [ETHERNET] PORT-LIST authenticator vlan Show authorized and unauthorized vlans for 802.1X authenticator. ■ show vlans VLAN-ID Show detailed VLAN information for the VLAN with the ID supplied. ■...
Page 609
Command Line Interface Reference Guide show VLAN-ID ■ show ip mroute interface VLAN-ID Specify the VLAN ID of the IP multicast routing interface to show. ■ show ip pim interface VLAN-ID Specify the VLAN ID of the PIM interface to show. ■...
Page 610
Command Line Interface Reference Guide show If a 'VLAN-ID' is specified, shows the ports that are currently members of the VLAN identified by the 'VLAN-ID'. If a 'PORT-LIST' is specified, shows all the VLANs of which at least one port in the 'PORT-LIST' is a member. Next Available Options: vlan -- Show detailed VLAN information for the VLAN with the ID supplied.
Page 611
Command Line Interface Reference Guide show Usage: show vrrp [...] Description: Show VRRP configuration and statistics information. Next Available Options: config -- Show VRRP configuration information for the device(p. 540) ■ statistics -- Show VRRP statistics information for the device(p. 594) ■...
Page 612
Command Line Interface Reference Guide show If 'auth-server' keyword has been specified then the authentication server-related configuration items are shown. If 'web-server' keyword has been specified then the web server-related configuration items are shown. If PORT-LIST and 'detail' keyword has been specified then the detailed configuration of Web Authentication for the specified ports is shown.
Page 613
Command Line Interface Reference Guide show Usage: show wireless-services vlans show wireless-services <SLOT-ID> show wireless-services <SLOT-ID> [radio-ports|uplinks] Description: Show wireless-services information. Parameters: o vlans - Display all radio-port VLANs. o <SLOT-ID> - Display summary table for the specified slot. o <SLOT-ID> radio-ports - Display radio-ports associated with the specified slot.
Command Line Interface Reference Guide snmp-server informs -- Specify if informs will be sent, rather than notifications. (p. 618) ■ retries < 0 to 255 > -- Specify the number of retries for informs. (p. 620) ■ timeout < 1 to 21474836 > -- Specify the interval between retries for informs, in seconds. ■...
Page 617
Command Line Interface Reference Guide snmp-server address_ipv6 ■ snmp-server host IPV6-ADDR IPv6 address of SNMP notification host. Next Available Options: community -- Name of the SNMP community (up to 32 characters). (ASCII-STR) (p. 615) ■ informs -- Specify if informs will be sent, rather than notifications.(p.
Page 618
Command Line Interface Reference Guide snmp-server contact ■ snmp-server contact CONTACT Name of the switch administrator. dhcp-snooping ■ [no] snmp-server enable traps dhcp-snooping Traps for DHCP-Snooping. dst-ip-of-request ■ snmp-server response-source dst-ip-of-request Destination Ip address of the snmp request pdu will be used as the source ip address in the snmp response pdu.
Page 619
Command Line Interface Reference Guide snmp-server Disables SNMP support for the hpSwitchAuthentication MIB. extended ■ [no] snmp-server enable traps snmp-authentication extended Send traps for Extended Authentication failures. host ■ [no] snmp-server host Usage: [no] snmp-server host IP-ADDR COMMUNITY-STR [none|debug|all|not-info|critical] [informs [retries RETRY-COUNT] [timeout TIMEOUT]] Description: Define SNMP traps and their receivers.
Page 620
Command Line Interface Reference Guide snmp-server Description: Enable/Disable SNMP support for the hpSwitchAuthentication MIB. When the MIB access is enabled, Manager read/write access to the MIB is permitted. Operator read/write access to the MIB is always denied. For security reasons, network administrators are encouraged to disable SNMPV2c before using the MIB.
Page 621
Command Line Interface Reference Guide snmp-server Description of the switch location. login-failure-mgr ■ [no] snmp-server enable traps login-failure-mgr Traps for management interface login failure. loopback ■ snmp-server response-source loopback < 0 to 7 > For the specified loopback interface, lexicographically minimum configured ip address will be used as the source ip address in the snmp response pdu.
Page 622
■ snmp-server host IPV6-ADDR informs retries < 0 to 255 > Specify the number of retries for informs. Range: < 0 to 255 > snmp-authentication ■ [no] snmp-server enable traps snmp-authentication Select RFC-1157 (standard) or HP-ICF-SNMP (extended) traps. Next Available Options: standard -- Send traps for Standard Authentication failures.(p. 620) ■...
Page 623
Description: Enable/disable event traps to be sent by the switch. Next Available Options: link-change -- Traps for link-up and link-down. ([ethernet] PORT-LIST) (p. 618) ■ snmp-authentication -- Select RFC-1157 (standard) or HP-ICF-SNMP (extended) traps.(p. 620) ■ dhcp-snooping -- Traps for DHCP-Snooping.(p. 616) ■ arp-protect -- Traps for Dynamic ARP Protection.(p.
Page 624
Command Line Interface Reference Guide snmp-server view ■ [no] snmp-server community COMMUNITY < Operator | Manager > Usage: [no] snmp-server community ASCII-STR [manager|operator] [restricted|unrestricted] Description: Add/delete SNMP community. Parameters: o community ASCII-STR - Enter up to 32 characters to name an SNMP community.
Page 628
Command Line Interface Reference Guide snmpv3 Set authentication protocol. Supported Values: ■ MD5 -- Set the authentication protocol to md5. ■ SHA -- Set the authentication protocol to sha. Next Available Option: authpassword -- Set authentication password. (ASCII-STR) (p. 625) ■...
Page 629
Command Line Interface Reference Guide snmpv3 group ■ [no] snmpv3 group < ManagerPriv | ManagerAuth | OperatorAuth | ... > Configure SNMPv3 User to Group entry. Supported Values: ■ ManagerPriv -- Require privacy and authentication, can access all objects. ■ ManagerAuth -- Require authentication, can access all objects. ■...
Page 630
Command Line Interface Reference Guide snmpv3 max-msg-size < 484 to 65535 > -- Set maximum message size value; default is 1472. (p. 628) ■ port-mask -- Set range of udp ports with this mask. (TCP/UDP-PORT) (p. 629) ■ retries < 0 to 255 > -- Set retries value; default is 3. (p.
Page 631
Command Line Interface Reference Guide snmpv3 Next Available Option: tagvalue -- Set tag value that selects entries in the snmpTargetAddr table. (ASCII-STR) (p. 632) ■ only ■ [no] snmpv3 only Accept only SNMP v3 messages. params ■ [no] snmpv3 params PARAMS Configure SNMPv3 Target Parameter entry.
Page 632
Command Line Interface Reference Guide snmpv3 privpassword ■ snmpv3 user USERNAME auth AUTHPASSWORD priv PRIVPASSWORD Set Privacy password. ■ snmpv3 user USERNAME auth AUTHPASSWORD priv < DES | AES > PRIVPASSWORD Set Privacy password. ■ snmpv3 user USERNAME auth < MD5 | SHA > AUTHPASSWORD priv PRIVPASSWORD Set Privacy password.
Page 633
Command Line Interface Reference Guide snmpv3 ■ snmpv3 targetaddress TARGETADDRESS params PARAMS IPV6-ADDR retries < 0 to 255 > Set retries value; default is 3. Range: < 0 to 255 > sec-model ■ [no] snmpv3 group < ManagerPriv | ManagerAuth | OperatorAuth | ... > user USER sec-model <...
Page 634
Command Line Interface Reference Guide snmpv3 Set list of values used to select this entry from snmpNotifyTable. ■ snmpv3 targetaddress TARGETADDRESS params PARAMS IPV6-ADDR taglist TAGLIST Set list of values used to select this entry from snmpNotifyTable. tagvalue ■ snmpv3 notify NOTIFY tagvalue TAGVALUE Set tag value that selects entries in the snmpTargetAddr table.
Page 635
Command Line Interface Reference Guide snmpv3 Next Available Option: sec-model -- Set security model. (p. 631) ■ ■ [no] snmpv3 user Configure SNMPv3 User entry. Next Available Option: username -- Set authentication paramaters. (ASCII-STR) (p. 633) ■ username ■ snmpv3 user USERNAME Set authentication paramaters.
sntp OVERVIEW Category: Switch Management Primary context: config Related Commands show sntp (page 592) timesync (page 689) Usage: [no] sntp [broadcast|unicast] [no] sntp server priority <PRIORITY> <IP-ADDR | IPV6-ADDR> [version] sntp poll-interval <30-720> Description: Configure the Simple Network Time Protocol (SNTP). The first version of the command specifies whether the switch operates in broadcast or unicast mode.
Page 637
Command Line Interface Reference Guide sntp ipaddr ■ [no] sntp server priority < 1 to 3 > IP-ADDR SNTP server IPv4 address. Next Available Option: version < 1 to 7 > -- Version of the SNTP server.(p. 635) ■ ipv6addr ■...
Command Line Interface Reference Guide spanning-tree o priority <0-15> or <0-65535> (default is 32768 and step 8 respectively) - The device priority - used along with the switch MAC address to determine which device is the root. If 802.1w or 802.1s STP version is set, then the range of 0-61440 is divided into steps of 4096.
Page 641
Command Line Interface Reference Guide spanning-tree -- Configure internal spanning tree (IST) instance. (p. 644) ■ port-list -- Configure internal spanning tree (IST) instance ports parameters ([ethernet] ■ PORT-LIST) (p. 648) path-cost -- Set the internal port pathcost for the IST (default is 'auto'). (p.
Command Line Interface Reference Guide spanning-tree mcheck -- Force the port to transmit RST BPDUs. (p. 645) ■ path-cost -- Set port's path cost value. (p. 646) ■ auto -- Use dynamic method of selecting a value for the path cost. (p.
Page 644
Command Line Interface Reference Guide spanning-tree Range: < 0 to 65535 > clear-debug-counters ■ spanning-tree clear-debug-counters Clear spanning tree debug counters. Next Available Options: instance < 0 to 16 > -- Clear spanning tree instance debug counters. (NUMBER) (p. 643) ■...
Page 645
Command Line Interface Reference Guide spanning-tree ■ RSTP-operation -- The protocol operates as Rapid STP on all ports except those ports where a system that is using 802.1d Spanning Tree has been detected. ■ spanning-tree force-version < STP-compatible | RSTP-operation | MSTP-operation > Set Spanning Tree protocol compatibility mode.
Page 646
Command Line Interface Reference Guide spanning-tree must have at least one VLAN mapped to it. The VLANs unmapped from other instances are automatically mapped to the IST instance. Only IST VLANs can be directly mapped to other instances. When VLANs are mapped to an instance they are automatically unmapped from the instance they were mapped to before.
Page 647
Command Line Interface Reference Guide spanning-tree 'spanning-tree legacy-mode' is the equivalent of executing: spanning-tree legacy-path-cost spanning-tree force-version stp-compatible 'no spanning-tree legacy-mode' is the equivalent of executing: no spanning-tree legacy-path-cost spanning-tree force-version mstp-operation legacy-path-cost ■ [no] spanning-tree legacy-path-cost Set 802.1D (legacy) or 802.1t (not legacy) default pathcost values. max-hops ■...
Page 648
Command Line Interface Reference Guide spanning-tree ■ [no] spanning-tree pending instance < 1 to 16 > ID of the MST instance to configure. Range: < 1 to 16 > Next Available Option: vlan -- Configure VLANs for the MST instance.(p. 653) ■...
Page 649
Command Line Interface Reference Guide spanning-tree Next Available Options: path-cost < 1 to 200000000 > -- Set port's path cost to the fixed value.(p. 646) ■ auto -- Use dynamic method of selecting a value for the path cost.(p. 641) ■...
Page 650
Command Line Interface Reference Guide spanning-tree point-to-point-mac ■ spanning-tree [ETHERNET] PORT-LIST point-to-point-mac < True | False | Auto > Set the administrative point-to-point status. Supported Values: ■ True -- Treat the port as if it is connected to a point-to-point LAN segment. ■...
Page 651
Command Line Interface Reference Guide spanning-tree If enabled, this takes precendence over the pvst-filter configuration for a port. o root-guard - Applies only to MSTP. If TRUE causes the port not to be selected as Root Port for the CIST or any MSTI. o tcn-guard - Applies only to MSTP.
Page 652
Command Line Interface Reference Guide spanning-tree Usage: spanning-tree [ethernet] PORT-LIST <<admin-edge-port>|auto-edge-port>| <mcheck>| <path-cost <1-65535>|<1-200000000>|auto>>| <point-to-point <true|false|auto>>| <bpdu-filter>| <bpdu-protection>| <pvst-filter>| <pvst-protection>| <root-guard> | <tcn-guard>| <hello-time <1-10>>| <priority <0-15>>> Description: Configure the port-specific parameters of the spanning tree protocol for individual ports. Parameters: o admin-edge-port - Applies only to RSTP/MSTP.
Page 653
Command Line Interface Reference Guide spanning-tree RSTP/MSTP. When correctly set for each port, it improves the operation of protocol. 'True' indicates that the port will be treated as if it is connected to a point-to-point LAN segment, regardless of any information to the contrary that the switch receives.
Page 654
Command Line Interface Reference Guide spanning-tree ■ spanning-tree clear-debug-counters ports [ETHERNET] PORT-LIST Clear spanning tree port(s) debug counters. Next Available Option: instance < 0 to 16 > -- Clear spanning tree instance debug counters. (NUMBER) (p. 643) ■ priority ■ spanning-tree [ETHERNET] PORT-LIST priority < 0 to 15 > Set port priority (the value is in range of 0-240 divided into steps of 16 that are numbered from 0 to 15, default is step 8).
Page 655
Command Line Interface Reference Guide spanning-tree Enables or disables the PVST protection feature on the port or range of ports specified. command indicates which ports are not expected to receive any PVST BPDUs. Default: Disabled on all ports reset ■ spanning-tree pending reset Copy active configuration to pending.
startup-default OVERVIEW Category: manager Primary context: manager Related Commands show config (page 540) show flash (page 552) Usage: startup-default [<primary|secondary>] config FILENAME Description: Set the default configuration file. A separate configuration file may be set as the default for each software image, or a single configuration file may be set as the default when booting either image by omitting the optional 'primary|secondary' parameter.
static-mac OVERVIEW Category: config Primary context: config Related Commands the section called static-mac” (page 594) Usage: static-mac <MAC-ADDR> vlan <VLAN-ID> interface <PORT-LIST> Description: Lock down a MAC address to a port on a vlan. Parameters: o MAC-ADDR - MAC address to lock down. o vlan VLAN-ID - VLAN on which to lock down the MAC address.
svlan OVERVIEW Category: Primary context: config Related Commands qinq (page 409) vlan (page 706) show qinq (page 582) show svlans (page 597) Usage: [no] svlan VLAN-ID [...] Description: Add, delete, edit SVLAN configuration or enter a SVLAN context. If an existing 'SVLAN VLAN-ID' is specified you are put into the context for that SVLAN, and can then execute commands for that SVLAN.
Command Line Interface Reference Guide svlan dhcp-bootp -- Configure the interface to use DHCP/Bootp server to acquire parameters. ■ 666) ip-addr -- Interface IP address/mask. (IP-ADDR/mask-LENGTH) (p. 668) ■ ■ svlan VLAN-ID ipv6 -- Configure various IP parameters for the VLAN (p.
Page 666
Command Line Interface Reference Guide svlan Next Available Option: direction < in | out | connection-rate-filter | ... > -- (p. 666) ■ address ■ [no] svlan VLAN-ID ip address Usage: [no] ip address [dhcp-bootp|IP-ADDR/mask-LENGTH] Description: Set IP parameters for communication within an IP network. Each VLAN represents an IP interface having its own unique configuration.
Page 667
Command Line Interface Reference Guide svlan following syntax: ipv6 address 1234:abcd::5678/40 ipv6 address 2001:0db8:1:1:ffff:ffff:ffff:fffe/64 anycast ipv6 address 2001:0db8:0:1::/64 eui-64 Only link-local addreses are configured without PREFIX-LEN as below: ipv6 address FE80:0:0:0:0123:0456:0789:0abc link-local Multiple addresses may be configured on a single VLAN. Next Available Options: autoconfig -- Automatic address...
Page 668
Command Line Interface Reference Guide svlan Automatic address configuration. binary-range ■ svlan VLAN-ID qos dscp < 0 to 63 > Specify the DSCP code-point in binary. Range: < 0 to 63 > connection-rate-filter ■ svlan VLAN-ID connection-rate-filter Usage: connection-rate-filter unblock < host SRC-IP-ADDR | SRC-IP-ADDRESS/mask >...
Page 669
Command Line Interface Reference Guide svlan Specify DSCP policy to use. Next Available Options: integer-range < 0 to 63 > -- Specify the DSCP code-point in decimal. (p. 667) ■ binary-range < 0 to 63 > -- Specify the DSCP code-point in binary. (BINARY) (p.
Page 670
Command Line Interface Reference Guide svlan Usage: [no] ip ... Description: Configure various IP parameters for the VLAN. The 'ip' command must be followed by a feature-specific keyword. Use 'ip ?' to get a list of all possible options. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 671
Command Line Interface Reference Guide svlan Next Available Options: anycast -- Address that is assigned to a set of interfaces that typically belong to different ■ nodes(p. 665) eui-64 -- An IPv6 EUI-64 address that can be automatically configured on any interface(p.
Page 672
Command Line Interface Reference Guide svlan Parameters: o 1-4 - Mirror destination number o NAME-STR - Friendly name associated with the mirror destination number. o ACL-NAME - Standard or Extended Access Control List number. o <in|out|both> direction of the traffic to be monitored. Next Available Option: <...
Page 673
Command Line Interface Reference Guide svlan protocol-group ■ [no] svlan VLAN-ID protocol PROTOCOL-GROUP Enter a list of protocols for the current VLAN delimited by commas. protocols ■ [no] svlan VLAN-ID protocol < IPX | IPv4 | IPv6 | ... > Set a predefined protocol for the current VLAN.
Page 674
Command Line Interface Reference Guide svlan Description: Assign ports to current VLAN as tagged. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command. unblock ■ svlan VLAN-ID connection-rate-filter unblock Resets a host previously blocked by the connection rate filter Next Available Options: -- Resets all previously blocked by the connection rate filter...
Page 675
Command Line Interface Reference Guide svlan 'no qos dscp-map <codepoint>' will remove the settings for the specified codepoint from the running configuration. priority is set to no-override and the name is deleted (the priority and name can only be removed if no QoS feature is configured to use this DSCP Policy).
system OVERVIEW Category: Primary context: config Related Commands To change global system parameters COMMAND STRUCTURE ■ [no] system fan-pref-airflow-dir -- Changes the preferred fan airflow direction (p. 677) < port-to-power | power-to-port > -- (p. 677) ■ COMMAND DETAILS fan-pref-airflow-dir (p. 677) int (p.
tacacs-server OVERVIEW Category: Accounting Primary context: config Related Commands show (page 511) Usage: [no] tacacs-server host IP-ADDR [key KEY-STR] [no] tacacs-server key KEY-STR tacacs-server timeout <1-255> Description: Configure TACACS+ authentication servers. The first version of the command adds (or removes, if 'no' is specified) a TACACS+ server to (from) the list of servers that will be used for authentication.
Page 681
Command Line Interface Reference Guide tacacs-server host ■ [no] tacacs-server host IP-ADDR IP address of the server to use. Next Available Option: -- Encryption key to use with server.(p. 679) ■ ■ [no] tacacs-server host IP-ADDR key Encryption key to use with server. Next Available Option: -- (ASCII-STR) (p.
task-monitor OVERVIEW Category: Primary context: manager Related Commands Usage: [no] task-monitor FEATURE Description: Enable the task monitoring of the specified feature. COMMAND STRUCTURE ■ [no] task-monitor -- Monitor cpu usage by task group. (p. 680) EXAMPLES Example: task-monitor When the task-monitor command is enabled, the show cpu command summarizes the processor usage: ProCurve(config)# task-monitor cpu ProCurve(config)# show cpu...
telnet OVERVIEW Category: Switch Management Primary context: manager Related Commands Usage: telnet <IPV4-ADDR|IPV6-ADDR|HOSTNAME|SWITCH-NUM> Description: Initiate an outbound telnet session to another network device. The destination can be specified using one of the following parameter types: o IPV4-ADDR - IPv4 address of device to telnet to. o IPV6-ADDR - IPv6 address of device to telnet to.
telnet-server OVERVIEW Category: Switch Management Primary context: config Related Commands the section called console” (page 543) Usage: [no] telnet-server Description: Enable/disable telnet server on the switch. For remote clients to use telnet, the switch must first be configured for IPv4. By default, telnet access is enabled. Use 'show console' command to see the status of this function.
terminal OVERVIEW Category: Switch Management Primary context: manager Related Commands the section called terminal” (page 598) Usage: terminal [length <2-1000> | width <53-1920>] Description: Set the dimensions of the terminal window. COMMAND STRUCTURE ■ terminal length < 2 to 1000 > -- Set the height of the terminal window (NUMBER) (p.
tftp OVERVIEW Category: Primary context: config Related Commands Usage: [no] tftp [client|server] Description: Enable/disable TFTP, trivial file transfer protocol. If SFTP is enabled, TFTP will be disabled. If SFTP is to be enabled using SNMP, both TFTP and auto-TFTP MUST first be disabled. COMMAND STRUCTURE ■...
time OVERVIEW Category: Switch Management Primary context: config Related Commands ip (page 290) sntp (page 634) clock (page 86) Usage: time [HH:MM:SS] [MM/DD[/[yy]yy]] [daylight-time-rule <none|alaska|continental-us-and-canada| middle-europe-and-portugal| southern-hemisphere| western-europe|user-defined> [begin-date <MM/DD>] [end-date <MM/DD>] [timezone <-720..840>] Description: Display/set current time, date, and local time parameters. Called without any parameters displays the information mentioned above.
Command Line Interface Reference Guide time Example: timesync sntp Select SNTP as the time source and configure it with unicast mode and an SNTP server at 10.28.227.141 with the default server version (3) and default poll interval (720 seconds): ProCurve(config)# timesync sntp Example: time timezone daylight-time-rule Set the time zone and daylight time rule for Vancouver, Canada: ProCurve(config)# time timezone -480 daylight-time-rule continental-us-and-canada...
[probes <1-5>] - Number of probe queries to send out for each hop. The default value is 3. o [source <IP_ADDR|VLAN-ID>] - The source IPv4 address or VLAN. Examples: (1) hp-switch# traceroute 1.1.1.1 COMMAND STRUCTURE ■ traceroute host-name -- Hostname of the destination device. (ASCII-STR) (p.
Command Line Interface Reference Guide traceroute probes < 1 to 5 > -- Number of Probes <1-5>. (p. 692) ■ timeout < 1 to 120 > -- Traceroute timeout in seconds <1-120>. (p. 693) ■ vlan -- Source VLAN. (VLAN-ID) (p.
Page 694
Command Line Interface Reference Guide traceroute Next Available Options: minttl < 1 to 255 > -- Minimum time to live <1-255>.(p. 692) ■ maxttl < 1 to 255 > -- Maximum time to live <1-255>.(p. 692) ■ timeout < 1 to 120 > -- Traceroute timeout in seconds <1-120>.(p.
Page 695
Command Line Interface Reference Guide traceroute ■ traceroute HOST-NAME probes < 1 to 5 > Number of Probes <1-5>. Range: < 1 to 5 > ■ traceroute source VLAN-ID probes < 1 to 5 > Number of Probes <1-5>. Range: < 1 to 5 > ■...
[probes <1-5>] - Number of probe queries to send out for each hop. The default value is 3. Examples: (1) hp-switch# traceroutev6 80fe::20b:cdff:fedd:9a62 (2)ProCurve# traceroute6 2001:db8::10 traceroute to 2001:db8::10 1 hop min, 30 hops max, 5 sec. timeout, 3 probes...
Command Line Interface Reference Guide traceroute6 ■ traceroute6 ipv6-addr -- Destination IPv6 adddress. (IPV6-ADDR) (p. 696) maxttl < 1 to 255 > -- Maximum time to live <1-255>. (p. 697) ■ minttl < 1 to 255 > -- Minimum time to live <1-255>. (p.
Page 699
Command Line Interface Reference Guide traceroute6 Next Available Options: minttl < 1 to 255 > -- Minimum time to live <1-255>.(p. 697) ■ maxttl < 1 to 255 > -- Maximum time to live <1-255>.(p. 697) ■ timeout < 1 to 120 > -- Traceroute timeout in seconds <1-120>.(p.
Page 700
Command Line Interface Reference Guide traceroute6 Default: 1 probes ■ traceroute6 IPV6-ADDR probes < 1 to 5 > Number of times a traceroute is performed to locate the IPv6 device at any hop in the route to the specified host before the operation times out.
Page 701
Command Line Interface Reference Guide traceroute6 Next Available Options: minttl < 1 to 255 > -- Minimum time to live <1-255>.(p. 697) ■ maxttl < 1 to 255 > -- Maximum time to live <1-255>.(p. 697) ■ timeout < 1 to 120 > -- Traceroute timeout in seconds <1-120>.(p.
trunk OVERVIEW Category: Primary context: config Related Commands switch-interconnect (page 675) Usage: trunk [ethernet] PORT-LIST <trk1|trk2...trkN> [trunk|lacp] no trunk [ethernet] PORT-LIST Description: Add or remove a switch port from a port trunk. Each port on the switch (up to 8 ports total) can be made a member of a port trunk.
Command Line Interface Reference Guide trunk EXAMPLES Example: trunk with dt-lacp Option for Distributed Trunking Configure the trunk ports using the trunk command with the dt-lacp option. The trunk groups must be identical in both switches, for example, both the Local and Remote switch trunks are configured as trk10 with the dt-lacp option.
Page 704
Command Line Interface Reference Guide trunk ■ Trk24 -- Trunk group 24 ■ Trk25 -- Trunk group 25 ■ Trk26 -- Trunk group 26 ■ Trk27 -- Trunk group 27 ■ Trk28 -- Trunk group 28 ■ Trk29 -- Trunk group 29 ■...
vlan OVERVIEW Category: VLANs Primary context: config Related Commands show vlans (page 607) ip (page 290) ipv6 (page 313) router (page 471) mirror-port (page 381) Usage: [no] vlan VLAN-ID [...] Description: Add, delete, edit VLAN configuration or enter a VLAN context. If an existing VLAN-ID is specified you are put into the context for that VLAN, and can then execute commands for that VLAN.
Page 709
Command Line Interface Reference Guide vlan -- Add or remove a UDP server address for the VLAN (p. 749) ■ ip-addr -- IP address of the protocol server. (IP-ADDR) (p. 729) ■ port-name < dns | ntp | netbios-ns | ... > -- (NUMBER) (p.
Page 710
Command Line Interface Reference Guide vlan chain-name -- Specify key chain to use for MD5 authentication. (ASCII-STR) (p. 720) ■ passive -- Configures an ospf interface as passive. (p. 739) ■ priority < 0 to 255 > -- Set priority of this router as a designated router. (p.
Page 711
Command Line Interface Reference Guide vlan max-graft-retries < 1 to 10 > -- Set the maximum number of times this router will resend ■ a Graft on this interface (p. 734) override-interval < 500 to 6000 > -- Set the value inserted into the Override Interval field ■...
Page 712
Command Line Interface Reference Guide vlan receive < V1-only | V2-only | V1-or-V2 | ... > -- Define RIP version for incoming packets. ■ (p. 745) rip-compatible < V1-only | V2-only | V1-or-V2 > -- Define RIP version for incoming and ■...
Page 713
Command Line Interface Reference Guide vlan ns-interval -- Configures the neighbor discovery time between neighbor solicitation requests ■ sent for an unresolved destination, or between duplicate address detection neighbor solicitation requests (p. 737) number < 1000 to 3600000 > -- Configures the neighbor discovery time between neighbor ■...
Page 716
Command Line Interface Reference Guide vlan o dhcp-bootp - The switch attempts to get its configuration from a DHCP/Bootp server. o IP-ADDR/mask-LENGTH - Assign an IP address to the switch or VLAN. The IP-ADDR/mask-LENGTH may be specified in two ways using the following syntax: ip address 192.32.36.87/24 ip address 192.32.36.87 255.255.255.0...
Page 717
Command Line Interface Reference Guide vlan Usage: [no] ip irdp <multicast|broadcast> Description: Specify the destination address to be used for router advertisements. It has to be either multicast or broadcast. If the value of this object is 'multicast' (the default), router advertisements will be sent to the all-hosts multicast address, 224.0.0.1.
Page 718
Command Line Interface Reference Guide vlan rip-compatible < V1-only | V2-only | V1-or-V2 > -- Define RIP version for incoming and outgoing ■ packets.(p. 747) ■ vlan VLAN-ID connection-rate-filter unblock all Resets all previously blocked by the connection rate filter ■...
Page 719
Command Line Interface Reference Guide vlan ■ vlan VLAN-ID ip ospf all area Specify an OSPF area. Next Available Options: area-id -- Single integer or IP address style dotted decimal. (OSPF-AREA-ID) (p. 717) ■ backbone -- The backbone area (the same as 0.0.0.0).(p.
Page 720
Command Line Interface Reference Guide vlan OSPF authentication key (maximum 8 characters). ■ vlan VLAN-ID ip ospf all authentication-key Set simple authentication method and key. Next Available Option: authentication-key -- OSPF authentication key (maximum 8 characters). (OCTET-STR) (p. 717) ■ ■...
Page 721
Command Line Interface Reference Guide vlan ■ none -- Do not use authentication. ■ text -- Use simple password. auth-key-text ■ vlan VLAN-ID ip rip authentication-key OCTET-STR Set RIP authentication key (maximum 16 characters). ■ vlan VLAN-ID ip rip IP-ADDR authentication-key OCTET-STR Set RIP authentication key (maximum 16 characters).
Page 722
Command Line Interface Reference Guide vlan ■ vlan VLAN-ID ip ospf all area backbone The backbone area (the same as 0.0.0.0). backup ■ vlan VLAN-ID vrrp vrid < 1 to 255 > backup Usage: vrrp vrid <VRID> backup Description: Designate the virtual router instance as a Backup. There is no default value.
Page 723
Command Line Interface Reference Guide vlan ■ vlan VLAN-ID ip ospf IP-ADDR md5-auth-key-chain CHAIN-NAME Specify key chain to use for MD5 authentication. ■ vlan VLAN-ID ip ospf all md5-auth-key-chain CHAIN-NAME Specify key chain to use for MD5 authentication. connection-rate-filter ■ vlan VLAN-ID connection-rate-filter Usage: connection-rate-filter unblock <...
Page 724
Command Line Interface Reference Guide vlan dhcp ■ [no] vlan VLAN-ID ipv6 address dhcp Configure a DHCPv6 client. Next Available Option: full -- Obtain IPv6 address & Configuration information from DHCPv6 server.(p. 725) ■ dhcp-bootp ■ vlan VLAN-ID ip address dhcp-bootp Configure the interface to use DHCP/Bootp server to acquire parameters.
Page 725
Command Line Interface Reference Guide vlan enable ■ [no] vlan VLAN-ID ipv6 enable Enable IPv6 on an interface and configures an automatically generated link-local addr. ■ [no] vlan VLAN-ID vrrp vrid < 1 to 255 > enable Usage: [no] vrrp vrid <VRID> enable Description: Enable/disable operation of the virtual router instance.
Page 726
Command Line Interface Reference Guide vlan Usage: [no] ipv6 mld fastleave < port-list > Description: Enables MLD fast-leaves on the specified ports in the selected VLAN. The no form of the command disables MLD fast-leave on the specified ports in the selected VLAN. forbid ■...
Page 727
Command Line Interface Reference Guide vlan Usage: [no] ip forward-protocol udp IP-ADDR PORT-NUM|PORT-NAME Description: Add or remove a UDP server address for the VLAN. The broadcast packets received by the switch on this VLAN are to be forwarded to the specified application server. This is a VLAN context command.
Page 728
Command Line Interface Reference Guide vlan ■ vlan VLAN-ID ip ospf IP-ADDR hello-interval < 1 to 65535 > Set hello interval in seconds; the default is 10. Range: < 1 to 65535 > ■ vlan VLAN-ID ip ospf all hello-interval < 1 to 65535 > Set hello interval in seconds;...
Page 729
Command Line Interface Reference Guide vlan host ■ vlan VLAN-ID connection-rate-filter unblock host IP-ADDR Match packets from the specified IP address. igmp ■ [no] vlan VLAN-ID ip igmp Usage: [no] ip igmp [...] Description: Enable/disable/configure IP Multicast Group Protocol (IGMP) feature on a VLAN.
Page 730
Command Line Interface Reference Guide vlan ■ [no] vlan VLAN-ID service-policy SERVICE-POLICY in Apply policy on inbound packets. integer-range ■ vlan VLAN-ID qos dscp < 0 to 63 > Specify the DSCP code-point in decimal. Range: < 0 to 63 > interface ■...
Page 731
Command Line Interface Reference Guide vlan Next Available Options: access-group -- Apply the specified access control list on this VLAN interface (ASCII-STR) ■ 713) address -- Set IP parameters for communication within an IP network(p. 713) ■ proxy-arp -- Enable/disable proxy ARP(p.
Page 732
Command Line Interface Reference Guide vlan ■ [no] vlan VLAN-ID ip rip IP-ADDR Specify the IP address the request is for. Next Available Options: authentication-type < none | text > -- Set authentication type used on this interface.(p. 718) ■ authentication-key -- Set RIP authentication key (maximum 16 characters).(p.
Page 733
Command Line Interface Reference Guide vlan ■ vlan VLAN-ID vrrp vrid < 1 to 255 > primary-ip-address IP-ADDR Specify IP address. ip-recv-mac-address ■ [no] vlan VLAN-ID ip-recv-mac-address Usage: [no] ip-recv-mac-address <macaddress> interval <1-255> Description: Associates a L3-mac-address with a VLAN. To associate L3-Mac-Address for a VLAN.
Page 734
Command Line Interface Reference Guide vlan Next Available Option: link-local -- Configure a link-local IPv6 address.(p. 733) ■ ipv6-addr/mask ■ [no] vlan VLAN-ID ipv6 address IPV6-ADDR/PREFIX-LEN Configure IPv6 address represented in CIDR notation. Next Available Options: anycast -- Address that is assigned to a set of interfaces that typically belong to different ■...
Page 735
Command Line Interface Reference Guide vlan lan-prune-delay ■ [no] vlan VLAN-ID ip pim-dense lan-prune-delay Usage: [no] ip pim-dense lan-prune-delay Description: Turn on/off the LAN Prune Delay Option on this interface. Default is 'on'. ■ [no] vlan VLAN-ID ip pim-sparse lan-prune-delay Usage: [no] ip pim-sparse lan-prune-delay Description: Turn on/off the LAN Prune Delay Option on this interface.
Page 736
Command Line Interface Reference Guide vlan Usage: [no] ip irdp maxadvertinterval <4-1800> Description: Set the maximum time (in seconds) allowed between sending unsolicited router advertisements. Range: < 4 to 1800 > max-graft-retries ■ vlan VLAN-ID ip pim-dense max-graft-retries < 1 to 10 > Usage: ip pim-dense max-graft-retries <1-10>...
Page 737
Command Line Interface Reference Guide vlan minadvertinterval ■ vlan VLAN-ID ip irdp minadvertinterval < 3 to 1800 > Usage: [no] ip irdp minadvertinterval <3-1800> Description: Set the minimum time (in seconds) allowed between sending unsolicited router advertisements. Must be no greater than the maximum time between sending unsolicited router advertisements.
Page 738
Command Line Interface Reference Guide vlan forward -- Instruct the device to forward incoming multicast packets received on the specified ■ ports ([ethernet] PORT-LIST) (p. 724) fastleave -- Enables MLD fast-leaves on the specified ports in the selected VLAN ([ethernet] ■...
Page 739
Command Line Interface Reference Guide vlan name ■ vlan VLAN-ID name NAME Usage: name ASCII-STR Description: Set the VLAN's name. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 740
Command Line Interface Reference Guide vlan solicitation requests sent for an unresolved destination, or between duplicate address detection neighbor solicitation requests. When set to a non-default value, this is included in router advertisements as the ra-retranstime value. Next Available Option: number <...
Page 741
Command Line Interface Reference Guide vlan authentication -- Disable authentication.(p. 717) ■ md5-auth-key-chain -- Set MD5 authentication method and key chain.(p. 734) ■ cost < 1 to 65535 > -- Set metric of this interface.(p. 721) ■ dead-interval < 1 to 65535 > -- Set dead interval in seconds; the default is 40.(p.
Page 742
Command Line Interface Reference Guide vlan Usage: [no] ip pim-dense [...] Description: Enable/disable/configure PIM-DM protocol on the VLAN interface. Use direct and 'no' versions of the command to enable/disable PIM-DM on the interface. Use 'ip pim-dense ?' to get the list of all configuration options.
Page 743
Command Line Interface Reference Guide vlan poison-reverse ■ [no] vlan VLAN-ID ip rip poison-reverse Enable/disable poison reverse on this interface. ■ [no] vlan VLAN-ID ip rip IP-ADDR poison-reverse Enable/disable poison reverse on this interface. ■ [no] vlan VLAN-ID ip rip all poison-reverse Enable/disable poison reverse on this interface.
Page 744
Command Line Interface Reference Guide vlan Range: < 1 to 600 > preempt-mode ■ [no] vlan VLAN-ID vrrp vrid < 1 to 255 > preempt-mode Usage: [no] vrrp vrid <VRID> preempt-mode Description: Enable/disable preempt mode for the virtual router instance. The default value is 'enabled'.
Page 746
Command Line Interface Reference Guide vlan Enter a list of protocols for the current VLAN delimited by commas. protocols ■ [no] vlan VLAN-ID protocol < IPX | IPv4 | IPv6 | ... > Set a predefined protocol for the current VLAN. Supported Values: ■...
Page 747
Command Line Interface Reference Guide vlan enabled, the device cannot become Querier for the subnet unless the VLAN has an IP Address (use the 'show ip' command to determine this). Each subnet must have at least one IGMP Querier-capable device in order for IGMP to function properly.
Page 748
Command Line Interface Reference Guide vlan Supported Values: ■ V1-only -- Accept RIP version 1 updates only. ■ V2-only -- Accept RIP version 2 updates only. ■ V1-or-V2 -- Accept both RIP 1 and RIP 2 updates. ■ disabled -- Do not accept RIP updates. ■...
Page 749
Command Line Interface Reference Guide vlan ip-addr -- Specify the IP address the request is for. (IP-ADDR) (p. 729) ■ -- Process the request for all IP addresses.(p. 715) ■ rip-compatible ■ vlan VLAN-ID ip rip < V1-only | V2-only | V1-or-V2 > Define RIP version for incoming and outgoing packets.
Page 751
Command Line Interface Reference Guide vlan transit-delay ■ vlan VLAN-ID ip ospf transit-delay < 1 to 3600 > Set transit delay in seconds; the default is 1. Range: < 1 to 3600 > ■ vlan VLAN-ID ip ospf IP-ADDR transit-delay < 1 to 3600 > Set transit delay in seconds;...
Page 752
Command Line Interface Reference Guide vlan Next Available Options: -- Resets all previously blocked by the connection rate filter (p. 715) ■ host -- Match packets from the specified IP address. (IP-ADDR) (p. 727) ■ src-ip -- Match packets from the specified subnet. (IP-ADDR/mask-LENGTH) (p.
Page 753
Command Line Interface Reference Guide vlan Usage: [no] voice Description: Labels this VLAN as a Voice VLAN, allowing you to separate, prioritize, and authenticate voice traffic moving through your network. This is a VLAN context command. It can be called directly from the VLAN context or follow the 'vlan VLAN-ID' command.
Page 754
Command Line Interface Reference Guide vlan well-defined ■ vlan VLAN-ID qos dscp < af11 | af12 | af13 | ... > Usage: [no] qos dscp-map <0|1...63|af11|af12|af13|af21|af22|af23|af31|af32| af33|af41|af42|af43|ef|cs0..cs7|000000|000001...111111>| [priority <<0-7>|no-override>] [name <str>] Description: Define mapping between a DSCP (Differentiated-Services Codepoint) value and an 802.1p priority. The mapping is used to assign priority for IPv4 packets if a QoS classifier uses this DSCP policy as the method of traffic prioritization.
walkMIB OVERVIEW Category: SNMP Primary context: manager Related Commands getMIB (page 192) setMIB (page 504) Usage: walkmib OBJECT-STR [OBJECT-STR ...] Description: Walk through all instances of the object specified displaying the MIB object names, instances and values. COMMAND STRUCTURE ■ walkMIB object -- The mib object to start from.
web-management OVERVIEW Category: Switch Management Primary context: config Related Commands show (page 511) crypto (page 138) crypto (page 138) Usage: [no] web-management [management-url] URL [support-url] URL [<plaintext | ssl [<TCP-PORT>] >] Description: Enable/disable the device web server. Parameters: o management-url - Specify URL to load when the [?] button is clicked on the device's web interface.
Page 758
Command Line Interface Reference Guide web-management management-url ■ [no] web-management management-url Specify URL for web interface [?] button. Next Available Option: management-url -- Specify URL for web interface [?] button. (ASCII-STR) (p. 756) ■ ■ web-management management-url MANAGEMENT-URL Specify URL for web interface [?] button. plaintext ■...
wireless-services OVERVIEW Category: Primary context: config Related Commands Usage: wireless-services <SLOT-ID> [<reload|shutdown>] Description: Configure parameters for the wireless-services module or change the module's state (reload or shutdown). Parameters: o <SLOT-ID> - Configure parameters for the wireless-services module. o <SLOT-ID> reload - Reboot wireless-services module. o <SLOT-ID>...
Page 760
Command Line Interface Reference Guide wireless-services Reboot wireless-services module. shutdown ■ wireless-services SLOT-ID shutdown Shutdown (halt) the wireless-services module. tech ■ wireless-services SLOT-ID tech Enter the configuration context for the wireless-services module. wireless-services ■ wireless-services SLOT-ID Usage: wireless-services <SLOT-ID> [<reload|shutdown>] Description: Configure parameters for the wireless-services module or change the module's state (reload or shutdown).
wireless-services OVERVIEW Category: Primary context: manager Related Commands Usage: wireless-services <SLOT-ID> <reload|shutdown> Description: Display parameters for the wireless-services module or change the module's state (reload or shutdown). NOTES Multiple Contexts This command also is available in the config and operator contexts. COMMAND STRUCTURE ■...
wireless-services OVERVIEW Category: Primary context: operator Related Commands Usage: wireless-services SLOT-ID Description: Display parameters for the wireless-services module. Parameters: o <slotID> - Device slot identifier for the wireless-services module. NOTES Multiple Contexts This command also is available in the config and manager contexts. COMMAND STRUCTURE ■...
write OVERVIEW Category: Switch Management Primary context: manager Related Commands the section called config” (page 540) Usage: write <memory|terminal> Description: View or save the running configuration of the switch. write terminal - displays the running configuration of the switch on the terminal write memory - saves the running configuration of the switch to flash.