The administrator should be familiar with wireless technologies, networking concepts, Ethernet concepts, IP addressing and SNMP. To avoid confusion amongst RFS6000 and RFS7000 CLI users, generic examples are used throughout this guide. These examples are relevant to each switch.
Motorola RF Switch CLI Reference Guide The syntax, parameters and descriptions within this guide can also be used generically for a RFS6000 and RFS7000 model switch. However, some subtle differences do exist amongst these baselines. These differences are strongly noted within the specific commands impacted.
Page 5
Chapter Jump to this section if you want to... Chapter 10, “Crypto-map Understand the ( commands within the crypto-map) Instance” switch CLI. Chapter 11, “Crypto- Summarize the ( commands crypto trustpoint) trustpoint Instance” within the switch CLI. Chapter 12, “Interface Understand the ( commands within the config-if)
Page 6
Motorola RF Switch CLI Reference Guide Chapter Jump to this section if you want to... Chapter 24, “SOLE Instance” Review the instance commands (config-rtls-sole) within the switch CLI Chapter 25, “Smart RF Review the instance (config-wireless-smart-rf) Instance” commands within the switch CLI Chapter 26, “Role Instance”...
NOTE: Indicates tips or special requirements. CAUTION: Indicates conditions that can cause equipment damage or data loss. SWITCH NOTE: Indicates caveats unique to a RFS6000 or RFS7000 model switch. WARNING! Indicates a condition or procedure that could result in personal injury or equipment damage.
Motorola RF Switch CLI Reference Guide Notational Conventions The following notational conventions are used in this document: • Italics are used to highlight specific items in the general text, and to identify chapters and sections in this and related documents.
Page 9
xiii The pipe symbol. This is used to separate the variables/keywords in a list. For example, the command RFSwitch> show ..is documented as show [autoinstall|banner|ip|ldap|..] where: • set – The command • [autoinstall|banner|ip|ldap|..] – Indicates the different commands that can be combined with the show command. However, only one of the above list can be used at a time.
Page 10
Motorola RF Switch CLI Reference Guide Any command/keyword/variable or a combination of them inside a ‘{‘ & ‘}’ pair is optional. All optional commands follow the same conventions as listed above. However they are displayed itali- cized. For example, the command RFSwitch>...
Page 11
Motorola Service Information Use the Motorola Support Center as the primary contact for any technical problem, question, or support issue involving Motorola products. Motorola Support Center responds to calls by email, telephone or fax within the time limits set forth in individual contractual...
Motorola RF Switch CLI Reference Guide General Information For general information, contact Motorola at: Telephone (North America): 1-800-722-6234 Telephone (International): +1-631-738-5200 Website: http://www.motorola.com...
Page 13
OTHER LEGAL ENTITY, YOU REPRESENT AND WARRANT THAT YOU HAVE THE AUTHORITY TO BIND THAT COMPANY, PERSON OR ENTITY. 1. LICENSE GRANT. Subject to the terms of this Agreement, Motorola, Inc. and/or its subsidiaries ("Licensor") hereby grants Licensee a limited, personal, non-sublicensable, non transferable, non-exclusive license to use the software that Licensee is about to download or install and the documentation that accompanies it (collectively, the "Software") for...
Motorola RF Switch CLI Reference Guide 3. INTELLECTUAL PROPERTY; CONTENT. All title and intellectual property rights in and to the Software (including but not limited to any images, photographs, animations, video, audio, music, text and "applets" incorporated into the Software), and any copies you are permitted to make herein are owned by Licensor or its suppliers.
Page 15
6. DISCLAIMER OF WARRANTIES. To the maximum extent permitted by applicable law, Licensor and its suppliers provide the Software and any (if any) Support Services AS IS AND WITH ALL FAULTS, and hereby disclaim all warranties and conditions, either express, implied or statutory, including, but not limited to, any (if any) implied warranties or conditions of merchantability, of fitness for a particular purpose, of lack of viruses, of accuracy or completeness of responses, of results, and of lack of negligence or lack of...
Page 16
"Restricted Rights" as provided for in FAR, 48 CFR 52.227-14 (JUNE 1987) or DFAR, 48 CFR 252.227- 7013 (OCT 1988), as applicable. The "Manufacturer" for purposes of these regulations is Motorola, Inc., One Symbol Plaza, Holtsville, NY 11742. 12. EXPORT RESTRICTIONS. Licensee shall comply with all export laws and restrictions and regulations of the Department of Commerce, the United States Department of Treasury Office of Foreign Assets Control ("OFAC"), or other United States or foreign agency or...
Page 17
waiver. This Agreement shall be governed by the laws of the State of New York without regard to the conflicts of law provisions thereof. The application the United Nations Convention of Contracts for the International Sale of Goods is expressly excluded. Unless waived by Licensor for a particular instance, any action or proceeding arising out of this Agreement must be brought exclusively in the state or federal courts of New York and Licensee hereby consents to the jurisdiction of such courts for any such action or proceeding.
This chapter describes the commands defined by the switch Command Line Interface (CLI). Access the CLI (on the supported RFS6000 and RFS7000 models) by running a terminal emulation program on a computer connected to the serial port on the front of the switch, or by using a Telnet session via secure shell (SSH) to access the switch over the network.
Introduction 1- Table 1.1 RF Switch CLI Hierarchy User Exec Mode Priv Exec Mode Global Configuration Mode wireless-acl firewall network-element-id ratelimit role virtual-ip wwan 1.2 Getting Context Sensitive Help Enter a question mark (?) at the system prompt to display a list of commands available for each mode.
Page 42
Motorola RF Switch CLI Reference Guide Command Description (prompt)# command keyword ? Lists the next available syntax option for the command NOTE: The system prompt varies depending on which configuration mode you are in. NOTE: Enter Ctrl + V to use ? as a regular character and not as a character used for displaying context sensitive help.
Introduction 1- It is possible to abbreviate commands and keywords to allow a unique abbreviation. For example, “configure terminal” can be abbreviated as . Since the abbreviated config t command is unique, the switch accepts the abbreviation and executes the command. Enter the help command (available in any command mode) to provide the following description: RFSwitch>help...
Motorola RF Switch CLI Reference Guide • Enter commands in uppercase, lowercase, or mixed case. Only passwords are case sensitive • If an instance name (or other parameter) contains whitespace, the name must be enclosed in quotes RFSwitch.(Cfg)> spol "Default Switch Policy"...
Page 45
Introduction 1- Table 1.2 Key Combinations Used to Move the Cursor Function Keystrokes Summary Function Details Left Arrow or Ctrl-B Back character Moves the cursor one character to the left When entering a command that extends beyond a single line, press the Left Arrow or Ctrl-B keys repeatedly to scroll back to the system prompt and verify the beginning of the command entry.
1-10 Motorola RF Switch CLI Reference Guide Function Keystrokes Summary Function Details Ctrl-Z Enters the command and returns to the root prompt Ctrl-L Refreshes the input line 1.4.2 Completing a Partial Command Name If you cannot remember a command name (or if you want to reduce the amount of typing you have to perform) enter the first few letters of a command, then press the Tab key.
Introduction 1- RFSwitch# co NOTE: The characters entered before the question mark are reprinted to the screen to complete the command entry. 1.4.3 Deleting Entries Use any of the following keys (or key combinations) to delete command entries: Keystrokes Purpose Backspace Deletes the character to the left of the cursor Ctrl-D...
1-12 Motorola RF Switch CLI Reference Guide 1.4.6 Transposing Mistyped Characters If you have mistyped a command entry, you can transpose the mistyped characters. To transpose characters, use the following key combination: Keystrokes Purpose Ctrl-T Transposes the character to the left of the cursor with the character located at the cursor 1.4.7 Controlling Capitalization...
Common Commands This chapter describes the CLI commands used in the USER EXEC, PRIV EXEC, and GLOBAL CONFIG modes. The PRIV EXEC command set contains those commands available within the USER EXEC mode. Some commands can be entered in either mode. Commands entered in either USER EXEC mode or PRIV EXEC mode are referred to as EXEC mode commands.
Motorola RF Switch CLI Reference Guide 2.1.1 clrscr Common Commands Clears the screen and refreshes the prompt (#) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax clrscr Parameters None Example RFSwitch#clrscr RFSwitch#...
Common Commands 2.1.2 exit Common Commands Ends the current mode and moves to the previous mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config)#exit RFSwitch#...
Motorola RF Switch CLI Reference Guide 2.1.3 help Common Commands Use this command to access the advanced help feature. Use “?” anytime at the command prompt to access the help topic. Two kinds of help are provided: 1. Full help is available when ready to enter a command argument.
Page 53
Common Commands 2.1.4 no Common Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example (User Exec) RFSwitch>no ? cluster-cli Cluster context mobile-unit mobile-unit index page...
Page 54
Motorola RF Switch CLI Reference Guide access-list Configure access-lists autoinstall autoinstall configuration command banner Reset login banner to nothing bridge Bridge group commands country-code Clear the currently configured country code. All existing configurations will be erased crypto encryption module errdisable...
2.1.5 service Common Commands Service commands are used to manage the switch configuration in all modes. Depending on the mode, different service commands will display. • RFS7000 • RFS6000 • RFS4000 Syntax (User Executable Mode) service [diag|encrypt|kill|locator|save-cli|show|undefine| wireless] service [locator|save-cli|undefine]...
Page 56
Motorola RF Switch CLI Reference Guide service show [cli|command-history|crash-info|diag|info| memory|process|reboot-history|rtls|startup-log| upgrade-history|watchdog] service show [cli|command-history|crash-info|info|memory| process|reboot-history|startup-log|upgrade-history| watchdog] service show diag [hardware|led-status|limits|period|stats| tech-support-period|tech-support-url|top] service show rtls [location-history|rfid] service show rtls location-history service show rtls rfid events reader {<1-48>} service undefine ecspec {<ECSpec-name>}...
Page 57
Common Commands Parameters (User Executable Mode) diag Diagnostics commands [enable|identify|limit| • enable – Enables in-service diagnostics period| • identify – Identifies a switch by flashing its LEDs tech-support-period| • limit [buffer|fan|filesys|inodes|load|maxFDs| tech-support-url] pkbuffers|procRAM|ram|routecache|temperature] – Sets the diagnostic limit command • buffer []<0-65535> – Configures the buffer usage warning limit.
Page 58
2-10 Motorola RF Switch CLI Reference Guide • routecache <0-65535> – Configures IP route cache usage. Set a value between 0 and 65553. • temperature <1-6> [critical|high|low] – Sets the number of temperature sensors for the switch. • critical <0.0 - 250.0> – Critical temperature limit •...
Page 59
Common Commands 2-11 save-cli Saves the CLI tree for all modes in HTML show [cli|command- Displays running system information history|crash-info|diag| • cli – Shows the CLI tree of the current mode info|memory|process| • command-history – Displays the command (except show reboot-history|rtls| commands) history startup-log|...
Page 60
2-12 Motorola RF Switch CLI Reference Guide • info – Shows a snapshot of available support information • memory – Shows memory statistics • watchdog – Shows watchdog status • process – Shows processes (sorted by memory usage) • reboot-history – Shows a reboot history •...
Page 61
Common Commands 2-13 service diag [enable|identify|limit|period| tech-support-period|tech-support-url] service encrypt secret 2 <pass-phrase> <plain-text> service firewall disable service firewall ip igmp snooping robustness-variable <1-7> service kill conncection {<1-64>} service pktcap on [bridge|deny|drop|interface|router|vlan] service pktcap on [bridge|drop] {[count <1- 1000000>|filter|hex|snap <1-1518>|verbose|write]} service pktcap on bridge filter on [<LINE>|arp|capwap|dst|ether|host|icmp|igmp|ip|ip6|l2|l3| l4|net|not|port|src|tcp|udp|vlan|wlan] service pktcap on bridge filter [arp|capwap|icmp|ip|ip6|...
Page 62
2-14 Motorola RF Switch CLI Reference Guide service pktcap on bridge filter src [<IP>|net <IP/MASK>| port <0-65536>] {[and|or] <LINE>} service pktcap on bridge filter tcp {[[and|or] <LINE>|[ack|fin|or|rst|syn] {[and|or] <LINE>]} service pktcap on bridge filter vlan <1-4095> {[and|or] <LINE>} service pktcap on bridge filter wlan <1-2> {[and|or] <LINE>} service pktcap on bridge [hex|verbose] {[count <1-1000000>|...
Page 63
Common Commands 2-15 service show rtls grid x <0-9000> y <0-9000> service show rtls rfid events reader {<1-48>} service show securitymgr flows [details|source] service show securitymgr flows details {source [<IP>|any] destination [<IP>|any] protocol [any|icmp|tcp|udp]} service show securitymgr flows source [<IP>|any] destination [<IP>|any] protocol [any|icmp|tcp|udp] service show smart-rf [debug-config|sensitivity] service show smart-rf debug-config...
Page 64
2-16 Motorola RF Switch CLI Reference Guide service smart-rf interference [<radio-mac>|<radio-index>| <radio-index-list>] service undefine ecspec {<SPECNAME>} service wireless [ap-history|clear-ap-log|custom-cli|dot11i| dump-core|enhanced-beacon-table|enhanced-probe-table| free-packet-watermark|idle-radio-send-multicast| legacy-load-balance|map-radios|radio-misc-cfg|rate-scale| request-ap-log|save-ap-log|snmp-trap-throttle| sync-radio-entries|vlan-cache] service wireless [dumpcore|legacy-load-balance|rate-scale| save-ap-log|sync-radio-entries] service wireless ap-history [clear|enable] service wireless clear-ap-log {<1-1024>} service wireless custom-cli [sh-wi-mobile-unit|sh-wi-radio]...
Page 65
Common Commands 2-17 service wireless radio-misc-cfg <hex-mask> service wireless request-ap-log <ap-index> service wireless snmp-trap-throttle <1-20> service wireless vlan-cache enable Parameters (Privilege Executable Mode) clear Performs a variety of reset functions [all|aplogs|clitree|cores| • all – Removes all core, dump and panic files dumps|fw|panics| •...
Page 66
2-18 Motorola RF Switch CLI Reference Guide copy tech-support Copies files for tech support purposes [<file>|<URL>] • tech-support [<file>|<URL>] [tftp|ftp|sftp] – Copies [tftp|ftp|sftp] extensive system information useful to technical support for troubleshooting. • FILE – File to which to copy •...
Page 67
Common Commands 2-19 diag [enable|identify| Sets or displays switch diagnostic values limit|period| • enable – Enables in-service diagnostics tech-support-period| • fanduty <40-100> – CPU fan PWM duty cycle. tech-support-url] Set a value between 40-100%. Setting a value below 60 is considered unreliable. •...
Page 68
2-20 Motorola RF Switch CLI Reference Guide • routecache <0-65535> – Configures IP route cache usage. Set between 0 and 65553. • temperature <1-6> [critical|high|low] – Sets the number of temperature sensors for the switch. • critical <0.0 - 250.0> – Critical temperature limit •...
Page 69
Common Commands 2-21 pktcap on Packet capturing [bridge|interface|router| • on – Defines the packet capture location vpn] • bridge [count|hex|snap|verbose|write|filter] – Captures [count|filter|verbose| packet at the bridge write] • count <1-1000000> – Limits the captured packet count • filter [<LINE>|arp|capwap|dst|ether|host|icmp|igmp| ip|ip6|l2|l3|l4|net|not|port|src|tcp|udp|vlan|wlan] –...
Page 70
2-22 Motorola RF Switch CLI Reference Guide • verbose <1-1000000> – Displays full packet body • filter – Captures the filter • snap <1-1518>– Captured data length • write [<FILE>|URL] – Captures to a file • FILE – File to which to copy •...
Page 71
Common Commands 2-23 • count <1-1000000> – Limits capture packet count • filter – Captures filter • verbose – Displays full packet body • write – Captures to a file • snap <1-1518> – Captured data length • hex – Show full packet body •...
Page 72
2-24 Motorola RF Switch CLI Reference Guide show [cli| Displays running system information command-history| • cli – Shows the CLI tree of the current mode crash-info|diag|fw|info| • command-history – Displays a command (except show ip|last-passwd|memory| commands) history pm|process| • crash-info – Displays information about core, panic and...
Page 73
Common Commands 2-25 • pm history – Process Monitor • history [WORD|all] – Displays state changes for a process, the time they happened and events • WORD – Process name • all – All processes • process – Shows processes (sorted by memory usage) •...
Page 74
2-26 Motorola RF Switch CLI Reference Guide show securitymgr flows Service Security Manager parameters • flows [details|source] – Sessions established • details – Shows detail flow statistics • source [A.B.C.D|any] – Shows the source IP address • [A.B.C.D|any] – Flows where source address is A.B.C.D or flows with any source address...
Page 75
Common Commands 2-27 smart-rf [clear- Displays Smart-RF Management Commands history|load-from- • clear-history– clears assignment history file|replay|rescue|restore| • load-from-file – load record from file save-to-file|simulate] • replay enable – set replay mode • enable – enable replay mode • rescue <MAC> – force rescue operation •...
Page 76
2-28 Motorola RF Switch CLI Reference Guide watchdog Enables the switch watchdog wireless [ap-history| Wireless parameters clear-ap-log • ap-history [clear|enable] – Access-port history |custom-cli|dot11i| • clear – Delete all history of all APs dump-core| • enable – Enable the tracking of AP history enhanced-beacon-table| •...
Page 77
Common Commands 2-29 • radio-desc – description of radio where the mobile- unit is associated • radio-id – The radio index to which the mobile-unit is associated • ssid – The ssid of the mobile-units wlan • state – The current state of the mobile-unit •...
Page 78
2-30 Motorola RF Switch CLI Reference Guide • num-mu – The number of mobile devices associated with this radio • power – The configured and current transmit power of the radio • pref-id – The adoption preference id of the radio •...
Page 79
Common Commands 2-31 • enhanced-probe-table [enable|erase-report|max-mu| preferred|window-time] – Enhanced probe table for MU locationing. • enable – Enables the Enhanced Probe Table feature for MU locationing. • erase-report – Erases the reports for Enhanced Probe Table feature. • max-mu <0-512> – Sets the maximum MUs in the Enhance Probe Table report.
Page 80
2-32 Motorola RF Switch CLI Reference Guide Syntax (Global Config Mode) (Global Config) service [advanced-vty|dhcp|diag|password-encryption|pm| prompt|radius|redundancy|set|show|terminal-length| watchdog] service [advanced-vty|dhcp|watchdog] service diag [enable|limit|period|tech-support-period| tech-support-url] service password-encryption secret 2 <pass-phrase> service pm sys-restart service prompt crash-info service radius {restart} service redundancy dynamic-ap-load-balance start service set [command-history|reboot-history|upgrade-history] <10-100>...
Page 81
Common Commands 2-33 pm sys-restart Process Monitor • sys-restart – Enables the PM to restart the system when a processes fails prompt crash-info Enable crash-info prompt • crash-info – Enables a crash-info prompt radius restart Enable radius server • restart – Restarts the radius server with an updated configuration redundancy dynamic-ap- Configure redundancy group parameters...
Page 82
2-34 Motorola RF Switch CLI Reference Guide Usage Guidelines set by the user cannot be disabled without knowing service password-encryption the old password. Refer the note below for more clarification. NOTE: The command used to no service password-encryption disable the encryption, now requires the user to know the old password.
If the current context contains instances, the show command (usually) displays a list of these instances. • When invoked with the display_parameter, it displays information about that component. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax show <parameter> Parameters Display...
Page 86
2-38 Motorola RF Switch CLI Reference Guide Display Parameters Description Mode Example interfaces Displays the current interface status Common page 2-50 and configuration Displays the internet protocol Common page 2-52 ldap Displays the LDAP server Common page 2-59 configuration licenses...
Page 87
Common Commands 2-39 Display Parameters Description Mode Example redundancy Display configuration details for Common page 2-76 dynamic-ap-load- dynamic AP Load Balance balance redundancy group Displays redundancy group Common page 2-77 parameters redundancy Displays the state transition history Common page 2-80 history of the switch redundancy...
Page 88
2-40 Motorola RF Switch CLI Reference Guide Display Parameters Description Mode Example version Displays software and hardware Common page 2-98 version information wireless Displays wireless configuration Common page 2-99 commands wlan-acl Displays WLAN ACL information Common page 2-117 access-list Displays the access list Internet...
Page 89
Common Commands 2-41 Display Parameters Description Mode Example securitymgr Displays debug information for ACL, Privilege/ page 2-132 VPN and NAT Global Config sessions Displays currently open and active Privilege/ page 2-133 connections Global Config startup-config Displays the content of the startup Privilege/ page 2-134 configuration...
2-42 Motorola RF Switch CLI Reference Guide 2.2.1 autoinstall Common to all modes Displays the autoinstall configuration information Syntax show autoinstall status Parameters status Displays status of autoinstall Example RFSwitch>show autoinstall RFSwitch>feature enabled config --not-set-- cluster cfg yes --not-set--...
Common Commands 2-43 2.2.2 banner Common to all modes Displays the message of the day string. This string can be used to alert the user to specific information that might be of interest. Syntax show banner motd Parameters motd Displays the Message of the Day banner Example RFSwitch>show banner motd...
2-44 Motorola RF Switch CLI Reference Guide 2.2.3 commands Common to all modes Displays the available commands for the current mode Syntax RFSwitch>show commands Parameters None Example RFSwitch#show commands acknowledge alarm-log (all|<1-65535>) acknowledge alarm-log (all|<1-65535>) archive tar /create (FILE|URL) .FILE archive tar /create (FILE|URL) .FILE...
Common Commands 2-45 2.2.4 crypto Common to all modes Displays the encryption mode information Syntax show crypto[ipsec|isakmp|key|map|pki] show crypto ipsec[sa| security-association|transformset] show crypto isakmp[policy <1-10000>|sa] show crypto keymy pubkey rsa show crypto map[interface <interface-name>|tag <tag-name>] show crypto pki[request <trustpoint-name>|trustpoints] Parameters ipsec Displays the IPSEC policy...
Page 94
2-46 Motorola RF Switch CLI Reference Guide pki [request|trustpoints] Displays Public Key Infrastructure (PKI) commands • request <trustpoint-name> – Displays the certificate requests • trustpoints – Displays the trustpoints and their configuration Usage Guidelines The security engine periodically updates the IPSec and Isakamp statistics (every 60...
Page 95
Common Commands 2-47 Subject Name: Common Name: Symbol Technologies Issuer Name: Common Name: Symbol Technologies Valid From: Sep 13 16:14:49 2006 GMT Valid Until: Sep 13 16:14:49 2007 GMT Trustpoint :tptest ----------------------------------------------- CA certificate configured Subject Name: Common Name: monarch Organizational Unit: wid Organization: symbol...
2-48 Motorola RF Switch CLI Reference Guide 2.2.5 environment Common to all modes Displays the environmental information such as fan speed, ambient temperature inside the switch and CPU temperature. Syntax show environment Parameters None Example RFSwitch>show environment upwind of CPU temperature : 30.0 C CPU die temperature : 49.0 C...
Common Commands 2-49 2.2.6 history Common to all modes Displays the command history Syntax show history Parameters None Example RFSwitch>show history 1 admin 2 enable 3 con ter 4 exit 5 show autoinstall 6 con ter 7 show autoinstall 8 show banner 9 show banner motd 10 show command...
2-50 Motorola RF Switch CLI Reference Guide 2.2.7 interfaces Common to all modes Displays the status of the different switch interfaces Syntax show interfaces [WORD|ge|me1|sa|switchport|vlan] Parameters show interfaces Displays the interface name [WORD|ge|me1|sa| • WORD– Displays interface name switchport|vlan] •...
Page 99
Output packets 0, bytes 0, dropped 0 Sent 0 broadcasts, 0 multicasts Output errors 0, collisions 0, late collisions 0, excessive collisions 0 RFS6000#show interfaces wan Interface wan Hardware Type PPP, Interface Mode Layer 3 index=8, metric=1, mtu=1500, (PAL-IF) <UP,POINTOPOINT,RUNNING,NOARP,MULTICAST >...
Page 100
2-52 Motorola RF Switch CLI Reference Guide 2.2.8 ip Common to all modes Displays Internet Protocol (IP) related information Syntax show ip [access-group|arp|ddns|dhcp| dhcp-vendor-options|domain-name|dos|http|igmp|interface| name-server|nat|route|routing|ssh|telnet] show ip access-group [<interface-name>|all|ge|me1|role|sa| vlan <1-4094>] show ip arp show ip ddnsbinding show ip dhcp[binding|class|pool|sharednetwork|]...
Page 101
Common Commands 2-53 Parameters access-group Displays the ACLs attached to an interface [<interface-name> • <interface-name> – Enter the name of the interface to |all|ge|me1|role|sa|> which the ACL is associated. access-group lists the |vlan <1-4094>] details of the ACLs configured on the particular Layer 3 or Layer 2 interface.
Page 102
2-54 Motorola RF Switch CLI Reference Guide http Hyper Text Transfer Protocol (HTTP) [secure-server|server] • secure-server – Secure HTTP server • server – HTTP server interface [<interface- Use the show ip interface command to display the name>|brief|ge|me1|sa| administrative and operational status of all Layer-3 vlan] interfaces or a specified Layer-3 interface.
Page 103
Common Commands 2-55 route [<IP>|<IP/Mask> Display IP routing table entries |detail] • <IP> – Network in the IP routing table • <IP/Mask> – Number of valid bits in the network prefix IP prefix <network>/<length>, e.g., 35.0.0.0/8 • detail – Displays the IP routing table in detail routing IP routing status Secured Shell (SSH) server...
Page 104
2-56 Motorola RF Switch CLI Reference Guide interface. In this case, it is the physical interface that is disconnected not the virtual interface. When the ethernet interface comes back up, it will restart the DHCP client on any virtual interfaces (SVIs) of which the physical interface is a member port. This ensures if the interface was disconnected and reconnected to a different interface, it obtains a new IP address, route, name server, domain name etc.
Page 105
: motorola.com RFSwitch#show ip http server HTTP server: Running Config status: Enabled RFSwitch#show ip http secure-server HTTP secure server: Running Config status: Enabled Trustpoint: default-trustpoint RFSwitch#show ip interface brief RFS6000#show ip interface brief Interface IP-Address/Mask Status Protocol 10.1.1.100/24 down vlan1 192.168.1.1/24 vlan11 192.168.11.1/24...
Page 106
2-58 Motorola RF Switch CLI Reference Guide RFSwitch#show ip interface vlan 1 brief Interface IP-Address Status Protocol vlan1 157.235.208.233 (DHCP)up RFSwitch#show ip name-server 157.235.3.195 dynamic 157.235.3.196 dynamic RFSwitch#show ip routing IP routing is on RFSwitch(config)#show ip route detail Codes: K - kernel/icmp, C - connected, S - static, D - DHCP >...
Common Commands 2-59 2.2.9 ldap Common to all modes Displays LDAP information Syntax show ldap configuration [primary|secondary] Parameters ldap configuration Displays LDAP information. [primary|secondary] • Configuration [primary|secondary] – Sets the LDAP configuration server parameters • primary – Defines the Primary LDAP server •...
Page 108
2-60 Motorola RF Switch CLI Reference Guide (sAMAccountName=%{Stripped-User-Name:-%{User-Name}}) Bind DN cn=kumar,ou=symbol,dc=activedirectory,dc=com Base DN : ou=symbol,dc=activedirectory,dc=com Password : 0 symbol@123 Password Attribute : UserPassword Group Name : cn Group Membership Filter: (&(objectClass=group)(member=%{Ldap-UserDn})) Group Member Attr : radiusGroupName Net timeout : 1 second(s)
Common Commands 2-61 2.2.10 licenses Common to all modes Displays the different licenses installed on the switch Syntax show licenses Parameters None Example RFSwitch(config)#show licenses feature usage license string license value usage 2FFD7fE9 CD016155 14A92C70 48...
2-62 Motorola RF Switch CLI Reference Guide 2.2.11 logging Common to all modes Displays logging status and other information Syntax show logging Parameters None Example RFSwitch(config)#show logging Logging module: enabled Aggregation time: disabled Console logging: level debugging Buffered logging: level informational...
Common Commands 2-63 2.2.12 mac Common to all modes Shows all MAC information with respect to groups and access lists Syntax show mac [access-list|access-group] interface>|all|ge <1-4>| show mac access-group [< me1|sa <1-4>|vlan <1-4094>] Parameters mac [access-list Displays MAC information access-group] •...
Common Commands 2-65 2.2.14 management Common to all modes Displays the L3 management interface name Syntax show management Parameters None Example RFSwitch>show management Mgmt Interface: vlan1 Management access permitted via any vlan interface RFSwitch>...
2-66 Motorola RF Switch CLI Reference Guide 2.2.15 mobility Common to all modes Displays the mobility parameters Syntax show mobility [event-log|forwarding|global| mobile-unit|peer|statistics] show mobility event-log [mobile-unit|peer] show mobility forwarding <MAC> show mobility mobile-unit [MAC>|detail] show mobility peer [<IP>|detail] show mobility statistics <MAC>...
Page 115
Common Commands 2-67 global Global Mobility parameters mobile-unit Mobile-units in the Mobility Database peer Mobility peers statistics Mobile-unit Statistics RFSwitch(config)#show mobility event-log mobile-unit Time Event Evt-Src-IP MU-Mac MU-IP HS-IP CS-IP 09/14 19:17:52 IP-UPD-MU 00-0f-3d-e9-a6-54 157.235.208.134 157.235.208.16 157.235.208.16 09/14 19:17:51 ADD-MU 00-0f-3d-e9-a6-54 0.0.0.0 157.235.208.16 157.235.208.16 09/14 19:17:51 DEL-MU...
Common Commands 2-69 2.2.16 ntp Common to all modes Displays NTP protocol information Syntax show ntp [association|status] Parameters ntp [association Displays the Network Time Protocol (NTP) configuration detail|status] • association detail – Displays existing NTP associations • detail – Displays NTP association details •...
Page 118
2-70 Motorola RF Switch CLI Reference Guide rcv time 00000000.00000000 (Feb 07 06:28:16 UTC 2036) xmt time c8b42a7e.6eb04252 (Sep 14 19:22:38 UTC 2006) filtdelay = 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 RFSwitch>show ntp status Clock is synchronized, stratum 0, actual frequency is 0.0000 Hz, precision is 2^0 reference time is 00000000.00000000 (Feb 07 06:28:16 UTC...
Common Commands 2-71 2.2.17 port-channel Common to all modes Displays port-channel load-balance information • RFS7000 SWITCH NOTE: This command is not supported on: • RFS6000 • RFS4000 Syntax show port-channel load-balance Parameters load-balance Displays the existing load balancing configuration Example RFSwitch>show port-channel load-balance...
Motorola RF Switch CLI Reference Guide 2.2.18 power Common to all modes Displays the power configuration and status for the RFS6000 switch Supported in the following platforms: • RFS4000 • RFS6000 SWITCH NOTE: This command is not supported on: •...
Common Commands 2-73 2.2.19 privilege Common to all modes Displays the privileges of the current user Syntax show privilege Parameters None Example RFSwitch>show privilege Current user privilege: superuser RFSwitch>...
2-74 Motorola RF Switch CLI Reference Guide 2.2.20 radius Common to all modes Displays RADIUS status and information Syntax show radius [configuration|eap configuration|group| A.B.C.D/M|proxy|rad-user|trust-point] Parameters radius [configuration| Displays RADIUS configuration commands eap configuration group| • configuration – RADIUS server configuration nas <IP/Mask>|proxy|...
Page 123
Common Commands 2-75 Proxy Realm Details ___________________ Realm : symbol.com IP Address : 10.10.10.5 Port : 1812 Shared secret : 0 secret123...
2-76 Motorola RF Switch CLI Reference Guide 2.2.21 redundancy dynamic-ap-load-balance Common to all modes Displays the configuration for the Dynamic AP Load Balancing feature Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax show redundancy dynamic-ap-load-balance config...
Common Commands 2-77 2.2.22 redundancy group Common to all modes This command displays the switch’s IP address, number of active neighbors, group license, installed license, cluster AP adoption count, switch adoption count, hold time, discovery time, heartbeat interval, cluster id and switch mode. In a cluster, this command displays the redundancy runtime and configuration of the “self-switch”.
Page 126
2-78 Motorola RF Switch CLI Reference Guide Redundancy Protocol Version : 2.0 Redundancy Group License : Not Applicable Cluster AP Adoption Count Switch AP Adoption Count : Not Applicable Redundancy State : Disabled Radio Portals adopted by Group : Not Applicable...
Page 127
Common Commands 2-79 Redundancy Protocol Version : 2.0 Redundancy Group License Cluster AP Adoption Count : Not Applicable Switch AP Adoption Count : Not Applicable Redundancy State : Disabled Radio Portals adopted by Group : Not Applicable Radio Portals adopted by this Switch : Not Applicable Rogue APs detected in this Group : Not Applicable Rogue APs detected by this Switch...
2-80 Motorola RF Switch CLI Reference Guide 2.2.23 redundancy history Common to all modes Displays the switch state transition history Syntax show redundancy history Parameters None Example RFSwitch>show redundancy history State Transition History Time Event Triggered state --------------------------------------------------------- Sat Oct 06 12:07:55...
Common Commands 2-81 2.2.24 redundancy members Common to all modes Displays the member switches in the cluster. The user can provide the of the IP address switch in cluster whose information alone is needed. Syntax show redundancymembers [<IP>|brief] Parameters redundancymembers Displays member switches in the cluster [<IP>|brief]...
2-82 Motorola RF Switch CLI Reference Guide 2.2.25 rtls Common to all modes Displays the Real Time Locating System status and information Syntax show rtls [aeroscout|espi|filter|ekahau| reference-tags|rfid|site|sole|tags|zone]...
Page 131
Common Commands 2-83 Parameters rtls [aeroscout|espi|filter| Displays the Real Time Locating System status and ekahau| information. reference-tags| • aeroscout – Displays aeroscout configurations rfid|site|sole|tags|zone] • espi [adapter|ecspecs|subscriber|tags] – Displays ESPI configuration • adapter [active|ale-tcp] – Displays Adapter Configuration • active – Displays adapters that are currently active •...
Page 132
2-84 Motorola RF Switch CLI Reference Guide rtls tags [<tag-id>| Displays Tags/Assets (passive, active, wi-fi, uwb) aeroscout|all|ekahau|g2| Information mobile-unit| • <tag-id> – Displays detailed tag information for specific |rfid|uri|zone|] tag ID • aeroscout – Displays located aeroscout tags • all – Displays all tags •...
Common Commands 2-85 2.2.26 smtp-notification Common to all modes Displays the set smtp-notification parameters Syntax show smtp-notification traps Parameters traps Displays trap enable flags Example RFSwitch(config)#show smtp-notification traps ----------------------------------------------------------------- -Global enable flag for Trap SMTP-Notification Disabled ----------------------------------------------------------------- -Enable flag status for Individual Trap SMTP-Notification ----------------------------------------------------------------- --Module Type Trap Type...
Common Commands 2-87 2.2.27 snmp Common to all modes Displays SNMP user information Syntax show snmp user [snmpmanager|snmpoperator|snmptrap] Parameters snmp user Displays SNMP user information [snmpmanager| • snmpmanager – Shows SNMP manager information snmpoperator|snmptrap • snmpoperator – Shows SNMP operator information •...
2-88 Motorola RF Switch CLI Reference Guide 2.2.28 snmp-server Common to all modes Displays SNMP server information Syntax show snmp-server traps wireless-statistics[mesh|mobile-unit| radio|wireless-switch|wlan] Parameters traps wireless-statistics Displays existing wireless-stats rate trap enabled flags [mesh| • mesh – Displays existing mesh rate traps mobile-unit| radio| •...
Page 137
Common Commands 2-89 redundancy grpAuthLevelChanged misc lowFsSpace misc processMaxRestartsReached wireless station associated wireless station disassociated wireless station deniedAssociationOnCapability wireless station deniedAssociationOnShortPream wireless station deniedAssociationOnSpectrum wireless station deniedAssociationOnErr wireless station deniedAssociationOnSSID wireless station deniedAssociationOnRates wireless station deniedAssociationOnInvalidWPAWPA2IE wireless station deniedAssociationAsPortCapacityReached wireless station tkipCounterMeasures wireless station deniedAuthentication...
Common Commands 2-91 2.2.29 spanning-tree Common to all modes Displays Spanning Tree information Syntax show spanning-tree mst [config|detail|instance] show spanning-tree mst detail interface [<interface-name>|ge|me1|sa|vlan <1-4094>] show spanning-tree mst instance <1-15> interface <IF NAME>||vlan <1-4094>}] Parameters config Displays MST configuration information detail interface Displays detailed interface information [<interface-name>|...
Page 140
2-92 Motorola RF Switch CLI Reference Guide %------------------------------------------------------ RFSwitch(config)# RFSwitch(config)#show spanning-tree mst detail interface ge % Bridge up - Spanning Tree Enabled % CIST Root Path Cost 0 - CIST Root Port 0 - CIST Bridge Priority 32768 % Forward Delay 15 - Hello Time 2 - Max Age 20 - Max-hops 20...
Common to all modes Displays the members of the static channel groups Supported in the following platforms: • RFS7000 • RFS4000 SWITCH NOTE: This command is not supported in: • RFS6000 Syntax show static-channel-group Parameters None Example RFSwitch(config)#show static-channel-group...
2-94 Motorola RF Switch CLI Reference Guide 2.2.31 terminal Common to all modes Displays the terminal information for the device Syntax show terminal Parameters None Example RFSwitch>show terminal Terminal Type: vt102 Length: 44 Width: 125 RFSwitch>...
Common Commands 2-95 2.2.32 timezone Common to all modes Displays the timezone set on the device Syntax show timezone Parameters None Example RFSwitch>show timezone Timezone is Etc/UTC RFSwitch>...
2-96 Motorola RF Switch CLI Reference Guide 2.2.33 traffic-shape Common to all modes Displays traffic shaping parameters Supported in the following platforms: • RFS7000 SWITCH NOTE: This command is not supported in: • RFS6000 Syntax show traffic-shape [config|priority-map|statistics] Parameters •...
Common Commands 2-97 2.2.34 users Common to all modes Displays a list of users connected to the device Syntax show users Parameters None Example RFSwitch>show users Line User Uptime Location 0 con 0 316 admin 06:08:11 ttyS0 130 vty 0 2308 admin 00:35:18 RFSwitch>...
2-98 Motorola RF Switch CLI Reference Guide 2.2.35 version Common to all modes Displays the current software & hardware version on the device Syntax show version {verbose} Parameters verbose Displays software and hardware version information Example RFSwitch>show version RFSwitch version 3.2.0.0-024D MIB=01a Copyright (c) 2006-2007 Motorola, Inc.
Common to all modes range differs from switch to switch. radio-group • RFS7000 – Supports a range between 0-255 • RFS6000 – Supports a range between 0-64 • RFS4000 – Supports a range between 1-6 Displays the wireless configuration parameters and information Syntax...
Page 148
2-100 Motorola RF Switch CLI Reference Guide show wireless mesh statistics {<1-32> {detail}} show wireless mobile-unit {[<1-8192>|<MAC>|association- history|association-stats|probe-history|radio| roaming|statistics|voice|wlan]} show wireless mobile-unit [<1-8192>|<MAC>|association-stats] show wireless mobile-unit association-history {<MAC>} show wireless mobile-unit probe-history [<1-200>|config- list] show wireless mobile-unit radio <1-4096> show wireless mobile-unit roaming database show wireless mobile-unit statistics [<1-4096>|<MAC>...
Page 149
Common Commands 2-101 show wireless wips [configured-ap-def-essids| configured-bad-essids|fake-ap-flood|filter-list| suspicious-ap] Parameters aap-version Displays the minimum adaptive firmware version string ap [<1-48>|<MAC>| Status of the adopted access port config [<1-48>|<MAC>]] • <1-48> – Defines the index of the access port • <MAC> – Sets the MAC address of a access port •...
Page 150
2-102 Motorola RF Switch CLI Reference Guide channel-power Lists the channels and power levels available for a radio [11a|11b|11bg] • 11a – Defines the radio as 802.11a [indoor|outdoor] • 11b – Defines the radio as 802.11b • 11bg – Defines the radio as 802.11bg These options are available for all the above radio types: •...
Page 151
Common Commands 2-103 ignored-aps Displays list of ignored-aps detected by the switch known {ap statistics Displays known AP parameters. {<1-1024>}} • ap – Optional. Defines a known AP index <1-1024> • statistics – Optional. Displays known adaptive AP stats • <1-1024> – Optional. Displays adaptive ap statistics for known adaptive APs between 1-1024 mac-auth-local Displays mac-auth-local entries for index <1-1000>.
Page 152
2-104 Motorola RF Switch CLI Reference Guide mobile-unit {[<1- Displays the parameters of associated mobile units. All 8192>|<MAC>|associatio parameters are optional. n-history| • <1-8192> – Index of mobile unit association-stats|probe- • <MAC> – MAC address of mobile unit history|radio|roaming|sta • association-history {<MAC>}– Displays the association...
Page 153
Common Commands 2-105 multicast-packet-limit Displays the multicast-packet-limit non-preferred-ap- Displays non preferred AP attempt threshold attempts-threshold phrase-to-key Displays the WEP keys generated by a passphrase [wep128|wep64] • wep128 – Displays WEP128 keys <pass-phrase> • wep64 – Displays WEP64 keys • <pass-phrase> – The passphrase to generate the keys for.
Page 154
2-106 Motorola RF Switch CLI Reference Guide radio {[<1-4096>| Radio related commands. All parameters are optional. admission-control|all| • <1-4096> – Defines information on a single radio’s index beacon-table|config| • admission-control voice {<1-4096>} – Displays summary monitor-table|statistics| information for all radios that have admission control unadopted|uptime|voice] enabled.
Page 155
Common Commands 2-107 • unadopted – Displays a list of unadopted radios • uptime – Displays the uptime of all adopted radios • voice <1-4094> – Displays voice call details • <1-4094> – Optional. Defines a single radio’s index radio-group {<1-256>} Displays radios in specified group •...
Page 156
2-108 Motorola RF Switch CLI Reference Guide smart-rf Displays smart-rf related management information [calibration-status| • calibration-status – Displays smart-rf calibration status. configuration| • configuration – Displays smart-rf configuration history|radio] information • history – Displays smart-rf assignment history since last calibration •...
Page 157
Common Commands 2-109 wlan [config|statistics] Displays wireless LAN parameters. The following information is displayed: • config [<1-256>|all|enabled] – Displays the wireless LAN configuration information. All parameters optional. • <1-256> – The selected wlan • all – all wlans in the configuration •...
Page 158
2-110 Motorola RF Switch CLI Reference Guide (config-wireless) Executable Mode Displays the (config- wireless) configuration parameters and information Syntax show wireless ap [LIST|config] show wireless config [<1-1024>|LIST] show wireless radio [<1-4096>|admission-control|all| beacon-table|config|monitor-table|statistics|unadopted| uptime|voice]} show wireless wlan [config|statistics] show wireless wlan config [<1-256>|all|enabled] show wireless wlan statistics <1-256>...
Page 159
Common Commands 2-111 show wireless wlan Configures wireless LAN related parameters [config • config [<1-256>|all|enabled] – Configures wlan {all|enabled}| statistics • <1-256> – Displays wlan index detail} <1-256> • all – Displays all the configured wlans • enabled – Displays only the currently enabled wlans •...
Page 163
Common Commands 2-115 00-0E-9B-98-F9-34 1 4280716777 Unassociation 00-0E-9B-98-F9-34 1 4280717937 Association RFSwitch(config)# RFSwitch(config)#show wireless mobile-unit radio 1 index MAC-address radio type wlan vlan/tunnel ready IP- address last active Posture Status 00-0E-9B-98-F9-34 1 11g 1 vlan 1 192.168.2.45 0 Sec Listed 1 of a total of 1 mobile-units RFSwitch(config)# RFS7000>show wireless wlan config #enabled...
Page 164
2-116 Motorola RF Switch CLI Reference Guide rate-limit: wired-to-wireless: unlimited wireless-to-wired: unlimited Client Bridge Backhaul is disabled on this WLAN This WLAN is an extended WLAN NAC Mode: none RFSwitch(config)# RFS7000(config-wireless)#show wireless ap Number of access-ports adopted Number of AAPs adopted...
Common Commands 2-117 2.2.37 wlan-acl Common to all modes Displays the WLAN based access control list information Syntax show wlan-acl [<1-256>|all] Parameters wlan-acl [ <1-256>|all] Displays WLAN based access control list information • <1-256> – Displays ACLs attached to the specified WLAN ID •...
2-118 Motorola RF Switch CLI Reference Guide 2.2.38 access-list Privilege / Global Config Displays the access lists (numbered and named) configured on the switch. The numbered access list displays numbered ACLs. The named access list displays named ACL details.
Common Commands 2-119 2.2.39 aclstats Privilege / Global Config Displays the statistics of configured access lists Syntax show aclstats [access-list|vlan <1-4094>] show aclstats {<1-99>|<100-199>|<1300-1999>|<2000-2699>| <acl-name>} show aclstats vlan <1-4094> Parameters access-list {<1- Displays configured access lists. 99>|<100-199>|<1300- • <1-99> - IP standard access list 1999>|<2000-2699>| •...
2-120 Motorola RF Switch CLI Reference Guide 2.2.40 alarm-log Privilege / Global Config Displays the contents of the alarm log on the device Syntax show alarm-log {<1-65535>|acknowledged|all|count|new| severity-to-limit} show alarm-log severity-to-limit {critical| informational|major|normal|warning} Parameters alarm-log [<1-65535>| Displays the contents of the alarm log on the device.
Common Commands 2-121 2.2.41 boot Privilege / Global Config Displays the boot configuration of the device Syntax show boot Parameters None Example RFSwitch#show boot Image Build Date Install Date Version ----- -------------------- -------------------- ------ -------- Primary Oct 16 03:55:43 2008 Sep 15 00:53:56 2008 1.3.0.0-018B Secondary...
2-122 Motorola RF Switch CLI Reference Guide 2.2.42 clock Privilege / Global Config Displays the system clock Syntax show clock Parameters None Example RFSwitch#show clock Jun 01 00:51:34 UTC 2007 RFSwitch#...
Common Commands 2-123 2.2.43 debugging Privilege / Global Config Displays the debugging configuration information Syntax show debugging mstp Parameters mstp Displays the current MSTP configuration Example RFSwitch(config)#show debugging mstp MSTP debugging status: RFSwitch(config)#...
2-124 Motorola RF Switch CLI Reference Guide 2.2.44 dhcp Privilege / Global Config Displays existing DHCP server configurations Syntax show dhcp [config|status] Parameters config Displays the current DHCP server configuration status Displays whether the DHCP server is running Example...
Common Commands 2-125 2.2.45 file Privilege / Global Config Displays the file system information Syntax show file [information|systems] Parameters file Displays the filesystem information. [information|systems] • information <FILE> Displays file information • <FILE> Displays the information on file • systems Lists existing filesystems Example RFSwitch#show file systems...
Common Commands 2-127 2.2.47 password-encryption Privilege / Global Config Displays the global password encryption status Syntax show password-encryption status Parameters status Displays the existing password-encryption status Example RFSwitch#show password-encryption status Password encryption is disabled RFSwitch#...
2-128 Motorola RF Switch CLI Reference Guide 2.2.48 running-config Privilege / Global Config Displays the contents of those configuration files wherein all configured MAC and IP access lists are applied to an interface Syntax show running-config [full|include-factory] Parameters running-config...
Page 178
2-130 Motorola RF Switch CLI Reference Guide ip dhcp trust interface me1 ip address 10.1.1.100/24 interface vlan1 ip address 172.16.10.2/24 rtls rfid espi sole line con 0 line vty 0 24 RFSwitch(Config)# RFSwitch(config)#show running-config include-factory ! configuration of RFSwitch version 4.0.0.0-008D version 1.0...
Page 179
Common Commands 2-131 spanning-tree mst config name My Name no management secure ip domain-lookup service diag period 1000 service diag enable country-code us redundancy group-id 1 redundancy interface-ip 0.0.0.0 redundancy mode primary redundancy hold-period 15 redundancy heartbeat-period 5 redundancy discovery-period 30 no redundancy handle-stp enable no redundancy dhcp-server enable no redundancy enable...
Common Commands 2-133 2.2.50 sessions Privilege / Global Config Displays the list of current active open sessions on the device Syntax show sessions Parameters None Example RFSwitch#show sessions SESSION USER LOCATION IDLE START TIME Console 06:24m May 31 18:31:36 2007 ** 2 10.10.10.1 00:00m...
2-134 Motorola RF Switch CLI Reference Guide 2.2.51 startup-config Privilege / Global Config Displays the complete startup configuration script on the console Syntax show startup-config Parameters None Example RFS7000(config)#show startup-config ! configuration of RFS7000 version 4.1.0.0-003D version 1.3 aaa authentication login default local none...
Page 183
Common Commands 2-135 snmp-server user snmptrap v3 encrypted auth md5 0x22b4e8506bf66b435abdde2 b996e8100 snmp-server user snmpmanager v3 encrypted auth md5 0x22b4e8506bf66b435abd de2b996e8100 snmp-server user snmpoperator v3 encrypted auth md5 0x0153e87f2d43032f221 b1f3e340942d2 firewall dhcp-snoop-conflict-detection disable firewall dhcp-snoop-conflict-logging disable ip http server ip http secure-trustpoint default-trustpoint ip http secure-server ip ssh ip telnet...
Page 184
2-136 Motorola RF Switch CLI Reference Guide interface vlan1 ip address 172.16.10.2/24 rtls rfid espi sole line con 0 line vty 0 24 RFS7000(config)#...
Common Commands 2-137 2.2.52 upgrade-status Privilege / Global Config Displays the last image-upgrade status Syntax show upgrade-status {detail} Parameters None Example RFSwitch#show upgrade-status Last Image Upgrade Status : Successful Last Image Upgrade Time : Mon May 21 16:27:40 2007 RFSwitch#...
2-138 Motorola RF Switch CLI Reference Guide 2.2.53 mac-name User /Privilege Exec Displays the configured MAC name Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax show mac-name Parameters None Example RFSwitch(config-wireless)#show mac-name Index MAC Address...
2-140 Motorola RF Switch CLI Reference Guide 2.2.55 role Priv Exe Mode Displays existing role name Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax show role [<role-name>|mobile-units] Parameters role [<role-name>| Displays existing role name mobile-units] •...
Page 189
2.2.56 virtual-IP Global Config Mode Displays all the virtual-IPs present in the configuration Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax show virtual-ip [config|status] Parameters show virtual-ip Displays all the virtual-ip’s present in the configuration.
2-142 Motorola RF Switch CLI Reference Guide RFS7000>show virtual-ip config RFS7K-1(config)#show virtual-ip config Virtual-IP Status : Enabled Cluster Redundancy Status : Enabled Priority Selection Mode : Automatic Learning Timeout(sec) Advertisement Timeout(sec) Gratuitous ARP Timeout(sec) : 180 Virtual-IP Server Port : 51525 Switch IP : 192.168.11.4...
Page 191
Common Commands 2-143 Total Number of Peers Peer Status Information +--------------------------------------------------------- -------------+ Peer IP Status Advts Sent Advts Recvd +--------------------------------------------------------- -------------+ | 192.168.11.5 | Slave 600214 +--------------------------------------------------------- -------------+ Virtual IP Master Details +--------------------------------------------------+ | Vlan | Priority | SwitchID Virtual IP ---------------------------------------------------+ | 3232238340| 192.168.11.4|...
Page 192
2-144 Motorola RF Switch CLI Reference Guide RFS7K-1(config)#no virtual-ip vmac Removes the configured vmac on the switch...
[config|dns-server] Parameters config Displays wwan signal configuration dns-server Displays wwan DNS server addresses Example RFS6000#show wwan config Access Port Name : isp.cingular Auth-type: chap Username : isp@cingulargprs.com RFS6000# RFS6000#show wwan dns-server Preferred DNS server : 209.183.54.151 Alternate DNS server : 209.183.54.151...
[<1-256>|all] Parameters aap-wlan-acl [<1-32>|all] Applies an ACL on wlan for an aap. • <1-32> – Displays ACLs attached to the specified wlan id for aap • all – Displays ACLs attached to wlan port Example RFS6000(config)#show aap-wlan-acl 8 RFS6000(config)#...
2-148 Motorola RF Switch CLI Reference Guide 2.2.59 aap-wlan-acl-stats Privilege / Global Config Displays the acl stats for wlan Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax show aap-wlan-acl-stats Parameters aap-wlan-acl-stats Displays IP filtering wlan based statistics...
Common Commands 2-149 2.2.60 protocol-list Common to all Modes Displays the list of protocols Supported in the following platforms: • RFS7000 • RFS6000 Syntax show protocol-list Parameters show protocol-list Displays the list of protocols Example RFS6000(config)#show protocol-list Protocol Name...
2-150 Motorola RF Switch CLI Reference Guide 2.2.61 service-list Common to all Modes Displays the list of services Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax show service-list Parameters show service-list Displays the list of services...
User Exec Commands Logging in to the switch places you within the USER EXEC command mode. Typically, a login requires a user name and password. You have three login attempts before a connection attempt is refused. USER EXEC commands (available at the user level) are a subset of the commands available at the privileged level.
Page 202
Motorola RF Switch CLI Reference Guide Table 3.1 User Exec Mode Command Summary Command Description Ref. exit Ends the current mode and moves down to the page 2-3 previous mode help Describes the interactive help system page 2-4 logout Exits the EXEC mode...
Page 203
• ge <1-5> – Available only in RFS4000 • ge <1-8> – Available only in RFS6000 • me1 – Available in both RFS7000 and RFS6000 • up1 – Available only in RFS6000 • sa <1-4> – Available only in RFS7000 •...
Page 204
Motorola RF Switch CLI Reference Guide Parameters crypto [ipsec|isakmp] sa Clears IPSec/ISAKMP SAs for a given peer {<IP>} • ipsec sa {<IP> } – Clears IPSec SA’s • isakmp sa {<IP> } – Clears ISAKMP SA’s • sa – Clears all IPSec/ISAKMP SA's •...
A new context redundancy supports the cluster-cli. Any commands executed under this context are executed on all members of the cluster. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax cluster-cli enable Parameters enable Enables the cluster context Example RFSwitch>...
Motorola RF Switch CLI Reference Guide 3.1.3 disable User Exec Commands Enables the PRIV mode to use the disable command. Use the command to exit disable the PRIV mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
User Exec Commands 3.1.4 enable User Exec Commands Use the enable command to enter the PRIV mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax enable Parameters None Example RFSwitch>enable RFSwitch#...
Motorola RF Switch CLI Reference Guide 3.1.5 logout User Exec Commands Use this command instead of the command to exit the EXEC mode exit Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax logout Parameters None...
Use the command to toggle the switch paging function. Enabling this command displays the CLI command output page by page, instead of running the entire output at once. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax page...
3-11 3.1.8 quit User Exec Commands Use this command to exit the current mode and move to the previous mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax quit Parameters None Example The switch logs off upon execution of the command...
3-12 Motorola RF Switch CLI Reference Guide 3.1.9 telnet User Exec Commands Opens a telnet session Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax telnet <IP> port Parameters telnet <IP> port Defines the IP address or hostname of a remote system •...
3-13 3.1.10 terminal User Exec Commands Sets the length/number of lines displayed within the terminal window Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax terminal [length <0-512>|no [length <0-512>|width]| width <0-512>] Parameters length <0-512> Sets the number of lines on a screen no [length <0-512>|...
3-14 Motorola RF Switch CLI Reference Guide 3.1.11 traceroute User Exec Commands Traces the route to its defined destination Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax traceroute [[<IP>|<hostname>]|ip [<IP>|<hostname>]] Parameters [<IP>|<hostname>] Traces the route to a destination IP address or a hostname ip [<IP>|<hostname>]...
Privileged Exec Commands Most PRIV EXEC commands set operating parameters. Privileged-level access should be password protected to prevent unauthorized use. The PRIV EXEC command set includes commands contained within the USER EXEC mode. The PRIV EXEC mode also provides access to configuration modes, and includes advanced testing commands. The PRIV EXEC mode prompt consists of the host name of the device followed by a pound sign (#).
Page 216
Motorola RF Switch CLI Reference Guide Table 4.1 Priv Exec Mode Command Summary Command Description Ref. clear Resets switch functions to last saved configuration page 4-9 clock Configures the software system clock page 4-13 clrscr Clears the displayed screen page 2-2...
Page 217
Privileged Exec Commands Table 4.1 Priv Exec Mode Command Summary Command Description Ref. Negates a command or sets its defaults page 2-5 page Toggles the paging function page 4-39 ping Sends ICMP echo messages to a specified location page 4-40 Displays the current directory page 4-41 quit...
Privileged Exec Commands 4.1.2 archive Priv Exec Command Manages file archive operations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax archive tar /table [<FILE>|<URL>] archive tar /create [<FILE>|<URL>] [<FILE>|<DIR>] archive tar /xtract [<FILE>|<URL>] <DIR> Parameters...
Page 220
Motorola RF Switch CLI Reference Guide flash/log/startup.log flash/log/radius/ RFSwitch#dir flash:/ How to view the output tar file? Directory of flash:/ drwx 1024 Thu Apr 17 08:25:50 2007 hotspot drwx Fri Apr 8 12:27:20 2007 drwx 1024 Thu Apr 7 16:23:34 2007...
Page 221
Privileged Exec Commands 4.1.3 cd Priv Exec Command Changes the current directory Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax cd {<DIR>} Parameters <DIR> Changes current directory to DIR. This parameter is optional. When this parameter is not provided, the current directory name is displayed.
Motorola RF Switch CLI Reference Guide 4.1.4 change-passwd Priv Exec Command Changes the password of a logged user Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax change-passwd Parameters None Usage Guidelines A password must be between 8 to 32 characters in length. For security, the console does not display user entered key words or the old password and new password fields.
4-13 4.1.6 clock Priv Exec Command Configures the software system clock Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax clock set HH:MM:SS <1-31> <MONTH> <1993-2035> Parameters HH:MM:SS Sets the time in hours, minutes, and seconds <1-31>...
4-14 Motorola RF Switch CLI Reference Guide 4.1.7 cluster-cli Priv Exec Command Use this command to access the cluster-cli context. The cluster-cli context provides centralized management to configure all members of cluster from one member. Any command executed under this context is executed on all switches in the cluster.
Privileged Exec Commands 4-15 4.1.8 configure Priv Exec Command Enters the configuration mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax configure terminal Parameters terminal Enables configuration from the terminal Example RFSwitch#configure terminal Enter configuration commands, one per line. End with CNTL/Z.
4-16 Motorola RF Switch CLI Reference Guide 4.1.9 copy Priv Exec Command Copies any file (config,log,txt ...etc) from any location to the switch and vice-versa NOTE: Copying a new config file onto an existing running-config file merges it with the existing running-config on the switch. Both, the existing running-config and the new config file are applied as the current running-config.
Privileged Exec Commands 4-25 4.1.11 delete Priv Exec Command Deletes a specified file from the system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax delete [/force <FILE>|/recursive <FILE>|<FILE>] Parameters /force Forces deletion without a prompt /recursive...
4-26 Motorola RF Switch CLI Reference Guide 4.1.12 diff Priv Exec Command Displays the differences between 2 files Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax diff [<FILE>|<URL>] [<FILE>|<URL>] Parameters <FILE> The first <FILE> is the source file for the diff. The second <FILE>...
4-28 Motorola RF Switch CLI Reference Guide 4.1.13 dir Priv Exec Command View the list of files on a filesystem Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax dir {[/all|/recursive] [<DIR>|all-filesystems]} Parameters /all Lists all files...
4-30 Motorola RF Switch CLI Reference Guide 4.1.15 edit Priv Exec Command Edits a text file Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax edit <FILE> Parameters <FILE> Name of the file to be modified...
Privileged Exec Commands 4-33 4.1.18 halt Priv Exec Command Stops (halts) the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax halt Parameters None Example RFSwitch#halt Wireless switch will be halted, do you want to continue?
Privileged Exec Commands 4-35 4.1.20 logout Priv Exec Command Exits the EXEC mode and stops (halts) the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax logout Parameters None Example RFSwitch#logout RFSwitch release 3.0.0.0-200B Login as 'cli' to access CLI.
4-36 Motorola RF Switch CLI Reference Guide 4.1.21 mkdir Priv Exec Command Creates a new directory in the filesystem Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax mkdir <DIR> Parameters <DIR> Directory name Example RFSwitch#mkdir TestDIR...
Privileged Exec Commands 4-37 4.1.22 more Priv Exec Command Displays the contents of a file Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax more <FILE> Parameters <FILE> Displays the contents of the file Example RFSwitch#more flash:/log/messages.log Sep 08 12:27:30 2006: %PM-5-PROCSTOP: Process "radiusd"...
Page 252
4-38 Motorola RF Switch CLI Reference Guide User 'admin' logged in with role of ' superuser' from auth source 'local' Sep 08 12:28:01 2006: %NSM-6-DHCPDEFRT: Default route with gateway 157.235.208.246 learnt via DHCP Sep 08 12:28:01 2006: %NSM-6-DHCPIP: Interface vlan1 acquired IP address 157.235.208.93/24 via DHCP...
Priv Exec Command Toggles switch paging. Enabling this command displays the command output page by page instead of running the entire output at once. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax page Parameters None...
Privileged Exec Commands 4-41 4.1.25 pwd Priv Exec Command View the contents of the current directory Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch#pwd flash:/ RFSwitch#...
4-42 Motorola RF Switch CLI Reference Guide 4.1.26 quit Priv Exec Command Exits the current mode and moves to the previous mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax quit Parameters None Example RFSwitch#quit RFSwitch release 4.0.0.0-XXXX...
Privileged Exec Commands 4-43 4.1.27 reload Priv Exec Command Halts the switch and performs a warm reboot Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax reload Parameters None Example RFSwitch#reload...
4-44 Motorola RF Switch CLI Reference Guide 4.1.28 rename Priv Exec Command Renames a file in the existing filesystem Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax rename <FILE> <FILE> Parameters <FILE> Specifies the file to rename. The first <FILE> is the old file name.
4-45 4.1.29 rmdir Priv Exec Command Deletes an existing file from the file system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax rmdir <DIR> Parameters <DIR> Defines the name of the directory to delete Example...
4-46 Motorola RF Switch CLI Reference Guide 4.1.30 telnet Priv Exec Command Opens a telnet session Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax telnet <IP> {<port>} Parameters telnet <IP> {<port>} Defines the IP address or hostname of a remote system •...
4-47 4.1.31 terminal Priv Exec Command Sets the length/number of lines displayed within the terminal window Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax terminal [length <0-512>|no [length <0-512>|width]| width <0-512>] Parameters length <0-512> Sets the number of lines on a screen •...
4-48 Motorola RF Switch CLI Reference Guide 4.1.32 traceroute Priv Exec Command Traces a route to a destination Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax traceroute [[<IP>|<hostname>]|ip [<IP>|<hostname>]] Parameters [<IP>|<hostname>] Traces the route to a destination IP address or a hostname ip [<IP>|<hostname>]...
Privileged Exec Commands 4-49 4.1.33 upgrade Priv Exec Command Upgrades the software image Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax upgrade <URL> {background} Parameters <URL> Location of the target firmware image used in upgrade background Optional.
Page 264
4-50 Motorola RF Switch CLI Reference Guide kernel/ISR 100.00%) Sep 08 15:58:44 2009: %PM-4-PROCNORESP: Process "logd" is not responding Jan 08 15:58:44 2009: %PM-4-PROCNORESP: Process "logd" is not responding Jan08 15:58:44 2009: %PM-4-PROCNORESP: Process "logd" is not responding Jan 08 15:58:44 2009: %PM-4-PROCNORESP: Process "logd"...
4-54 Motorola RF Switch CLI Reference Guide 4.1.36 format Priv Exec Command Formats file system Supported in the following platforms: • RFS7000 Syntax format cf: Parameters Formats compact flash Example RFSwitch#format cf:...
Global Configuration Commands The term global is used to indicate characteristics or features effecting the system as a whole. Use the Global Configuration Mode to configure the system globally, or enter specific configuration modes to configure specific elements (such as interfaces or protocols).
Motorola RF Switch CLI Reference Guide 5.1 Global Configuration Commands Table 5.1 summarizes the Global Config commands Table 5.1 Global Config Mode Command Summary Command Description Ref. Configures the current authentication, authorization page 5-5 and accounting (aaa) login settings access-list...
Page 271
Global Configuration Commands Table 5.1 Global Config Mode Command Summary Command Description Ref. license Sets license management commands page 5-58 line Configures a terminal line page 5-59 local Sets the username and password for local user page 5-60 authentication logging Modifies message logging facilities page 5-61 Configures MAC access-lists...
Page 272
Motorola RF Switch CLI Reference Guide Table 5.1 Global Config Mode Command Summary Command Description Ref. spanning-tree Configures spanning tree commands page 5-107 timezone Configures the timezone page 5-111 traffic-shape Configures traffic shaping page 5-112 username Establishes user name authentication...
5.1.1 aaa Global Configuration Commands Configures the current Authentication, Authorization and Accounting (AAA) login settings Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax aaa [authentication|nas|vpn-authentication] aaa authentication login default [local|none|radius] aaa nas <name> aaa vpn-authentication [primary|secondary] <IP> key [0 <secret>|2 <secret>|<secret>] {authport <1024-65535>}...
Page 274
Motorola RF Switch CLI Reference Guide vpn-authentication Sets the configuration for VPN authentication using [primary|secondary] RADIUS. [<IP> key [0 <secret>| • primary – Sets the configuration for the primary server. 2 <secret>|<secret>] • secondary – Sets the configuration for the secondary {authport <1024-65535>}...
Extended ACLs, and the name can be any valid alphanumeric string (not exceeding 64 characters). With numbered ACLs, the rule parameters have to be specified on the same command line along with the ACL identifier. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax access-list [<1-99>|<100-199>|<1300-1999>|<2000-2699>] For Standard IP ACLs: access-list [<1-99>|<1300-1999>] [deny|permit|mark]...
Page 277
Global Configuration Commands Parameters access-list Adds a standard access list entry. [<1-99>|<1300-1999>] • [<1-99>|<1300-1999>] – Defines access list number from [permit|deny] 1-99 or 1300-1999 [<IP/MASK>|any| • [deny|permit] – Defines action types on an ACL. host <IP>] {[rule- • [<IP/MASK>| host <IP>| any] – <IP/MASK> is the precedence <1-5000>...
Page 278
5-10 Motorola RF Switch CLI Reference Guide access-list [<1- Adds a standard access list entry. 99>|<1300-1999>] • [<1-99>|<1300-1999>] – Defines access list number from mark [8021p <0- 1-99 or 1300-1999 7>|dscp <0-63>|tos • mark – Marks a packet. The action type mark <0-255>] [<IP/...
Page 279
Global Configuration Commands 5-11 access-list Adds an Extended IP access list entry. [<100-199>|<2000- • (<100-199>|<2000-2699>) – For ICMP extended ACLs, the 2699>] [permit|deny] ACL must be between 2000-2699 [icmp|ip|tcp|udp] • [deny|permit] – Defines action types on an ACL. [<IP/MASK>|any| • [icmp|ip|tcp|udp] – The protocol type for the extended host <IP>] {[rule- ACL entry precedence <1-5000>...
Page 280
5-12 Motorola RF Switch CLI Reference Guide access-list Adds an Extended IP access list entry. [<100-199>|<2000- • (<100-199>|<2000-2699>) – For ICMP extended ACLs, the 2699>] mask [8021p ACL must be between 2000-2699 <0-7>|dscp <0-63>|tos • mark – Marks a packet. The action type mark <0-255>]...
Page 281
Global Configuration Commands 5-13 Use an access list command under the global configuration to create an access list. The switch supports port, router and WLAN ACLs • When the access list is applied on an Ethernet port, it becomes a port ACL •...
5-16 Motorola RF Switch CLI Reference Guide 5.1.4 banner Global Configuration Commands Defines a login banner for the switch. Use to delete a previously configured {no} banner banner. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax {no} banner motd [<message>|default]...
Global Configuration Commands Reboots the switch with an image in the mentioned partition (either the primary or secondary partition) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax boot system [primary|secondary] Parameters system Specifies the boot image used after reboot [primary|secondary] •...
• RFS4000 SWITCH NOTE: The interfaces mentioned below are supported in the following platforms: • ge <index> – RFS7000 and RFS4000 supports 4 GEs and RFS6000 supports 8 GEs • sa <1-4> – Supported on RFS7000, and sa <1-6> on RFS4000 •...
Page 287
• sa <1-4> – Static Aggregate interface index. Only supported on RFS7000 • me1 – Fast Ethernet interface • up1 – WAN interface. Only available on RFS6000 and RFS4000 • ageing-time [0|<10-1000000>] – The time duration a learned MAC address persists after the last update •...
5-21 5.1.7 country-code Global Configuration Commands Sets the country of operation Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax {no} country-code <code> Parameters <code> A two (2) letter ISO-3166 country code. To view country codes, use the show wireless country-code-list command.
5-22 Motorola RF Switch CLI Reference Guide 5.1.8 crypto Global Configuration Commands Use crypto to define system level local ID for ISAKMP negotiation and to enter the ISAKMP Policy, ISAKMP Client or ISAKMP Peer command set. NOTE: moves to the crypto isakmp(policy)Priority instance.
Page 292
5-24 Motorola RF Switch CLI Reference Guide Parameters ipsec (security- Configures IPSEC policies. association| transform- • security-association – Defines the security association set) parameter used to define its lifetime • lifetime (kilobyte | seconds) – The lifetime of IPSEC security association. It can be defined in either: kilobytes –...
Page 293
Global Configuration Commands 5-25 isakmp Configures the Internet Security Association and Key Management Protocol (ISAKMP) policy. [client|keepalive|key| • client configuration (group) (default) – Leads to the peer|policy] config-cryptogroup instance For more details see Crypto-group Instance on page 7-1. • keepalive <10-3600> – Sets a keepalive interval for use with remote peers.
Page 294
5-26 Motorola RF Switch CLI Reference Guide Authentication key management functions. [export|generate|import| • export rsa <name> URL [tftp|ftp] – Exports a keypair related configuration zeroize] • generate rsa <name> <1024-2048> – Generates a keypair • <1024-2048> – Size of keypair in bits •...
Page 295
Global Configuration Commands 5-27 pki [authenticate|enroll| Configures certificate parameters. The public key export|import|trustpoint] infrastructure is a protocol that creates encrypted public keys using digital certificates from certificate authorities. The PKI ensures each online party is who they claim to be. •...
Page 296
5-28 Motorola RF Switch CLI Reference Guide Usage Guidelines Follow the table to calculate how many character are required to add the key size for authentication and encryption. This is used while configuring Manual IPSEC only. For example, To create a key with authentication type as ESP-SHA and encryption type as AES-192, enter 20+16=36 characters.
Page 297
Global Configuration Commands 5-29 RFSwitch(config-crypto-map)#set session-key inbound esp 257 cipher 12345678901234567890123456789012345678901234 authenticator 12345678901234567890123456789012345678901234 RFSwitch(config-crypto-map)#set session-key outbound esp 258 cipher 12345678901234567890123456789012345678901234 authenticator 12345678901234567890123456789012345678901234 RFSwitch(config-crypto-map)#exit RFSwitch(config)#interface vlan11 RFSwitch(config-if)#crypto map manual RFSwitch(config-if)#show running-config ! configuration of RFS7000 version 1.2.0.0-024D version 1.1 aaa authentication login default none service prompt crash-info username "admin"...
Page 299
Global Configuration Commands 5-31 set transform-set tfset-manual ........................interface vlan11 ip address 11.1.1.2/24 crypto map manual ........................RFSwitch(config-if)# Usage Guidelines A peer address can be deleted with a wrong isakmp value. Crypto currently matches only the IP address when a command is issued RFSwitch(config)#crypto isakmp key 12345678 address 4.4.4.4 RFSwitch(config)#show running-config...
(trusted network) using IPSec VPN functionality. A Motorola client is associated to a WLAN (say wlan1) attached to vlan2 on the switch. vlan2 is on subnet 10.1.1.x and is running a DHCP server that assigns IP addresses for this subnet.
Page 301
Global Configuration Commands 5-33 In case the client is VPN enabled, it initiates a connection with the VPN server on our switch, the “conversation” that occurs between the peers consists of device authentication via Internet Key Exchange (IKE), followed by user authentication using IKE Extended Authentication (Xauth), push client relate configuration (using Mode Configuration), and IPsec security association (SA) creation.
Page 302
5-34 Motorola RF Switch CLI Reference Guide 4. Create and configure another VLAN interface named vlan3. RFSwitch(config)#interface vlan 3 RFSwitch(config-if)#ip address dhcp Use the commands below to configure IPSec VPN on the switch: 1. Create an Extended ACL. RFSwitch(config-ext-nacl)#ip access-list extended 101 2.
Global Configuration Commands 5-35 5.1.8.2 Use Case 2: Configuring Site-to-Site VPN Intranets use unregistered addresses connected over the public internet by site-to-site VPN. In this scenario, NAT is required for the connections to the public internet. However NAT is not required for traffic between the two intranets, which can be transmitted using a VPN tunnel over the public Internet.
Page 305
Global Configuration Commands 5-37 RFSwitch(config-crypto-map)#set transformset TFSET RFSwitch(config-crypto-map)#set security-association lifetime seconds 3600 f.Associate the crypto map with a VLAN interface. RFSwitch(config)#interface vlan1 RFSwitch(config-if)#ip address 15.1.1.20/24 RFSwitch(config-if)#crypto map THIRDMAP RFSwitch(config-if)#interface vlan2100 RFSwitch(config-if)#ip address 13.1.1.20/24 RFSwitch(config-if)#ip route 0.0.0.0/0 15.1.1.2...
Page 306
5-38 Motorola RF Switch CLI Reference Guide 5.1.9 do Global Configuration Commands Runs commands from either the User Exec or Priv Exec mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax do <privilege mode commands>...
Global Configuration Commands 5-39 5.1.10 end Global Configuration Commands Ends the current mode and changes to the EXEC mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None. Example RFSwitch(config)#end RFSwitch#? Priv Exec commands:...
5-40 Motorola RF Switch CLI Reference Guide 5.1.11 errdisable Global Configuration Commands Enables the timeout mechanism for the port to be enabled back after an error Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax errdisable recovery [cause bpduguard|interval <10-1000000>]...
5-41 5.1.12 ftp Global Configuration Commands Configures the switch as an FTP server Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ftp [enable|password|rootdir|username] ftp password [0 <secret>|1 <secret>|<secret>] ftp rootdir <DIR> ftp username <LINE> Parameters...
Page 310
5-42 Motorola RF Switch CLI Reference Guide Usage Guidelines NOTE: The string size of encrypted password (option 1, Password is encrypted with SHA1 algorithm) must be exactly 40 characters. Example RFSwitch(config)#ftp enable RFSwitch(config)#...
5-43 5.1.13 hostname Global Configuration Commands Changes the system’s network name Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax hostname <host-name> Parameters <host-name> The name of the switch. This name is displayed when the switch is accessed from any network.
SWITCH NOTE: The interfaces mentioned below are supported in the following platforms: • ge <index> – RFS7000 supports 4 GE’s and RFS6000 supports 8 GE’s • sa <1-4> – Only supported with RFS7000 • me1 – Only supported with RFS7000 and RFS6000 •...
Page 313
Gigabit Ethernet interface (4 for RFS7000 and 8 for RFS6000) Fast Ethernet interface sa <1-4> Static Aggregate interface (in RFS7000 only) WAN interface (in RFS6000 only) vlan <1-4094> Defines the VLAN interface wwan( Supported on Defines Wireless WAN Interface RFS4000 and RFS6000)
Page 314
5-46 Motorola RF Switch CLI Reference Guide 5.1.15 ip Global Configuration Commands Configures a selected Internet Protocol (IP) component Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 NOTE: Using moves you to the access-list extended instance. For more information, see...
Page 315
Global Configuration Commands 5-47 ip dhcp excluded-address <IP-range-low> {<IP-range-high>} ip dhcp option <option-name> <option-code> [ascii|ip] ip dhcp ping timeout <1-10> ip dhcp pool <pool-name> ip domain-name <domain-name> ip dos [ascend|bcast-mcast-icmp|chargen|enable|fraggle| ftp-bounce|invalid-protocol|option-route| router-solicit|router-advt| smurf|snork|tcp-intercept|tcp-max-incomplete|twinge] log [<0-8>|alerts|critical|debugging|emergencies|error| informational|none|notifications|warnings] ip http [secure-server|secure-trustpoint|server] ip http [secure-server|server] ip http secure-trustpoint <trustpoint-name>...
Page 316
5-48 Motorola RF Switch CLI Reference Guide ip nat inside destination static <IP> <port> [tcp|udp] <outside-global-IP> {<outside-port>} ip nat inside destination static <IP> {<outside-global-IP> <outside-port>} ip nat inside source list <acl-name> interface [<interface- name>|vlan <1-4094>] overload ip nat inside source static <local-IP> <outside-global-IP>...
Page 317
Global Configuration Commands 5-49 ip dhcp [bootp|class| DHCP server configuration excluded-address|option| • bootp ignore – Defines the BOOTP specific configuration. ping|pool] • ignore – Configures the DHCP server to ignore BOOTP requests • class <class-name> – Defines a DHCP class and enters the DHCP class configuration mode •...
Page 318
5-50 Motorola RF Switch CLI Reference Guide http [secure-server| Hyper Text Transfer Protocol (HTTP) configuration secure-trustpoint| • secure-server – Sets the device to start the Secure HTTP server] Server (HTTPS) • secure-trustpoint <trustpoint-name> – Sets the name of the trustpoint used for secure connection to <trustpoint- name>...
Page 319
Global Configuration Commands 5-51 nat [inside|outside] Defines Network Address Translation (NAT) configuration [destination|source] values. These following commands are possible for NAT • ip nat [inside|outside] destination static <IP> <port> [tcp|udp] <outside-global-IP> {<outside-port>} – Sets the parameters for translation for inside destination •...
Page 321
Global Configuration Commands 5-53 dos [ascend| Configures the Denial of Service (DOS) attack parameters. bcast-mcast-icmp| • ascend – Enables Ascend DoS checks chargen|enable|fraggle| • bcast-mcast-icmp – Detects Broadcast/Multicast Icmp ftp-bounce| traffic as attack invalid-protocol| • chargen – Enables chargen DoS checks option-route|router-advt| •...
Page 322
5-54 Motorola RF Switch CLI Reference Guide • tcp -max-incomplete – Configures the maximum half- open TCP connections in the system • high <1-1000> – Sets the upper threshold value between 1 and 1000 • low <1 - 1000> – Sets the lower threshold value...
Page 323
Global Configuration Commands 5-55 igmp snooping Configures IGMP Snooping parameters. {[querier|unknown- • unknown-multicast-fwd – Optional. Forwards packets multicast-fwd|vlan]} from unregistered multicast servers • querier {[address|max-response-time|query- interval|timer|version]}}– Configures IGMP querier. All options are optional • address <IP> – Sets GMP querier source IP address •...
Page 324
5-56 Motorola RF Switch CLI Reference Guide Usage Guidelines 1 1. Use the command along with ip to undo any IP based configuration. [no] ip(access-list|default-gateway|dos|dhcp|domain-lookup| domain-name|http|local|name-server|nat|route|routing|ssh|telnet) 2. When using the parameter, enter the following contexts: ip access-list • ext-nacl – Extended ACL. For more information, see Chapter 14, Extended ACL Instance •...
Page 325
Global Configuration Commands 5-57 5. The switch leads you to a new mode (config-dhcp-class). Use this mode to add an address range used with the DHCP class associated with the pool. RFSwitch(config-dhcp-class)#address range 11.22.33.44 Example RFSwitch(config)#ip access-list extended TestACL RFSwitch(config-ext-nacl)# RFSwitch(config)#ip access-list standard TestStdACL RFSwitch(config-std-nacl)# RFSwitch(config)#ip dhcp pool TestPool...
5-58 Motorola RF Switch CLI Reference Guide 5.1.16 license Global Configuration Commands Adds a feature license Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax license <feature> <license-key> Parameters <feature> The feature for which the license is to be added <license-key>...
Configures the terminal line Opens the config-line mode, where you can configure the various parameters for the selected terminal. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax line [console|vty] line console <0-0> line vty <0-871> {<0-871>} Parameters line console <0-0>...
5-60 Motorola RF Switch CLI Reference Guide 5.1.18 local Global Configuration Commands Sets the username and password for local user authentication Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax local username <username> password [<password>|0 <password>| 2 <password>]...
Page 331
Global Configuration Commands 5-63 monitor [<0-7>|alerts| Sets the terminal lines logging level critical|debugging| emergencies|errors| informational| notifications|warnings] Enables the logging of system messages snmp-set enable Set logging for SNMP set requests • enable – Enable SNMP set logging syslog [<0-7>|alerts| Sets the syslog servers logging level critical|debugging| emergencies|errors| informational|...
5-64 Motorola RF Switch CLI Reference Guide 5.1.20 mac Global Configuration Commands Configures MAC access lists (goes to the MAC ACL mode) For more information on this mode, see Chapter 16, Extended MAC ACL Instance. Supported in the following platforms: •...
5-65 5.1.21 mac-address-table Global Configuration Commands Configures the MAC address table Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax mac-address-table aging-time [0|<10-1000000>] Parameters aging-time The duration for which a learned mac address persists after [0|<10-1000000>] the last update •...
5-66 Motorola RF Switch CLI Reference Guide 5.1.22 mac-name Global Configuration Commands Sets a name to the MAC address Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax mac-name <MAC> <mac-name> Parameters <MAC> <name> The MAC address to set a ease-of-use name for <mac-name>...
Global Configuration Commands Sets management interface properties Limits local access (through web/telnet) to management interfaces only. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax management secure Parameters secure Limits local access (Web/Telnet etc.) to the management...
5-68 Motorola RF Switch CLI Reference Guide 5.1.24 ntp Global Configuration Commands Configure Network Time Protocol (NTP) values Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ntp [access-group|authenticate|authentication-key|autokey| broadcast|broadcastdelay|master|peer|server|trusted-key] ntp access-group [peer|query-only|serve|serve-only] [<1-99>|<100-199>|<1300-1999>|<2000-2699>] ntp authenticate ntp authentication-key <key>...
Page 337
Global Configuration Commands 5-69 Parameters access-group Controls NTP access. [peer|query-only|serve| • peer – Provides full access serve-only] [<1-99>| • query-only – Allows only control queries <100-199>|<1300-1999>| • serve – Provides server and query access <2000-2699>] • serve-only – Provides only server access •...
Page 338
5-70 Motorola RF Switch CLI Reference Guide broadcast Configures the NTP broadcast service. [client|destination] • client – Listens to NTP broadcasts • destination <IP> {[key <1-65534>|version <1-4>]}– Configures broadcast destination address • IP Address – Defines the destination broadcast IP address •...
Page 339
Global Configuration Commands 5-71 • prefer {version <1-4>} – Sets the preference for autokey. Optionally set the NTP version to use • version <1-4> {prefer} – Sets the NTP version to use. Optionally set this peer as preferred peer server Configures the NTP server.
Page 340
5-72 Motorola RF Switch CLI Reference Guide RFSwitch(config)#ntp peer TestPeer autokey ? prefer Prefer this peer when possible version Configure NTP version <cr> RFSwitch(config)#ntp peer TestPeer autokey prefer ? version Configure NTP version <cr> RFSwitch(config)#ntp peer TestPeer autokey prefer version ? <1-4>...
5-73 5.1.25 prompt Global Configuration Commands Configures and sets the systems prompt Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax prompt <prompt> Parameters <prompt> Enter the new prompt displayed by the system. The following operational modifiers are available.
5-74 Motorola RF Switch CLI Reference Guide 5.1.26 radius-server Global Configuration Commands Enters the RADIUS server mode, the system prompt changes from the default config mode to the RADIUS server mode Supported in the following platforms: • RFS7000 • RFS6000 •...
Page 343
Global Configuration Commands 5-75 retransmit <1-100> Specifies the number of retries to active server. • <0-100> – Number of retries for a transaction (default is 3) timeout <1-1000> Time to wait for a RADIUS server to reply. • <1-1000> – Wait time (default 5 seconds) Usage Guidelines The RADIUS server host is used to configure RADIUS server details.
Global Configuration Commands 5-77 5.1.28 redundancy Global Configuration Commands Configures redundancy group parameters Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax redundancy [auto-revert|auto-revert-period| critical-resource-ip|dhcp-server|discovery-period| dynamic-ap-load-balance|enable|group-id|handle-stp| heartbeat-period|hold-period|interface-ip|manual-revert| member-ip|mode] redundancy auto-revert enable redundancy auto-revert-period <1-1800> redundancy critical-resource-ip <IP>...
Page 346
5-78 Motorola RF Switch CLI Reference Guide Parameters auto-revert enable Enables auto-revert auto-revert-period Sets the redundancy auto-revert delay interval in <1-1800> minutes. The default is 5 minutes critical-resource-ip Sets critical resource IP address <ip_address> • <ip_address> – IP address of the critical resource...
Page 347
Global Configuration Commands 5-79 interface-ip <IP> Sets the redundancy interface IP address manual-revert Reverts standby to non-active mode member-ip <IP> Adds a member with the IP <IP> to this redundancy group mode [primary|standby] Sets the mode to either primary or standby Example RFSwitch(config)#redundancy discovery-period 20 RFSwitch(config)#...
5-80 Motorola RF Switch CLI Reference Guide 5.1.29 role Global Configuration Commands Configures role parameters Opens the role configuration mode to enable further configuration of the (confi-role) role. For more information, see Chapter 26, Role Instance. NOTE: Avance Security Licence must be installed for Role Based Firewall to work.
Page 349
Global Configuration Commands 5-81 RFSwitch(config-role)# ? RFSwitch(config)#role assignment immediate enable RFS7000(config)#show role role officeuser 10 authentication-type any encryption-type any ap-location exact "office" essid office mu-mac any group any role globaluser 11 authentication-type any encryption-type any ap-location any essid any mu-mac any group any role default-role 10001 authentication-type any...
5-82 Motorola RF Switch CLI Reference Guide 5.1.30 rtls Global Configuration Commands Configures Real Time Location System (RTLS) parameters This enables the Switch to provide complete visibility to the location of assets and thereby enabling location based service. Supported in the following platforms: •...
Retrieves system data (tables, log files, configuration, status and operation) for debugging and problem resolution Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 To view the command of User Exec and Priv Exec Mode, refer to Chapter 2,...
Page 352
5-84 Motorola RF Switch CLI Reference Guide diag [enable|limit|period| Services diagnostics configuration. tech-support-period| • enable – Enable in service diagnostics tech-support-url] • limit – Displays diagnostic limit command • period <100-30000> – Sets diagnostics period • tech-support-period <10-10080> – Sets the tech support period.
Page 353
Global Configuration Commands 5-85 set [command- Sets service parameters. history|reboot- • command-history <10-300> – Sets the number of history|upgrade-history] previous commands to remember. Default 200 • reboot-history <10-100> – Sets the number of previous reboot details to remember. Default 50 •...
Page 356
5-88 Motorola RF Switch CLI Reference Guide Parameters authenticate enable Enables SMTP Server authentication enable traps [all| Enables SMTP notification for traps dhcp-server|diagnostics| • all – Enables SMTP Notification for all traps miscellaneous|mobility| • dhcp-server [dhcpServerDown|dhcpServerUp]– Enables nsm|radius-server| dhcp-server traps redundancy|snmp •...
Page 357
Global Configuration Commands 5-89 • miscellaneous [caCertExpired|lowFsSpace|periodicHeartbeat| processMaxRestartsReached|savedConfigModified| serverCertExpired|switchEvent] – Enables miscellaneous traps • caCertExpired – CA certificate has expired • lowFsSpace – Available file system space is lower than the limit • periodicHeartbeat – Periodic Heartbeat • processMaxRestartsReached – Process has reached max restart.
Page 358
5-90 Motorola RF Switch CLI Reference Guide • nsm [dhcpIPChanged] – Enables nsm traps and changes the DHCP IP • radius-server [radiusServerDown|radiusServerUp] – Enables radius-server traps • radiusServerDown – Radius Server is down • radiusServerUp – Radius Server is up •...
Page 359
Global Configuration Commands 5-91 • wireless [ap-detection|ids|radio|self-healing|station| wlan] – Enables wireless traps • ap-detection [externalAPDetected| externalAPRemoved] – Enables wireless AP detection traps • externalAPDetected – Detects an external AP • externalAPRemoved – Removes an external AP • id [muExcessiveEvents|radioExcessiveEvents| switchExcessiveEvents] – Enables wireless IDS traps •...
Page 360
5-92 Motorola RF Switch CLI Reference Guide • associated – Wireless station associated • deniedAssociationAsPortCapacity Reached – Wireless station denied association due to port capacity reached • deniedAssociationOnCapability – Wireless station denied association due to unsupported capability • deniedAssociationOnErr – Wireless station denied association due to internal error •...
Page 361
Global Configuration Commands 5-93 • wlan [vlanUserLimitReached|webPortalUnavailable| webPortalUnconnected||webPortalUnreachable] – Enables wireless wlan traps when: • vlanUserLimitReached – WLAN-VLAN user limit is reached • webPortalUnavailable – Web portal unavailable • webPortalUnconnected – Web portal disconnected • webPortalUnreachable – Web portal unreachable password 0 <password>...
Page 368
5-100 Motorola RF Switch CLI Reference Guide deniedAssociationOnSpectrum| deniedAssociationOnSSID|deniedAuthent ication| disassociated|radiusAuthFailed| tkipCounterMeasures|vlanChanged]} – Enables wireless station traps • associated– Wireless station associated • deniedAssociationAsPortCapacityReached – Wireless station denied association - port capacity reached • deniedAssociationOnCapability – Wireless station denied association due to unsupported capability •...
Page 369
Global Configuration Commands 5-101 • tkipCounterMeasures – TKIP counter measures invoked • vlanChanged – Wireless station VLAN ID has changed • wlan {[vlanUserLimitReached|webPortal Unavailable|webPortalUnreachable|webPortal Unconnected]}– Enables wireless wlan traps • vlanUserLimitReached – WALN/VLAN user limit reached • webPortalUnavailable – Webportal is unavailable •...
Page 370
5-102 Motorola RF Switch CLI Reference Guide snmp-server enable traps Modifies wireless-stats rate traps wireless-statistics [mesh| • mesh [avg-bit-speed-less-than| min-packets|mobile-unit| avg-retry-greater-than|avg-signal-less-than| radio|wireless-switch|wlan] gave-up-percent-greater-than| nu-percent-greater-than| num-mobile-units-greater-than| pktsps-greater-than|tput-greater-than| undecrypt-percent-greater-than] – Modifies mesh rate traps • avg-bit-speed-less-than – Average bit speed in Mbps between <0.00> and <54.00>...
Page 371
Global Configuration Commands 5-103 • tput-greater-than – Throughput in Mbps is greater than 0.00 and less than or equal to 100000.00 • undecrypt-percent-greater-than – Percentage of undecryptable pkts is greater than 0.00 and less than or equal to 100.00 • min-packets <1-65535> – Minimum packets required for sending the trap •...
Page 372
5-104 Motorola RF Switch CLI Reference Guide • pktsps-greater-than – Packets per sec is greater than 0.00 and less than or equal to 100000.00 • tput-greater-than – Throughput in Mbps is greater than 0.00 and less than or equal to 100000.00...
Page 373
Global Configuration Commands 5-105 user [snmpmanager| Defines a user who can access the SNMP engine. snmpoperator|snmptrap] • snmpmanager v3– Manager user • v3 [auth|encrypted] – User using v3 security model • auth md5 <password> – Sets authentication parameters for the user •...
Global Configuration Commands 5-107 5.1.34 spanning-tree Global Configuration Commands Configures spanning-tree commands Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax spanning-tree [mst|portfast] spanning-tree mst [<0-15> priority <0-61440>| cisco-interoperability [enable|disable]|configuration| forward-time <4-30>|hello-time <1-10>|max-age <6-40>| max-hops <7-127>]...
Page 376
5-108 Motorola RF Switch CLI Reference Guide Parameters mst [<0-15> priority Enables the Multiple Spanning Tree Protocol on a bridge <0-61440>| • <0-15> priority <0-61440> – Set the bridge priority for an cisco-interoperability MST instance to the value specified. Use the no...
Page 377
Global Configuration Commands 5-109 • max-age <6-40> – Max-age is the maximum time in seconds for which (if a bridge is the root bridge) a message is considered valid. This prevents the frames from looping indefinitely. The value of max-age must be greater than twice the value of hello time plus one, but less than twice the value of forward delay minus one The permissible range for max-age is 6-40 seconds.
Page 378
5-110 Motorola RF Switch CLI Reference Guide portfast Enables the portfast feature on a bridge. It has the [bpdufilter|bpduguard] following options: default • bpdufilter default – Use the command to bpdu-filter set the portfast BPDU filter for the port. Use the parameter with this command to revert the port BPDU filter value to default.
5-111 5.1.35 timezone Global Configuration Commands Configures switch timezone settings Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax timezone <timezone> Parameters <timezone> Press <tab> to traverse a list of files. This displays a list of files containing timezone information.
Page 385
Global Configuration Commands 5-117 username admin password 1 8e67bb26b358e2ed20fe552ed6fb832f397a507d username admin privilege superuser username operator password 1 fe96dd39756ac41b74283a9292652d366d73931f username Jiri password 1 399f01e13e372ba2dc02f37d869021873e60aa85 3. The password in the above running configuration is displayed in an encrypted format even though it was entered as plain text in Step 1.
5-118 Motorola RF Switch CLI Reference Guide 5.1.38 vpn Global Configuration Commands Configures VPN authentication settings Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax vpn authentication-method [local|radius] Parameters authentication-method Selects the authentication scheme. [local|radius] • local – Used for user based authentication •...
This command moves you to the instance. For more information, see config-wireless Chapter 20, Wireless Instance. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax wireless Parameters None Usage Guidelines The wireless command is used to enter the config-wireless instance wherein you can configure wireless parameters.
5-120 Motorola RF Switch CLI Reference Guide 5.1.40 wlan-acl Global Configuration Commands Applies an ACL on a WLAN index Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax wlan-acl <1-256> [<1-99>|<100-199>|<1300-1999>| <2000-2699>|<acl-name>] [in|out] Parameters WLAN index number <1-256>...
Page 389
Global Configuration Commands 5-121 When a packet goes out of a access port, it becomes outbound traffic to the wireless LAN index. Apply an ACL to a WLAN index in outbound direction to filter traffic from both wired and wireless interfaces. can be attached both in the inbound and outbound directions.
Page 390
5-122 Motorola RF Switch CLI Reference Guide ip access-list standard stdacl3 deny host 30.0.0.14 rule-precedence 54 no access-list stdacl wlan-acl 5 stdacl1 in wlan-acl 6 stdacl2 in The stdacl must be detached from the interface to which it was associated and stdacl3 must be attached to that interface.
Global Configuration Commands 5-123 5.1.41 network-element-id Global Configuration Commands Use this command to set system’s network-element-ID Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax network-element-id <element-id> Parameters <element-id> Specifies system’s network element ID Example RFSwitch(config)#network-element-id test...
5-124 Motorola RF Switch CLI Reference Guide 5.1.42 firewall Global Configuration Commands Use this command to set system’s network-element-ID Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax firewall [802.2-encapsulation|dhcp-snoop-conflict- detection|dhcp-snoop-conflict-logging|clamp|enable|flow| virtual-defrag|vlan-stacking] firewall enable firewall 802.2-encapsulation permit...
Page 393
Global Configuration Commands 5-125 clamp [path-mtu| Configures wireless firewall tcp-mss] • clamp [path-mtu|tcp-mss] – Displays clamp value • path-mtu – Displays limit discovered path-mtu • tcp-mss – Displays limit TCP to inner path-mtu dhcp-snoop-conflict- Displays IP Address, MAC Address conflict detection detection disable based on dip-snoop-table •...
Page 394
1st fragment to a value between 8 and 1500 vlan-stacking permit Configures 802.1q VLAN stacking. • permit – Permits 802.1q VLAN stacking that can bypass the firewall. Motorola does not recommend the use of this option Example RFSwitch(config)#firewall clamp RFSwitch(config)#...
5-127 5.1.43 virtual-ip Global Configuration Commands Displays virtual-ip configuration of the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax virtual-ip [<A.B.C.D/M>|advt-timeout <1-5>|enable| garp-timeout <30-600>|learning-timeout <2-5>|priority|vmac] virtual-ip <A.B.C.D/M> vlan <1-4096> virual-ip priority [<1-256>|auto] virual-ip vmac <AA-BB-CC-DD-EE-FF>...
Page 396
5-128 Motorola RF Switch CLI Reference Guide vmac Virtual MAC to be used by the master <AA-BB-CC-DD-EE-FF> • <AA-BB-CC-DD-EE-FF> – Allowed VMACs: from 00:15:70:88:8a:90 to 00:15:70:88:8b:8f Example RFS7K-1(config)#virtual-ip 192.168.11.10/24 vlan 11 RFS7K-1(config)# RFS7K-1(config)#show virtual-ip config VIP Status : Disabled Cluster Redundancy Status...
Global Configuration Commands 5-129 5.1.44 wwan Global Configuration Commands Configures wirless wan finterface Supported in RFS6000 platform only Syntax wwan [apn<STRING>|disable|enable|password<STRING> |username<STRING>] Parameters apn <STRING> Enter the access point name provided by the service provider. • <STRING> – A string of up to 25 characters...
Crypto-isakmp Instance The (config-crypto-isakmp) instance is used to configure ISAKMP policies. To enter this instance, use this command: RFSwitch(config)#crypto isakmp policy <1-10000> RFSwitch(config-crypto-isakmp)# 6.1 Crypto ISAKMP Config Commands Table 6.1 summarizes commands crypto-isakmp Table 6.1 Crypto ISAKMP Command Summary Command Description Ref.
Page 404
Motorola RF Switch CLI Reference Guide Table 6.1 Crypto ISAKMP Command Summary Command Description Ref. lifetime Sets the lifetime for the ISAKMP security association page 6-11 Negates a command or sets its defaults page 6-12 service Defines the switch’s service commands...
Crypto ISAKMP Config Commands Configures the encryption level of the data transmitted using the crypto-isakmp command Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax encryption [3des|aes|aes-192|aes-256|des] Parameters 3des Triple data encryption standard Advanced data encryption standard...
Motorola RF Switch CLI Reference Guide 6.1.4 end Crypto ISAKMP Config Commands Ends and exits the current mode and changes to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
6.1.5 exit Crypto ISAKMP Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None. Example RFSwitch(config-crypto-isakmp)#exit...
Motorola RF Switch CLI Reference Guide 6.1.6 group Crypto ISAKMP Config Commands Specifies the Diffie-Hellman group (1 or 2) used by the IKE policy to generate keys (which is then used to create an IPSec SA) Supported in the following platforms: •...
6.1.7 hash Crypto ISAKMP Config Commands Specifies the hash algorithm used to authenticate data transmitted over the IKE SA Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax hash [md5|sha] Parameters Choose the MD5 hash algorithm...
6-10 Motorola RF Switch CLI Reference Guide 6.1.8 help Crypto ISAKMP Config Commands Displays the system’s interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-crypto-isakmp)#help CLI provides advanced help feature.
6-11 6.1.9 lifetime Crypto ISAKMP Config Commands Specifies how long an IKE SA is valid before it expires • RFS7000 • RFS6000 • RFS4000 Syntax lifetime <seconds> Parameters <seconds> Specifies how many seconds an IKE SA lasts before it expires.
Page 414
6-12 Motorola RF Switch CLI Reference Guide 6.1.10 no Crypto ISAKMP Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [authentication|encryption|group|hash|lifetime] Parameters None. Example RFSwitch(config-crypto-isakmp)#no lifetime...
Crypto ISAKMP Config Commands Invokes service commands to troubleshoot or debug the (config-crypto-isakmp) instance configurations. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters Displays the CLI tree of current mode Example...
Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 : • port-channel • static-channel-group NOTE: For more details, see...
Page 418
6-16 Motorola RF Switch CLI Reference Guide banner Display Message of the Day Login banner boot Display boot configuration. clock Display system clock commands Show command lists crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information...
Page 419
Crypto-isakmp Instance 6-17 terminal Display terminal configuration parameters timezone Display timezone traffic-shape Display traffic shaping upgrade-status Display last image upgrade status users Display information about currently logged in users version Display software & hardware version wireless Wireless configuration commands virtual-ip IP Redundancy Feature wlan-acl wlan based acl...
Crypto-group Instance The ( instance configures the default group properties of the config-crypto-group) ISAKMP client. To navigate to this instance, use the command: RFSwitch(config)#crypto isakmp client configuration group default RFSwitch(config-crypto-group)# 7.1 Crypto Group Config Commands Table 7.1 summarizes the switch commands config-crypto-group Table 7.1 Crypto Group Command Summary...
Page 422
Motorola RF Switch CLI Reference Guide Table 7.1 Crypto Group Command Summary Command Description Ref. show Shows running system information page 7-9 wins Defines a Windows Name Server (WINS) page 7-12...
Motorola RF Switch CLI Reference Guide 7.1.2 dns Crypto Group Config Commands Specifies the DNS server address(es) to assign to a client Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax dns <IP> <IP > The first DNS server address to assign Example RFSwitch(config-crypto-group)#dns-server 172.1.17.1...
7.1.3 end Crypto Group Config Commands Ends and exits the current mode and changes to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-crypto-group)#end...
Motorola RF Switch CLI Reference Guide 7.1.4 exit Crypto Group Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
Crypto-group Instance 7.1.5 help Crypto Group Config Commands Displays the system’s interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-crypto-group)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
Motorola RF Switch CLI Reference Guide 7.1.6 service Crypto Group Config Commands Invokes service commands used troubleshoot or debug (config-crypto-isakmp) instance configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters Displays the CLI tree of current mode...
Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 : • port-channel • static-channel-group NOTE: For more details on the show command see...
Page 430
7-10 Motorola RF Switch CLI Reference Guide banner Display Message of the Day Login banner boot Display boot configuration. clock Display system clock commands Show command lists crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information...
Page 431
Crypto-group Instance 7-11 terminal Display terminal configuration parameters timezone Display timezone traffic-shape Display traffic shaping upgrade-status Display last image upgrade status users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl...
7-12 Motorola RF Switch CLI Reference Guide 7.1.8 wins Crypto Group Config Commands Specifies the Windows Internet Naming Service (WINS) servers to assign to a client Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax wins <IP>...
Motorola RF Switch CLI Reference Guide 8.1.2 end Crypto Peer Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
8.1.3 exit Crypto Peer Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-crypto-peer)#exit...
Motorola RF Switch CLI Reference Guide 8.1.4 help Crypto Peer Config Commands Accesses the system’s interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-crypto-peer)#help CLI provides advanced help feature.
Page 439
Crypto-peer Instance 8.1.5 no Crypto Peer Config Commands Negates a command or sets it’s defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no set aggressive-mode password Parameters command for parameters details Example RFSwitch(config-crypto-peer)#no set aggrerssive-mode...
Motorola RF Switch CLI Reference Guide 8.1.6 service Crypto Peer Config Commands Invokes service commands to troubleshoot or debug the (config-crypto-peer) instance configuration Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters...
Page 441
Crypto-peer Instance 8.1.7 set Crypto Peer Config Commands Configures the aggressive-mode of config-crypto-peer • RFS7000 • RFS6000 • RFS4000 set aggerssive-mode password [0 <password>|2 <password>| <password>] Parameters aggressive-mode Defines aggressive mode attributes password [0 • password – Specifies a tunnel-password attribute <password>|2...
8-10 Motorola RF Switch CLI Reference Guide 8.1.8 show Crypto Peer Config Commands Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: •...
Page 443
Crypto-peer Instance 8-11 banner Display Message of the Day Login banner boot Display boot configuration. clock Display system clock commands Show command lists crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration...
Page 444
8-12 Motorola RF Switch CLI Reference Guide terminal Display terminal configuration parameters timezone Display timezone upgrade-status Display last image upgrade status users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless...
Crypto-ipsec Instance Use the instance to define the transform configuration for (config-crypto-ipsec) securing data (esp-3des, esp-sha-hmac etc.). To navigate to this instance, use the command RFSwitch(config)#crypto ipsec transform-set <transform-set-name> <encryption-type> <auth-type> RFSwitch(config-crypto-ipsec)# The transform set is assigned to a crypto map using the map’s transform-set command. For more details, see crypto-map transform set page...
Page 446
Motorola RF Switch CLI Reference Guide Table 9.1 Crypto IPsec Command Summary (Continued) Command Description Ref. Negates a command or set its defaults page 9-7 service Invokes service commands to troubleshoot or debug page 9-11 instance configurations (config-crypto-isakmp)
9.1.1 end Crypto IPSec Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-crypto-ipsec)#end...
Motorola RF Switch CLI Reference Guide 9.1.2 exit Crypto IPSec Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
Crypto-ipsec Instance 9.1.3 help Crypto IPSec Config Commands Accesses the system’s interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-crypto-peer)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
Motorola RF Switch CLI Reference Guide 9.1.4 mode Crypto IPSec Config Commands Configures the IPSec mode of operation Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax mode [transport|tunnel] Parameters transport Transport mode tunnel Tunnel mode...
Page 451
Crypto-ipsec Instance 9.1.5 no Crypto IPSec Config Commands Negates a command or sets it’s defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no mode Parameters mode Sets default to tunnel mode. Example RFSwitch(config-crypto-ipsec)#no mode...
Motorola RF Switch CLI Reference Guide 9.1.6 show Crypto IPSec Config Commands Use this command to view current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: •...
Page 453
Crypto-ipsec Instance debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server licenses Show any installed licenses logging...
Page 454
9-10 Motorola RF Switch CLI Reference Guide users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl wwan Wireless wan interface RFSwitch(config-crypto-ipsec)#show...
Crypto IPSec Config Commands Invokes service commands to troubleshoot or debug the (config-crypto-peer) instance configuration Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters Displays the CLI tree of current mode Example...
Crypto-map Instance The ( commands define a Certificate Authority (CA) trustpoint. config-crypto-map) This is a separate instance, but belongs to the mode under the crypto pki trustpoint instance. config To navigate to this instance, use the command: RFSwitch(config)#crypto map <map-name> <sequence> [ipsec-isakmp|ipsec-manual] {dynamic} RFSwitch(config-crypto-map)# 10.1 Crypto Map Config Commands...
Page 458
10-2 Motorola RF Switch CLI Reference Guide Table 10.1 Crypto Map Command Summary (Continued) Command Description Ref. service Invokes service commands to troubleshoot or debug the page 10-10 instance configurations Sets values for encryption/decryption parameters page 10-12 show Displays the running system information...
10-4 Motorola RF Switch CLI Reference Guide 10.1.2 end Crypto Map Config Commands Ends and exits the current mode and moves to the to PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 •...
10.1.3 exit Crypto Map Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-crypto-map)#exit...
10-6 Motorola RF Switch CLI Reference Guide 10.1.4 help Crypto Map Config Commands Displays the system’s interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-crypto-map)#help CLI provides advanced help feature.
(or if the packet fails any of the security checks), it is discarded. If all checks pass, the packet is forwarded normally. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax match address <acl-id> Parameters...
Page 464
10-8 Motorola RF Switch CLI Reference Guide Usage Guidelines Crypto map entries do not directly contain the selectors used to determine which data to secure. Instead, the crypto map entry refers to an access control list. An access control list (ACL) is assigned to the crypto map using the match address command.
Page 465
10-9 10.1.6 no Crypto Map Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [match|set] Parameters Use the commands configured under this instance. Example RFSwitch(config-crypto-map)#no match address <WORD>...
10-10 Motorola RF Switch CLI Reference Guide 10.1.7 service Crypto Map Config Commands Invokes service commands to troubleshoot or debug the (config-crypto-peer) instance configuration Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli...
Page 467
Crypto-map Instance 10-11 +-remote-type [no set remote-type] +-security-association +-level +-perhost [no set security-association level perhost] +-lifetime [no set security-association lifetime] +-session-key +-inbound +-ah [no set session-key ( inbound | outbound ) ah] +-esp [no set session-key ( inbound | outbound ) esp] ............
10-12 Motorola RF Switch CLI Reference Guide 10.1.8 set Crypto Map Config Commands Configures set parameters for the peer device Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax set [localid|mode|peer|pfs|remote-type {ipsec-l2tp|xauth}| security-association|session-key|transform-set) set localid [dn|hostname]<name>...
Page 469
Crypto-map Instance 10-13 mode [aggressive|main] Sets the mode of the tunnels for this Crypto Map • aggressive – Initiates aggressive mode • main – Initiates main mode peer Sets the IP address of the peer device. This can be set for [ipaddress| multiple remote peers.
Page 470
10-14 Motorola RF Switch CLI Reference Guide security-association Defines the lifetime (in kilobytes and/or seconds) of the [level perhost|lifetime IPSec SAs created by this crypto map {kilobyte|seconds}] • level perhost – Specifies the security association granularity level for identities • lifetime [kilobyte|seconds] – Security an association...
Page 471
Crypto-map Instance 10-15 RFSwitch(config-crypto-map)#set pfs If left at the default setting, no perfect forward secrecy (PFS) is used during IPSec SA key generation. If PFS is specified, the specified Diffie-Hellman Group exchange is used for the initial (and all subsequent) key generations. This means no data linkage between prior keys and future keys.
10-16 Motorola RF Switch CLI Reference Guide 10.1.9 show Crypto Map Config Commands Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: •...
Page 473
Crypto-map Instance 10-17 dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server licenses Show any installed licenses logging Show logging configuration and buffer...
Page 474
10-18 Motorola RF Switch CLI Reference Guide version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl wwan Wireless wan interface RFSwitch(config-crypto-map)#show...
Crypto-trustpoint Instance commands define a Certificate Authority (CA) (config-crypto-trustpoint) trustpoint. This is a separate instance, but belongs to the crypto pki trustpoint mode under the instance. config To navigate to this instance, use the command RFSwitch(config)#crypto pki trustpoint <trustpoint-name> RFSwitch(config-trustpoint)# 11.1 Trustpoint (PKI) Config Commands Table 11.1 summarizes...
Page 476
11-2 Motorola RF Switch CLI Reference Guide Table 11.1 Trustpoint (PKI) Config Command Summary Command Description Ref. ip-address Sets an IP address for the trustpoint page 11-10 Negates a command or sets its defaults page 11-11 password Sets the challenge password (applicable only for...
11-4 Motorola RF Switch CLI Reference Guide 11.1.2 company-name Trustpoint (PKI) Config Commands Sets the company name (Applicable only for request) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax company-name <company-name> Parameters <company-name> Company name (2 to 64 characters)
11.1.3 email Trustpoint (PKI) Config Commands Sets the e-mail ID for the trustpoint Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax email <email> Parameters <email> Sets email address (2 to 64 characters) for the trustpoint Example RFSwitch(config-trustpoint)#email abcTestemailID@symbol.com...
11-6 Motorola RF Switch CLI Reference Guide 11.1.4 end Trustpoint (PKI) Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 •...
11.1.5 exit Trustpoint (PKI) Config Commands Ends the current mode and moves to previous the mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-trustpoint)#exit...
Crypto-trustpoint Instance 11-9 11.1.7 help Trustpoint (PKI) Config Commands Displays the systems interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-trustpoint)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
11-10 Motorola RF Switch CLI Reference Guide 11.1.8 ip-address Trustpoint (PKI) Config Commands Sets an IP address for the trustpoint Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ip-address <IP> Parameters <IP> Enter the IP address for the trustpoint Example RFSwitch(config-trustpoint)#ip-address 157.200.200.02...
Page 485
Crypto-trustpoint Instance 11-11 11.1.9 no Trustpoint (PKI) Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [company-name|email|fqdn|ip-address|subject-name] Parameters None. Example RFSwitch(config-trustpoint)#no ip-address RFSwitch(config-trustpoint)#...
11-12 Motorola RF Switch CLI Reference Guide 11.1.10 password Trustpoint (PKI) Config Commands Sets the challenge password (applicable only for requests) to access the trustpoint Syntax password [0<password>|2<password>|<password>] Parameters 0 <password> Password <password> is specified as unencrypted, the password should be between 4 to 20 characters 2 <password>...
Crypto-trustpoint Instance 11-13 11.1.11 rsakeypair Trustpoint (PKI) Config Commands Configures a RSA Keypair to associate with the trustpoint Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax rsakeypair <keypair-name> Parameters <keypair-name> RSA Keypair Identifier Usage Guidelines The RSA key pair configures the switch to have Rivest, Shamir, and Adelman (RSA) key pairs.
11-14 Motorola RF Switch CLI Reference Guide 11.1.12 service Trustpoint (PKI) Config Commands Invokes service commands to troubleshoot or debug the crypto pki trustpoint instance configuration Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli...
11-16 Motorola RF Switch CLI Reference Guide 11.1.13 show Trustpoint (PKI) Config Commands Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: •...
Page 491
Crypto-trustpoint Instance 11-17 debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server licenses Show any installed licenses logging...
Page 492
11-18 Motorola RF Switch CLI Reference Guide users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl wwan Wireless wan interface RFSwitch(config-crypto-map)#show...
Creates a subject name to configure a trustpoint (the subject name is a collection of required parameters to configure a trustpoint) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax subject-name <name> <country> <state> <city> <org> <org-unit>...
Page 494
11-20 Motorola RF Switch CLI Reference Guide WORD Organization( 2 to 64 characters ) RFSwitch(config-trustpoint)#subject-name TestPool US OH PB SYMBOL ? WORD Organization Unit( 2 to 64 characters ) RFSwitch(config-trustpoint)#subject-name TestPool US OH PB SYMBOL WID ? <cr> RFSwitch(config-trustpoint)#subject-name TestPool US OH PB...
Interface Instance Use the instance to configure the interfaces – Ethernet, VLAN and tunnel (config-if) associated with the switch. To switch to this mode, use the command: For RFSwitch7000: RFSwitch(config)#interface [<interface-name>|ge <1-4>|me1| sa <1-4>|vlan <1-4094>] RFSwitch(config-if)# For RFSwitch6000: RFSwitch(config)#interface [<interface-name>|ge <1-8>|me1| up1|vlan <1-4094>] RFSwitch(config-if)# For RFSwitch4000:...
Page 496
12-2 Motorola RF Switch CLI Reference Guide Table 12.1 Interface Config Command Summary (Continued) Command Description Ref. crypto Defines the encryption module page 12-5 description Creates an interface specific description page 12-6 duplex Sets the duplex mode used by the interface...
Page 497
Interface Instance 12-3 Table 12.1 Interface Config Command Summary (Continued) Command Description Ref. speed Specifies the speed of a fast-ethernet (10/100) or a page 12-32 gigabit ethernet port (10/100/1000) static- Configures static channel commands page 12-33 channel- group storm-control Sets broadcast rate-limit value page 12-36 switchport Sets switching mode characteristics...
12-5 12.1.2 crypto Interface Config Commands Sets the encryption module to use for this interface Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax crypto map <map-tag> Parameters map <map-tag> Assigns a Crypto Map • <map-tag> – Crypto Map tag Usage Guidelines At any given instance you can add one crypto mapset to an single interface.
12-6 Motorola RF Switch CLI Reference Guide 12.1.3 description Interface Config Commands Creates an interface specific description Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax description <description> Parameters <description> Defines the characters describing this interface Example RFSwitch(config-if)#description "interface for RetailKing"...
(config-if) interface mode • The duplex cannot be set until the speed is set to a non-auto value Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax duplex [auto|full|half] Parameters auto Sets the ports duplexity automatically. The port...
12-8 Motorola RF Switch CLI Reference Guide 12.1.5 end Interface Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
12.1.6 exit Interface Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-if)#exit RFSwitch(config)#...
12-10 Motorola RF Switch CLI Reference Guide 12.1.7 help Interface Config Commands Displays the system’s interactive help Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-if)#help CLI provides advanced help feature.
Page 505
12.1.8 ip Interface Config Commands Sets the IP address for the assigned Fast Ethernet interface (ME), and VLAN Interface Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ip [access-group|address|arp|dhcp|helper-address|nat] ip access-group [<1-99>|<100-199>|<1300-1999>| <2000-2699>|WORD in] ip arp [rate-limit|trust] ip dhcp trust ip address [<IP/Mask>...
Page 506
12-12 Motorola RF Switch CLI Reference Guide ip address [ <IP Mask> Sets a static IP address and network mask for a Layer 3 {secondary}|dhcp] SVI (Switch Virtual Interface) • <IP/ Mask> {secondary} – Sets the IP address (10.0.0.1/8) • secondary – Defines an optional secondary IP address •...
Interface Instance 12-13 Example RFSwitch(config-if)#ip access-group 110 in RFSwitch(config-if)# RFSwitch(config-if)#ip address 192.168.234.1/24 RFSwitch(config-if)# 12.1.8.1 Creating Helper Address using DHCP Server Follow the steps below to create a helper address on VLAN 2000 for using a DHCP server on VLAN 1000: RFSwitch(config)#interface vlan 1000 RFSwitch(config-if)#ip address 172.168.100.1/24 RFSwitch(config-if)#interface vlan 2000...
12-14 Motorola RF Switch CLI Reference Guide 12.1.9 mac Interface Config Commands Applies a MAC access list (ACL) to Gigabit Ethernet interface NOTE: The access list cannot be applied on a management interface (me1). Supported in the following platforms: •...
The TFTP/FTP server providing the switch its config file at startup must be accessible via this interface. VLAN 1 is the default management interface for the switch. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax management Parameters...
Page 510
12-16 Motorola RF Switch CLI Reference Guide 12.1.11 no Interface Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands are not supported on RFS6000: •...
Interface Config Commands Selects the load-balance criteria of an aggregated port Supported in the following platforms: • RFS7000 • RFS4000 SWITCH NOTE: RFS6000 does not support this command. Syntax port-channel load-balance [src-dst-ip|src-dst-mac] Parameters load-balance Sets load-balancing for port channel [src-dst-ip|src-dst-mac] •...
12-18 Motorola RF Switch CLI Reference Guide The following example defines the load balance based on the IP or MAC address: RFSwitch(config)#interface sa1 RFSwitch(config-if)#port-channel load-balance src--dst-ip RFSwitch(config-if)# 12.1.12.1 Configuring a Port Aggregation for configuring port aggregation. Follow static-channel-group port-channel the steps below to configure port aggregation: 1.
Page 513
Interface Instance 12-19 5. Use the command to select the criteria used to determine which link is port-channel selected for a given packet. The port-channel selection is based on either source- destination IP or source destination MAC RFS7000(config-if)#port-channel load-balance src-dst-ip RFS7000(config-if)# The default port-channel criteria is based on source-destination IP.
Page 514
12-20 Motorola RF Switch CLI Reference Guide MAC> no matter what host the MU is accessing. But in src-dst-mac balancing, the same link is selected always.
GE port is set to low. Power is applied in order of priority, power overlaods are removed in reverse order of priority. Supported in the following platforms: • RFS6000 • RFS4000 SWITCH NOTE: This command is not supported with: •...
Page 516
12-22 Motorola RF Switch CLI Reference Guide RFSwitch(config-if)#exit RFSwitch(config)#interface ge3 RFSwitch(config-if)#power priority critical RFSwitch(config-if)#exit RFSwitch(config)#show power configuration Power usage trap at 80% of max power (148 of 185 Watts) port Priority Power limit Enabled high 29.7W high 14.0W crit 29.7W high 29.7W...
Interface Config Commands Invokes service commands to troubleshoot or debug the instance (config-if) configuration. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters Displays the CLI tree of the current mode Example RFSwitch(config-if)#service show cli...
Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <parameter>...
Page 520
12-26 Motorola RF Switch CLI Reference Guide crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces...
Page 521
Interface Instance 12-27 users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl wwan Wireless wan interface RFSwitch(config-if)#show...
12-28 Motorola RF Switch CLI Reference Guide 12.1.16 shutdown Interface Config Commands Disables the selected interface, the interface is administratively enabled unless explicitly disabled using this command Displays current system information running on the switch Supported in the following platforms: •...
12.1.17 spanning-tree Interface Config Commands Configures spanning tree parameters Displays current system information running on the switch. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax spanning-tree [bpdufilter|bpduguard|edgeport|force-version| guard|link-type|mst|portfast] spanning-tree bpdufilter [enable|disable] spanning-tree bpduguard [enable|disable] spanning-tree [edgeport|portfast] spanning-tree force-version <1-3>...
Page 524
12-30 Motorola RF Switch CLI Reference Guide bpduguard [disable|enable] Use this command to enable or disable the BPDU guard feature on a port. Use the no parameter with this command to set the BPDU guard feature to default values. When the BPDU guard is set for a bridge, all portfast- enabled ports that have the BPDU-guard set to default shut down the port upon receiving a BPDU.
Page 525
Interface Instance 12-31 mst [<0-15> Configures MST values on a spanning tree [cost <1-200000000>| • <0-15> [cost <1-200000000>|port-priority <0-240>] – port-priority <0-240>]| Defines the Instance ID port-cisco-interoperability • cost <1-200000000> – Defines the path cost for a [disable|enable]] port • port-priority <0-240> – Defines the port priority for a bridge •...
12-32 Motorola RF Switch CLI Reference Guide 12.1.18 speed Interface Config Commands Specifies the speed of a fast-ethernet (10/100) or a gigabit-ethernet port (10/100/1000) Displays current system information running on the switch. Supported in the following platforms: • RFS7000 •...
Adds an interface to a static channel group Displays current system information running on the switch. Supported in the following platforms: • RFS7000 • RFS4000 SWITCH NOTE: RFS6000 does not support this command Syntax static-channel-group <1-4> Parameters <1-4> Sets a static channel group to associate the link with...
Page 529
Interface Instance 12-35 Sets the trunking mode characteristics trunk [allowed |native] • allowed vlan – Configures trunk characteristics when the port is in trunk-mode • vlan [add|none|remove] – Sets allowed vlans • none – Allows no vlans to Xmit/Rx through the Layer2 interface •...
Spanning tree-mst Instance Use the instance to configure the switch’s Multi Spanning Tree Protocol (config-mst) (MSTP) configuration. To switch to this instance, use the command: RFSwitch(config)#spanning-tree mst configuration RFSwitch(config-mst)# 13.1 mst Config Commands Table 13.1 summarizes the commands: (config-mst) Table 13.1 MSTI configuration commands Command Description Ref.
Page 532
13-2 Motorola RF Switch CLI Reference Guide Command Description Ref. service Invokes service commands needed to troubleshoot or page 13-11 debug instance configurations (config-if) show Shows running system information page 13-13...
13-4 Motorola RF Switch CLI Reference Guide 13.1.2 end mst Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
13.1.3 exit mst Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-mst)#exit RFSwitch(config)#...
13-6 Motorola RF Switch CLI Reference Guide 13.1.4 help mst Config Commands Displays the system’s interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-mst)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
13-7 13.1.5 instance mst Config Commands Associates VLAN(s) with an instance Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax instance <1-15> vlan <vlan-id> Parameters <1-15> Defines the instance ID to which the VLAN is associated vlan <vlan-id>...
13-8 Motorola RF Switch CLI Reference Guide 13.1.6 name mst Config Commands Sets the name for the MST region Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax name <region-name> Parameters <region-name> Sets MST region name...
Page 539
13-9 13.1.7 no mst Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [instance|name|revision] Parameters instance Sets the MST Instance • vlan – Delete the association of vlan with this instance •...
13-10 Motorola RF Switch CLI Reference Guide 13.1.8 revision mst Config Commands Sets the revision number of the MST bridge Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax revision <0-255> Parameters revision <0-255> Defines the revision number for configuration information...
13.1.9 service mst Config Commands Invokes service commands needed to troubleshoot or debug instance (config-if) configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters None Example RFSwitch(config-mst)#service show cli MSTI configuration mode:...
Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <parameter>...
Page 544
13-14 Motorola RF Switch CLI Reference Guide dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server...
Page 545
Spanning tree-mst Instance 13-15 version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl wwan Wireless wan interface RFSwitch(config-mst)#show...
Extended ACL Instance The Extended ACL instance is used to manage the extended (config-ext-nacl) Access Control List entries associated with the switch. To navigate to this instance, use the command RFSwitch(config)#ip access-list extended [<ACL-name>| <100-199>|<2000-2699>] RFSwitch(config-ext-nacl)# 14.1 Extended ACL Config Commands Table 14.1 summarizes commands:...
Page 548
14-2 Motorola RF Switch CLI Reference Guide Table 14.1 Extended ACL Config Command Summary (Continued) Command Description Ref. permit Specifies packets to forward page 14-22 service Invokes the service commands to troubleshoot or page 14-28 debug instance configurations (config-if) show...
Page 551
Extended ACL Instance 14-5 Parameters Use with a deny command to reject IP packets deny ip [<source-IP/ Mask>|any|host • deny – Sets the action type on an ACL <IP>][<dest-IP/ • ip – Specifies an IP (to match to a protocol) Mask>|any|host <IP>] •...
Page 552
14-6 Motorola RF Switch CLI Reference Guide deny icmp [<source-IP/ Use with the deny command to reject ICMP packets Mask>|any|host <IP>] • deny – Rejects ICMP packets [<dest-IP/Mask>|any|host • icmp – Specifies ICMP as the protocol <IP>] {<ICMP-type> • [<source-ip/mask>|any|host <IP>] – The source <source- {<ICMP-code>}} {log}...
Page 553
Extended ACL Instance 14-7 deny [tcp|udp] [<source-IP/ Use with the deny command to reject TCP or UDP packets Mask>|any|host <IP>] {eq • deny – Rejects TCP or UDP packets <source-port>|range • tcp|udp – Specifies TCP or UDP as the protocol <starting-source-port>...
Page 554
14-8 Motorola RF Switch CLI Reference Guide • ftp-data – port 20 • gopher – gopher port 70 • https – https port 443 • ldap – ldap port 389 • nntp – nntp port 119 • ntp – ntp port 123 •...
Page 555
Extended ACL Instance 14-9 deny proto [<1- Use with the deny command to deny any protocol other 254>|WORD|eigrp|gre| than TCP , UDP or ICMP packets igmp|igp|ospf|vrrp] • <1-254] – Displays protocol number [<source-IP/ • <WORD> – Refers to any protocol name Mask>|any|host •...
14-10 Motorola RF Switch CLI Reference Guide Usage Guidelines Use this command to deny traffic between networks/hosts based on the protocol type selected in the access list configuration. The following protocol types are supported: • ip • icmp • tcp •...
Extended ACL Instance 14-11 14.1.2.3 Example - Denying UDP Based Traffic The following example denies UDP traffic with a source port range between 20 - 23 (from the source subnet to destination subnet): RFSwitch(config-ext-nacl)#deny udp range 20 23 192.168.1.0/24 192.168.2.0/24 RFSwitch(config-ext-nacl)#permit ip any any RFSwitch(config-ext-nacl)# 14.1.2.4 Example - Denying ICMP Based Traffic...
14-12 Motorola RF Switch CLI Reference Guide 14.1.3 end Extended ACL Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode The prompt changes to RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 •...
14.1.4 exit Extended ACL Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-ext-nacl)#exit...
14-14 Motorola RF Switch CLI Reference Guide 14.1.5 help Extended ACL Config Commands Displays the system’s interactive help system Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-ext-nacl)#help CLI provides advanced help feature.
14-15 14.1.6 mark Extended ACL Config Commands Specifies packets to mark Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax mark [8021p|dscp|tos] mark [8021p <vlan-priority-value>|dscp <dscp-codepoint-value>|tos <tos-value>] [icmp|ip|tcp|udp] mark [8021p <vlan-priority-value>|dscp <dscp-codepoint- value>|tos <tos-value>] icmp [<source-ip/mask>|any|host <ip>] [<dest-ip/mask>|any|host <ip>] {<ICMP-type>...
Page 562
14-16 Motorola RF Switch CLI Reference Guide tos <tos-value> Sets the TOS value to <tos-value>. The least significant two bits of the <tos-value> must be 0. ip [<source-IP/ Use with mark command to mark a packet Mask>|any|host <IP>] • ip – Specifies an IP (to match to a protocol) [<dest-IP/Mask>|...
Page 563
Extended ACL Instance 14-17 icmp [<source-IP/ Use with the mark command to mark ICMP packets mask>|any|host <IP>] • deny – Rejects ICMP packets [<dest-IP/Mask>|any| • icmp – Specifies ICMP as the protocol host <IP>] {<ICMP-type> • [<source-IP/mask>|any|host <IP>] – The source <source- {<ICMP-code>}} {log} IP>...
Page 564
14-18 Motorola RF Switch CLI Reference Guide [tcp|udp] [<source-IP/ Use with the mark command to mark TCP or UDP packets Mask>|any|host <IP>] {eq • deny – Rejects TCP or UDP packets <source-port>|range • tcp|udp – Specifies TCP or UDP as the protocol <starting-source-port>...
Extended ACL Instance 14-19 Usage Guidelines Marks traffic between networks/hosts based on the protocol type selected in the access list configuration Use the mark option to specify the type of service (tos) and priority value. The tos value is marked in the IP header and the 802.1p priority value is marked in the dot1q frame. The following types of protocols are supported: •...
Page 566
14-20 Motorola RF Switch CLI Reference Guide RFSwitch(config-ext-nacl)# mark tos 160 udp 192.168.2.0/24 range 5060 5061 RFSwitch(config-ext-nacl)# RFSwitch(config-ext-nacl)# mark dscp 40 udp 192.168.2.0/24 range 5060 5061 RFSwitch(config-ext-nacl)#...
Page 567
Extended ACL Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [deny|mark|permit] Negates all the syntax combinations used in the deny, mark and permit designations to...
14-22 Motorola RF Switch CLI Reference Guide 14.1.8 permit Extended ACL Config Commands Permits specific packets. NOTE: ACLs do not allow DHCP messages to flow by default. Configure an Access Control Entry (ACE) to allow DHCP messages to flow through.
Page 569
Extended ACL Instance 14-23 Parameters Use with a permit command to allow IP packets permit ip [<source-IP/ Mask>|any|host <IP>] • deny – Sets the action type on an ACL [<dest-IP/mask>|any|host • IP – Specifies an IP (to match to a protocol) <IP>] {log} {rule- •...
Page 570
14-24 Motorola RF Switch CLI Reference Guide permit icmp [<source-IP/ Use with the permit command to allow ICMP packets Mask>|any|host <ip>] • deny – Rejects ICMP packets [<dest-IP/Mask>|any| • icmp – Specifies ICMP as the protocol host <IP>] {<ICMP-type> • [<source-IP/Mask>|any|host <IP>] – The source {<ICMP-code>}} {log}...
Page 571
Extended ACL Instance 14-25 permit [tcp|udp] [<source- Use with the permit command to allow TCP or UDP ip/mask>|any|host <IP>] packets {eq <source-port>|range • deny – Rejects TCP or UDP packets <starting-source-port> • tcp|udp – Specifies TCP or UDP as the protocol <ending-source-port>} •...
Page 572
14-26 Motorola RF Switch CLI Reference Guide permit proto Use with the permit command to allow any protocol [<1-254>|WORD|eigrp|gre| other than TCP , UDP or ICMP packets igmp|igp|ospf|vrrp] • <1-254] – Displays protocol number [<source-IP/ • <WORD> – Refers to any protocol name Mask>|any|host...
Extended ACL Instance 14-27 • ip • icmp • tcp • udp The last ACE in the access list is an implicit deny statement. Whenever the interface receives the packet, its content is checked against all the ACEs in the ACL. It is allowed based on the ACL configuration. •...
14-28 Motorola RF Switch CLI Reference Guide 14.1.9 service Extended ACL Config Commands Invokes service commands to troubleshoot or debug the (config-if) instance configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli...
Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <paramater>...
Page 576
14-30 Motorola RF Switch CLI Reference Guide dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server...
Page 577
Extended ACL Instance 14-31 version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl wwan Wireless wan interface RFS6000(config-ext-nacl)#show Example RFS6000(config-ext-nacl)#show access-list Extended IP access list 120 RFS6000(config-ext-nacl)#...
14-32 Motorola RF Switch CLI Reference Guide 14.2 Configuring IP Extended ACL IP Extended ACLs contain rules based on the following parameters: • Source IP address • Destination IP address • IP Protocol • Source Port–if protocol is TCP or UDP •...
Standard ACL Instance The Standard ACL instance is used to manage the standard Access (config-std-acl) Control List entries associated with the switch. To navigate to this instance, use the command: RFSwitch(config)#ip access-list standard [<ACL-name>| <1-99>|<1300-1999>] RFSwitch(config-std-acl)# 15.1 Standard ACL Config Commands Table 15.1 summarizes the commands:...
Page 582
15-2 Motorola RF Switch CLI Reference Guide Table 15.1 Standard ACL Config Command Summary (Continued) Command Description Ref. permit Specifies packets to forward page 15-12 service Invokes service commands to troubleshoot or debug page 15-14 instance configurations (config-if) show Displays running system information...
Standard ACL Instance 15-3 15.1.1 clrscr Standard ACL Config Commands Clears the display screen Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax clrscr Parameters None Example RFSwitch(config-std-nacl)#clrscr RFSwitch(config-std-nacl)#...
Standard ACL Instance 15-5 Whenever the interface receives the packet, its content is checked against all the ACEs in the ACL. It is allowed/denied based on the ACL configuration. NOTE: The log option is functional only for router ACL’s. The log option results in an informational logging message for the packet matching the entry sent to the console.
15-6 Motorola RF Switch CLI Reference Guide 15.1.3 end Standard ACL Config Commands Ends and exits from the current mode and moves to the PRIV EXEC mode. The prompt changes to RFSwitch# Supported in the following platforms: • RFS7000 •...
15.1.4 exit Standard ACL Config Commands Ends the current mode and moves to previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-std-nacl)#exit RFSwitch(config)#...
15-8 Motorola RF Switch CLI Reference Guide 15.1.5 help Standard ACL Config Commands Displays the system’s interactive help in HTML format Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-std-nacl)#help CLI provides advanced help feature.
15-9 15.1.6 mark Standard ACL Config Commands Specifies packets to mark Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax mark [8021p|dscp|tos] mark 8021p <vlan-priority-value> mark dscp <dscp-codepoint-value> mark tos <tos-value> [<source-IP/Mask>|any|host <IP>] {log} {rule-precedence <1-5000>} Parameters 8021p <vlan-priority-...
15-10 Motorola RF Switch CLI Reference Guide Use with a mark command to mark packets [<source-IP/Mask>| any|host <IP>] {log} • <source-IP/Mask>|any|host <IP> – The keyword <source- {rule-precedence IP> is the source IP address of the network or host in <1-5000>} dotted decimal format.
Page 591
15.1.7 no Standard ACL Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [deny|mark|permit] Negates all the syntax combinations used in deny, mark and permit designations. Parameters...
Standard ACL Instance 15-13 Whenever the interface receives the packet, its content is checked against all the ACEs in the ACL. It is allowed based on the ACL’s configuration. NOTE: The log option is functional only for router ACLs. The log option displays an informational logging message about the packet matching the entry sent to the console.
15-14 Motorola RF Switch CLI Reference Guide 15.1.9 service Standard ACL Config Commands Invokes service commands to troubleshoot or debug instance (config-if) configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters...
15-16 Motorola RF Switch CLI Reference Guide 15.1.10 show Standard ACL Config Commands Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: •...
Page 597
Standard ACL Instance 15-17 dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server licenses Show any installed licenses logging Show logging configuration and buffer...
Page 598
15-18 Motorola RF Switch CLI Reference Guide version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl RFSwitch(config-std-nacl)#show...
Standard ACL Instance 15-19 15.2 Use Case: Configuring IP Standard ACL IP Standard ACLs contain rules based on Source IP Address. You can create either a Numbered IP Standard ACL or a Named IP Standard IP Address. Execute the following CLI commands to configure an IP based standard ACL: 1.
Extended MAC ACL Instance Use the instance to configure (config-ext-macl) mac access-list ACLs. To navigate to this instance, use the command: extended RFSwitch(config)#mac access-list extended <acl-name> RFSwitch(config-ext-macl)# 16.1 MAC Extended ACL Config Commands Table summarizes commands: config-ext-macl Table 16.1 MAC Extended ACL Config Command Summary Command Description Ref.
Page 602
16-2 Motorola RF Switch CLI Reference Guide Table 16.1 MAC Extended ACL Config Command Summary (Continued) Command Description Ref. service Invokes service commands to troubleshoot or debug page 16-18 instance configurations (config-if) show Shows running system information page 16-20...
Extended MAC ACL Instance 16-3 16.1.1 clrscr MAC Extended ACL Config Commands Clears the display screens Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax clrscr Parameters None Example RFSwitch(config-ext-macl)#clrscr RFSwitch(config-ext-macl)#...
16-4 Motorola RF Switch CLI Reference Guide 16.1.2 deny MAC Extended ACL Config Commands Specifies packets to reject NOTE: Use a decimal value representation of ethertypes to implement designation for a packet. The command set for permit/deny/mark Extended MAC ACLs provide the hexadecimal values for each listed ethertype.
Page 605
Extended MAC ACL Instance 16-5 Parameters deny [<MAC/Mask>|any|host Define a source and destination MAC address and <MAC>] [<MAC/Mask>|any| Mask specifying the bits to match. The source and host <MAC>] {[dot1p| destination wildcards can be any one of the rule-precedence|type|vlan]} following: •...
16-6 Motorola RF Switch CLI Reference Guide Usage Guidelines The deny command disallows traffic based on layer 2 (data-link layer) data. The MAC access list denies traffic from a particular source MAC address or any MAC address. It can also disallow traffic from a list of MAC addresses based on the source mask.
16.1.3 end MAC Extended ACL Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-ext-macl)#end...
16-8 Motorola RF Switch CLI Reference Guide 16.1.4 exit MAC Extended ACL Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 •...
Extended MAC ACL Instance 16-9 16.1.5 help MAC Extended ACL Config Commands Displays the system’s interactive help (in HTML format) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-ext-macl)#help CLI provides advanced help feature.
16-10 Motorola RF Switch CLI Reference Guide 16.1.6 mark MAC Extended ACL Config Commands Specifies the packet to mark NOTE: Use a decimal value representation of ethertypes to implement permit/deny/mark designations for a packet. An Extended MAC ACL provides the hexadecimal values for each listed ethertype. The switch supports all ethertypes.
Page 611
Extended MAC ACL Instance 16-11 Parameters 8021p<0-7> Modifies the 802.1p VLAN user priority • xx:xx:xx:xx:xx:xx/ xx:xx:xx:xx:xx:xx – Source MAC address and mask • any – Any source host • host – Exact source MAC address to match tos<0-255> Modifies the TOS bits in an IP header •...
16-12 Motorola RF Switch CLI Reference Guide type [8021q|<1-65535>| Defines an ethertype value represented as an arp|appletalk|ip|ipv6ipx|rarp| integer or keyword for well-known ethertypes (like vlan|wisp] IP, IPv6, ARP etc.) vlan <1-4095> Defines the VLAN tag ID to match dscp <0-63>...
Page 613
MAC Extended ACL Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [deny|mark|permit] Negates all the syntax combinations used in deny, mark and permit designations to...
16-14 Motorola RF Switch CLI Reference Guide 16.1.8 permit MAC Extended ACL Config Commands Specifies packets to forward NOTE: Use a decimal value representation of ethertypes to implement permit/deny/mark designations for a packet. An Extended MAC ACL provides the hexadecimal values for each listed ethertype. The switch supports all ethertypes.
Page 615
Extended MAC ACL Instance 16-15 permit [<dest-IP/ Bit mask specifying the bits to match. The destination wildcard can be one of the following: Mask>|any|host <IP>] {<ICMP-type> {<ICMP-code>}} • xx:xx:xx:xx:xx:xx/ xx:xx:xx:xx:xx:xx – Destination MAC address and mask • any – Uses any available destination host •...
16-16 Motorola RF Switch CLI Reference Guide The permit command in the MAC ACL disallows traffic based on layer 2 (data-link layer) information. A MAC access list permits traffic from a source MAC address or any MAC address. It also has an option to allow traffic from a list of MAC addresses (based on the source mask).
Extended MAC ACL Instance 16-17 16.1.8.3 Permitting IP Traffic The example below permits IP based traffic from a source MAC address to any destination MAC address: RFSwitch(config-ext-macl)#permit host 11:22:33:44:55:66 any type ip RFSwitch(config-ext-macl)#...
16-18 Motorola RF Switch CLI Reference Guide 16.1.9 service MAC Extended ACL Config Commands Invokes service commands to troubleshoot or debug instance (config-if) configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli...
16-20 Motorola RF Switch CLI Reference Guide 16.1.10 show MAC Extended ACL Config Commands Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: •...
Page 621
Extended MAC ACL Instance 16-21 banner Display Message of the Day Login banner boot Display boot configuration. clock Display system clock commands Show command lists crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration wios dataplane environment show environmental information file Display filesystem information firewall...
Page 622
16-22 Motorola RF Switch CLI Reference Guide terminal Display terminal configuration parameters traffic-shape Display traffic shaping timezone Display timezone upgrade-status Display last image upgrade status users Display information about currently logged in users version Display software & hardware version virtual-ip...
Extended MAC ACL Instance 16-23 16.2 Configuring MAC Extended ACL MAC Extended ACLs contain rules based on the following parameters: • Source MAC address • Destination MAC address • Ethertype– accepts well known types like IP, ARP, VLAN or an integer value between 1-65535.
DHCP Server Instance Use the instance to configure the DHCP server address pool associated (config-dhcp) with the switch. To move to this instance, use the command. RFSwitch(config)#ip dhcp pool <pool-name> RFSwitch(config-dhcp)# Also refer to Chapter 12, Interface Instance, Section 12.1.8 ip for other DHCP related configurations.
Page 626
17-2 Motorola RF Switch CLI Reference Guide Table 17.1 DHCP Server Command Summary Command Description Ref. client-name Assigns a client name page 17-10 clrscr Clears the display screen page 17-11 ddns Configures Dynamic DNS (DDNS) values page 17-12 default-router Configures a default router’s IP address...
Page 627
DHCP Server Instance 17-3 Table 17.1 DHCP Server Command Summary Command Description Ref. service Invokes service commands to troubleshoot or debug page 17-30 instance configurations (config-dhcp) show Displays the running system information page 17-31 unitcast-enable Enables unicast for DHCP page 17-35 update Controls the usage of Dynamic DNS (DDNS) page 17-34...
17-4 Motorola RF Switch CLI Reference Guide 17.1.1 address DHCP Config Commands Specifies a range of addresses for the DHCP network pool Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax address range <low IP address> <high IP address>...
17.1.2 bootfile DHCP Config Commands Assigns a bootfile name for the DHCP configuration on the network pool Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax bootfile <FILE> Parameters bootfile <FILE> Sets the boot image for BOOTP clients. The file name can contain letters, numbers, dots and hyphens.
17-6 Motorola RF Switch CLI Reference Guide 17.1.3 class DHCP Config Commands Associates a DHCP class with a pool This command is used in Step 4 of Creating a DHCP User Class. The CLI prompt moves to a sub-instance .The configuration mode...
DHCP Server Instance 17-7 3. Create a Pool named , using mode. (config)# RFSwitch(config)#ip dhcp pool WID RFSwitch(config-dhcp)# 4. Associate the DHCP class, created in Step 1 with the pool created in Step 3. The switch supports the association of 8 DHCP classes with a pool. RFSwitch(config-dhcp)#class RFS7000DHCPclass RFSwitch(config-dhcp-class)# 5.
Page 632
17-8 Motorola RF Switch CLI Reference Guide address config-dhcp-class Sets an address range for a DHCP class within a DHCP server address pool Syntax address range <low IP Address> <high IP Address> Parameters range <low IP Address> Assigns an address range for the DHCP class <high IP Address>...
DHCP Config Commands Assigns a name to the client-identifier A client identifier is used to reserve an IP address for a DHCP client. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax client-identifier <identifier> Parameters client-identifier Prepends a null character.
17-14 Motorola RF Switch CLI Reference Guide 17.1.8 default-router DHCP Config Commands Configures the default router or gateway IP address for the network pool. To remove the default router list, use the command. no default-router Supported in the following platforms: •...
Sets the DNS server’s IP address available to all DHCP clients connected to the pool. Use command to remove the DNS server list. no dns-server Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax dns-server <IP address> Parameters dns-server <IP address>...
17-16 Motorola RF Switch CLI Reference Guide 17.1.10 domain-name DHCP Config Commands Sets the domain name for the network pool. Use the command to no domain-name remove the domain name. Supported in the following platforms: • RFS7000 • RFS6000 •...
17-17 17.1.11 end DHCP Config Commands Exits the current mode and moves to the PRIV EXEC mode. The prompt changes to RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-dhcp)#end RFSwitch#...
17-18 Motorola RF Switch CLI Reference Guide 17.1.12 exit DHCP Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch#(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
Reserves an IP address (manually) based on a DHCP client’s hardware address. Use the command to remove this from the DHCP pool. hardware-address Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax hardware-address <MAC> {[ethernet|token-ring]} Parameters hardware-address Sets the client's hardware address to <MAC>.
17-20 Motorola RF Switch CLI Reference Guide 17.1.14 help DHCP Config Commands Displays the system’s interactive help in HTML format Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-dhcp)#help CLI provides advanced help feature.
Defines a fixed IP address for the host in dotted decimal format Use the command to remove the host from the DHCP pool. no host Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax host <IP> Parameters host <IP>...
17-22 Motorola RF Switch CLI Reference Guide 17.1.16 lease DHCP Config Commands Sets a valid lease time for the IP address used by DHCP clients in the network pool Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax lease [{<0-365>...
Page 647
DHCP Server Instance 17-23 NOTE: The factory default lease period for a pool – network pool or host pool is configured as 1 day. Example RFSwitch(config-dhcp)#lease 1 0 0 RFSwitch(config-dhcp)# RFSwitch(config)#show running-config ..........................ip dhcp pool Test4lease host 3.33.33.3 client-name test4lease client-identifier tested4lease ..........
17-26 Motorola RF Switch CLI Reference Guide 17.1.19 network DHCP Config Commands Sets the network pool’s IP address This address maps the current DHCP pool with a specific network. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax network [<IP>|<IP/Mask>]...
17.1.20 next-server DHCP Config Commands Sets the IP address of the next server in the boot process Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax next-server <IP> Parameters next-server <IP> Sets the next server in boot process •...
Page 652
17-28 Motorola RF Switch CLI Reference Guide 17.1.21 no DHCP Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [address|bootfile|class|client-identifier|client-name| ddns|default-router|dns-server|domain-name|hardware-address| host|lease|netbios-name-server|netbios-node-type|network| next-server|option|update|unicast-table] Parameters command negates any command associated with it. Wherever required, use the same parameters associated with the command getting negated.
DHCP Server Instance 17-29 17.1.22 option DHCP Config Commands Defines the DHCP option used in DHCP pools Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax option <option-name> [<IP>|<option-name>] Parameters option name [<IP>| Sets raw DHCP options <option-name>] •...
17-30 Motorola RF Switch CLI Reference Guide 17.1.23 service DHCP Config Commands Invokes service commands to troubleshoot or debug instance (config-dhcp) configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters show cli...
Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <paramater>...
Page 656
17-32 Motorola RF Switch CLI Reference Guide dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server...
Page 657
DHCP Server Instance 17-33 version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl RFSwitch(config-dhcp)#...
17-34 Motorola RF Switch CLI Reference Guide 17.1.25 update DHCP Config Commands Controls the usage of the DDNS service Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax update dns override Parameters update dns override Controls the usage of the DDNS service •...
17-36 Motorola RF Switch CLI Reference Guide 17.2 Configuring the DHCP Server using Switch CLI The switch DHCP configuration is conducted by creating pools and mapping them to L3 interfaces (SVI). • A Network pool is the pool with “include” ranges. When the network pool is mapped to a L3 interface, DHCP clients requesting IPs from the L3 interface get an IP from the configured range.
DHCP Server Instance 17-37 17.2.1 Creating network pool To create a network pool: 1. Create a DHCP server dynamic address pool. RFSwitch(config)#ip dhcp pool test 2. Map the DHCP pool to the network pool. RFSwitch(config-dhcp)#network 192.168.0.0/24 3. Add the address range for the dynamic pool. RFSwitch(config-dhcp)#address range 192.168.0.30 192.168.0.60 4.
17-38 Motorola RF Switch CLI Reference Guide 17.2.2 Creating a Host Pool To create a host pool: 1. Create a DHCP server host address pool. RFSwitch(config)#ip dhcp pool hostpool 2. Assign the client name of the host for which static allocation is required.
DHCP Server Instance 17-39 17.2.3 Troubleshooting DHCP Configuration 1. The DHCP Server is disabled by default. Use the following command to enable the DHCP Server: RFSwitch(config)#service dhcp This command administratively enables the DHCP server. If the DHCP configuration is incomplete, it is possible the DHCP server will be disabled even after the execution of this command.
Page 664
17-40 Motorola RF Switch CLI Reference Guide 5. A host pool should have its corresponding network pool configured, otherwise the host pool is useless. The fixed IP address configured in the host pool must be in the subnet of the corresponding network pool.
DHCP Server Instance 17-41 17.2.4 Creating a DHCP Option To create a DHCP option: 1. To create a non standard option named “tftp-server”. RFSwitch(config)#ip dhcp option tftp-server 183 ip 2. Enter the DHCP pool —”test”. RFSwitch(config)#ip dhcp pool test 3. Assign a value to the DHCP option configured above. RFSwitch(config-dhcp)#option tftp-server 192.168.0.100 4.
DHCP Class Instance Use the (config-dhcpclass) instance to configure DHCP user classes. The switch supports a maximum of 8 user classes per DHCP class. To navigate to this instance use the command: RFSwitch(config)#ip dhcp class <class-name> RFSwitch(config-dhcpclass)# Refer to ip on page 12-11 DHCP Class Instance on page 18-1 for other DHCP related configurations.
Page 668
18-2 Motorola RF Switch CLI Reference Guide Table 18.1 DHCP Server Class Config Commands Command Description Ref. Negates a command or sets its defaults page 18-8 option Defines DHCP Server options page 18-9 service Invokes service commands to troubleshoot or debug...
DHCP Class Instance 18-3 18.1.1 clrscr DHCP Server Class Config Commands Clears the display screen Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax clrscr Parameters None Example RFSwitch(config-dhcpclass)#clrscr RFSwitch(config-dhcpclass)#...
18-4 Motorola RF Switch CLI Reference Guide 18.1.2 end DHCP Server Class Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 •...
18.1.3 exit DHCP Server Class Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-dhcpclass)#exit...
18-6 Motorola RF Switch CLI Reference Guide 18.1.4 help DHCP Server Class Config Commands Displays the system’s interactive help in HTML format Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-dhcpclass)#help CLI provides advanced help feature.
DHCP Class Instance 18-7 18.1.5 multiple-user-class DHCP Server Class Config Commands Enables the multiple-user-class option Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax multiple-user-class Parameters None Example RFSwitch(config-dhcpclass)#multiple-user-class RFSwitch(config-dhcpclass)#...
Page 674
18-8 Motorola RF Switch CLI Reference Guide 18.1.6 no DHCP Server Class Config Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [multiple-user-class|option] np option user-class <class-name>...
18.1.7 option DHCP Server Class Config Commands Specifies a value for DHCP user class options Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax option user-class <class-name> Parameters user-class <class-name> Creates/modifies DHCP server user class options •...
Page 676
18-10 Motorola RF Switch CLI Reference Guide 4. Associate the DHCP class, created in Step 1 with the pool created in Step 3. The switch supports the association of 8 DHCP classes with a pool. RFSwitch(config-dhcp)#class RFS7000DHCPclass RFSwitch(config-dhcp-class)# 5. The switch moves to a new mode (config-dhcp-class). Use this mode to add an address range for the DHCP class associated with the pool.
18.1.8 service DHCP Server Class Config Commands Invokes service commands to troubleshoot or debug instance configurations (config-if) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters None Example RFSwitch(config-dhcpclass)#service show cli DHCP Server Class Config mode:...
18-12 Motorola RF Switch CLI Reference Guide 18.1.9 show DHCP Server Class Config Commands Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: •...
Page 679
DHCP Class Instance 18-13 crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server licenses...
Page 680
18-14 Motorola RF Switch CLI Reference Guide users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl RFSwitch(config-dhcpclass)#show RFSwitch(config-dhcpclass)#show ip dhcp binding MAC/Client-Id Expiry Time...
Radius Server Instance Use the instance to configure local RADIUS server parameters. (config-radsrv) Local (Onboard) RADIUS server commands are listed under this mode. To navigate to this instance, use the command: RFSwitch(config)#radius-server local RFSwitch(config-radsrv)# 19.1 Radius Configuration Commands Table 19.1 summarizes the Global Config command: Table 19.1 RADIUS Server Command Summary Command...
Page 682
19-2 Motorola RF Switch CLI Reference Guide Table 19.1 RADIUS Server Command Summary Command Description Ref. group Sets RADIUS user group parameters. page 19-10 NOTE: This command navigates to another sub-instance called with config-radsrv-group its own command summary. help Displays the interactive help system...
Radius Server Instance 19-3 19.1.1 authentication Radius Configuration Commands Configures the authentication scheme used with the RADIUS server Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax authentication [data-source|eap-auth-type] authentication data-source [ldap|local] authentication eap-auth-type [all|peap-gtc| peap-mschapv2|tls|ttls-md5|ttls-mschapv2|ttls-pap] Parameters...
Page 684
19-4 Motorola RF Switch CLI Reference Guide eap-auth-type Defines RADIUS EAP and default authentication [all| configurations peap-gtc| peap-mschapv2|tls| • all – Enables TTLS and PEAP settings ttls-md5|ttls-mschapv2 • peap-gtc – Defines the EAP and PEAP settings used with ttls-pap] the default authentication configuration •...
Page 685
Radius Server Instance 19-5 19.1.2 ca Radius Configuration Commands Configures CA (Certificate Authority) parameters Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ca trust-point <trustpoint-name> Parameters trust-point Defines the trustpoint configuration <trustpoint-name> • <trustpoint-name> – Displays the existing trustpoint...
To enable the certificate revocation list, ensure the is loaded using a crl list command. crypto pki import <trustpoint-name> crl Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax crl-check enable Parameters enable Enables the CRL check Usage Guidelines TLS uses certificates for authentication.
19-8 Motorola RF Switch CLI Reference Guide 19.1.5 end Radius Configuration Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
19.1.6 exit Radius Configuration Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-radsrv)#exit RFSwitch(config)#...
19-10 Motorola RF Switch CLI Reference Guide 19.1.7 group Radius Configuration Commands Configures RADIUS user groups The CLI moves to the sub-instance to create a new group. config-radsrv-group The prompt changes from RFSwitch(config-radsrv)# RFSwitch(config-radsrv-group)# Supported in the following platforms: •...
Radius Server Instance 19-11 Table 19.2 RADIUS User Group Command Summary Command Description Ref. service Invokes RADIUS service commands if stopped page 19-18 show Displays running system information page 19-19 19.1.7.1 clrscr group Clears the display screen Syntax clrscr Parameters None Example...
19-12 Motorola RF Switch CLI Reference Guide 19.1.7.3 exit group Ends the current mode and moves to the previous mode ). The prompt (config-radsrv) changes to RFSwitch(config)# Syntax exit Parameters None Example RFSwitch(config-radsrv-group)#exit RFSwitch(config-radsrv)#group 19.1.7.4 group group Establishes RADIUS user group parameters. This command creates a group within the...
Radius Server Instance 19-13 Parameters enable Defines this group as a guest group guest-group Usage Guidelines Creates a guest group. The guest user created using can only be part of the rad-user guest group. Example RFSwitch(config-radsrv-group)#guest-group enable RFSwitch(config-radsrv-group)# 19.1.7.6 help ...
Page 694
19-14 Motorola RF Switch CLI Reference Guide 19.1.7.7 no group Use this command to negate a command or set its defaults Syntax no [policy|rad-user|rate-limit] no policy [day|time|vlan|wlan] no policy wlan [<1-256>|all] <1-256> no rate-limit [wired-to-wireless|wireless-to-wired] Parameters policy [day|time|vlan| Defines the RADIUS group access policy configuration wlan] •...
Radius Server Instance 19-15 RFSwitch(config-radsrv-group)# RFSwitch(config-radsrv-group)#no policy vlan RFSwitch(config-radsrv-group)# RFSwitch(config-radsrv-group)#no policy wlan 2 5 RFSwitch(config-radsrv-group)# RFSwitch(config-radsrv-group)#no rad-user all RFSwitch(config-radsrv-group)# RFSwitch(config-radsrv-group)#no service radius %%Info: Radius service stopped... RFSwitch(config-radsrv-group)# 19.1.7.8 policy group Sets the authorization policies for a particular group (like day/time of access, WLANs allowed etc.) NOTE: A user-based VLAN is effective only if dynamic VLAN authorization is enabled for the WLAN (as defined within the WLAN...
Page 696
19-16 Motorola RF Switch CLI Reference Guide Parameters Day of access policy configuration [all|su|mo|tu|we|th|fr|sa| • all – All days (from Sunday to Saturday) weekdays] • su – Sunday • mo – Monday • tu – Tuesday • we – Wednesday •...
Radius Server Instance 19-17 RFSwitch(config-radsrv-group)#policy wlan 20 21 22 23 RFSwitch(config-radsrv-group)# 19.1.7.9 rad-user Radius Configuration Commands Adds an existing RADIUS user to this group. If the RADIUS user is not available in the Onboard RADIUS server’s database, create a new RADIUS user using the rad-user command from within the mode.
19-18 Motorola RF Switch CLI Reference Guide wireless-to-wired Up link direction from wireless client to network <100-100000> • <100-100000> – Rate in the range of <100-100000> kbps Usage Guidelines to remove the [no] rate-limit [wired-to-wireless|wireless-to-wired] rate limit applied to the group.
Radius Server Instance 19-19 +-enable [guest-group enable] +-help [help] ......................................... RFSwitch(config-radsrv-group)# 19.1.7.12 show Radius Configuration Commands Displays current system information running on the switch Syntax show <paramater> Parameters Displays the parameters for which information can be viewed using the show command Example RFSwitch(config-radsrv-group)#show ?
Page 700
19-20 Motorola RF Switch CLI Reference Guide history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server licenses Show any installed licenses logging Show logging configuration and buffer Internet Protocol (IP) mac-name Displays the co nfigured MAC names...
Radius Server Instance 19-21 RFSwitch(config-radsrv-group)# 19.1.7.13 wlan 19.1.7.14 Example–Creating a Group sub-instance is explained in the example below: (config-radsrv-group) 1. Create a group called Sales in the local RADIUS server database. RFSwitch(config-radsrv)#group sales 2. Check the RADIUS user group’s configuration. RFSwitch(config-radsrv-group)#? RADIUS user group configuration commands: 3.
Page 702
19-22 Motorola RF Switch CLI Reference Guide 7. Use to add a NAS entry for the group. (config-radsrv)#nas RFSwitch(config-radsrv)#nas ? A.B.C.D/M Radius client IP address RFSwitch(config-radsrv)#nas 10.10.10.0/24 ? Radius client shared secret RFSwitch(config-radsrv)#nas 10.10.10.0/24 key ? Password is specified UNENCRYPTED...
Radius Server Instance 19-23 19.1.8 help Radius Configuration Commands Displays the system’s interactive help in HTML format Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-radsrv)#help? help Description of the interactive help system RFSwitch(config-radsrv)#help CLI provides advanced help feature.
19-24 Motorola RF Switch CLI Reference Guide 19.1.9 ldap-server Radius Configuration Commands Sets the LDAP server configuration It uses the existing external database (active directory with the onboard RADIUS server) instead of the local database on the switch. Supported in the following platforms: •...
Page 705
Radius Server Instance 19-25 Parameters ldap-server primary host Sets the primary LDAP server’s configuration <IP> port <1-65535> • host < IP> – Sets the LDAP server’s IP configuration login <user-name> • <IP> – Defines the LDAP server IP address bind-dn •...
Radius Server Instance 19-27 19.1.10 nas Radius Configuration Commands Sets the configuration of the RADIUS client Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax nas <IP/Mask> key [0<key>|2<key>|<key>] Parameters <IP/Mask> Sets the RADIUS client’s IP address [0<key>|2<key>|<key>] Sets the RADIUS client’s shared key...
Page 708
19-28 Motorola RF Switch CLI Reference Guide 19.1.11 no Radius Configuration Commands Negates a command or sets its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [authentication|ca|crl-check|group|ldap-server|nas|proxy| rad-user|server] Parameters None Example RFSwitch(config-radsrv)#no authentication data-source...
19-29 19.1.12 proxy Radius Configuration Commands Configures a proxy RADIUS server based on the realm/suffix Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax proxy [realm|retry-count|retry-delay] proxy relam <relam-name> server <IP> port <1024-65535> secret{<secret>|<secret>|<secret>} Parameters relam <relam-name>...
Page 710
19-30 Motorola RF Switch CLI Reference Guide Example RFSwitch(config-radsrv)#proxy realm Test server 10.10.10.1 port 2220 secret "Very Very Secret !!!" RFSwitch(config-radsrv)# RFSwitch(config-radsrv)#proxy retry-count 5 RFSwitch(config-radsrv)# RFSwitch(config-radsrv)#proxy retry-delay 8 RFSwitch(config-radsrv)#...
Radius Server Instance 19-31 19.1.13 rad-user Radius Configuration Commands Sets RADIUS user parameters Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax rad-user <user-name> rad-user <user-name> [access|password|privilege] access [console|ssh|telnet|web] rad-user <user-name> rad-user <user-name> password [0 <password>|2 <password>...
Page 712
19-32 Motorola RF Switch CLI Reference Guide password Sets the RADIUS user password [0<password>|2<passwo • 0 <password> – Defines the password as rd>|<password>] group UNENCRYPTED guest expiry-time • 2 <password> – The password is encrypted with a <HH:MM> expiry-date password encryption secret <MM:DD:YYYY>...
19-34 Motorola RF Switch CLI Reference Guide 19.1.14 server Radius Configuration Commands Configures server certificate parameters used by a RADIUS server The server certificate is a part of a trustpoint created using crypto on page 5-22. Supported in the following platforms: •...
Page 715
Invokes the service commands to troubleshoot or debug the instance (config-radsrv) configuration This command is also used to enable the RADIUS server. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters None Example...
Displays current system information running on the switch Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <paramater>...
Page 718
19-38 Motorola RF Switch CLI Reference Guide dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server...
Page 719
Radius Server Instance 19-39 virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl RFSwitch(config-radsrv)#show...
Wireless Instance Use the instance to configure local RADIUS server parameters (config-wireless) associated with the switch. To navigate to this instance, use the command from the Global Config mode. RFSwitch(config)#wireless RFSwitch(config-wireless)# 20.1 Wireless Configuration Commands This table summarizes commands: (config-wireless) Command Description Ref.
Page 722
20-2 Motorola RF Switch CLI Reference Guide Command Description Ref. ap-containment Defines the Rogue AP containment page 20-16 configuration ap-detection Defines the AP detection configuration page 20-17 ap-image Defines the path to upload the new image over page 20-19 an AP...
Page 723
Wireless Instance 20-3 Command Description Ref. dhcp-one-portal- Enables forwarding of DHCP responses to one page 20-40 forward portal. dhcp-sniff-state Records mobile unit DHCP state information page 20-41 dot11-shared-key-auth Enables support for 802.11 shared key page 20-42 authentication Ends the current mode and moves to the EXEC page 20-43 mode exit...
Page 724
Displays running system information page 20-96 smart-rf Config Smart-RF Management Parameters page 20-101 smart-scan-channels Specify a list channels to motorola clients to page 20-102 perform smart-scan wlan Sets WLAN related parameters page 20-103 wlan-bw-allocation Allocates radio bandwidth (per WLAN)
Page 725
Wireless Instance 20-5 Command Description Ref. non-preferred-ap- Displays number of attempts after which page 20-137 attempts-threshold switch will adopt non preferred APs test Testing neighbor report page 20-138...
• RFS6000 • RFS4000 The number of AAP’s supported differ from switch to switch. • RFS7000 – Supports up to 256 AAP’s • RFS6000 – Supports up to 64 AAP’s • RFS4000 – Supports up to 24 AAP’s Syntax aap [aap-version|auto-upgrade|config-apply|fwupdate| include-config] aap aap-version [aap5131|aap7131] <version-number>...
Page 727
Wireless Instance 20-7 config-apply Applies AAP configuration settings [def-delay|mesh-delay] • def-delay – Sets the default time to delay before <30-10000> applying AAP configuration • <30 -10000> – Set the delay time (in seconds) • mesh-delay – Defines the interval to delay before applying AAP configuration to Mesh APs •...
20-8 Motorola RF Switch CLI Reference Guide 20.1.2 admission-control Wireless Configuration Commands Enable admission control for voice traffic across all radios Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax admission-control voice enable Parameters voice enable Enables admission control for voice on all radios.
20.1.3 adopt-unconf-radio Wireless Configuration Commands Adopts a radio (even if not yet configured). Default templates are used for configuring the adopted radio Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax adopt-unconf-radio enable Parameters None Usage Guidelines...
20-10 Motorola RF Switch CLI Reference Guide 20.1.4 adoption-pref-id Wireless Configuration Commands Preference identifier for the switch All radios configured with this preference identifier are more likely to be adopted by this switch. Supported in the following platforms: • RFS7000 •...
Page 731
Wireless Instance 20-11 20.1.5 ap Wireless Configuration Commands Defines the name, location and other parameters of access ports Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ap [<ap-index>|<ap-index-list>|<MAC>] [aap-admin-passwd| aap-mgmt-vlan|aap-native-vlan-id|adoption-policy| aap-native-vlan-tag|country-code|lan-acl|location |name|radio-config|secure-mode||secure-mode-staging] ap <ap-index> aap-admin-passwd <LINE>...
Page 732
20-12 Motorola RF Switch CLI Reference Guide ap <MAC> adoption-policy [allow|deny] ap <MAC> country-code <country-code> ap <MAC> lan-acl ap <MAC> location <location> ap <MAC> name <name> ap <MAC> secure-mode [enable|secret [0 <secret>| 2 <secret>|<secret>] ap <MAC> secure-mode-staging enable ap <MAC> radio-config [2-4-wlan-5-0-wlan|2-4-wlan-5-0-wlan-...
Page 733
Wireless Instance 20-13 Parameters <ap-index> Sets a single AP index. Use the show wireless ap [adoption-policy|aap- command to view the AP’s index value. admin-passwd| aap- • adoption-policy [allow|deny]– Specifies adoption policy mgmt-vlan |aap-native- • allow – Allow adoption vlan-id|aap-native-vlan- • deny – Deny adoption tag|country-code| •...
Page 734
20-14 Motorola RF Switch CLI Reference Guide • enable – Configure secure-mode to a set of APs (specified by LIST). The AP's MAC and mode will be saved in the running configuration. If secure-mode is enabled, the WISP-e for this AP is secured •...
Page 735
Wireless Instance 20-15 <ap-index-list> A list (eg: 1,3,7) or range (eg: 3-7) of AP indices from the [aap-admin-passwd|aap- command show wireless ap native-vlan-id|aap- mgmt-vlan| aap-native-vlan- tag|adoption-policy| country-code| location|lan-acl| name|secure-code| secure-mode-stagging] <MAC-address> Lists an AP’s MAC address. [aap-admin-passwd|aap- native-vlan-id|aap- native-vlan- tag|adoption-policy| country- code|location|lan-acl| name|radio-config|...
Page 738
20-18 Motorola RF Switch CLI Reference Guide detect-wired-rouge Detection of the rogue APs which are also found on the enable wired network • enable – Starts detecting rogue APs on the wired network enable Allows access ports to look for APs...
20-19 20.1.8 ap-image Wireless Configuration Commands Defines the path to upload the new image over an AP Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ap-image [ap100|ap300-ids-sensor|ap300-wisp|ap300-wispe| ap4131|ap5131|ap650-wispe|ap7131|revert-ap4131] <file-path> Parameters [ap100| The interface to upload new AP image. The following APs...
20-22 Motorola RF Switch CLI Reference Guide 20.1.10 ap-standby-attempts-threshold Wireless Configuration Commands Sets the number of attempts after which the standby switch starts adopting APs. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ap-standby-attempts-threshold <attempts>...
20.1.11 ap-timeout Wireless Configuration Commands Changes the default inactivity timeout for access ports Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax ap-timeout <index> <timeout> Parameters • <index> – Access-ports identified by a single index or by <index>...
20-24 Motorola RF Switch CLI Reference Guide 20.1.12 ap-udp-port Wireless Configuration Commands Configures the UDP port for layer 3 adoption of APs You also need to configure the DHCP server providing the APs the same parameter. Supported in the following platforms: •...
Wireless Configuration Commands Specifies a list of channels that will be used when automatic channel scan (ACS) and dynamic frequency selection (DFS) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax auto-select-channels [11a|11bg] [<channel-list>| add <channel-list>|remove <channel-list>]...
20-26 Motorola RF Switch CLI Reference Guide 20.1.14 broadcast-tx-speed Wireless Configuration Commands Configure the rate at which broadcast and multicast traffic is transmitted between the switch and mobile unit Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
Refer section config-wireless-client-list Commands on page 20-29 command summary. (config-wireless-client-list) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax client [exclude-list|include-list] <list-name> Parameters exclude-list <list-name> Sets the wireless client exclude list configuration. A MU NAC check is conducted, except for those in the exclude list.
20-28 Motorola RF Switch CLI Reference Guide 20.1.15.1 Configuring a Client Refer to the configurations below to: • Create an exclude list. RFSwitch(config-wireless)#client exclude-list protected-hosts RFSwitch(config-wireless-client-list)# • Add a host entry into the exclude list. RFSwitch(config-wireless-client-list)# station printers 00:00:AA:DD:EE:11/00:00:FF:DD:EE:11 RFSwitch(config-wireless-client-list)# station testing-host1 00:11:AA:03:1B:FE •...
Wireless Instance 20-29 20.1.15.2 config-wireless-client-list Commands to enter the ( (config-wireless)# client config-wireless-client-list) instance. Use this instance, to create an exclude list or include list. This table summarizes commands: config-wireless-client-list Command Description clrscr Clears the display screen Ends the current mode and moves to the EXEC mode exit Ends the current mode and moves to the previous mode help...
Page 750
20-30 Motorola RF Switch CLI Reference Guide Parameters <host-name> Defines an index for this host entry in the client list. The [<MAC>|<MAC/Mask>] host station name <host-name> must be of size 1-21 characters. • <MAC> –Sets the MU mac address in AA-BB-CC-DD-EE- FF or AA:BB:CC:DD:EE:FF or AABB.CCDD.EEFF format...
20-32 Motorola RF Switch CLI Reference Guide 20.1.17 cluster-master-support Wireless Configuration Commands Sets the parameters for cluster master support This is required for cluster level functions. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax cluster-master-support enable...
NOTE: The number of APs supported by command differs convert-ap for each switch. • RFS7000 supports <1-256> APs • RFS6000 supports <1-64> APs • RFS4000 supports <1-6> APs Syntax convert-ap <ap-index> [default|sensor|standalone] convert-ap <ap-index> [default|standalone] convert-ap <ap-index> sensor {static-ip <IP/Mask>...
Page 754
20-34 Motorola RF Switch CLI Reference Guide Parameters <ap-index> Sets the indices of the APs to be converted. [default|sensor| • <ap-index> – The index of the AP to be converted. This standalone] index can be found from the 'show wireless ap' command •...
Wireless Instance 20-35 Example RFSwitch(config-wireless)#convert-ap 1 default 20.1.18.1 Converting an AP to Sensor To convert an AP300 to a sensor: 1. Use command to setup the sensor. sensor RFSwitch(config-wireless)#sensor default-config ? ip-mode configure the IP address mode of the sensors wips-server-ip specify IP addresses of the WIPS server Select either as the sensor parameter.
20-36 Motorola RF Switch CLI Reference Guide 20.1.19 country-code Wireless Configuration Commands Sets the country of operation All existing radio configurations will be erased Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 country-code <country-code> Parameters <country-code>...
Wireless Instance 20-37 20.1.20 debug Wireless Configuration Commands Debugging functions for the Cellcontroller (wireless) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax debug cc [access-port|all|alt|ap-containment|ap-detect| capwap|cluster|config|dot11|eap|ids|kerberos|l3-mob|loc-ap| loc-mu|media|mobile-unit|radio|radius|self-heal|smart|snmp| system|wips|wisp|wlan] {debug|err|info|warn} Parameters access-port Sets the parameters for the access-port logs...
Page 758
20-38 Motorola RF Switch CLI Reference Guide loc-ap Sets the parameters for the AP locationing logs loc-mu Sets the parameters for the MU locationing logs media Sets the parameters for the encapsulation media logs mobile-unit Sets the parameters for the mobile-unit logs...
Page 759
Wireless Instance 20-39 capwap capwap logs cluster cluster related logs config configuration change logs dot11 datapath logs 802.1x/eap logs intrusion detection logs kerberos kerberos logs l3-mob Layer3 mobility logs loc-ap loc-ap logs loc-mu loc-mu logs media encapsulation media logs mobile-unit mobile-unit logs radio radio logs...
20-40 Motorola RF Switch CLI Reference Guide 20.1.21 dhcp-one-portal-forward Wireless Configuration Commands Enables the option to forward DHCP responses to one portal when the destination mobile- unit is known from the response content Supported in the following platforms: • RFS7000 •...
Wireless Instance 20-41 20.1.22 dhcp-sniff-state Wireless Configuration Commands Records mobile unit DHCP state information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax dhcp-sniff-state enable Parameters enable Allows support for recording DHCP state information for mobile units...
20-42 Motorola RF Switch CLI Reference Guide 20.1.23 dot11-shared-key-auth Wireless Configuration Commands Enables support for 802.11 shared key authentication NOTE: Shared key authentication has known weaknesses that can compromise your WEP key. It should only be configured to accommodate wireless stations unable to carry out Open-System authentication.
20.1.24 end Wireless Configuration Commands Ends and exits the current mode and changes to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-wireless)#end RFSwitch#...
20-44 Motorola RF Switch CLI Reference Guide 20.1.25 exit Wireless Configuration Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
20-45 20.1.26 fix-broadcast-dhcp-rsp Wireless Configuration Commands Converts broadcast DHCP server responses to unicast Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax fix-broadcast-dhcp-rsp enable Parameters enable Enables support for converting broadcast DHCP server responses to unicast...
20-46 Motorola RF Switch CLI Reference Guide 20.1.27 help Wireless Configuration Commands Displays the system’s interactive help (in HTML format) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-wireless)#help CLI provides advanced help feature.
Wireless Configuration Commands Configures the WLAN hotspot configuration This overrides or adds to the existing hotspot configuration on the WLAN. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax hotspot query <query-index> <query-field> [controller-ip|ssid|mu-ip|controller-name|user-string] Parameters <query-index>...
20-48 Motorola RF Switch CLI Reference Guide 20.1.29 load-balance Wireless Configuration Commands Configures the user load balance mode Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax load-balance [by-count|by-throughput] Parameters by-count In load balance by user count, the load on the radio is measured by the number of MUs associated.
20-49 20.1.30 mac-auth-local Wireless Configuration Commands Configures the local MAC authentication list Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax mac-auth-local <1-1000> [allow|deny|rate-limit] mac-auth-local <1-1000> [allow|deny] <starting-MAC> <ending-MAC> [<list>|not-mapped] {<radio-desc>| zone [<1-48>|default|unknown]} mac-auth-local <1-1000> rate-limit [wired-to-wireless|wireless-to-wired] <100-1000000>...
Page 770
20-50 Motorola RF Switch CLI Reference Guide <radio-desc> Optional radio description substring. zone Optional GeoFencing location information for devices [<1-48>|default| matching this ACL information. unknown] • <1-48> – Administrator defined-id • default – The user has been located within the site in the default zone •...
Wireless Instance 20-51 20.1.31 manual-wlan-mapping Wireless Configuration Commands Manually maps WLANs configured on a radio Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax manual-wlan-mapping enable Parameters enable Enables support for manual WLAN mapping. Usage Guidelines...
20-54 Motorola RF Switch CLI Reference Guide 20.1.34 multicast-packet-limit Wireless Configuration Commands Sets a multicast packet limit, per second, for a VLAN. This limits the broadcast/multicast packets per VLAN. The default value is 32 broadcast/multicast packets per second. Setting the limit to 0 disables this control.
20.1.35 multicast-throttle-watermark Wireless Configuration Commands Configures watermarks for supporting bursts of broadcast/multicast frames Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax multicast-throttle-watermarks low <0-100> high <0-100> Parameters low <0-100> Sets the low water-mark. If the percentage of free packets in the system is lower than this threshold, the incoming frame is dropped.
20-56 Motorola RF Switch CLI Reference Guide 20.1.36 nas-id Wireless Configuration Commands Configures the NAS ID to be sent to the RADIUS server Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax nas-id <nas-id> To override nas-id on a per WLAN basis: wlan <1-4098>...
20.1.37 nas-port-id Wireless Configuration Commands Configures the NAS port ID that must be sent to the RADIUS server Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax nas-port-id <port-id> Parameters <port-id> The port ID to be sent to the RADIUS server.
Page 778
20-58 Motorola RF Switch CLI Reference Guide 20.1.38 no Wireless Configuration Commands Negates a command or sets its defaults. All the parameters mentioned in the syntax can be negated using the command. Supported in the following platforms: • RFS7000 •...
Wireless Configuration Commands Responds to ARP requests from the RON to the WLAN on behalf of mobile units Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 proxy-arp enable Parameters enable Enables the support for proxy arp...
• RFS4000 The radios range differs from switch to switch. group-id • RFS7000 – Supports a range between 0-255 • RFS6000 – Supports a range between 0-64 • RFS4000 – Supports a range between 1-6 Syntax radio [<1-4096>|<radio-list>|add|all-11a|all-11an|all-11b| all-11bg|all-11bgn|antenna-mode|configure-8021X| default-11a|default-11an|default-11b|default-11bg| default-11bgn|dns-name] radio [<1-4096>|<radio-list>|all-11a|all-11an|all-llb|...
Page 783
Wireless Instance 20-63 radio <1-4096> adoption-policy [allow|deny] radio <1-4096> adoption-pref-id <0-65535> radio <1-4096> ampdu [min-spacing|rx-limit|tx-enable| tx-limit] radio <1-4096> ampdu min-spacing [.25|.5|0|1|2|4|8] radio <1-4096> ampdu rx-limit [16383|32767|65535|8191] radio <1-4096> ampdu tx-enable radio <1-4096> ampdu tx-limit <0-65535> radio <1-4096> antenna-mode [diversity|mimo|primary| secondary] radio <1-4096>...
Page 784
20-64 Motorola RF Switch CLI Reference Guide radio <1-4096> group-id <1-256> radio <1-4096> location-led [start-flashing|stop-flashing] radio <1-4096> location-message <message> radio <1-4096> mac <MAC> radio <1-4096> max-mobile-units <units> radio <1-4096> mu-power <0-20> radio <1-4096> moto-simple-voice enable radio <1-4096> nas-id <nas-id> radio <1-4096> nas-port-id <nas-port-id>...
Page 785
Wireless Instance 20-65 channel-power|client-bridge|detector|dtim-period| enforce-spec-mgmt|enhanced-beacon-table| enhanced-probe-table|location-led| location-message|max-mobile-units|moto-simple-voice| mu-power|on-channel-scan|reset|reset-ap| rf-mode|rss|rts-threshold|run-acs|self-heal-offset|speed| wmm|tunnel] radio [all-llan|default-11an] [adoption-policy|ampdu| antenna-mode|bss|channel-power|rf-mode|speed|tunnel| short-gi] radio [all-11b|default-11b] [adoption-policy| antenna-mode|base-bridge|beacon-interval|bridge-fwd-delay| bridge-hello|bridge-max-ageout|bridge-msg-age| bridge-priority|bss|channel-power|client-bridge|detector| dtim-period|enhanced-beacon-table|enhanced-probe-table| location-message|max-mobile-units|mu-power| on-channel-scan|reset|reset-ap|rf-mode|rss| rts-threshold|run-acs|self-heal-offset|speed|tunnel| short-preamble] radio [all-11bg|default-11bg] [admission-control| adoption-policy|adoption-pref-idantenna-mode|base-bridge| beacon-interval|bridge-fwd-delay|bridge-hello| bridge-max-ageout|bridge-msg-age|bridge-priority|bss| channel-power|client-bridge|detector|dtim-period| enhanced-beacon-table|enhanced-probe-table|location-led location-message|max-mobile-units|moto-simple-voice| mu-power|on-channel-scan|reset|reset-ap| rf-mode|rss|rts-threshold|run-acs|self-heal-offset| speed|tunnel|short-preamble|wmm] radio [all-llbgn|default-11bgn] [adoption-policy|ampdu| antenna-mode|bss|channel-power|rf-mode|speed|tunnel| short-gi] radio add <1-4096>...
Page 786
20-66 Motorola RF Switch CLI Reference Guide Parameters <1-4096> Defines a single radio index. <radio-list> Creates a list (1,3,7) or range (3-7) of radio indices. add <1-4096> <MAC> Adds the specified radio to the radio list at index specified [11a|11an|11b|11bg| for the value in the range 1-4096.
Page 787
Wireless Instance 20-67 The following is the list of parameters for the radio <1-4096>, radio [all- 11a|all-11an|all-11b|all-11bg|all-11bgn|default-11a||default- commands. 11an|default-11b|default-11bg|default-11bgn] admission-control voice Sets the admission control parameters for voice. The [max-mus <0-256>| following options are configured: max-perc <0-100>| • max-mus <0-256> – Configure the maximum number of max-roamed-mus <0- MUs to be admitted 256>|...
Page 788
20-68 Motorola RF Switch CLI Reference Guide antenna-mode Defines the antenna diversity mode. Select from the [diversity|mimo|primary| following options: secondary] • diversity–Full diversity (both antennas) • mimo – MIMO • primary–Primary antenna only • secondary–Secondary antenna only Note: Before executing this command, ensure the radio is present and is a AP300 model.
Page 789
Wireless Instance 20-69 bss [<1-4>|add-wlans| Maps WLANs to radio BSSIDs auto] <wlans> • <1-4>– Sets the BSS where WLANs are mapped • add-wlans <wlans> – Adds new WLANs to existing radios. The other WLANs on the radios are left as is. •...
Page 790
20-70 Motorola RF Switch CLI Reference Guide client-bridge Defines client bridge settings. [bb-radio| • bb-radio <1-16> <MAC>– add the preferred base bridge bridge-selectmode| details enable| • <1-16> – Enables the capability mesh-timeout <2-200>| • MAC – MAC address in AA-BB-CC-DD-EE-FF format ssid <SSID>]...
Page 791
Specifies the radio groups to balance user load. • For RFS7000, <0-255> – Radio group identifier used for an access-port, 0 disables the grouping • For RFS6000, <0-64> – Radio group identifier used for an access-port, 0 disables the grouping...
Page 792
20-72 Motorola RF Switch CLI Reference Guide location-led Changes the mode of operation of the LEDs on an AP. [start-flashing| • start-flashing – Requests parent-ap of specified radio to stop-flashing] begin flashing its LEDs to help locate it • stop-flashing – Requests parent-ap of specified radio to...
Page 793
Wireless Instance 20-73 rf-mode [a|an|b|bg|bgn| Selects the radio speed based on the radio mode selected. custom|g|n] rss enable Remote Site Survivability (RSS) enables the delivery of secure uninterrupted wireless service in remote locations in the event of a device failure. rts-threshold <0-2347>...
20-77 20.1.42 rate-limit Wireless Configuration Commands Sets the default rate limit per user in kbps, and applies to all enabled WLANs Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax rate-limit [wired-to-wireless|wireless-to-wired] <100- 100000> Parameters wired-to-wireless Down link direction from network to wireless client <100-100000>...
20-78 Motorola RF Switch CLI Reference Guide 20.1.43 secure-wispe-default-secret Wireless Configuration Commands Configures the default shared secret for secure WISPE If a new shared secret is not configured for an AP or a list of APs, then a default shared secret will be assigned.
Page 800
20-80 Motorola RF Switch CLI Reference Guide action [both|none| Defines the radio’s self healing action when neighbors are open-rates|raise-power] detected as down. radio [<1-4096>| • both – Raises the power to max and open all rates <radio-list>] • none – No action taken •...
Page 802
20-82 Motorola RF Switch CLI Reference Guide default-config [ Invokes the default configuration sent to sensors when gateway-ip|ip-mode| configured. wips-server-ip] • gateway-ip <IP> – Configure the gateway IP address for sensors to <IP> • ip-mode [dhcp|static <IP/Mask>] – Configures the IP address of the sensors •...
For more information, see Chapter 2, Section 2.1.5 service page 2-7. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service [clear|show|smart-rf|wireless] service clear wireless mobile-unit association-statistics service show [cli|radio-neighbor|smart-rf|wireless] service show cli service show cli radio-neighbor mu <MAC>...
Page 804
20-84 Motorola RF Switch CLI Reference Guide service show wireless group <1-256> service show wireless mu-cache-entry {[<1-8192>|<MAC>]} service show wireless mvlan <1-256> service show wireless radio {[<1-4094>|description|mapping]} service show wireless radio-cache-entry {<MAC>} service show wireless vlan-cache-entry {[<1-8192>|<MAC>]} service show wireless waiting {<0-99> {<0-99>}}...
Page 805
Wireless Instance 20-85 service wireless enhanced-beacon-table scan-interval <10-60> service wireless enhanced-beacon-table scan-time <100-1000> service wireless enhanced-probe-table [enable|erase-report| max-mu|preferred|window-time] service wireless enhanced-probe-table [enable|erase-report] service wireless enhanced-probe-table max-mu <0-512> service wireless enhanced-probe-table preferred <MAC> service wireless enhanced-probe-table window-time <10-60> service wireless free-packet-watermark <0-100> service wireless idle-radio-send-multicast enable service wireless map-radios <1-127>...
Page 806
20-86 Motorola RF Switch CLI Reference Guide show [cli| Displays the current running system information for this radio-neighbor||smart-rf| mode. wireless] • cli – Shows the CLI commands available in this mode • radio-neighbor mu <MAC> – Displays neighboring radios for a station •...
Page 807
Wireless Instance 20-87 • ap-history {<MAC>} – Displays access port history for all MACs. Provide the optional <MAC> parameter to view ap-history for a AP with that MAC address • buffer-counters – Displays allocations for the different buffers • enhanced-beacon-table [config|report] – Displays Enhanced Beacon Table information •...
Page 808
20-88 Motorola RF Switch CLI Reference Guide • description – Description and location co-ordinates of radios • mapping – Radio-to-CPU Mapping • radio-cache-entry {<MAC>} – Displays Radio Cache information. Dumps the whole table if no parameter is given • <MAC> – MAC address of radio-cache entry to show •...
Page 809
Wireless Instance 20-89 • restore [<MAC>|<1-4094>|<index-list>] – Removes radio rescue operation on a given radio • <MAC> – MAC address of a single radio • <1-4094> – Radio index • <index-list> – List of radio indices • save-to-file – Saves smart-rf records to the file smart.bin •...
Page 810
20-90 Motorola RF Switch CLI Reference Guide wireless [ap-history| Configures wireless parameters. clear-ap-log|custom-cli| • ap-history [clear|enable] – Configures access port history dot11i|dump-core| • clear – Clears all history of all APs enhanced-beacon-table| • enable – Enables tracking of AP history enhanced-probe-table| •...
Page 811
Wireless Instance 20-91 • username – The Radius username of the user connected through this device (shown only if applicable and available) • vlan – The VLAN-ID assigned to the mobile-unit • wlan-desc – The WLAN description the mobile-unit is using •...
Page 812
20-92 Motorola RF Switch CLI Reference Guide • dot11i – modify dot11i service parameters • dump-core – Creates a core file of the ccsrvr process • enhanced-beacon-table [channel-set|enable| erase-report|max-ap|scan-interval|scan-time] – Enhanced beacon table for AP locationing • channel-set [a|an|b|bg|bgn] <1-200> – Adds channels to the different radio types.
Page 813
Wireless Instance 20-93 • free-packet-watermark <0-100>– The free packets threshold in percent. If the percentage of free packets is lower than this number, then additional packets will not be queued in the datapath • idle-radio-send-multicast enable – Enables forwarding multicast packets to radios without associated mobile units •...
Page 814
20-94 Motorola RF Switch CLI Reference Guide Example RFSwitch(config-wireless)#service show wireless ap-history AP MAC Radio Timestamp Event Reason ============================================================ ======= 00-A0-F8-BF-8A-4B 20070926-20:23:10 Adoption RFSwitch(config-wireless)# RFSwitch(config-wireless)#service show wireless mvlan 20 Wlan 20: pool_size =1 ----------------------------------------------------- [ 0]: wlan=20, vlan_id=1, limit=0, users=0, log_sent=0...
Page 815
Wireless Instance 20-95 RFSwitch(config-wireless)# RFSwitch(config-wireless)#service show wireless radio description # access-port MAC start BSS radio description coordinates 1] 00-A0-F8-BF-8A-4B 00-A0-F8-BF-EF-B0 11bg RADIO1 0 0 0 2] 00-A0-F8-BF-8A-4B 00-A0-F8-BF-ED-BC 11a RADIO2 0 0 0 RFSwitch(config-wireless)# RFSwitch(config-wireless)#service show wireless snmp-trap- throttle throttle : 10 (default = 10) traps allowed through throttle: 9 traps dropped through throttle: 0 RFSwitch(config-wireless)#...
20-96 Motorola RF Switch CLI Reference Guide 20.1.47 show Wireless Configuration Commands Displays current system information running on the switch For other show commands, see Chapter 2, Section 2.2 show page 2-37. Supported in the following platforms: • RFS7000 •...
Page 817
Wireless Instance 20-97 boot Display boot configuration clock Display system clock commands Show command lists crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session...
Page 818
20-98 Motorola RF Switch CLI Reference Guide sessions Display current active open connections smtp-notification Display SNMP engine parameters snmp Display SNMP engine parameters snmp-server Display SNMP engine parameters spanning-tree Display spanning tree information startup-config Contents of startup configuration static-channel-group static channel group...
Page 819
Wireless Instance 20-99 ........................................ RFSwitch(config-wireless) RFSwitch(config-wireless)#show wireless radio-group group_id | radios ---------------------------------------------------------- 11 | 1,4 RFSwitch(config-wireless)# RFS7000(config-wireless)#show wireless ap Number of access-ports adopted Number of AAPs adopted Available AP licenses Available AAP licenses Redundancy enabled Redundancy mode : active RFS7000(config-wireless)# RFSwitch(config-wireless)show service-list qmtp...
20.1.48 smart-rf Wireless Configuration Commands Configures Smart-RF Management parameters and moves to the instance (config-wireless-smart-rf) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 NOTE: initiates the smart-rf (config-wireless-smart-rf) instance. For more details see Chapter 25, Smart RF Instance.
20-102 Motorola RF Switch CLI Reference Guide 20.1.49 smart-scan-channels Wireless Configuration Commands Specifies a list of channels for Motorola clients to do smart-scan Syntax smart-scan-channels [<channel-list>|add <channel-list>| remove <channel-list>] Parameters <channel-list> A comma-separated list of channels add <channel-list> Add one or more channels to existing channel list remove <channel-list>...
Wireless Instance 20-103 20.1.50 wlan Wireless Configuration Commands Configures Wireless LAN related commands NOTE: Manual mapping of wlan will be erased when the actual wlan is disabled and enabled immediately. Syntax wlan [<1-256>|<wlan-list>] [80211-extensions|802.11w-mfp| aap-proxy-radius|accounting|acl|add-vlan|answer-bcast-ess| authentication-type|client-bridge-backhaul| deny-static-mu|description|dot11i|enable|encryption- type|hold-time|hotspot| inactivity-timeout|independent|ip|kdc|mobility| max-flows-per-mu| mu-mu-disallow|nac-mode|nac-server|nas-id|nas-port-id| qos|radius|secure-beacon|set-vlan-user-limit|...
Page 828
20-108 Motorola RF Switch CLI Reference Guide add-vlan [<1-4094>| Instead of starting a new VLAN assignment for given <vlan-list>] WLAN, this command adds a VLAN assignment to an {limit <1-4094>} existing VLAN assignment. All prior VLAN settings are retained. • [<1-4094>|<vlan-list>] – Sets the VLAN range list <vlan- list>.
Page 829
Wireless Instance 20-109 description <description> Sets the description for this WLAN. Use to identify the selected WLAN.
Page 830
20-110 Motorola RF Switch CLI Reference Guide dot11i [handshake | key| Modifies tkip/ccmp (802.11i) related parameters. key-rotation | • handshake timeout <100-5000> retransmit <1-10> – key-rotation-interval| Sets a handshake for the timeout and retransmission opp-pmk-caching | intervals phrase|pmk-caching | • timeout <100-5000> – Sets the timeout (in...
Page 831
Wireless Instance 20-111 • second-key [enable|key|phrase] – Configures a secondary set of key/passphrase for this WLAN • enable – Enables the use of a secondary key/passphrase • key [0 <secret-key>|2 <secret-key>|<secret-key>] – Configures the key (PMK) • phrase [0 <secret-key>|2 <secret-key>|<secret-key>] – Configures the passphrase •...
Page 832
20-112 Motorola RF Switch CLI Reference Guide encryption-type Sets the encryption type for this WLAN. Options include: [ccmp|keyguard| • ccmp – AES Counter Mode CBC-MAC Protocol none|tkip|tkip-ccmp| (AES-CCM CCMP) wep128|wep64| • keyguard – Keyguard-MCM (Mobile Computing Mode) web128-keyguard] • none – No encryption •...
Page 833
Wireless Instance 20-113 hotspot [allow-eap| Modifies hotspot related parameters allow-list|cache-ageout| • allow-eap – allow EAP authentication in addition to web connection-mode| based login ntf-logout-port| • allow-list <1-32> <IP> – Specifies the allowed list that redirect-to-hostname| user can access without prior authentication. Typically simultaneous-users| this would be the external web-page's IP address query|webpage|...
Page 834
20-114 Motorola RF Switch CLI Reference Guide • <0-8192> – The number of MAC addresses that are allowed to use that username at the same time. 0 implies disabling of the checks • webpage external [failure|login|welcome] <URL> – Modifies hotspot page parameters •...
Page 835
Wireless Instance 20-115 • main-logo – The main logo for the page • small-logo – A small logo for the page • title – The page title Note: The full syntax for the internal page definition is as follows: wlan 1 hotspot webpage internal welcome title Welcome to hotspot page.
Page 836
20-116 Motorola RF Switch CLI Reference Guide ip [arp|dhcp] Sets Internet Protocol settings for ARP and DHCP packets. • arp [rate-limit <1-1000000>|trust] – Address Resolution Protocol configuration • dhcp trust – Dynamic Host Resolution Protocol configuration • trust – Sets the arp/dhcp responses as trusted for this wlan/range •...
Page 837
Wireless Instance 20-117 Modifies KDC related parameters. [password|realm|server] • password [0 <secret>|2 <secret>|<secret>] – Create a KDC server password (up to 127 characters) • 0 <secret>– Password is specified unencrypted • 2 <secret>– Password is encrypted with a password- encryption secret •...
Page 838
20-118 Motorola RF Switch CLI Reference Guide nac-mode [bypass-nac- Sets the Network Access Control (NAC) mode configuration except-include-list| • bypass-nac-except-include-list – No MU NAC check is do-nac-except-exclude- done except for those in include list. Devices in the list|none] include list have NAC checks •...
Page 839
Wireless Instance 20-119 nac-server Configure a NAC server IP address and an optional [primary|secondary| authentication port number. timeout] • [primary|secondary] [<IP> {auth-port <port>}|radius-key [0 <secret>|2 <secret>|<secret>]] – Primary server or secondary server’s IP address • <IP> {auth-port <port>} – Set an EAP server IP address and optional EAP server authentication port (default: is 1812) •...
Page 840
20-120 Motorola RF Switch CLI Reference Guide Quality of Service commands [classification | • classification [background|best-effort|video|voice|wmm] mcast-with-dot11i| – Select how traffic on this WLAN is classified (relative mcast1|mcast2| prioritization on the access port) prioritize-voice| • low – All traffic on this wlan is treated as low priority...
Page 841
Wireless Instance 20-121 • rate-limit [wired-to-wireless|wireless-to-wired] <100-1000000> – Sets traffic rate limit for users on the selected WLAN • wired-to-wireless – Down link direction - from network to wireless client • wireless-to-wired – Up link direction - from wireless client to network •...
Page 842
20-122 Motorola RF Switch CLI Reference Guide • aisfn <2-15> – Arbitration Inter Frame Spacing Number (AIFSN) is the wait time in milliSeconds between data frames. This value is derived using AIFSN and the slot-time • <2-15> – The AIFSN spacing number •...
Page 844
20-124 Motorola RF Switch CLI Reference Guide • authentication-protocol [chap|pap] – Sets the RADIUS Authentication Protocol for RADIUS request. Select from CHAP or PAP • dscp <0-63> – Specify a Differentiated Services Code Point (DSCP) value to provide QoS to RADIUS packets. Set a value in the range 0 to 63 •...
Page 845
Wireless Instance 20-125 • server [primary|secondary] [<IP> {acct-port <port>}| radius-key [0 <key>|2 <key>|<key>]] – Sets the primary or secondary RADIUS server for the selected WLAN • primary – Sets primary RADIUS server information • secondary – Sets secondary RADIUS server information •...
Page 846
20-126 Motorola RF Switch CLI Reference Guide smart-scan-channels Specifies a list of channels to motorola clients to perform a [<channel-list>| smart-scan. The following are the options set: add <channel-list>| • <channel-list> – A comma separated list of channels to remove <channel-list>] scan.
Page 847
Wireless Instance 20-127 vlan [<1-4094>| Sets the VLAN assignment of this WLAN. This command <vlan-list>] starts a new VLAN assignment for a WLAN index. All prior {limit <0-8192>} VLAN settings are erased. • [<1-4094>|<vlan-list>] –Establishes the VLAN range list It can be either a single index, a list (1,3,7) or a range (3- •...
Page 854
20-134 Motorola RF Switch CLI Reference Guide wips events 80211- Configures parameters related to the detection of replay-check-failure| ad- anomalous frames on the RF network. The parameters are: hoc-advertising- • 80211-replay-check-failure – Detects 802.11 replay authorized-ssid | ad-hoc- failure network-violation- •...
Page 855
Wireless Instance 20-135 • fake-ap-flood– Detects suspected ap flood (based on wips events [identical- number of APs observed in a minute) source-and-destination- addresses | • frames-from-unassociated-stations – Detects frames impersonation-attack- from unassociated stations detected|non-changing- • frames-with-bad-essids – filter-ageout <1-86400> – wep-iv|replay-injection- Detects filters age-out duration for the mobile unit frames attack |...
Page 856
20-136 Motorola RF Switch CLI Reference Guide For the above parameters, the following values are set. • enable – Enables monitoring, filtering and triggering alarms • filter-ageout <ageout> – Sets the number of seconds mobile units are filtered in the range <1-86400>...
20-137 20.1.54 non-preferred-ap-attempts-threshold Wireless Configuration Commands Displays the number of attempts after which switch will adopt non preferred APs Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax RFS6000(config-wireless)non-preferred-ap-attempts-threshold <0-20> Parameters non-preferred-ap- Displays the number of attempts after which switch will...
20-138 Motorola RF Switch CLI Reference Guide 20.1.55 test Wireless Configuration Commands Testing neighbour report on air Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax RFS7000(config-wireless)test dot11k [make-bcn-rep| send-beacon-req|send-nbr-rep] RFS7000(config-wireless) test dot11k make-bcn-rep mu <MAC> neighbor <MAC>...
Page 859
Wireless Instance 20-139 send-beacon-req [<1- Triggers the beacon send request 8192>|MU|mu] • <1-8192> – A single index • MU – A list (eg: 1,3,7) or range (eg: 3-7) of indices • mu – Displays mobile-units mac address • MAC –Displays mac address in AA-BB-CC-DD-EE-FF format •...
RTLS Instance Use the instance to configure Real Time Location System (RTLS) (config-rtls) parameters. To navigate to this instance, use the command RFSwitch(config)#rtls RFSwitch(config-rtls)# 21.1 RTLS Config Commands This summarizes commands: config-rtls Command Description Ref. aeroscout Configures aeroscout parameters page 21-3 clear Clears locationing information page 21-4...
Page 862
21-2 Motorola RF Switch CLI Reference Guide Command Description Ref. Negates a command or sets its defaults page 21-11 reference-tag Configures reference tags page 21-14 rfid Configures RFID readers page 21-16 service Invokes service commands to troubleshoot or debug page 21-17...
21-6 Motorola RF Switch CLI Reference Guide 21.1.4 end RTLS Config Commands Ends and exits the current mode and changes to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
NOTE: command instantiates sub- (config-rtls-espi) espi instance. For more details see ESPI Instance on page 22-1. The prompt changes from RFSwitch(config-rtls)# RFSwitch(config-rtls-espi) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax espi Parameters None Example RFSwitch(config-rtls)espi RFSwitch(config-rtls-espi)
21-8 Motorola RF Switch CLI Reference Guide 21.1.6 exit RTLS Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
RTLS Instance 21-9 21.1.7 help RTLS Config Commands Displays the interactive help system for RTLS instance Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-rtls)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
Page 871
RTLS Instance 21-11 21.1.9 no RTLS Config Commands Negates a RTLS command or set its defaults Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [aeroscout|ekahau|reference-tag|service|site| switch|ap|zone] Parameters aeroscout [enable| Negates aeroscout configuration multi-cast-listen|addr] • enable – Disable SOLE adapter •...
Page 872
21-12 Motorola RF Switch CLI Reference Guide service [filter <1-100> Negates service configuration for: {length| • filter <1-100> {length|memory-bank|offset} – Negates memory-bank|offset RFID tag filter configuration for the selected index }|inventory {<1- • length – Length of tag filter 100>|default] •...
Page 873
RTLS Instance 21-13 RFSwitch(config-rtls)#no ekahau enable RFSwitch(config-rtls)# RFSwitch(config-rtls)#no ekahau engine RFSwitch(config-rtls)# RFSwitch(config-rtls)#no service inventory 1 zone 1 RFSwitch(config-rtls)#...
21-14 Motorola RF Switch CLI Reference Guide 21.1.10 reference-tag RTLS Config Commands Configures fixed RFID tag as reference tag and sets its coordinates within a specified location Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax reference-tag rfid <tag-id>...
Page 875
RTLS Instance 21-15 Example RFSwitch(config-rtls)#reference-tag rfid Symbol-Moto coordinates x 600 y 600 orientation 180 range 40 RFSwitch(config-rtls)#...
21-16 Motorola RF Switch CLI Reference Guide 21.1.11 rfid RTLS Config Commands Configures RFID reader parameters Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 NOTE: command instantiates sub- (config-rtls-rfid) rfid instance. For more details see RFID Instance on page 23-1.
RTLS Config Commands Invokes service commands to troubleshoot or debug instance (config-rtls) configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service [filter|inventory|show] service filter <1-100> [action|length|mask| memory-bank|name|offset] service filter <1-100> action [allow|deny] service filter <1-100> length <1-128>...
Page 878
21-18 Motorola RF Switch CLI Reference Guide Parameters service filter <1-100> Configures RFID tag filter [action|length <1- • action [allow|deny] – Configures action for tag filter. By 128>|mask| default its configured to allow memory- • length <1-128> – Configures number of bits to compare bank|name|offset<0-32>]...
Page 879
RTLS Instance 21-19 • start-trigger – Configures start trigger for tag inventory • gpi – Configures GPI event based start trigger • port <1-65535> – Configures GPI port number • event <0-1> – Configures a boolean GPI event value that causes GPI event to trigger •...
21-20 Motorola RF Switch CLI Reference Guide 21.1.13 show RTLS Config Commands Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: •...
Page 881
RTLS Instance 21-21 Example RFSwitch(config-rtls)#show ? access-list Internet Protocol (IP) aclstats Show ACL Statistics information alarm-log Display all alarms currently in the system autoinstall autoinstall configuration banner Display Message of the Day Login banner boot Display boot configuration. clock Display system clock commands Show command lists crypto...
Page 882
21-22 Motorola RF Switch CLI Reference Guide sessions Display current active open connections smtp-notifications Display SNMP engine parameters snmp Display SNMP engine parameters snmp-server Display SNMP engine parameters spanning-tree Display spanning tree information startup-config Contents of startup configuration static-channel-group static channel group membership...
Page 883
RTLS Instance 21-23 Swith Geo Coordinates : Not configured Number of APs RFSwitch(config-rtls)#...
21-24 Motorola RF Switch CLI Reference Guide 21.1.14 site RTLS Config Commands Configures RTLS site dimensions Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax site [description|dimension|name|scale] site description <description> site dimension [unit [feet|meters]|x <1-9000> y <1-9000>...
Page 885
• <1-90> – Configures scale value ranging between1-90 • auto – Configures auto scale Usage Guidelines to rollback the configurations [no] site [description |dimension|name] made using the command site Example RFSwitch(config-rtls)#site description "Motorola RMZ Ecospace, India, 5th Floor" RFSwitch(config-rtls)# RFSwitch(config-rtls)#site name "BLR-RMZ Ecospace" RFSwitch(config-rtls)#...
21-26 Motorola RF Switch CLI Reference Guide 21.1.15 sole RTLS Config Commands Sets Smart Opportunistic Location Engine (SOLE) related configuration commands This command leads you to the sub-instance. (config-rtls-sole)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
21-28 Motorola RF Switch CLI Reference Guide 21.1.17 zone RTLS Config Commands Configures the zone. Maximum of 16 zones can be configured for a site. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax <0-65535> <0-65535> ] zone <1-48>...
Page 889
RTLS Instance 21-29 21.1.18 ap RTLS Config Commands Configures ap coordinates • RFS7000 • RFS6000 • RFS4000 Syntax ap <MAC> coordinates x <0-9000> y <0-9000> z <0-180> Parameters <MAC> coordinates x <0- Select a single zone index for configuration 9000>...
ESPI Instance Use the instance to configure Enterprise Services Programming (config-rtls-espi) Interface (ESPI) related configuration commands. To navigate to this instance, use the commands RFSwitch(config)#rtls RFSwitch(config-rtls)#espi RFSwitch(config-rtls-espi)# 22.1 ESPI Config Commands Table 22.1 summarizes commands: config-rtls-espi Table 22.1 ESPI Config Command Summary Command Description Ref.
Page 892
22-2 Motorola RF Switch CLI Reference Guide Table 22.1 ESPI Config Command Summary (Continued) Command Description Ref. show Shows running system information page 22-...
22.1.3 end ESPI Config Commands Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-rtls-espi)#end RFSwitch#...
22-6 Motorola RF Switch CLI Reference Guide 22.1.4 exit ESPI Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 Syntax exit...
ESPI Instance 22-7 22.1.5 help ESPI Config Commands Displays the system’s interactive help in HTML format Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-rtls-espi)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
Page 898
22-8 Motorola RF Switch CLI Reference Guide 22.1.6 no ESPI Config Commands Defines the name of the adapter or disables the adapter(s) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 no adapter ale-tcp [enable|port <3000-3100>] Parameters...
22.1.7 service ESPI Config Commands Invokes service commands to troubleshoot or debug instance configurations (config-if) Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters None Example RFSwitch(config-rtls-espi)#service show cli ESPI Config mode:...
22-10 Motorola RF Switch CLI Reference Guide 22.1.8 show ESPI Config Commands Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: •...
Page 901
ESPI Instance 22-11 debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server licenses Show any installed licenses logging...
Page 902
22-12 Motorola RF Switch CLI Reference Guide upgrade-status Display last image upgrade status users Display information about currently logged in users version Display software & hardware version wireless Wireless configuration commands wlan-acl wlan based acl RFSwitch(config-rtls-espi)#show RFSwitch(config-rtls-espi)#show rtls espi ?
RFID Instance instance is used to configure RFID reader related (config-rtls-rfid) configuration parameters. To navigate to this instance, use the commands RFSwitch(config)#rtls RFSwitch(config-rtls)#rfid RFSwitch(config-rtls-rfid)# 23.1 RFID Config Commands Table 23.1 summarizes commands: config-rtls-rfid Table 23.1 RFID Config Commands Command Description Ref.
Page 904
23-2 Motorola RF Switch CLI Reference Guide Table 23.1 RFID Config Commands Command Description Ref. service Invokes service commands to troubleshoot or page 23-12 debug instance configurations (config-rtls) show Displays the running system information page 23-15...
23.1.1 activate RFID Instance Activates and enables the Real Time Location System (RTLS ) adapter Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 activate Parameters None Usage Guidelines Use [no] to disable and deactivate the RTLS adapter...
23-5 23.1.3 end RFID Instance Ends and exits the current mode and changes to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-rtls-rfid)#end RFSwitch#...
23-6 Motorola RF Switch CLI Reference Guide 23.1.4 exit RFID Instance Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax...
RFID Instance 23-7 23.1.5 help RFID Instance Displays the interactive help system for RTLS instance Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-rtls-rfid)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
Page 910
23-8 Motorola RF Switch CLI Reference Guide 23.1.6 no RFID Instance Supported in the following platforms: Negates a RTLS command or set its defaults • RFS7000 • RFS6000 • RFS4000 Syntax no [activate|reader|service] Parameters activate Deactivates/disables RTLS adapter reader...
RFID Instance 23-9 23.1.7 reader RFID Instance Configures RFID Readers parameters Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax reader [<index>|<reader-index-list>] reader <index> [antenna|coordinates|description| enable|id|name] reader <index> antenna [<antenna>|<antenna-list>] reader <index> antenna <antenna-list> [coordinates x <x-coordinate>...
Page 912
23-10 Motorola RF Switch CLI Reference Guide antenna Configures the RFID readers antenna. Select a antenna [<antenna>|<antenna- using its index, between <1-8> or range (eg:3-7) of antenna list>] coordinates x <x- indices or any RFID reader antenna coordinate> y <y- •...
Page 913
RFID Instance 23-11 reader [<index>|<reader- Sets a user friendly name to a RFID reader or a group of index-list>] name RFID readers to <name> (1-20 characters) <name> Usage Guidelines to rollback any configurations [no] reader [<index>|<range>][options] performed using the command reader Example RFSwitch(config-rtls-rfid)#reader 1 antenna 1 coordinates x...
23-12 Motorola RF Switch CLI Reference Guide 23.1.8 service RFID Instance Invokes service commands to troubleshoot or debug (config-if) instance configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli service reader [<reader-index>|<reader-index-list>] [antenna|upgrade] service reader [<reader-index>|<reader-index-list>] antenna...
Page 915
RFID Instance 23-13 service reader Displays the RFID reader configuration information [<reader-index>| • <reader-index> – The RFID reader index <reader-index-list>] • <reader-index-list> – A list of comma separated RFID antenna [<antenna- reader indices index>|<antenna- • antenna [<antenna-index>|<antenna-list>|all] – The list>|any] filter [<tag- antenna information filter-index>|<tag-filter- •...
Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <parameter>...
Page 918
23-16 Motorola RF Switch CLI Reference Guide dhcp DHCP Server Configuration wios dataplane environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP)
Page 919
RFID Instance 23-17 timezone Display timezone traffic-shape Display traffic shaping upgrade-status Display last image upgrade status users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl RFSwitch(config-rtls-rfid)#show RFSwitch(config-rtls-rfid)#show rtls rfid ? LLRP...
SOLE Instance Use the instance to configure SOLE Location Engine related (config-rtls-sole) parameters. To navigate to this instance, use the commands RFSwitch(config)#rtls RFSwitch(config-rtls)#sole RFSwitch(config-rtls-sole)# 24.1 SOLE Config Commands Table 24.1 summarizes commands: config-rtls-sole Table 24.1 Location Engine Config Command Summary Command Description Ref.
Page 922
24-2 Motorola RF Switch CLI Reference Guide Table 24.1 Location Engine Config Command Summary (Continued) Command Description Ref. service Invokes service commands to troubleshoot or debug page 24-11 instance configurations (config-rtls) show Displays the running system information page 24-13 rssi-filter...
SOLE Instance 24-3 24.1.1 clrscr SOLE Instance Clears the display screen Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax clrscr Parameters None Example RFSwitch(config-rtls-sole)#clrscr RFSwitch(config-rtls-sole)#...
24-4 Motorola RF Switch CLI Reference Guide 24.1.2 end SOLE Instance Ends and exits the current mode and changes to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
24-5 24.1.3 exit SOLE Instance Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax exit Parameters None Example RFSwitch(config-rtls-sole)#exit RFSwitch(config-rtls-sole)#...
24-6 Motorola RF Switch CLI Reference Guide 24.1.4 help SOLE Instance Displays the interactive help system for RTLS instance Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-rtls-sole)#help CLI provides advanced help feature.
Page 929
SOLE Instance 24-9 24.1.6 no SOLE Instance Disables the locationing adapter(s) and its configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 no [aap-rssi-update-interval|locate|mobile-nit|redundancy| rssi-filter] Parameters aap-rssi-update-interval Disables AAP probe packet interval locate Negates Location commands...
24-10 Motorola RF Switch CLI Reference Guide 24.1.7 redundancy SOLE Instance Enables redundancy support across cluster members for SOLE Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax redundancy enable Parameters redundancy enable Enables the redundancy support across cluster members for...
24.1.8 service SOLE Instance Invokes service commands to troubleshoot or debug instance (config-rtls) configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters None Example RFSwitch(config-rtls-sole)#service show cli Location Engine Config mode:...
Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <parameters>...
Page 934
24-14 Motorola RF Switch CLI Reference Guide crypto encryption module debugging Debugging information outputs dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces...
Page 935
SOLE Instance 24-15 users Display information about currently logged in users version Display software & hardware version virtual-ip IP Redundancy Feature wireless Wireless configuration commands wlan-acl wlan based acl RFSwitch(config-rtls-sole)#show RFSwitch(config-rtls-sole)#show rtls sole ? peers Show SOLE peer information probes Show probe information RFSwitch(config-rtls-sole)# RFSwitch(config-rtls-sole)#show rtls sole peers...
SOLE Instance 24-17 24.1.11 aap-rssi-update-interval SOLE Instance Displays AAP probe packet interval value in seconds Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax aap-rssi-update-interval <5-3600> Parameters aap-rssi-update-interval Displays aap-rssi filter value in seconds <5-3600> Example...
Smart RF Instance Use the instance to configure Smart RF related (config-wireless-smart-rf) configuration commands. To navigate to the instance, config-wireless-smart-rf use the following commands: RFSwitch(config)#wireless RFSwitch(config-wireless)#smart-rf RFSwitch(config-wireless-smart-rf)# 25.1 smart-rf Config Commands The following table summarizes commands: config-wireless-smart-rf Command Description Ref. assignable- Specifies the power range during power-assignment page 25-3...
Page 940
25-2 Motorola RF Switch CLI Reference Guide Command Description Ref. help Displays the interactive help system page 25-9 hold-time The number of seconds to disable interference page 25-10 avoidance after a detection Negates commands or resets values to default page 25-11...
25-3 25.1.1 assignable-power-range Smart RF Instance Specifies the power range during power assignment Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax assignable-power-range [<lower bound> <upper bound>] Parameters assignable-power-range Specifies the power range during power assignment [<lower bound>...
25-6 Motorola RF Switch CLI Reference Guide 25.1.4 end Smart RF Instance Ends and exits the current mode and moves to the PRIV EXEC mode. The prompt changes RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
25.1.5 exit Smart RF Instance Ends the current mode and moves to the previous mode ( ). The prompt config-wireless changes to RFSwitch(config-wireless)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 exit Parameters None Example RFSwitch(config-wireless-smart-rf)#exit RFSwitch(config-wireless)#...
Smart RF Instance 25-9 25.1.7 help Smart RF Instance Displays the system’s interactive help in HTML format Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFS7000(config-wireless-smart-rf)#help CLI provides advanced help feature.
25-10 Motorola RF Switch CLI Reference Guide 25.1.8 hold-time Smart RF Instance Defines the number of seconds to disable interference avoidance after a detection This prevents a radio from changing channels continuously. Supported in the following platforms: • RFS7000 •...
Page 949
Smart RF Instance 25-11 25.1.9 no Smart RF Instance Disables the Smart RF configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax no [assignable-power-range|auto-assign|extensive-scan| hold-time|number-of-rescuers|radio|recover| retry-threshold|scan-dwell-time|schedule-calibrate| select-channels|service|smart-rf-module|verbose] no assignable-power-range [<4-20> <4-20>] no auto-assign [all|channel|detector|power|rescuer] no extensive-scan enable no number-of-rescuers no radio [<1-4096>|MAC-ADDRESS|RADIO|all-11a|all-11b|...
Page 950
25-12 Motorola RF Switch CLI Reference Guide auto-assign [all |channel Negates the auto-assign commands |detector|power|rescuer] • all - Disables all auto-assignment features enable • channel enable – Disables channel assignments • detector enable – Disables detector assignments • power enable – Disables power assignments •...
Page 951
Smart RF Instance 25-13 radio [<1-4096>| Negates all radio related commands MAC- Address|RADIO| • <1-4096> – For each of the radio, the following values all-11a|all-11b|all-11bg] are negated or reset: • antenna-gain <GAIN> – Resets the set antenna gain value • coverage-rate [1|2|5p5|6|9|11|12|18|24|36|48|54 ] – Resets the selected coverage rate value •...
Page 952
25-14 Motorola RF Switch CLI Reference Guide radio [<1-4096>|MAC • all-11a - for all 802.11a radios, the following values are Address|RADIO| negated or reset: all-11a|all-11b|all-11bg] • antenna-gain <GAIN> – Resets the set antenna gain value (contd..) • coverage-rate [1|2|5p5|6|9|11|12|18|24|36|48|54)]- Resets the selected coverage rate value •...
Page 953
Smart RF Instance 25-15 scan-dwell-time <1-10> Resets the time a scan dwells on a channel during scan schedule-calibrate Resets the calibration schedule parameters [enable|interval| • enable – Disables the calibration schedule feature start-time] • interval – Negates the calibration schedule interval •...
Page 954
25-16 Motorola RF Switch CLI Reference Guide retry-threshold The average number retries to cause a radio to re-run channel selection scan-dwell-time The number of seconds to dwell on a channel during scan schedule-calibrate configure calibration schedule parameters select-channels Revert selected-channels to default...
25-18 Motorola RF Switch CLI Reference Guide 25.1.10 number-of-rescuers Smart RF Instance Configures the number of rescuers to cover faulty radio conditions Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax number-of-rescuers <1-5> Parameters <1-5> The number of rescuers to use to cover faulty radio number-of-rescuers conditions.
25-19 25.1.11 radio Smart RF Instance Configures the different Smart RF radio parameters Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax radio [<1-4096>|MAC-ADDRESS|RADIO|all-11a|all-11b|all-11bg] antenna-gain|coverage-rate| radio <1-4096> [ lock-auto-assign | radio-mac | rescuer] radio <1-4096> anternna-gain <GAIN>...
Page 958
25-20 Motorola RF Switch CLI Reference Guide radio all-11b anternna-gain <GAIN> radio all-11b coverage-rate [1|2|5p5|6|9|11|12|18|24|36|48|54] radio all-11b lock-auto-assign [all|channel|detector|power|rescuer] radio all-11bg anternna-gain <GAIN> radio all-11bg coverage-rate [1|2|5p5|6|9|11|12|18|24|36|48|54] radio all-11bg lock-auto-assign [all|channel|detector|power|rescuer] Parameters <1-4096> [antenna-gain | Sets the following parameters for the selected radio: coverage-rate | •...
Page 959
Smart RF Instance 25-21 AA-BB-CC-DD-EE-FF Sets the following parameters for the selected radio [antenna-gain | • antenna-gain <GAIN> – Sets the antenna-gain value to coverage-rate | GAIN for the selected radio lock-auto-assign | • coverage-rate [1|2|5p5|6|9|11|12|18|24|36|48|54] – Sets rescuer] the coverage rate threshold value for under-coverage detection to the selected value from the list •...
Page 960
25-22 Motorola RF Switch CLI Reference Guide all-11a [antenna-gain| Sets the radio parameters for all 802.11a radios coverage-rate|lock-auto- • antenna-gain <GAIN> – Sets the antenna-gain value to assign] GAIN for the selected radio • coverage-rate [1|2|5p5|6|9|11|12|18|24|36|48|54] – Sets the coverage rate threshold value for under-coverage detection to the selected value from the list •...
Smart RF Instance Sets the threshold for the average number of retries performed before a radio re-runs a channel scan Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax retry-threshold <0.0-15.0> Parameters <0.0-15.0> The value in decimal number. This is the average number of retries a radio makes before it re-runs the channel scan.
25.1.15 scan-dwell-time Smart RF Instance Sets the time in seconds to dwell on a channel during a channel scan Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax scan-dwell-time <1-10> Parameters scan-dwell-time <1-10> The duration in seconds to dwell on a channel during a channel scan.
25-28 Motorola RF Switch CLI Reference Guide 25.1.16 schedule-calibrate Smart RF Instance Configures the calibrate schedule parameters This is used to configure parameters that schedule the automatic configuration of the Smart RF feature. Supported in the following platforms: • RFS7000 •...
Selects a list of channels for Automatic Channel Scan and Smart RF Use this command to add channels or remove them from the channel list. Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax select-channel [<WORD>|add<WORD>|remove <WORD>] Parameters <WORD>...
25-30 Motorola RF Switch CLI Reference Guide 25.1.18 service Smart RF Instance Invokes service commands to troubleshoot or debug (config-wireless-smart-rf) instance configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli service smart-rf [clear-history|load-from-file|max-history...
Page 969
Smart RF Instance 25-31 Parameters show cli Displays the CLI tree of the current mode smart-rf [clear-history | Smart RF related commands are executed from this service load-from-file| command. max-history|replay| • clear-history – Clears assignment history rescue|restore| • load-from-file – Loads Smart RF record from file save-to-file|simulate| smart.bin step-calibrate]...
Page 970
25-32 Motorola RF Switch CLI Reference Guide • assign-prepare – Prepares assignment • assign-rescuers – Assigns rescuers along with recovering power • collect-data – Collects site measurement data • prepare-detectors – Prepare prior to assign detectors • pull-rf-config – Pull RF-configuration from cluster members •...
25-34 Motorola RF Switch CLI Reference Guide 25.1.19 show Smart RF Instance Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: •...
Page 973
Smart RF Instance 25-35 show wireless smart-rf radio spectrum [MAC_ADDRESS| all-11a|all-11bg] Parameters Displays the parameters for which information can be viewed using the show command Example RFSwitch(config-wireless-smart-rf)#show ? access-list Internet Protocol (IP) aclstats Show ACL Statistics information alarm-log Display all alarms currently in the system autoinstall autoinstall configuration...
Page 974
25-36 Motorola RF Switch CLI Reference Guide radius RADIUS configuration commands redundancy Display redundancy group parameters role Configure role parameters rtls Real Time Locating System commands running-config Current Operating configuration securitymgr Securitymgr parameters sessions Display current active open connections snmp...
Page 975
Smart RF Instance 25-37 default-ap Information for default access-port hotspot-config Wlan hotspot configuration Intrusion detection parameters known Known AP related parameters mac-auth-local list out the mac-auth-local entries mesh Mesh related parameters mobile-unit Details of associated mobile- units multicast-packet-limit multicast-packet-limit phrase-to-key display the WEP keys generated by a passphrase qos-mapping...
Page 977
Smart RF Instance 25-39 RFSwitch(config-wireless-smart-rf)#show wireless smart-rf history Smart Master IP: 0.0.0.0 0.0.0.0 Cluster Master : Last Calibration Started at: Sun Sep 7 06:03:33 2008 Last Calibration Ended at: Sun Sep 7 06:03:33 2008 Next calibration Starts at: not scheduled Smart RF assignment history since last calibration, up to 9216 entries RFSwitch(config-wireless-smart-rf)#...
25.1.21 verbose Smart RF Instance Enables the verbose mode that records every Smart RF assignment Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 verbose enable Parameters verbose enable Enables the verbose mode where every Smart RF assignment is recorded.
Role Instance Use the instance to configure Role related configuration commands. To (config-role) navigate to the instance, use the following commands: config-role RFSwitch(config)#role <rolename> <rolepriority> RFSwitch(config-role)# For more information on the command, see role on page 5-80. role 26.1 Role Config Commands The following table summarizes commands: config-role...
Page 982
26-2 Motorola RF Switch CLI Reference Guide Command Description Ref. mu-mac Sets MU MAC configuration properties page 26-12 Negates role commands. page 26-14 service Invokes service commands to troubleshoot or debug page 26-18 instance configurations (config-dhcp) show Displays the running system information...
AP co-ordinates defined. The role based firewall has to know which zone the MU is located when it associates for the ap-parameter option to work. • The ‘ap-location’ parameter defines the zone or zones you wish to match. Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax...
Role Instance 26-5 26.1.2 authentication-type Role Config Commands Selects authentication type for the role Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax authentication-type [any|eq|neq] authentication-type any authentication-type eq [eap|hotspot|kerberos|mac-auth|none] authentication-type neq[eap|hotspot|kerberos|mac-auth|none] Parameters Any type of authentication...
26-6 Motorola RF Switch CLI Reference Guide 26.1.3 encryption-type Role Config Commands Selects encryption for the role Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax encryption-type [any|eq|neq] encryption-type any encryption-type eq [ccmp|keyguard|none|tkip|tkip-ccmp| wep128|wep128-keyguard|wep64] encryption-type neq [ccmp|keyguard|none|tkip|tkip-ccmp|...
Page 987
Role Instance 26-7 Encryption type must not be one of the listed options [ccmp|keyguard|none|tki p|tkip-ccmp| wep128|wep128- keyguard|wep64] Example RFSwitch(config-role)#encryption-type wep128 RFSwitch(config-role)#...
Role Instance 26-9 26.1.5 group Role Config Commands Sets group configuration for the role Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax group [any|contains|exact|not-contains] group any group contains <WORD> group exact <WORD> group not-contains <WORD>...
Page 990
26-10 Motorola RF Switch CLI Reference Guide 26.1.6 ip Role Config Commands Sets IP parameters for the role Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax ip access-group [<1-99>|<100-199>|<1300-1999>| <2000-2699>|<WORD>] [in|out] acl-precedence <1-100> Parameters access-group Sets the ACL precedence for the following ACL List entries [<1-99>|...
Role Instance 26-11 26.1.7 mac Role Config Commands Sets MAC access group configuration commands Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax mac access-group <WORD> [in|out] acl-precedence <1-100> Parameters access-group <word> Sets MAC access group configuration parameters [in|out] acl-precedence •...
26-12 Motorola RF Switch CLI Reference Guide 26.1.8 mu-mac Role Config Commands Configures the MU MAC addresses for role based firewall Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax mu-mac [<MAC Address>|<MAC Address>/<Mask>|any] Parameters <MAC Address>...
Role Instance 26-13 26.1.9 clrscr Role Config Commands Clears the display screen Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax clrscr Parameters None Example RFSwitch(config-role)#clrscr RFSwitch(config-role)#...
Page 994
26-14 Motorola RF Switch CLI Reference Guide 26.1.10 no Role Config Commands Negates role commands Supported in the following platforms: • RFS6000 • RFS7000 • RFS4000 Syntax no [ap-location|authentication-type|encryption-type|essid| group|ip|mac|mu-mac] no ap-location no authentication-type no encryption-type no essid no group no ip access-group [<1-99>|<100-199>|<1300-1999>|...
26-15 26.1.11 end Role Config Commands Exits the current mode and moves to the PRIV EXEC mode. The prompt changes to RFSwitch# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax Parameters None Example RFSwitch(config-role)#end RFSwitch#...
26-16 Motorola RF Switch CLI Reference Guide 26.1.12 exit Role Config Commands Ends the current mode and moves to the previous mode (GLOBAL-CONFIG). The prompt changes to RFSwitch#(config)# Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000...
Role Instance 26-17 26.1.13 help Role Config Commands Displays the system’s interactive help in HTML format Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax help Parameters None Example RFSwitch(config-role)#help CLI provides advanced help feature. When you need help, anytime at the command line please press '?'.
26-18 Motorola RF Switch CLI Reference Guide 26.1.14 service Role Config Commands Invokes service commands to troubleshoot or debug instance (config-role) configurations Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 Syntax service show cli Parameters None...
Displays current system information Supported in the following platforms: • RFS7000 • RFS6000 • RFS4000 SWITCH NOTE: The following commands display only for RFS6000 and RFS4000: • power The following commands display only for RFS7000 and RFS4000: • port-channel • static-channel-group Syntax show <paramater>...
Page 1000
26-20 Motorola RF Switch CLI Reference Guide dhcp DHCP Server Configuration environment show environmental information file Display filesystem information firewall Wireless firewall Display FTP Server configuration history Display the session command history interfaces Interface status Internet Protocol (IP) ldap LDAP server...