The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Symbols
$ matches the end of a string 1-7
( ) in commands 1-11
* matches 0 or more sequences of a pattern 1-7
+ matches 1 or more sequences of a pattern 1-7
. matches any single character 1-7
? command 1-1
? matches 0 or 1 occurrence of a pattern 1-7
^ matches the beginning of a string 1-7
_ matches a comma (,), left brace ({), left parenthesis 1-7
" 1-10
Numerics
10-Gigabit Ethernet uplink
showing the mode 2-567
802.1Q trunk ports and native VLANs 2-910
802.1Q tunnel ports
configuring 2-855
802.1S Multiple Spanning Tree
802.1X
configuring for multiple hosts 2-184
configuring for single host 2-184
configuring multiple domains 2-184
disabling port control 2-177
enabling port control 2-177
802.1X Critical Authentication
disabling on a port 2-179
disabling on a VLAN 2-182
EAPOL
disabling send success packets 2-180
enabling send success packets 2-180
enabling on a port 2-179
enabling on a VLAN 2-182
returning delay time to default setting 2-181
setting delay time on a port 2-181
802.1X critical authentication
configure parameters 2-22
802.1X critical recovery delay, configuring 2-22
802.1X Port Based Authentication
debugging 802.1X Port Based Authentication 2-131
displaying port based authentication 2-552
enabling accounting for authentication sessions 2-4
enabling authentication on the system 2-195
enabling guest VLAN 2-183
enabling guest VLAN supplicant 2-176, 2-184
enabling manual control of auth state 2-191
enabling periodic re-authentication of the client 2-194
initializing re-authentication of dot1x ports 2-193
initializing state machines 2-187
receive session termination message upon reboot 2-5
setting maximum number for EAP requests 2-190
setting the reauthentication timer 2-196
A
aaa authorization network command 2-178
abbreviating commands
context-sensitive help 1-1
Access Gateway Module
connecting to a module 2-19
connecting to a remote module 2-472
connecting to a specific remote module 2-495
access-group
displaying mac interface 2-671
show mode interface 2-440, 2-513, 2-741
access groups
access lists
clearing an access template 2-94
defining ARP 2-18
displaying ARP information 2-517
See also ACLs, MAC ACLs, and VACLs
access maps
applying with VLAN filter 2-911
access-node-identifier, setting for the switch 2-442
access-policies, applying using host-mode 2-26
ACLs
access-group mode 2-6
balancing hardware regions 2-11
capturing control packets 2-8
determining ACL hardware programming 2-9
disabling hardware statistics 2-212
displaying mac access-group interface 2-671
enabling hardware statisctics 2-212
using ACL naming conventions for MAC ACLs 2-327
action clause
specifying drop or forward action in a VACL 2-12
addresses, configuring a maximum 2-427
adjacency
debugging the adjacency table 2-124
disabling the debug facility 2-124
displaying information about the adjacency table 2-514
displaying IPC table entries 2-124
aggregate policer
displaying information 2-742
aging time
displaying MAC address aging time 2-674
MAC address table 2-330
alarms
displaying operational status 2-556
alternation
description 1-10
anchoring
description 1-10
ancp, show multicast 2-516
ANCP client
port identifier 2-14
remote server 2-15
set router to become 2-16
ARP
access list, displaying detailed information 2-517
defining access-lists 2-18
ARP inspection
enforce certain types of checking 2-233
ARP packet
deny based on DHCP bindings 2-166
permit based on DHCP bindings 2-407
changing the control-direction 2-20
configure actions for events
configuring the actions 2-23
configuring port-control 2-31
enabling reauthentication 2-30
enabling Webauth fallback 2-25
host-mode configuration 2-26
setting priority of methods 2-33
setting the timer 2-35
setting username 2-899
specifying the order of methods 2-29
using an MD5-type encryption method 2-899
verifying MD5 signature 2-900
verifying the checksum for Flash memory 2-900
authentication control-direction command 2-20
authentication critical recovery delay command 2-22
authentication event command 2-23
authentication fallback command 2-25
authentication host-mode 2-26
authentication methods, setting priority 2-33
authentication methods, specifying the order of attempts 2-29
authentication open command 2-28
authentication order command 2-29
authentication periodic command 2-30
authentication port-control command 2-31
authentication priority command 2-33
authentication timer, setting 2-35
authentication timer command 2-35
authentication violation command 2-37
auth fail VLAN
enable on a port 2-176
set max number of attempts 2-175
Auth Manager
configuring
authentication timer 2-35
authorization state
enabling manual control 2-191
authorization state of a controlled port 2-191
automatic installation
displaying status 2-523
automatic medium-dependent interface crossover
Auto-MDIX
disabling 2-374
enabling 2-374
auto-negotiate interface speed
example 2-834
auto-QoS
configuring for VoIP 2-59
displaying configuration 2-524
auto qos srnd4 command 2-47
B
baby giants
displaying the system MTU setting 2-770
setting the maximum Layer 2 payload size 2-881
BackboneFast
displaying debugging messages 2-153
displaying spanning tree status 2-762
enabling debugging 2-153
bandwidth command 2-67
bindings
store for DHCP snooping 2-244
BOOT environment variable
displaying information 2-527
bootflash
displaying information 2-525
BPDUs
debugging spanning tree activities 2-151
bridge protocol data units
broadcast suppression level
C
cable diagnostics
TDR
displaying test results 2-528
testing conditions of copper cables 2-882
call home
displaying information 2-530
e-mailing output 2-75
entering configuration submode 2-70
executing 2-75
manually send test message 2-78
receiving information 2-73
sending alert group message 2-76
submitting information 2-73
call home destination profiles
displaying 2-532
Catalyst 4507R 2-425
CDP
configuring tunneling encapsulation rate 2-315
displaying
neighbor information 2-535
enabling protocol tunneling for 2-312
set drop threshold for 2-314
CEF
displaying next-hop information 2-601
displaying VLAN configuration information 2-601
chassis
displaying
chassis MAC address ranges 2-669
current and peak traffic meter readings 2-669
percentage of backplane utilization 2-669
switching clock failure recovery mode 2-669
circuit-id
setting for an interface 2-444
circuit-id, setting for an interface VLAN range 2-445
cisco-desktop
macro apply 2-339
Cisco Express Forwarding
cisco-phone
macro apply 2-341
cisco-router
macro apply 2-343
cisco-switch
macro apply 2-345
CISP
See Client Information Signalling Protocol
cisp enable command 2-83
class maps
creating 2-87
defining the match criteria 2-367
monitor capture 2-380
clear commands
clearing Gigabit Ethernet interfaces 2-92
clearing IGMP group cache entries 2-101
clearing interface counters 2-89
clearing IP access lists 2-94, 2-95
clearing IP ARP inspection statistics VLAN 2-96
clearing IP DHCP snooping database statistics 2-100
clearing MFIB counters and routes 2-104
clearing MFIB fastdrop entries 2-105
clearing PAgP channel information 2-112
clearing QoS aggregate counters 2-116
clearing VLAN interfaces 2-93
clear ip wccp command 2-106
clear nmsp statistics command 2-111
Client Information Signalling Protocol 2-178
Client Information Signalling Protocol, enabling 2-83
CLI string search
anchoring 1-10
expressions 1-7
filtering 1-6
multiple-character patterns 1-8
multipliers 1-9
parentheses for recall 1-11
searching outputs 1-6
single-character patterns 1-7
using 1-6
command 2-380
command modes
accessing privileged EXEC mode 1-5
exiting 1-5
understanding user EXEC and configuration modes 1-5
condition interface
debugging interface-related activities 2-126
condition vlan
debugging VLAN output 2-129
configuration, saving 1-11
configuring
root as secondary 2-820
configuring a SPAN session to monitor
limit SPAN source traffic 2-393
configuring critical recovery 2-22
configuring forward delay 2-816
configuring root as primary 2-820
CoPP
attaching
policy map to control plane 2-493
displaying
policy-map class information 2-716
entering configuration mode 2-119
removing
service policy from control plane 2-493
CoS
assigning to Layer 2 protocol packets 2-313
counter command 2-121
counters
clearing interface counters 2-89
critical authentication, configure 802.1X parameters 2-22
critical recovery, configuring 802.1X parameter 2-22
D
DAI
clear statistics 2-96
DBL
displaying qos dbl 2-743
debug commands
debugging backup events 2-125
debugging DHCP snooping events 2-136
debugging DHCP snooping messages 2-137
debugging EtherChannel/PAgP/shim 2-132
debugging IPC activity 2-135
debugging IP DHCP snooping security messages 2-138
debugging NVRAM activities 2-142
debugging PAgP activities 2-143
debugging port manager activities 2-146
debugging spanning tree activities 2-151
debugging spanning tree backbonefast 2-153
debugging spanning tree UplinkFast 2-156
debugging supervisor redundancy 2-150
debugging VLAN manager activities 2-157
displaying monitor activity 2-140
displaying the adjacency table 2-124
enabling debug dot1x 2-131
enabling debugging messages for ISL VLAN IDs 2-160
enabling debugging messages for VTP 2-161
enabling debugging of UDLD activity 2-162
enabling switch shim debugging 2-154
enabling VLAN manager file system error tests 2-158
limiting debugging output for VLANs 2-129
limiting interface debugging output 2-126
limiting output for debugging standby state changes 2-127
shortcut to the debug condition interface 2-134
debugging
activity monitoring 2-140
DHCP snooping events 2-136
DHCP snooping packets 2-137
IPC activities 2-135
IP DHCP snooping security packets 2-138
NVRAM activities 2-142
PAgP activities 2-143
PAgP shim 2-132
PM activities 2-146
PPPoE Intermediate Agent 2-148
spanning tree BackboneFast events 2-153
spanning tree switch shim 2-154
spanning tree UplinkFast events 2-156
VLAN manager activities 2-157
VLAN manager IOS file system error tests 2-158
VTP protocol debug messages 2-161
debug nmsp command 2-141
debug spanning tree switch 2-154
debug sw-vlan vtp 2-161
default form of a command, using 1-6
DHCP
clearing database statistics 2-100
DHCP bindings
configuring bindings 2-243
deny ARP packet based on matches 2-166
permit ARP packet based on matches 2-407
DHCP snooping
clearing binding entries 2-97
clearing database 2-99
displaying binding table 2-603
displaying configuration information 2-602
displaying status of DHCP database 2-606
displaying status of error detection 2-559
enabling DHCP globally 2-242
enabling IP source guard 2-278
enabling on a VLAN 2-251
enabling option 82 2-246, 2-248
enabling option-82 2-253
enabling rate limiting on an interface 2-249
enabling trust on an interface 2-250
establishing binding configuration 2-243
renew binding database 2-474
store generated bindings 2-244
diagnostic fpga soft-error recover command 2-172
diagnostic test
bootup packet memory 2-546
displaying attributes 2-540
display module-based results 2-542
running 2-174
show results for TDR 2-528
testing conditions of copper cables 2-882
displaying error disable recovery 2-560
displaying inline power status 2-730
displaying monitoring activity 2-140
displaying PoE policing and monitoring status 2-738
displaying SEEPROM information
GBIC 2-567
displaying SPAN session information 2-770, 2-837
document conventions 1-xxii
document organization 1-xxi
DoS
CoPP
attaching policy map to control plane 2-493
displaying policy-map class information 2-716
entering configuration mode 2-119
removing service policy from control plane 2-493
entering
CoPP configuration mode 2-119
DOS attack
protecting system's resources 2-228
dot1x credentials (global configuration) command 2-178
drop threshold, Layer 2 protocol tunneling 2-314
DSCP rewrite for IP packets
enable 2-463
dual-capable port
selecting a connector 2-376
duplex mode
configuring autonegotiation on an interface 2-198
configuring full duplex on an interface 2-198
configuring half duplex on an interface 2-198
dynamic ARP inspection
preventing 2-228
Dynamic Host Configuration Protocol
E
EAP
restarting authentication process 2-190
EIGRP (Enhanced IGRP)
filters
routing updates, preventing 2-404
enabling
debugging for UDLD 2-162
voice VLANs 2-849
enabling open access 2-28
environmental
alarms 2-556
displaying information 2-556
status 2-556
temperature 2-556
epm access control command 2-200
erase a file 2-201
error disable detection
clearing error disable on an interface 2-90
enabling error disable detection 2-90, 2-204
enabling per-VLAN on BPDU guard 2-204
error-disabled state
displaying 2-586
error disable recovery
configuring recovery mechanism variables 2-206
displaying recovery timer information 2-560
enabling ARP inspection timeout 2-206
specifying recovery cause 2-206
EtherChannel
assigning interfaces to EtherChannel groups 2-79
debugging EtherChannel 2-132
debugging PAgP shim 2-132
debugging spanning tree activities 2-151
displaying information for a channel 2-561
removing interfaces from EtherChannel groups 2-79
EtherChannel guard
detecting STP misconfiguration 2-807
Explicit Host Tracking
clearing the database 2-103
enabling per-VLAN 2-265
expressions
matching multiple expression occurrences 1-9
multiple-character patterns 1-8
multiplying pattern occurrence 1-11
single-character patterns 1-7
Extensible Authentication Protocol
F
fallback profile, specifying 2-25
field replaceable unit (FRU)
displaying status information 2-556
filters
EIGRP
routing updates, preventing 2-404
Flash memory file system
displaying file system information 2-525
verifying checksum 2-900
flow control
configuring a gigabit interface for pause frames 2-209
displaying per-interface statistics for flow control 2-565
G
GBIC
displaying SEEPROM information 2-567
generic-error-message, setting for the switch 2-442
Gigabit Ethernet interface
clearing the hardware logic 2-92
Gigabit Ethernet uplink
showing the mode 2-567
global configuration mode
using 1-5
H
hardware module
resetting a module by toggling the power 2-214
hardware statistics
disabling 2-212
enabling 2-212
hardware uplink
showing the mode 2-567
helper addresses, IP 2-619
hot standby protocol
debugging 2-127
disabling debugging 2-127
limiting output 2-127
hw-module beacon command 2-213
I
identifier-string, setting for the switch 2-442
ID mapping, creating an ANCP client 2-14
IDPROMs
displaying SEEPROM information
chassis 2-567
clock module 2-567
fan trays 2-567
module 2-567
mux buffer 2-567
power supplies 2-567
supervisor engine 2-567
ifIndex persistence
clearing SNMP ifIndex commands 2-793
compress SNMP ifIndex table format 2-798
disabling globally 2-797
disabling on an interface 2-794
enabling globally 2-797
enabling on an interface 2-794
IGMP
applying filters for host joining on Layer 2 interfaces 2-255
clearing IGMP group cache entries 2-101
configuring frequency for IGMP host-query messages 2-258
creating an IGMP profile 2-257
displaying IGMP interface configuration information 2-608
displaying profiles 2-609
setting maximum group numbers 2-256
IGMP profiles
displaying 2-609
IGMP snooping
clearing the EHT database 2-103
configuring a Layer 2 interface as a group member 2-269
configuring a Layer 2 interface as a multicast router 2-267
configuring a static VLAN interface 2-269
displaying multicast information 2-616
displaying VLAN information 2-610, 2-614, 2-617
enabling 2-260
enabling immediate-leave processing 2-266
enabling on a VLAN 2-264
enabling per-VLAN Explicit Host Tracking 2-265
informs
enabling 2-795
inline power
displaying inline power status 2-730
In Service Software Upgrade
inspection log
clearing log buffer 2-95
interface
displaying suppressed multicast bytes 2-580
interface capabilities
displaying 2-576
interface configuration mode
summary 1-5
interface link
display cable disconnect time 2-583
interfaces
configuring dot1q tunnel ports 2-855
creating an interface-range macro 2-165
debugging output of interface related activities 2-126
displaying description 2-582
displaying error-disabled state 2-586
displaying information when tunneling is enabled 2-664
displaying status 2-582
displaying traffic for a specific interface 2-573
entering interface configuration mode 2-219
executing a command on multiple ports in a range 2-222
selecting an interface to configure 2-219
setting a CoS value for Layer 2 packets 2-313
setting drop threshold for Layer 2 packets 2-314
setting the interface type 2-855
interface speed
configuring interface speed 2-832
interface transceiver
displaying diagnostic data 2-590
internal VLAN allocation
configuring 2-913
default setting 2-913
displaying allocation information 2-783
Internet Group Management Protocol
IP address of remote ANCP server, setting 2-15
IP ARP
applying ARP ACL to VLAN 2-226
clearing inspection statistics 2-96
clearing status of log buffer 2-95
controlling packet logging 2-237
enabling dynamic inspection 2-235
limit rate of incoming requests 2-228
set per-port config trust state 2-232
showing status of dynamic ARP inspection 2-597
showing status of log buffer 2-600
IPC
debugging IPC activities 2-135
IP DHCP Snooping
IP header validation
disabling 2-277
enabling 2-277
IP interfaces
displaying usability status 2-618
IP multicast
displaying multicast routing table information 2-624
ip multicast multipath command 2-272
IP packets
enable DSCP rewrite 2-463
IP phone and standard desktop
enabling Cisco-recommended features 2-341
IP Port Security
enabling 2-278
IP source binding
adding or deleting 2-274
displaying bindingstagging 2-629
IP source guard
debugging messages 2-138
displaying configuration and filters 2-630
enabling on DHCP snooping 2-278
IPv4 statistics, enabling collection 2-121
IPv6 MLD
configuring queries 2-293, 2-295
configuring snooping last-listener-query-intervals 2-295
configuring snooping listener-message-suppression 2-297
configuring snooping robustness-variables 2-298
configuring tcn topology change notifications 2-300
counting snooping last-listener-queries 2-293
displaying information 2-642
displaying ports for a switch or VLAN 2-644
displaying querier information 2-645
enabling snooping 2-291
enabling snooping on a VLAN 2-301
IPv6 statistics, enabling collection 2-121
ip wccp check services all command 2-284
ip wccp command 2-281
ip wccp group-address command 2-281
ip wccp group-list command 2-281
ip wccp group-listen command 2-286
ip wccp password command 2-281, 2-282
ip wccp redirect command 2-288
ip wccp redirect exclude in command 2-290
ip wccp redirect-list command 2-281
ISSU
canceling process 2-303
configuring rollback timer 2-311
displaying capability 2-647
displaying client information 2-649
displaying compatibility matrix 2-651
displaying endpoint information 2-655
displaying entities 2-656
displaying FSM session 2-657
displaying messages 2-658
displaying negotiated 2-659
displaying rollback-timer 2-660
displaying session information 2-661
displaying software version 2-662
displaying state 2-662
forcing switchover to standby supervisor engine 2-310
loading new image 2-306
starting process 2-308
stopping rollback timer 2-304
J
Jumbo frames
enabling jumbo frames 2-398
L
LACP
deselecting channeling protocol 2-81
enabling LACP on an interface 2-81
setting channeling protocol 2-81
lacp port-priority command 2-317
lacp system-priority command 2-318
Layer 2
displaying ACL configuration 2-671
Layer 2 interface type
specifying a nontrunking, nontagged single VLAN interface 2-855
specifying a trunking VLAN interface 2-855
Layer 2 protocol ports
displaying 2-664
Layer 2 protocol tunneling error recovery 2-315
Layer 2 switching
enabling voice VLANs 2-849
modifying switching characteristics 2-849
Layer 2 traceroute
IP addresses 2-887
Layer 3 interface, assign counters 2-121
Layer 3 switching
displaying information about an adjacency table 2-514
displaying port status 2-588
displaying status of native VLAN tagging 2-588
link-status event messages
disabling
enabling
LLDP
enabling power negotiation 2-319
lldp tlv-select power-management command 2-319
log buffer
show status 2-600
logging
controlling IP ARP packets 2-237
M
MAB, display information 2-669
MAB, enable and configure 2-326
mab command 2-326
MAC Access Control Lists
MAC ACLs
defining extended MAC access list 2-327
displaying MAC ACL information 2-779
naming an ACL 2-327
MAC addresses
disabling MAC address learning per VLAN 2-334
displaying
notification settings 2-200, 2-641, 2-680
MAC address filtering
configuring 2-338
disabling 2-338
enabling 2-338
MAC address learning on a VLAN, enabling 2-334
MAC address table
adding static entries 2-365
clearing dynamic entries 2-108, 2-110
configuring aging time 2-330
displaying dynamic table entry information 2-676
displaying entry count 2-675
displaying information 2-672
displaying interface-based information 2-678
displaying multicast information 2-681
displaying notification information 2-683
displaying protocol-based information 2-685
displaying static table entry information 2-687
displaying the MAC address aging time 2-674
displaying VLAN-based information 2-689
enabling authentication bypass 2-188
enabling notifications 2-336
learning in the protocol buckets 2-331
removing static entries 2-365
mac address-table learning vlan command 2-334
MAC address tables
adding static entries 2-338
deleting secure or specific addresses 2-113
disabling IGMP snooping on static MAC addresses 2-338
removing static entries 2-338
mac-address-table static 2-338
MAC address unicast filtering
dropping unicast traffic 2-338
MAC authentication bypass (MAB), display information 2-669
MAC authorization bypass(MAB), enable and configure 2-326
macro
displaying descriptions 2-364
macro auto global processing command 2-347, 2-349, 2-352, 2-353, 2-355, 2-357, 2-359, 2-361, 2-691
macro auto monitor command 2-358
macro keywords
help strings 2-2
macros
adding a global description 2-364
cisco global 2-362
system-cpp 2-363
mapping secondary VLANs to MST instance 2-457
mapping VLAN(s) to an MST instance 2-216
match (class-map configuration) command 2-13, 2-168, 2-169, 2-170, 2-171, 2-367, 2-838, 2-839, 2-841, 2-843, 2-847
maximum transmission unit (MTU)
displaying the system MTU setting 2-770
setting the maximum Layer 2 payload size 2-881
MD5
verifying MD5 signature 2-900
message digest 5
MFIB
clearing ip mfib counters 2-104
clearing ip mfib fastdrop 2-105
displaying all active MFIB routes 2-621
displaying MFIB fastdrop table entries 2-623
enabling IP MFIB fastdrops 2-271
MLD
configuring snooping last-listener-query-intervals 2-295
configuring snooping listener-message-suppression 2-297
configuring snooping robustness-variables 2-298
configuring topology change notifications 2-300
counting snooping last-listener-queries 2-293
enabling snooping 2-291
enabling snooping on a VLAN 2-301
MLD snooping
displaying 2-645
modes
access-group 2-6
show access-group interface 2-440, 2-513, 2-741
switching between PVST+, MST, and Rapid PVST 2-812
module password clearing 2-91
module reset
resetting a module by toggling the power 2-214
monitor capture {access-list | class-map} command 2-379
monitor capture mycap match command 2-386
monitor capture start command 2-388
--More-- prompt
filter 1-6
search 1-7
MST
designating the primary and secondary root 2-820
displaying MST protocol information 2-766
displaying region configuration information 2-766
displaying spanning tree information 2-766
entering MST configuration submode 2-814
setting configuration revision number 2-487
setting path cost and port priority for instances 2-813
setting the forward delay timer for all instances 2-816
setting the hello-time delay timer for all instances 2-817
setting the max-age timer for all instances 2-818
setting the MST region name 2-399
specifying the maximum number of hops 2-819
switching between PVST+ and Rapid PVST 2-812
using the MST configuration submode revision command 2-487
using the submode name command 2-399
MTU
displaying global MTU settings 2-770
multi-auth, setting 2-26
Multicase Listener Discovery
multicast
enabling storm control 2-837
show ancp 2-516
multicast/unicast packets
prevent forwarding 2-854
Multicast Forwarding Information Base
multi-domain, setting 2-26
multiple-character patterns 1-8
Multiple Spanning Tree
N
native VLAN
controlling tagging of traffic 2-875
displaying ports eligible for native tagging 2-781
displaying ports eligible for tagging 2-781
enabling tagging on 802.1Q trunk ports 2-910
specifing the tagging of traffic 2-876
NetFlow
enabling NetFlow statistics 2-274
including infer fields in routing statistics 2-274
next-hop
displaying CEF VLAN information 2-601
nmsp attachment suppress command 2-401
nmsp command 2-400
no form of a command, using 1-6
NVRAM
debugging NVRAM activities 2-142
O
open access on a port, enabling 2-28
output
pattern searches 1-7
P
packet counters (statistics)
clear for PPPoE Intermediate Agent 2-115
packet counters, display for PPPoE Intermediate Agent 2-739
packet forwarding
prevent unknown packets 2-854
packet memory failure
direct switch action upon detection 2-173
packet memory test
bootup, displaying results 2-546, 2-548
ongoing, displaying results 2-550
PACL
access-group mode 2-6
paging prompt
PAgP
clearing port channel information 2-112
debugging PAgP activity 2-143
deselecting channeling protocol 2-81
displaying port channel information 2-713
hot standby mode
returning to defaults 2-403
selecting ports 2-403
input interface of incoming packets
learning 2-402
returning to defaults 2-402
setting channeling protocol 2-81
parentheses 1-11
password
clearing on an intelligent line module 2-91
establishing enhanced password security 2-899
setting username 2-899
PBR
redistributing route maps 1-xxii
PM activities
debugging 2-146
disabling debugging 2-146
PoE policing
configure on an interface 2-435
PoE policing and monitoring
displaying status 2-738
police (percent) command 2-413
police (two rates) command 2-415, 2-417
police command 2-409
policing, configure PoE 2-435
policing and monitoring status
displaying PoE 2-738
Policy Based Routing
policy maps
creating 2-421
marking 2-497
See also QoS, hierarchical policies
traffic classification
defining trust states 2-889
port, dual-capable
selecting the connector 2-376
Port Aggregation Protocol
port-based authentication
displaying debug messages 2-131
displaying statistics and status 2-552
enabling 802.1X 2-191
host modes 2-184
manual control of authorization state 2-191
periodic re-authentication
enabling 2-194
re-authenticating 802.1X-enabled ports 2-193
switch-to-client frame-retransmission number 2-190
port channel
accessing 2-221
creating 2-221
displaying information 2-713
load distribution method
resetting to defaults 2-423
setting 2-423
port-channel standalone-disable command 2-424
port control, changing from unidirectional or bidirectional 2-20
port-control value, configuring 2-31
port range
executing 2-222
port security
debugging ports security 2-147
deleting secure or specific addresses 2-113
displaying settings for an interface or switch 2-724
enabling 2-860
filter source IP and MAC addresses 2-278
setting action upon security violation 2-860
setting the rate limit for bad packets 2-860
sticky port 2-860
Port Trust Device
displaying 2-744
power efficient-ethernet auto command 2-429
power inline four-pair forced command 2-433
power inline logging global command 2-434
power negotiation through LLDP, enabling 2-319
power status
displaying inline power 2-730
displaying power status 2-730
power supply
configuring combined and redundant power on the Catalyst 4507R 2-425
configuring inline power 2-430
configuring power consumption 2-425
displaying the SEEPROM 2-567
setting inline power state 2-428
PPPoE Discovery
enable vendor-tag stripping on packetsPPPoE Server
enable vendor-tag stripping on Discovery packets 2-448
PPPoE Discovery packets, limit rate arriving on an interfsce 2-446
PPPoE Intermediate Agent
clear statistics (packet counters) 2-115
debugging 2-148
pppoe intermediate-agent
enable intermediate agent on a switch 2-439
enable on an interface VLAN range 2-441
enable PPPoE Intermediate Agent on an interface 2-440
enable vendor-tag stripping of Discovery packets 2-448
format-type (global) 2-442
limit rate of PPPoE Discovery packets 2-446
set circuit-id or remote-id for an interface 2-444
set circuit-id or remote-id for an interface VLAN range 2-445
set trust configuration on an interface 2-446, 2-447
PPPoE Intermediate Agent, display configuration and statistics (packet counters) 2-739
priority command 2-449
priority-queue command 2-123
Private VLAN
privileged EXEC mode, summary 1-5
prompts
system 1-5
protocol tunneling
configuring encapsulation rate 2-315
disabling 2-312
displaying port information 2-664
enabling 2-312
setting a CoS value for Layer 2 packets 2-313
setting a drop threshold for Layer 2 packets 2-314
PVLANs
configuring isolated, primary, and community PVLANs 2-451
controlling tagging of native VLAN traffic 2-875
disabling sticky-ARP 2-275
displaying map information for VLAN SVIs 2-585
displaying PVLAN information 2-786
enabling interface configuration mode 2-855
enabling sticky-ARP 2-275
mapping VLANs to the same SVI 2-455
specifying host ports 2-855
specifying promiscuous ports 2-855
PVST+
switching between PVST and MST 2-812
Q
QoS
account Layer 2 encapsulation 2-461
attaching a policy-map to an interface 2-488
automatic configuration 2-39, 2-43, 2-47, 2-51, 2-55, 2-59, 2-61
class maps
creating 2-87
defining the match criteria 2-367
clearing aggregate counters 2-116
configuring auto 2-59
defining a named aggregate policer 2-463
displaying aggregate policer information 2-742
displaying auto configuration 2-524
displaying class maps information 2-538
displaying configuration information 2-524
displaying configurations of policies 2-719
displaying policy map information 2-715, 2-722
displaying QoS information 2-741
displaying QoS map information 2-745
egress queue-sets
enabling the priority queue 2-123
enabling global configuration mode 2-51, 2-460
enabling per-VLAN QoS for a Layer 2 interface 2-465
hierarchical policies
average-rate traffic shaping on a class 2-508
bandwidth allocation for a class 2-67, 2-86
creating a service policy 2-491
marking 2-497
strict priority queueing (LLQ) 2-449
policy maps
creating 2-421
marking 2-497
trust states 2-889
setting the trust state 2-463
specifying flow-based match criteria 2-370
Supervisor Engine 6-E
setting CoS 2-499
setting DSCP 2-501
setting precedence values 2-504
setting QoS group identifiers 2-507
QoS CoS
configuring for tunneled Layer 2 protocol packets 2-313
quality of service
question command 1-1
queueing information
displaying 2-744
queue limiting
configuring packet limits 2-465
R
Rapid PVST
switching between PVST and MST 2-812
re-authenticating 802.1X-enabled ports 2-193
re-authentication
periodic 2-194
set the time 2-196
reauthentication, enabling 2-30
reboots
restoring bindings across 2-243
redundancy
accessing the main CPU 2-467
changing from active to standby supervisor engine 2-470
displaying information 2-747
displaying ISSU config-sync failure information 2-750
displaying redundancy facility information 2-747
displaying RF client list 2-747
displaying RF operational counters 2-747
displaying RF states 2-747
enabling automatic synchronization 2-66
forcing switchover to standby supervisor engine 2-470
mismatched command listing 2-468
set the mode 2-377
synchronizing the route processor configurations 2-365
related documentation 1-xxii
remote-id, setting for an interface 2-444
remote-id, setting for an interface VLAN range 2-445
remote SPAN
renew commands
ip dhcp snooping database 2-474
rep admin vlan command 2-475
rep block port command 2-476
rep lsl-age-timer command 2-479
rep preempt delay command 2-480
rep preempt segment command 2-481
rep segment command 2-482
rep stcn command 2-485
resetting PVLAN trunk
setting switchport to trunk 2-855
retry failed authentiation, configuring 2-23
rj45 connector, selecting the connector 2-376
ROM monitor mode
summary 1-6
Route Processor Redundancy
router, set to become ANCP client 2-16
RPF
disabling IPv4 exists-only checks 2-280
enabling IPv4 exists-only checks 2-280
RPR
set the redundancy mode 2-377
RSPAN
converting VLAN to RSPAN VLAN 2-473
displaying list 2-788
S
saving configuration changes 1-11
secure address, configuring 2-425
secure ports, limitations 2-861
server (AAA) alive actions, configuring 2-23
server (AAA) dead actions, configuring 2-23
service-policy command (policy-map class) 2-491
session classification, defining 2-26
set the redundancy mode 2-377
sfp connector, selecting the connector 2-376
shape command 2-508
shell trigger command 2-511, 2-755
show ancp multicast 2-516
show authentication interface command 2-518
show authentication registration command 2-518
show authentication sessions command 2-518
show capture command 2-702
show commands
filtering parameters 1-7
searching and filtering 1-6
show platform commands 1-11
show ipv6 snooping counters command 2-641
show ip wccp command 2-632
show ip wccp detail command 2-632
show ip wccp view command 2-632
show mab command 2-669
show mac address-table learning command 2-200, 2-680
show macro auto monitor device command 2-694, 2-695, 2-697
show monitor capture command 2-704, 2-706
show monitor capture file command 2-706
show nmsp command 2-710
show vlan group command 2-782
show vlan mapping command 2-784
Simple Network Management Protocol
single-character patterns
special characters 1-7
single-host, setting 2-26
slaveslot0
displaying information on the standby supervisor 2-758
slot0
displaying information about the system 2-760
SNMP
debugging spanning tree activities 2-151
ifIndex persistence
clearing SNMP ifIndex commands 2-793
compress SNMP ifIndex table format 2-798
disabling globally 2-797
disabling on an interface 2-794
enabling globally 2-797
enabling on an interface 2-794
informs
disabling 2-795
enabling 2-795
traps
configuring to send when storm occurs 2-835
disabling 2-795
enabling 2-795
mac-notification
adding 1
removing 1
SPAN commands
configuring a SPAN session to monitor 2-393
displaying SPAN session information 2-770, 2-837
SPAN enhancements
displaying status 2-702
Spanning Tree Protocol
SPAN session
displaying session information 2-702
filter ACLs 2-393
specify encap type 2-393
turn off host learning based on ingress packets 2-393
special characters
anchoring, table 1-10
SSO 2-377
standard desktop
enabling Cisco-recommended features 2-339
standard desktop and Cisco IP phone
enabling Cisco-recommended features 2-341
sticky address, configuring 2-426
sticky-ARP
disabling on PVLANs 2-275
enabling on PVLANs 2-275
sticky port
deleting 2-113
enabling security 2-860
storm control
configuring for action when storm occurs 2-835
disabling suppression mode 2-559
displaying settings 2-768
enabling 2-835
enabling broadcast 2-835, 2-837
enabling multicast 2-835, 2-837
enabling suppression mode 2-559
enabling timer to recover from error disable 2-206
multicast, enabling 2-837
setting high and low levels 2-835
setting suppression level 2-559
STP
configuring link type for a port 2-810
configuring tunneling encapsulation rate 2-315
debugging all activities 2-151
debugging spanning tree activities 2-151
debugging spanning tree BackboneFast events 2-153
debugging spanning tree UplinkFast 2-156
detecting misconfiguration 2-807
displaying active interfaces only 2-762
displaying BackboneFast status 2-762
displaying bridge status and configuration 2-762
displaying spanning tree debug messages 2-151
displaying summary of interface information 2-762
enabling BPDU filtering by default on all PortFast ports 2-824
enabling BPDU filtering on an interface 2-803
enabling BPDU guard by default on all PortFast ports 2-825
enabling BPDU guard on an interface 2-805
enabling extended system ID 2-808
enabling loop guard as a default on all ports 2-811
enabling PortFast by default on all access ports 2-826
enabling PortFast mode 2-822
enabling protocol tunneling for 2-312
enabling root guard 2-809
enabling spanning tree BackboneFast 2-802
enabling spanning tree on a per VLAN basis 2-830
enabling spanning tree UplinkFast 2-828
setting an interface priority 2-827
setting drop threshold for 2-314
setting pathcost 2-806
setting the default pathcost calculation method 2-821
subinterface configuration mode, summary 1-6
SVI
creating a Layer 3 interface on a VLAN 2-224
switching characteristics
excluding from link-up calculation 2-853
modifying 2-853
returning to interfaces
capture function 2-853
switchport 2-876
switchport interfaces
displaying status of Layer 3 port 2-588
displaying status of native VLAN tagging 2-588
switchport vlan mapping command 2-879
switch shim
debugging 2-154
disabling debugging 2-154
switch to router connection
enabling Cisco-recommended features 2-343
switch to switch connection
enabling Cisco-recommended features 2-345
switch virtual interface
sw-vlan 2-157
system prompts 1-5
T
Tab key
command completion 1-1
tables
characters with special meaning 1-7
mac access-list extended subcommands 2-327
multipliers 1-9
relationship between duplex and speed commands 2-833
show cable-diagnostics tdr command output fields 2-529
show cdp neighbors detail field descriptions 2-537
show cdp neighbors field descriptions 2-536
show ip dhcp snooping command output 2-519, 2-669
show ip interface field descriptions 2-619
show policy-map control-plane field descriptions 2-717
show vlan command output fields 2-787
show vtp command output fields 2-791
special characters 1-9
special characters used for anchoring 1-10
speed command options 2-370, 2-832
valid interface types 2-219
TAC
displaying information useful to TAC 2-771
TCAM
debugging spanning tree activities 2-151
TDR
displaying cable diagnostic test results 2-528
test condition of copper cables 2-882
temperature readings
displaying information 2-556
timer information 2-560
traffic monitor
display status 2-669
traffic shaping
enable on an interface 2-510
traps, enabling 2-795
trunk encapsulation
setting format 2-876
trunk interfaces
displaying trunk interfaces information 2-595
trunk port, configuring VLAN mapping 2-879
trunk ports, display VLAN mapping information 2-784
trust configuration, setting on an interface 2-446, 2-447
trust state
setting 2-232
tunnel ports
displaying information about Layer 2 protocol 2-664
TX queues
allocating bandwidth 2-891
returning to default values 2-891
setting priority to high 2-891
specifying burst size 2-891
specifying traffic rate 2-891
U
UDLD
displaying administrative and operational status 2-773
enabling by default on all fiber interfaces 2-893
enabling on an individual interface 2-895
preventing a fiber interface from being enabled 2-895
resetting all shutdown ports 2-897
setting the message timer 2-893
Unidirectional Link Detection
unidirection port control, changing from bidirectional 2-20
unknown multicast traffic, preventing 2-854
unknown unicast traffic, preventing 2-854
user EXEC mode, summary 1-5
username
setting password and privilege level 2-899
V
VACLs
access-group mode 2-6
applying VLAN access maps 2-911
displaying VLAN access map information 2-779
specifying an action in a VLAN access map 2-12
specifying the match clause for a VLAN access-map sequence 2-366
using a VLAN filter 2-911
VLAN
applying an ARP ACL 2-226
configuring 2-902
configuring service policies 2-906
converting to RSPAN VLAN 2-473
displaying CEF information 2-601
displaying CEF next-hop information 2-601
displaying information on switch interfaces 2-610, 2-614
displaying information on VLAN switch interfaces 2-617
displaying information sorted by group IP address 2-610, 2-614
displaying IP address and version information 2-610, 2-614
displaying Layer 2 VLAN information 2-776
displaying statistical information 2-700
displaying VLAN information 2-777
enabling dynamic ARP inspection 2-235
enabling Explicit Host Tracking 2-265
enabling guest per-port 2-183
enabling guest VLAN supplicant 2-176, 2-184
entering VLAN configuration mode 2-906, 2-908
native frames
enabling tagging on all 802.1Q trunk ports 2-910
pruning the list for VTP 2-876
setting the list of allowed 2-876
VLAN, create or modify a group 2-912
VLAN Access Control Lists
VLAN access map
VLAN database
resetting 2-486
VLAN debugging
limiting output 2-129
vlan group command 2-912
VLAN groups, display VLANs mapped 2-782
VLAN link-up calculation
excluding a switch port 2-853
including a switch port 2-853
VLAN manager
debugging 2-157
disabling debugging 2-157
IOS file system error tests
debugging 2-158
disabling debugging 2-158
VLAN mapping
configuring 2-879
displaying 2-784
VLAN mapping, configure on trunk port 2-879
VLAN mapping on trunk ports, display information 2-784
VLAN Query Protocol
VLAN query protocol (VQPC)
debugging 2-164
VLANs
clearing
counters 2-117
clearing hardware logic 2-93
configuring
internal allocation scheme 2-913
displaying
internal VLAN allocation information 2-783
RSPAN VLANs 2-788
entering VLAN configuration mode 2-908
VMPS
configuring servers 2-917
reconfirming dynamic VLAN assignments 2-164, 2-915
voice VLANs
enabling 2-849
VoIP
configuring auto-QoS 2-59
VQP
per-server retry count 2-916
reconfirming dynamic VLAN assignments 2-164, 2-915
VTP
configuring the administrative domain name 2-921
configuring the device in VTP client mode 2-920
configuring the device in VTP server mode 2-924
configuring the device in VTP transparent mode 2-925
configuring tunnel encapsulation rate 2-315
creating a VTP domain password 2-922
displaying domain information 2-790
displaying statistics information 2-790
enabling protocol tunneling for 2-312
enabling pruning in the VLAN database 2-923
enabling VTP version 2 mode 2-926
modifying the VTP configuration storage file name 2-919
set drop threshold for 2-314
VTP protocol code
activating debug messages 2-161
deactivating debug messages 2-161
W
Webauth fallback, enabling 2-25