Allied-telesis AT-9000 Series Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Computerhardware Allied-telesis AT-9000 Series herunter. Allied Telesis AT-9000 Series User Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 148
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 0
613-001823 Rev. A
AT-9000 Series
Gigabit Ethernet Switches
AT-9000/12PoE
AT-9000/28
AT-9000/28PoE
AT-9000/28SP
AT-9000/52
Management Software Command Line Interface User’s
Guide
AlliedWare Plus Version 2.1.8.0
Seitenansicht 0
1 2 3 4 5 6 ... 147 148

Inhaltsverzeichnis

Seite 1 - AT-9000 Series

613-001823 Rev. AAT-9000 SeriesGigabit Ethernet Switches AT-9000/12PoE AT-9000/28 AT-9000/28PoE AT-9000/28SP AT-9000/52Management Software Comman

Seite 2 - Copyright

Contents10Adding Static MAC Addresses ...

Seite 3

Chapter 4: Basic Command Line Management Commands72

Seite 4

Chapter 64: SNMPv3 Commands972NO SNMP-SERVER ENGINEID LOCALSyntaxno snmp-server engineid localParametersNoneModeGlobal Configuration modeDescriptionUs

Seite 5

AT-9000 Switch Command Line User’s Guide973NO SNMP-SERVER GROUPSyntaxno snmp-server group name noauth|auth|privParametersnameSpecifies the name of a g

Seite 6

Chapter 64: SNMPv3 Commands974NO SNMP-SERVER HOSTSyntaxno snmp-server host ipaddress informs|traps v3 auth|noauth|priv usernameParametersipaddressSpec

Seite 7

AT-9000 Switch Command Line User’s Guide975ExampleThis example deletes the host entry with the IPv4 address 187.87.165.12. The user name associated wi

Seite 8

Chapter 64: SNMPv3 Commands976NO SNMP-SERVER USERSyntaxno snmp-server user userParametersuserSpecifies the name of a user you want to delete from the

Seite 9

AT-9000 Switch Command Line User’s Guide977NO SNMP-SERVER VIEWSyntaxno snmp-server view view OIDParametersviewSpecifies the name of a view to be delet

Seite 10 - Contents

Chapter 64: SNMPv3 Commands978SHOW SNMP-SERVERSyntaxshow snmp-serverParametersNoneModePrivileged Exec modeDescriptionUse this command to display the c

Seite 11

AT-9000 Switch Command Line User’s Guide979SHOW SNMP-SERVER GROUPSyntaxshow snmp-server groupParametersNoneModePrivileged Exec modeDescriptionUse this

Seite 12

Chapter 64: SNMPv3 Commands980SHOW SNMP-SERVER HOSTSyntaxshow snmp-server hostParametersNoneModePrivileged Exec modeDescriptionUse this command to dis

Seite 13

AT-9000 Switch Command Line User’s Guide981SHOW SNMP-SERVER USERSyntaxshow snmp-server userParametersNoneModePrivileged Exec modeDescriptionUse this c

Seite 14

73Chapter 5Temperature and Fan Control Overview “Overview” on page 74 “Displaying the System Environmental Status” on page 75 “Controlling Eco-Mode

Seite 15

Chapter 64: SNMPv3 Commands982SHOW SNMP-SERVER VIEWSyntaxshow snmp-server viewParameterNoneModePrivileged Exec modeDescriptionUse this command to disp

Seite 16

AT-9000 Switch Command Line User’s Guide983SNMP-SERVERSyntaxsnmp-serverParametersNoneModeGlobal Configuration modeDescriptionUse this command to activ

Seite 17

Chapter 64: SNMPv3 Commands984SNMP-SERVER ENGINEID LOCALSyntaxsnmp-server engineid local engine-id|defaultParametersengine-idSpecifies the SNMPv3 engi

Seite 18

AT-9000 Switch Command Line User’s Guide985SNMP-SERVER GROUPSyntaxsnmp-server group name auth|noauth|priv read readview|write writeviewParametersnameS

Seite 19

Chapter 64: SNMPv3 Commands986ExamplesThis example creates a group called “sta5west” with a minimum security level of privacy. The group has a read vi

Seite 20

AT-9000 Switch Command Line User’s Guide987SNMP-SERVER HOSTSyntaxsnmp-server host ipaddress informs|traps version 3 auth|noauth|priv usernameParameter

Seite 21

Chapter 64: SNMPv3 Commands988ExampleThis example configures SNMPv3 to send trap messages to an end node with the IPv4 address 149.157.192.12. The use

Seite 22

AT-9000 Switch Command Line User’s Guide989SNMP-SERVER USERSyntaxsnmp-server user username groupname [auth sha|md5 auth_password] [priv des priv_passw

Seite 23

Chapter 64: SNMPv3 Commands990 To create a user that has authentication but not privacy, include the AUTH keyword but not the PRIV keyword. To creat

Seite 24

AT-9000 Switch Command Line User’s Guide991SNMP-SERVER VIEWSyntaxsnmp-server view viewname oid excluded|includedParametersviewnameSpecifies the name o

Seite 25

Chapter 5: Temperature and Fan Control Overview74OverviewThe switch monitors the environmental status, such as temperature and voltage, and the status

Seite 26

Chapter 64: SNMPv3 Commands992This example creates the new view “AlliedTelesis” that limits the available MIB objects to those in the OID 1.3.6.1.4.1.

Seite 27

993Section XNetwork ManagementThis section contains the following chapters: Chapter 65, “sFlow Agent” on page 995 Chapter 66, “sFlow Agent Commands”

Seite 29

995Chapter 65sFlow AgentThis chapter contains the following topics: “Overview” on page 996 “Configuring the sFlow Agent” on page 998 “Configuring t

Seite 30

Chapter 65: sFlow Agent996OverviewThe sFlow agent allows the switch to gather data about the traffic on the ports and to send the data to an sFlow col

Seite 31

AT-9000 Switch Command Line User’s Guide997 Number of ingress and egress packets with errors Number of ingress packets with unknown protocolsTo conf

Seite 32

Chapter 65: sFlow Agent998Configuring the sFlow AgentThe command for defining the IP address of the sFlow collector is the SFLOW COLLECTOR IP command.

Seite 33

AT-9000 Switch Command Line User’s Guide999Configuring the PortsTo configure the ports so that their performance data is collected by the sFlow agent,

Seite 34

Chapter 65: sFlow Agent1000Configuring thePolling IntervalThe polling interval determines how frequently the agent queries the packet counters of the

Seite 35

AT-9000 Switch Command Line User’s Guide1001Enabling the sFlow AgentUse the SFLOW ENABLE command in the Global Configuration mode to activate the sFlo

Seite 36

AT-9000 Switch Command Line User’s Guide75Displaying the System Environmental StatusThe switch monitors the environmental status of the switch and any

Seite 37

Chapter 65: sFlow Agent1002Disabling the sFlow AgentTo stop the sFlow agent from collecting performance data on the ports on the switch and from sendi

Seite 38 - Document Conventions

AT-9000 Switch Command Line User’s Guide1003Displaying the sFlow AgentTo view the IP addresses and UDP port settings of the collectors as defined in t

Seite 39

Chapter 65: sFlow Agent1004Configuration ExampleHere is an example of how to configure the sFlow agent. The IP address of the sFlow collector is 152.2

Seite 40 - Contacting Allied Telesis

AT-9000 Switch Command Line User’s Guide1005This last command activates the sFlow agent on the switch.Depending on the amount of traffic on the ports

Seite 41 - Getting Started

Chapter 65: sFlow Agent1006

Seite 42

1007Chapter 66sFlow Agent CommandsThe sFlow agent commands are summarized in Table 92 and described in detail within the chapter.Table 92. sFlow Agent

Seite 43 - Interface

Chapter 66: sFlow Agent Commands1008NO SFLOW COLLECTOR IPSyntaxno sflow collector ip ipaddressParametersipaddressSpecifies the IP address of an sFlow

Seite 44 - Management Sessions

AT-9000 Switch Command Line User’s Guide1009NO SFLOW ENABLESyntaxno sflow enableParametersNoneModeGlobal Configuration modeDescriptionUse this command

Seite 45 - Web Browser Windows

Chapter 66: sFlow Agent Commands1010SFLOW COLLECTOR IPSyntaxsflow collector ip ipaddress [port udp_port]ParametersipaddressSpecifies the IP address of

Seite 46

AT-9000 Switch Command Line User’s Guide1011SFLOW ENABLESyntaxsflow enableParametersNoneModeGlobal Configuration modeDescriptionUse this command to ac

Seite 47 - Management Interfaces

Chapter 5: Temperature and Fan Control Overview76Controlling Eco-Mode LEDAlliedWare Plus products provide an Eco-Mode LED control to conserve addition

Seite 48 - Local Manager Account

Chapter 66: sFlow Agent Commands1012SFLOW POLLING-INTERVALSyntaxsflow polling-interval polling-intervalParameterspolling-intervalSpecifies the maximum

Seite 49 - AlliedWare Plus Command Modes

AT-9000 Switch Command Line User’s Guide1013This example removes sFlow monitoring on port 21 using the NO form of the command:awplus> enableawplus#

Seite 50

Chapter 66: sFlow Agent Commands1014SFLOW SAMPLING-RATESyntaxsflow sampling-rate sampling-rateParameterssampling-rateSpecifies the sampling rate on a

Seite 51

AT-9000 Switch Command Line User’s Guide1015This example disables packet sampling on port 7:awplus> enableawplus# configure terminalawplus(config)#

Seite 52 - Moving Down the Hierarchy

Chapter 66: sFlow Agent Commands1016SHOW SFLOWSyntaxshow sflow [database]ParametersNoneModePrivileged Exec modeDescriptionUse this command to display

Seite 53

AT-9000 Switch Command Line User’s Guide1017The fields are described in Table 93.Table 93. SHOW SFLOW CommandParameter DescriptionNumber of Collectors

Seite 54 - VLAN Command

Chapter 66: sFlow Agent Commands1018ExampleThis example displays the settings of the sFlow agent:awplus> enableawplus# show sflow

Seite 55

1019Chapter 67LLDP and LLDP-MEDThis chapter contains the following topics “Overview” on page 1020 “Enabling LLDP and LLDP-MED on the Switch” on page

Seite 56 - Moving Up the Hierarchy

Chapter 67: LLDP and LLDP-MED1020OverviewLink Layer Discovery Protocol (LLDP) and Link Layer Discovery Protocol for Media Endpoint Devices (LLDP-MED)

Seite 57 - DISABLE command

AT-9000 Switch Command Line User’s Guide1021MandatoryLLDP TLVsMandatory LLDP TLVs are sent by default on ports that send TLVs. The TLVs are defined in

Seite 58 - Port Numbers in Commands

77Chapter 6Temperature and Fan Control CommandsThe temperature and fan control commands are summarized in Table 6.Table 6. Temperature and Fan Control

Seite 59

Chapter 67: LLDP and LLDP-MED1022System capabilities The device’s router and bridge functions, and whether or not these functions are currently enable

Seite 60 - Combo Ports 25 to 28

AT-9000 Switch Command Line User’s Guide1023The switch does not verify whether a device connected to a port is LLDP-compatible prior to sending mandat

Seite 61 - Command Format

Chapter 67: LLDP and LLDP-MED1024Extended power managementThe following PoE information: Power Type field: Power Sourcing Entity (PSE). Power Source

Seite 62 - Startup Messages

AT-9000 Switch Command Line User’s Guide1025Enabling LLDP and LLDP-MED on the SwitchTo enable LLDP and LLDP-MED on the switch, use the LLDP RUN comman

Seite 63

Chapter 67: LLDP and LLDP-MED1026Configuring Ports to Only Receive LLDP and LLDP-MED TLVsThis is the first in a series of examples that show how to co

Seite 64

AT-9000 Switch Command Line User’s Guide1027Configuring Ports to Send Only Mandatory LLDP TLVsThis example illustrates how to configure the ports to r

Seite 65 - Starting a Management Session

Chapter 67: LLDP and LLDP-MED1028Configuring Ports to Send Optional LLDP TLVsThis example illustrates how to configure the ports to send optional LLDP

Seite 66

AT-9000 Switch Command Line User’s Guide1029Here are the commands to configure the ports to send the TLVs:awplus> enableEnter the Privileged Execut

Seite 67

Chapter 67: LLDP and LLDP-MED1030Configuring Ports to Send Optional LLDP-MED TLVsThis section explains how to configure the ports to send these option

Seite 68

AT-9000 Switch Command Line User’s Guide1031awplus# show lldp interface port1.0.3,port1.0.4Use the SHOW LLDP INTERFACE command to confirm the configur

Seite 69

Chapter 6: Temperature and Fan Control Commands78ECOFRIENDLY LEDSyntaxecofriendly ledParametersNoneModeGlobal Configuration modeDescriptionUse this co

Seite 70 - What to Configure First

Chapter 67: LLDP and LLDP-MED1032Configuring Ports to Send LLDP-MED Civic Location TLVsCivic location TLVs specify the physical addresses of network d

Seite 71 - Assigning a Name

AT-9000 Switch Command Line User’s Guide10333. Move to the Port Interface mode of the ports to which the entry is to be assigned. (A civic location en

Seite 72 - Management IP

Chapter 67: LLDP and LLDP-MED1034This series of commands adds the new location entry to port 14 and configures the port to include the location TLV in

Seite 73

AT-9000 Switch Command Line User’s Guide1035Configuring Ports to Send LLDP-MED Coordinate Location TLVsCoordinate location TLVs specify the locations

Seite 74 - Saving Your

Chapter 67: LLDP and LLDP-MED10363. Move to the Port Interface mode of the ports to which the entry is to be assigned. (A coordinate location entry ca

Seite 75 - Ending a Management Session

AT-9000 Switch Command Line User’s Guide1037This series of commands adds the entry to port 15 and configures the port to include the TLV in its advert

Seite 76

Chapter 67: LLDP and LLDP-MED1038awplus# show location coord-location interface port1.0.15Use the SHOW LOCATION command to confirm the configuration.a

Seite 77 - Basic Command Line Management

AT-9000 Switch Command Line User’s Guide1039Configuring Ports to Send LLDP-MED ELIN Location TLVsThis type of TLV specifies the location of a network

Seite 78 - Clearing the Screen

Chapter 67: LLDP and LLDP-MED1040This series of commands adds the entry to port 5 and configures the port to include the TLV in its advertisements:awp

Seite 79 - Displaying the On-line Help

AT-9000 Switch Command Line User’s Guide1041Removing LLDP TLVs from PortsTo stop ports from sending optional LLDP TLVs, use this command:no lldp tlv-s

Seite 80

AT-9000 Switch Command Line User’s Guide79NO ECOFRIENDLY LEDSyntaxno ecofriendly ledParametersNoneModeGlobal Configuration modeDescriptionUse this com

Seite 81

Chapter 67: LLDP and LLDP-MED1042Removing LLDP-MED TLVs from PortsTo remove optional LLDP-MED TLVs from ports, use the NO LLDP MED-TLV-SELECT command:

Seite 82

AT-9000 Switch Command Line User’s Guide1043Deleting LLDP-MED Location EntriesThe command for deleting LLDP-MED location entries from the switch is:no

Seite 83

Chapter 67: LLDP and LLDP-MED1044Disabling LLDP and LLDP-MED on the SwitchTo disable LLDP and LLDP-MED on the switch, use the NO LLDP RUN command in t

Seite 84

AT-9000 Switch Command Line User’s Guide1045Displaying General LLDP SettingsTo view the timers and other general LLDP and LLDP-MED settings, use the S

Seite 85 - ? (Question Mark Key)

Chapter 67: LLDP and LLDP-MED1046Displaying Port SettingsTo view the LLDP and LLDP-MED settings of the individual ports on the switch, use the SHOW LL

Seite 86

AT-9000 Switch Command Line User’s Guide1047Displaying or Clearing Neighbor InformationThere are two commands for displaying the information the switc

Seite 87 - CLEAR SCREEN

Chapter 67: LLDP and LLDP-MED1048This example clears the information the switch has received from all the neighbors:awplus> enableawplus# clear lld

Seite 88 - CONFIGURE TERMINAL

AT-9000 Switch Command Line User’s Guide1049Displaying Port TLVsTo view the TLVs of the individual ports on the switch, use the SHOW LLDP LOCAL-INFO I

Seite 89

Chapter 67: LLDP and LLDP-MED1050Displaying and Clearing StatisticsThe switch maintains LLDP and LLDP-MED performance statistics for the the individua

Seite 90

1051Chapter 68LLDP and LLDP-MED CommandsThe Link Layer Discovery Protocol commands are summarized in Table 100 and described in detail within the chap

Seite 91

Chapter 6: Temperature and Fan Control Commands80SHOW ECOFRIENDLYSyntaxshow ecofriendlyParametersNoneModePrivileged Exec modeDescriptionUse this comma

Seite 92

Chapter 68: LLDP and LLDP-MED Commands1052“LLDP NOTIFICATION-INTERVAL” on page 1066Global ConfigurationSets the notification interval, which is the mi

Seite 93

AT-9000 Switch Command Line User’s Guide1053“NO LLDP MED-TLV-SELECT” on page 1083Port Interface Stops ports from transmitting specified LLDP-MED TLVs.

Seite 94

Chapter 68: LLDP and LLDP-MED Commands1054CLEAR LLDP STATISTICSSyntaxclear lldp statistics [interface port]ParametersportSpecifies a port. You can spe

Seite 95

AT-9000 Switch Command Line User’s Guide1055CLEAR LLDP TABLESyntaxclear lldp table [interface port]ParametersportSpecifies a port. You can specify mor

Seite 96

Chapter 68: LLDP and LLDP-MED Commands1056LLDP HOLDTIME-MULTIPLIERSyntaxlldp holdtime-multiplier holdtime-multiplierParametersholdtime-multiplierSpeci

Seite 97

AT-9000 Switch Command Line User’s Guide1057LLDP LOCATIONSyntaxlldp location civic-location-id|coord-location-id|elin-location-id location_idParameter

Seite 98

Chapter 68: LLDP and LLDP-MED Commands1058This example adds the coordinate location ID 11 to port 2:awplus> enableawplus# configure terminalawplus(

Seite 99

AT-9000 Switch Command Line User’s Guide1059LLDP MANAGEMENT-ADDRESSSyntaxlldp management-address ipaddressParametersipaddressSpecifies an IP address.M

Seite 100

Chapter 68: LLDP and LLDP-MED Commands1060ExamplesThis example configures port 2 to transmit the IP address 149.122.54.2 as its management IP address

Seite 101 - Chapter 5

AT-9000 Switch Command Line User’s Guide1061LLDP MED-NOTIFICATIONSSyntaxlldp med-notificationsParametersNoneModePort Interface modeDescriptionUse this

Seite 102 - Overview

AT-9000 Switch Command Line User’s Guide81SHOW SYSTEM ENVIRONMENTSyntaxshow system environmentParametersNoneModePrivileged Exec modeDescriptionUse thi

Seite 103

Chapter 68: LLDP and LLDP-MED Commands1062LLDP MED-TLV-SELECTSyntaxlldp med-tlv-select capabilities|network-policy|location|power-management-ext|inven

Seite 104 - Controlling Eco-Mode LED

AT-9000 Switch Command Line User’s Guide1063ExamplesThis example configures ports 3 to 8 to send the inventory management TLV to their neighbors:awplu

Seite 105 - Commands

Chapter 68: LLDP and LLDP-MED Commands1064LLDP NON-STRICT-MED-TLV-ORDER-CHECKSyntaxlldp non-strict-med-tlv-order-checkParametersNoneModeGlobal Configu

Seite 106 - ECOFRIENDLY LED

AT-9000 Switch Command Line User’s Guide1065LLDP NOTIFICATIONSSyntaxlldp notificationsParametersNoneModePort Interface modeDescriptionUse this command

Seite 107 - NO ECOFRIENDLY LED

Chapter 68: LLDP and LLDP-MED Commands1066LLDP NOTIFICATION-INTERVALSyntaxlldp notification-interval intervalParametersintervalSpecifies the notificat

Seite 108 - SHOW ECOFRIENDLY

AT-9000 Switch Command Line User’s Guide1067LLDP REINITSyntaxlldp reinit delayParametersdelaySpecifies the re-initialization delay value. The range is

Seite 109 - SHOW SYSTEM ENVIRONMENT

Chapter 68: LLDP and LLDP-MED Commands1068LLDP RUNSyntaxlldp runParametersNoneModeGlobal Configuration modeDescriptionUse this command to activate LLD

Seite 110 - Parameter Description

AT-9000 Switch Command Line User’s Guide1069LLDP TIMERSyntaxlldp timer intervalParametersintervalSpecifies the transmit interval. The range is 5 to 32

Seite 111 - Basic Operations

Chapter 68: LLDP and LLDP-MED Commands1070LLDP TLV-SELECTSyntaxlldp tlv-select all|tlvParametersallConfigures a port to send all optional TLVs.tlvSpec

Seite 112

AT-9000 Switch Command Line User’s Guide1071To remove optional TLVs from ports, refer to “NO LLDP TLV-SELECT” on page 1087.Confirmation Command“SHOW L

Seite 113 - Basic Switch Management

AT-9000 Switch Command Line User’s Guide11Host Node Topology ...

Seite 114 - Adding a Name to the Switch

Chapter 6: Temperature and Fan Control Commands82ExampleThe following example displays environmental information for the switch:awplus# show system en

Seite 115 -  Contact: JordanB

Chapter 68: LLDP and LLDP-MED Commands1072ExamplesThis example configures ports 3 to 5 to transmit all the optional LLDP TLVs:awplus> enableawplus#

Seite 116 - Displaying Parameter Settings

AT-9000 Switch Command Line User’s Guide1073LLDP TRANSMIT RECEIVESyntaxlldp transmit receive|transmitParameterstransmitConfigures ports to send LLDP a

Seite 117

Chapter 68: LLDP and LLDP-MED Commands1074LLDP TX-DELAYSyntaxlldp tx-delay tx-delayParameterstx-delaySpecifies the transmission delay timer in seconds

Seite 118 - Pinging Network Devices

AT-9000 Switch Command Line User’s Guide1075LOCATION CIVIC-LOCATIONSyntaxlocation civic-location identifier id_numberParametersid_numberSpecifies an I

Seite 119 - Resetting the Switch

Chapter 68: LLDP and LLDP-MED Commands1076Here are the guidelines to using the location parameters: The country parameter must be two uppercase chara

Seite 120

AT-9000 Switch Command Line User’s Guide1077After you create a location entry, use “LLDP LOCATION” on page 1057 to assign the location entry to a port

Seite 121 - filename2

Chapter 68: LLDP and LLDP-MED Commands1078LOCATION COORD-LOCATIONSyntaxlocation coordinate-location identifier id_numberParametersid_numberSpecifies a

Seite 122

AT-9000 Switch Command Line User’s Guide1079This command is also used to remove parameter values from existing LLDP-MED coordinate location entries. T

Seite 123 - “SHOW BAUD-RATE” on page 128

Chapter 68: LLDP and LLDP-MED Commands1080ExamplesThis example creates a new coordinate location entry with these specifications.ID number: 16Latitud

Seite 124

AT-9000 Switch Command Line User’s Guide1081LOCATION ELIN-LOCATIONSyntaxlocation elin-location elin_id identifier id_numberParameterselin_idSpecifies

Seite 125

83Section IIBasic OperationsThis section contains the following chapters: Chapter 7, “Basic Switch Management” on page 85 Chapter 8, “Basic Switch M

Seite 126

Chapter 68: LLDP and LLDP-MED Commands1082NO LLDP MED-NOTIFICATIONSSyntaxno lldp med-notificationsParametersNoneModePort Interface modeDescriptionUse

Seite 127 - Configuring the Banners

AT-9000 Switch Command Line User’s Guide1083NO LLDP MED-TLV-SELECTSyntaxno lldp med-tlv-select capabilities|network-policy|location|power-management-e

Seite 128

Chapter 68: LLDP and LLDP-MED Commands1084ExamplesThis example stops port 8 from transmitting all LLDP-MED TLVs:awplus> enableawplus# configure ter

Seite 129

AT-9000 Switch Command Line User’s Guide1085NO LLDP NOTIFICATIONSSyntaxno lldp notificationsParametersNoneModePort Interface modeDescriptionUse this c

Seite 130

Chapter 68: LLDP and LLDP-MED Commands1086NO LLDP RUNSyntaxno lldp runParametersNoneModeGlobal Configuration modeDescriptionUse this command to disabl

Seite 131 - Chapter 8

AT-9000 Switch Command Line User’s Guide1087NO LLDP TLV-SELECTSyntaxno lldp tlv-select all|tlvParametersallRemoves all optional LLDP TLVs from a port.

Seite 132

Chapter 68: LLDP and LLDP-MED Commands1088NO LLDP TRANSMIT RECEIVESyntaxno lldp transmit|receiveParameterstransmitStops ports from sending LLDP and LL

Seite 133 - BANNER EXEC

AT-9000 Switch Command Line User’s Guide1089NO LOCATIONSyntaxno location civic-location|coord-location|elin-location identifier id_numberParametersciv

Seite 134

Chapter 68: LLDP and LLDP-MED Commands1090This example removes the ELIN location IDs 3 and 4:awplus> enableawplus# configure terminalawplus(config)

Seite 135 - BANNER LOGIN

AT-9000 Switch Command Line User’s Guide1091SHOW LLDPSyntaxshow lldpParametersNone.ModePrivileged Exec modeDescriptionUse this command to display gene

Seite 137 - BANNER MOTD

Chapter 68: LLDP and LLDP-MED Commands1092ExampleThe following example displays general LLDP settings:awplus# show lldpHold-time Multiplier The holdti

Seite 138

AT-9000 Switch Command Line User’s Guide1093SHOW LLDP INTERFACESyntaxshow lldp interface [port]ParametersportSpecifies a port, You can specify more th

Seite 139 - BAUD-RATE SET

Chapter 68: LLDP and LLDP-MED Commands1094ExamplesThis example displays the LLDP settings for all the ports on the switch:awplus# show lldp interfaceT

Seite 140 - CLOCK SET

AT-9000 Switch Command Line User’s Guide1095SHOW LLDP LOCAL-INFO INTERFACESyntaxshow lldp local-info [interface port]ParametersportSpecifies a port, Y

Seite 141 - ERASE STARTUP-CONFIG

Chapter 68: LLDP and LLDP-MED Commands1096Figure 181. SHOW LLDP LOCAL-INFO INTERFACE CommandFigure 182. SHOW LLDP LOCAL-INFO INTERFACE Command (contin

Seite 142 - EXEC-TIMEOUT

AT-9000 Switch Command Line User’s Guide1097SHOW LLDP NEIGHBORS DETAILSyntaxshow lldp neighbors detail [interface port]ParametersportSpecifies a port.

Seite 143

Chapter 68: LLDP and LLDP-MED Commands1098Figure 183. SHOW LLDP NEIGHBORS DETAIL CommandFigure 184. SHOW LLDP NEIGHBORS DETAIL Command (continued)The

Seite 144

AT-9000 Switch Command Line User’s Guide1099System Capabilities (Supported)The device’s functions supported by the switch. System Capabilities (Enable

Seite 145 - HOSTNAME

Chapter 68: LLDP and LLDP-MED Commands1100LLDP-MED Capabilities The LLDP-MED TLVs that are supported and enabled on the switch, and the device type, w

Seite 146 - LINE CONSOLE

AT-9000 Switch Command Line User’s Guide1101ExamplesThis example displays the information from all of the neighbors on the switch:awplus# show lldp ne

Seite 147 - LINE VTY

85Chapter 7Basic Switch ManagementThis chapter contains the following: “Adding a Name to the Switch” on page 86 “Adding Contact and Location Informa

Seite 148 - NO HOSTNAME

Chapter 68: LLDP and LLDP-MED Commands1102SHOW LLDP NEIGHBORS INTERFACESyntaxshow lldp neighbors interface [port]ParametersportSpecifies a port. You c

Seite 149

AT-9000 Switch Command Line User’s Guide1103ExamplesThis example displays a summary of the information from all the neighbors connected to the switch:

Seite 150

Chapter 68: LLDP and LLDP-MED Commands1104SHOW LLDP STATISTICSSyntaxshow lldp statisticsParametersNoneModeUser Exec mode and Privileged Exec modeDescr

Seite 151 - PING IPv6

AT-9000 Switch Command Line User’s Guide1105ExampleThe following example displays LLDP statistics for the switch:awplus# show lldp statisticsTLVs Unre

Seite 152

Chapter 68: LLDP and LLDP-MED Commands1106SHOW LLDP STATISTICS INTERFACESyntaxshow lldp statistics interface [port]ParametersportSpecifies a port. You

Seite 153

AT-9000 Switch Command Line User’s Guide1107ExamplesThis example displays the statistics for all the ports:awplus# show lldp statistics interfaceThis

Seite 154 - SERVICE MAXMANAGER

Chapter 68: LLDP and LLDP-MED Commands1108SHOW LOCATIONSyntaxshow location civic-location|coord-location|elin-location [identifier id-number|interface

Seite 155 - SHOW BANNER LOGIN

AT-9000 Switch Command Line User’s Guide1109ExamplesThe following example displays all the civic location entries on the switch:awplus# show location

Seite 156 - SHOW BAUD-RATE

Chapter 68: LLDP and LLDP-MED Commands1110

Seite 157 - SHOW CLOCK

1111Chapter 69Address Resolution Protocol (ARP)This chapter contains the following topics: “Overview” on page 1112 “Adding Static ARP Entries” on pa

Seite 158 - SHOW RUNNING-CONFIG

Chapter 7: Basic Switch Management86Adding a Name to the SwitchThe switch will be easier to identify if you assign it a name. The switch displays its

Seite 159 - SHOW SWITCH

Chapter 69: Address Resolution Protocol (ARP)1112OverviewThe Address Resolution Protocol (ARP) is used to associate an IPv4 address with a MAC address

Seite 160

AT-9000 Switch Command Line User’s Guide1113Adding Static ARP EntriesIn most cases, the ARP table can be populated dynamically; however, the switch al

Seite 161 - SHOW SYSTEM

Chapter 69: Address Resolution Protocol (ARP)1114Deleting Static and Dynamic ARP EntriesThe ARP cache contains two types of ARP entries: dynamic and s

Seite 162

AT-9000 Switch Command Line User’s Guide1115Displaying the ARP TableTo display the ARP table on the switch, use the SHOW ARP command in the User Exec

Seite 163 - SHOW USERS

Chapter 69: Address Resolution Protocol (ARP)1116

Seite 164

1117Chapter 70Address Resolution Protocol (ARP) CommandsThe ARP commands are summarized in Table 111 and described in detail within the chapter.Table

Seite 165 - SHOW VERSION

Chapter 70: Address Resolution Protocol (ARP) Commands1118ARP Syntaxarp ipaddress macaddress port_numberParametersipaddressSpecifies the IP address of

Seite 166 - SNMP-SERVER CONTACT

AT-9000 Switch Command Line User’s Guide1119ExampleThe following example creates an ARP entry for the IP address 192.168.1.3 and the MAC address 7a:54

Seite 167 - SNMP-SERVER LOCATION

Chapter 70: Address Resolution Protocol (ARP) Commands1120CLEAR ARP-CACHESyntaxclear arp-cacheParametersNoneModesUser Exec mode and Privileged Exec mo

Seite 168 - SYSTEM TERRITORY

AT-9000 Switch Command Line User’s Guide1121NO ARP (IP ADDRESS)Syntaxno arp ipaddressParametersipaddressSpecifies the IP address of a static ARP entry

Seite 169

AT-9000 Switch Command Line User’s Guide87Adding Contact and Location InformationThe commands for assigning the switch contact and location informatio

Seite 170

Chapter 70: Address Resolution Protocol (ARP) Commands1122SHOW ARPSyntaxshow arpParametersNoneModesUser Exec mode and Privileged Exec modeDescriptionU

Seite 171 - Port Parameters

AT-9000 Switch Command Line User’s Guide1123ExampleThe following example displays the ARP entries in the ARP cache on the switch:awplus# show arpType

Seite 172 - Adding Descriptions

Chapter 70: Address Resolution Protocol (ARP) Commands1124

Seite 173

1125Chapter 71RMONThis chapter contains the following topics: “Overview” on page 1126 “RMON Port Statistics” on page 1127 “RMON Histories” on page

Seite 174 - Chapter 9: Port Parameters

Chapter 71: RMON1126OverviewThe RMON (Remote MONitoring) MIB is used with SNMP applications to monitor the operations of network devices. The switch s

Seite 175

AT-9000 Switch Command Line User’s Guide1127RMON Port StatisticsTo view port statistics using an SNMP program and the RMON section in the MIB, you mus

Seite 176 - Enabling or Disabling Ports

Chapter 71: RMON1128awplus(config-if)# rmon collection stats 16awplus(config-if)# exitawplus(config)# interface port1.0.20awplus(config-if)# rmon coll

Seite 177

AT-9000 Switch Command Line User’s Guide1129RMON HistoriesRMON histories are snapshots of port statistics. They are taken by the switch at predefined

Seite 178

Chapter 71: RMON1130snapshot every minute for five minutes on a port, you specify five buckets (one bucket for each minute) and an interval of sixty s

Seite 179

AT-9000 Switch Command Line User’s Guide1131Here is an example of the information.Figure 192. SHOW RMON HISTORY CommandThe fields are defined in Table

Seite 180

Chapter 7: Basic Switch Management88Displaying Parameter SettingsTo display the current parameter settings on the switch, use the SHOW RUNNING-CONFIG

Seite 181 - Resetting Ports

Chapter 71: RMON1132RMON AlarmsRMON alarms are used to generate alert messages when packet activity on designated ports rises above or falls below spe

Seite 182

AT-9000 Switch Command Line User’s Guide1133The following sections explain how to create and manage the various elements of an alarm: “Creating RMON

Seite 183

Chapter 71: RMON1134The owner parameter is useful in situations where more than one person is managing the switch. You can use it to identify who crea

Seite 184

AT-9000 Switch Command Line User’s Guide1135The range is 1 to 65535 seconds.The DELTA and ABSOLUTE parameters define the type of change that has to oc

Seite 185

Chapter 71: RMON1136The next series of steps creates the event, which enters a message in the event log whenever the thresholds are crossed:Here are t

Seite 186

AT-9000 Switch Command Line User’s Guide1137Here are the steps to creating the alarm:Creating anAlarm - Example2This example creates an alarm that mon

Seite 187

Chapter 71: RMON1138Phase 2: Adding the RMON Statistics Group to the PortThe steps here add a statistics group to port 20 so that the port statistics

Seite 188 - Displaying Port

AT-9000 Switch Command Line User’s Guide1139Phase 3: Creating the EventThe event in this example is to send an SNMP trap and to log a message in the e

Seite 189

Chapter 71: RMON1140awplus# show rmon alarmUse the SHOW RMON ALARM command to verify the new alarm.

Seite 190 - Displaying SFP Information

1141Chapter 72RMON CommandsThe RMON commands are summarized in Table 114 and described in detail within the chapter.Table 114. RMON CommandsCommand Mo

Seite 191 - Port Parameter Commands

AT-9000 Switch Command Line User’s Guide89Manually Setting the Date and TimeTo manually set the date and time on the switch, use the CLOCK SET command

Seite 192

Chapter 72: RMON Commands1142“SHOW RMON HISTORY” on page 1162Privileged Exec Displays the RMON history groups that are assigned to the ports on the sw

Seite 193 - Command Mode Description

AT-9000 Switch Command Line User’s Guide1143NO RMON ALARMSyntaxno rmon alarm alarm_idParametersalarm_idSpecifies the ID number of the alarm you want t

Seite 194 - BACKPRESSURE

Chapter 72: RMON Commands1144NO RMON COLLECTION HISTORYSyntaxno rmon collection history collection_idParameterscollection_idSpecifies the ID number of

Seite 195

AT-9000 Switch Command Line User’s Guide1145NO RMON COLLECTION STATSSyntaxno rmon collection stats stats_idParametersstats_idSpecifies the ID number o

Seite 196

Chapter 72: RMON Commands1146NO RMON EVENTSyntaxno rmon event event_idParametersevent_idSpecifies the ID number of the event you want to delete from t

Seite 197 - CLEAR PORT COUNTER

AT-9000 Switch Command Line User’s Guide1147RMON ALARMSyntaxrmon alarm alarm_id oid.stats_id interval interval delta|absolute rising-threshold rising-

Seite 198 - DESCRIPTION

Chapter 72: RMON Commands1148rising_event_idSpecifies the ID number of the event the switch is to perform when the falling threshold is crossed. The e

Seite 199

AT-9000 Switch Command Line User’s Guide1149Confirmation Command“SHOW RMON ALARM” on page 1158ExampleThis example creates an RMON alarm that monitors

Seite 200

Chapter 72: RMON Commands1150RMON COLLECTION HISTORYSyntaxrmon collection history history_id [buckets buckets] [interval interval] [owner owner]Parame

Seite 201

AT-9000 Switch Command Line User’s Guide1151RMON statistics histories are only viewable from an SNMP application program. There are no commands in the

Seite 202 - EGRESS-RATE-LIMIT

Chapter 7: Basic Switch Management90Pinging Network DevicesIf the switch is unable to communicate with a network device, such as a syslog server or a

Seite 203 - FCTRLLIMIT

Chapter 72: RMON Commands1152RMON COLLECTION STATSSyntaxrmon collection stats stats_id [owner owner]Parametersstats_idSpecifies the ID number of a new

Seite 204 - FLOWCONTROL

AT-9000 Switch Command Line User’s Guide1153RMON EVENT LOGSyntaxrmon event event_id log description description [owner owner]Parametersevent_idSpecifi

Seite 205

Chapter 72: RMON Commands1154RMON EVENT LOG TRAPSyntaxrmon event event_id log trap community_string [description description] [owner owner]Parameterse

Seite 206

AT-9000 Switch Command Line User’s Guide1155ExampleThis example creates an event for RMON alarms with an ID of 2, a community string of “station43a,”

Seite 207 - HOLBPLIMIT

Chapter 72: RMON Commands1156RMON EVENT TRAPSyntaxrmon event event_id trap community_string [description description] [owner owner]Parametersevent_idS

Seite 208

AT-9000 Switch Command Line User’s Guide1157ExampleThe following example creates an event with an ID of 4, a community string of “st_west8,” and a des

Seite 209 - NO EGRESS-RATE-LIMIT

Chapter 72: RMON Commands1158SHOW RMON ALARMSyntaxshow rmon alarmParametersNoneModePrivileged Exec modeDescriptionUse this command to display the RMON

Seite 210 - NO FLOWCONTROL

AT-9000 Switch Command Line User’s Guide1159The fields are described in Table 116.ExampleThe following example displays the RMON alarms on the switch:

Seite 211 - NO SHUTDOWN

Chapter 72: RMON Commands1160SHOW RMON EVENTSyntaxshow rmon eventParametersNoneModePrivileged Exec modeDescriptionUse this command to display the RMON

Seite 212 - NO SNMP TRAP LINK-STATUS

AT-9000 Switch Command Line User’s Guide1161ExampleThe following example displays the RMON events on the switch:awplus# show rmon eventEvent type (con

Seite 213 - NO STORM-CONTROL

AT-9000 Switch Command Line User’s Guide91Resetting the SwitchTo reset the switch, use either the REBOOT or RELOAD command in the Privileged Exec mode

Seite 214 - POLARITY

Chapter 72: RMON Commands1162SHOW RMON HISTORYSyntaxshow rmon historyParametersNoneModePrivileged Exec modeDescriptionUse this command to display the

Seite 215

AT-9000 Switch Command Line User’s Guide1163ExampleThe following example displays the history groups that are assigned to the ports on the switch:awpl

Seite 216

Chapter 72: RMON Commands1164SHOW RMON STATISTICSSyntaxshow rmon statisticsParametersNoneModePrivileged Exec modeDescriptionUse this command to displa

Seite 217 - RENEGOTIATE

1165Chapter 73Advanced Access Control Lists (ACLs)This chapter describes the following topics: “Overview” on page 1166 “Creating ACLs” on page 1169

Seite 218

Chapter 73: Advanced Access Control Lists (ACLs)1166OverviewAccess Control Lists (ACLs) act as filters to control the ingress packets on ports. They a

Seite 219 - SHOW FLOWCONTROL INTERFACE

AT-9000 Switch Command Line User’s Guide1167Actions The action defines the response to packets that match the filtering criterion of the ACL. There ar

Seite 220

Chapter 73: Advanced Access Control Lists (ACLs)1168Guidelines Here are the ACL guidelines: An ACL can have a permit, deny, or copy-to-mirror action.

Seite 221 - SHOW INTERFACE

AT-9000 Switch Command Line User’s Guide1169Creating ACLsThis section provides examples of how to create all of the ACL types. See the following: “Cr

Seite 222 - Interface Port number

Chapter 73: Advanced Access Control Lists (ACLs)1170Numbered IPv4 ACL with IP Packets ExamplesThis is the command format for creating ACLs that filter

Seite 223

AT-9000 Switch Command Line User’s Guide1171 host ipaddress— Matches packets with a specified IPv4 address and is an alternative to the IPADRESS/MASK

Seite 224

Contents12NO BOOT CONFIG-FILE ...

Seite 225 - SHOW INTERFACE BRIEF

Chapter 7: Basic Switch Management92Restoring the Default Settings to the SwitchTo restore the default settings to the switch, delete or rename the ac

Seite 226

Chapter 73: Advanced Access Control Lists (ACLs)1172deny ACL for the denied traffic flow. This is illustrated in the example in Table 124 on page 1172

Seite 227 - SHOW INTERFACE STATUS

AT-9000 Switch Command Line User’s Guide1173NoteThe permit ACLS are added to the ports before the deny ACL to ensure that packets are compared against

Seite 228

Chapter 73: Advanced Access Control Lists (ACLs)1174Here is an example of an ACL that filters tagged packets. See Table 126. It blocks all tagged pack

Seite 229 - Parameter

AT-9000 Switch Command Line User’s Guide1175is only necessary when you want a port to forward a subset of packets that are otherwise discarded. deny—

Seite 230

Chapter 73: Advanced Access Control Lists (ACLs)1176Numbered IPv4 ACL with Protocol Packets ExampleThis is the command format for creating Numbered IP

Seite 231

AT-9000 Switch Command Line User’s Guide1177The VLAN parameter determines if an ACL filters VLANs. You use the parameter to specify the VID. You can s

Seite 232 - SHOW RUNNING-CONFIG INTERFACE

Chapter 73: Advanced Access Control Lists (ACLs)1178The SRC_IPADDRESS and DST_IPADDRESS parameters specify the source and destination IPv4 addresses.

Seite 233 - SHOW STORM-CONTROL

AT-9000 Switch Command Line User’s Guide1179The following example configures two Numbered IPv4 ACLs. ACL 3017 permits packets from TCP port 67 to 87 o

Seite 234

Chapter 73: Advanced Access Control Lists (ACLs)1180together with the port mirror feature, explained in Chapter 21, “Port Mirror” on page 379.The SRC_

Seite 235 - SHOW SYSTEM PLUGGABLE

AT-9000 Switch Command Line User’s Guide1181The VLAN parameter determines if an ACL filters VLANs. You use the parameter to specify the VID. You can s

Seite 236 - SHOW SYSTEM PLUGGABLE DETAIL

AT-9000 Switch Command Line User’s Guide93Another way to delete the file is with the ERASE STARTUP-CONFIG command, also in the Privileged Exec mode. T

Seite 237 - SHUTDOWN

Chapter 73: Advanced Access Control Lists (ACLs)1182 copy-to-mirror— Copies all ingress packets that match the ACL to the destination port of the mir

Seite 238 - SNMP TRAP LINK-STATUS

AT-9000 Switch Command Line User’s Guide1183The example in Table 131 configures port 19 to reject packets containing destination MAC addresses startin

Seite 239

Chapter 73: Advanced Access Control Lists (ACLs)1184Assigning ACLs to PortsBefore you can assign an ACL to a port, you must first create an ACL. The c

Seite 240

AT-9000 Switch Command Line User’s Guide1185In this example, ports 12 and 13 are assigned an ACL, ID number 3075, that blocks all untagged ingress pac

Seite 241 - STORM-CONTROL

Chapter 73: Advanced Access Control Lists (ACLs)1186awplus(config)# interface port1.0.7Move to the Port Interface mode for port 7.awplus(config_if)# m

Seite 242

AT-9000 Switch Command Line User’s Guide1187Removing ACLs from PortsThe command that you use to remove an ACL from a port depends on which type of ACL

Seite 243 - Power Over Ethernet

Chapter 73: Advanced Access Control Lists (ACLs)1188This example removes a MAC ACL with an ID number of 4037 from port 5:Table 135. Removing MAC Addre

Seite 244

AT-9000 Switch Command Line User’s Guide1189Restricting Remote AccessYou can access the switch remotely through the VTY lines. Unrestricted remote acc

Seite 245 - Prioritization

Chapter 73: Advanced Access Control Lists (ACLs)1190Assigning MACACLs to VTYLinesThis example creates two MAC ACLs. The first MAC ACL created, with an

Seite 246 - Enabling and Disabling PoE

AT-9000 Switch Command Line User’s Guide1191Assigning NamedIPv4 and IPv6ACLs to VTYLinesWhen you create a named IPv4 or IPv6 ACL, you enter the comman

Seite 247

Chapter 7: Basic Switch Management94Setting the Baud Rate of the Console PortThe Console port is used for local management of the switch. To set its b

Seite 248

Chapter 73: Advanced Access Control Lists (ACLs)1192Assigning Named IPv6 ACLs to VTY LinesThis example creates a Named IPv6 ACL, called “deny-all-but-

Seite 249 - Prioritizing Ports

AT-9000 Switch Command Line User’s Guide1193awplus(config)# ipv6 access-list deny-all-but-oneCreates a Named IPv6 ACL call “deny-all-but-one-ipv6” and

Seite 250

Chapter 73: Advanced Access Control Lists (ACLs)1194Unrestricting Remote Access To restore unrestricted remove access to VTY lines through the Telnet

Seite 251 - Managing Legacy PDs

AT-9000 Switch Command Line User’s Guide1195Deleting Numbered IP and MAC Address ACLsThe NO ACCESS-LIST command in the Global Configuration mode is th

Seite 252 - Monitoring Power Consumption

Chapter 73: Advanced Access Control Lists (ACLs)1196Displaying the ACLsThere are several ways of displaying information about ACLs on the switch. You

Seite 253 - Displaying PoE Information

AT-9000 Switch Command Line User’s Guide1197awplus# show interface port1.0.1-port1.0.5 access-groupFigure 198. SHOW INTERFACE ACCESS-GROUP CommandDisp

Seite 254

Chapter 73: Advanced Access Control Lists (ACLs)1198

Seite 255 - Power Over Ethernet Commands

1199Chapter 74ACL CommandsThe Access Control List (ACL) commands are summarized in Table 143 and described in detail within the chapter.Table 143. Acc

Seite 256

Chapter 74: ACL Commands1200“NO MAC ACCESS-GROUP” on page 1231Port Interface Removes MAC address ACLs from ports on the switch.“SHOW ACCESS-LIST” on p

Seite 257

AT-9000 Switch Command Line User’s Guide1201ACCESS-CLASSSyntaxaccess-class <3000 - 3699>|<4000 - 4699>Parameters3000 - 3699Specifies the I

Seite 258 - NO POWER-INLINE ALLOW-LEGACY

AT-9000 Switch Command Line User’s Guide95NoteThe baud rate is the only adjustable parameter on the Console port.For reference information, refer to “

Seite 259 - NO POWER-INLINE DESCRIPTION

Chapter 74: ACL Commands1202ExampleThis example assigns the switch an IP address of 10.0.0.20/24. It creates a Numbered ACL with an ID of 3022 that al

Seite 260 - NO POWER-INLINE ENABLE

AT-9000 Switch Command Line User’s Guide1203ACCESS-GROUPSyntaxaccess-group id_numberParametersid_numberSpecifies the ID number of an access control li

Seite 261 - NO POWER-INLINE MAX

Chapter 74: ACL Commands1204ExamplesThis example adds an IP ACL with an ID of 3022 to port 15:awplus> enableawplus# configure terminalawplus(config

Seite 262 - NO POWER-INLINE PRIORITY

AT-9000 Switch Command Line User’s Guide1205ACCESS-LIST (MAC Address)Syntaxaccess-list id_number action src_mac_address|any src_mac_mask dst_mac_addre

Seite 263

Chapter 74: ACL Commands1206dst_mac_addressSpecifies the destination MAC address of the ingress packets. Choose from the following options:dst_mac_add

Seite 264 - NO SERVICE POWER-INLINE

AT-9000 Switch Command Line User’s Guide1207awplus(config_if)# mac access-group 4002awplus(config_if)# mac access-group 4003awplus(config_if)# mac acc

Seite 265

Chapter 74: ACL Commands1208ACCESS-LIST ICMPSyntaxaccess-list id_number action icmp src_ipaddress dst_ipaddress [vlan vid]Parametersid_numberSpecifies

Seite 266 - POWER-INLINE ALLOW-LEGACY

AT-9000 Switch Command Line User’s Guide1209ipaddress/mask: Matches packets that have a destination IP address of a specific subnet or end node. host

Seite 267 - POWER-INLINE DESCRIPTION

Chapter 74: ACL Commands1210This example adds a deny access list to ports 4 and 5 to discard all untagged ingress packets that are ICMP, from the 152.

Seite 268 - POWER-INLINE ENABLE

AT-9000 Switch Command Line User’s Guide1211ACCESS-LIST IPSyntaxaccess-list id_number action ip src_ipaddress dst_ipaddress [vlan vid]Parametersid_num

Seite 269 - POWER-INLINE MAX

Chapter 7: Basic Switch Management96Configuring the Management Session TimersYou should always conclude a management session by logging off so that if

Seite 270 - POWER-INLINE PRIORITY

Chapter 74: ACL Commands1212dst_ipaddress: Specifies the destination IP address of the ingress packets the access list should filter. Here are the pos

Seite 271

AT-9000 Switch Command Line User’s Guide1213This example creates a deny access list, ID number 3095, that discards all untagged ingress packets that h

Seite 272 - POWER-INLINE USAGE-THRESHOLD

Chapter 74: ACL Commands1214This example configures ports 22 and 23 to accept only untagged ingress packets containing destination addresses in the 14

Seite 273 - SERVICE POWER-INLINE

AT-9000 Switch Command Line User’s Guide1215ACCESS-LIST PROTOSyntaxaccess-list id_number action proto protocol_number src_ipaddress dst_ipaddress [vla

Seite 274 - SHOW POWER-INLINE

Chapter 74: ACL Commands1216dst_ipaddressSpecifies the destination IP address of the ingress packets the access list should filter. Choose one of the

Seite 275

AT-9000 Switch Command Line User’s Guide12179 IGP (Interior Gateway Protocol) (IANA)11 Network Voice Protocol (RFC741)17 UDP (User Datagram Protocol)

Seite 276

Chapter 74: ACL Commands1218Confirmation Commands“SHOW ACCESS-LIST” on page 1232 and “SHOW INTERFACE ACCESS-GROUP” on page 1234ExamplesThis example ad

Seite 277

AT-9000 Switch Command Line User’s Guide1219awplus(config_if)# access-group 3011awplus(config_if)# endawplus# show access-listawplus# show interface p

Seite 278

Chapter 74: ACL Commands1220ACCESS-LIST TCPSyntaxaccess-list id_number action tcp src_ipaddress eq|lt|gt|ne|range src_tcp_port dst_ipaddress eq|lt|gt|

Seite 279 - SHOW POWER-INLINE INTERFACE

AT-9000 Switch Command Line User’s Guide1221ltMatches packets that are less than the TCP port number specified by the SRC_TCP_PORT or DST_TCP_PORT par

Seite 280

AT-9000 Switch Command Line User’s Guide97Both the first_line_id and the last_line_id parameters have value of 0 to 9. You can specify one VTY line or

Seite 281

Chapter 74: ACL Commands1222ModeGlobal Configuration modeDescriptionUse this command to create access control lists that filter ingress packets based

Seite 282

AT-9000 Switch Command Line User’s Guide1223This example creates an ACL that causes port 14 to discard all tagged ingress TCP packets with the VID 27,

Seite 283

Chapter 74: ACL Commands1224ACCESS-LIST UDPSyntaxaccess-list id_number action udp src_ipaddress eq|lt|gt|ne|range src_udp_port dst_ipaddress eq|lt|gt|

Seite 284

AT-9000 Switch Command Line User’s Guide1225ltMatches packets that are less than the UDP port number specified by the SRC_UDP_PORT or DST_UDP_PORT par

Seite 285 - Chapter 13

Chapter 74: ACL Commands1226ModeGlobal Configuration modeDescriptionUse this command to create access control lists that filter ingress packets based

Seite 286

AT-9000 Switch Command Line User’s Guide1227This example defines an ACL that causes port 18 to discard all untagged ingress packets that have source a

Seite 287

Chapter 74: ACL Commands1228MAC ACCESS-GROUPSyntaxmac access-group id_numberParametersid_numberSpecifies the ID number of a MAC address access control

Seite 288

AT-9000 Switch Command Line User’s Guide1229NO ACCESS-LISTSyntaxno access-list id_numberParametersid_numberSpecifies the ID number of an access list y

Seite 289 - Management

Chapter 74: ACL Commands1230NO ACCESS-GROUPSyntaxno access-group id_numberParametersid_numberSpecifies the ID number of an access list. The range is 3

Seite 290

AT-9000 Switch Command Line User’s Guide1231NO MAC ACCESS-GROUPSyntaxno mac access-group id_numberParametersid_numberSpecifies the ID number of a MAC

Seite 291 - Default Gateway

Chapter 7: Basic Switch Management98Setting the Maximum Number of Manager SessionsThe switch supports up to three manager sessions simultaneously so t

Seite 292 - Address and

Chapter 74: ACL Commands1232SHOW ACCESS-LISTSyntaxshow access-list [<3000-3699>|<4000-4699>|<list-name>]Parameters<3000-3699>I

Seite 293 - Displaying an

AT-9000 Switch Command Line User’s Guide1233ExampleThis example displays Numbered IP, MAC, and Named IP ACLs:awplus# show access-listFigure 200. SHOW

Seite 294 - Adding an IPv6

Chapter 74: ACL Commands1234SHOW INTERFACE ACCESS-GROUPSyntaxshow interface port access-groupParametersportSpecifies a port number. You can specify mo

Seite 295

1235Chapter 75Quality of Service (QOS) CommandsThe Quality of Service (QoS) commands are summarized in Table 145.Table 145. Quality of Service Command

Seite 296 - Deleting an IPv6

Chapter 75: Quality of Service (QOS) Commands1236 Section X: Network Management“SHOW MLS QOS MAPS COS-QUEUE” on page 1252Privileged Exec Displays the

Seite 297

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1237MLS QOS ENABLESyntaxmls qos enableParametersNone.ModeGlobal Configuration mo

Seite 298

Chapter 75: Quality of Service (QOS) Commands1238 Section X: Network ManagementMLS QOS MAP COS-QUEUESyntaxmls qos map cos-queue cos_priority to egress

Seite 299

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1239awplus(config-if)# mls qos trust cosawplus(config-if)# mls qos map cos-queue

Seite 300

Chapter 75: Quality of Service (QOS) Commands1240 Section X: Network ManagementMLS QOS MAP DSCP-QUEUESyntaxmls qos map dscp-queue dscp_priority to egr

Seite 301 - CLEAR IPV6 NEIGHBORS

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1241awplus(config-if)# mls qos map dscp-queue 11 to 7awplus(config-if)# mls qos

Seite 302 - IP ADDRESS

AT-9000 Switch Command Line User’s Guide99Configuring the BannersThe switch has banner messages you may use to identify the switch or to display other

Seite 303

Chapter 75: Quality of Service (QOS) Commands1242 Section X: Network ManagementMLS QOS QUEUESyntaxmls qos queue priorityParameterspriority Specifies a

Seite 304 - IP ADDRESS DHCP

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1243MLS QOS SET COSSyntaxmls qos set cos priorityParameterspriority Specifies a

Seite 305

Chapter 75: Quality of Service (QOS) Commands1244 Section X: Network ManagementMLS QOS SET DSCPSyntaxmls qos set dscp priorityParameterspriority Speci

Seite 306 - IP ROUTE

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1245MLS QOS TRUST COSSyntaxmls qos trust cosParametersNone.ModePort Interface mo

Seite 307 - 143.87.132.45:

Chapter 75: Quality of Service (QOS) Commands1246 Section X: Network ManagementMLS QOS TRUST DSCPSyntaxmls qos trust dscpParametersNone.ModePort Inter

Seite 308 - IPV6 ADDRESS

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1247NO MLS QOS ENABLESyntaxno mls qos enableParametersNone.ModeGlobal Configurat

Seite 309

Chapter 75: Quality of Service (QOS) Commands1248 Section X: Network ManagementNO WRR-QUEUE WEIGHTSyntaxno wrr-queue weightParametersNone.ModePort Int

Seite 310 - IPV6 ROUTE

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1249SHOW MLS QOS INTERFACESyntaxshow mls qos interface portParametersport Specif

Seite 311 - 45ab:672:934c::78:17cb:

Chapter 75: Quality of Service (QOS) Commands1250 Section X: Network ManagementFigure 203. SHOW MLS QOS INTERFACE Command - Strict Priority (continued

Seite 312 - NO IP ADDRESS

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1251The fields in the display are described in Table 146.ExampleThis example dis

Seite 313 - NO IP ADDRESS DHCP

Chapter 7: Basic Switch Management100The commands for setting the banners are located in the Global Configuration mode with the exception of the SHOW

Seite 314 - NO IP ROUTE

Chapter 75: Quality of Service (QOS) Commands1252 Section X: Network ManagementSHOW MLS QOS MAPS COS-QUEUESyntaxshow mls qos maps cos-queue interface

Seite 315 - NO IPV6 ADDRESS

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1253SHOW MLS QOS MAPS DSCP-QUEUESyntaxshow mls qos maps dscp-queue interface por

Seite 316 - NO IPV6 ROUTE

Chapter 75: Quality of Service (QOS) Commands1254 Section X: Network ManagementFigure 206. SHOW MLS QOS MAPS DSCP-QUEUE CommandThe mappings of DSCP pr

Seite 317 - SHOW IP INTERFACE

AT-9000 Switch Command Line User’s GuideSection X: Network Management 1255WRR-QUEUE WEIGHTSyntaxwrr-queue weight weightsParametersweights Specifies th

Seite 318 - SHOW IP ROUTE

Chapter 75: Quality of Service (QOS) Commands1256 Section X: Network Managementawplus(config)# interface port1.0.3awplus(config-if)# wrr-queue weight

Seite 319

1257Section XIManagement SecurityThis section contains the following chapters: Chapter 76, “Local Manager Accounts” on page 1259 Chapter 77, “Local

Seite 321 - SHOW IPV6 ROUTE

1259Chapter 76Local Manager AccountsThis chapter provides the following topics: “Overview” on page 1260 “Creating Local Manager Accounts” on page 12

Seite 322

Chapter 76: Local Manager Accounts1260OverviewEach AT-9000 Series switch is pre-configured at the factory with one default manager account. The factor

Seite 323 - Chapter 15

AT-9000 Switch Command Line User’s Guide1261Figure 207. Password Prompt for Command Mode RestrictionIf the manager enters the correct password, the Pr

Seite 324

AT-9000 Switch Command Line User’s Guide101To remove messages without assigning new messages, use the NO versions of the commands. This example remove

Seite 325 - SNTP Server

Chapter 76: Local Manager Accounts1262Password encryption is activated with the SERVICE PASSWORD-ENCRYPTION command and deactivated with the NO SERVIC

Seite 326

AT-9000 Switch Command Line User’s Guide1263Creating Local Manager AccountsThe command for creating local manager accounts is the USERNAME command in

Seite 327

Chapter 76: Local Manager Accounts1264Passwords entered in encrypted form remain encrypted in the running configuration even if you disable password e

Seite 328 - Disabling the SNTP Client

AT-9000 Switch Command Line User’s Guide1265Deleting Local Manager AccountsTo delete local manager accounts from the switch, use the NO USERNAME comma

Seite 329 - Displaying the SNTP Client

Chapter 76: Local Manager Accounts1266Activating Command Mode Restriction and Creating the Special PasswordCommand mode restriction is a security feat

Seite 330 - Displaying the Date and Time

AT-9000 Switch Command Line User’s Guide1267Deactivating Command Mode Restriction and Deleting the Special PasswordThe command for deactivating comman

Seite 331 - SNTP Client Commands

Chapter 76: Local Manager Accounts1268Activating or Deactivating Password EncryptionPassword encryption controls the manner in which the switch stores

Seite 332 - CLOCK SUMMER-TIME

AT-9000 Switch Command Line User’s Guide1269Displaying the Local Manager AccountsTo view the local accounts on the switch, use “SHOW RUNNING-CONFIG” o

Seite 333 - CLOCK TIMEZONE

Chapter 76: Local Manager Accounts1270

Seite 334 - NO CLOCK SUMMER-TIME

1271Chapter 77Local Manager Account CommandsThe local manager account commands are summarized in Table 147 and described in detail within the chapter.

Seite 335 - NO NTP PEER

AT-9000 Switch Command Line User’s Guide13Guidelines...

Seite 336 - NTP PEER

Chapter 7: Basic Switch Management102

Seite 337 - PURGE NTP

Chapter 77: Local Manager Account Commands1272ENABLE PASSWORDSyntaxenable password [8] passwordParameters8Specifies that the password is encrypted.pas

Seite 338

AT-9000 Switch Command Line User’s Guide1273awplus> enableawplus# configure terminalawplus(config)# enable password 8 1255bbf963118fcf750aca356d35f

Seite 339 - SHOW NTP ASSOCIATIONS

Chapter 77: Local Manager Account Commands1274NO ENABLE PASSWORDSyntaxno enable passwordParametersNoneModeGlobal Configuration modeDescriptionUse this

Seite 340

AT-9000 Switch Command Line User’s Guide1275NO SERVICE PASSWORD-ENCRYPTIONSyntaxno service password-encryptionParametersNoneModeGlobal Configuration m

Seite 341 - SHOW NTP STATUS

Chapter 77: Local Manager Account Commands1276NO USERNAMESyntaxno username nameParametersnameSpecifies the name of the manager account you want to del

Seite 342

AT-9000 Switch Command Line User’s Guide1277SERVICE PASSWORD-ENCRYPTIONSyntaxservice password-encryptionParametersNoneModeGlobal Configuration modeDes

Seite 343

Chapter 77: Local Manager Account Commands1278USERNAMESyntaxusername name privilege level password [8] passwordParametersnameSpecifies the name of a n

Seite 344

AT-9000 Switch Command Line User’s Guide1279ExamplesThis example creates a manager account for the user, allen. The privilege level is 15 to give the

Seite 345

Chapter 77: Local Manager Account Commands1280

Seite 346 - Adding Static MAC Addresses

1281Chapter 78Telnet ServerThis chapter provides the following topics: “Overview” on page 1282 “Enabling the Telnet Server” on page 1283 “Disabling

Seite 347

103Chapter 8Basic Switch Management CommandsThe basic switch management commands are summarized in Table 8.Table 8. Basic Switch Management CommandsCo

Seite 348 - Deleting MAC Addresses

Chapter 78: Telnet Server1282OverviewThe switch comes with a Telnet server so that you can remotely manage the device from Telnet clients on your netw

Seite 349

AT-9000 Switch Command Line User’s Guide1283Enabling the Telnet ServerTo enable the server, go to the Global Configuration mode and issue the SERVICE

Seite 350 - Setting the Aging Timer

Chapter 78: Telnet Server1284Disabling the Telnet ServerTo disable the Telnet server, use the NO SERVICE TELNET command in the Global Configuration mo

Seite 351

AT-9000 Switch Command Line User’s Guide1285Displaying the Telnet ServerTo display the status of the Telnet server, use the SHOW TELNET command in the

Seite 352 - Chapter 17: MAC Address Table

Chapter 78: Telnet Server1286

Seite 353 - MAC Address Table Commands

1287Chapter 79Telnet Server CommandsThe Telnet server commands are summarized in Table 148 and described in detail within the chapter.Table 148. Telne

Seite 354 - CLEAR MAC ADDRESS-TABLE

Chapter 79: Telnet Server Commands1288NO SERVICE TELNETSyntaxno service telnetParametersNoneModeGlobal Configuration modeDescriptionUse this command t

Seite 355

AT-9000 Switch Command Line User’s Guide1289SERVICE TELNETSyntaxservice telnetParametersNoneModeGlobal Configuration modeDescriptionUse this command t

Seite 356 - MAC ADDRESS-TABLE AGEING-TIME

Chapter 79: Telnet Server Commands1290SHOW TELNETSyntaxshow telnetParametersNoneModeUser Exec mode and Privileged Exec modeDescriptionUse this command

Seite 357

1291Chapter 80Telnet ClientThis chapter provides the following topics: “Overview” on page 1292 “Starting a Remote Management Session with the Telnet

Seite 358 - MAC ADDRESS-TABLE STATIC

Chapter 8: Basic Switch Management Commands104“REBOOT” on page 124 Privileged Exec Resets the switch.“RELOAD” on page 125 Privileged Exec Resets the s

Seite 359

Chapter 80: Telnet Client1292OverviewThe switch has a Telnet client. You may use the client to remotely manage other network devices from the switch.

Seite 360 - NO MAC ADDRESS-TABLE STATIC

AT-9000 Switch Command Line User’s Guide1293Starting a Remote Management Session with the Telnet ClientHere are the steps to using the Telnet client o

Seite 361

Chapter 80: Telnet Client1294

Seite 362 - SHOW MAC ADDRESS-TABLE

1295Chapter 81Telnet Client CommandsThe Telnet client commands are summarized in Table 149 and described in detail within the chapter.Table 149. Telne

Seite 363

Chapter 81: Telnet Client Commands1296TELNETSyntaxtelnet ipv4_address [port]Parametersipv4_addressSpecifies the IPv4 address of a remote device you wa

Seite 364

AT-9000 Switch Command Line User’s Guide1297TELNET IPV6Syntaxtelnet ipv6 ipv6_address [port]Parametersipv6_addressSpecifies the IPv6 address of a remo

Seite 365

Chapter 81: Telnet Client Commands1298

Seite 366

1299Chapter 82Secure Shell (SSH) ServerThis chapter provides the following topics: “Overview” on page 1300 “Support for SSH” on page 1301 “SSH and

Seite 367

Chapter 82: Secure Shell (SSH) Server1300OverviewThe Secure Shell (SSH) protocol is an alternative to the Telnet protocol for remote management of the

Seite 368 - Chapter 19: Enhanced Stacking

AT-9000 Switch Command Line User’s Guide1301Support for SSHThe implementation of the SSH protocol on the switch is compliant with the SSH protocol ver

Seite 369

AT-9000 Switch Command Line User’s Guide105BANNER EXECSyntaxbanner execParametersNoneModeGlobal Configuration modeDescriptionUse this command to creat

Seite 370

Chapter 82: Secure Shell (SSH) Server1302 The SSH server uses protocol port 22. This parameter cannot be changed. If you are using the enhanced stac

Seite 371 - Save the configuration

AT-9000 Switch Command Line User’s Guide1303SSH and Enhanced StackingThe switch allows for encrypted SSH management sessions between a management stat

Seite 372 - Configuring a Member Switch

Chapter 82: Secure Shell (SSH) Server1304Because enhanced stacking does not allow for SSH encrypted management sessions between a management station a

Seite 373

AT-9000 Switch Command Line User’s Guide1305Creating the Encryption Key PairThe first step to using the SSH server on the switch for remote management

Seite 374

Chapter 82: Secure Shell (SSH) Server1306Enabling the SSH ServerThe switch does not allow you to enable the SSH server and begin remote management unt

Seite 375

AT-9000 Switch Command Line User’s Guide1307Disabling the SSH ServerIf you decide that you want to disable the server because you do not want to remot

Seite 376

Chapter 82: Secure Shell (SSH) Server1308Deleting Encryption KeysTo delete encryption keys from the switch, use the CRYPTO KEY DESTROY HOSTKEY command

Seite 377

AT-9000 Switch Command Line User’s Guide1309Displaying the SSH ServerTo display the current settings of the server, enter this command in the Privileg

Seite 378 - Member Switches

Chapter 82: Secure Shell (SSH) Server1310

Seite 379

1311Chapter 83SSH Server CommandsThe SSH server commands are summarized in Table 150 and described in detail within the chapter.Table 150. Secure Shel

Seite 380

Chapter 8: Basic Switch Management Commands106This example deletes the banner:awplus> enableawplus# configure terminalawplus(config)# no banner exe

Seite 381

Chapter 83: SSH Server Commands1312CRYPTO KEY DESTROY HOSTKEYSyntaxcrypto key destroy hostkey dsa|rsa|rsa1ParametersdsaDeletes the DSA key.rsaDeletes

Seite 382

AT-9000 Switch Command Line User’s Guide1313This example deletes the RSA1 key:awplus> enableawplus# configure terminalawplus(config)# crypto key de

Seite 383

Chapter 83: SSH Server Commands1314CRYPTO KEY GENERATE HOSTKEYSyntaxcrypto key generate hostkey dsa|rsa|rsa1 [value]ParametersdsaCreates a DSA key tha

Seite 384

AT-9000 Switch Command Line User’s Guide1315NoteCreating a key is a very CPU intensive process for the switch. The switch does not stop forwarding net

Seite 385

Chapter 83: SSH Server Commands1316NO SERVICE SSHSyntaxno service sshParametersNoneModeGlobal Configuration modeDescriptionUse this command to disable

Seite 386

AT-9000 Switch Command Line User’s Guide1317SERVICE SSHSyntaxservice sshParametersNoneModeGlobal Configuration modeDescriptionUse this command to enab

Seite 387 - Disabling Enhanced Stacking

Chapter 83: SSH Server Commands1318SHOW CRYPTO KEY HOSTKEYSyntaxshow crypto key hostkey [dsa|rsa|rsa1]ParametersdsaDisplays the DSA key.rsaDisplays th

Seite 388

AT-9000 Switch Command Line User’s Guide1319SHOW SSH SERVERSyntaxshow ssh serverParametersNoneModesPrivileged Exec and Global Configuration modesDescr

Seite 389 - Enhanced Stacking Commands

Chapter 83: SSH Server Commands1320

Seite 390

1321Chapter 84Non-secure HTTP Web Browser ServerThis chapter describes the following topics: “Overview” on page 1322 “Enabling the Web Browser Serve

Seite 391 - ESTACK COMMAND-SWITCH

AT-9000 Switch Command Line User’s Guide107BANNER LOGINSyntaxbanner loginParametersNoneModeGlobal Configuration modeDescriptionUse this command to con

Seite 392 - ESTACK RUN

Chapter 84: Non-secure HTTP Web Browser Server1322OverviewThe switch has a web browser server. The server is used to remotely manage the unit over the

Seite 393 - NO ESTACK COMMAND-SWITCH

AT-9000 Switch Command Line User’s Guide1323Enabling the Web Browser ServerThe command to activate the web browser server for non-secure HTTP operatio

Seite 394 - NO ESTACK RUN

Chapter 84: Non-secure HTTP Web Browser Server1324Setting the Protocol Port NumberThe default setting of port 80 for the protocol port of the HTTP web

Seite 395 - RCOMMAND

AT-9000 Switch Command Line User’s Guide1325Disabling the Web Browser ServerThe command to disable the HTTP server is the NO SERVICE HTTP command in t

Seite 396 - REBOOT ESTACK MEMBER

Chapter 84: Non-secure HTTP Web Browser Server1326Displaying the Web Browser ServerTo display whether the HTTP web server is enabled or disabled on th

Seite 397

1327Chapter 85Non-secure HTTP Web Browser Server CommandsThe non-secure HTTP web browser server commands are summarized in Table 151 and described in

Seite 398 - SHOW ESTACK

Chapter 85: Non-secure HTTP Web Browser Server Commands1328SERVICE HTTPSyntaxservice httpParametersNoneModeGlobal Configuration modeDescriptionUse thi

Seite 399

AT-9000 Switch Command Line User’s Guide1329IP HTTP PORTSyntaxip http port portParametersportSpecifies the TCP port number the HTTP web server listens

Seite 400 - SHOW ESTACK COMMAND-SWITCH

Chapter 85: Non-secure HTTP Web Browser Server Commands1330NO SERVICE HTTPSyntaxno http serverParametersNoneModeGlobal Configuration modeDescriptionUs

Seite 401 - SHOW ESTACK REMOTELIST

AT-9000 Switch Command Line User’s Guide1331SHOW IP HTTPSyntaxshow ip httpParametersNoneModePrivileged Exec modeDescriptionUse this command to display

Seite 402

Chapter 8: Basic Switch Management Commands108This example removes the login banner:awplus> enableawplus# configure terminalawplus(config)# no bann

Seite 403 - UPLOAD CONFIG REMOTELIST

Chapter 85: Non-secure HTTP Web Browser Server Commands1332

Seite 404 - UPLOAD IMAGE REMOTELIST

1333Chapter 86Secure HTTPS Web Browser ServerThis chapter describes the following topics: “Overview” on page 1334 “Creating a Self-signed Certificat

Seite 405

Chapter 86: Secure HTTPS Web Browser Server1334OverviewThe switch has a web browser server for remote management of the unit with a web browser applic

Seite 406

AT-9000 Switch Command Line User’s Guide1335Private CAs allow companies to keep track of the certificates and control access to various network device

Seite 407 - Port Mirror

Chapter 86: Secure HTTPS Web Browser Server1336NoteIf the certificate will be issued by a private or public CA, you should check with the CA to see if

Seite 408

AT-9000 Switch Command Line User’s Guide1337Creating a Self-signed CertificateHere are the main steps to configuring the switch for a self-signed cert

Seite 409

Chapter 86: Secure HTTPS Web Browser Server1338At this point, the switch, if it has a management IP address, is ready for remote management with a web

Seite 410 - Chapter 21: Port Mirror

AT-9000 Switch Command Line User’s Guide1339The switch is now ready for remote web browser management with HTTPS, provided that it has a management IP

Seite 411

Chapter 86: Secure HTTPS Web Browser Server1340Configuring the HTTPS Web Server for a Certificate Issued by a CAHere are the main steps to configuring

Seite 412

AT-9000 Switch Command Line User’s Guide13417. Designate the new certificate from the CA as the active certificate on the switch with “IP HTTPS CERTIF

Seite 413 - Displaying the Port Mirror

AT-9000 Switch Command Line User’s Guide109BANNER MOTDSyntaxbanner motdParametersNoneModeGlobal Configuration modeDescriptionUse this command to creat

Seite 414

Chapter 86: Secure HTTPS Web Browser Server1342awplus(config)# crypto certificate 1 request 124.201.76.54 Production ABC_Industries San_Jose Californi

Seite 415 - Port Mirror Commands

AT-9000 Switch Command Line User’s Guide1343The switch, if it has a management IP address, is now ready for remote HTTPS web browser management. To st

Seite 416

Chapter 86: Secure HTTPS Web Browser Server1344Enabling the Web Browser ServerThe command to activate the web browser server for secure HTTPS operatio

Seite 417 - MIRROR INTERFACE

AT-9000 Switch Command Line User’s Guide1345Disabling the Web Browser ServerThe command to disable the HTTPS mode is the NO SERVICE HTTPS command in t

Seite 418

Chapter 86: Secure HTTPS Web Browser Server1346Displaying the Web Browser ServerTo display whether the HTTPS web server is enabled or disabled on the

Seite 419 - NO MIRROR INTERFACE

1347Chapter 87Secure HTTPS Web Browser Server CommandsThe secure HTTPS web browser server commands are summarized in Table 152 and described in detail

Seite 420 - SHOW MIRROR

Chapter 87: Secure HTTPS Web Browser Server Commands1348CRYPTO CERTIFICATE DESTROYSyntaxcrypto certificate id_number destroyParametersid_numberSpecifi

Seite 421

AT-9000 Switch Command Line User’s Guide1349CRYPTO CERTIFICATE GENERATESyntaxcrypto certificate id_number generate length passphrase common_name organ

Seite 422

Chapter 87: Secure HTTPS Web Browser Server Commands1350countrySpecifies the ISO 3166-1 initials of a country. This parameter must be two uppercase ch

Seite 423 - (IGMP) Snooping

AT-9000 Switch Command Line User’s Guide1351 Organizational unit: Sales Organization: Jones_Industries Location: San_Jose State: California Count

Seite 424

Chapter 8: Basic Switch Management Commands110This example removes the message-of-the-day banner:awplus> enableawplus# configure terminalawplus(con

Seite 425

Chapter 87: Secure HTTPS Web Browser Server Commands1352CRYPTO CERTIFICATE IMPORTSyntaxcrypto certificate id_number importParametersid_numberSpecifies

Seite 426 - Host Node Topology

AT-9000 Switch Command Line User’s Guide1353CRYPTO CERTIFICATE REQUESTSyntaxcrypto certificate id_number request common_name organizational_unit organ

Seite 427 - Enabling IGMP Snooping

Chapter 87: Secure HTTPS Web Browser Server Commands1354DescriptionUse this command to create certificate enrollment requests for submittal to public

Seite 428

AT-9000 Switch Command Line User’s Guide1355SERVICE HTTPSSyntaxservice httpsParametersNoneModeGlobal Configuration modeDescriptionUse this command to

Seite 429

Chapter 87: Secure HTTPS Web Browser Server Commands1356IP HTTPS CERTIFICATESyntaxip https certificate id_numberParametersid_numberSpecifies a certifi

Seite 430 - Disabling IGMP Snooping

AT-9000 Switch Command Line User’s Guide1357NO SERVICE HTTPSSyntaxno service httpsParametersNoneModeGlobal Configuration modeDescriptionUse this comma

Seite 431 - Displaying IGMP Snooping

Chapter 87: Secure HTTPS Web Browser Server Commands1358SHOW CRYPTO CERTIFICATESyntaxshow crypto certificate id_numberParametersid_numberSpecifies a c

Seite 432

AT-9000 Switch Command Line User’s Guide1359SHOW IP HTTPSSyntaxshow ip httpParametersNoneModePrivileged Exec modeDescriptionUse this command to displa

Seite 433 - IGMP Snooping Commands

Chapter 87: Secure HTTPS Web Browser Server Commands1360ExampleThis example displays the status of the HTTPS server and basic information about the ce

Seite 434 - CLEAR IP IGMP

1361Chapter 88RADIUS and TACACS+ ClientsThis chapter describes the following topics: “Overview” on page 1362 “Remote Manager Accounts” on page 1363

Seite 435 - IP IGMP LIMIT

AT-9000 Switch Command Line User’s Guide111BAUD-RATE SETSyntaxbaud-rate set 1200|2400|4800|9600|19200|38400|57600|115200ParametersNoneModeGlobal Confi

Seite 436 - IP IGMP QUERIER-TIMEOUT

Chapter 88: RADIUS and TACACS+ Clients1362OverviewThe switch has RADIUS and TACACS+ clients for remote authentication. Here are the two features that

Seite 437 - IP IGMP SNOOPING

AT-9000 Switch Command Line User’s Guide1363Remote Manager AccountsThe switch has one local manager account. The account is referred to as a local acc

Seite 438

Chapter 88: RADIUS and TACACS+ Clients1364the switch, the privilege level of an account is ignored and all accounts have access to the entire command

Seite 439

AT-9000 Switch Command Line User’s Guide13654. Configure the RADIUS or TACACS+ client on the switch by entering the IP addresses of up to three authen

Seite 440 - IP IGMP SNOOPING MROUTER

Chapter 88: RADIUS and TACACS+ Clients1366Managing the RADIUS ClientThe following subsections describe how to manage the RADIUS client: “Adding IP Ad

Seite 441 - IP IGMP STATUS

AT-9000 Switch Command Line User’s Guide1367The AUTH-PORT parameter specifies the UDP destination port for RADIUS authentication requests. If 0 is spe

Seite 442 - NO IP IGMP SNOOPING

Chapter 88: RADIUS and TACACS+ Clients1368This example sets the RADIUS timeout to 15 seconds:awplus> enableawplus# configure terminalawplus(config)

Seite 443 - NO IP IGMP SNOOPING MROUTER

AT-9000 Switch Command Line User’s Guide1369Deleting ServerIP AddressesTo delete the IP address of a RADIUS server from the list of servers on the swi

Seite 444 - SHOW IP IGMP SNOOPING

Chapter 88: RADIUS and TACACS+ Clients1370Managing the TACACS+ ClientThe following subsections describe how to manage the TACACS+ client: “Adding IP

Seite 445

AT-9000 Switch Command Line User’s Guide1371This example adds the IP address 115.16.172.54 as a TACACS+ authentication server at the bottom of the lis

Seite 446

Contents14Disabling the Spanning Tree Protocol ...5

Seite 447 - Multicast Commands

Chapter 8: Basic Switch Management Commands112CLOCK SETSyntaxclock set hh:mm:ss dd mmm yyyyParametershh:mm:ssSpecifies the hour, minute, and second fo

Seite 448

Chapter 88: RADIUS and TACACS+ Clients1372Deleting IPAddresses ofTACACS+ServersTo delete the IP address of a TACACS+ server from the client on the swi

Seite 449

AT-9000 Switch Command Line User’s Guide1373Configuring Remote Authentication of Manager AccountsCheck that you performed the following steps before a

Seite 450

Chapter 88: RADIUS and TACACS+ Clients1374uses for remote Telnet and SSH sessions. (For background information, refer to “VTY Lines” on page 41.)Toggl

Seite 451

AT-9000 Switch Command Line User’s Guide1375The LINE_ID parameter has a range of 0 to 9. The following example of the command toggles off remote authe

Seite 452

Chapter 88: RADIUS and TACACS+ Clients1376

Seite 453 - File System

1377Chapter 89RADIUS and TACACS+ Client CommandsThe commands for the RADIUS and TACACS+ clients are summarized in Table 154 and described in detail wi

Seite 454

Chapter 89: RADIUS and TACACS+ Client Commands1378“RADIUS-SERVER TIMEOUT” on page 1395Global ConfigurationSpecifies the maximum amount of time the RAD

Seite 455

AT-9000 Switch Command Line User’s Guide1379AAA ACCOUNTING LOGINSyntaxaaa accounting login default start-stop|stop-only|none group radius|tacacs Param

Seite 456

Chapter 89: RADIUS and TACACS+ Client Commands1380Confirmation Commands“SHOW RADIUS” on page 1396“SHOW TACACS” on page 1398ExamplesTo configure RADIUS

Seite 457 - destinationfile

AT-9000 Switch Command Line User’s Guide1381AAA AUTHENTICATION ENABLE (TACACS+)Syntaxaaa authentication enable default group tacacs [local]Parametersd

Seite 458

AT-9000 Switch Command Line User’s Guide113ERASE STARTUP-CONFIGSyntaxerase startup-configParametersNoneModePrivileged Exec modeDescriptionUse this com

Seite 459

Chapter 89: RADIUS and TACACS+ Client Commands1382command is attempted if a TACACS+ server is not available, use the following commands:awplus> ena

Seite 460 - Chapter 26: File System

AT-9000 Switch Command Line User’s Guide1383AAA AUTHENTICATION LOGINSyntaxaaa authentication login default [group radius|tacacs] [local]Parametersdefa

Seite 461

Chapter 89: RADIUS and TACACS+ Client Commands1384Confirmation Commands“SHOW RADIUS” on page 1396“SHOW TACACS” on page 1398ExamplesTo enable RADIUS se

Seite 462

AT-9000 Switch Command Line User’s Guide1385IP RADIUS SOURCE-INTERFACESyntaxip radius source-interface Ipv4 Address | VIDParametersIpv4 AddressIndicat

Seite 463 - File System Commands

Chapter 89: RADIUS and TACACS+ Client Commands1386This example removes the RADIUS source IP address from the RADIUS client:awplus> enableawplus# co

Seite 464

AT-9000 Switch Command Line User’s Guide1387LOGIN AUTHENTICATIONSyntaxlogin authenticationParametersNoneModesConsole Line and Virtual Terminal Line mo

Seite 465

Chapter 89: RADIUS and TACACS+ Client Commands1388This example activates remote authentication for remote Telnet and SSH management sessions that use

Seite 466 - DELETE FORCE

AT-9000 Switch Command Line User’s Guide1389NO LOGIN AUTHENTICATIONSyntaxno login authenticationParametersNoneModesConsole Line and Virtual Terminal L

Seite 467

Chapter 89: RADIUS and TACACS+ Client Commands1390NO RADIUS-SERVER HOSTSyntaxno radius-server host ipaddressParameteripaddressSpecifies an IP address

Seite 468

AT-9000 Switch Command Line User’s Guide1391NO TACACS-SERVER HOSTSyntaxno tacacs-server host ipaddressParameteripaddressSpecifies an IP address of a T

Seite 469 - SHOW FILE SYSTEMS

Chapter 8: Basic Switch Management Commands114EXEC-TIMEOUTSyntaxexec-timeout valueParametersexec-timeoutSpecifies the session timer in minutes. The ra

Seite 470

Chapter 89: RADIUS and TACACS+ Client Commands1392RADIUS-SERVER HOSTSyntaxradius-server host ipaddress [acct-port value] [auth-port value] [key value]

Seite 471 - Boot Configuration Files

AT-9000 Switch Command Line User’s Guide1393ExamplesThis example adds a RADIUS server with the IP address 176.225.15.23. The UDP port is 1811, and the

Seite 472

Chapter 89: RADIUS and TACACS+ Client Commands1394RADIUS-SERVER KEYSyntaxradius-server key valueParameterskeySpecifies the global encryption key of th

Seite 473

AT-9000 Switch Command Line User’s Guide1395RADIUS-SERVER TIMEOUTSyntaxradius-server timeout valueParameterstimeoutSpecifies the maximum amount of tim

Seite 474

Chapter 89: RADIUS and TACACS+ Client Commands1396SHOW RADIUSSyntaxshow radiusParametersNoneModesPrivileged Exec modeDescriptionUse this command to di

Seite 475

AT-9000 Switch Command Line User’s Guide1397ExampleThis example displays the configuration of the RADIUS client:awplus# show radiusAccounting Port The

Seite 476

Chapter 89: RADIUS and TACACS+ Client Commands1398SHOW TACACSSyntaxshow tacacsParametersNoneModePrivileged Exec modeDescriptionUse this command to dis

Seite 477 - Chapter 29

AT-9000 Switch Command Line User’s Guide1399ExampleThis example displays the configuration of the TACACS+ client on the switch:awplus# show tacacsServ

Seite 478 - BOOT CONFIG-FILE

Chapter 89: RADIUS and TACACS+ Client Commands1400TACACS-SERVER HOSTSyntaxtacacs-server host ipaddress [key value]ParametershostSpecifies an IP addres

Seite 479

AT-9000 Switch Command Line User’s Guide1401TACACS-SERVER KEYSyntaxtacacs-server key valueParametersvalueSpecifies the global encryption key of the TA

Seite 480 - COPY RUNNING-CONFIG

AT-9000 Switch Command Line User’s Guide115This example sets the session timer for the first (vty 0) Telnet or SSH session to 5 minutes:awplus> ena

Seite 481

Chapter 89: RADIUS and TACACS+ Client Commands1402TACACS-SERVER TIMEOUTSyntaxtacacs-server timeout valueParameterstimeoutSpecifies the maximum amount

Seite 482

1403Appendix ASystem Monitoring CommandsThe system monitoring commands are summarized in Table 157 and described in detail within the chapter.Table 15

Seite 483 - NO BOOT CONFIG-FILE

Chapter : System Monitoring Commands1404SHOW CPUSyntaxshow cpu [sort pri|runtime|sleep|thrds]ParameterspriSorts the list by process priorities.runtime

Seite 484 - SHOW BOOT

AT-9000 Switch Command Line User’s Guide1405SHOW CPU HISTORYSyntaxshow cpu historyParametersNoneModePrivileged Exec modeDescriptionUse this command to

Seite 485

Chapter : System Monitoring Commands1406SHOW CPU USER-THREADSSyntaxshow cpu user-threadsParametersNoneModePrivileged Exec modeDescriptionUse this comm

Seite 486 - SHOW STARTUP-CONFIG

AT-9000 Switch Command Line User’s Guide1407SHOW MEMORYSyntaxshow memory [sort peak|size|stk]ParameterspeakSorts the list by the peak amounts of memor

Seite 487

Chapter : System Monitoring Commands1408SHOW MEMORY ALLOCATIONSyntaxshow memory allocation processParameterprocessSpecifies a system process.ModePrivi

Seite 488

AT-9000 Switch Command Line User’s Guide1409SHOW MEMORY HISTORYSyntaxshow memory historyParametersNoneModePrivileged Exec modeDescriptionUse this comm

Seite 489 - File Transfer

Chapter : System Monitoring Commands1410SHOW MEMORY POOLSSyntaxshow memory poolsParametersNoneModePrivileged Exec modeDescriptionUse this command to d

Seite 490

AT-9000 Switch Command Line User’s Guide1411SHOW PROCESSSyntaxshow memory process [sort cpu|mem]ParameterscpuSorts the list by percentage of CPU utili

Seite 491 - Software with

Chapter 8: Basic Switch Management Commands116HELPSyntaxhelpParametersNoneModeAll modesDescriptionUse this command to learn how to use on-line help. E

Seite 492 - Switch with

Chapter : System Monitoring Commands1412SHOW SYSTEM SERIALNUMBERSyntaxshow system serialnumberParametersNoneModesUser Exec mode and Privileged Exec mo

Seite 493 - Uploading Files

AT-9000 Switch Command Line User’s Guide1413SHOW SYSTEM INTERRUPTSSyntaxshow system interruptsParametersNoneModePrivileged Exec modeDescriptionUse thi

Seite 494 - 20100601091645.txt

Chapter : System Monitoring Commands1414SHOW TECH-SUPPORTSyntaxshow tech-support [all]ParametersallPerforms the full set of technical support commands

Seite 495

AT-9000 Switch Command Line User’s Guide1415With the ALL option, the command performs the previous commands and these additional commands: SHOW ARP

Seite 496

Chapter : System Monitoring Commands1416

Seite 497 - Waiting to send

1417Appendix BManagement Software Default SettingsThis appendix lists the factory default settings of the switch. The features are listed in alphabeti

Seite 498 - Chapter 30: File Transfer

Appendix B: Management Software Default Settings1418Boot Configuration FileThe following table lists the name of the default configuration file.Boot C

Seite 499

AT-9000 Switch Command Line User’s Guide1419Class of ServiceThe following table lists the default mappings of the IEEE 802.1p priority levels to the e

Seite 500

Appendix B: Management Software Default Settings1420Console PortThe following table lists the default settings for the Console port.NoteThe baud rate

Seite 501 - File Transfer Commands

AT-9000 Switch Command Line User’s Guide1421802.1x Port-Based Network Access ControlThe following table describes the 802.1x Port-based Network Access

Seite 502 - COPY FILENAME ZMODEM

AT-9000 Switch Command Line User’s Guide117HOSTNAMESyntaxhostname nameParametersnameSpecifies a name of up to 39 alphanumeric characters for the switc

Seite 503 - COPY FLASH TFTP

Appendix B: Management Software Default Settings1422The following table lists the default settings for RADIUS accounting.RADIUS Accounting Settings De

Seite 504 - COPY TFTP FLASH

AT-9000 Switch Command Line User’s Guide1423Enhanced StackingThe following table lists the enhanced stacking default setting.Enhanced Stacking Setting

Seite 505

Appendix B: Management Software Default Settings1424GVRPThis section provides the default settings for GVRP.GVRP Setting DefaultStatus DisabledGIP Sta

Seite 506 - COPY ZMODEM

AT-9000 Switch Command Line User’s Guide1425IGMP SnoopingThe following table lists the IGMP Snooping default settings.IGMP Snooping Setting DefaultIGM

Seite 507

Appendix B: Management Software Default Settings1426Link Layer Discovery Protocol (LLDP and LLDP-MED)The following table lists the default settings fo

Seite 508

AT-9000 Switch Command Line User’s Guide1427MAC Address-based Port SecurityThe following table lists the MAC address-based port security default setti

Seite 509 - Event Messages

Appendix B: Management Software Default Settings1428MAC Address TableThe following table lists the default setting for the MAC address table.MAC Addre

Seite 510

AT-9000 Switch Command Line User’s Guide1429Management IP AddressThe following table lists the default settings for the management IP address.Manageme

Seite 511 - Event Log

Appendix B: Management Software Default Settings1430Manager AccountThe following table lists the manager account default settings.NoteLogin names and

Seite 512

AT-9000 Switch Command Line User’s Guide1431Port SettingsThe following table lists the port configuration default settings.Port Configuration Setting

Seite 513 - Displaying the Event Log

Chapter 8: Basic Switch Management Commands118LINE CONSOLESyntaxline console 0ParametersNoneModeGlobal Configuration modeDescriptionUse this command t

Seite 514 - Clearing the Event Log

Appendix B: Management Software Default Settings1432RADIUS ClientThe following table lists the RADIUS configuration default settings.RADIUS Configurat

Seite 515 - Event Log Commands

AT-9000 Switch Command Line User’s Guide1433Remote Manager Account AuthenticationThe following table describes the remote manager account authenticati

Seite 516 - CLEAR LOG BUFFERED

Appendix B: Management Software Default Settings1434RMONThe following table lists the default settings for RMON collection histories. There are no def

Seite 517 - LOG BUFFERED

AT-9000 Switch Command Line User’s Guide1435Secure Shell ServerThe following table lists the SSH default settings.NoteThe SSH port number is not adjus

Seite 518

Appendix B: Management Software Default Settings1436sFlow AgentThe default settings for the sFlow agent are listed in this table.sFlow Agent Setting D

Seite 519 - NO LOG BUFFERED

AT-9000 Switch Command Line User’s Guide1437Simple Network Management Protocol (SNMPv1, SNMPv2c and SNMPv3)The following table describes the default s

Seite 520 - OUtputID Type Status Details

Appendix B: Management Software Default Settings1438Simple Network Time ProtocolThe following table lists the SNTP default settings.SNTP Setting Defau

Seite 521 - SHOW LOG

AT-9000 Switch Command Line User’s Guide1439Spanning Tree Protocols (STP, RSTP and MSTP)This section provides the default settings for STP and RSTP.Sp

Seite 522

Appendix B: Management Software Default Settings1440MultipleSpanning TreeProtocolThe following table describes the RSTP default settings.Loop Guard Di

Seite 523

AT-9000 Switch Command Line User’s Guide1441System NameThe default setting for the system name is listed in this table.System Name Setting DefaultSyst

Seite 524 - SHOW LOG CONFIG

AT-9000 Switch Command Line User’s Guide119LINE VTYSyntaxline vty first_line_id [last_line_id]Parametersfirst_line_idSpecifies the number of a VTY lin

Seite 525 - SHOW LOG REVERSE

Appendix B: Management Software Default Settings1442TACACS+ Client The following table lists the TACACS+ client configuration default settings.TACACS+

Seite 526 - SHOW LOG TAIL

AT-9000 Switch Command Line User’s Guide1443Telnet ServerThe default settings for the Telnet server are listed in this table.NoteThe Telnet port numbe

Seite 527 - Syslog Client

Appendix B: Management Software Default Settings1444VLANsThis section provides the VLAN default settings.VLAN Setting DefaultDefault VLAN Name Default

Seite 528

AT-9000 Switch Command Line User’s Guide1445Web ServerThe following table lists the web server default settings.Web Server Configuration Setting Defau

Seite 529 - program

Appendix B: Management Software Default Settings1446

Seite 530 - Chapter 34: Syslog Client

1447Command IndexAAAA ACCOUNTING LOGIN command 1379AAA ACCOUNTING LOGIN TACACS command 1379AAA AUTHENTICATION DOT1X DEFAULT GROUP command 881AAA AUTHE

Seite 531

Index1448ENABLE command 24, 64ENABLE PASSWORD command 1266, 1272END command 28, 65ERASE STARTUP-CONFIG command 92, 113, 454ESTACK COMMAND-SWITCH comma

Seite 532

AT-9000 Switch Command Line User’s Guide1449NO ECOFRIENDLY LED command 79NO EGRESS-RATE-LIMIT command 181NO ENABLE PASSWORD command 1267, 1274NO ESTAC

Seite 533

Index1450NO SWITCHPORT VLAN-STACKING command 832NO TACACS-SERVER HOST command 1372, 1391NO TACACS-SERVER KEY command 1401NO TACACS-SERVER TIMEOUT comm

Seite 534

AT-9000 Switch Command Line User’s Guide1451SHOW IP INTERFACE command 265, 289SHOW IP ROUTE command 263, 265, 290SHOW IPV6 INTERFACE command 269, 292S

Seite 535 - Syslog Client Commands

Chapter 8: Basic Switch Management Commands120NO HOSTNAMESyntaxno hostnameParametersNoneModeGlobal Configuration modeDescriptionUse this command to de

Seite 536 - LOG HOST

Index1452SPANNING-TREE MODE MSTP command 676SPANNING-TREE MODE RSTP command 606, 634SPANNING-TREE MODE STP command 582, 598SPANNING-TREE MST CONFIGURA

Seite 537

AT-9000 Switch Command Line User’s Guide121PINGSyntaxping ipaddress|hostnameParametersipaddressSpecifies the IP address of the network device to recei

Seite 538 - NO LOG HOST

AT-9000 Switch Command Line User’s Guide15SPANNING-TREE RSTP ENABLE...

Seite 539

Chapter 8: Basic Switch Management Commands122NoteThe switch sends the ICMP Echo Requests from the ports of the VLAN assigned the management IP addres

Seite 540

AT-9000 Switch Command Line User’s Guide123PING IPv6Syntaxping ipv6 <ipv6-address> repeat <1-99> size <36-18024> Parametersipv6-addr

Seite 541 - Port Trunks

Chapter 8: Basic Switch Management Commands124REBOOTSyntaxrebootParametersNoneModePrivileged Exec modeDescriptionUse this command to reset the switch.

Seite 542

AT-9000 Switch Command Line User’s Guide125RELOADSyntaxreloadParametersNoneModePrivileged Exec modeDescriptionUse this command to reset the switch. Yo

Seite 543 - Static Port Trunks

Chapter 8: Basic Switch Management Commands126SERVICE MAXMANAGERSyntaxservice maxmanager valueParametersvalueSpecifies the maximum number of manager s

Seite 544

AT-9000 Switch Command Line User’s Guide127SHOW BANNER LOGINSyntaxshow banner login ParametersNoneModePrivileged Exec modeDescriptionUse this command

Seite 545

Chapter 8: Basic Switch Management Commands128SHOW BAUD-RATESyntaxshow baud-rateParametersNoneModeUser Exec mode and Privileged Exec modeDescriptionUs

Seite 546

AT-9000 Switch Command Line User’s Guide129SHOW CLOCKSyntaxshow clockParametersNoneModesUser Exec modeDescriptionUse this command to display the syste

Seite 547

Chapter 8: Basic Switch Management Commands130SHOW RUNNING-CONFIGSyntaxshow running-configParametersNoneModesPrivileged Exec modeDescriptionUse this c

Seite 548

AT-9000 Switch Command Line User’s Guide131SHOW SWITCHSyntaxshow switchParametersNoneModesPrivileged Exec modeDescriptionUse this command to view the

Seite 549

Contents16Port VLAN Identifier ...

Seite 550

Chapter 8: Basic Switch Management Commands132ExampleThe following example displays the switch information:awplus# show switchActive Spanning Tree ver

Seite 551 - Displaying Static Port Trunks

AT-9000 Switch Command Line User’s Guide133SHOW SYSTEMSyntaxshow systemParametersNoneModesUser Exec and Privileged Exec modesDescriptionUse this comma

Seite 552

Chapter 8: Basic Switch Management Commands134SHOW SYSTEM SERIALNUMBERSyntaxshow system serialnumberParametersNoneModeUser Exec and Privileged Exec mo

Seite 553 - Static Port Trunk Commands

AT-9000 Switch Command Line User’s Guide135SHOW USERSSyntaxshow usersParametersNoneModesPrivileged Exec modeDescriptionUse this command to display the

Seite 554 - NO STATIC-CHANNEL-GROUP

Chapter 8: Basic Switch Management Commands136ExampleThis example displays the managers who are logged on to the switch:awplus# show usersIdle The num

Seite 555 - PORT-CHANNEL LOAD-BALANCE

AT-9000 Switch Command Line User’s Guide137SHOW VERSIONSyntaxshow versionParametersNoneModeUser Exec and Privileged Exec modesDescriptionUse this comm

Seite 556

Chapter 8: Basic Switch Management Commands138SNMP-SERVER CONTACTSyntaxsnmp-server contact contactParameterscontactSpecifies the name of the person re

Seite 557 - SHOW STATIC-CHANNEL-GROUP

AT-9000 Switch Command Line User’s Guide139SNMP-SERVER LOCATIONSyntaxsnmp-server location locationParameterslocationSpecifies the location of the swit

Seite 558 - STATIC-CHANNEL-GROUP

Chapter 8: Basic Switch Management Commands140SYSTEM TERRITORYSyntaxsystem territory territoryParametersterritorySpecifies the territory of the switch

Seite 559

AT-9000 Switch Command Line User’s Guide141This example removes the current territory information:awplus> enableawplus# configure terminalawplus(co

Seite 560

AT-9000 Switch Command Line User’s Guide17SHOW GVRP MACHINE ...

Seite 561 - Chapter 38

Chapter 8: Basic Switch Management Commands142

Seite 562

143Chapter 9Port ParametersThis chapter contains the following: “Adding Descriptions” on page 144 “Setting the Speed and Duplex Mode” on page 145 “

Seite 563 - Load Distribution

Chapter 9: Port Parameters144Adding DescriptionsThe ports will be easier to identify if you give them descriptions. The descriptions are viewed with t

Seite 564

AT-9000 Switch Command Line User’s Guide145Setting the Speed and Duplex ModeThe twisted pair ports on the switch can operate at 10, 100, or 1000 Mbps,

Seite 565 - Creating New Aggregators

Chapter 9: Port Parameters146This example sets the speeds of ports 11 and 17 to 100Mbps:awplus> enableawplus# configure terminalawplus(config)# int

Seite 566

AT-9000 Switch Command Line User’s Guide147Setting the MDI/MDI-X Wiring ConfigurationThe wiring configurations of twisted pair ports that operate at 1

Seite 567 - Adding Ports to Aggregators

Chapter 9: Port Parameters148Enabling or Disabling PortsDisabling ports turns off their receivers and transmitters so that they cannot forward traffic

Seite 568

AT-9000 Switch Command Line User’s Guide149Enabling or Disabling BackpressurePorts use backpressure during periods of packet congestion, to prevent pa

Seite 569 - Deleting Aggregators

Chapter 9: Port Parameters150Enabling or Disabling Flow ControlWhen a port that is operating in full-duplex mode needs to temporarily stop its local o

Seite 570 - Displaying Aggregators

AT-9000 Switch Command Line User’s Guide151This example configures port 21 not to send pause packets during periods of packet congestion:awplus> en

Seite 571

Contents18Provider Ports ...

Seite 572

Chapter 9: Port Parameters152If flow control is not configured on a port, this message is displayed:Flow control is not set on interface port1.0.2

Seite 573 - LACP Commands

AT-9000 Switch Command Line User’s Guide153Resetting PortsIf a port is experiencing a problem, you may be able to correct it with the RESET command in

Seite 574 - CHANNEL-GROUP

Chapter 9: Port Parameters154Configuring Threshold Limits for Ingress PacketsYou can set threshold limits for the ingress packets on the ports. The th

Seite 575

AT-9000 Switch Command Line User’s Guide155To remove threshold limits from the ports, use the NO STORM-CONTROL command, also in the Port Interface mod

Seite 576 - LACP SYSTEM-PRIORITY

Chapter 9: Port Parameters156Displaying Threshold Limit Settings on PortsTo display the threshold settings for the ingress packets on the ports, use t

Seite 577 - NO CHANNEL-GROUP

AT-9000 Switch Command Line User’s Guide157Reinitializing Auto-NegotiationIf you believe that a port set to Auto-Negotiation is not using the highest

Seite 578

Chapter 9: Port Parameters158Restoring the Default SettingsTo restore the default settings on a port, use the PURGE command in the Port Interface mode

Seite 579

AT-9000 Switch Command Line User’s Guide159Displaying Port SettingsThere are several ways to display port settings. See the following: “Displaying Sp

Seite 580 - SHOW ETHERCHANNEL

Chapter 9: Port Parameters160Figure 46. SHOW INTERFACE CommandThe fields are described in Table 13 on page 194. For a description of the command, see

Seite 581 - SHOW ETHERCHANNEL DETAIL

AT-9000 Switch Command Line User’s Guide161Displaying or Clearing Port StatisticsTo view packet statistics for the individual ports, use the SHOW PLAT

Seite 582 - Chapter 39: LACP Commands

AT-9000 Switch Command Line User’s Guide19Configuring Authenticator Ports ...

Seite 583 - SHOW ETHERCHANNEL SUMMARY

Chapter 9: Port Parameters162Displaying SFP Information To view information on a plugged SFP on the switch, use the SHOW SYSTEM PLUGGABLE command in t

Seite 584 - SHOW LACP SYS-ID

163Chapter 10Port Parameter CommandsThe port parameter commands are summarized in Table 11.Table 11. Port Parameter CommandsCommand Mode Description“B

Seite 585 - SHOW PORT ETHERCHANNEL

Chapter 10: Port Parameter Commands164“NO STORM-CONTROL” on page 185Port Interface Removes threshold limits for broadcast, multicast, or unknown unica

Seite 586

165“STORM-CONTROL” on page 213 Port Interface Sets a maximum limit of the number of broadcast, multicast, or unknown unicast packets forwarded by a po

Seite 587 - Spanning Tree Protocols

Chapter 10: Port Parameter Commands166BACKPRESSURESyntaxbackpressure on|offParametersonActivates backpressure on the ports.offDeactivates backpressure

Seite 588

AT-9000 Switch Command Line User’s Guide167This example configures ports 8 and 21 to 100 Mbps, half-duplex mode, with backpressure disabled:awplus>

Seite 589 - STP, RSTP and MSTP Protocols

Chapter 10: Port Parameter Commands168BPLIMITSyntaxbplimit bplimitParametersbplimitSpecifies the number of cells for backpressure. A cell represents 1

Seite 590

AT-9000 Switch Command Line User’s Guide169CLEAR PORT COUNTERSyntaxclear port counter portParametersportSpecifies the port whose packet counters you w

Seite 591

Chapter 10: Port Parameter Commands170DESCRIPTIONSyntaxdescription descriptionParametersdescriptionSpecifies a description of 1 to 240 alphanumeric ch

Seite 592 - Path Costs and Port Costs

AT-9000 Switch Command Line User’s Guide171This example removes the current name from port 11 without assigning a new name:awplus> enableawplus# co

Seite 593 - Port Priority

CopyrightCopyright © 2014, Allied Telesis, Inc.All rights reserved.This product includes software licensed under the BSD License. As such, the followi

Seite 594

Contents20Chapter 63: SNMPv1 and SNMPv2c Commands ...945NO SNMP-SE

Seite 595

Chapter 10: Port Parameter Commands172DUPLEXSyntaxduplex auto|half|fullParametersautoActivates Auto-Negotiation for the duplex mode, so that the duple

Seite 596 - Point-to-Point and Edge Ports

AT-9000 Switch Command Line User’s Guide173ExamplesThis example sets the duplex mode on port 11 half-duplex:awplus> enableawplus# configure termina

Seite 597 - (Full-duplex Mode)

Chapter 10: Port Parameter Commands174EGRESS-RATE-LIMITSyntaxegress-rate-limit valueParametersvalueSpecifies the maximum amount of traffic that can be

Seite 598 - Mixed STP and RSTP Networks

AT-9000 Switch Command Line User’s Guide175FCTRLLIMITSyntaxfctrllimit fctrllimitParametersfctrllimitSpecifies the number of cells for flow control. A

Seite 599 - Spanning Tree and VLANs

Chapter 10: Port Parameter Commands176FLOWCONTROLSyntaxflowcontrol send|receive|both on|offParametersendControls whether a port sends pause packets du

Seite 600 - RSTP and MSTP BPDU Guard

AT-9000 Switch Command Line User’s Guide177partner. If it is off, a port does not respond to pause packets and continues to transmit packets. At the d

Seite 601

Chapter 10: Port Parameter Commands178This example configures port 1 and 2 to 10 Mbps, full-duplex mode. The send portion of flow control is disabled

Seite 602 - STP, RSTP, MSTP Loop Guard

AT-9000 Switch Command Line User’s Guide179HOLBPLIMITSyntaxholbplimit holbplimitParameterholbplimitSpecifies the threshold at which a port signals a h

Seite 603

Chapter 10: Port Parameter Commands180Figure 48. Head of Line BlockingThe HOL Limit parameter can help prevent this problem from occurring. It sets a

Seite 604

AT-9000 Switch Command Line User’s Guide181NO EGRESS-RATE-LIMITSyntaxno egress-rate-limitParametersNoneModePort Interface modeDescriptionUse this comm

Seite 605

AT-9000 Switch Command Line User’s Guide21Chapter 66: sFlow Agent Commands ...

Seite 606

Chapter 10: Port Parameter Commands182NO FLOWCONTROLSyntaxno flowcontrolParameterNoneModePort Interface modeDescriptionUse this command to disable flo

Seite 607 - STP and RSTP Root Guard

AT-9000 Switch Command Line User’s Guide183NO SHUTDOWNSyntaxno shutdownParametersNoneModePort Interface modeDescriptionUse this command to enable port

Seite 608

Chapter 10: Port Parameter Commands184NO SNMP TRAP LINK-STATUSSyntaxno snmp trap link-statusParameterNoneModePort Interface modeDescriptionUse this co

Seite 609 - Procedures

AT-9000 Switch Command Line User’s Guide185NO STORM-CONTROLSyntaxno storm-control broadcast|multicast|dlfParametersbroadcastSpecifies broadcast packet

Seite 610

Chapter 10: Port Parameter Commands186POLARITYSyntaxpolarity auto|mdi|mdixParametersautoActivates auto-MDI/MDIX.mdiSets a port’s wiring configuration

Seite 611

AT-9000 Switch Command Line User’s Guide187This example sets ports 4 and 18 to the MDI-X wiring configuration:awplus> enableawplus# configure termi

Seite 612 - Setting the Switch Parameters

Chapter 10: Port Parameter Commands188PURGESyntaxpurgeParametersNoneModePort Interface modeDescriptionUse this command to restore the default settings

Seite 613

AT-9000 Switch Command Line User’s Guide189RENEGOTIATESyntaxrenegotiateParametersNoneModePort Interface modeDescriptionUse this command to prompt a po

Seite 614 - Setting the Port Parameters

Chapter 10: Port Parameter Commands190RESETSyntaxresetParametersNoneModePort Interface modeDescriptionUse this command to perform a hardware reset on

Seite 615

AT-9000 Switch Command Line User’s Guide191SHOW FLOWCONTROL INTERFACESyntaxshow flowcontrol interface portParameterportSpecifies the port whose flow c

Seite 616 - Displaying STP Settings

Contents22NO LLDP TLV-SELECT ...

Seite 617 - STP Commands

Chapter 10: Port Parameter Commands192ExampleThis command displays the flow control settings for port 2:awplus# show flowcontrol interface port1.0.2Rx

Seite 618 - Chapter 42: STP Commands

AT-9000 Switch Command Line User’s Guide193SHOW INTERFACESyntaxshow interface [port]ParameterportSpecifies the port whose current status you want to v

Seite 619 - NO SPANNING-TREE STP ENABLE

Chapter 10: Port Parameter Commands194Figure 50. SHOW INTERFACE CommandThe fields are described in Table 13.Interface port1.0.1Link is UP, administrat

Seite 620 - SHOW SPANNING-TREE

AT-9000 Switch Command Line User’s Guide195Link is The status of the link on the port. This field is UP when the port has a link with a network device

Seite 621

Chapter 10: Port Parameter Commands196ExamplesThis command displays the current operational state of all the ports:awplus# show interfaceThis command

Seite 622 - SPANNING-TREE FORWARD-TIME

AT-9000 Switch Command Line User’s Guide197SHOW INTERFACE BRIEFSyntaxshow interface briefParameterNoneModesPrivileged Exec modeDescriptionUse this com

Seite 623 - SPANNING-TREE GUARD ROOT

Chapter 10: Port Parameter Commands198ExampleThe following example displays the administrative and link statuses of all of the ports on the switch:awp

Seite 624 - SPANNING-TREE HELLO-TIME

AT-9000 Switch Command Line User’s Guide199SHOW INTERFACE STATUSSyntaxshow interface [port] statusParameterportSpecifies the port whose parameter sett

Seite 625 - SPANNING-TREE MAX-AGE

Chapter 10: Port Parameter Commands200ExamplesThis command displays the settings of all the ports:awplus# show interface statusThis command displays t

Seite 626 - SPANNING-TREE MODE STP

AT-9000 Switch Command Line User’s Guide201SHOW PLATFORM TABLE PORT COUNTERSSyntaxshow platform table port [port] countersParameterportSpecifies the p

Seite 627 - SPANNING-TREE PATH-COST

AT-9000 Switch Command Line User’s Guide23SHOW RMON EVENT ...

Seite 628 - SPANNING-TREE PORTFAST

Chapter 10: Port Parameter Commands202MulticastPkts Number of received and transmitted multicast packets.BroadcastPkts Number of received and transmit

Seite 629

AT-9000 Switch Command Line User’s Guide203ExamplesThis command displays the statistics for ports 21 and 23:awplus# show platform table port port1.0.2

Seite 630

Chapter 10: Port Parameter Commands204SHOW RUNNING-CONFIG INTERFACESyntaxshow running-config interface portParametersportSpecifies a port, multiple po

Seite 631

AT-9000 Switch Command Line User’s Guide205SHOW STORM-CONTROLSyntaxshow storm-control [port]ParametersportSpecifies the port whose storm-control, thre

Seite 632 - SPANNING-TREE STP ENABLE

Chapter 10: Port Parameter Commands206ExamplesThis command displays the settings of all the ports:awplus# show storm-controlThis command displays the

Seite 633

AT-9000 Switch Command Line User’s Guide207SHOW SYSTEM PLUGGABLESyntaxshow system pluggableParametersNoneModePrivileged Exec modeDescriptionUse this c

Seite 634

Chapter 10: Port Parameter Commands208SHOW SYSTEM PLUGGABLE DETAILSyntaxshow system pluggable detailParametersNoneModePrivileged Exec modeDescriptionU

Seite 635

AT-9000 Switch Command Line User’s Guide209SHUTDOWNSyntaxshutdownParameterNoneModePort Interface modeDescriptionUse this command to disable ports. Por

Seite 636 - Hello Time, and

Chapter 10: Port Parameter Commands210SNMP TRAP LINK-STATUSSyntaxsnmp trap link-statusParameterNoneModePort Interface modeDescriptionUse this command

Seite 637 - Disabling BPDU

AT-9000 Switch Command Line User’s Guide211SPEEDSyntaxspeed auto|10|100|1000ParametersautoActivates Auto-Negotiation so that the speed is configured a

Seite 638

Contents24NO MLS QOS ENABLE...

Seite 639 - Configuring Port

Chapter 10: Port Parameter Commands212This example activates Auto-Negotiation on port 15:awplus> enableawplus# configure terminalawplus(config)# in

Seite 640

AT-9000 Switch Command Line User’s Guide213STORM-CONTROLSyntaxstorm-control broadcast|multicast|dlf level valueParametersbroadcastSpecifies broadcast

Seite 641

Chapter 10: Port Parameter Commands214ExamplesThis example sets the maximum threshold level of 5,000 packets per second for ingress broadcast packets

Seite 642

215Chapter 11Power Over Ethernet “Overview” on page 216 “Enabling and Disabling PoE” on page 218  “Adding PD Descriptions to Ports” on page 220  “

Seite 643

Chapter 11: Power Over Ethernet216OverviewThe AT-9000/12PoE and AT-9000/28PoE switches feature Power over Ethernet (PoE) on the 10/100Base-Tx ports. P

Seite 644 - Displaying RSTP Settings

AT-9000 Switch Command Line User’s Guide217The AT-9000/12POE switch has a power budget of 125 watts. The AT-9000/28POE switch has a power budget of 37

Seite 645 - RSTP Commands

Chapter 11: Power Over Ethernet218Enabling and Disabling PoEEnabling PoE on ports allows the switch to supply power to PDs connected to the ports. In

Seite 646 - Chapter 44: RSTP Commands

AT-9000 Switch Command Line User’s Guide219This example disables PoE individually on port 5 to port 8:awplus> enableawplus# configure terminalawplu

Seite 647 - NO SPANNING-TREE PORTFAST

Chapter 11: Power Over Ethernet220Adding PD Descriptions to PortsPDs connected to the ports are easier to identify if you give them descriptions. To a

Seite 648

AT-9000 Switch Command Line User’s Guide221Prioritizing PortsWhen the total power requirements of the PDs exceed the total available power of the swit

Seite 649 - NO SPANNING-TREE LOOP-GUARD

AT-9000 Switch Command Line User’s Guide25Disabling the SSH Server ...

Seite 650

Chapter 11: Power Over Ethernet222Managing the Maximum Power Limit on PortsTo manage the switch’s power and optimize its power distribution, the switc

Seite 651 - NO SPANNING-TREE RSTP ENABLE

AT-9000 Switch Command Line User’s Guide223Managing Legacy PDsThe PoE switch automatically detects whether or not a device plugged into the PoE-enable

Seite 652

Chapter 11: Power Over Ethernet224Monitoring Power ConsumptionYou can monitor the power consumption of the switch and PDs by configuring the unit to t

Seite 653

AT-9000 Switch Command Line User’s Guide225Displaying PoE InformationThe switch allows you to display PoE information using three commands. Each comma

Seite 654

Chapter 11: Power Over Ethernet226This example displays the PoE information of port 1 through port 4:awplus# show power inline interface port1.0.1-por

Seite 655

227Chapter 12Power Over Ethernet CommandsThe Power over Ethernet (PoE) commands are summarized in Table 22. These commands are only supported on the P

Seite 656

Chapter 12: Power Over Ethernet Commands228“POWER-INLINE PRIORITY” on page 242Port Interface Assigns a PoE priority level to a port.“POWER-INLINE USAG

Seite 657

AT-9000 Switch Command Line User’s Guide229CLEAR POWER-INLINE COUNTERS INTERFACESyntaxclear power-inline counters interface [port]ParameterportSpecifi

Seite 658

Chapter 12: Power Over Ethernet Commands230NO POWER-INLINE ALLOW-LEGACYSyntaxno power-inline allow-legacyParametersNoneModePort Interface modeDescript

Seite 659 - SPANNING-TREE LINK-TYPE

AT-9000 Switch Command Line User’s Guide231NO POWER-INLINE DESCRIPTIONSyntaxno power-inline descriptionParametersNoneModePort Interface modeDescriptio

Seite 660 - SPANNING-TREE LOOP-GUARD

Contents26Removing the Accounting Method List...1368Deleting

Seite 661

Chapter 12: Power Over Ethernet Commands232NO POWER-INLINE ENABLESyntaxno power-inline enableParametersNoneModePort Interface modeDescriptionUse this

Seite 662 - SPANNING-TREE MODE RSTP

AT-9000 Switch Command Line User’s Guide233NO POWER-INLINE MAXSyntaxno power-inline maxParametersNoneModePort Interface modeDescriptionUse this comman

Seite 663

Chapter 12: Power Over Ethernet Commands234NO POWER-INLINE PRIORITYSyntaxno power-inline priorityParametersNoneModePort Interface modeDescriptionUse t

Seite 664

AT-9000 Switch Command Line User’s Guide235NO POWER-INLINE USAGE-THRESHOLDSyntaxno power-inline usage-thresholdParametersNoneModeGlobal Configuration

Seite 665

Chapter 12: Power Over Ethernet Commands236NO SERVICE POWER-INLINESyntaxno service power-inlineParametersNoneModeGlobal Configuration modeDescriptionU

Seite 666

AT-9000 Switch Command Line User’s Guide237NO SNMP-SERVER ENABLE TRAP POWER-INLINESyntaxno snmp-server enable trap power-inlineParametersNoneModeGloba

Seite 667

Chapter 12: Power Over Ethernet Commands238POWER-INLINE ALLOW-LEGACYSyntaxpower-inline allow-legacyParametersNoneModePort Interface modeDescriptionUse

Seite 668 - SPANNING-TREE RSTP ENABLE

AT-9000 Switch Command Line User’s Guide239POWER-INLINE DESCRIPTIONSyntaxpower-inline description descriptionParametersdescriptionSpecifies a PD descr

Seite 669 - Chapter 45

Chapter 12: Power Over Ethernet Commands240POWER-INLINE ENABLESyntaxpower-inline enableParametersNoneModePort Interface modeDescriptionUse this comman

Seite 670

AT-9000 Switch Command Line User’s Guide241POWER-INLINE MAXSyntaxpower-inline max max_powerParametersmax_powerSpecifies the maximum power limit of the

Seite 671

AT-9000 Switch Command Line User’s Guide27RADIUS Client ...

Seite 672

Chapter 12: Power Over Ethernet Commands242POWER-INLINE PRIORITYSyntaxpower-inline priority critical|high|lowParameterscriticalSets ports to the Criti

Seite 673 - MSTI Guidelines

AT-9000 Switch Command Line User’s Guide243ExampleThis example assigns the Critical priority level to port 5:awplus> enableawplus# configure termin

Seite 674 - VLAN and MSTI Associations

Chapter 12: Power Over Ethernet Commands244POWER-INLINE USAGE-THRESHOLDSyntaxpower-inline usage-threshold thresholdParametersthresholdSpecifies the po

Seite 675 - Ports in Multiple MSTIs

AT-9000 Switch Command Line User’s Guide245SERVICE POWER-INLINESyntaxservice power-inlineParametersNoneModeGlobal Configuration modeDescriptionUse thi

Seite 676

Chapter 12: Power Over Ethernet Commands246SHOW POWER-INLINESyntaxshow power-inlineParameterNoneModePrivileged Exec modeDescriptionUse this command to

Seite 677

AT-9000 Switch Command Line User’s Guide247Table 23. SHOW POWER-INLINE CommandField DescriptionNominal Power The switch’s total available power in wat

Seite 678 - Guidelines

Chapter 12: Power Over Ethernet Commands248ExampleThis example displays PoE information about the switch and ports:awplus# show power-inlineOper The P

Seite 679

AT-9000 Switch Command Line User’s Guide249SHOW POWER-INLINE COUNTERS INTERFACESyntaxshow power-inline counters interface portParameterportSpecifies a

Seite 680

Chapter 12: Power Over Ethernet Commands250ExampleThis command displays the PoE event counters for ports 4 to 6:awplus# show power-inline counters int

Seite 681 - Summary of Guidelines

AT-9000 Switch Command Line User’s Guide251SHOW POWER-INLINE INTERFACESyntaxshow power-inline interface portParameterportSpecifies a port. You can dis

Seite 682

Contents28

Seite 683 - Associating VLANs to MSTIs

Chapter 12: Power Over Ethernet Commands252SHOW POWER-INLINE INTERFACE DETAILSyntaxshow power-inline interface port detailParameterportSpecifies a por

Seite 684

AT-9000 Switch Command Line User’s Guide253PoE admin The status of PoE on the port. The status can be one of the following: Enabled: PoE is enabled.

Seite 685

Chapter 12: Power Over Ethernet Commands254ExamplesThis example displays PoE information for port 1:awplus# show power-inline interface port1.0.1 deta

Seite 686

AT-9000 Switch Command Line User’s Guide255SNMP-SERVER ENABLE TRAP POWER-INLINESyntaxsnmp-server enable trap power-inlineParametersNoneModeGlobal Conf

Seite 687 - MSTP Root Guard

Chapter 12: Power Over Ethernet Commands256

Seite 688

257Chapter 13IPv4 and IPv6 Management AddressesThis chapter contains the following information: “Overview” on page 258 “Assigning an IPv4 Management

Seite 689 - MSTP Commands

Chapter 13: IPv4 and IPv6 Management Addresses258OverviewThis chapter explains how to assign the switch an IP address. The switch must have an IP addr

Seite 690 - Chapter 46: MSTP Commands

AT-9000 Switch Command Line User’s Guide259Here are the guidelines to assigning the switch management IPv4 and IPv6 addresses: The switch supports on

Seite 691 - INSTANCE MSTI-ID PRIORITY

Chapter 13: IPv4 and IPv6 Management Addresses260 If you assign both IPv4 and IPv6 addresses to the switch, they must be assigned to the same VLAN.

Seite 692

AT-9000 Switch Command Line User’s Guide261Assigning an IPv4 Management Address and Default GatewayThis section covers the following topics: “Adding

Seite 693 - INSTANCE MSTI-ID VLAN

1FiguresFigure 1: Command Modes ...

Seite 694

Chapter 13: IPv4 and IPv6 Management Addresses262Here are several examples of the command. The first example assigns the switch the management IPv4 ad

Seite 695

AT-9000 Switch Command Line User’s Guide263The next series of commands assigns the management address 143.24.55.67 and subnet mask 255.255.255.0 to th

Seite 696 - NO SPANNING-TREE MSTP ENABLE

Chapter 13: IPv4 and IPv6 Management Addresses264NoteIf an IPv4 default gateway is already assigned to the switch, you must delete it prior to enterin

Seite 697

AT-9000 Switch Command Line User’s Guide265awplus> enableawplus# configure terminalawplus(config)# no ip route 0.0.0.0/0 149.121.43.23Displaying an

Seite 698 - SHOW SPANNING-TREE MST CONFIG

Chapter 13: IPv4 and IPv6 Management Addresses266Assigning an IPv6 Management Address and Default GatewayThis section covers the following topics: “A

Seite 699 - SHOW SPANNING-TREE MST

AT-9000 Switch Command Line User’s Guide267NoteIf there is a management IPv6 address already assigned to the switch, you must delete it prior to enter

Seite 700

Chapter 13: IPv4 and IPv6 Management Addresses268The IPADDDRESS parameter is the default gateway to be assigned the switch. The address must be an IPv

Seite 701

AT-9000 Switch Command Line User’s Guide269Displaying anIPv6ManagementAddress andDefault GatewayThere are two commands for displaying a management IPv

Seite 702

Chapter 13: IPv4 and IPv6 Management Addresses270

Seite 703

271Chapter 14IPv4 and IPv6 Management Address CommandsThe IPv4 and IPv6 management address commands are summarized in Table 27.Table 27. Management IP

Seite 704 - SPANNING-TREE MODE MSTP

Allied Telesis is committed to meeting the requirements of the open source licenses including the GNU General Public License (GPL) and will make all r

Seite 705 - SPANNING-TREE MSTP ENABLE

List of Figures2Figure 50: SHOW INTERFACE Command...

Seite 706

Chapter 14: IPv4 and IPv6 Management Address Commands272“SHOW IPV6 INTERFACE” on page 292Privileged Exec Displays the IPv4 management address.“SHOW IP

Seite 707 - SPANNING-TREE MST INSTANCE

AT-9000 Switch Command Line User’s Guide273CLEAR IPV6 NEIGHBORSSyntaxclear ipv6 neighborsParametersNoneModePrivileged Exec modeDescriptionUse this com

Seite 708

Chapter 14: IPv4 and IPv6 Management Address Commands274IP ADDRESSSyntaxip address ipaddress/maskParametersipaddressSpecifies a management IPv4 addres

Seite 709

AT-9000 Switch Command Line User’s Guide275ExamplesThis example assigns the switch the IPv4 management address 142.35.78.21 and subnet mask 255.255.25

Seite 710

Chapter 14: IPv4 and IPv6 Management Address Commands276IP ADDRESS DHCPSyntaxip address dhcpParametersNoneModeVLAN Interface modeDescriptionUse this c

Seite 711 - <region-name>

AT-9000 Switch Command Line User’s Guide277ExampleThis example activates the DHCP client so that the switch obtains its IPv4 management address from a

Seite 712 - REVISION

Chapter 14: IPv4 and IPv6 Management Address Commands278IP ROUTESyntaxip route 0.0.0.0/0 ipaddressParametersipaddressSpecifies an IPv4 default gateway

Seite 713 - Virtual LANs

AT-9000 Switch Command Line User’s Guide279ExampleThis example assigns the switch the IPv4 default gateway address 143.87.132.45:awplus> enableawpl

Seite 714

Chapter 14: IPv4 and IPv6 Management Address Commands280IPV6 ADDRESSSyntaxipv6 address ipaddress/maskParametersipaddressSpecifies an IPv6 management a

Seite 715 - Port-based and Tagged VLANs

AT-9000 Switch Command Line User’s Guide281and syslog servers). The VLAN must already exist on the switch before you use this command.Confirmation Com

Seite 716

AT-9000 Switch Command Line User’s Guide3Figure 110: Edge Port ...

Seite 717 -  Tagged VLANs

Chapter 14: IPv4 and IPv6 Management Address Commands282IPV6 ROUTESyntaxipv6 route ::/0 ipaddressParametersipaddressSpecifies an IPv6 address of a def

Seite 718 - Port-based VLAN Overview

AT-9000 Switch Command Line User’s Guide283ExampleThis example assigns the switch the IPv6 default gateway address 45ab:672:934c::78:17cb:awplus> e

Seite 719 - Identifier

Chapter 14: IPv4 and IPv6 Management Address Commands284NO IP ADDRESSSyntaxno ip addressParametersNoneModeVLAN Interface modeDescriptionUse this comma

Seite 720

AT-9000 Switch Command Line User’s Guide285NO IP ADDRESS DHCPSyntaxno ip address dhcpParametersNoneModeVLAN Interface modeDescriptionUse this command

Seite 721 - Example 1

Chapter 14: IPv4 and IPv6 Management Address Commands286NO IP ROUTESyntaxno ip route 0.0.0.0/0 ipaddressParametersipaddressSpecifies the current defau

Seite 722 - Example 2

AT-9000 Switch Command Line User’s Guide287NO IPV6 ADDRESSSyntaxno ipv6 addressParametersNoneModeVLAN Interface modeDescriptionUse this command to del

Seite 723

Chapter 14: IPv4 and IPv6 Management Address Commands288NO IPV6 ROUTESyntaxno ipv6 route ::/0 ipaddressParametersipaddressSpecifies the current IPv6 d

Seite 724 - Tagged VLAN Overview

AT-9000 Switch Command Line User’s Guide289SHOW IP INTERFACESyntaxshow ip interfaceParametersNoneModePrivileged Exec modeDescriptionUse this command t

Seite 725

Chapter 14: IPv4 and IPv6 Management Address Commands290SHOW IP ROUTESyntaxshow ip routeParametersNoneModePrivileged Exec modeDescriptionUse this comm

Seite 726 - Tagged VLAN

AT-9000 Switch Command Line User’s Guide291ExampleThe following example displays the routes on the switch:awplus# show ip route

Seite 727

List of Figures4Figure 170: SHOW SNMP-SERVER Command...

Seite 728

Chapter 14: IPv4 and IPv6 Management Address Commands292SHOW IPV6 INTERFACESyntaxshow ipv6 interfaceParametersNoneModePrivileged Exec modeDescriptionU

Seite 729 - Creating VLANs

AT-9000 Switch Command Line User’s Guide293SHOW IPV6 ROUTESyntaxshow ipv6 routeParametersNoneModePrivileged Exec modeDescriptionUse this command to di

Seite 730

Chapter 14: IPv4 and IPv6 Management Address Commands294

Seite 731

295Chapter 15Simple Network Time Protocol (SNTP) ClientThis chapter contains the following information: “Overview” on page 296 “Activating the SNTP

Seite 732 - Adding Tagged Ports to VLANs

Chapter 15: Simple Network Time Protocol (SNTP) Client296OverviewThe switch has a Simple Network Time Protocol (SNTP) client for setting its date and

Seite 733

AT-9000 Switch Command Line User’s Guide297Activating the SNTP Client and Specifying the IP Address of an NTP or SNTP ServerTo activate the SNTP clien

Seite 734

Chapter 15: Simple Network Time Protocol (SNTP) Client298Configuring Daylight Savings Time and UTC OffsetIf the time that the NTP or SNTP server provi

Seite 735

AT-9000 Switch Command Line User’s Guide299In this example, the client is configured for ST and a UTC offset of +2 hours and 45 minutes:awplus> ena

Seite 736 - Deleting VLANs

Chapter 15: Simple Network Time Protocol (SNTP) Client300Disabling the SNTP ClientTo disable the SNTP client so that the switch does not obtain its da

Seite 737 - Displaying the VLANs

AT-9000 Switch Command Line User’s Guide301Displaying the SNTP ClientTo display the settings of the SNTP client on the switch, use the SHOW NTP ASSOCI

Seite 738

5Table 1. Remote Software Tool Settings ...

Seite 739 - Port-based and Tagged VLAN

Chapter 15: Simple Network Time Protocol (SNTP) Client302Displaying the Date and TimeTo display the date and time, use the SHOW CLOCK command in the U

Seite 740 - NO SWITCHPORT ACCESS VLAN

303Chapter 16SNTP Client CommandsThe SNTP commands are summarized in Table 31.Table 31. Simple Network Time Protocol CommandsCommand Mode Description“

Seite 741 - NO SWITCHPORT TRUNK

Chapter 16: SNTP Client Commands304CLOCK SUMMER-TIMESyntaxclock summer-timeParametersNoneModeGlobal Configuration modeDescriptionUse this command to e

Seite 742

AT-9000 Switch Command Line User’s Guide305CLOCK TIMEZONESyntaxclock timezone +hh:mm|-hh:mmParametershh:mmSpecifies the number of hours and minutes di

Seite 743

Chapter 16: SNTP Client Commands306NO CLOCK SUMMER-TIMESyntaxno clock summer-timeParametersNoneModeGlobal Configuration modeDescriptionUse this comman

Seite 744 - SHOW VLAN

AT-9000 Switch Command Line User’s Guide307NO NTP PEERSyntaxno ntp serverParameterNoneModeGlobal Configuration modeDescriptionUse this command to deac

Seite 745

Chapter 16: SNTP Client Commands308NTP PEERSyntaxntp peer ipaddressParameteripaddressSpecifies an IP address of an SNTP or NTP server.ModeGlobal Confi

Seite 746 - SWITCHPORT ACCESS VLAN

AT-9000 Switch Command Line User’s Guide309PURGE NTPSyntaxpurge ntpParameterNoneModeGlobal Configuration modeDescriptionUse this command to disable th

Seite 747

Chapter 16: SNTP Client Commands310SHOW CLOCKSyntaxshow clockParametersNoneModesUser Exec mode and Privileged Exec modeDescriptionUse this command to

Seite 748 - SWITCHPORT MODE ACCESS

AT-9000 Switch Command Line User’s Guide311SHOW NTP ASSOCIATIONSSyntaxshow ntp associationsParametersNoneModePrivileged Exec modeDescriptionUse this c

Seite 749 - SWITCHPORT MODE TRUNK

Tables6Table 50. Event Log Commands ...

Seite 750

Chapter 16: SNTP Client Commands312ExampleThe following example displays the settings of the SNTP client:awplus# show ntp associationsUTC Offset The t

Seite 751 - SWITCHPORT TRUNK ALLOWED VLAN

AT-9000 Switch Command Line User’s Guide313SHOW NTP STATUSSyntaxshow ntp statusParametersNoneModePrivileged Exec modeDescriptionUse this command to di

Seite 752

Chapter 16: SNTP Client Commands314

Seite 753

315Chapter 17MAC Address TableThis chapter discusses the following topics: “Overview” on page 316 “Adding Static MAC Addresses” on page 318 “Deleti

Seite 754 - SWITCHPORT TRUNK NATIVE VLAN

Chapter 17: MAC Address Table316OverviewThe MAC address table stores the MAC addresses of all the network devices that are connected to the switch’s p

Seite 755

AT-9000 Switch Command Line User’s Guide317The period of time the switch waits before purging inactive dynamic MAC addresses is called the aging time.

Seite 756

Chapter 17: MAC Address Table318Adding Static MAC AddressesThe command for adding static unicast MAC addresses to the switch is MAC ADDRESS-TABLE STAT

Seite 757

AT-9000 Switch Command Line User’s Guide319awplus> enableawplus# configure terminalawplus(config)# mac address-table static 00:a0:d2:18:1a:11 disca

Seite 758

Chapter 17: MAC Address Table320Deleting MAC AddressesTo delete MAC addresses from the switch, use the CLEAR MAC ADDRESS-TABLE command in the Privileg

Seite 759 - Chapter 49

AT-9000 Switch Command Line User’s Guide321This example deletes all of the dynamic addresses learned on port 20: awplus> enableawplus# clear mac ad

Seite 760

AT-9000 Switch Command Line User’s Guide7Table 110. Deleting ARP Entries ...

Seite 761 - Figure 137. GVRP Example

Chapter 17: MAC Address Table322Setting the Aging TimerThe aging timer defines the length of time that inactive dynamic MAC addresses remain in the ta

Seite 762

AT-9000 Switch Command Line User’s Guide323Displaying the MAC Address TableTo view the aging time or the MAC address table, use the SHOW MAC ADDRESS-T

Seite 763

Chapter 17: MAC Address Table324This example displays the addresses learned on the ports in a VLAN with the VID 8:awplus# show mac address-table vlan

Seite 764 - GVRP and Network Security

325Chapter 18MAC Address Table CommandsThe MAC address table commands are summarized in Table 33.Table 33. MAC Address Table CommandsCommand Mode Desc

Seite 765

Chapter 18: MAC Address Table Commands326CLEAR MAC ADDRESS-TABLESyntaxclear mac address-table dynamic|static [address macaddress]|[interface port]|[vl

Seite 766 - Enabling GVRP on the Switch

AT-9000 Switch Command Line User’s Guide327ExamplesThis example deletes all of the dynamic addresses from the table:awplus> enableawplus# clear mac

Seite 767 - Enabling GIP on the Switch

Chapter 18: MAC Address Table Commands328MAC ADDRESS-TABLE AGEING-TIMESyntaxmac address-table ageing-time value|noneParameterageing-timeSpecifies the

Seite 768 - Enabling GVRP on the Ports

AT-9000 Switch Command Line User’s Guide329This example disables the aging timer so that the switch does not delete inactive dynamic MAC addresses fro

Seite 769 - Setting the GVRP Timers

Chapter 18: MAC Address Table Commands330MAC ADDRESS-TABLE STATICSyntaxmac address-table static macaddress forward|discard interface port [vlan vlan-n

Seite 770

AT-9000 Switch Command Line User’s Guide331Confirmation Command“SHOW MAC ADDRESS-TABLE” on page 334ExamplesThis example adds the static MAC address 44

Seite 772 - Disabling GIP on the Switch

Chapter 18: MAC Address Table Commands332NO MAC ADDRESS-TABLE STATICSyntaxno mac address-table static macaddress forward|discard interface port [vlan

Seite 773 - Disabling GVRP on the Switch

AT-9000 Switch Command Line User’s Guide333Confirmation Command“SHOW MAC ADDRESS-TABLE” on page 334ExamplesThis example deletes the MAC address 00:A0:

Seite 774

Chapter 18: MAC Address Table Commands334SHOW MAC ADDRESS-TABLESyntaxshow mac address-table begin|exclude|include [interface port]|[vlan vid]Parameter

Seite 775 - Displaying GVRP

AT-9000 Switch Command Line User’s Guide335An example of the table is shown in Figure 77.Figure 77. SHOW MAC ADDRESS-TABLE CommandThe Aging Interval f

Seite 776

Chapter 18: MAC Address Table Commands336The Multicast Switch Forwarding Database contains the multicast addresses. The columns are defined in this ta

Seite 777

337Chapter 19Enhanced StackingThis chapter discusses the following topics: “Overview” on page 338 “Configuring the Command Switch” on page 341 “Con

Seite 778

Chapter 19: Enhanced Stacking338OverviewEnhanced stacking is a management tool that allows you to manage different AT-9000 Switches from one managemen

Seite 779 - CONVERT DYNAMIC VLAN

AT-9000 Switch Command Line User’s Guide339 A member switch can be any distance from the command switch, so long as the distance adheres to Ethernet

Seite 780 - GVRP APPLICANT STATE ACTIVE

Chapter 19: Enhanced Stacking3402. On the switch chosen to be the command switch, activate enhanced stacking and change its stacking status to command

Seite 781 - GVRP APPLICANT STATE NORMAL

AT-9000 Switch Command Line User’s Guide341Configuring the Command SwitchHere is an example on how to configure the switch as the command switch of th

Seite 782 - GVRP ENABLE

9PrefaceThis is the command line management guide for the AT-9000/12POE, AT-9000/28, AT-9000/28POE, AT-9000/28SP, and AT-9000/52 Managed Layer 2-4 Gig

Seite 783 - GVRP REGISTRATION

Chapter 19: Enhanced Stacking3422. After creating the common VLAN on the switch, assign it the management IP address and default gateway:3. Use the ES

Seite 784 - GVRP TIMER JOIN

AT-9000 Switch Command Line User’s Guide343awplus# writeSave the configuration.

Seite 785 - GVRP TIMER LEAVE

Chapter 19: Enhanced Stacking344Configuring a Member SwitchThis example shows you how to configure the switch as a member switch of an enhanced stack.

Seite 786 - GVRP TIMER LEAVEALL

AT-9000 Switch Command Line User’s Guide3453. To save the configuration, enter the WRITE command in the Privileged Executive mode.4. Connect the switc

Seite 787 - NO GVRP ENABLE

Chapter 19: Enhanced Stacking346Managing the Member Switches of an Enhanced StackHere are the steps on how to manage the member switches of an enhance

Seite 788 - NO GVRP TIMER JOIN

AT-9000 Switch Command Line User’s Guide3476. When you are finished managing the member switch, enter the EXIT command from the User Exec mode or Priv

Seite 789 - NO GVRP TIMER LEAVE

Chapter 19: Enhanced Stacking348Changing the Enhanced Stacking ModeIf you want to change the enhanced stacking mode of a switch from command to member

Seite 790 - NO GVRP TIMER LEAVEALL

AT-9000 Switch Command Line User’s Guide3492. On the member switch, change its mode from member to command with the ESTACK COMMAND-SWITCH command.3. O

Seite 791 - PURGE GVRP

Chapter 19: Enhanced Stacking350Uploading Boot Configuration Files from the Command Switch to Member SwitchesYou may use the enhanced stacking feature

Seite 792 - SHOW GVRP APPLICANT

AT-9000 Switch Command Line User’s Guide351The second prompt is shown here:Enter the list of switches ->At the prompt, enter the enhanced stack num

Seite 793 - SHOW GVRP CONFIGURATION

10Document ConventionsThis document uses the following conventions:NoteNotes provide additional information.CautionCautions inform you that performing

Seite 794 - SHOW GVRP MACHINE

Chapter 19: Enhanced Stacking352Here are the steps to perform on the command switch to upload the configuration file from its file system to the membe

Seite 795 - SHOW GVRP STATISTICS

AT-9000 Switch Command Line User’s Guide353Here is another example of the feature. This example uploads a configuration file to a new switch in an enh

Seite 796 - Transmit GARP Messages: Empty

Chapter 19: Enhanced Stacking3543. Use the ESTACK RUN command in the Global Configuration mode to activate enhanced stacking on the switch. It is not

Seite 797 - SHOW GVRP TIMER

AT-9000 Switch Command Line User’s Guide3553. If the new member switch is to use BOOT.CFG as the name of its active boot configuration file, you compl

Seite 798

Chapter 19: Enhanced Stacking356awplus# show estack remotelistReconfirm the enhanced stacking ID number of the replacement member switch.awplus# confi

Seite 799 - MAC Address-based VLANs

AT-9000 Switch Command Line User’s Guide357Uploading the Management Software from the Command Switch to Member SwitchesYou may use enhanced stacking t

Seite 800

Chapter 19: Enhanced Stacking358CautionA member switch stops forwarding network traffic after it receives the management software from the command swi

Seite 801

AT-9000 Switch Command Line User’s Guide359Disabling Enhanced StackingThe command that disables enhanced stacking on a switch is the NO ESTACK RUN com

Seite 802

Chapter 19: Enhanced Stacking360

Seite 803 - Switches

361Chapter 20Enhanced Stacking CommandsThe enhanced stacking commands are summarized in Table 36.Table 36. Enhanced Stacking CommandsCommand Mode Desc

Seite 804

AT-9000 Switch Command Line User’s Guide11Where to Find Web-based GuidesThe installation and user guides for all of the Allied Telesis products are av

Seite 805

Chapter 20: Enhanced Stacking Commands362“UPLOAD IMAGE REMOTELIST” on page 376Global ConfigurationUploads the management software on the command switc

Seite 806 - General Steps

AT-9000 Switch Command Line User’s Guide363ESTACK COMMAND-SWITCHSyntaxestack command-switchParameterNoneModeGlobal Configuration modeDescription Use

Seite 807

Chapter 20: Enhanced Stacking Commands364ESTACK RUNSyntaxestack runParameterNoneModeGlobal Configuration modeDescriptionUse this command to activate e

Seite 808

AT-9000 Switch Command Line User’s Guide365NO ESTACK COMMAND-SWITCHSyntaxno estack command-switchParameterNoneModeGlobal Configuration modeDescription

Seite 809 - Removing MAC Addresses

Chapter 20: Enhanced Stacking Commands366NO ESTACK RUNSyntaxno estack runParameterNoneModeGlobal Configuration modeDescriptionUse this command to disa

Seite 810

AT-9000 Switch Command Line User’s Guide367RCOMMANDSyntaxrcommand switch_idParametersswitch_idSpecifies the ID number of a member switch you want to m

Seite 811 - Displaying VLANs

Chapter 20: Enhanced Stacking Commands368REBOOT ESTACK MEMBERSyntaxreboot estack member id_number | allParametersid_numberSpecifies the enhanced stack

Seite 812

AT-9000 Switch Command Line User’s Guide369ExamplesThis example reboots a member switch that has the ID number 3:awplus> enableawplus# configure te

Seite 813

Chapter 20: Enhanced Stacking Commands370SHOW ESTACKSyntaxshow estackParametersNoneModePrivileged Exec modeDescriptionUse this command to display whet

Seite 814

AT-9000 Switch Command Line User’s Guide371ExampleThe following example displays whether enhanced stacking is enabled or disabled on the switch and wh

Seite 816

12Contacting Allied TelesisIf you need assistance with this product, you may contact Allied Telesis technical support by going to the Support & Se

Seite 817 - macaddress

Chapter 20: Enhanced Stacking Commands372SHOW ESTACK COMMAND-SWITCHSyntaxshow estack command-switchParametersNoneModePrivileged Exec modeDescriptionUs

Seite 818

AT-9000 Switch Command Line User’s Guide373SHOW ESTACK REMOTELISTSyntaxshow estack remotelist [name] [series]ParametersnameSorts the list of switches

Seite 819

Chapter 20: Enhanced Stacking Commands374This example sorts the switches by host name:awplus> enableawplus# configure terminalawplus(config)# show

Seite 820 - SHOW VLAN MACADDRESS

AT-9000 Switch Command Line User’s Guide375UPLOAD CONFIG REMOTELISTSyntaxupload config remotelistParametersNoneModeGlobal Configuration modeDescriptio

Seite 821

Chapter 20: Enhanced Stacking Commands376UPLOAD IMAGE REMOTELISTSyntaxupload image remotelistParametersNoneModeGlobal Configuration modeDescriptionUse

Seite 822 - VLAN MACADDRESS

AT-9000 Switch Command Line User’s Guide377CautionThe member switches stop forwarding network traffic after they receive the management software from

Seite 823 - Sales and the VID 3:

Chapter 20: Enhanced Stacking Commands378

Seite 824

379Chapter 21Port MirrorThis chapter discusses the following topics: “Overview” on page 380 “Creating the Port Mirror or Adding New Source Ports” on

Seite 825

Chapter 21: Port Mirror380OverviewThe port mirror is a management tool that allows you to monitor the traffic on one or more ports on the switch. It w

Seite 826

AT-9000 Switch Command Line User’s Guide381Creating the Port Mirror or Adding New Source PortsThe command to create the port mirror is the MIRROR INTE

Seite 827

13Section IGetting StartedThis section contains the following chapters: Chapter 1, “AlliedWare Plus Command Line Interface” on page 15 Chapter 2, “S

Seite 828

Chapter 21: Port Mirror382Removing Source Ports or Deleting the Port MirrorTo remove source ports from the port mirror, enter the Port Interface mode

Seite 829 - Private Port VLANs

AT-9000 Switch Command Line User’s Guide383Combining the Port Mirror with Access Control ListsYou may combine the port mirror with an access control l

Seite 830

Chapter 21: Port Mirror384awplus(config)# interface port1.0.14,port1.0.15Enter the Port Interface modes for ports 14 and 15.awplus(config-if)# access-

Seite 831 - Functionality

AT-9000 Switch Command Line User’s Guide385Displaying the Port MirrorTo display the port mirror, go to the Privileged Exec mode and enter the SHOW MIR

Seite 832

Chapter 21: Port Mirror386

Seite 833 - Creating Private VLANs

387Chapter 22Port Mirror CommandsThe port mirror commands are summarized in Table 38.Table 38. Port Mirror CommandsCommand Mode Description“MIRROR” on

Seite 834 - Adding Host and Uplink Ports

Chapter 22: Port Mirror Commands388MIRRORSyntaxmirrorParametersNoneModePort Interface modeDescriptionUse this command to designate the destination por

Seite 835

AT-9000 Switch Command Line User’s Guide389MIRROR INTERFACESyntaxmirror interface source_ports direction receive|transmit|bothParameterssource_portsSp

Seite 836 - Displaying Private VLANs

Chapter 22: Port Mirror Commands390ExampleThis example configures the port mirror to copy the ingress traffic on ports 3 and 4, the source ports, to p

Seite 837 - Private Port VLAN Commands

AT-9000 Switch Command Line User’s Guide391NO MIRROR INTERFACESyntaxno mirror interface source_portsParameterssource_portsSpecifies a source port of t

Seite 839 - PRIVATE-VLAN

Chapter 22: Port Mirror Commands392SHOW MIRRORSyntaxshow mirrorParametersNoneModesPrivileged Exec modeDescriptionUse this command to display the sourc

Seite 840 - SHOW VLAN PRIVATE-VLAN

AT-9000 Switch Command Line User’s Guide393If you are using the port mirror with access control lists to copy subsets of ingress packets on source por

Seite 841

Chapter 22: Port Mirror Commands394

Seite 842

395Chapter 23Internet Group Management Protocol (IGMP) SnoopingThis chapter discusses the following topics: “Overview” on page 396 “Host Node Topolo

Seite 843 - Voice VLAN Commands

Chapter 23: Internet Group Management Protocol (IGMP) Snooping396OverviewIGMP snooping allows the switch to control the flow of multicast packets from

Seite 844 - NO SWITCHPORT VOICE VLAN

AT-9000 Switch Command Line User’s Guide397improves switch performance and network security by restricting the flow of multicast packets to only those

Seite 845 - SWITCHPORT VOICE DSCP

Chapter 23: Internet Group Management Protocol (IGMP) Snooping398Host Node TopologyThe switch has a host node topology setting. You use this setting t

Seite 846 - SWITCHPORT VOICE VLAN

AT-9000 Switch Command Line User’s Guide399Enabling IGMP SnoopingThe command to enable IGMP Snooping on the switch is the IP IGMP SNOOPING command in

Seite 847

Chapter 23: Internet Group Management Protocol (IGMP) Snooping400Configuring the IGMP Snooping CommandsThis table lists the IGMP Snooping commands wit

Seite 848

AT-9000 Switch Command Line User’s Guide401This example limits the switch to two multicast groups and specifies that there is only one host node per p

Seite 849 - VLAN Stacking

15Chapter 1AlliedWare Plus Command Line InterfaceThis chapter has the following sections: “Management Sessions” on page 16 “Management Interfaces” o

Seite 850

Chapter 23: Internet Group Management Protocol (IGMP) Snooping402Disabling IGMP SnoopingThe command to disable IGMP Snooping on the switch is the NO I

Seite 851 - Section III: File System 823

AT-9000 Switch Command Line User’s Guide403Displaying IGMP SnoopingTo display the settings of IGMP Snooping and its status, use the SHOW IP IGMP SNOOP

Seite 852 - Components

Chapter 23: Internet Group Management Protocol (IGMP) Snooping404

Seite 853 - VLAN Stacking Process

405Chapter 24IGMP Snooping CommandsThe IGMP snooping commands are summarized in Table 41 and are described in detail within the chapter.Table 41. Inte

Seite 854 - Example of VLAN Stacking

Chapter 24: IGMP Snooping Commands406CLEAR IP IGMPSyntaxclear ip igmpParametersNoneModePrivileged Exec modeDescriptionUse this command to clear all IG

Seite 855 - Section III: File System 827

AT-9000 Switch Command Line User’s Guide407IP IGMP LIMITSyntaxip igmp limit multicastgroupsParametermulticastgroupsSpecifies the maximum number of mul

Seite 856 - 828 Section III: File System

Chapter 24: IGMP Snooping Commands408IP IGMP QUERIER-TIMEOUTSyntaxip igmp querier-timeout timeoutParameterstimeoutSpecifies the time period in seconds

Seite 857 - Section III: File System 829

AT-9000 Switch Command Line User’s Guide409IP IGMP SNOOPINGSyntaxip igmp snoopingParametersNoneModeGlobal Configuration modeDescriptionUse this comman

Seite 858 - 830 Section III: File System

Chapter 24: IGMP Snooping Commands410IP IGMP SNOOPING FLOOD-UNKNOWN-MCASTSyntaxip igmp snooping flood-unknown-mcastParameterNoneModeGlobal Configurati

Seite 859 - VLAN Stacking Commands

AT-9000 Switch Command Line User’s Guide411awplus> enableawplus# configure terminalawplus(config)# ip igmp snoopingawplus(config)# ip igmp snooping

Seite 860 - NO SWITCHPORT VLAN-STACKING

Chapter 1: AlliedWare Plus Command Line Interface16Management SessionsYou can manage the switch locally or remotely. Local management is conducted thr

Seite 861 - PLATFORM VLAN-STACKING-TPID

Chapter 24: IGMP Snooping Commands412IP IGMP SNOOPING MROUTERSyntaxip igmp snooping mrouter interface portParameterportSpecifies a port connected to a

Seite 862 - SHOW VLAN VLAN-STACKING

AT-9000 Switch Command Line User’s Guide413IP IGMP STATUSSyntaxip igmp status single | multipleParameterssingleActivates the single-host per port sett

Seite 863 - SWITCHPORT VLAN-STACKING

Chapter 24: IGMP Snooping Commands414NO IP IGMP SNOOPINGSyntaxno ip igmp snoopingParametersNoneModeGlobal Configuration modeDescriptionUse this comman

Seite 864 - 836 Section III: File System

AT-9000 Switch Command Line User’s Guide415NO IP IGMP SNOOPING MROUTERSyntaxno ip igmp snooping mrouter interface portParameterportSpecifies a multica

Seite 865 - Port Security

Chapter 24: IGMP Snooping Commands416SHOW IP IGMP SNOOPINGSyntaxshow ip igmp snoopingParametersNoneModePrivileged Exec modeDescriptionUse this command

Seite 866

AT-9000 Switch Command Line User’s Guide417The information the command displays is explained in Table 42.Table 42. SHOW IP IGMP SNOOPING CommandParame

Seite 867 - Chapter 58

Chapter 24: IGMP Snooping Commands418ExampleThe following example displays the IGMP snooping parameters:awplus# show ip igmp snoopingPort/Trunk ID The

Seite 868

419Chapter 25Multicast CommandsThe multicast commands are summarized in Table 43.Table 43. Multicast CommandsCommand Mode Description“NO SWITCHPORT BL

Seite 869

Chapter 25: Multicast Commands420NO SWITCHPORT BLOCK EGRESS-MULTICASTSyntaxno switchport block egress-multicastParametersNoneModePort Interface modeDe

Seite 870 - Configuring Ports

AT-9000 Switch Command Line User’s Guide421NO SWITCHPORT BLOCK INGRESS-MULTICASTSyntaxno switchport block ingress-multicastParametersNoneModePort Inte

Seite 871

AT-9000 Switch Command Line User’s Guide17To support remote management, the switch must have a management IP address. For instructions on how to assig

Seite 872

Chapter 25: Multicast Commands422SWITCHPORT BLOCK EGRESS-MULTICASTSyntaxswitchport block egress-multicastParametersNoneModePort Interface modeDescript

Seite 873

AT-9000 Switch Command Line User’s Guide423SWITCHPORT BLOCK INGRESS-MULTICASTSyntaxswitchport block ingress-multicastParametersNoneModePort Interface

Seite 874

Chapter 25: Multicast Commands424

Seite 875 - INTERFACE Command

425Section IIIFile SystemThis section contains the following chapters: Chapter 26, “File System” on page 427 Chapter 27, “File System Commands” on p

Seite 877

427Chapter 26File SystemThis chapter discusses the following topics: “Overview” on page 428 “Copying Boot Configuration Files” on page 429 “Renamin

Seite 878 - NO SWITCHPORT PORT-SECURITY

Chapter 26: File System428OverviewThe file system in the switch stores the following types of files: Boot configuration files Encryption key pairsTh

Seite 879

AT-9000 Switch Command Line User’s Guide429Copying Boot Configuration FilesMaintaining a history of the configuration settings of the switch can prove

Seite 880 - SHOW PORT-SECURITY INTERFACE

Chapter 26: File System430Renaming Boot Configuration FilesTo rename boot configuration files in the file system, use the MOVE command, found in the P

Seite 881

AT-9000 Switch Command Line User’s Guide431Deleting Boot Configuration FilesIf the file system becomes cluttered with unnecessary configuration files,

Seite 882

Chapter 1: AlliedWare Plus Command Line Interface18The switch supports the following MIBs for SNMP management: atistackinfo.mib atiEdgeSwtich.mib R

Seite 883

Chapter 26: File System432Displaying the Specifications of the File SystemThe User Exec mode and the Privileged Exec mode have a command that lets you

Seite 884

AT-9000 Switch Command Line User’s Guide433Listing the Files in the File SystemTo view the names of the files in the file system of the switch, use th

Seite 885 - SWITCHPORT PORT-SECURITY

Chapter 26: File System434

Seite 886

435Chapter 27File System CommandsThe file system commands are summarized in Table 45.Table 45. File System CommandsCommand Mode Description“COPY” on p

Seite 887

Chapter 27: File System Commands436COPYSyntaxcopy sourcefile.cfg destinationfile.cfgParameterssourcefile.cfgSpecifies the name of the boot configurati

Seite 888

AT-9000 Switch Command Line User’s Guide437DELETESyntaxdelete filename.cfgParameterfilename.cfgSpecifies the name of the boot configuration file to be

Seite 889

Chapter 27: File System Commands438DELETE FORCESyntaxdelete force filename.extParameterfilename.extSpecifies the name of the boot configuration file t

Seite 890

AT-9000 Switch Command Line User’s Guide439DIRSyntaxdirParameterNoneModePrivileged Exec modeDescriptionUse this command to list the names of the files

Seite 891 - Chapter 60

Chapter 27: File System Commands440MOVESyntaxmove filename1.cfg filename2.cfgParametersfilename1.cfgSpecifies the name of the boot configuration file

Seite 892

AT-9000 Switch Command Line User’s Guide441SHOW FILE SYSTEMSSyntaxshow file systemsParameterNoneModePrivileged Exec modeDescriptionUse this command to

Seite 893 - Authentication Process

AT-9000 Switch Command Line User’s Guide19Management InterfacesThe switch has two management interfaces: AlliedWare Plus command line Web browser wi

Seite 894 - Port Roles

Chapter 27: File System Commands442ExampleThe following example displays the specifications of the file system:awplus# show file systemsS/D/V The memo

Seite 895

443Chapter 28Boot Configuration FilesThis chapter discusses the following topics: “Overview” on page 444 “Specifying the Active Boot Configuration F

Seite 896

Chapter 28: Boot Configuration Files444OverviewThe changes that you make to the parameters settings of the switch are saved as a series of commands in

Seite 897 -  Multi supplicant mode

AT-9000 Switch Command Line User’s Guide445Specifying the Active Boot Configuration FileTo create or designate a new active boot configuration file fo

Seite 898

Chapter 28: Boot Configuration Files446Here are a couple examples of the command. The first example creates a new active boot configuration file calle

Seite 899 - Multi Supplicant

AT-9000 Switch Command Line User’s Guide447Creating a New Boot Configuration FileIt is a good idea to periodically make copies of the current configur

Seite 900

Chapter 28: Boot Configuration Files448Displaying the Active Boot Configuration FileTo display the name of the active boot configuration file on the s

Seite 901

449Chapter 29Boot Configuration File CommandsThe boot configuration file commands are summarized in Table 47 and described in detail within the chapte

Seite 902

Chapter 29: Boot Configuration File Commands450BOOT CONFIG-FILESyntaxboot config-file filename.cfgParameterfilenameSpecifies the name of a boot config

Seite 903 - RADIUS Server

AT-9000 Switch Command Line User’s Guide451Confirmation Command“SHOW BOOT” on page 456.ExamplesThis example designates a file called “region2asw.cfg”

Seite 904 - Guest VLAN

Chapter 1: AlliedWare Plus Command Line Interface20Local Manager AccountYou must log on to manage the switch. This requires a valid user name and pass

Seite 905 - RADIUS Accounting

Chapter 29: Boot Configuration File Commands452COPY RUNNING-CONFIGSyntaxcopy running-config filename.cfgParameterfilenameSpecifies a name for a new bo

Seite 906

AT-9000 Switch Command Line User’s Guide453COPY RUNNING-CONFIG STARTUP-CONFIGSyntaxcopy running-config startup-configParametersNoneModePrivileged Exec

Seite 907

Chapter 29: Boot Configuration File Commands454ERASE STARTUP-CONFIGSyntaxerase startup-configParametersNoneModePrivileged Exec modeDescriptionUse this

Seite 908

AT-9000 Switch Command Line User’s Guide455NO BOOT CONFIG-FILESyntaxno boot config-fileParameterNoneModeGlobal Configuration modeDescriptionUse this c

Seite 909

Chapter 29: Boot Configuration File Commands456SHOW BOOTSyntaxshow bootParameterNoneModePrivileged Exec modeDescriptionUse this command to display the

Seite 910

AT-9000 Switch Command Line User’s Guide457ExampleThis command displays the name of the active boot configuration file and the version numbers of the

Seite 911 - Operating Modes

Chapter 29: Boot Configuration File Commands458SHOW STARTUP-CONFIGSyntaxshow startup-configParametersNoneModePrivileged Exec modeDescriptionUse this c

Seite 912

AT-9000 Switch Command Line User’s Guide459WRITESyntaxwriteParametersNoneModePrivileged Exec modeDescriptionUse this command to update the active boot

Seite 913 - Configuring Reauthentication

Chapter 29: Boot Configuration File Commands460

Seite 914

461Chapter 30File TransferThis chapter discusses the following topics: “Overview” on page 462 “Uploading or Downloading Files with TFTP” on page 463

Seite 915

AT-9000 Switch Command Line User’s Guide21AlliedWare Plus Command ModesThe AlliedWare Plus command line interface consists of a series of modes that a

Seite 916

Chapter 30: File Transfer462OverviewThis chapter discusses how to download files onto the switch and upload files onto the switch. You can download th

Seite 917

AT-9000 Switch Command Line User’s Guide463Uploading or Downloading Files with TFTP “Downloading New Management Software with TFTP” next “Downloadin

Seite 918

Chapter 30: File Transfer464The IPADDRESS parameter is the IP address of the TFTP server, and the FILENAME parameter is the name of the new management

Seite 919 - Control Commands

AT-9000 Switch Command Line User’s Guide465In this example of the command, the IP address of the TFTP server is 152.34.67.8, and the filename of the b

Seite 920

Chapter 30: File Transfer466To upload a file from the file system of the switch using TFTP:1. Start a local or remote management session on the switch

Seite 921

AT-9000 Switch Command Line User’s Guide467Uploading or Downloading Files with Zmodem “Downloading Files to the Switch with Zmodem” next “Uploading

Seite 922

Chapter 30: File Transfer4687. At this point, do one of the following: To configure the switch using the settings in the newly designated active boot

Seite 923 - AUTH DYNAMIC-VLAN-CREATION

AT-9000 Switch Command Line User’s Guide469After you enter the command, the switch displays this message:Waiting to send ...4. Use your terminal or te

Seite 924 - VLAN assignments:

Chapter 30: File Transfer470Downloading Files with Enhanced StackingIf you are using the enhanced stacking feature, you can automate the process of up

Seite 925 - AUTH GUEST-VLAN

AT-9000 Switch Command Line User’s Guide4714. Enter the ID numbers of the switches to receive the management software from the command switch. The ID

Seite 926 - AUTH HOST-MODE

5Preface ... 9Document Conventi

Seite 927

Chapter 1: AlliedWare Plus Command Line Interface22NoteBy default, the mode prompts are prefixed with the “awplus” string. To change this string, use

Seite 928 - AUTH REAUTHENTICATION

Chapter 30: File Transfer472

Seite 929 - AUTH TIMEOUT QUIET-PERIOD

473Chapter 31File Transfer CommandsThe file transfer commands are summarized in Table 49 and described in detail within the chapter.Table 49. File Tra

Seite 930 - AUTH TIMEOUT REAUTH-PERIOD

Chapter 31: File Transfer Commands474COPY FILENAME ZMODEMSyntax:copy filename.cfg zmodemParametersfilenameSpecifies the filename of a configuration fi

Seite 931 - AUTH TIMEOUT SERVER-TIMEOUT

AT-9000 Switch Command Line User’s Guide475COPY FLASH TFTPSyntaxcopy flash tftp ipaddress filenameParametersipaddressSpecifies the IP address of a TFT

Seite 932 - AUTH TIMEOUT SUPP-TIMEOUT

Chapter 31: File Transfer Commands476COPY TFTP FLASHSyntaxcopy tftp flash ipaddress filenameParametersipaddressSpecifies the IP address of a TFTP serv

Seite 933 - AUTH-MAC ENABLE

AT-9000 Switch Command Line User’s Guide477ExamplesThis example downloads the new management software file “at9000_app.img” to the switch from a TFTP

Seite 934 - AUTH-MAC REAUTH-RELEARNING

Chapter 31: File Transfer Commands478COPY ZMODEMSyntaxcopy zmodemParametersNoneModePrivileged Exec modeDescriptionUse this command together with a Zmo

Seite 935 - DOT1X CONTROL-DIRECTION

AT-9000 Switch Command Line User’s Guide479UPLOAD IMAGE REMOTELISTSyntaxupload image remotelistParametersNoneModeGlobal Configuration modeDescriptionU

Seite 936

Chapter 31: File Transfer Commands480

Seite 937 - DOT1X EAP

481Section IVEvent MessagesThis section contains the following chapters: Chapter 32, “Event Log” on page 483 Chapter 33, “Event Log Commands” on pag

Seite 938

AT-9000 Switch Command Line User’s Guide23Console Line mode awplus (config-line)#  Sets the session timer for local management sessions. Activates a

Seite 940 - DOT1X MAX-REAUTH-REQ

483Chapter 32Event LogThis chapter covers the following topics: “Overview” on page 484 “Displaying the Event Log” on page 485 “Clearing the Event L

Seite 941 - DOT1X PORT-CONTROL AUTO

Chapter 32: Event Log484OverviewA managed switch is a complex piece of computer equipment that includes both hardware and software components. Multipl

Seite 942

AT-9000 Switch Command Line User’s Guide485Displaying the Event LogThere are two commands to display the messages stored in the event log. Both displa

Seite 943

Chapter 32: Event Log486Clearing the Event LogTo clear all the messages from the event log, use the CLEAR LOG BUFFERED command in the Privileged Exec

Seite 944 - DOT1X TIMEOUT TX-PERIOD

487Chapter 33Event Log CommandsThe event log commands are summarized in Table 50 and described in detail within this chapter.Table 50. Event Log Comma

Seite 945

Chapter 33: Event Log Commands488CLEAR LOG BUFFEREDSyntaxclear log bufferedParametersNone.ModePrivileged Exec modeDescriptionUse this command to delet

Seite 946 - NO AUTH DYNAMIC-VLAN-CREATION

AT-9000 Switch Command Line User’s Guide489LOG BUFFEREDSyntaxlog buffered level level program programParameterslevel Specifies the minimum severity le

Seite 947 - NO AUTH GUEST-VLAN

Chapter 33: Event Log Commands490Confirmation Command“SHOW LOG CONFIG” on page 496ExamplesThis example configures the log to save event messages that

Seite 948 - NO AUTH REAUTHENTICATION

AT-9000 Switch Command Line User’s Guide491NO LOG BUFFEREDSyntaxno log buffered [level level]|[program program]|[msgtext msgtext]ParameterslevelSpecif

Seite 949 - NO AUTH-MAC ENABLE

Chapter 1: AlliedWare Plus Command Line Interface24Moving Down the HierarchyTo move down the mode hierarchy, you have to step through each mode in seq

Seite 950 - NO DOT1X PORT-CONTROL

Chapter 33: Event Log Commands492awplus# configure terminalawplus(config)# no log buffered Program macOUtputID Type Status Details--------------------

Seite 951 - SHOW AUTH-MAC INTERFACE

AT-9000 Switch Command Line User’s Guide493SHOW LOGSyntaxshow logParametersNoneModePrivileged Exec modeDescriptionUse this command to display the mess

Seite 952

Chapter 33: Event Log Commands494Table 53 lists the modules and their abbreviations.Severity (continued) Warning: The issue reported by the message m

Seite 953

AT-9000 Switch Command Line User’s Guide495ExampleThe following command displays the messages in the event log:awplus# show logPKI Public Key Infrastr

Seite 954

Chapter 33: Event Log Commands496SHOW LOG CONFIGSyntaxshow log configParametersNoneModesPrivileged Exec modeDescriptionUse this command to display the

Seite 955 - SHOW DOT1X

AT-9000 Switch Command Line User’s Guide497SHOW LOG REVERSESyntaxshow log reverseParametersNoneModePrivileged Exec modeDescriptionUse this command to

Seite 956 - SHOW DOT1X INTERFACE

Chapter 33: Event Log Commands498SHOW LOG TAILSyntaxshow log tail [number]ParameternumberSpecifies the number of event messages to display. The range

Seite 957

499Chapter 34Syslog ClientThis chapter covers the following topics: “Overview” on page 500 “Creating Syslog Server Definitions” on page 501 “Deleti

Seite 958

Chapter 34: Syslog Client500OverviewThe switch has a syslog client. The client enables the switch to send its event messages to syslog servers on your

Seite 959 - Section IX

AT-9000 Switch Command Line User’s Guide501Creating Syslog Server DefinitionsTo configure the switch to send event messages to a syslog server, create

Seite 960

AT-9000 Switch Command Line User’s Guide25LINE VTYCommandYou use this command to move from the Global Configuration mode to the Virtual Terminal Line

Seite 961 - SNMPv1 and SNMPv2c

Chapter 34: Syslog Client502ENCO Encryption keysESTACK Enhanced stackingEVTLOG Event logFILE File systemGARP GARP GVRPHTTP Web serverIGMPSNOOP IGMP sn

Seite 962

AT-9000 Switch Command Line User’s Guide503This example of the command creates a new syslog definition for a syslog server that has the IP address 149

Seite 963

Chapter 34: Syslog Client504Deleting Syslog Server DefinitionsTo delete syslog server definitions from the switch, use the NO LOG HOST command in the

Seite 964 - Enabling SNMPv1 and SNMPv2c

AT-9000 Switch Command Line User’s Guide505Displaying the Syslog Server DefinitionsTo view the IP addresses of the syslog servers use the SHOW LOG CON

Seite 965 - Creating Community Strings

Chapter 34: Syslog Client506

Seite 966

507Chapter 35Syslog Client CommandsThe syslog client commands are summarized in Table 57 and described in detail within the chapter.Table 57. Syslog C

Seite 967

Chapter 35: Syslog Client Commands508LOG HOSTSyntaxlog host ipaddress [level level] [program program]ParametersipaddressSpecifies the IP address of a

Seite 968 - Deleting Community Strings

AT-9000 Switch Command Line User’s Guide509This example creates a new syslog definition for a syslog server that has the IP address 149.152.122.143. T

Seite 969 - Disabling SNMPv1 and SNMPv2c

Chapter 35: Syslog Client Commands510NO LOG HOSTSyntaxno log host ipaddressParametersipaddressSpecifies an IP address of a syslog server.ModeGlobal Co

Seite 970 - Displaying SNMPv1 and SNMPv2c

AT-9000 Switch Command Line User’s Guide511SHOW LOG CONFIGSyntaxshow log configParametersNoneModesPrivileged Exec modeDescriptionUse this command to d

Seite 971 - Exec mode:

Chapter 1: AlliedWare Plus Command Line Interface26Figure 8. INTERFACE PORT Command - Multiple PortsThe INTERFACE PORT command is also located in the

Seite 972

Chapter 35: Syslog Client Commands512ExampleThis example displays the configurations of the syslog server entries:awplus# show log config

Seite 973 - SNMPv1 and SNMPv2c Commands

513Section VPort TrunksThis section contains the following chapters: Chapter 36, “Static Port Trunks” on page 515 Chapter 37, “Static Port Trunk Com

Seite 975 - NO SNMP-SERVER

515Chapter 36Static Port TrunksThis chapter covers the following topics: “Overview” on page 516 “Creating New Static Port Trunks or Adding Ports To

Seite 976 - NO SNMP-SERVER COMMUNITY

Chapter 36: Static Port Trunks516OverviewStatic port trunks are groups of two to eight ports that act as single virtual links between the switch and o

Seite 977 - NO SNMP-SERVER ENABLE TRAP

AT-9000 Switch Command Line User’s Guide517 Source MAC Address / Destination MAC Address (Layer 2) Source IP Address (Layer 3) Destination IP Addre

Seite 978 - Global Configuration mode

Chapter 36: Static Port Trunks518For example, assume you selected source and destination MAC addresses for the load distribution method in our previou

Seite 979

AT-9000 Switch Command Line User’s Guide519are compatible with the device to which the trunk will be connected. When you create a static port trunk, t

Seite 980

Chapter 36: Static Port Trunks520Creating New Static Port Trunks or Adding Ports To Existing TrunksThe command to create new static port trunks or to

Seite 981

AT-9000 Switch Command Line User’s Guide521Specifying the Load Distribution MethodThe load distribution method defines how the switch distributes the

Seite 982

AT-9000 Switch Command Line User’s Guide27NoteA VLAN must be identified in this command by its VID and not by its name.VLANDATABASECommandYou use this

Seite 983 - SHOW RUNNING-CONFIG SNMP

Chapter 36: Static Port Trunks522Removing Ports from Static Port Trunks or Deleting TrunksTo remove ports from a static port trunk, enter the Port Int

Seite 984

AT-9000 Switch Command Line User’s Guide523Displaying Static Port TrunksTo display the member ports of static port trunks, use the SHOW STATIC-CHANNEL

Seite 985 - SHOW SNMP-SERVER COMMUNITY

Chapter 36: Static Port Trunks524

Seite 986

525Chapter 37Static Port Trunk CommandsThe static port trunk commands are summarized in Table 58 and described in detail within the chapter..Table 58.

Seite 987

Chapter 37: Static Port Trunk Commands526NO STATIC-CHANNEL-GROUPSyntaxno static-channel-groupParametersNoneModePort Interface modeDescriptionUse this

Seite 988

AT-9000 Switch Command Line User’s Guide527PORT-CHANNEL LOAD-BALANCESyntaxport-channel load-balance src-mac|dst-mac|src-dst-mac|src-ip|dst-ip|src-dst-

Seite 989 - SNMP-SERVER COMMUNITY

Chapter 37: Static Port Trunk Commands528ExampleThis example sets the load distribution method to destination MAC address for a trunk with an ID numbe

Seite 990 - SNMP-SERVER ENABLE TRAP

AT-9000 Switch Command Line User’s Guide529SHOW STATIC-CHANNEL-GROUPSyntaxshow static-channel-groupParametersNoneModesUser Exec mode and Privileged Ex

Seite 991 - SNMP-SERVER ENABLE TRAP AUTH

Chapter 37: Static Port Trunk Commands530STATIC-CHANNEL-GROUPSyntaxstatic-channel-group id_numberParametersid_numberSpecifies an ID number of a static

Seite 992

AT-9000 Switch Command Line User’s Guide531 Ports can be members of just one static port trunk at a time. A port that is already a member of a trunk

Seite 993

Chapter 1: AlliedWare Plus Command Line Interface28Moving Up the HierarchyThere are four commands for moving up the mode hierarchy. They are the EXIT,

Seite 994

Chapter 37: Static Port Trunk Commands532

Seite 995

533Chapter 38Link Aggregation Control Protocol (LACP)This chapter covers the following topics: “Overview” on page 534 “Creating New Aggregators” on

Seite 996

Chapter 38: Link Aggregation Control Protocol (LACP)534OverviewThe Link Aggregation Control Protocol (LACP) is used to increase the bandwidth between

Seite 997 - SNMPv3 Commands

AT-9000 Switch Command Line User’s Guide535Base Port The lowest numbered port in an aggregator is referred to as the base port. You cannot change the

Seite 998

Chapter 38: Link Aggregation Control Protocol (LACP)536 The lowest numbered port in an aggregator is called the base port. You cannot add ports that

Seite 999

AT-9000 Switch Command Line User’s Guide537Creating New AggregatorsTo create a new aggregator, move to the Port Interface mode of the aggregator’s mem

Seite 1000 - NO SNMP-SERVER ENGINEID LOCAL

Chapter 38: Link Aggregation Control Protocol (LACP)538Setting the Load Distribution MethodThe load distribution method determines the manner in which

Seite 1001 - NO SNMP-SERVER GROUP

AT-9000 Switch Command Line User’s Guide539Adding Ports to AggregatorsThe command to add ports to existing aggregators is the same command to create n

Seite 1002 - NO SNMP-SERVER HOST

Chapter 38: Link Aggregation Control Protocol (LACP)540Removing Ports from AggregatorsTo remove ports from an aggregator, use the NO CHANNEL-GROUP com

Seite 1003

AT-9000 Switch Command Line User’s Guide541Deleting AggregatorsTo delete an aggregator, remove all its ports with the NO CHANNEL-GROUP command, in the

Seite 1004 - NO SNMP-SERVER USER

AT-9000 Switch Command Line User’s Guide29Figure 16. Returning to the Privileged Exec Mode with the END CommandDISABLECommandTo return to the User Exe

Seite 1005 - NO SNMP-SERVER VIEW

Chapter 38: Link Aggregation Control Protocol (LACP)542Displaying AggregatorsThere are five SHOW commands for LACP. Two of them are mentioned here. Fo

Seite 1006 - SHOW SNMP-SERVER

AT-9000 Switch Command Line User’s Guide543Here is an example of the information.Figure 103. SHOW LACP SYS-ID CommandIt should be mentioned that while

Seite 1007 - SHOW SNMP-SERVER GROUP

Chapter 38: Link Aggregation Control Protocol (LACP)544

Seite 1008 - SHOW SNMP-SERVER HOST

545Chapter 39LACP CommandsThe LACP port trunk commands are summarized in Table 59 and described in detail within the chapter.Table 59. LACP Port Trunk

Seite 1009 - SHOW SNMP-SERVER USER

Chapter 39: LACP Commands546CHANNEL-GROUPSyntaxchannel-group id_numberParametersid_numberSpecifies the ID number of a new or an existing aggregator. T

Seite 1010 - SHOW SNMP-SERVER VIEW

AT-9000 Switch Command Line User’s Guide547ExamplesThese commands create a new aggregator consisting of ports 11 to 16. The ID number of the aggregato

Seite 1011 - SNMP-SERVER

Chapter 39: LACP Commands548LACP SYSTEM-PRIORITYSyntaxlacp system-priority priorityParametersprioritySpecifies the LACP system priority value for the

Seite 1012 - SNMP-SERVER ENGINEID LOCAL

AT-9000 Switch Command Line User’s Guide549NO CHANNEL-GROUPSyntaxno channel-groupParametersNoneModePort Interface modeDescriptionUse this command to r

Seite 1013 - SNMP-SERVER GROUP

Chapter 39: LACP Commands550PORT-CHANNEL LOAD-BALANCESyntaxport-channel load-balance src-mac|dst-mac|src-dst-mac|src-ip|dst-ip|src-dst-ipParameterssrc

Seite 1014 - Examples

AT-9000 Switch Command Line User’s Guide551Confirmation Command“SHOW ETHERCHANNEL DETAIL” on page 553ExampleThis example sets the load distribution me

Seite 1015 - SNMP-SERVER HOST

Chapter 1: AlliedWare Plus Command Line Interface30Port Numbers in CommandsThe ports on the switch are identified in the commands with the PORT parame

Seite 1016 - Chapter 64: SNMPv3 Commands

Chapter 39: LACP Commands552SHOW ETHERCHANNELSyntaxshow etherchannel id_numberParametersid_numberSpecifies the ID number of the aggregator.ModePrivile

Seite 1017 - SNMP-SERVER USER

AT-9000 Switch Command Line User’s Guide553SHOW ETHERCHANNEL DETAILSyntaxshow etherchannel detailParametersNoneModePrivileged Exec modeDescriptionUse

Seite 1018 - Confirmation Command

Chapter 39: LACP Commands554ExampleThis example displays detailed information about aggregators:awplus# show etherchannel detail

Seite 1019 - SNMP-SERVER VIEW

AT-9000 Switch Command Line User’s Guide555SHOW ETHERCHANNEL SUMMARYSyntaxshow etherchannel summaryParametersNoneModePrivileged Exec modeDescriptionUs

Seite 1020

Chapter 39: LACP Commands556SHOW LACP SYS-IDSyntaxshow lacp sys-idParametersNoneModePrivileged Exec modeDescriptionUse this command to display the LAC

Seite 1021 - Network Management

AT-9000 Switch Command Line User’s Guide557SHOW PORT ETHERCHANNELSyntaxshow port etherchannel [interface port]ParametersportSpecifies the port of an a

Seite 1022

Chapter 39: LACP Commands558

Seite 1023 - Chapter 65

559Section VISpanning Tree ProtocolsThis section contains the following chapters: Chapter 40, “STP, RSTP and MSTP Protocols” on page 561 Chapter 41,

Seite 1025

561Chapter 40STP, RSTP and MSTP ProtocolsThis chapter covers the following topics: “Overview” on page 562 “Bridge Priority and the Root Bridge” on p

Seite 1026 - Configuring the sFlow Agent

AT-9000 Switch Command Line User’s Guide31You can also combine individual ports and port ranges in the same command, as illustrated in these commands,

Seite 1027 - Configuring the Ports

Chapter 40: STP, RSTP and MSTP Protocols562OverviewThe Spanning Tree Protocol (STP), Rapid Spanning Tree Protocol (RSTP) and Multiple Spanning Tree Pr

Seite 1028 - Polling Interval

AT-9000 Switch Command Line User’s Guide563Bridge Priority and the Root BridgeThe first task that bridges perform when a spanning tree protocol is act

Seite 1029 - Enabling the sFlow Agent

Chapter 40: STP, RSTP and MSTP Protocols564Path Costs and Port CostsAfter the root bridge has been selected, the bridges determine if the network cont

Seite 1030 - Disabling the sFlow Agent

AT-9000 Switch Command Line User’s Guide565Port PriorityIf two paths have the same port cost, the bridges must select a preferred path. In some instan

Seite 1031 - Displaying the sFlow Agent

Chapter 40: STP, RSTP and MSTP Protocols566Forwarding Delay and Topology ChangesIf there is a change in the network topology due to a failure, removal

Seite 1032 - Configuration Example

AT-9000 Switch Command Line User’s Guide567Hello Time and Bridge Protocol Data Units (BPDU)The bridges that are part of a spanning tree domain communi

Seite 1033

Chapter 40: STP, RSTP and MSTP Protocols568Point-to-Point and Edge PortsPart of the task of configuring RSTP or MSTP is defining the port types on the

Seite 1034 - Chapter 65: sFlow Agent

AT-9000 Switch Command Line User’s Guide569Figure 110. Edge PortA port can be both a point-to-point and an edge port at the same time. It operates in

Seite 1035 - Chapter 66

Chapter 40: STP, RSTP and MSTP Protocols570Mixed STP and RSTP NetworksRSTP IEEE 802.1w is fully compliant with STP IEEE 802.1d. A network can have bot

Seite 1036 - NO SFLOW COLLECTOR IP

AT-9000 Switch Command Line User’s Guide571Spanning Tree and VLANsSTP and RSTP support a single-instance spanning tree that encompasses all the ports

Seite 1037 - NO SFLOW ENABLE

Contents6Saving Your Changes ...

Seite 1038 - SFLOW COLLECTOR IP

Chapter 1: AlliedWare Plus Command Line Interface32Combo Ports 25 to 28Ports 25 to 28 on the AT-9000/28, AT-9000/28POE, and AT-9000/28SP Managed Layer

Seite 1039 - SFLOW ENABLE

Chapter 40: STP, RSTP and MSTP Protocols572RSTP and MSTP BPDU GuardThis feature monitors the RSTP or MSTP edge ports on the switch for BPDU packets. E

Seite 1040 - SFLOW POLLING-INTERVAL

AT-9000 Switch Command Line User’s Guide573Here are the guidelines to this feature: BPDU guard is configured for each port and has only two possible

Seite 1041

Chapter 40: STP, RSTP and MSTP Protocols574STP, RSTP, MSTP Loop GuardAlthough spanning tree is designed to detect and prevent the formation of loops i

Seite 1042 - SFLOW SAMPLING-RATE

AT-9000 Switch Command Line User’s Guide575If you configured the SNMP community strings on the switch, an SNMP trap is sent to your management worksta

Seite 1043

Chapter 40: STP, RSTP and MSTP Protocols576Figure 114. Loop Guard Example 2But if loop guard is enabled on port 14 on switch 3, the port, instead of c

Seite 1044 - SHOW SFLOW

AT-9000 Switch Command Line User’s Guide577In the first example, the root bridge stops transmitting BPDUs. If switch 3 is not using loop guard, it con

Seite 1045

Chapter 40: STP, RSTP and MSTP Protocols578Figure 117. Loop Guard Example 5Switch 3Switch 1Old root bridgeRSTP stops operatingPort 4Loop guard changes

Seite 1046

AT-9000 Switch Command Line User’s Guide579STP and RSTP Root GuardThe Root Guard feature enforces the root bridge placement in a network. It ensures t

Seite 1047 - LLDP and LLDP-MED

Chapter 40: STP, RSTP and MSTP Protocols580

Seite 1048

581Chapter 41Spanning Tree Protocol (STP) ProceduresThis chapter provides the following procedures: “Designating STP as the Active Spanning Tree Prot

Seite 1049 - Optional LLDP

AT-9000 Switch Command Line User’s Guide33Command FormatThe following sections describe the command line interface features and the command syntax con

Seite 1050

Chapter 41: Spanning Tree Protocol (STP) Procedures582Designating STP as the Active Spanning Tree ProtocolBefore you can configure the STP parameters

Seite 1051 - MED TLVs

AT-9000 Switch Command Line User’s Guide583Enabling the Spanning Tree ProtocolTo enable STP on the switch, use the SPANNING-TREE STP ENABLE command in

Seite 1052

Chapter 41: Spanning Tree Protocol (STP) Procedures584Setting the Switch ParametersThis table lists the STP functions that are controlled at the switc

Seite 1053

AT-9000 Switch Command Line User’s Guide585This example of the command sets the switch’s priority value to 8,192: awplus> enableawplus# configure t

Seite 1054 - Chapter 67: LLDP and LLDP-MED

Chapter 41: Spanning Tree Protocol (STP) Procedures586Setting the Port ParametersThis table lists the STP functions that are controlled at the port le

Seite 1055

AT-9000 Switch Command Line User’s Guide587Disabling the Spanning Tree ProtocolTo disable STP on the switch, use the NO SPANNING-TREE STP ENABLE comma

Seite 1056 -  mac-phy-config

Chapter 41: Spanning Tree Protocol (STP) Procedures588Displaying STP SettingsTo view the STP settings on the switch, use the SHOW SPANNING-TREE in the

Seite 1057

589Chapter 42STP CommandsThe STP commands are summarized in Table 62 and described in detail within the chapter.Table 62. Spanning Tree Protocol Comma

Seite 1058 -  Network-policy

Chapter 42: STP Commands590“SPANNING-TREE PORTFAST BPDU-GUARD” on page 601Port Interface Enables the BPDU guard feature on a port so that the switch m

Seite 1059 - INTERFACE command to confirm

AT-9000 Switch Command Line User’s Guide591NO SPANNING-TREE STP ENABLESyntaxno spanning-tree stp enableParametersNoneModeGlobal Configuration modeDesc

Seite 1060

Chapter 1: AlliedWare Plus Command Line Interface34Startup MessagesThe switch generates the following series of status messages whenever it is powered

Seite 1061

Chapter 42: STP Commands592SHOW SPANNING-TREESyntaxshow spanning-tree [interface port]ParametersportSpecifies a port. You can specify more than one po

Seite 1062

AT-9000 Switch Command Line User’s Guide593ExamplesThis command displays the STP settings for all the ports:awplus# show spanning-treeThis command dis

Seite 1063

Chapter 42: STP Commands594SPANNING-TREE FORWARD-TIMESyntaxspanning-tree forward-time forwardtimeParametersforwardtimeSpecifies the forward time. The

Seite 1064

AT-9000 Switch Command Line User’s Guide595SPANNING-TREE GUARD ROOTSyntaxspanning-tree guard root ParametersNoneModePort Interface modeDescriptionUse

Seite 1065

Chapter 42: STP Commands596SPANNING-TREE HELLO-TIMESyntaxspanning-tree hello-time hellotimeParametershellotimeSpecifies the hello time. The range is 1

Seite 1066

AT-9000 Switch Command Line User’s Guide597SPANNING-TREE MAX-AGESyntaxspanning-tree max-age maxageParametersmaxageSpecifies the max-age parameter. The

Seite 1067

Chapter 42: STP Commands598SPANNING-TREE MODE STPSyntaxspanning-tree mode stpParametersNoneModeGlobal Configuration modeDescriptionUse this command to

Seite 1068

AT-9000 Switch Command Line User’s Guide599SPANNING-TREE PATH-COSTSyntaxspanning-tree path-cost path-costParameterspath-costSpecifies the cost of a po

Seite 1069 - Removing LLDP TLVs from Ports

Chapter 42: STP Commands600SPANNING-TREE PORTFASTSyntaxspanning-tree portfastParametersNoneModePort Interface modeDescriptionUse this command to desig

Seite 1070

AT-9000 Switch Command Line User’s Guide601SPANNING-TREE PORTFAST BPDU-GUARDSyntaxspanning-tree portfast bpdu-guardParametersNoneModePort Interface mo

Seite 1071

AT-9000 Switch Command Line User’s Guide35Figure 20. Startup Messages (continued)Initializing System ... done!Initializi

Seite 1072

Chapter 42: STP Commands602SPANNING-TREE PRIORITY (Bridge Priority)Syntaxspanning-tree priority priorityParametersprioritySpecifies a priority number

Seite 1073

AT-9000 Switch Command Line User’s Guide603SPANNING-TREE Priority (Port Priority)Syntaxspanning-tree priority priorityParametersprioritySpecifies the

Seite 1074 - Displaying Port Settings

Chapter 42: STP Commands604SPANNING-TREE STP ENABLESyntaxspanning-tree stp enableParametersNoneModeGlobal Configuration modeDescriptionUse this comman

Seite 1075

605Chapter 43Rapid Spanning Tree Protocol (RSTP) ProceduresThis chapter provides the following procedures: “Designating RSTP as the Active Spanning T

Seite 1076

Chapter 43: Rapid Spanning Tree Protocol (RSTP) Procedures606Designating RSTP as the Active Spanning Tree ProtocolThe first step to using RSTP on the

Seite 1077 - Displaying Port TLVs

AT-9000 Switch Command Line User’s Guide607Enabling the Rapid Spanning Tree ProtocolTo enable RSTP on the switch, use the SPANNING-TREE RSTP ENABLE co

Seite 1078

Chapter 43: Rapid Spanning Tree Protocol (RSTP) Procedures608Configuring the Switch ParametersThis table lists the RSTP parameters that are set in the

Seite 1079 - LLDP and LLDP-MED Commands

AT-9000 Switch Command Line User’s Guide609This example increases the forward time to 25 seconds and the hello time to 8 seconds. The forward time con

Seite 1080

Chapter 43: Rapid Spanning Tree Protocol (RSTP) Procedures610To disable the BPDU guard feature on the switch, use the NO SPANNING-TREE BPDU-GUARD comm

Seite 1081

AT-9000 Switch Command Line User’s Guide611Configuring the Port ParametersThis table lists the RSTP port parameters. These parameters are set on the i

Seite 1082 - CLEAR LLDP STATISTICS

Chapter 1: AlliedWare Plus Command Line Interface36Figure 21. Startup Messages (continued)Initializing FTAB ... done!I

Seite 1083 - CLEAR LLDP TABLE

Chapter 43: Rapid Spanning Tree Protocol (RSTP) Procedures612Configuring PortPrioritiesIf RSTP discovers a loop in the topology, but the two paths tha

Seite 1084 - LLDP HOLDTIME-MULTIPLIER

AT-9000 Switch Command Line User’s Guide613This example uses the NO SPANNING-TREE command to remove port 21 as an edge port:awplus> enableawplus# c

Seite 1085 - LLDP LOCATION

Chapter 43: Rapid Spanning Tree Protocol (RSTP) Procedures614Edge ports that are disabled by the feature remain disabled until you manually enable the

Seite 1086

AT-9000 Switch Command Line User’s Guide615Disabling the Rapid Spanning Tree ProtocolTo disable RSTP on the switch, use the NO SPANNING-TREE RSTP ENAB

Seite 1087 - LLDP MANAGEMENT-ADDRESS

Chapter 43: Rapid Spanning Tree Protocol (RSTP) Procedures616Displaying RSTP SettingsTo view the RSTP settings on the switch, use the SHOW SPANNING-TR

Seite 1088

617Chapter 44RSTP CommandsThe RSTP commands are summarized in Table 65 and described in detail within the chapter.Table 65. Rapid Spanning Tree Protoc

Seite 1089 - LLDP MED-NOTIFICATIONS

Chapter 44: RSTP Commands618“SPANNING-TREE LINK-TYPE” on page 631Port Interface Designates point-to-point ports and shared ports.“SPANNING-TREE LOOP-G

Seite 1090 - LLDP MED-TLV-SELECT

AT-9000 Switch Command Line User’s Guide619NO SPANNING-TREE PORTFASTSyntaxno spanning-tree portfastParametersNoneModePort Interface modeDescriptionUse

Seite 1091

Chapter 44: RSTP Commands620NO SPANNING-TREE ERRDISABLE-TIMEOUT ENABLESyntaxno spanning-tree errdisable-timeout enableParametersNoneModeGlobal Configu

Seite 1092

AT-9000 Switch Command Line User’s Guide621NO SPANNING-TREE LOOP-GUARDSyntaxno spanning-tree loop-guardParametersNoneModePort Interface modeDescriptio

Seite 1093 - LLDP NOTIFICATIONS

37Chapter 2Starting a Management SessionThis chapter has the following sections: “Starting a Local Management Session” on page 38 “Starting a Remote

Seite 1094 - LLDP NOTIFICATION-INTERVAL

Chapter 44: RSTP Commands622NO SPANNING-TREE PORTFAST BPDU-GUARDSyntaxno spanning-tree portfast bpdu-guardParametersNoneModePort Interface modeDescrip

Seite 1095 - LLDP REINIT

AT-9000 Switch Command Line User’s Guide623NO SPANNING-TREE RSTP ENABLESyntaxno spanning-tree rstp enableParametersNoneModeGlobal Configuration modeDe

Seite 1096 - LLDP RUN

Chapter 44: RSTP Commands624SHOW SPANNING-TREESyntaxshow spanning-treeParametersNoneModesPrivileged Exec modeDescriptionUse this command to display th

Seite 1097 - LLDP TIMER

AT-9000 Switch Command Line User’s Guide625ExampleThis example displays the RSTP settings on the switch:awplus# show spanning-tree

Seite 1098 - LLDP TLV-SELECT

Chapter 44: RSTP Commands626SPANNING-TREE ERRDISABLE-TIMEOUT ENABLESyntaxspanning-tree errdisable-timeout enableParametersNoneModeGlobal Configuration

Seite 1099

AT-9000 Switch Command Line User’s Guide627SPANNING-TREE ERRDISABLE-TIMEOUT INTERVALSyntaxspanning-tree errdisable-timeout interval intervalParameters

Seite 1100

Chapter 44: RSTP Commands628SPANNING-TREE FORWARD-TIMESyntaxspanning-tree forward-time forwardtimeParametersforwardtimeSpecifies the forward time. The

Seite 1101 - LLDP TRANSMIT RECEIVE

AT-9000 Switch Command Line User’s Guide629SPANNING-TREE GUARD ROOTSyntaxspanning-tree guard root ParametersNoneModePort Interface modeDescriptionUse

Seite 1102 - LLDP TX-DELAY

Chapter 44: RSTP Commands630SPANNING-TREE HELLO-TIMESyntaxspanning-tree hello-time hellotimeParametershellotimeSpecifies the hello time. The range is

Seite 1103 - LOCATION CIVIC-LOCATION

AT-9000 Switch Command Line User’s Guide631SPANNING-TREE LINK-TYPESyntaxspanning-tree link-type point-to-point|sharedParameterspoint-to-pointAllows fo

Seite 1104

Chapter 2: Starting a Management Session38Starting a Local Management SessionTo start a local management session on the switch, perform the following

Seite 1105

Chapter 44: RSTP Commands632SPANNING-TREE LOOP-GUARDSyntaxspanning-tree loop-guardParametersNoneModePort Interface modeDescriptionUse this command to

Seite 1106 - LOCATION COORD-LOCATION

AT-9000 Switch Command Line User’s Guide633SPANNING-TREE MAX-AGESyntaxspanning-tree max-age maxageParametersmaxageSpecifies the maximum age parameter.

Seite 1107

Chapter 44: RSTP Commands634SPANNING-TREE MODE RSTPSyntaxspanning-tree mode rstpParametersNoneModeGlobal Configuration modeDescriptionUse this command

Seite 1108

AT-9000 Switch Command Line User’s Guide635SPANNING-TREE PATH-COSTSyntaxspanning-tree path-cost path-costParameterspath-costSpecifies the cost of a po

Seite 1109 - LOCATION ELIN-LOCATION

Chapter 44: RSTP Commands636SPANNING-TREE PORTFASTSyntaxspanning-tree portfastParametersNoneModePort Interface modeDescriptionUse this command to desi

Seite 1110 - NO LLDP MED-NOTIFICATIONS

AT-9000 Switch Command Line User’s Guide637SPANNING-TREE PORTFAST BPDU-GUARDSyntaxspanning-tree portfast bpdu-guardParametersNoneModePort Interface mo

Seite 1111 - NO LLDP MED-TLV-SELECT

Chapter 44: RSTP Commands638SPANNING-TREE PRIORITY (Bridge Priority)Syntaxspanning-tree priority priorityParametersprioritySpecifies a priority number

Seite 1112

AT-9000 Switch Command Line User’s Guide639SPANNING-TREE PRIORITY (Port Priority)Syntaxspanning-tree priority priorityParametersprioritySpecifies the

Seite 1113 - NO LLDP NOTIFICATIONS

Chapter 44: RSTP Commands640SPANNING-TREE RSTP ENABLESyntaxspanning-tree rstp enableParametersNoneModeGlobal Configuration modeDescriptionUse this com

Seite 1114 - NO LLDP RUN

641Chapter 45Multiple Spanning Tree ProtocolThis chapter provides background information about the Multiple Spanning Tree Protocol (MSTP). It covers t

Seite 1115 - NO LLDP TLV-SELECT

AT-9000 Switch Command Line User’s Guide395. Enter a user name and password. If this is the initial management session of the switch, enter “manager”

Seite 1116 - NO LLDP TRANSMIT RECEIVE

Chapter 45: Multiple Spanning Tree Protocol642OverviewAs mentioned in Chapter 40, “STP, RSTP and MSTP Protocols” on page 561, STP and RSTP are referre

Seite 1117 - NO LOCATION

AT-9000 Switch Command Line User’s Guide643Multiple Spanning Tree Instance (MSTI)The individual spanning trees in MSTP are referred to as Multiple Spa

Seite 1118

Chapter 45: Multiple Spanning Tree Protocol644Figure 123. MSTP Example of Two Spanning Tree InstancesAn MSTI can contain more than one VLAN. This is i

Seite 1119 - SHOW LLDP

AT-9000 Switch Command Line User’s Guide645MSTI GuidelinesFollowing are several guidelines to keep in mind about MSTIs: The AT-9000 Switch can suppor

Seite 1120

Chapter 45: Multiple Spanning Tree Protocol646VLAN and MSTI AssociationsPart of the task to configuring MSTP involves assigning VLANs to spanning tree

Seite 1121 - SHOW LLDP INTERFACE

AT-9000 Switch Command Line User’s Guide647Ports in Multiple MSTIsA port can be a member of more than one MSTI at a time if it is a tagged member of o

Seite 1122

Chapter 45: Multiple Spanning Tree Protocol648Multiple Spanning Tree RegionsAnother important concept of MSTP is regions. An MSTP region is defined as

Seite 1123 - Description

AT-9000 Switch Command Line User’s Guide649Table 66 illustrates the concept of regions. It shows one MSTP region consisting of two AT-9000 Switches. E

Seite 1124

Chapter 45: Multiple Spanning Tree Protocol650RegionGuidelinesFollowing are several points to remember about regions. A network can contain any numbe

Seite 1125 - SHOW LLDP NEIGHBORS DETAIL

AT-9000 Switch Command Line User’s Guide651Common andInternalSpanning Tree(CIST)MSTP has a default spanning tree instance called the Common and Intern

Seite 1126

Chapter 2: Starting a Management Session40Starting a Remote Telnet or SSH Management SessionHere are the requirements for remote management of the swi

Seite 1127

Chapter 45: Multiple Spanning Tree Protocol652An MSTP region can be considered as a virtual bridge. The implication is that other MSTP regions and STP

Seite 1128 -  Voice VLAN ID

AT-9000 Switch Command Line User’s Guide653Summary of GuidelinesCareful planning is essential for the successful implementation of MSTP. This section

Seite 1129

Chapter 45: Multiple Spanning Tree Protocol654NoteThe AlliedWare Plus MSTP implementation complies fully with the new IEEE 802.1s standard. Any other

Seite 1130 - SHOW LLDP NEIGHBORS INTERFACE

AT-9000 Switch Command Line User’s Guide655Associating VLANs to MSTIsAllied Telesis recommends that you assign all VLANs on a switch to an MSTI. You s

Seite 1131

Chapter 45: Multiple Spanning Tree Protocol656Figure 126. CIST and VLAN Guideline - Example 2 When port 4 on switch B receives a BPDU, the switch note

Seite 1132 - SHOW LLDP STATISTICS

AT-9000 Switch Command Line User’s Guide657Connecting VLANs Across Different RegionsSpecial consideration needs to be taken into account when you conn

Seite 1133

Chapter 45: Multiple Spanning Tree Protocol658There are several ways to address this issue. The first is to have only one MSTP region for each subnet

Seite 1134

AT-9000 Switch Command Line User’s Guide659MSTP Root GuardThe Root Guard feature enforces the root bridge placement in a network. It ensures the port

Seite 1135

Chapter 45: Multiple Spanning Tree Protocol660

Seite 1136 - SHOW LOCATION

661Chapter 46MSTP CommandsThe MSTP commands are summarized in Table 68 and described in detail within the chapter.Table 68. Multiple Spanning Tree Pro

Seite 1137

AT-9000 Switch Command Line User’s Guide41VTY Lines The switch has ten VTY (virtual teletypewriter) lines. Each line supports one remote Telnet or SSH

Seite 1138

Chapter 46: MSTP Commands662“SPANNING-TREE MSTP ENABLE” on page 677Global ConfigurationDesignates the MSTP mode on the switch.“SPANNING-TREE MST CONFI

Seite 1139 - Chapter 69

AT-9000 Switch Command Line User’s Guide663INSTANCE MSTI-ID PRIORITYSyntaxinstance msti-id priority priorityParametersprioritySpecifies a port priorit

Seite 1140

Chapter 46: MSTP Commands664Use the no command, NO INSTANCE MSTI-ID PRIORITY, to restore the default priority value of 32768.Confirmation Command“SHOW

Seite 1141 - Adding Static ARP Entries

AT-9000 Switch Command Line User’s Guide665INSTANCE MSTI-ID VLANSyntaxinstance msti-id vlan vid|vidlistParametersvidSpecifies a VLAN ID.vidlistSpecifi

Seite 1142

Chapter 46: MSTP Commands666NO SPANNING-TREE ERRDISABLE-TIMEOUT ENABLESyntaxspanning-tree errdisable-timeout enableParametersNoneModeGlobal Configurat

Seite 1143 - Displaying the ARP Table

AT-9000 Switch Command Line User’s Guide667NO SPANNING-TREE PORTFASTSyntaxno spanning-tree portfastParametersNoneModePort Interface modeDescriptionUse

Seite 1144

Chapter 46: MSTP Commands668NO SPANNING-TREE MSTP ENABLESyntaxno spanning-tree mstp enableParametersNoneModeGlobal Configuration modeDescriptionUse th

Seite 1145

AT-9000 Switch Command Line User’s Guide669SHOW SPANNING-TREESyntaxshow spanning-treeParametersNoneModesPrivileged Exec modeDescriptionUse this comman

Seite 1146

Chapter 46: MSTP Commands670SHOW SPANNING-TREE MST CONFIGSyntaxshow spanning-tree mst configParametersNoneModePrivileged Executive ModeDescriptionUse

Seite 1147

AT-9000 Switch Command Line User’s Guide671SHOW SPANNING-TREE MST Syntaxshow spanning-tree mst ParametersNoneModePrivileged Executive ModeDescriptionU

Seite 1148 - CLEAR ARP-CACHE

AT-9000 Switch Command Line User’s Guide7CLOCK SET...

Seite 1149 - NO ARP (IP ADDRESS)

Chapter 2: Starting a Management Session42What to Configure FirstHere are a few suggestions on what to configure during your initial management sessio

Seite 1150 - SHOW ARP

Chapter 46: MSTP Commands672SHOW SPANNING-TREE MST INSTANCESyntaxshow spanning-tree mst instance <msti-id>Parametersinstance Specifies an instan

Seite 1151

AT-9000 Switch Command Line User’s Guide673SPANNING-TREE ERRDISABLE-TIMEOUT ENABLESyntaxspanning-tree errdisable-timeout enableParametersNoneModeGloba

Seite 1152

Chapter 46: MSTP Commands674SPANNING-TREE ERRDISABLE-TIMEOUT INTERVALSyntaxspanning-tree errdisable-timeout interval intervalParametersintervalSpecifi

Seite 1153 - Chapter 71

AT-9000 Switch Command Line User’s Guide675SPANNING-TREE GUARD ROOTSyntaxspanning-tree guard root ParametersNoneModePort Interface modeDescriptionUse

Seite 1154

Chapter 46: MSTP Commands676SPANNING-TREE MODE MSTPSyntaxspanning-tree mode mstpParametersNoneModeGlobal Configuration modeDescriptionUse this command

Seite 1155 - RMON Port Statistics

AT-9000 Switch Command Line User’s Guide677SPANNING-TREE MSTP ENABLESyntaxspanning-tree mstp enableParametersNoneModeGlobal Configuration modeDescript

Seite 1156 - Deleting Statistics

Chapter 46: MSTP Commands678SPANNING-TREE MST CONFIGURATIONSyntaxspanning-tree mst configurationParametersNoneModeGlobal Configuration modeDescription

Seite 1157 - RMON Histories

AT-9000 Switch Command Line User’s Guide679SPANNING-TREE MST INSTANCESyntaxspanning-tree mst instance <1-15> Parametersinstance Specifies an ins

Seite 1158 - History Groups

Chapter 46: MSTP Commands680SPANNING-TREE PATH-COSTSyntaxspanning-tree path-cost path-costParameterspath-costSpecifies the cost of a port to the root

Seite 1159 - Deleting History

AT-9000 Switch Command Line User’s Guide681SPANNING-TREE PORTFASTSyntaxspanning-tree portfastParametersNoneModePort Interface modeDescriptionUse this

Seite 1160 - RMON Alarms

AT-9000 Switch Command Line User’s Guide43Figure 24. SHOW BOOT CommandThe name of your new active boot configuration file is displayed in the “Current

Seite 1161 - Statistics Groups

Chapter 46: MSTP Commands682SPANNING-TREE PORTFAST BPDU-GUARDSyntaxspanning-tree portfast bpdu-guardParametersNoneModeGlobal Configuration modeDescrip

Seite 1162

AT-9000 Switch Command Line User’s Guide683REGIONSyntaxregion <region-name>Parametersregion-nameSpecifies the name of an MST region. Up to 32 ch

Seite 1163 - Alarm - Example

Chapter 46: MSTP Commands684REVISIONSyntaxrevision <revision-number>Parametersrevision-numberSpecifies the revision number. The range is 0 to 25

Seite 1164 - Enter_log_message

685Section VIIVirtual LANsThis section contains the following chapters: Chapter 47, “Port-based and Tagged VLANs” on page 687 Chapter 48, “Port-base

Seite 1166 - Chapter 71: RMON

687Chapter 47Port-based and Tagged VLANsThis chapter covers the following topics: “Overview” on page 688 “Port-based VLAN Overview” on page 690 “Ta

Seite 1167 - Phase 4: Creating the Alarm

Chapter 47: Port-based and Tagged VLANs688OverviewA VLAN is a group of ports that form a logical Ethernet segment on an Ethernet switch. The ports of

Seite 1168 - Use the SHOW RMON ALARM

AT-9000 Switch Command Line User’s Guide689Virtual LANs can also span more than one switch. This makes it possible to create VLANs of end nodes that a

Seite 1169 - RMON Commands

Chapter 47: Port-based and Tagged VLANs690Port-based VLAN OverviewAs the “Overview” on page 688 explains, a VLAN consists of a group of ports that for

Seite 1170 - Chapter 72: RMON Commands

AT-9000 Switch Command Line User’s Guide691For example, if you had a port-based VLAN named Marketing that spanned three switches, assign the Marketing

Seite 1171 - NO RMON ALARM

Chapter 2: Starting a Management Session44This example assigns the name “Engineering_sw2” to the switch:awplus> enableawplus# configure terminalawp

Seite 1172 - NO RMON COLLECTION HISTORY

Chapter 47: Port-based and Tagged VLANs692Guidelines toCreating a Port-based VLANBelow are the guidelines to creating a port-based VLAN. Each port-ba

Seite 1173 - NO RMON COLLECTION STATS

AT-9000 Switch Command Line User’s Guide693Port-basedExample 1Figure 132 illustrates an example of one AT-9000 switch with three port-based VLANs. (Th

Seite 1174 - NO RMON EVENT

Chapter 47: Port-based and Tagged VLANs694Port-basedExample 2Figure 133 illustrates more port-based VLANs. In this example, two VLANs, Sales and Engin

Seite 1175 - RMON ALARM

AT-9000 Switch Command Line User’s Guide695The table below lists the port assignments for the Sales, Engineering, and Production VLANs on the switches

Seite 1176

Chapter 47: Port-based and Tagged VLANs696Tagged VLAN OverviewThe second type of VLAN is the tagged VLAN. VLAN membership in a tagged VLAN is determin

Seite 1177

AT-9000 Switch Command Line User’s Guide697NoteFor explanations of VLAN name and VLAN identifier, refer back to “VLAN Name” on page 690 and “VLAN Iden

Seite 1178 - RMON COLLECTION HISTORY

Chapter 47: Port-based and Tagged VLANs698Tagged VLANExampleFigure 134 illustrates how tagged ports can be used to interconnect IEEE 802.1q based prod

Seite 1179

AT-9000 Switch Command Line User’s Guide699The port assignments for the VLANs are described in Table 70.Table 70. VLAN Port AssignmentsSwitchSales VLA

Seite 1180 - RMON COLLECTION STATS

Chapter 47: Port-based and Tagged VLANs700This example is nearly identical to the “Port-based Example 2” on page 694. Tagged ports have been added to

Seite 1181 - RMON EVENT LOG

AT-9000 Switch Command Line User’s Guide701Creating VLANsTo create VLANs, use the VLAN command in the VLAN Configuration mode. You must specify a name

Seite 1182 - RMON EVENT LOG TRAP

AT-9000 Switch Command Line User’s Guide45This example assigns the management IPv4 address to a new VLAN called Tech_Support, with the VID 5. The VLAN

Seite 1183

Chapter 47: Port-based and Tagged VLANs702Adding Untagged Ports to VLANsTo add a port to a VLAN as an untagged port, it may be necessary to first set

Seite 1184 - RMON EVENT TRAP

AT-9000 Switch Command Line User’s Guide703This example designates ports 11 to 18 as untagged ports of a VLAN with the VID 4. The SWITCHPORT MODE ACCE

Seite 1185

Chapter 47: Port-based and Tagged VLANs704Adding Tagged Ports to VLANsThere are three steps to adding ports as tagged ports to VLANs:1. Set the mode o

Seite 1186 - SHOW RMON ALARM

AT-9000 Switch Command Line User’s Guide705This example adds ports 18 to 21 as tagged members to VLANs with the VIDs 7 and 13:awplus> enableawplus#

Seite 1187

Chapter 47: Port-based and Tagged VLANs706Removing Untagged Ports from VLANsTo remove untagged ports from their current VLAN assignments and return th

Seite 1188 - SHOW RMON EVENT

AT-9000 Switch Command Line User’s Guide707Removing Tagged Ports from VLANsUse the SWITCHPORT TRUNK ALLOWED VLAN command to remove ports as tagged mem

Seite 1189

Chapter 47: Port-based and Tagged VLANs708Deleting VLANsTo delete VLANs from the switch, use the NO VLAN command in the VLAN Configuration mode. You c

Seite 1190 - SHOW RMON HISTORY

AT-9000 Switch Command Line User’s Guide709Displaying the VLANsTo display the VLANs on the switch, use the SHOW VLAN ALL command in the User Exec mode

Seite 1191

Chapter 47: Port-based and Tagged VLANs710

Seite 1192 - SHOW RMON STATISTICS

711Chapter 48Port-based and Tagged VLAN CommandsThe VLAN commands are summarized in Table 71 and described in detail within the chapter.Table 71. Port

Seite 1193 - Chapter 73

Chapter 2: Starting a Management Session46Saving YourChangesTo permanently save your changes in the active boot configuration file, use the WRITE comm

Seite 1194

Chapter 48: Port-based and Tagged VLAN Commands712NO SWITCHPORT ACCESS VLANSyntaxno switchport access vlanParametersNoneModePort Interface modeDescrip

Seite 1195

AT-9000 Switch Command Line User’s Guide713NO SWITCHPORT TRUNKSyntaxno switchport trunkParametersNoneModePort Interface modeDescriptionUse this comman

Seite 1196

Chapter 48: Port-based and Tagged VLAN Commands714NO SWITCHPORT TRUNK NATIVE VLANSyntaxno switchport trunk native vlanParametersNoneModePort Interface

Seite 1197 - Creating ACLs

AT-9000 Switch Command Line User’s Guide715NO VLANSyntaxno vlan vidParametersvidSpecifies the VID of the VLAN you want to delete.ModeVLAN Configuratio

Seite 1198

Chapter 48: Port-based and Tagged VLAN Commands716SHOW VLANSyntaxshow vlan vid |allParametersvidSpecifies the VID of the VLAN you want to display.allS

Seite 1199

AT-9000 Switch Command Line User’s Guide717ExampleThe following example displays the tagged and untagged VLANs on the switch:awplus# show vlanState Th

Seite 1200

Chapter 48: Port-based and Tagged VLAN Commands718SWITCHPORT ACCESS VLANSyntaxswitchport access vlan vidParametersvidSpecifies the ID number of the VL

Seite 1201

AT-9000 Switch Command Line User’s Guide719ExamplesThis example adds ports 5 and 7 as untagged ports to a VLAN with the VID 12:awplus> enableawplus

Seite 1202

Chapter 48: Port-based and Tagged VLAN Commands720SWITCHPORT MODE ACCESSSyntaxswitchport mode access [ingress-filter enable|disable]ParametersenableAc

Seite 1203

AT-9000 Switch Command Line User’s Guide721SWITCHPORT MODE TRUNKSyntaxswitchport mode trunk [ingress-filter enable|disable]ParametersenableActivates i

Seite 1204

AT-9000 Switch Command Line User’s Guide47Ending a Management SessionTo end a management session, go to either the Privileged Exec mode or the User Ex

Seite 1205

Chapter 48: Port-based and Tagged VLAN Commands722This example designates port 18 as a tagged port and disables ingress filtering so that it accepts a

Seite 1206

AT-9000 Switch Command Line User’s Guide723SWITCHPORT TRUNK ALLOWED VLANSyntaxes for Adding Tagged Ports to VLANsswitchport trunk allowed vlan allswit

Seite 1207

Chapter 48: Port-based and Tagged VLAN Commands724 Ports can be tagged members of more than one VLAN at a time. The specified VLANs must already exi

Seite 1208

AT-9000 Switch Command Line User’s Guide725This example adds ports 22 to 24 as tagged ports to all the VLANs, except for the VLAN with a VID of 11. Th

Seite 1209 - Numbered MAC

Chapter 48: Port-based and Tagged VLAN Commands726SWITCHPORT TRUNK NATIVE VLANSyntaxswitchport trunk native vlan vid|noneParametersvidSpecifies the VI

Seite 1210

AT-9000 Switch Command Line User’s Guide727This example reestablishes the Default_VLAN as the native VLAN for tagged ports 18 and 20:awplus> enable

Seite 1211

Chapter 48: Port-based and Tagged VLAN Commands728VLANSyntaxvlan vid [name name]ParametersvidSpecifies a VLAN identifier. The range is 2 to 4094. The

Seite 1212 - Assigning ACLs to Ports

AT-9000 Switch Command Line User’s Guide729DescriptionUse this command to create port-based and tagged VLANs. You can create just one VLAN at a time.C

Seite 1213 - Address ACLs to

Chapter 48: Port-based and Tagged VLAN Commands730

Seite 1214

731Chapter 49GARP VLAN Registration ProtocolThis chapter covers the following topics: “Overview” on page 732 “Guidelines” on page 735 “GVRP and Net

Seite 1215 - Removing ACLs from Ports

Chapter 2: Starting a Management Session48

Seite 1216

Chapter 49: GARP VLAN Registration Protocol732OverviewThe GARP VLAN Registration Protocol (GVRP) allows network devices to share VLAN information and

Seite 1217 - Restricting Remote Access

AT-9000 Switch Command Line User’s Guide733Figure 137 provides an example of how GVRP works.Figure 137. GVRP ExampleThe example consists of three swit

Seite 1218 - ACLs to VTY

Chapter 49: GARP VLAN Registration Protocol734Without GVRP, you would have to manually add the Sales VLAN to switch #2. But with GVRP, the VLAN is add

Seite 1219 - IPv4 and IPv6

AT-9000 Switch Command Line User’s Guide735GuidelinesHere are the guidelines to GVRP: GVRP is supported with STP, RSTP, MSTP or without spanning tree

Seite 1220

Chapter 49: GARP VLAN Registration Protocol736GVRP and Network SecurityGVRP should be used with caution because it can expose your network to unauthor

Seite 1221

AT-9000 Switch Command Line User’s Guide737GVRP-inactive Intermediate SwitchesIf two GVRP-active devices are separated by a GVRP-inactive switch, the

Seite 1222 - Unrestricting Remote Access

Chapter 49: GARP VLAN Registration Protocol738Enabling GVRP on the SwitchThe command for enabling GVRP on the switch is found in the Global Configurat

Seite 1223

AT-9000 Switch Command Line User’s Guide739Enabling GIP on the SwitchThe GARP Information Propagation (GIP) component can be enabled separately from G

Seite 1224 - Displaying the ACLs

Chapter 49: GARP VLAN Registration Protocol740Enabling GVRP on the PortsTo activate GVRP on the ports so that they transmit GVRP PDUs, use the GVRP RE

Seite 1225 - Assigned to VTY

AT-9000 Switch Command Line User’s Guide741Setting the GVRP TimersThe switch has a Join Timer, a Leave Timer, and a Leave All Timer. You should not ch

Seite 1226

49Chapter 3Basic Command Line ManagementThis chapter contains the following sections: “Clearing the Screen” on page 50 “Displaying the On-line Help”

Seite 1227 - ACL Commands

Chapter 49: GARP VLAN Registration Protocol742Disabling GVRP Timers on the SwitchTo disable GVRP timer configurations, use the NO GVRP TIMER commands

Seite 1228 - Chapter 74: ACL Commands

AT-9000 Switch Command Line User’s Guide743Disabling GVRP on the PortsTo disable GVRP on the ports, use the GVRP REGISTRATION NONE command in the Port

Seite 1229 - ACCESS-CLASS

Chapter 49: GARP VLAN Registration Protocol744Disabling GIP on the SwitchYou can disable the GARP Information Propagation (GIP) component separately f

Seite 1230

AT-9000 Switch Command Line User’s Guide745Disabling GVRP on the SwitchTo disable GVRP to stop the switch from learning any further dynamic VLANs or G

Seite 1231 - ACCESS-GROUP

Chapter 49: GARP VLAN Registration Protocol746Restoring the GVRP Default SettingsTo disable GVRP and to return the timers to their default settings, u

Seite 1232

AT-9000 Switch Command Line User’s Guide747Displaying GVRPAlthough there are five commands that display GVRP information, you will probably only need

Seite 1233 - ACCESS-LIST (MAC Address)

Chapter 49: GARP VLAN Registration Protocol748

Seite 1234 - Confirmation Commands

749Chapter 50GARP VLAN Registration Protocol CommandsThe GARP VLAN registration protocol commands are summarized in Table 73 and described in detail w

Seite 1235

Chapter 50: GARP VLAN Registration Protocol Commands750“SHOW GVRP APPLICANT” on page 764User Exec and Privileged ExecDisplays parameters for the GIP-c

Seite 1236 - ACCESS-LIST ICMP

AT-9000 Switch Command Line User’s Guide751CONVERT DYNAMIC VLANSyntaxconvert dynamic vlanParametersNoneModeVLAN Configuration modeDescriptionUse this

Seite 1237

Chapter 3: Basic Command Line Management50Clearing the ScreenIf your screen becomes cluttered with commands, you can start fresh by entering the CLEAR

Seite 1238

Chapter 50: GARP VLAN Registration Protocol Commands752GVRP APPLICANT STATE ACTIVESyntaxgvrp applicant state activeParametersNoneModeGlobal Configurat

Seite 1239 - ACCESS-LIST IP

AT-9000 Switch Command Line User’s Guide753GVRP APPLICANT STATE NORMALSyntaxgvrp applicant state normalParametersNoneModeGlobal Configuration modeDesc

Seite 1240

Chapter 50: GARP VLAN Registration Protocol Commands754GVRP ENABLESyntaxgvrp enableParametersNoneModeGlobal Configuration modeDescriptionUse this comm

Seite 1241

AT-9000 Switch Command Line User’s Guide755GVRP REGISTRATIONSyntaxgvrp registration normal|noneParametersnormalEnables GVRP on a port. This is the def

Seite 1242

Chapter 50: GARP VLAN Registration Protocol Commands756GVRP TIMER JOINSyntaxgvrp timer join valueParametersvalueSpecifies the Join Timer in centisecon

Seite 1243 - ACCESS-LIST PROTO

AT-9000 Switch Command Line User’s Guide757GVRP TIMER LEAVESyntaxgvrp timer leave valueParametersvalueSpecifies the Leave Timer in centiseconds, which

Seite 1244

Chapter 50: GARP VLAN Registration Protocol Commands758GVRP TIMER LEAVEALLSyntaxgvrp timer leaveall valueParametersvalueSpecifies the Leave All Timer

Seite 1245

AT-9000 Switch Command Line User’s Guide759NO GVRP ENABLESyntaxno gvrp enableParametersNoneModeGlobal Configuration modeDescriptionUse this command to

Seite 1246

Chapter 50: GARP VLAN Registration Protocol Commands760NO GVRP TIMER JOIN Syntaxno gvrp timer joinParametersNoneModeGlobal Configuration modeDescripti

Seite 1247

AT-9000 Switch Command Line User’s Guide761NO GVRP TIMER LEAVESyntaxno gvrp timer leave valueParametersNoneModeGlobal Configuration modeDescriptionUse

Seite 1248 - ACCESS-LIST TCP

AT-9000 Switch Command Line User’s Guide51Displaying the On-line HelpThe command line interface has an on-line help system to assist you with the comm

Seite 1249

Chapter 50: GARP VLAN Registration Protocol Commands762NO GVRP TIMER LEAVEALLSyntaxno gvrp timer leaveallParametersNoneModeGlobal Configuration modeDe

Seite 1250

AT-9000 Switch Command Line User’s Guide763PURGE GVRPSyntaxpurge gvrpParametersNoneModeGlobal Configuration modeDescriptionUse this command to disable

Seite 1251

Chapter 50: GARP VLAN Registration Protocol Commands764SHOW GVRP APPLICANTSyntaxshow gvrp applicantParameterNoneModePrivileged Exec modeDescriptionUse

Seite 1252 - ACCESS-LIST UDP

AT-9000 Switch Command Line User’s Guide765SHOW GVRP CONFIGURATIONSyntaxshow gvrp configurationParametersNoneModePrivileged Exec modeDescriptionUse th

Seite 1253

Chapter 50: GARP VLAN Registration Protocol Commands766SHOW GVRP MACHINESyntaxshow gvrp machineParameterNoneModePrivileged Exec modeDescriptionUse thi

Seite 1254

AT-9000 Switch Command Line User’s Guide767SHOW GVRP STATISTICSSyntaxshow gvrp statisticsParameterNoneModePrivileged Exec modeDescriptionUse this comm

Seite 1255

Chapter 50: GARP VLAN Registration Protocol Commands768 Receive GARP Messages: Empty Transmit GARP Messages: Empty Receive GARP Messages: Bad Messa

Seite 1256 - MAC ACCESS-GROUP

AT-9000 Switch Command Line User’s Guide769SHOW GVRP TIMERSyntaxshow gvrp timerParameterNoneModePrivileged Exec modeDescriptionUse this command to dis

Seite 1257 - NO ACCESS-LIST

Chapter 50: GARP VLAN Registration Protocol Commands770

Seite 1258 - NO ACCESS-GROUP

771Chapter 51MAC Address-based VLANsThis chapter contains the following topics: “Overview” on page 772 “Guidelines” on page 777 “General Steps” on

Seite 1259 - NO MAC ACCESS-GROUP

Contents8NO FLOWCONTROL ...

Seite 1260 - SHOW ACCESS-LIST

Chapter 3: Basic Command Line Management52Figure 27. Displaying the Class of a Parameterawplus> enableawplus# configure terminalawplus(config)# hos

Seite 1261

Chapter 51: MAC Address-based VLANs772OverviewAs explained in Chapter 47, “Port-based and Tagged VLANs” on page 687, VLANs are used to create independ

Seite 1262 - SHOW INTERFACE ACCESS-GROUP

AT-9000 Switch Command Line User’s Guide773Obviously, mapping source MAC addresses to egress ports can become cumbersome if you are dealing with a MAC

Seite 1263 - Chapter 75

Chapter 51: MAC Address-based VLANs774The switch can support more than one MAC-address VLAN at a time, and ports can be egress members of more than on

Seite 1264

AT-9000 Switch Command Line User’s Guide775 If the packet’s destination MAC address is in the MAC address table, but the port where the address was l

Seite 1265 - MLS QOS ENABLE

Chapter 51: MAC Address-based VLANs776VLAN Hierarchy The switch employs a VLAN hierarchy when handling untagged packets that arrive on a port that is

Seite 1266 - MLS QOS MAP COS-QUEUE

AT-9000 Switch Command Line User’s Guide777GuidelinesHere are the guidelines to MAC address-based VLANs: The switch can support up to a total of 4094

Seite 1267

Chapter 51: MAC Address-based VLANs778General StepsThere are three main steps to creating a MAC address-based VLAN:1. Use the VLAN MACADDRESS command

Seite 1268 - MLS QOS MAP DSCP-QUEUE

AT-9000 Switch Command Line User’s Guide779Creating MAC Address-based VLANsThe VLAN MACADDRESS command in the VLAN Configuration mode is the first com

Seite 1269

Chapter 51: MAC Address-based VLANs780Adding MAC Addresses to VLANs and Designating Egress PortsThe MAC addresses and egress ports are specified with

Seite 1270 - MLS QOS QUEUE

AT-9000 Switch Command Line User’s Guide781Removing MAC AddressesTo remove MAC addresses from egress ports in a MAC address-based VLAN, use the NO VLA

Seite 1271 - MLS QOS SET COS

AT-9000 Switch Command Line User’s Guide53Saving Your Configuration ChangesTo permanently save your changes to the parameter settings on the switch, y

Seite 1272 - MLS QOS SET DSCP

Chapter 51: MAC Address-based VLANs782Deleting VLANsTo delete MAC address-based VLANs from the switch, use the NO VLAN command in the VLAN Configurati

Seite 1273 - MLS QOS TRUST COS

AT-9000 Switch Command Line User’s Guide783Displaying VLANsTo display the MAC address-based VLANS on the switch, use the SHOW VLAN MACADDRESS command

Seite 1274 - MLS QOS TRUST DSCP

Chapter 51: MAC Address-based VLANs784Example of Creating a MAC Address-based VLANHere is an example of how to create this type of VLAN. This example

Seite 1275 - NO MLS QOS ENABLE

AT-9000 Switch Command Line User’s Guide785Use the VLAN SET MACADDRESS command in the Port Interface mode to designate port 1 as an egress port of all

Seite 1276 - NO WRR-QUEUE WEIGHT

Chapter 51: MAC Address-based VLANs786

Seite 1277 - SHOW MLS QOS INTERFACE

787Chapter 52MAC Address-based VLAN CommandsThe MAC address-based VLAN commands are summarized in Table 77 and described in detail within the chapter.

Seite 1278 - (continued)

Chapter 52: MAC Address-based VLAN Commands788NO VLANSyntaxno vlan vidParametersvidSpecifies the VID of the VLAN you want to delete. You can specify j

Seite 1279

AT-9000 Switch Command Line User’s Guide789NO VLAN MACADDRESS (Global Configuration Mode)Syntaxno vlan vid macaddress|destaddress mac-addressParameter

Seite 1280 - SHOW MLS QOS MAPS COS-QUEUE

Chapter 52: MAC Address-based VLAN Commands790NO VLAN MACADDRESS (Port Interface Mode)Syntaxno vlan vid macaddress|destaddress mac-addressParametersvi

Seite 1281 - SHOW MLS QOS MAPS DSCP-QUEUE

AT-9000 Switch Command Line User’s Guide791This example removes the MAC address 00:30:84:75:11:B2 from the egress port 11 to 14 in a VLAN with the VID

Seite 1282

Chapter 3: Basic Command Line Management54Ending a Management SessionTo end a management session, go to either the Privileged Exec mode or the User Ex

Seite 1283 - WRR-QUEUE WEIGHT

Chapter 52: MAC Address-based VLAN Commands792SHOW VLAN MACADDRESSSyntaxshow vlan macaddressParametersNoneModePrivileged Exec modeDescriptionUse this

Seite 1284

AT-9000 Switch Command Line User’s Guide793The information is described here.ExampleThe following example displays the MAC addresses and egress ports

Seite 1285 - Management Security

Chapter 52: MAC Address-based VLAN Commands794VLAN MACADDRESSSyntaxvlan vid name name type macaddressParametersvidSpecifies a VLAN identifier in the r

Seite 1286

AT-9000 Switch Command Line User’s Guide795ExampleThis example creates a MAC address-based VLAN that has the name Sales and the VID 3:awplus> enabl

Seite 1287 - Local Manager Accounts

Chapter 52: MAC Address-based VLAN Commands796VLAN SET MACADDRESS (Global Configuration Mode)Syntaxvlan set vid macaddress|destaddress mac-addressPara

Seite 1288

AT-9000 Switch Command Line User’s Guide797This example adds the MAC address 00:30:84:32:76:1A to a MAC address-based VLAN with the VID 12:awplus>

Seite 1289 - Encryption

Chapter 52: MAC Address-based VLAN Commands798VLAN SET MACADDRESS (Port Interface Mode)Syntaxvlan set vid macaddress|destaddress mac-addressParameters

Seite 1290

AT-9000 Switch Command Line User’s Guide799This example assigns the MAC address 00:30:84:75:11:B2 to ports 11 to 14 in a VLAN that has the VID 24:awpl

Seite 1291

Chapter 52: MAC Address-based VLAN Commands800

Seite 1292

801Chapter 53 Private Port VLANsThis chapter provides the following topics: “Overview” on page 802 “Guidelines” on page 804 “Creating Private VLANs

Seite 1293

55Chapter 4Basic Command Line Management CommandsThe basic command line commands are summarized in Table 5.Table 5. Basic Command Line CommandsCommand

Seite 1294

Chapter 53: Private Port VLANs802OverviewPrivate VLANs (also called private port VLANs) create special broadcast domains in which the traffic of the m

Seite 1295

AT-9000 Switch Command Line User’s Guide803Private VLANFunctionalityThe following describes host and uplink port functionality in a private VLAN, and

Seite 1296

Chapter 53: Private Port VLANs804GuidelinesHere are the guidelines to private VLANs: A private VLAN can have any number of host ports, up to all the

Seite 1297 - Configuration

AT-9000 Switch Command Line User’s Guide805Creating Private VLANsThe command to initially create private VLANs is the PRIVATE-VLAN command in the VLAN

Seite 1298

Chapter 53: Private Port VLANs806Adding Host and Uplink PortsPrivate VLANs have host ports and uplink ports. A private VLAN can have more than one upl

Seite 1299 - Chapter 77

AT-9000 Switch Command Line User’s Guide807Deleting VLANsTo delete private VLANs from the switch, use the NO VLAN command in the VLAN Configuration mo

Seite 1300 - ENABLE PASSWORD

Chapter 53: Private Port VLANs808Displaying Private VLANsThe SHOW VLAN PRIVATE-VLAN command in the Privileged Exec mode displays the private VLANs cur

Seite 1301

809Chapter 54Private Port VLAN CommandsThe private port VLAN commands are summarized in Table 79 and described in detail within the chapter.Table 79.

Seite 1302 - NO ENABLE PASSWORD

Chapter 54: Private Port VLAN Commands810NO VLANSyntaxno vlan vidParametersvidSpecifies the VID of the VLAN you want to delete. You can specify just o

Seite 1303

AT-9000 Switch Command Line User’s Guide811PRIVATE-VLANSyntaxprivate-vlan vidParametersvidSpecifies a VLAN identifier. The range is 2 to 4094. The VID

Seite 1304 - NO USERNAME

Chapter 4: Basic Command Line Management Commands56“QUIT” on page 70 All modes except the User Exec and Privileged ExecMoves you up one mode.“WRITE” o

Seite 1305 - SERVICE PASSWORD-ENCRYPTION

Chapter 54: Private Port VLAN Commands812SHOW VLAN PRIVATE-VLANSyntaxshow vlan private-vlanParametersNoneModePrivileged Exec modeDescriptionUse this c

Seite 1306 - USERNAME

AT-9000 Switch Command Line User’s Guide813SWITCHPORT MODE PRIVATE-VLAN HOSTSyntaxswitchport mode private-vlan host vidParametersvidSpecifies the VID

Seite 1307

Chapter 54: Private Port VLAN Commands814SWITCHPORT MODE PRIVATE-VLAN PROMISCUOUSSyntaxswitchport mode private-vlan promiscuous vidParametersvidSpecif

Seite 1308

815Chapter 55Voice VLAN CommandsThe voice VLAN commands are summarized in Table 80 and described in detail within the chapter.Table 80. Voice VLAN Com

Seite 1309 - Telnet Server

Chapter 55: Voice VLAN Commands816NO SWITCHPORT VOICE VLANSyntaxno switchport voice vlanParametersNoneModePort Interface modeDescriptionUse this comma

Seite 1310

AT-9000 Switch Command Line User’s Guide817SWITCHPORT VOICE DSCPSyntaxswitchport voice dscp valueParametersvalueSpecifies a DSCP value of 0 to 63. You

Seite 1311 - Enabling the Telnet Server

Chapter 55: Voice VLAN Commands818SWITCHPORT VOICE VLANSyntaxswitchport voice vlan vidParametersvidSpecifies the ID number (VID) of the VLAN that func

Seite 1312 - Disabling the Telnet Server

AT-9000 Switch Command Line User’s Guide819ExampleThis example adds ports 5 through 16 to a voice VLAN that has a VID of 12:awplus> enableawplus# c

Seite 1313 - Displaying the Telnet Server

Chapter 55: Voice VLAN Commands820SWITCHPORT VOICE VLAN PRIORITYSyntaxswitchport voice vlan priority valueParametersvalueSpecifies a Class of Service

Seite 1314 - Chapter 78: Telnet Server

821Chapter 56VLAN StackingThis chapter provides the following topics: “Overview” on page 822 “Components” on page 824 “VLAN Stacking Process” on pa

Seite 1315 - Telnet Server Commands

AT-9000 Switch Command Line User’s Guide57? (Question Mark Key)Syntax?ParametersNoneModesAll modesDescriptionUse the question mark key to display on-l

Seite 1316 - NO SERVICE TELNET

Chapter 56: VLAN Stacking822 Section III: File SystemOverviewVLAN stacking is a way to label tagged and untagged packets with new 802.1Q headers. In t

Seite 1317 - SERVICE TELNET

AT-9000 Switch Command Line User’s GuideSection III: File System 823when they exit the network. The inner VID is native to the packets, but is ignored

Seite 1318 - SHOW TELNET

Chapter 56: VLAN Stacking824 Section III: File SystemComponentsThere are four components to VLAN stacking: VLAN Customer ports Provider port Ether

Seite 1319 - Telnet Client

AT-9000 Switch Command Line User’s GuideSection III: File System 825VLAN Stacking ProcessFigure 146 illustrates the VLAN stacking process.Figure 146.

Seite 1320

Chapter 56: VLAN Stacking826 Section III: File SystemExample of VLAN StackingHere is an example of how to configure VLAN stacking. In the example, the

Seite 1321

AT-9000 Switch Command Line User’s GuideSection III: File System 827The next steps add the customer ports to the VLAN.This series of steps adds the pr

Seite 1322 - Chapter 80: Telnet Client

Chapter 56: VLAN Stacking828 Section III: File SystemThe final series of steps changes the EtherType/Length value to 0x8100.awplus(config-if)# switchp

Seite 1323 - Telnet Client Commands

AT-9000 Switch Command Line User’s GuideSection III: File System 829awplus(config)# platform vlan-stacking-tpid 8100Change the EtherType/Length value

Seite 1324

Chapter 56: VLAN Stacking830 Section III: File System

Seite 1325 - TELNET IPV6

831Chapter 57VLAN Stacking CommandsThe VLAN stacking commands are summarized in Table 82.Table 82. VLAN Stacking CommandsCommand Mode Description“NO

Seite 1326

Chapter 4: Basic Command Line Management Commands58This example displays the class of the value for the SPANNING-TREE HELLO-TIME command in the Global

Seite 1327 - Secure Shell (SSH) Server

Chapter 57: VLAN Stacking Commands832 Section III: File SystemNO SWITCHPORT VLAN-STACKINGSyntaxno switchport vlan-stackingParametersNone.ModePort Inte

Seite 1328

AT-9000 Switch Command Line User’s GuideSection III: File System 833PLATFORM VLAN-STACKING-TPIDSyntaxplatform vlan-stacking-tpid tpidParameterstpid Sp

Seite 1329 - Support for SSH

Chapter 57: VLAN Stacking Commands834 Section III: File SystemSHOW VLAN VLAN-STACKINGSyntaxshow vlan vlan-stackingParametersNone.ModePort Interface mo

Seite 1330

AT-9000 Switch Command Line User’s GuideSection III: File System 835SWITCHPORT VLAN-STACKINGSyntaxswitchport vlan-stacking customer-edge-port|provider

Seite 1331 - SSH and Enhanced Stacking

Chapter 57: VLAN Stacking Commands836 Section III: File System

Seite 1332

837Section VIIIPort SecurityThis section contains the following chapters: Chapter 58, “MAC Address-based Port Security” on page 839 Chapter 59, “MAC

Seite 1334 - Enabling the SSH Server

839Chapter 58MAC Address-based Port SecurityThis chapter contains the following topics: “Overview” on page 840 “Configuring Ports” on page 842 “Ena

Seite 1335 - Disabling the SSH Server

Chapter 58: MAC Address-based Port Security840OverviewThis feature lets you control access to the ports on the switch based on the source MAC addresse

Seite 1336 - Deleting Encryption Keys

AT-9000 Switch Command Line User’s Guide841after learning three addresses. The switch also sends an SNMP trap.Guidelines Here are the guidelines to MA

Seite 1337 - Displaying the SSH Server

AT-9000 Switch Command Line User’s Guide59CLEAR SCREENSyntaxclear screenParametersNoneModesUser Exec and Privileged Exec modesDescriptionUse this comm

Seite 1338

Chapter 58: MAC Address-based Port Security842Configuring PortsThere are three things you need to decide before you configure MAC address-based port s

Seite 1339 - SSH Server Commands

AT-9000 Switch Command Line User’s Guide843awplus> enableawplus# configure terminalawplus(config)# interface port1.0.4,port1.0.5awplus(config-if)#

Seite 1340 - CRYPTO KEY DESTROY HOSTKEY

Chapter 58: MAC Address-based Port Security844Enabling MAC Address-based Security on PortsAfter you have configured a port for MAC address-based secur

Seite 1341

AT-9000 Switch Command Line User’s Guide845Disabling MAC Address-based Security on PortsTo remove MAC address-based security from ports, use the NO SW

Seite 1342 - CRYPTO KEY GENERATE HOSTKEY

Chapter 58: MAC Address-based Port Security846Displaying Port SettingsThere are two commands that display information about the MAC address-based port

Seite 1343

AT-9000 Switch Command Line User’s Guide847Figure 149 on page 847 is an example of the information.Figure 149. Example of SHOW PORT-SECURITY INTRUSION

Seite 1344 - NO SERVICE SSH

Chapter 58: MAC Address-based Port Security848

Seite 1345 - SERVICE SSH

849Chapter 59MAC Address-based Port Security CommandsThe MAC address-based port security commands are summarized in Table 84 and described in detail w

Seite 1346 - SHOW CRYPTO KEY HOSTKEY

Chapter 59: MAC Address-based Port Security Commands850NO SWITCHPORT PORT-SECURITYSyntaxno switchport port-securityParametersNoneModePort Interface mo

Seite 1347 - SHOW SSH SERVER

AT-9000 Switch Command Line User’s Guide851NO SWITCHPORT PORT-SECURITY AGINGSyntaxno switchport port-security agingParametersNoneModePort Interface mo

Seite 1348

Chapter 4: Basic Command Line Management Commands60CONFIGURE TERMINALSyntaxconfigure terminalParametersNoneModePrivileged Exec modeDescriptionUse this

Seite 1349 - Chapter 84

Chapter 59: MAC Address-based Port Security Commands852SHOW PORT-SECURITY INTERFACESyntaxshow port-security interface portParametersportSpecifies the

Seite 1350

AT-9000 Switch Command Line User’s Guide853Port Status The status of the port. The status can be Enabled or Disabled. A port that has a status of Enab

Seite 1351

Chapter 59: MAC Address-based Port Security Commands854ExampleThis example displays the port security settings for ports 5 to 8:awplus# show port-secu

Seite 1352

AT-9000 Switch Command Line User’s Guide855SHOW PORT-SECURITY INTRUSION INTERFACESyntaxshow port-security intrusion interface portParameterportSpecifi

Seite 1353

Chapter 59: MAC Address-based Port Security Commands856Figure 152. Example of SHOW PORT-SECURITY INTRUSION INTERFACE CommandPort Security Intrusion Li

Seite 1354 - HTTP server enabled. Port 80

AT-9000 Switch Command Line User’s Guide857SWITCHPORT PORT-SECURITYSyntaxswitchport port-securityParametersNoneModePort Interface modeDescriptionUse t

Seite 1355

Chapter 59: MAC Address-based Port Security Commands858SWITCHPORT PORT-SECURITY AGINGSyntaxswitchport port-security agingParametersNoneModePort Interf

Seite 1356 - SERVICE HTTP

AT-9000 Switch Command Line User’s Guide859SWITCHPORT PORT-SECURITY MAXIMUMSyntaxswitchport port-security maximum valueParametersvalueSpecifies the ma

Seite 1357 - IP HTTP PORT

Chapter 59: MAC Address-based Port Security Commands860SWITCHPORT PORT-SECURITY VIOLATIONSyntaxswitchport port-security violation protect|restrict|shu

Seite 1358 - NO SERVICE HTTP

AT-9000 Switch Command Line User’s Guide861This example sets the intrusion action for ports 22 to 24 to restrict. After learning their maximum numbers

Seite 1359 - SHOW IP HTTP

AT-9000 Switch Command Line User’s Guide61COPY RUNNING-CONFIG STARTUP-CONFIGSyntaxcopy running-config startup-configParametersNoneModePrivileged Exec

Seite 1360

Chapter 59: MAC Address-based Port Security Commands862

Seite 1361 - Chapter 86

863Chapter 60802.1x Port-based Network Access ControlThis chapter contains the following topics: “Overview” on page 864 “Authentication Process” on

Seite 1362

Chapter 60: 802.1x Port-based Network Access Control864OverviewThis chapter explains 802.1x port-based network access control. This port security feat

Seite 1363 - Distinguished

AT-9000 Switch Command Line User’s Guide865Authentication ProcessBelow is a brief overview of the authentication process that occurs between a supplic

Seite 1364

Chapter 60: 802.1x Port-based Network Access Control866Port RolesPart of the task to implementing this feature is specifying the roles of the ports on

Seite 1365 - generate

AT-9000 Switch Command Line User’s Guide867Authentication Methods for Authenticator PortsAuthenticator ports support two authentication methods: 802.

Seite 1366

Chapter 60: 802.1x Port-based Network Access Control868Operational Settings for Authenticator PortsAn authenticator port can have one of three possibl

Seite 1367

AT-9000 Switch Command Line User’s Guide869Operating Modes for Authenticator PortsAuthenticator ports have three modes: Single host mode Multi host

Seite 1368

Chapter 60: 802.1x Port-based Network Access Control870Note, however, that should the client who performed the initial log on fail to periodically rea

Seite 1369

AT-9000 Switch Command Line User’s Guide871As mentioned earlier, should the client who performed the initial logon fail to reauthenticate when necessa

Seite 1370

AT-9000 Switch Command Line User’s Guide9SHOW POWER-INLINE COUNTERS INTERFACE ...

Seite 1371

Chapter 4: Basic Command Line Management Commands62DISABLESyntaxdisableParametersNoneModePrivileged Exec modeDescriptionUse this command to return to

Seite 1372

Chapter 60: 802.1x Port-based Network Access Control872Figure 155. Multi Supplicant ModeRADIUSAuthenticationServerPort 6Role: AuthenticatorOperating M

Seite 1373

AT-9000 Switch Command Line User’s Guide873Supplicant and VLAN AssociationsOne of the challenges to managing a network is accommodating end users who

Seite 1374

Chapter 60: 802.1x Port-based Network Access Control874Single Host Mode Here are the operating characteristics for the switch when an authenticator po

Seite 1375

AT-9000 Switch Command Line User’s Guide875Supplicant VLANAttributes on theRADIUS ServerThe following information must be entered as part of a supplic

Seite 1376 - CRYPTO CERTIFICATE DESTROY

Chapter 60: 802.1x Port-based Network Access Control876Guest VLANAn authenticator port in the unauthorized state typically accepts and transmits only

Seite 1377 - CRYPTO CERTIFICATE GENERATE

AT-9000 Switch Command Line User’s Guide877RADIUS AccountingThe switch supports RADIUS accounting on authenticator ports. This feature sends informati

Seite 1378

Chapter 60: 802.1x Port-based Network Access Control878General StepsHere are the general steps to implementing 802.1x Port-based Network Access Contro

Seite 1379

AT-9000 Switch Command Line User’s Guide879GuidelinesHere are the general guidelines to this feature: Ports operating under port-based access control

Seite 1380 - CRYPTO CERTIFICATE IMPORT

Chapter 60: 802.1x Port-based Network Access Control880 Authenticator and supplicant ports must be untagged ports. They cannot be tagged ports. Auth

Seite 1381 - CRYPTO CERTIFICATE REQUEST

AT-9000 Switch Command Line User’s Guide881Enabling 802.1x Port-Based Network Access Control on the SwitchTo activate 802.1x Port-based Network Access

Seite 1382

AT-9000 Switch Command Line User’s Guide63DOSyntaxdo commandParametercommandSpecifies the Privileged Exec mode command to perform. ModeGlobal Configur

Seite 1383 - SERVICE HTTPS

Chapter 60: 802.1x Port-based Network Access Control882Configuring Authenticator PortsDesignatingAuthenticatorPortsYou have to designate ports as auth

Seite 1384 - IP HTTPS CERTIFICATE

AT-9000 Switch Command Line User’s Guide883awplus> enableawplus# configure terminalawplus(config)# interface port1.0.16awplus(config-if)# auth-mac

Seite 1385 - NO SERVICE HTTPS

Chapter 60: 802.1x Port-based Network Access Control884This example configures port 8 to use the multi host mode so that it forwards traffic from all

Seite 1386 - SHOW CRYPTO CERTIFICATE

AT-9000 Switch Command Line User’s Guide885Configuring ReauthenticationTable 86 lists the commands in the Port Interface mode for configuring reauthen

Seite 1387 - SHOW IP HTTPS

Chapter 60: 802.1x Port-based Network Access Control886Removing Ports from the Authenticator RoleTo remove ports from the authenticator role so that t

Seite 1388

AT-9000 Switch Command Line User’s Guide887Disabling 802.1x Port-Based Network Access Control on the SwitchTo disable 802.1x port-based network access

Seite 1389 - RADIUS and TACACS+ Clients

Chapter 60: 802.1x Port-based Network Access Control888Displaying Authenticator PortsTo view the settings of authenticator ports on the switch, use th

Seite 1390

AT-9000 Switch Command Line User’s Guide889Displaying EAP Packet StatisticsTo display EAP packet statistics of authenticator ports, use the SHOW DOT1X

Seite 1391 - Remote Manager Accounts

Chapter 60: 802.1x Port-based Network Access Control890

Seite 1392

891Chapter 61802.1x Port-based Network Access Control CommandsThe 802.1x port-based network access control commands are summarized in Table 87 and des

Seite 1393

Chapter 4: Basic Command Line Management Commands64ENABLESyntaxenableParametersNoneModeUser Exec mode DescriptionUse this command to move from the Use

Seite 1394 - Managing the RADIUS Client

Chapter 61: 802.1x Port-based Network Access Control Commands892“AUTH-MAC REAUTH-RELEARNING” on page 906Port Interface Forces ports that are using MAC

Seite 1395 - Server Timeout

AT-9000 Switch Command Line User’s Guide893“NO AUTH-MAC ENABLE” on page 921Port Interface Deactivates MAC address-based authentication on authenticato

Seite 1396

Chapter 61: 802.1x Port-based Network Access Control Commands894AAA AUTHENTICATION DOT1X DEFAULT GROUP RADIUSSyntaxaaa authentication dot1x default gr

Seite 1397 - RADIUS Client

AT-9000 Switch Command Line User’s Guide895AUTH DYNAMIC-VLAN-CREATIONSyntaxauth dynamic-vlan-creation single| multiParameterssingleSpecifies that an a

Seite 1398 - Managing the TACACS+ Client

Chapter 61: 802.1x Port-based Network Access Control Commands896This example activates dynamic VLAN assignment on authenticator port 4. When the initi

Seite 1399

AT-9000 Switch Command Line User’s Guide897AUTH GUEST-VLANSyntaxauth guest-vlan vidParametersvidSpecifies the ID number of a VLAN that is the guest VL

Seite 1400

Chapter 61: 802.1x Port-based Network Access Control Commands898AUTH HOST-MODESyntaxauth host-mode single-host| multi-host| multi-supplicantParameters

Seite 1401

AT-9000 Switch Command Line User’s Guide899This example configures authenticator port 8 to the multi host operating mode, so that networks users can u

Seite 1402

Chapter 61: 802.1x Port-based Network Access Control Commands900AUTH REAUTHENTICATIONSyntaxauth reauthenticationParametersNoneModePort Interface modeD

Seite 1403

AT-9000 Switch Command Line User’s Guide901AUTH TIMEOUT QUIET-PERIODSyntaxauth timeout quiet-period valueParametersquiet-periodSets the number of seco

Seite 1404

AT-9000 Switch Command Line User’s Guide65ENDSyntaxendParametersNoneModeAll modes below the Global Configuration mode.DescriptionUse this command to r

Seite 1405 - RADIUS and TACACS+ Client

Chapter 61: 802.1x Port-based Network Access Control Commands902AUTH TIMEOUT REAUTH-PERIODSyntaxauth timeout reauth-period valueParametersreauth-perio

Seite 1406

AT-9000 Switch Command Line User’s Guide903AUTH TIMEOUT SERVER-TIMEOUTSyntaxauth timeout server-timeout valueParametersserver-timeoutSets the timer us

Seite 1407 - AAA ACCOUNTING LOGIN

Chapter 61: 802.1x Port-based Network Access Control Commands904AUTH TIMEOUT SUPP-TIMEOUTSyntaxauth timeout supp-timeout valueParameterssupp-timeoutSe

Seite 1408

AT-9000 Switch Command Line User’s Guide905AUTH-MAC ENABLESyntaxauth-mac enableParametersNoneModePort Interface modeDescriptionUse this command to act

Seite 1409 - tacacs [

Chapter 61: 802.1x Port-based Network Access Control Commands906AUTH-MAC REAUTH-RELEARNINGSyntaxauth-mac reauth-relearningParametersNoneModePrivileged

Seite 1410

AT-9000 Switch Command Line User’s Guide907DOT1X CONTROL-DIRECTIONSyntaxdot1x control-direction in|bothParametersdirSpecifies whether authenticator po

Seite 1411 - AAA AUTHENTICATION LOGIN

Chapter 61: 802.1x Port-based Network Access Control Commands908broadcast and multicast packets while discarding ingress broadcast and multicast traff

Seite 1412

AT-9000 Switch Command Line User’s Guide909DOT1X EAPSyntaxdot1x eap discard|forward|forward-untagged-vlan|forward-vlanParametersdiscardDiscards all in

Seite 1413 - IP RADIUS SOURCE-INTERFACE

Chapter 61: 802.1x Port-based Network Access Control Commands910This example configures the switch to discard all EAP packets when 802.1x authenticati

Seite 1414

AT-9000 Switch Command Line User’s Guide911DOT1X INITIALIZE INTERFACESyntaxdot1x initialize interface portParametersportSpecifies a port. You can ente

Seite 1415 - LOGIN AUTHENTICATION

Chapter 4: Basic Command Line Management Commands66EXITSyntaxexitParametersNoneModeAll modesDescriptionUse this command to move down one mode in the m

Seite 1416

Chapter 61: 802.1x Port-based Network Access Control Commands912DOT1X MAX-REAUTH-REQSyntaxdot1x max-reauth-req valueParametersmax-reauth-reqSpecifies

Seite 1417 - NO LOGIN AUTHENTICATION

AT-9000 Switch Command Line User’s Guide913DOT1X PORT-CONTROL AUTOSyntaxdot1x port-control autoParametersNoneModePort Interface modeDescriptionUse thi

Seite 1418 - NO RADIUS-SERVER HOST

Chapter 61: 802.1x Port-based Network Access Control Commands914DOT1X PORT-CONTROL FORCE-AUTHORIZEDSyntaxdot1x port-control force-authorizedParameters

Seite 1419 - NO TACACS-SERVER HOST

AT-9000 Switch Command Line User’s Guide915DOT1X PORT-CONTROL FORCE-UNAUTHORIZEDSyntaxdot1x port-control force-unauthorizedParametersNoneModePort Inte

Seite 1420 - RADIUS-SERVER HOST

Chapter 61: 802.1x Port-based Network Access Control Commands916DOT1X TIMEOUT TX-PERIODSyntaxdot1x timeout tx-period valueParametersvalueSets the numb

Seite 1421

AT-9000 Switch Command Line User’s Guide917NO AAA AUTHENTICATION DOT1X DEFAULT GROUP RADIUSSyntaxno aaa authentication dot1x default group radiusParam

Seite 1422 - RADIUS-SERVER KEY

Chapter 61: 802.1x Port-based Network Access Control Commands918NO AUTH DYNAMIC-VLAN-CREATIONSyntaxno auth dynamic-vlan-creationParametersNoneModePort

Seite 1423 - RADIUS-SERVER TIMEOUT

AT-9000 Switch Command Line User’s Guide919NO AUTH GUEST-VLANSyntaxno auth guest-vlanParametersNoneModePort Interface modeDescriptionUse this command

Seite 1424 - SHOW RADIUS

Chapter 61: 802.1x Port-based Network Access Control Commands920NO AUTH REAUTHENTICATIONSyntaxno auth reauthenticationParametersNoneModePort Interface

Seite 1425

AT-9000 Switch Command Line User’s Guide921NO AUTH-MAC ENABLESyntaxno auth-mac enableParametersNoneModePort Interface modeDescriptionUse this command

Seite 1426 - SHOW TACACS

AT-9000 Switch Command Line User’s Guide67LENGTHSyntaxlength valueParametersvalueSpecifies the maximum number of lines that the SHOW commands display

Seite 1427

Chapter 61: 802.1x Port-based Network Access Control Commands922NO DOT1X PORT-CONTROLSyntaxno dot1x port-controlParametersNoneModePort Interface modeD

Seite 1428 - TACACS-SERVER HOST

AT-9000 Switch Command Line User’s Guide923SHOW AUTH-MAC INTERFACESyntaxshow auth-mac interface portParametersportSpecifies a port. You can display mo

Seite 1429 - TACACS-SERVER KEY

Chapter 61: 802.1x Port-based Network Access Control Commands924SHOW AUTH-MAC SESSIONSTATISTICS INTERFACESyntaxshow auth-mac sessionstatistics interfa

Seite 1430 - TACACS-SERVER TIMEOUT

AT-9000 Switch Command Line User’s Guide925SHOW AUTH-MAC STATISTICS INTERFACESyntaxshow auth-mac statistics interface portParametersportSpecifies a po

Seite 1431 - System Monitoring Commands

Chapter 61: 802.1x Port-based Network Access Control Commands926SHOW AUTH-MAC SUPPLICANT INTERFACESyntaxshow auth-mac supplicant interface portParamet

Seite 1432 - SHOW CPU

AT-9000 Switch Command Line User’s Guide927SHOW DOT1XSyntaxshow dot1xParametersNoneModePrivileged Exec modeDescriptionUse this command to display whet

Seite 1433 - SHOW CPU HISTORY

Chapter 61: 802.1x Port-based Network Access Control Commands928SHOW DOT1X INTERFACESyntaxshow dot1x interface portParametersportSpecifies a port. You

Seite 1434 - SHOW CPU USER-THREADS

AT-9000 Switch Command Line User’s Guide929SHOW DOT1X STATISTICS INTERFACESyntaxshow dot1x statistics interface portParametersportSpecifies a port. Yo

Seite 1435 - SHOW MEMORY

Chapter 61: 802.1x Port-based Network Access Control Commands930SHOW DOT1X SUPPLICANT INTERFACESyntaxshow dot1x supplicant interface port [brief]Param

Seite 1436 - SHOW MEMORY ALLOCATION

931Section IXSimple Network Management ProtocolsThis section contains the following chapters: Chapter 62, “SNMPv1 and SNMPv2c” on page 933 Chapter 6

Seite 1437 - SHOW MEMORY HISTORY

Chapter 4: Basic Command Line Management Commands68This example returns the number of lines to the default setting for local management sessions:awplu

Seite 1439 - SHOW PROCESS

933Chapter 62SNMPv1 and SNMPv2cThis chapter contains the following topics: “Overview” on page 934 “Enabling SNMPv1 and SNMPv2c” on page 936 “Creati

Seite 1440 - SHOW SYSTEM SERIALNUMBER

Chapter 62: SNMPv1 and SNMPv2c934OverviewThe Simple Network Management Protocol (SNMP) is another way for you to monitor and configure the switch. Thi

Seite 1441 - SHOW SYSTEM INTERRUPTS

AT-9000 Switch Command Line User’s Guide935To configure the switch to send trap or inform messages, you have to add to one or more of the community st

Seite 1442 - SHOW TECH-SUPPORT

Chapter 62: SNMPv1 and SNMPv2c936Enabling SNMPv1 and SNMPv2cTo enable SNMP on the switch, use the SNMP-SERVER command, found in the Global Configurati

Seite 1443

AT-9000 Switch Command Line User’s Guide937Creating Community StringsTo create SNMPv1 and SNMPv2c community strings, use the SNMP-SERVER COMMUNITY com

Seite 1444

Chapter 62: SNMPv1 and SNMPv2c938Adding or Removing IP Addresses of Trap or Inform ReceiversThe command to add IP addresses of trap or inform receiver

Seite 1445 - Appendix B

AT-9000 Switch Command Line User’s Guide939This example assigns the IP address 143.154.76.17 as an inform message receiver to the community string “st

Seite 1446 - Boot Configuration File

Chapter 62: SNMPv1 and SNMPv2c940Deleting Community StringsTo delete community strings, use the NO SNMP-SERVER COMMUNITY command. Here is the format:n

Seite 1447 - Class of Service

AT-9000 Switch Command Line User’s Guide941Disabling SNMPv1 and SNMPv2cTo disable SNMP on the switch, use the NO SNMP-SERVER command. You cannot remot

Seite 1448 - Console Port

AT-9000 Switch Command Line User’s Guide69LOGOUTSyntaxlogoutParametersNoneModeUser Exec and Privileged Exec modesDescriptionUse this command to end a

Seite 1449

Chapter 62: SNMPv1 and SNMPv2c942Displaying SNMPv1 and SNMPv2cTo learn whether SNMP is enabled or disabled on the switch, go to the Privileged Exec mo

Seite 1450 - Port 1813

AT-9000 Switch Command Line User’s Guide943To view the trap and inform receivers assigned to the community strings, use the SHOW RUNNING-CONFIG SNMP c

Seite 1451 - Enhanced Stacking

Chapter 62: SNMPv1 and SNMPv2c944

Seite 1452

945Chapter 63SNMPv1 and SNMPv2c CommandsThe SNMPv1 and SNMPv2c commands are summarized in Table 88 and described in detail within the chapter.Table 88

Seite 1453 - IGMP Snooping

Chapter 63: SNMPv1 and SNMPv2c Commands946“SHOW SNMP-SERVER VIEW” on page 959Privileged Exec Displays the SNMP views.“SNMP-SERVER” on page 960 Global

Seite 1454

AT-9000 Switch Command Line User’s Guide947NO SNMP-SERVERSyntaxno snmp-serverParametersNoneModeGlobal Configuration modeDescriptionUse this command to

Seite 1455

Chapter 63: SNMPv1 and SNMPv2c Commands948NO SNMP-SERVER COMMUNITYSyntaxno snmp-server community communityParametercommunitySpecifies an SNMP communit

Seite 1456 - MAC Address Table

AT-9000 Switch Command Line User’s Guide949NO SNMP-SERVER ENABLE TRAPSyntaxno snmp-server enable trapParametersNoneModeGlobal Configuration modeDescri

Seite 1457 - Management IP Address

Chapter 63: SNMPv1 and SNMPv2c Commands950NO SNMP-SERVER ENABLE TRAP AUTHSyntaxno snmp-server enable trap authParametersNoneModeGlobal Configuration m

Seite 1458 - Manager Account

AT-9000 Switch Command Line User’s Guide951NO SNMP-SERVER HOSTSyntaxno snmp-server host ipaddress traps|informs version 1|2c community_stringParameter

Seite 1459 - Port Settings

Chapter 4: Basic Command Line Management Commands70QUITSyntaxquitParametersNoneModeAll modes except the User Exec and Privileged Exec modes.Descriptio

Seite 1460

Chapter 63: SNMPv1 and SNMPv2c Commands952ExamplesThis example removes the IPv4 address 115.124.187.4 of a trap receiver from the private community st

Seite 1461

AT-9000 Switch Command Line User’s Guide953NO SNMP-SERVER VIEWSyntaxno snmp-server view viewname oidParametersviewnameSpecifies the name of the view t

Seite 1462

Chapter 63: SNMPv1 and SNMPv2c Commands954NO SNMP TRAP LINK-STATUSSyntaxno snmp trap link-statusParametersNoneModePort Interface modeDescriptionUse th

Seite 1463 - Secure Shell Server

AT-9000 Switch Command Line User’s Guide955SHOW RUNNING-CONFIG SNMPSyntaxshow running-config snmpParametersNoneModePrivileged Exec modeDescriptionUse

Seite 1464

Chapter 63: SNMPv1 and SNMPv2c Commands956SHOW SNMP-SERVERSyntaxshow snmp-serverParametersNoneModePrivileged Exec modeDescriptionUse this command to d

Seite 1465 - SNMP Status Disabled

AT-9000 Switch Command Line User’s Guide957SHOW SNMP-SERVER COMMUNITYSyntaxshow snmp-server communityParametersNoneModePrivileged Exec modeDescription

Seite 1466 - Simple Network Time Protocol

Chapter 63: SNMPv1 and SNMPv2c Commands958ExampleThis example displays the SNMPv1 and SNMPv2c community strings:awplus# show snmp-server community

Seite 1467

AT-9000 Switch Command Line User’s Guide959SHOW SNMP-SERVER VIEWSyntaxshow snmp-server viewParametersNoneModePrivileged Exec modeDescriptionUse this c

Seite 1468 - Protocol

Chapter 63: SNMPv1 and SNMPv2c Commands960SNMP-SERVERSyntaxsnmp-serverParametersNoneModeGlobal Configuration modeDescriptionUse this command to activa

Seite 1469 - System Name

AT-9000 Switch Command Line User’s Guide961SNMP-SERVER COMMUNITYSyntaxsnmp-server community community rw|roParameterscommunitySpecifies a new communit

Seite 1470 - TACACS+ Client

AT-9000 Switch Command Line User’s Guide71WRITESyntaxwriteParametersNoneModePrivileged Exec modeDescriptionUse this command to update the active boot

Seite 1471

Chapter 63: SNMPv1 and SNMPv2c Commands962SNMP-SERVER ENABLE TRAPSyntaxsnmp-server enable trapParametersNoneModeGlobal Configuration modeDescriptionUs

Seite 1472

AT-9000 Switch Command Line User’s Guide963SNMP-SERVER ENABLE TRAP AUTHSyntaxsnmp-server enable trap authParametersNoneModeGlobal Configuration modeDe

Seite 1473 - Web Server

Chapter 63: SNMPv1 and SNMPv2c Commands964SNMP-SERVER HOSTSyntaxsnmp-server host ipaddress traps|informs version 1|2c communityParametersipaddressSpec

Seite 1474

AT-9000 Switch Command Line User’s Guide965ExamplesThis example assigns the IPv4 address 149.44.12.44 of a trap receiver to the private community stri

Seite 1475 - Command Index

Chapter 63: SNMPv1 and SNMPv2c Commands966SNMP-SERVER VIEWSyntaxsnmp-server view viewname oid excluded|includedParametersviewnameSpecifies the name of

Seite 1476

AT-9000 Switch Command Line User’s Guide967This example creates the new view “AlliedTelesis” that limits the available MIB objects to those in the OID

Seite 1477

Chapter 63: SNMPv1 and SNMPv2c Commands968SNMP TRAP LINK-STATUSSyntaxsnmp trap link-statusParametersNoneModePort Interface modeDescriptionUse this com

Seite 1478

969Chapter 64SNMPv3 CommandsThe SNMPv3 commands are summarized in Table 91 and described in detail within the chapter.Table 91. SNMPv3 CommandsCommand

Seite 1479

Chapter 64: SNMPv3 Commands970“SNMP-SERVER GROUP” on page 985Global ConfigurationCreates SNMPv3 groups.“SNMP-SERVER HOST” on page 987 Global Configura

Seite 1480

AT-9000 Switch Command Line User’s Guide971NO SNMP-SERVERSyntaxno snmp-serverParametersNoneModeGlobal Configuration modeDescriptionUse this command to

Kommentare zu diesen Handbüchern

Keine Kommentare