Index
Symbols
$ matches the end of a string 1-7
( ) in commands 1-11
* matches 0 or more sequences of a pattern 1-7
+ matches 1 or more sequences of a pattern 1-7
. matches any single character 1-7
? command 1-1
? matches 0 or 1 occurrence of a pattern 1-7
^ matches the beginning of a string 1-7
_ matches a comma (,), left brace ({), left parenthesis 1-7
" 1-10
Numerics
10-Gigabit Ethernet uplink
showing the mode 2-567
802.1Q trunk ports and native VLANs 2-910
802.1Q tunnel ports
configuring 2-855
802.1S Multiple Spanning Tree
802.1X
configuring for multiple hosts 2-184
configuring for single host 2-184
configuring multiple domains 2-184
disabling port control 2-177
enabling port control 2-177
802.1X Critical Authentication
disabling on a port 2-179
disabling on a VLAN 2-182
EAPOL
disabling send success packets 2-180
enabling send success packets 2-180
enabling on a port 2-179
enabling on a VLAN 2-182
returning delay time to default setting 2-181
setting delay time on a port 2-181
802.1X critical authentication
configure parameters 2-22
802.1X critical recovery delay, configuring 2-22
802.1X Port Based Authentication
debugging 802.1X Port Based Authentication 2-131
displaying port based authentication 2-552
enabling accounting for authentication sessions 2-4
enabling authentication on the system 2-195
enabling guest VLAN 2-183
enabling guest VLAN supplicant 2-176, 2-184
enabling manual control of auth state 2-191
enabling periodic re-authentication of the client 2-194
initializing re-authentication of dot1x ports 2-193
initializing state machines 2-187
receive session termination message upon reboot 2-5
setting maximum number for EAP requests 2-190
setting the reauthentication timer 2-196
A
aaa authorization network command 2-178
abbreviating commands
context-sensitive help 1-1
Access Gateway Module
connecting to a module 2-19
connecting to a remote module 2-472
connecting to a specific remote module 2-495
access-group
displaying mac interface 2-671
show mode interface 2-440, 2-513, 2-741
access groups
access lists
clearing an access template 2-94
defining ARP 2-18
displaying ARP information 2-517
See also ACLs, MAC ACLs, and VACLs
access maps
applying with VLAN filter 2-911
access-node-identifier, setting for the switch 2-442
access-policies, applying using host-mode 2-26
ACLs
access-group mode 2-6
balancing hardware regions 2-11
capturing control packets 2-8
determining ACL hardware programming 2-9
disabling hardware statistics 2-212
displaying mac access-group interface 2-671
enabling hardware statisctics 2-212
using ACL naming conventions for MAC ACLs 2-327
action clause
specifying drop or forward action in a VACL 2-12
addresses, configuring a maximum 2-427
adjacency
debugging the adjacency table 2-124
disabling the debug facility 2-124
displaying information about the adjacency table 2-514
displaying IPC table entries 2-124
aggregate policer
displaying information 2-742
aging time
displaying MAC address aging time 2-674
MAC address table 2-330
alarms
displaying operational status 2-556
alternation
description 1-10
anchoring
description 1-10
ancp, show multicast 2-516
ANCP client
port identifier 2-14
remote server 2-15
set router to become 2-16
ARP
access list, displaying detailed information 2-517
defining access-lists 2-18
ARP inspection
enforce certain types of checking 2-233
ARP packet
deny based on DHCP bindings 2-166
permit based on DHCP bindings 2-407
changing the control-direction 2-20
configure actions for events
configuring the actions 2-23
configuring port-control 2-31
enabling reauthentication 2-30
enabling Webauth fallback 2-25
host-mode configuration 2-26
setting priority of methods 2-33
setting the timer 2-35
setting username 2-899
specifying the order of methods 2-29
using an MD5-type encryption method 2-899
verifying MD5 signature 2-900
verifying the checksum for Flash memory 2-900
authentication control-direction command 2-20
authentication critical recovery delay command 2-22
authentication event command 2-23
authentication fallback command 2-25
authentication host-mode 2-26
authentication methods, setting priority 2-33
authentication methods, specifying the order of attempts 2-29
authentication open command 2-28
authentication order command 2-29
authentication periodic command 2-30
authentication port-control command 2-31
authentication priority command 2-33
authentication timer, setting 2-35
authentication timer command 2-35
authentication violation command 2-37
auth fail VLAN
enable on a port 2-176
set max number of attempts 2-175
Auth Manager
configuring
authentication timer 2-35
authorization state
enabling manual control 2-191
authorization state of a controlled port 2-191
automatic installation
displaying status 2-523
automatic medium-dependent interface crossover
Auto-MDIX
disabling 2-374
enabling 2-374
auto-negotiate interface speed
example 2-834
auto-QoS
configuring for VoIP 2-59
displaying configuration 2-524
auto qos srnd4 command 2-47
B
baby giants
displaying the system MTU setting 2-770
setting the maximum Layer 2 payload size 2-881
BackboneFast
displaying debugging messages 2-153
displaying spanning tree status 2-762
enabling debugging 2-153
bandwidth command 2-67
bindings
store for DHCP snooping 2-244
BOOT environment variable
displaying information 2-527
bootflash
displaying information 2-525
BPDUs
debugging spanning tree activities 2-151
bridge protocol data units
broadcast suppression level
C
cable diagnostics
TDR
displaying test results 2-528
testing conditions of copper cables 2-882
call home
displaying information 2-530
e-mailing output 2-75
entering configuration submode 2-70
executing 2-75
manually send test message 2-78
receiving information 2-73
sending alert group message 2-76
submitting information 2-73
call home destination profiles
displaying 2-532
Catalyst 4507R 2-425
CDP
configuring tunneling encapsulation rate 2-315
displaying
neighbor information 2-535
enabling protocol tunneling for 2-312
set drop threshold for 2-314
CEF
displaying next-hop information 2-601
displaying VLAN configuration information 2-601
chassis
displaying
chassis MAC address ranges 2-669
current and peak traffic meter readings 2-669
percentage of backplane utilization 2-669
switching clock failure recovery mode 2-669
circuit-id
setting for an interface 2-444
circuit-id, setting for an interface VLAN range 2-445
cisco-desktop
macro apply 2-339
Cisco Express Forwarding
cisco-phone
macro apply 2-341
cisco-router
macro apply 2-343
cisco-switch
macro apply 2-345
CISP
See Client Information Signalling Protocol
cisp enable command 2-83
class maps
creating 2-87
defining the match criteria 2-367
monitor capture 2-380
clear commands
clearing Gigabit Ethernet interfaces 2-92
clearing IGMP group cache entries 2-101
clearing interface counters 2-89
clearing IP access lists 2-94, 2-95
clearing IP ARP inspection statistics VLAN 2-96
clearing IP DHCP snooping database statistics 2-100
clearing MFIB counters and routes 2-104
clearing MFIB fastdrop entries 2-105
clearing PAgP channel information 2-112
clearing QoS aggregate counters 2-116
clearing VLAN interfaces 2-93
clear ip wccp command 2-106
clear nmsp statistics command 2-111
Client Information Signalling Protocol 2-178
Client Information Signalling Protocol, enabling 2-83
CLI string search
anchoring 1-10
expressions 1-7
filtering 1-6
multiple-character patterns 1-8
multipliers 1-9
parentheses for recall 1-11
searching outputs 1-6
single-character patterns 1-7
using 1-6
command 2-380
command modes
accessing privileged EXEC mode 1-5
exiting 1-5
understanding user EXEC and configuration modes 1-5
condition interface
debugging interface-related activities 2-126
condition vlan
debugging VLAN output 2-129
configuration, saving 1-11
configuring
root as secondary 2-820
configuring a SPAN session to monitor
limit SPAN source traffic 2-393
configuring critical recovery 2-22
configuring forward delay 2-816
configuring root as primary 2-820
CoPP
attaching
policy map to control plane 2-493
displaying
policy-map class information 2-716
entering configuration mode 2-119
removing
service policy from control plane 2-493
CoS
assigning to Layer 2 protocol packets 2-313
counter command 2-121
counters
clearing interface counters 2-89
critical authentication, configure 802.1X parameters 2-22
critical recovery, configuring 802.1X parameter 2-22
D
DAI
clear statistics 2-96
DBL
displaying qos dbl 2-743
debug commands
debugging backup events 2-125
debugging DHCP snooping events 2-136
debugging DHCP snooping messages 2-137
debugging EtherChannel/PAgP/shim 2-132
debugging IPC activity 2-135
debugging IP DHCP snooping security messages 2-138
debugging NVRAM activities 2-142
debugging PAgP activities 2-143
debugging port manager activities 2-146
debugging spanning tree activities 2-151
debugging spanning tree backbonefast 2-153
debugging spanning tree UplinkFast 2-156
debugging supervisor redundancy 2-150
debugging VLAN manager activities 2-157
displaying monitor activity 2-140
displaying the adjacency table 2-124
enabling debug dot1x 2-131
enabling debugging messages for ISL VLAN IDs 2-160
enabling debugging messages for VTP 2-161
enabling debugging of UDLD activity 2-162
enabling switch shim debugging 2-154
enabling VLAN manager file system error tests 2-158
limiting debugging output for VLANs 2-129
limiting interface debugging output 2-126
limiting output for debugging standby state changes 2-127
shortcut to the debug condition interface 2-134
debugging
activity monitoring 2-140
DHCP snooping events 2-136
DHCP snooping packets 2-137
IPC activities 2-135
IP DHCP snooping security packets 2-138
NVRAM activities 2-142
PAgP activities 2-143
PAgP shim 2-132
PM activities 2-146
PPPoE Intermediate Agent 2-148
spanning tree BackboneFast events 2-153
spanning tree switch shim 2-154
spanning tree UplinkFast events 2-156
VLAN manager activities 2-157
VLAN manager IOS file system error tests 2-158
VTP protocol debug messages 2-161
debug nmsp command 2-141
debug spanning tree switch 2-154
debug sw-vlan vtp 2-161
default form of a command, using 1-6
DHCP
clearing database statistics 2-100
DHCP bindings
configuring bindings 2-243
deny ARP packet based on matches 2-166
permit ARP packet based on matches 2-407
DHCP snooping
clearing binding entries 2-97
clearing database 2-99
displaying binding table 2-603
displaying configuration information 2-602
displaying status of DHCP database 2-606
displaying status of error detection 2-559
enabling DHCP globally 2-242
enabling IP source guard 2-278
enabling on a VLAN 2-251
enabling option 82 2-246, 2-248
enabling option-82 2-253
enabling rate limiting on an interface 2-249
enabling trust on an interface 2-250
establishing binding configuration 2-243
renew binding database 2-474
store generated bindings 2-244
diagnostic fpga soft-error recover command 2-172
diagnostic test
bootup packet memory 2-546
displaying attributes 2-540
display module-based results 2-542
running 2-174
show results for TDR 2-528
testing conditions of copper cables 2-882
displaying error disable recovery 2-560
displaying inline power status 2-730
displaying monitoring activity 2-140
displaying PoE policing and monitoring status 2-738
displaying SEEPROM information
GBIC 2-567
displaying SPAN session information 2-770, 2-837
document conventions 1-xxii
document organization 1-xxi
DoS
CoPP
attaching policy map to control plane 2-493
displaying policy-map class information 2-716
entering configuration mode 2-119
removing service policy from control plane 2-493
entering
CoPP configuration mode 2-119
DOS attack
protecting system's resources 2-228
dot1x credentials (global configuration) command 2-178
drop threshold, Layer 2 protocol tunneling 2-314
DSCP rewrite for IP packets
enable 2-463
dual-capable port
selecting a connector 2-376
duplex mode
configuring autonegotiation on an interface 2-198
configuring full duplex on an interface 2-198
configuring half duplex on an interface 2-198
dynamic ARP inspection
preventing 2-228
Dynamic Host Configuration Protocol
E
EAP
restarting authentication process 2-190
EIGRP (Enhanced IGRP)
filters
routing updates, preventing 2-404
enabling
debugging for UDLD 2-162
voice VLANs 2-849
enabling open access 2-28
environmental
alarms 2-556
displaying information 2-556
status 2-556
temperature 2-556
epm access control command 2-200
erase a file 2-201
error disable detection
clearing error disable on an interface 2-90
enabling error disable detection 2-90, 2-204
enabling per-VLAN on BPDU guard 2-204
error-disabled state
displaying 2-586
error disable recovery
configuring recovery mechanism variables 2-206
displaying recovery timer information 2-560
enabling ARP inspection timeout 2-206
specifying recovery cause 2-206
EtherChannel
assigning interfaces to EtherChannel groups 2-79
debugging EtherChannel 2-132
debugging PAgP shim 2-132
debugging spanning tree activities 2-151
displaying information for a channel 2-561
removing interfaces from EtherChannel groups 2-79
EtherChannel guard
detecting STP misconfiguration 2-807
Explicit Host Tracking
clearing the database 2-103
enabling per-VLAN 2-265
expressions
matching multiple expression occurrences 1-9
multiple-character patterns 1-8
multiplying pattern occurrence 1-11
single-character patterns 1-7
Extensible Authentication Protocol
F
fallback profile, specifying 2-25
field replaceable unit (FRU)
displaying status information 2-556
filters
EIGRP
routing updates, preventing 2-404
Flash memory file system
displaying file system information 2-525
verifying checksum 2-900
flow control
configuring a gigabit interface for pause frames 2-209
displaying per-interface statistics for flow control 2-565
G
GBIC
displaying SEEPROM information 2-567
generic-error-message, setting for the switch 2-442
Gigabit Ethernet interface
clearing the hardware logic 2-92
Gigabit Ethernet uplink
showing the mode 2-567
global configuration mode
using 1-5
H
hardware module
resetting a module by toggling the power 2-214
hardware statistics
disabling 2-212
enabling 2-212
hardware uplink
showing the mode 2-567
helper addresses, IP 2-619
hot standby protocol
debugging 2-127
disabling debugging 2-127
limiting output 2-127
hw-module beacon command 2-213
I
identifier-string, setting for the switch 2-442
ID mapping, creating an ANCP client 2-14
IDPROMs
displaying SEEPROM information
chassis 2-567
clock module 2-567
fan trays 2-567
module 2-567
mux buffer 2-567
power supplies 2-567
supervisor engine 2-567
ifIndex persistence
clearing SNMP ifIndex commands 2-793
compress SNMP ifIndex table format 2-798
disabling globally 2-797
disabling on an interface 2-794
enabling globally 2-797
enabling on an interface 2-794
IGMP
applying filters for host joining on Layer 2 interfaces 2-255
clearing IGMP group cache entries 2-101
configuring frequency for IGMP host-query messages 2-258
creating an IGMP profile 2-257
displaying IGMP interface configuration information 2-608
displaying profiles 2-609
setting maximum group numbers 2-256
IGMP profiles
displaying 2-609
IGMP snooping
clearing the EHT database 2-103
configuring a Layer 2 interface as a group member 2-269
configuring a Layer 2 interface as a multicast router 2-267
configuring a static VLAN interface 2-269
displaying multicast information 2-616
displaying VLAN information 2-610, 2-614, 2-617
enabling 2-260
enabling immediate-leave processing 2-266
enabling on a VLAN 2-264
enabling per-VLAN Explicit Host Tracking 2-265
informs
enabling 2-795
inline power
displaying inline power status 2-730
In Service Software Upgrade
inspection log
clearing log buffer 2-95
interface
displaying suppressed multicast bytes 2-580
interface capabilities
displaying 2-576
interface configuration mode
summary 1-5
interface link
display cable disconnect time 2-583
interfaces
configuring dot1q tunnel ports 2-855
creating an interface-range macro 2-165
debugging output of interface related activities 2-126
displaying description 2-582
displaying error-disabled state 2-586
displaying information when tunneling is enabled 2-664
displaying status 2-582
displaying traffic for a specific interface 2-573
entering interface configuration mode 2-219
executing a command on multiple ports in a range 2-222
selecting an interface to configure 2-219
setting a CoS value for Layer 2 packets 2-313
setting drop threshold for Layer 2 packets 2-314
setting the interface type 2-855
interface speed
configuring interface speed 2-832
interface transceiver
displaying diagnostic data 2-590
internal VLAN allocation
configuring 2-913
default setting 2-913
displaying allocation information 2-783
Internet Group Management Protocol
IP address of remote ANCP server, setting 2-15
IP ARP
applying ARP ACL to VLAN 2-226
clearing inspection statistics 2-96
clearing status of log buffer 2-95
controlling packet logging 2-237
enabling dynamic inspection 2-235
limit rate of incoming requests 2-228
set per-port config trust state 2-232
showing status of dynamic ARP inspection 2-597
showing status of log buffer 2-600
IPC
debugging IPC activities 2-135
IP DHCP Snooping
IP header validation
disabling 2-277
enabling 2-277
IP interfaces
displaying usability status 2-618
IP multicast
displaying multicast routing table information 2-624
ip multicast multipath command 2-272
IP packets
enable DSCP rewrite 2-463
IP phone and standard desktop
enabling Cisco-recommended features 2-341
IP Port Security
enabling 2-278
IP source binding
adding or deleting 2-274
displaying bindingstagging 2-629
IP source guard
debugging messages 2-138
displaying configuration and filters 2-630
enabling on DHCP snooping 2-278
IPv4 statistics, enabling collection 2-121
IPv6 MLD
configuring queries 2-293, 2-295
configuring snooping last-listener-query-intervals 2-295
configuring snooping listener-message-suppression 2-297
configuring snooping robustness-variables 2-298
configuring tcn topology change notifications 2-300
counting snooping last-listener-queries 2-293
displaying information 2-642
displaying ports for a switch or VLAN 2-644
displaying querier information 2-645
enabling snooping 2-291
enabling snooping on a VLAN 2-301
IPv6 statistics, enabling collection 2-121
ip wccp check services all command 2-284
ip wccp command 2-281
ip wccp group-address command 2-281
ip wccp group-list command 2-281
ip wccp group-listen command 2-286
ip wccp password command 2-281, 2-282
ip wccp redirect command 2-288
ip wccp redirect exclude in command 2-290
ip wccp redirect-list command 2-281
ISSU
canceling process 2-303
configuring rollback timer 2-311
displaying capability 2-647
displaying client information 2-649
displaying compatibility matrix 2-651
displaying endpoint information 2-655
displaying entities 2-656
displaying FSM session 2-657
displaying messages 2-658
displaying negotiated 2-659
displaying rollback-timer 2-660
displaying session information 2-661
displaying software version 2-662
displaying state 2-662
forcing switchover to standby supervisor engine 2-310
loading new image 2-306
starting process 2-308
stopping rollback timer 2-304
J
Jumbo frames
enabling jumbo frames 2-398
L
LACP
deselecting channeling protocol 2-81
enabling LACP on an interface 2-81
setting channeling protocol 2-81
lacp port-priority command 2-317
lacp system-priority command 2-318
Layer 2
displaying ACL configuration 2-671
Layer 2 interface type
specifying a nontrunking, nontagged single VLAN interface 2-855
specifying a trunking VLAN interface 2-855
Layer 2 protocol ports
displaying 2-664
Layer 2 protocol tunneling error recovery 2-315
Layer 2 switching
enabling voice VLANs 2-849
modifying switching characteristics 2-849
Layer 2 traceroute
IP addresses 2-887
Layer 3 interface, assign counters 2-121
Layer 3 switching
displaying information about an adjacency table 2-514
displaying port status 2-588
displaying status of native VLAN tagging 2-588
link-status event messages
disabling
enabling
LLDP
enabling power negotiation 2-319
lldp tlv-select power-management command 2-319
log buffer
show status 2-600
logging
controlling IP ARP packets 2-237
M
MAB, display information 2-669
MAB, enable and configure 2-326
mab command 2-326
MAC Access Control Lists
MAC ACLs
defining extended MAC access list 2-327
displaying MAC ACL information 2-779
naming an ACL 2-327
MAC addresses
disabling MAC address learning per VLAN 2-334
displaying
notification settings 2-200, 2-641, 2-680
MAC address filtering
configuring 2-338
disabling 2-338
enabling 2-338
MAC address learning on a VLAN, enabling 2-334
MAC address table
adding static entries 2-365
clearing dynamic entries 2-108, 2-110
configuring aging time 2-330
displaying dynamic table entry information 2-676
displaying entry count 2-675
displaying information 2-672
displaying interface-based information 2-678
displaying multicast information 2-681
displaying notification information 2-683
displaying protocol-based information 2-685
displaying static table entry information 2-687
displaying the MAC address aging time 2-674
displaying VLAN-based information 2-689
enabling authentication bypass 2-188
enabling notifications 2-336
learning in the protocol buckets 2-331
removing static entries 2-365
mac address-table learning vlan command 2-334
MAC address tables
adding static entries 2-338
deleting secure or specific addresses 2-113
disabling IGMP snooping on static MAC addresses 2-338
removing static entries 2-338
mac-address-table static 2-338
MAC address unicast filtering
dropping unicast traffic 2-338
MAC authentication bypass (MAB), display information 2-669
MAC authorization bypass(MAB), enable and configure 2-326
macro
displaying descriptions 2-364
macro auto global processing command 2-347, 2-349, 2-352, 2-353, 2-355, 2-357, 2-359, 2-361, 2-691
macro auto monitor command 2-358
macro keywords
help strings 2-2
macros
adding a global description 2-364
cisco global 2-362
system-cpp 2-363
mapping secondary VLANs to MST instance 2-457
mapping VLAN(s) to an MST instance 2-216
match (class-map configuration) command 2-13, 2-168, 2-169, 2-170, 2-171, 2-367, 2-838, 2-839, 2-841, 2-843, 2-847
maximum transmission unit (MTU)
displaying the system MTU setting 2-770
setting the maximum Layer 2 payload size 2-881
MD5
verifying MD5 signature 2-900
message digest 5
MFIB
clearing ip mfib counters 2-104
clearing ip mfib fastdrop 2-105
displaying all active MFIB routes 2-621
displaying MFIB fastdrop table entries 2-623
enabling IP MFIB fastdrops 2-271
MLD
configuring snooping last-listener-query-intervals 2-295
configuring snooping listener-message-suppression 2-297
configuring snooping robustness-variables 2-298
configuring topology change notifications 2-300
counting snooping last-listener-queries 2-293
enabling snooping 2-291
enabling snooping on a VLAN 2-301
MLD snooping
displaying 2-645
modes
access-group 2-6
show access-group interface 2-440, 2-513, 2-741
switching between PVST+, MST, and Rapid PVST 2-812
module password clearing 2-91
module reset
resetting a module by toggling the power 2-214
monitor capture {access-list | class-map} command 2-379
monitor capture mycap match command 2-386
monitor capture start command 2-388
--More-- prompt
filter 1-6
search 1-7
MST
designating the primary and secondary root 2-820
displaying MST protocol information 2-766
displaying region configuration information 2-766
displaying spanning tree information 2-766
entering MST configuration submode 2-814
setting configuration revision number 2-487
setting path cost and port priority for instances 2-813
setting the forward delay timer for all instances 2-816
setting the hello-time delay timer for all instances 2-817
setting the max-age timer for all instances 2-818
setting the MST region name 2-399
specifying the maximum number of hops 2-819
switching between PVST+ and Rapid PVST 2-812
using the MST configuration submode revision command 2-487
using the submode name command 2-399
MTU
displaying global MTU settings 2-770
multi-auth, setting 2-26
Multicase Listener Discovery
multicast
enabling storm control 2-837
show ancp 2-516
multicast/unicast packets
prevent forwarding 2-854
Multicast Forwarding Information Base
multi-domain, setting 2-26
multiple-character patterns 1-8
Multiple Spanning Tree
N
native VLAN
controlling tagging of traffic 2-875
displaying ports eligible for native tagging 2-781
displaying ports eligible for tagging 2-781
enabling tagging on 802.1Q trunk ports 2-910
specifing the tagging of traffic 2-876
NetFlow
enabling NetFlow statistics 2-274
including infer fields in routing statistics 2-274
next-hop
displaying CEF VLAN information 2-601
nmsp attachment suppress command 2-401
nmsp command 2-400
no form of a command, using 1-6
NVRAM
debugging NVRAM activities 2-142
O
open access on a port, enabling 2-28
output
pattern searches 1-7
P
packet counters (statistics)
clear for PPPoE Intermediate Agent 2-115
packet counters, display for PPPoE Intermediate Agent 2-739
packet forwarding
prevent unknown packets 2-854
packet memory failure
direct switch action upon detection 2-173
packet memory test
bootup, displaying results 2-546, 2-548
ongoing, displaying results 2-550
PACL
access-group mode 2-6
paging prompt
PAgP
clearing port channel information 2-112
debugging PAgP activity 2-143
deselecting channeling protocol 2-81
displaying port channel information 2-713
hot standby mode
returning to defaults 2-403
selecting ports 2-403
input interface of incoming packets
learning 2-402
returning to defaults 2-402
setting channeling protocol 2-81
parentheses 1-11
password
clearing on an intelligent line module 2-91
establishing enhanced password security 2-899
setting username 2-899
PBR
redistributing route maps 1-xxii
PM activities
debugging 2-146
disabling debugging 2-146
PoE policing
configure on an interface 2-435
PoE policing and monitoring
displaying status 2-738
police (percent) command 2-413
police (two rates) command 2-415, 2-417
police command 2-409
policing, configure PoE 2-435
policing and monitoring status
displaying PoE 2-738
Policy Based Routing
policy maps
creating 2-421
marking 2-497
See also QoS, hierarchical policies
traffic classification
defining trust states 2-889
port, dual-capable
selecting the connector 2-376
Port Aggregation Protocol
port-based authentication
displaying debug messages 2-131
displaying statistics and status 2-552
enabling 802.1X 2-191
host modes 2-184
manual control of authorization state 2-191
periodic re-authentication
enabling 2-194
re-authenticating 802.1X-enabled ports 2-193
switch-to-client frame-retransmission number 2-190
port channel
accessing 2-221
creating 2-221
displaying information 2-713
load distribution method
resetting to defaults 2-423
setting 2-423
port-channel standalone-disable command 2-424
port control, changing from unidirectional or bidirectional 2-20
port-control value, configuring 2-31
port range
executing 2-222
port security
debugging ports security 2-147
deleting secure or specific addresses 2-113
displaying settings for an interface or switch 2-724
enabling 2-860
filter source IP and MAC addresses 2-278
setting action upon security violation 2-860
setting the rate limit for bad packets 2-860
sticky port 2-860
Port Trust Device
displaying 2-744
power efficient-ethernet auto command 2-429
power inline four-pair forced command 2-433
power inline logging global command 2-434
power negotiation through LLDP, enabling 2-319
power status
displaying inline power 2-730
displaying power status 2-730
power supply
configuring combined and redundant power on the Catalyst 4507R 2-425
configuring inline power 2-430
configuring power consumption 2-425
displaying the SEEPROM 2-567
setting inline power state 2-428
PPPoE Discovery
enable vendor-tag stripping on packetsPPPoE Server
enable vendor-tag stripping on Discovery packets 2-448
PPPoE Discovery packets, limit rate arriving on an interfsce 2-446
PPPoE Intermediate Agent
clear statistics (packet counters) 2-115
debugging 2-148
pppoe intermediate-agent
enable intermediate agent on a switch 2-439
enable on an interface VLAN range 2-441
enable PPPoE Intermediate Agent on an interface 2-440
enable vendor-tag stripping of Discovery packets 2-448
format-type (global) 2-442
limit rate of PPPoE Discovery packets 2-446
set circuit-id or remote-id for an interface 2-444
set circuit-id or remote-id for an interface VLAN range 2-445
set trust configuration on an interface 2-446, 2-447
PPPoE Intermediate Agent, display configuration and statistics (packet counters) 2-739
priority command 2-449
priority-queue command 2-123
Private VLAN
privileged EXEC mode, summary 1-5
prompts
system 1-5
protocol tunneling
configuring encapsulation rate 2-315
disabling 2-312
displaying port information 2-664
enabling 2-312
setting a CoS value for Layer 2 packets 2-313
setting a drop threshold for Layer 2 packets 2-314
PVLANs
configuring isolated, primary, and community PVLANs 2-451
controlling tagging of native VLAN traffic 2-875
disabling sticky-ARP 2-275
displaying map information for VLAN SVIs 2-585
displaying PVLAN information 2-786
enabling interface configuration mode 2-855
enabling sticky-ARP 2-275
mapping VLANs to the same SVI 2-455
specifying host ports 2-855
specifying promiscuous ports 2-855
PVST+
switching between PVST and MST 2-812
Q
QoS
account Layer 2 encapsulation 2-461
attaching a policy-map to an interface 2-488
automatic configuration 2-39, 2-43, 2-47, 2-51, 2-55, 2-59, 2-61
class maps
creating 2-87
defining the match criteria 2-367
clearing aggregate counters 2-116
configuring auto 2-59
defining a named aggregate policer 2-463
displaying aggregate policer information 2-742
displaying auto configuration 2-524
displaying class maps information 2-538
displaying configuration information 2-524
displaying configurations of policies 2-719
displaying policy map information 2-715, 2-722
displaying QoS information 2-741
displaying QoS map information 2-745
egress queue-sets
enabling the priority queue 2-123
enabling global configuration mode 2-51, 2-460
enabling per-VLAN QoS for a Layer 2 interface 2-465
hierarchical policies
average-rate traffic shaping on a class 2-508
bandwidth allocation for a class 2-67, 2-86
creating a service policy 2-491
marking 2-497
strict priority queueing (LLQ) 2-449
policy maps
creating 2-421
marking 2-497
trust states 2-889
setting the trust state 2-463
specifying flow-based match criteria 2-370
Supervisor Engine 6-E
setting CoS 2-499
setting DSCP 2-501
setting precedence values 2-504
setting QoS group identifiers 2-507
QoS CoS
configuring for tunneled Layer 2 protocol packets 2-313
quality of service
question command 1-1
queueing information
displaying 2-744
queue limiting
configuring packet limits 2-465
R
Rapid PVST
switching between PVST and MST 2-812
re-authenticating 802.1X-enabled ports 2-193
re-authentication
periodic 2-194
set the time 2-196
reauthentication, enabling 2-30
reboots
restoring bindings across 2-243
redundancy
accessing the main CPU 2-467
changing from active to standby supervisor engine 2-470
displaying information 2-747
displaying ISSU config-sync failure information 2-750
displaying redundancy facility information 2-747
displaying RF client list 2-747
displaying RF operational counters 2-747
displaying RF states 2-747
enabling automatic synchronization 2-66
forcing switchover to standby supervisor engine 2-470
mismatched command listing 2-468
set the mode 2-377
synchronizing the route processor configurations 2-365
related documentation 1-xxii
remote-id, setting for an interface 2-444
remote-id, setting for an interface VLAN range 2-445
remote SPAN
renew commands
ip dhcp snooping database 2-474
rep admin vlan command 2-475
rep block port command 2-476
rep lsl-age-timer command 2-479
rep preempt delay command 2-480
rep preempt segment command 2-481
rep segment command 2-482
rep stcn command 2-485
resetting PVLAN trunk
setting switchport to trunk 2-855
retry failed authentiation, configuring 2-23
rj45 connector, selecting the connector 2-376
ROM monitor mode
summary 1-6
Route Processor Redundancy
router, set to become ANCP client 2-16
RPF
disabling IPv4 exists-only checks 2-280
enabling IPv4 exists-only checks 2-280
RPR
set the redundancy mode 2-377
RSPAN
converting VLAN to RSPAN VLAN 2-473
displaying list 2-788
S
saving configuration changes 1-11
secure address, configuring 2-425
secure ports, limitations 2-861
server (AAA) alive actions, configuring 2-23
server (AAA) dead actions, configuring 2-23
service-policy command (policy-map class) 2-491
session classification, defining 2-26
set the redundancy mode 2-377
sfp connector, selecting the connector 2-376
shape command 2-508
shell trigger command 2-511, 2-755
show ancp multicast 2-516
show authentication interface command 2-518
show authentication registration command 2-518
show authentication sessions command 2-518
show capture command 2-702
show commands
filtering parameters 1-7
searching and filtering 1-6
show platform commands 1-11
show ipv6 snooping counters command 2-641
show ip wccp command 2-632
show ip wccp detail command 2-632
show ip wccp view command 2-632
show mab command 2-669
show mac address-table learning command 2-200, 2-680
show macro auto monitor device command 2-694, 2-695, 2-697
show monitor capture command 2-704, 2-706
show monitor capture file command 2-706
show nmsp command 2-710
show vlan group command 2-782
show vlan mapping command 2-784
Simple Network Management Protocol
single-character patterns
special characters 1-7
single-host, setting 2-26
slaveslot0
displaying information on the standby supervisor 2-758
slot0
displaying information about the system 2-760
SNMP
debugging spanning tree activities 2-151
ifIndex persistence
clearing SNMP ifIndex commands 2-793
compress SNMP ifIndex table format 2-798
disabling globally 2-797
disabling on an interface 2-794
enabling globally 2-797
enabling on an interface 2-794
informs
disabling 2-795
enabling 2-795
traps
configuring to send when storm occurs 2-835
disabling 2-795
enabling 2-795
mac-notification
adding 1
removing 1
SPAN commands
configuring a SPAN session to monitor 2-393
displaying SPAN session information 2-770, 2-837
SPAN enhancements
displaying status 2-702
Spanning Tree Protocol
SPAN session
displaying session information 2-702
filter ACLs 2-393
specify encap type 2-393
turn off host learning based on ingress packets 2-393
special characters
anchoring, table 1-10
SSO 2-377
standard desktop
enabling Cisco-recommended features 2-339
standard desktop and Cisco IP phone
enabling Cisco-recommended features 2-341
sticky address, configuring 2-426
sticky-ARP
disabling on PVLANs 2-275
enabling on PVLANs 2-275
sticky port
deleting 2-113
enabling security 2-860
storm control
configuring for action when storm occurs 2-835
disabling suppression mode 2-559
displaying settings 2-768
enabling 2-835
enabling broadcast 2-835, 2-837
enabling multicast 2-835, 2-837
enabling suppression mode 2-559
enabling timer to recover from error disable 2-206
multicast, enabling 2-837
setting high and low levels 2-835
setting suppression level 2-559
STP
configuring link type for a port 2-810
configuring tunneling encapsulation rate 2-315
debugging all activities 2-151
debugging spanning tree activities 2-151
debugging spanning tree BackboneFast events 2-153
debugging spanning tree UplinkFast 2-156
detecting misconfiguration 2-807
displaying active interfaces only 2-762
displaying BackboneFast status 2-762
displaying bridge status and configuration 2-762
displaying spanning tree debug messages 2-151
displaying summary of interface information 2-762
enabling BPDU filtering by default on all PortFast ports 2-824
enabling BPDU filtering on an interface 2-803
enabling BPDU guard by default on all PortFast ports 2-825
enabling BPDU guard on an interface 2-805
enabling extended system ID 2-808
enabling loop guard as a default on all ports 2-811
enabling PortFast by default on all access ports 2-826
enabling PortFast mode 2-822
enabling protocol tunneling for 2-312
enabling root guard 2-809
enabling spanning tree BackboneFast 2-802
enabling spanning tree on a per VLAN basis 2-830
enabling spanning tree UplinkFast 2-828
setting an interface priority 2-827
setting drop threshold for 2-314
setting pathcost 2-806
setting the default pathcost calculation method 2-821
subinterface configuration mode, summary 1-6
SVI
creating a Layer 3 interface on a VLAN 2-224
switching characteristics
excluding from link-up calculation 2-853
modifying 2-853
returning to interfaces
capture function 2-853
switchport 2-876
switchport interfaces
displaying status of Layer 3 port 2-588
displaying status of native VLAN tagging 2-588
switchport vlan mapping command 2-879
switch shim
debugging 2-154
disabling debugging 2-154
switch to router connection
enabling Cisco-recommended features 2-343
switch to switch connection
enabling Cisco-recommended features 2-345
switch virtual interface
sw-vlan 2-157
system prompts 1-5
T
Tab key
command completion 1-1
tables
characters with special meaning 1-7
mac access-list extended subcommands 2-327
multipliers 1-9
relationship between duplex and speed commands 2-833
show cable-diagnostics tdr command output fields 2-529
show cdp neighbors detail field descriptions 2-537
show cdp neighbors field descriptions 2-536
show ip dhcp snooping command output 2-519, 2-669
show ip interface field descriptions 2-619
show policy-map control-plane field descriptions 2-717
show vlan command output fields 2-787
show vtp command output fields 2-791
special characters 1-9
special characters used for anchoring 1-10
speed command options 2-370, 2-832
valid interface types 2-219
TAC
displaying information useful to TAC 2-771
TCAM
debugging spanning tree activities 2-151
TDR
displaying cable diagnostic test results 2-528
test condition of copper cables 2-882
temperature readings
displaying information 2-556
timer information 2-560
traffic monitor
display status 2-669
traffic shaping
enable on an interface 2-510
traps, enabling 2-795
trunk encapsulation
setting format 2-876
trunk interfaces
displaying trunk interfaces information 2-595
trunk port, configuring VLAN mapping 2-879
trunk ports, display VLAN mapping information 2-784
trust configuration, setting on an interface 2-446, 2-447
trust state
setting 2-232
tunnel ports
displaying information about Layer 2 protocol 2-664
TX queues
allocating bandwidth 2-891
returning to default values 2-891
setting priority to high 2-891
specifying burst size 2-891
specifying traffic rate 2-891
U
UDLD
displaying administrative and operational status 2-773
enabling by default on all fiber interfaces 2-893
enabling on an individual interface 2-895
preventing a fiber interface from being enabled 2-895
resetting all shutdown ports 2-897
setting the message timer 2-893
Unidirectional Link Detection
unidirection port control, changing from bidirectional 2-20
unknown multicast traffic, preventing 2-854
unknown unicast traffic, preventing 2-854
user EXEC mode, summary 1-5
username
setting password and privilege level 2-899
V
VACLs
access-group mode 2-6
applying VLAN access maps 2-911
displaying VLAN access map information 2-779
specifying an action in a VLAN access map 2-12
specifying the match clause for a VLAN access-map sequence 2-366
using a VLAN filter 2-911
VLAN
applying an ARP ACL 2-226
configuring 2-902
configuring service policies 2-906
converting to RSPAN VLAN 2-473
displaying CEF information 2-601
displaying CEF next-hop information 2-601
displaying information on switch interfaces 2-610, 2-614
displaying information on VLAN switch interfaces 2-617
displaying information sorted by group IP address 2-610, 2-614
displaying IP address and version information 2-610, 2-614
displaying Layer 2 VLAN information 2-776
displaying statistical information 2-700
displaying VLAN information 2-777
enabling dynamic ARP inspection 2-235
enabling Explicit Host Tracking 2-265
enabling guest per-port 2-183
enabling guest VLAN supplicant 2-176, 2-184
entering VLAN configuration mode 2-906, 2-908
native frames
enabling tagging on all 802.1Q trunk ports 2-910
pruning the list for VTP 2-876
setting the list of allowed 2-876
VLAN, create or modify a group 2-912
VLAN Access Control Lists
VLAN access map
VLAN database
resetting 2-486
VLAN debugging
limiting output 2-129
vlan group command 2-912
VLAN groups, display VLANs mapped 2-782
VLAN link-up calculation
excluding a switch port 2-853
including a switch port 2-853
VLAN manager
debugging 2-157
disabling debugging 2-157
IOS file system error tests
debugging 2-158
disabling debugging 2-158
VLAN mapping
configuring 2-879
displaying 2-784
VLAN mapping, configure on trunk port 2-879
VLAN mapping on trunk ports, display information 2-784
VLAN Query Protocol
VLAN query protocol (VQPC)
debugging 2-164
VLANs
clearing
counters 2-117
clearing hardware logic 2-93
configuring
internal allocation scheme 2-913
displaying
internal VLAN allocation information 2-783
RSPAN VLANs 2-788
entering VLAN configuration mode 2-908
VMPS
configuring servers 2-917
reconfirming dynamic VLAN assignments 2-164, 2-915
voice VLANs
enabling 2-849
VoIP
configuring auto-QoS 2-59
VQP
per-server retry count 2-916
reconfirming dynamic VLAN assignments 2-164, 2-915
VTP
configuring the administrative domain name 2-921
configuring the device in VTP client mode 2-920
configuring the device in VTP server mode 2-924
configuring the device in VTP transparent mode 2-925
configuring tunnel encapsulation rate 2-315
creating a VTP domain password 2-922
displaying domain information 2-790
displaying statistics information 2-790
enabling protocol tunneling for 2-312
enabling pruning in the VLAN database 2-923
enabling VTP version 2 mode 2-926
modifying the VTP configuration storage file name 2-919
set drop threshold for 2-314
VTP protocol code
activating debug messages 2-161
deactivating debug messages 2-161
W
Webauth fallback, enabling 2-25