TP-Link T2600G-28TS Reference Manual

TP-Link T2600G-28TS Reference Manual

Jetstream gigabit l2 managed switch
Hide thumbs Also See for T2600G-28TS:
Table of Contents

Advertisement

T2600G-28TS (TL-SG3424)
T2600G-52TS (TL-SG3452)
JetStream Gigabit L2 Managed Switch
REV1.0.3
1910011681

Advertisement

Table of Contents
loading

Summary of Contents for TP-Link T2600G-28TS

  • Page 1 T2600G-28TS (TL-SG3424) T2600G-52TS (TL-SG3452) JetStream Gigabit L2 Managed Switch REV1.0.3 1910011681...
  • Page 2 Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks or registered trademarks of their respective holders. No part of the specifications may be reproduced in any form or by any means or used to make any derivative such as translation, transformation, or adaptation without permission from TP-LINK TECHNOLOGIES CO., LTD.
  • Page 3: Table Of Contents

    CONTENTS Preface ......................1 Chapter 1 Using the CLI ..................5 1.1 Accessing the CLI ....................... 5 1.1.1 Logon by a console port ..................5 1.1.2 Logon by Telnet ....................7 1.1.3 Logon by SSH ....................11 1.2 CLI Command Modes ....................... 16 1.3 Privilege Restrictions ......................
  • Page 4 3.11 show vlan ........................33 3.12 show interface switchport ..................34 Chapter 4 MAC-based VLAN Commands............35 mac-vlan mac-address ..................... 35 mac-vlan ........................36 show mac-vlan ......................36 show mac-vlan interface ................... 37 Chapter 5 Protocol-based VLAN Commands ........... 38 protocol-vlan template ....................
  • Page 5 l2protocol-tunnel type ....................54 show l2protocol-tunnel global ................... 56 show l2protocol-tunnel interface ................56 Chapter 9 GVRP Commands ................58 gvrp ........................... 58 gvrp (interface)......................58 gvrp registration ......................59 gvrp timer ........................60 show gvrp interface ....................61 show gvrp global ....................... 61 Chapter 10 Voice VLAN Commands ..............
  • Page 6 12.6 user access-control port-based ................80 12.7 line ..........................80 12.8 password ........................81 12.9 login .......................... 83 12.10 login local ........................83 12.11 media-type rj45 ......................84 12.12 telnet ......................... 85 12.13 serial_port baud-rate ....................85 12.14 show password-recovery ..................86 12.15 show user account-list ....................
  • Page 7 15.4 ip dhcp snooping information option ..............104 15.5 ip dhcp snooping information strategy ..............105 15.6 ip dhcp snooping information remote-id ..............106 15.7 ip dhcp snooping information circuit-id ..............107 15.8 ip dhcp snooping trust .................... 107 15.9 ip dhcp snooping mac-verify ...................
  • Page 8 19.2 ip arp inspection trust ..................... 128 19.3 ip arp inspection(interface) ..................129 19.4 ip arp inspection limit-rate ..................130 19.5 ip arp inspection recover ..................131 19.6 show ip arp inspection .................... 131 19.7 show ip arp inspection interface ................132 19.8 show ip arp inspection statistics ................
  • Page 9 23.1 logging buffer ......................153 23.2 logging buffer level ....................153 23.3 logging file flash ...................... 154 23.4 logging file flash frequency ..................155 23.5 logging file flash level ..................... 156 23.6 logging host index ....................156 23.7 logging console ....................... 157 23.8 logging console level ....................
  • Page 10 25.12 show mac address-table interface ................177 25.13 show mac address-table count ................178 25.14 show mac address-table address ................178 25.15 show mac address-table vlan ................. 179 25.16 show mac address-table notification ..............179 25.17 show mac address-table security ................180 Chapter 26 System Configuration Commands ..........
  • Page 11 26.31 show cpu-utilization ....................202 26.32 show memory-utilization ..................203 Chapter 27 IPv6 Address Configuration Commands ........204 27.1 ipv6 enable ......................204 27.2 ipv6 address autoconfig..................204 27.3 ipv6 address link-local .................... 205 27.4 ipv6 address dhcp ....................206 27.5 ipv6 address ra .......................
  • Page 12 29.7 show qos interface ....................228 29.8 show qos cos-map ....................228 29.9 show qos dscp-map ....................229 29.10 show qos queue mode ................... 229 29.11 show qos status ...................... 230 Chapter 30 Port Mirror Commands ..............231 30.1 monitor session destination interface ..............231 30.2 monitor session source interface ................
  • Page 13 33.14 access-list policy action ..................253 33.15 redirect interface ..................... 254 33.16 s-condition ......................254 33.17 s-mirror ........................255 33.18 qos-remark ......................256 33.19 access-list bind acl(interface) ................. 256 33.20 access-list bind acl(vlan) ..................257 33.21 access-list bind(interface) ..................258 33.22 access-list bind(vlan) ....................
  • Page 14 34.25 show spanning-tree interface ................. 277 34.26 show spanning-tree interface-security ..............278 34.27 show spanning-tree mst ..................279 Chapter 35 Ethernet OAM Commands .............. 280 35.1 ethernet-oam ......................280 35.2 ethernet-oam mode ....................280 35.3 ethernet-oam link-monitor symbol-period ............... 281 35.4 ethernet-oam link-monitor frame ................
  • Page 15 37.8 ip igmp snooping last-listener query-inteval ............301 37.9 ip igmp snooping last-listener query-count............. 301 37.10 ip igmp snooping vlan-config .................. 302 37.11 ip igmp snooping vlan-config (router-port-forbidden) ..........304 37.12 ip igmp snooping multi-vlan-config ................. 304 37.13 ip igmp snooping multi-vlan-config (router-port-forbidden) ........306 37.14 ip igmp snooping multi-vlan-config (source-ip-replace) .........
  • Page 16 38.12 ipv6 mld snooping multi-vlan-config ............... 327 38.13 ipv6 mld snooping multi-vlan-config (router-port-forbidden) ........328 38.14 ipv6 mld snooping multi-vlan-config (source-ip-replace) ........329 38.15 ipv6 mld snooping querier vlan ................330 38.16 ipv6 mld snooping querier vlan (general query) ............. 330 38.17 ipv6 mld snooping max-groups ................
  • Page 17 39.18 show snmp-server group ..................356 39.19 show snmp-server user ..................356 39.20 show snmp-server community ................357 39.21 show snmp-server host ..................357 39.22 show snmp-server engineID ................... 358 39.23 show rmon history ....................358 39.24 show rmon event ....................359 39.25 show rmon alarm ....................
  • Page 18 42.2 interface loopback ....................377 42.3 switchport ........................ 378 42.4 interface range port-channel .................. 378 42.5 description ......................379 42.6 shutdown ........................ 380 42.7 interface port-channel ..................... 380 42.8 ip route ........................381 42.9 ipv6 routing ......................382 42.10 ipv6 route ........................ 382 42.11 show interface vlan ....................
  • Page 19 44.15 line console ......................401 44.16 login authentication(console) .................. 402 44.17 enable authentication(console) ................403 44.18 line telnet ........................ 403 44.19 login authentication(telnet) ..................404 44.20 line ssh ........................405 44.21 login authentication(ssh) ..................405 44.22 enable authentication(telnet) .................. 406 44.23 enable authentication(ssh) ..................
  • Page 20 45.25 show ip dhcp server binding ................... 423 45.26 clear ip dhcp server statistics ................. 424 45.27 clear ip dhcp server binding ................... 424 Chapter 46 DHCP Relay Commands ..............426 46.1 service dhcp relay ....................426 46.2 ip helper-address ....................426 46.3 ip dhcp relay information ..................
  • Page 21: Preface

    (Command Line Interface). The device mentioned in this Guide stands for T2600G-28TS/ T2600G-52TS JetStream Gigabit L2 Managed Switch without any explanation. The commands in this guilde apply to these models if not specially noted, and T2600G-28TS is taken as an example model in the example commands.
  • Page 22 Chapter 12: User Management Commands Provide information about the commands used for user management. Chapter 13: HTTP and HTTPS Commands Provide information about the commands used for configuring the HTTP and HTTPS logon. Chapter 14: ARP Commands Provide information about the commands used for configuring the ARP (Address Resolution Protocol) functions.
  • Page 23 Chapter 26: System Configuration Commands Provide information about the commands used for configuring the System information and System IP, reboot and reset the switch, upgrade the switch system and commands used for cable test. Chapter 27: IPv6 Address Configuration Commands Provide information about the commands used for configuring the System IPv6 addresses.
  • Page 24 Chapter 39: SNMP Commands Provide information about the commands used for configuring the SNMP (Simple Network Management Protocol) functions. Chapter 40: LLDP Commands Provide information about the commands used for configuring LLDP function. Chapter 41: sFlow Commands Provide information about the commands used for configuring the Sampled Flow function. Chapter 42: Static Routes Commands Provide information about the commands used for configuring the Static Route function.
  • Page 25: Chapter 1 Using The Cli

    If you are using the switch’s Micro-USB console port with the USB port of a Windows PC, a driver for the USB port is required. The USB driver is provided on the resource CD. Follow the InstallSheild Wizard to accomplish the installation. The TP-LINK USB Console Driver supports the following Windows operating systems: 32-bit Windows XP SP3 ...
  • Page 26 64-bit Windows 8.1  After the TP-LINK USB Console Driver is installed, the PC’s USB port will act as RS-232 serial port when the PC’s USB port is connected to the switch’s Micro-USB console port. And the PC’s USB port will act as standard USB port when the PC’s USB port is unplugged from the switch.
  • Page 27: 1.1.2 Logon By Telnet

    5. The DOS prompt ”T2600G-28TS>” will appear after pressing the Enter button as shown in Figure 1-2. It indicates that you can use the CLI now. Figure 1-2 Log in the Switch 1.1.2 Logon by Telnet For Telnet connection, you should also configure the Telnet login mode and login authentication information through console connection.
  • Page 28 Login Local Mode  Firstly, configure the Telnet login mode as “login local” in the prompted DOS screen shown in Figure 1-3. Figure 1-3 Configure login local mode Now, you can logon by Telnet in login local mode. Make sure the switch and the PC are in the same LAN. Click Start and type in cmd in the Search programs and files window and press the Enter button.
  • Page 29 3. Type the default user name and password (both of them are admin), then press the Enter button so as to enter User EXEC Mode. Figure 1-6 Enter into the User EXEC Mode 4. Type enable command to enter Privileged EXEC Mode. Figure 1-7 Enter into the Priviledged EXEC Mode Now you can manage your switch with CLI commands through Telnet connection.
  • Page 30 Now, you can logon by Telnet in login mode: 1. Make sure the switch and the PC are in the same LAN. Click Start and type in cmd in the Search programs and files window and press the Enter button. Figure 1-9 Run Window 2.
  • Page 31: 1.1.3 Logon By Ssh

    4. Type enable command to enter Privileged EXEC Mode. Figure 1-12 Enter into the Privileged EXEC Mode Now you can manage your switch with CLI commands through Telnet connection. Note: You can refer to Chapter 11 User Management Commands for detailed commands information of the Telnet connection configuration.
  • Page 32 Password Authentication Mode  Open the software to log on to the interface of PuTTY. Enter the IP address of the switch into Host Name field; keep the default value 22 in the Port field; select SSH as the Connection type.
  • Page 33 Key Authentication Mode  Select the key type and key length, and generate SSH key. Figure 1-16 Generate SSH Key Note: The key length is in the range of 512 to 3072 bits. During the key generation, randomly moving the mouse quickly can accelerate the key generation.
  • Page 34 After the key is successfully generated, please save the public key and private key to a TFTP server. Figure 1-17 Save the Generated Key Log on to the switch by Telnet and download the public key file from the TFTP server to the switch, as the following figure shows: Figure 1-18 Download the Public Key...
  • Page 35 Note: The key type should accord with the type of the key file. The SSH key downloading can not be interrupted. After the public key is downloaded, please log on to the interface of PuTTY and enter the IP address for login. Figure 1-19 SSH Connection Config...
  • Page 36: 1.2 Cli Command Modes

    Click Browse to download the private key file to SSH client software and click Open. Figure 1-20 Download the Private Key After successful authentication, please enter the login user name. If you log on to the switch without entering password, it indicates that the key has been successfully downloaded. Figure 1-21 Log on the Switch 1.2 CLI Command Modes The CLI is divided into different command modes: User EXEC Mode, Privileged EXEC Mode,...
  • Page 37 VLAN Configuration mode. Layer 2 Interface: Use the interface gigabitEthernet port, Use the end command or press interface Ctrl+Z to return to Privileged T2600G-28TS (config-if)# EXEC mode. port-channel Interface Enter the exit or the # command port-channel-id or Configuration to return to Global Configuration interface range mode.
  • Page 38 Use the switchport command to Configuration mode. switch to the Layer 2 interface mode. Use the interface vlan vlan-id command T2600G-28TS (config-if)# Use the end command or press Interface to enter VLAN Ctrl+Z to return to Privileged Interface mode from Configuration EXEC mode.
  • Page 39: 1.3 Privilege Restrictions

    e). Interface vlan: Configure parameters for the vlan-port. VLAN Configuration Mode: In this mode, users can create a VLAN and add a specified  port to the VLAN. 3. Some commands are global, that means they can be performed in all modes: show: display all information of switch, for example: statistic information, port information, ...
  • Page 40: Special Characters

    1.4.2 Special Characters You should pay attentions to the description below if the variable is a character string: These six characters ” < > , \ & can not be input.  If a blank is contained in a character string, single or double quotation marks should be used, ...
  • Page 41: Chapter 2 User Interface

    User EXEC Mode Privilege Requirement None. Example If you have set the password to access Privileged EXEC Mode from User EXEC Mode: T2600G-28TS>enable Enter password: T2600G-28TS# service password-encryption Description The service password-encryption command is used to encrypt the password when the password is defined or when the configuration is written, using the symmetric encryption algorithm.
  • Page 42: Enable Password

    Privilege Requirement Only Admin level users have access to these commands. Example Enable the global encryption function: T2600G-28TS(config)# service password-encryption enable password Description The enable password command is used to set or change the password for users to access Privileged EXEC Mode from User EXEC Mode. To remove the password, please use no enable password command.
  • Page 43: Enable Secret

    Example Set the super password as “admin” and unencrypted to access Privileged EXEC Mode from User EXEC Mode: T2600G-28TS(config)#enable password 0 admin enable secret Description The enable secret command is used to set a secret password, which is using an MD5 encryption algorithm, for users to access Privileged EXEC Mode from User EXEC Mode.
  • Page 44: Configure

    Set the secret password as “admin” and unencrypted to access Privileged EXEC Mode from User EXEC Mode. The password will be displayed in the encrypted form. T2600G-28TS(config)#enable secret 0 admin configure Description The configure command is used to access Global Configuration Mode from Privileged EXEC Mode.
  • Page 45: End

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Return to Global Configuration Mode from Interface Configuration Mode, and then return to Privileged EXEC Mode: T2600G-28TS(config-if)# exit T2600G-28TS(config)#exit T2600G-28TS# Description The end command is used to return to Privileged EXEC Mode. Syntax...
  • Page 46: History Clear

    Privilege Requirement None. Example Show the commands you have entered in the current mode: T2600G-28TS (config)# history 1 history history clear Description The history clear command is used to clear the commands you have entered in the current mode, therefore these commands will not be shown next time you use the history command.
  • Page 47: Chapter 3 Ieee 802.1Q Vlan Commands

    Example Create VLAN 2-10 and VLAN 100: T2600G-28TS(config)# vlan 2-10,100 Delete VLAN 2: T2600G-28TS(config)# no vlan 2 interface vlan Description The interface vlan command is used to create VLAN Interface and enter Interface VLAN Mode. To delete VLAN Interface, please use no interface vlan...
  • Page 48: Name

    Only Admin, Operator and Power User level users have access to these commands. Example Create VLAN Interface 2: T2600G-28TS(config)# interface vlan 2 name Description The name command is used to assign a description to a VLAN. To clear the description, please use no name command.
  • Page 49: Switchport Mode

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the Link Type of Gigabit Ethernet port 1/0/3 as “trunk”: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#switchport mode trunk switchport access vlan Description The switchport access vlan command is used to add the desired Access port to IEEE 802.1Q VLAN, or to remove a port from the corresponding VLAN.
  • Page 50: Switchport Trunk Allowed Vlan

    Example Configure Gigabit Ethernet port 1/0/3 whose link type is “access” to VLAN 2: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#switchport access vlan 2 switchport trunk allowed vlan Description The switchport trunk allowed vlan command is used to add the desired Trunk port to IEEE 802.1Q VLAN.
  • Page 51: Switchport General Allowed Vlan

    Only Admin, Operator and Power User level users have access to these commands. Example Configure Gigabit Ethernet port 1/0/4 whose link type is “general” to VLAN 2 and its egress-rule as “tagged”: T2600G-28TS(config)#interface gigabitEthernet 1/0/4 T2600G-28TS(config-if)#switchport mode general T2600G-28TS(config-if)#switchport general allowed vlan 2 tagged...
  • Page 52: Switchport Pvid

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the PVID of port 1/0/2 as 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# switchport pvid 2 show vlan summary Description The show vlan summary command is used to display the summarized information of IEEE 802.1Q VLAN.
  • Page 53: Show Vlan Brief

    —— Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. It is multi-optional. Using the show vlan command without parameter displays the detailed information of all VLANs. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of vlan 5: T2600G-28TS(config)# show vlan id 5...
  • Page 54: Show Interface Switchport

    —— The port number. port-channel-id —— The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the VLAN configuration information of all ports and port channels: T2600G-28TS(config)# show interface switchport...
  • Page 55: Chapter 4 Mac-Based Vlan Commands

    Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create VLAN 2 with the MAC address 00:11:11:01:01:12 and the name “TP”: T2600G-28TS(config)#mac-vlan mac-address 00:11:11:01:01:12 vlan 2 description TP...
  • Page 56: Mac-Vlan

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the Gigabit Ethernet port 1/0/3 for the MAC-based VLAN feature: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#mac-vlan show mac-vlan Description The show mac-vlan command is used to display the information of the MAC-based VLAN entry.
  • Page 57: Show Mac-Vlan Interface

    —— Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. Example Display the information of all the MAC-based VLAN entry: T2600G-28TS(config)#show mac-vlan all show mac-vlan interface Description The show mac-vlan interface command is used to display the port state of MAC-based VLAN.
  • Page 58: Chapter 5 Protocol-Based Vlan Commands

    Chapter 5 Protocol-based VLAN Commands Protocol VLAN (Virtual Local Area Network) is the way to classify VLANs based on Protocols. A Protocol is relative to a single VLAN ID. The untagged packets and the priority-tagged packets matching the protocol template will be tagged with this VLAN ID. protocol-vlan template Description The protocol-vlan template command is used to create Protocol-based VLAN...
  • Page 59: Protocol-Vlan Vlan

    Example Create a Protocol-based VLAN template named “TP” whose Ethernet protocol type is 0x2024: T2600G-28TS(config)#protocol-vlan template name TP frame ether_2 ether-type 2024 protocol-vlan vlan Description The protocol-vlan vlan command is used to create a Protocol-based VLAN entry. To delete a Protocol-based VLAN entry, please use no protocol-vlan vlan command.
  • Page 60: Protocol-Vlan Group

    Only Admin, Operator and Power User level users have access to these commands. Example Add Gigabit Ethernet port 20 to protocol group 1: T2600G-28TS(config)#interface gigabitEthernet 1/0/20 T2600G-28TS(config-if)#protocol-vlan group 1 show protocol-vlan template Description The show protocol-vlan template command is used to display the information of the Protocol-based VLAN templates.
  • Page 61: Show Protocol-Vlan Vlan

    Privilege Requirement None. Example Display the information of the Protocol-based VLAN templates: T2600G-28TS(config)#show protocol-vlan template show protocol-vlan vlan Description The show protocol-vlan vlan command is used to display the information about Protocol-based VLAN entry. Syntax show protocol-vlan vlan Command Mode...
  • Page 62: Chapter 6 Vlan-Vpn Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the VLAN-VPN function globally: T2600G-28TS(config)#dot1q-tunnel dot1q-tunnel tpid Description The dot1q-tunnel tpid command is used to configure Global TPID of the VLAN-VPN. To restore to the default value, please use the no dot1q-tunnel tpid command.
  • Page 63: Dot1Q-Tunnel Mapping

    Only Admin, Operator and Power User level users have access to these commands. Example Configure Global TPID of the VLAN-VPN as 0x9100: T2600G-28TS(config)#dot1q-tunnel tpid 9100 dot1q-tunnel mapping Description The dot1q-tunnel mapping command is used to enable the VLAN Mapping feature globally. To disable this function, please use the no dot1q-tunnel mapping command.
  • Page 64: Switchport Dot1Q-Tunnel Mapping

    Add a VLAN Mapping entry on the Gigabit Ethernet port 1/0/3 with the Customer VLAN as VLAN 2 and the Service Provider VLAN as VLAN 3: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#switchport dot1q-tunnel mapping 2 3 switchport dot1q-tunnel mode Description The switchport dot1q-tunnel mode command is used to configure the VPN port’s mode.
  • Page 65: Show Dot1Q-Tunnel

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the Gigabit Ethernet port 1/0/3 as the VPN UNI ports: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#switchport dot1q-tunnel mode uni show dot1q-tunnel Description The show dot1q-tunnel command is used to display the global configuration information of the VLAN VPN.
  • Page 66: Show Dot1Q-Tunnel Mapping

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of VLAN Mapping entry: T2600G-28TS(config)#show dot1q-tunnel mapping show dot1q-tunnel interface Description The show dot1q-tunnel mapping interface command is used to display the VLAN VPN port type.
  • Page 67: Chapter 7 Private Vlan Commands

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the VLAN 3 as the primary VLAN of the private VLAN: T2600G-28TS(config)#vlan 3 T2600G-28TS(config-vlan)#private-vlan primary private-vlan community Description The private-vlan community command is used to configure the designated VLAN as the community VLAN of the Private VLAN.
  • Page 68: Private-Vlan Isolated

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the VLAN 4 as the community VLAN of the private VLAN: T2600G-28TS(config)#vlan 4 T2600G-28TS(config-vlan)#private-vlan community private-vlan isolated Description The private-vlan isolated command is used to configure the designated VLAN as the isolated VLAN of the Private VLAN.
  • Page 69: Private-Vlan Association

    Only Admin and Operator level users have access to these commands. Example Associate primary VLAN 3 with community VLAN 4 as a private VLAN: T2600G-28TS(config)#vlan 3 T2600G-28TS(config-vlan)#private-vlan association 4 switchport private-vlan Description The switchport private-vlan command is used to configure the private VLAN mode for the switchport.
  • Page 70: Switchport Private-Vlan Host-Association

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure Gigabit Ethernet port 3 as “host”: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#switchport private-vlan host switchport private-vlan host-association Description The switchport private-vlan host-association command is used to add host type port to private VLAN.
  • Page 71: Switchport Private-Vlan Mapping

    Example Configure host type Gigabit Ethernet port 1/0/3 as a member of primary VLAN 3 and secondary VLAN 4, with the type of VLAN 4 as community: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#switchport private-vlan host-association 3 4 community switchport private-vlan mapping Description The switchport private-vlan mapping command is used to add promiscuous type port to private VLAN.
  • Page 72: Show Vlan Private-Vlan

    Only Admin and Operator level users have access to these commands. Example Display the configuration information of all Private VLAN: T2600G-28TS(config)#show vlan private-vlan show vlan private-vlan interface Description The show vlan private-vlan interface command is used to display the Private VLAN configuration information of the specified port(s).
  • Page 73 Example Display the configuration information of all the Ethernet ports: T2600G-28TS(config)#show vlan private-vlan interface...
  • Page 74: Chapter 8 L2Pt Commands

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the L2PT function globally: T2600G-28TS(config)# l2protocol-tunnel l2protocol-tunnel type Description The l2protocol-tunnel type command is used to configure the L2PT function on a specified port. To disable the L2PT function on the specified port, please...
  • Page 75 / interface port-channel / interface range port-channel) Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure port 1/0/3 as a UNI port for STP packets with the threshold as 1000 packets/second: T2600G-28TS(config)#interface gigabitEthernet 1/0/3...
  • Page 76: Show L2Protocol-Tunnel Global

    T2600G-28TS(config-if)# l2protocol-tunnel type uni stp threshold 1000 show l2protocol-tunnel global Description The show l2protocol-tunnel global command is used to display the global L2PT status. Syntax show l2protocol-tunnel global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None.
  • Page 77 Example Display the L2PT configuration information of Gigabit Ethernet port 1/0/1: T2600G-28TS(config)#show l2protocol-tunnel interface gigabitEthernet 1/0/1 Display the L2PT configuration information of all Ethernet ports: T2600G-28TS(config)#show l2protocol-tunnel interface...
  • Page 78: Chapter 9 Gvrp Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the GVRP function globally: T2600G-28TS(config)#gvrp gvrp (interface) Description The gvrp command is used to enable the GVRP function for the desired port. To disable it, please use no gvrp command. The GVRP feature can only be enabled for the trunk-type ports.
  • Page 79: Gvrp Registration

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the GVRP function for Gigabit Ethernet ports 1/0/2-6: T2600G-28TS(config)#interface range gigabitEthernet 1/0/2-6 T2600G-28TS(config-if-range)#gvrp gvrp registration Description The gvrp registration command is used to configure the GVRP registration type for the desired port.
  • Page 80: Gvrp Timer

    T2600G-28TS(config-if-range)#gvrp registration fixed gvrp timer Description The gvrp timer command is used to set a GVRP timer for the desired port. To restore to the default setting of a GARP timer, please use no gvrp timer command. Syntax gvrp timer { leaveall | join | leave } value...
  • Page 81: Show Gvrp Interface

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the GVRP configuration information of Gigabit Ethernet port 1: T2600G-28TS(config)#show gvrp interface gigabitEthernet 1/0/1 Display the GVRP configuration information of all Ethernet ports: T2600G-28TS(config)#show gvrp interface show gvrp global Description...
  • Page 82 Syntax show gvrp global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global GVRP status: T2600G-28TS(config)#show gvrp global...
  • Page 83: Chapter 10 Voice Vlan Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the Voice VLAN function for VLAN 10: T2600G-28TS(config)# voice vlan 10 voice vlan aging 10.2 Description The voice vlan aging command is used to set the aging time for a voice VLAN.
  • Page 84: Voice Vlan Priority

    Only Admin, Operator and Power User level users have access to these commands. Example Set the aging time for the Voice VLAN as 1 minute: T2600G-28TS(config)# voice vlan aging 1 voice vlan priority 10.3 Description The voice vlan priority command is used to configure the priority for the Voice VLAN.
  • Page 85: Voice Vlan Mac-Address

    Example Configure the priority of the Voice VLAN as 5: T2600G-28TS(config)# voice vlan priority 5 voice vlan mac-address 10.4 Description The voice vlan mac-address command is used to create Voice VLAN OUI. To delete the specified Voice VLAN OUI, please use no voice vlan mac-address command.
  • Page 86: Switchport Voice Vlan Security

    Example Configure the port 1/0/3 to operate in the auto voice VLAN mode: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# switchport voice vlan mode auto switchport voice vlan security 10.6 Description The switchport voice vlan security command is used to enable the Voice VLAN security feature.
  • Page 87: Show Voice Vlan

    Example Enable port 1/0/3 for the Voice VLAN security feature: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# switchport voice vlan security show voice vlan 10.7 Description The show voice vlan command is used to display the global configuration information of Voice VLAN.
  • Page 88: Show Voice Vlan Switchport

    Only Admin, Operator and Power User level users have access to these commands. Example Display the Voice VLAN configuration information of all ports and port channels: T2600G-28TS(config)# show voice vlan switchport Display the Voice VLAN configuration information of port 1/0/2: T2600G-28TS(config)# show voice vlan switchport gigabitEthernet 1/0/2...
  • Page 89: Chapter 11 Etherchannel Commands

    Chapter 11 Etherchannel Commands Etherchannel Commands are used to configure LAG and LACP function. LAG (Link Aggregation Group) is to combine a number of ports together to make a single high-bandwidth data path, which can highly extend the bandwidth. The bandwidth of the LAG is the sum of bandwidth of its member port.
  • Page 90: Port-Channel Load-Balance

    T2600G-28TS(config)# interface range gigabitEthernet 1/0/2-4 T2600G-28TS(config-if-range)# channel-group 1 mode on port-channel load-balance 11.2 Description The port-channel load-balance command is used to configure the Aggregate Arithmetic for LAG. To return to the default configurations, please use no port-channel load-balance command. Syntax...
  • Page 91: Lacp System-Priority

    Example Configure the Aggregate Arithmetic for LAG as “src-dst-ip”: T2600G-28TS(config)# port-channel load-balance src-dst-ip lacp system-priority 11.3 Description The lacp system-priority command is used to configure the LACP system priority globally. To return to the default configurations, please use no lacp system-priority command.
  • Page 92: Show Etherchannel

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the LACP port priority as 1024 for ports 1-3: T2600G-28TS(config)# interface range gigabitEthernet 1/0/1-3 T2600G-28TS(config-if-range)# lacp port-priority 1024 Configure the LACP port priority as 2048 for port 4: T2600G-28TS(config)# interface gigabitEthernet 1/0/4...
  • Page 93: Show Etherchannel Load-Balance

    Privilege Requirement None. Example Display the detailed information of EtherChannel Group 1: T2600G-28TS(config)# show etherchannel 1 detail show etherchannel load-balance 11.6 Description The show etherchannel load-balance command is used to display the Aggregate Arithmetic of LAG. Syntax show etherchannel load-balance...
  • Page 94: Show Lacp Sys-Id

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the internal LACP information of EtherChannel Group 1: T2600G-28TS(config)# show lacp 1 internal show lacp sys-id 11.8 Description The show lacp sys-id command is used to display the LACP system priority globally.
  • Page 95: Chapter 12 User Management Commands

    Chapter 12 User Management Commands User Manage Commands are used to manage the user’s logging information by Web, Telnet or SSH, so as to protect the settings of the switch from being randomly changed. user name (password) 12.1 Description The user name command is used to add a new user or modify the existed users’...
  • Page 96: User Name (Secret)

    Example Add and enable a new admin user named “tplink”, of which the password is “admin” and unencrypted: T2600G-28TS(config)#user name tplink privilege admin password 0 admin user name (secret) 12.2 Description The user name command is used to add a new user or modify the existed users’...
  • Page 97: Service Password-Recovery

    Example Add and enable a new admin user named “tplink”, of which the password is “admin”. The password will be displayed in the encrypted form. T2600G-28TS(config)#user name tplink privilege admin secret 0 admin service password-recovery 12.3 Description...
  • Page 98: User Access-Control Ip-Based

    Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the switch’s password recovery feature: T2600G-28TS(config)# service password-recovery user access-control ip-based 12.4 Description The user access-control ip-based command is used to limit the IP-range of the users for login.
  • Page 99: User Access-Control Mac-Based

    These interfaces are enabled by default. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure that only the user whose MAC address is 00:00:13:0A:00:01 is allowed to login: T2600G-28TS(config)# user access-control mac-based 00:00:13:0A:00:01...
  • Page 100: User Access-Control Port-Based

    Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure that only the users connected to ports 2-6 are allowed to login: T2600G-28TS(config)# user access-control port-based interface gigabitEthernet 1/0/2-6 line 12.7...
  • Page 101: Password

    Enter the Console port configuration mode and configure the console port 0: T2600G-28TS(config)#line console 0 Enter the Virtual Terminal configuration mode so as to prepare further configurations such as password and login mode for virtual terminal 0 to 5: T2600G-28TS(config)#line vty 0 5 password 12.8 Description The password command is used to configure the connection password.
  • Page 102 Example Configure the connection password of Console port connection 0 as “tplink” and unencrypted: T2600G-28TS(config)#line console 0 T2600G-28TS(config-line)#password 0 tplink Configure the connection password of virtual terminal connection 0-5 as “tplink” and unencrypted: T2600G-28TS(config)#line vty 0 5 T2600G-28TS(config-line)#password 0 tplink...
  • Page 103: Login

    Example Configure the login of Console port connection 0 as login mode: T2600G-28TS(config)#line console 0 T2600G-28TS(config-line)#login Configure the login of virtual terminal connection 0-5 as login mode: T2600G-28TS(config)#line vty 0 5 T2600G-28TS(config-line)#login login local 12.10 Description The login local command is used to configure the login mode of the switch which uses the user name and password to login.
  • Page 104: Media-Type Rj45

    Example Configure the login of virtual terminal connection 0-5 as login local mode: T2600G-28TS(config)#line vty 0 5 T2600G-28TS(config-line)#login local Configure the login of Console port connection 0 as login local mode: T2600G-28TS(config)#line console 0 T2600G-28TS(config-line)#login local media-type rj45 12.11 Description The media-type rj45 command is used to configure the console media type as RJ-45 for input.
  • Page 105: Telnet

    Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable the Telnet function: T2600G-28TS(config)# telnet disable serial_port baud-rate 12.13 Description The serial_port baud-rate command is used to configure the communication baud rate on the console port. To return to the default baud rate, please use no serial_port command.
  • Page 106: Show Password-Recovery

    Example Specify the communication baud rate on the console port to the default value: T2600G-28TS(config)# no serial_port show password-recovery 12.14 Description The show password-recovery command is used to display the status of the password-recovery feature. Syntax show password-recovery Command Mode...
  • Page 107: Show User Configuration

    Example Display the information of the current users: T2600G-28TS(config)# show user account-list show user configuration 12.16 Description The show user configuration command is used to display the security configuration information of the users, including access-control, max-number and the idle-timeout, etc.
  • Page 108 Example Display whether the Telnet function is enabled: T2600G-28TS(config)# show telnet-status...
  • Page 109: Chapter 13 Http And Https Commands

    Syntax ip http server no ip http server Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable the HTTP function: T2600G-28TS(config)# no ip http server...
  • Page 110: Ip Http Max-Users

    Only Admin and Operator level users have access to these commands. Example Configure the maximum number of the Admin and Guest users logging on to the HTTP server as 5 and 3: T2600G-28TS(config)# ip http max-users 5 3 ip http session timeout 13.3 Description The ip http session timeout command is used to configure the connection timeout of the HTTP server.
  • Page 111: Ip Http Secure-Server

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the timeout time of the HTTP connection as 15 minutes: T2600G-28TS(config)# ip http session timeout 15 ip http secure-server 13.4 Description The ip http secure-server command is used to enable the HTTPS server within the switch.
  • Page 112: Ip Http Secure-Protocol

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the protocol of SSL connection as SSL 3.0: T2600G-28TS(config)# ip http secure-protocol ssl3 ip http secure-ciphersuite 13.6 Description The ip http secure-ciphersuite command is used to configure the cipherSuites over the SSL connection supported by the switch.
  • Page 113: Ip Http Secure-Max-Users

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the ciphersuite to be used for encryption over the SSL connection as 3des-ede-cbc-sha: T2600G-28TS(config)# ip http secure-ciphersuite 3des-ede-cbc-sha ip http secure-max-users 13.7 Description The ip http secure-max-users command is used to configure the maximum number of users that are allowed to connect to the HTTPs server.
  • Page 114: Ip Http Secure-Session Timeout

    Example Configure the maximum number of the Admin and Guest users logging on to the HTTPs server as 5 and 3: T2600G-28TS(config)# ip http secure-max-users 5 3 ip http secure-session timeout 13.8 Description The ip http secure-session timeout command is used to configure the connection timeout of the HTTPS server.
  • Page 115: Ip Http Secure-Server Download Key

    Example Download an SSL Certificate named ssl-cert from TFTP server with the IP address of 192.168.0.146: T2600G-28TS(config)# ip http secure-server download certificate ssl-cert ip-address 192.168.0.146 Download an SSL Certificate named ssl-cert from TFTP server with the IP address of fe80::1234...
  • Page 116: Show Ip Http Configuration

    Example Download an SSL key named ssl-key from TFTP server with the IP address of 192.168.0.146: T2600G-28TS(config)# ip http secure-server download key ssl-key ip-address 192.168.0.146 Download an SSL key named ssl-key from TFTP server with the IP address of fe80::1234...
  • Page 117: Show Ip Http Secure-Server

    Privilege Requirement None. Example Display the configuration information of the HTTP server: T2600G-28TS(config)# show ip http configuration show ip http secure-server 13.12 Description The show ip http secure-server command is used to display the global configuration of SSL. Syntax show ip http secure-server...
  • Page 118: Chapter 14 Arp Commands

    Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create a static ARP entry with the IP as 192.168.0.1 and the MAC as 00:11:22:33:44:55: T2600G-28TS(config)# arp 192.168.0.1 00:11:22:33:44:55 arpa...
  • Page 119: Clear Arp-Cache

    Only Admin, Operator and Power User level users have access to these commands. Example Clear all the dynamic ARP entries: T2600G-28TS(config)# clear arp-cache arp timeout 14.3 Description This arp timeout command is used to configure the ARP aging time of the interface.
  • Page 120: Show Arp

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the ARP entry with the IP as 192.168.0.2: T2600G-28TS(config)# show ip arp 192.168.0.2 show ip arp (interface) 14.5 Description This show arp command is used to display the active ARP entries associated with a specified Layer 3 interface.
  • Page 121: Show Ip Arp Summary

    Privilege Requirement None. Example Display the ARP entry associated with VLAN interface 2 : T2600G-28TS(config)# show ip arp vlan 2 show ip arp summary 14.6 Description This show ip arp summary command is used to display the number of the active ARP entries.
  • Page 122: Chapter 15 Binding Table Commands

    Chapter 15 Binding Table Commands You can bind the IP address, MAC address, VLAN and the connected Port number of the Host together, which can be the condition for the ARP Inspection and IP verify source to filter the packets. ip source binding 15.1 Description...
  • Page 123: Ip Dhcp Snooping

    192.168.0.1 00:00:00:00:00:01 vlan 2 interface gigabitEthernet 1/0/5 arp-detection Delete the IP-MAC–VID-PORT entry with the index 5: T2600G-28TS(config)#no ip source binding index 5 ip dhcp snooping 15.2 Description The ip dhcp snooping command is used to enable DHCP Snooping function globally.
  • Page 124: Ip Dhcp Snooping Vlan

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCP Snooping function on VLAN 1,4,6-7: T2600G-28TS(config)#ip dhcp snooping vlan 1,4,6-7 ip dhcp snooping information option 15.4 Description The ip dhcp snooping information option command is used to enable the Option 82 function of DHCP Snooping.
  • Page 125: Ip Dhcp Snooping Information Strategy

    Example Enable the Option 82 function of DHCP Snooping on port 1/0/1: T2600G-28TS(config)#interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#ip dhcp snooping information option ip dhcp snooping information strategy 15.5 Description The ip dhcp snooping information strategy command is used to select the operation for the Option 82 field of the DHCP request packets from the Host.
  • Page 126: Ip Dhcp Snooping Information Remote-Id

    Example Replace the Option 82 field of the packets with the switch defined one and then send out on port 1/0/1: T2600G-28TS(config)#interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#ip dhcp snooping information strategy replace ip dhcp snooping information remote-id 15.6 Description The ip dhcp snooping information remote-id command is used to configure the customized sub-option Remote ID for the Option 82.
  • Page 127: Ip Dhcp Snooping Information Circuit-Id

    Example Enable and configure the customized sub-option Circuit ID for the Option 82 as “tplink” on port 1/0/1: T2600G-28TS(config)#interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#ip dhcp snooping information circuit-id tplink ip dhcp snooping trust 15.8 Description The ip dhcp snooping trust command is used to configure a port to be a Trusted Port.
  • Page 128: Ip Dhcp Snooping Mac-Verify

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the Gigabit Ethernet port 1/0/2 to be a Trusted Port: T2600G-28TS(config)#interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ip dhcp snooping trust ip dhcp snooping mac-verify 15.9 Description The ip dhcp snooping mac-verify command is used to enable the MAC Verify feature.
  • Page 129: Ip Dhcp Snooping Limit Rate

    Example Set the Flow Control of GigabitEthernet port 2 as 20 pps: T2600G-28TS(config)#interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ip dhcp snooping limit rate 20 ip dhcp snooping decline rate 15.11 Description The ip dhcp snooping decline rate command is used to enable the Decline Protect feature and configure the rate limit on DHCP Decine packets.
  • Page 130: Show Ip Source Binding

    Example Configure the rate limit of DHCP Decline packets as 20 packets per second on Gigabit Ethernet port 1/0/2: T2600G-28TS(config)#interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ip dhcp snooping decline 20 show ip source binding 15.12 Description The show ip source binding command is used to display the IP-MAC-VID- PORT binding table.
  • Page 131: Show Ip Dhcp Snooping

    T2600G-28TS(config)#show ip source binding show ip dhcp snooping 15.13 Description The show ip dhcp snooping command is used to display the running status of DHCP Snooping. Syntax show ip dhcp snooping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None.
  • Page 132: Show Ip Dhcp Snooping Information Interface

    Display the DHCP Snooping configuration of all Ethernet ports and port channels: T2600G-28TS#show ip dhcp snooping interface Display the DHCP Snooping configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ip dhcp snooping interface gigabitEthernet 1/0/5 show ip dhcp snooping information interface 15.15 Description...
  • Page 133 Display the DHCP snooping option 82 configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show dhcp snooping information interface gigabitEthernet 1/0/5...
  • Page 134: Chapter 16 Ipv6 Binding Table Commands

    Chapter 16 IPv6 Binding Table Commands You can bind the IPv6 address, MAC address, VLAN and the connected Port number of the Host together, which can be the condition for the ND Detection and IPv6 Source Guard to filter the packets.
  • Page 135: Ipv6 Dhcp Snooping

    2001::1 00:00:00:00:00:01 vlan 2 interface gigabitEthernet 1/0/5 nd-detection Delete the IPv6-MAC–VID-PORT entry with the index 5: T2600G-28TS(config)#no ipv6 source binding index 5 ipv6 dhcp snooping 16.2 Description The ipv6 dhcp snooping command is used to enable DHCPv6 Snooping function globally.
  • Page 136: Ipv6 Dhcp Snooping Vlan

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCPv6 Snooping function on VLAN 1,4,6-7: T2600G-28TS(config)#ipv6 dhcp snooping vlan 1,4,6-7 ipv6 dhcp snooping trust 16.4 Description The ipv6 dhcp snooping trust command is used to configure a port to be a Trusted Port.
  • Page 137: Ipv6 Nd Snooping

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the Gigabit Ethernet port 1/0/2 to be a Trusted Port: T2600G-28TS(config)#interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ipv6 dhcp snooping trust ipv6 nd snooping 16.5 Description The ipv6 nd snooping command is used to enable ND Snooping function globally.
  • Page 138: Ipv6 Nd Snooping Vlan

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the ND Snooping function on VLAN 1,4,6-7: T2600G-28TS(config)#ipv6 nd snooping vlan 1,4,6-7 ipv6 nd snooping max-entries 16.7 Description The ipv6 nd snooping max-entries command is used to specify the maximum number of binding entries that are allow to be binded to a port.
  • Page 139: Show Ipv6 Source Binding

    Example Configure the maximum number of binding entries from ND Snooping of Gigabit Ethernet port 1/0/2 is 100: T2600G-28TS(config)#interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ipv6 nd snooping max-entries 100 show ipv6 source binding 16.8 Description The show ipv6 source binding command is used to display the IPv6-MAC-VID- PORT binding table.
  • Page 140: Show Ipv6 Dhcp Snooping Interface

    —— The Ethernet port number port-channel-id —— The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DHCPv6 Snooping configuration of all Ethernet ports and port channels: T2600G-28TS#show ipv6 dhcp snooping interface...
  • Page 141: Show Ipv6 Nd Snooping

    Display the DHCPv6 Snooping configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ipv6 dhcp snooping interface gigabitEthernet 1/0/5 show ipv6 nd snooping 16.11 Description The show ipv6 nd snooping command is used to display the running status of ND Snooping. Syntax...
  • Page 142 Privilege Requirement None. Example Display the ND Snooping configuration of all Ethernet ports and port channels: T2600G-28TS#show ipv6 nd snooping interface Display the ND Snooping configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ipv6 nd snooping interface gigabitEthernet 1/0/5...
  • Page 143: Chapter 17 Ip Verify Source Commands

    Enable the IP Verify Source function for Gigabit Ethernet ports 5-10. Configure that only the packets with its source IP address, source MAC address and port number matched to the IP-MAC binding rules can be processed: T2600G-28TS(config)#interface range gigabitEthernet 1/0/5-10 T2600G-28TS(config-if-range)#ip verify source sip+mac...
  • Page 144: Show Ip Verify Source

    Parameters port —— The Ethernet port number Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the IP verify source configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ip verify source interface gigabitEthernet 1/0/5...
  • Page 145: Chapter 18 Ipv6 Verify Source Commands

    Enable the IPv6 Verify Source function for Gigabit Ethernet ports 5-10. Configure that only the packets with its source IPv6 address, source MAC address and port number matched to the IPv6-MAC binding rules can be processed: T2600G-28TS(config)#interface range gigabitEthernet 1/0/5-10...
  • Page 146: Show Ipv6 Verify Source

    T2600G-28TS(config-if-range)#ipv6 verify source sipv6+mac show ipv6 verify source 18.2 Description The show ipv6 verify source command is used to display the IPv6 Verify Source configuration information. Syntax show ipv6 verify source Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None.
  • Page 147 Example Display the IPv6 verify source configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ipv6 verify source interface gigabitEthernet 1/0/5...
  • Page 148: Chapter 19 Arp Inspection Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the ARP Detection function globally: T2600G-28TS(config)#ip arp inspection ip arp inspection trust 19.2 Description The ip arp inspection trust command is used to configure the port for which the ARP Detect function is unnecessary as the Trusted Port.
  • Page 149: Ip Arp Inspection(Interface)

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the Gigabit Ethernet ports 1/0/2-5 as the Trusted Port: T2600G-28TS(config)#interface range gigabitEthernet 1/0/2-5 T2600G-28TS(config-if-range)#ip arp inspection trust ip arp inspection(interface) 19.3 Description The ip arp inspection command is used to enable the ARP Defend function. To disable the ARP detection function, please use no ip arp inspection command.
  • Page 150: Ip Arp Inspection Limit-Rate

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the maximum amount of the received ARP packets per second as 50 pps for Gigabit Ethernet port 5: T2600G-28TS(config)#interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)#ip arp inspection limit-rate 50...
  • Page 151: Ip Arp Inspection Recover

    Only Admin, Operator and Power User level users have access to these commands. Example Restore Gigabit Ethernet port 1/0/5 to the ARP transmit status: T2600G-28TS(config)#interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)#ip arp inspection recover show ip arp inspection 19.6 Description The show ip arp inspection command is used to display the ARP detection global configuration including the enable/disable status and the Trusted Port list.
  • Page 152: Show Ip Arp Inspection Interface

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of Gigabit Ethernet port 1/0/1: T2600G-28TS(config)#show ip arp inspection interface gigabitEthernet 1/0/1 Display the configuration of all Ethernet ports: T2600G-28TS(config)#show ip arp inspection interface show ip arp inspection statistics 19.8...
  • Page 153: Clear Ip Arp Inspection Statistics

    Example Display the number of the illegal ARP packets received: T2600G-28TS(config)#show ip arp inspection statistics clear ip arp inspection statistics 19.9 Description The clear ip arp inspection statistics command is used to clear the statistic of the illegal ARP packets received.
  • Page 154: Chapter 20 Dos Defend Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the DoS defend function globally: T2600G-28TS(config)#ip dos-prevent ip dos-prevent type 20.2 Description The ip dos-prevent type command is used to select the DoS Defend Type. To disable the corresponding Defend Type, please use no ip dos-prevent type command.
  • Page 155: Show Ip Dos-Prevent

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the DoS Defend Type named Land attack: T2600G-28TS(config)#ip dos-prevent type land show ip dos-prevent 20.3 Description The show ip dos-prevent command is used to display the DoS information of the detected DoS attack, including enable/disable status, the DoS Defend Type, the count of the attack, etc.
  • Page 156 Syntax show ip dos-prevent Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DoS information of the detected DoS attack globally: T2600G-28TS(config)#show ip dos-prevent...
  • Page 157: Chapter 21 Ieee 802.1X Commands

    Authenticator: controls the physical access to the network based on the authentication status  of the supplicant. It is usually an 802.1X-supported network device, such as this TP-LINK switch. It acts as an intermediary (proxy) between the supplicant and the authentication server, requesting identity information from the supplicant, verifying that information with the authentication server, and relaying a response to the supplicant.
  • Page 158: Dot1X Handshake

    Description The dot1x handshake command is used enable the handshake feature. The handshake feature is used to detect the connection status between the TP-LINK 802.1x supplicant and the switch. Please disable the handshake feature if you are using a non-TP-LINK 802.1x-compliant client software. This feature is enabled by default.
  • Page 159: Dot1X Accounting

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the Authentication Method of IEEE 802.1X as “pap”: T2600G-28TS(config)#dot1x auth-method pap dot1x accounting 21.4 Description The dot1x accounting command is used to enable the IEEE 802.1X accounting function globally.
  • Page 160: Dot1X Guest-Vlan(Global)

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the Guest VLAN function for VLAN 5: T2600G-28TS(config)#dot1x guest-vlan 5 dot1x quiet-period 21.6 Description The dot1x quiet-period command is used to enable the quiet-period function.
  • Page 161: Dot1X Timeout

    Example Enable the quiet-period function: T2600G-28TS(config)#dot1x quiet-period Enable the quiet-period function and set the quiet-period as 5 seconds: T2600G-28TS(config)#dot1x quiet-period 5 dot1x timeout 21.7 Description The dot1x timeout command is used to configure the server timeout and the supplicant timeout. To restore to the default, please use no dot1x timeout command.
  • Page 162: Dot1X Max-Reauth-Req

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the server’s timeout value as 5 seconds: T2600G-28TS(config)#dot1x timeout server-timeout 5 dot1x max-reauth-req 21.8 Description The dot1x max-reauth-req command is used to configure the maximum transfer times of the repeated authentication request when the server cannot be connected.
  • Page 163: Dot1X

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IEEE 802.1X function for the Gigabit Ethernet port 1: T2600G-28TS(config)#interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#dot1x dot1x guest-vlan(interface) 21.10 Description The dot1x guest-vlan command is used to enable the guest VLAN function for a specified port.
  • Page 164: Dot1X Port-Control

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Guest VLAN function for Gigabit Ethernet port 1/0/2: T2600G-28TS(config)#interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#dot1x guest-vlan dot1x port-control 21.11 Description The dot1x port-control command is used to configure the Control Mode of IEEE 802.1X for the specified port.
  • Page 165: Dot1X Port-Method

    T2600G-28TS(config)#interface gigabitEthernet 1/0/20 T2600G-28TS(config-if)#dot1x port-control authorized-force dot1x port-method 21.12 Description The dot1x port-method command is used to configure the control type of IEEE 802.1X for the specified port. By default, the control type is “mac-based”. To restore to the default configuration, please use no dot1x port-method command.
  • Page 166: Show Dot1X Global

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of 801.X globally: T2600G-28TS(config)#show dot1x global show dot1x interface 21.14 Description The show dot1x interface command is used to display all ports or the specified port’s configuration information of 801.X.
  • Page 167 Example Display the configuration information of 801.X for Gigabit Ethernet port 20: T2600G-28TS(config)#show dot1x interface gigabitEthernet 1/0/20 Display the configuration information of 801.X for all Ethernet ports: T2600G-28TS(config)#show dot1x interface...
  • Page 168: Chapter 22 Pppoe Id-Insertion Commands

    To disable the PPPoE ID-Insertion function, please use no pppoe id-insertion command. Syntax pppoe id-insertion no pppoe id-insertion Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the PPPoE ID-Insertion function: T2600G-28TS(config)# pppoe id-insertion...
  • Page 169: Pppoe Circuit-Id(Interface)

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the PPPoE Circuit-ID Insertion function for the Gigabit Ethernet port 1/0/1: T2600G-28TS (config)# interface gigabitEthernet 1/0/1 T2600G-28TS (config-if)# pppoe circuit-id pppoe circuit-id type 22.3 Description The pppoe circuit-id type command is used to configure the type of PPPoE Circuit-ID for a specified port.
  • Page 170: Pppoe Remote-Id

    Example Configure the type of PPPoE Circuit-ID as “mac” for the Gigabit Ethernet port 1/0/1: T2600G-28TS (config)# interface gigabitEthernet 1/0/1 T2600G-28TS (config-if)# pppoe circuit-id type mac pppoe remote-id 22.4 Description The pppoe remote-id command is used to enable the PPPoE Remote-ID Insertion and configure the Remote-ID value for a specified port.
  • Page 171: Show Pppoe Id-Insertion Global

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of PPPoE Circuit-ID Insertion function globally: T2600G-28TS # show pppoe circuit-id global show pppoe id-insertion interface 22.6 Description The show pppoe id-insertion interface command is used to display all ports’...
  • Page 172 Display the configuration information of PPPoE Circuit-ID Insertion function of all Ethernet ports: T2600G-28TS# show pppoe id-insertion interface Display the configuration of PPPoE Circuit-ID Insertion function of the Gigabit Ethernet port 1/0/1 : T2600G-28TS# show pppoe id-insertion interface gigabitEthernet 1/0/1...
  • Page 173: Chapter 23 System Log Commands

    Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the system log buffer: T2600G-28TS(config)#logging buffer logging buffer level 23.2 Description The logging buffer level command is used to configure the severity level and the status of the configuration input to the log buffer.
  • Page 174: Logging File Flash

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Set the severity level as 5: T2600G-28TS(config)#logging buffer level 5 logging file flash 23.3 Description The logging file flash command is used to store the log messages in a file in the flash on the switch.
  • Page 175: Logging File Flash Frequency

    This option will reduce the life of the flash and is not recommended. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify the log file synchronization frequency as 10 hours: T2600G-28TS(config)#logging file flash frequency periodic10...
  • Page 176: Logging File Flash Level

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Save the log messages with their severities equal or higher than 7 to the flash : T2600G-28TS(config)#logging file flash level 7 logging host index 23.6 Description The logging host index command is used to configure the Log Host.
  • Page 177: Logging Console

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable log host 2 and set its IP address as 192.168.0.148, the level 5: T2600G-28TS(config)# logging host index 2 192.168.0.148 5 logging console 23.7 Description The logging console command is used to send the system logs to the console port.
  • Page 178: Logging Console Level

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Output the log information with severity levels between 0-7 to the console port: T2600G-28TS(config)# logging console level 7 logging monitor 23.9 Description The logging monitor command is used to display the system logs on the terminal devices.
  • Page 179: Logging Monitor Level

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable logging to the terminal devices: T2600G-28TS(config)# no logging monitor logging monitor level 23.10 Description The logging monitor level command is used to limit messages logged to the terminal devices.
  • Page 180: Clear Logging

    Example Output the log information with severity levels between 0-7 to the terminal devices: T2600G-28TS(config)# logging monitor level 7 clear logging 23.11 Description The clear logging command is used to clear the information in the log buffer and log file.
  • Page 181: Show Logging Loghost

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of the log host 2: T2600G-28TS(config)# show logging loghost 2 show logging buffer 23.14 Description The show logging buffer command is used to display the log information in the...
  • Page 182: Show Logging Flash

    Privilege Requirement None. Example Display the log information from level 0 to level 5 in the log buffer: T2600G-28TS(config)# show logging buffer level 5 show logging flash 23.15 Description The show logging flash command is used to display the log information in the log file according to the severity level.
  • Page 183: Chapter 24 Ssh Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the SSH function: T2600G-28TS(config)# ip ssh server ip ssh version 24.2 Description The ip ssh version command is used to enable the SSH protocol version. To disable the protocol version, please use no ip ssh version command.
  • Page 184: Ip Ssh Algorithm

    Only Admin, Operator and Power User level users have access to these commands. Example Enable SSH v2: T2600G-28TS(config)# ip ssh version v2 ip ssh algorithm 24.3 Description The ip ssh algorithm command is used to configure the algorithm in SSH function.
  • Page 185: Ip Ssh Timeout

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the idle-timeout time of SSH as 30 seconds: T2600G-28TS(config)# ip ssh timeout 30 ip ssh max-client 24.5 Description The ip ssh max-client command is used to specify the maximum number of the connections to the SSH server.
  • Page 186: Ip Ssh Download

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the maximum number of the connections to the SSH server as 3: T2600G-28TS(config)# ip ssh max-client 3 ip ssh download 24.6 Description The ip ssh download command is used to download the SSH key file from TFTP server.
  • Page 187: Remove Public-Key

    Download an SSH-1 type key file named ssh-key from TFTP server with the IP address fe80::1234: T2600G-28TS(config)# ip ssh download v1 ssh-key ip-address fe80::1234 remove public-key 24.7 Description The remove public-key command is used to remove the SSH public key from the switch.
  • Page 188 Example Display the global configuration of SSH: T2600G-28TS(config)# show ip ssh...
  • Page 189: Chapter 25 Mac Address Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Add a static Mac address entry to bind the MAC address 00:02:58:4f:6c:23, VLAN1 and port 1 together: T2600G-28TS(config)# mac address-table static 00:02:58:4f:6c:23 vid 1 interface gigabitEthernet 1/0/1...
  • Page 190: Mac Address-Table Aging-Time

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the aging time as 500 seconds: T2600G-28TS(config)# mac address-table aging-time 500 mac address-table filtering 25.3 Description The mac address-table filtering command is used to add the filtering address entry.
  • Page 191: Mac Address-Table Notification

    Example Add a filtering address entry of which VLAN ID is 1 and MAC address is 00:1e:4b:04:01:5d: T2600G-28TS(config)# mac address-table filtering 00:1e:4b:04:01:5d vid 1 mac address-table notification 25.4 Description The mac address-table notification command is used to configure global settings of MAC address table notification.
  • Page 192: Mac Address-Table Max-Mac-Count

    Example Enable the global MAC address notification and table full notification, specify the notification sending interval as 2 seconds: T2600G-28TS(config)# mac address-table notification global-status enable table-full-status enable interval 2 mac address-table max-mac-count 25.5 Description The mac address-table max-mac-count command is used to configure the Port Security.
  • Page 193: Mac Address-Table Notification (Interface)

    30. When the number of MAC address entries reaches 30 on this port, new entry will be dropped : T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)# mac address-table max-mac-count max-number 30 mode static status drop mac address-table notification (interface) 25.6...
  • Page 194: Mac Address-Table Security

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the learn-mode-change notification on port 1/0/2: T2600G-28TS(config)# mac address-table notification global-status enable T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# address-table notification learn-mode-change enable mac address-table security 25.7...
  • Page 195: Show Mac Address-Table

    Example Configure the max learned MAC address number is VLAN 2 as 1000, and drop the packets that have no match in the MAC address table: T2600G-28TS(config)# mac address-table security vid 2 max-learn 1000 drop show mac address-table 25.8...
  • Page 196: Clear Mac Address-Table

    Only Admin, Operator and Power User level users have access to these commands. Example Clear the information of all static address entries: T2600G-28TS(config)# clear mac address-table static show mac address-table aging-time 25.10 Description The show mac address-table aging-time command is used to display the Aging Time of the MAC address.
  • Page 197: Show Mac Address-Table Interface

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the security configuration of all ports: T2600G-28TS(config)# show mac address-table max-mac-count all Display the security configuration of port 1/0/1: T2600G-28TS(config)# show mac address-table max-mac-count interface gigabitEthernet 1/0/1 show mac address-table interface 25.12...
  • Page 198: Show Mac Address-Table Count

    Privilege Requirement None. Example Display the address configuration of port 1/0/1: T2600G-28TS(config)# show mac address-table interface gigabitEthernet 1/0/1 show mac address-table count 25.13 Description The show mac address-table count command is used to display the total amount of MAC address table.
  • Page 199: Show Mac Address-Table Vlan

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the MAC address configuration of vlan 1: T2600G-28TS(config)# show mac address-table vlan 1 show mac address-table notification 25.16 Description The show mac address-table notification command is used to display the...
  • Page 200: Show Mac Address-Table Security

    [ vid vid ] Parameter —— The specified VLAN id. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the MAC address security configuration of VLAN 1: T2600G-28TS(config)# show mac address-table security vid 1...
  • Page 201: Chapter 26 System Configuration Commands

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the system mode as manual, and the time is 12/20/2010 17:30:35 T2600G-28TS(config)# system-time manual 12/20/2010-17:30:35 system-time ntp 26.2 Description The system-time ntp command is used to configure the time zone and the IP address for the NTP Server.
  • Page 202 UTC-12:00 —— TimeZone for International Date Line West. UTC-11:00 —— TimeZone for Coordinated Universal Time-11. UTC-10:00 —— TimeZone for Hawaii. UTC-09:00 —— TimeZone for Alaska. UTC-08:00 —— TimeZone for Pacific Time(US Canada). UTC-07:00 —— TimeZone for Mountain Time(US Canada). UTC-06:00 —— TimeZone for Central Time(US Canada). UTC-05:00 ——...
  • Page 203: System-Time Dst Predefined

    New Zealand: Last Sunday in September, 02:00 ~ First Sunday in April, 03:00. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the daylight saving time as USA standard: T2600G-28TS(config)#system-time dst predefined USA...
  • Page 204: System-Time Dst Date

    system-time dst date 26.4 Description The system-time dst date command is used to configure the one-off daylight saving time. The start date is in the current year by default. The time range of the daylight saving time must shorter than one year, but you can configure it spanning years.
  • Page 205: System-Time Dst Recurring

    Example Configure the daylight saving time from zero clock, Apr 1st to zero clock Oct 1st and the offset is 30 minutes in 2015: T2600G-28TS(config)# system-time dst date Apr 1 00:00 2015 Oct 1 00:00 2015 30 system-time dst recurring 26.5...
  • Page 206: Hostname

    [ hostname ] no hostname Parameter hostname —— System Name. The length of the name ranges from 1 to 32 characters. By default, it is the device name, for example “T2600G-28TS”. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands.
  • Page 207: Location

    Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the system location as SHENZHEN: T2600G-28TS(config)# location SHENSHEN contact-info 26.8 Description The contact-info command is used to configure the system contact information.
  • Page 208: Ip Address

    Example Configure the system contact information as www.tp-link.com: T2600G-28TS(config)# contact-info www.tp-link.com ip address 26.9 Description This ip address command is used to configure the IP address and IP subnet mask for the specified interface manually. The interface type includes: routed port, port-channel interface, loopback interface and VLAN interface.
  • Page 209: Ip Address-Alloc

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCP Client function on the Lay 3 routed port 1/0/1: T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)# no switchport T2600G-28TS(config-if)# ip address-alloc dhcp Disable the IP address obtaining function on the VLAN interface 2:...
  • Page 210: Reset

    Privileged EXEC Mode Privilege Requirement Only Admin level users have access to these commands. Example Reset the software of the switch: T2600G-28TS# reset reboot 26.12 Description The reboot command is used to reboot the Switch. To avoid damage, please don’t turn off the device while rebooting.
  • Page 211: Copy Running-Config Startup-Config

    Example Specify the switch to save the configuration files and reboot in 200 minutes,: T2600G-28TS(config)# reboot-schedule in 200 save_before_reboot copy running-config startup-config 26.14...
  • Page 212: Copy Startup-Config Tftp

    Privileged EXEC Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Backup the configuration files to TFTP server with the IP 192.168.0.148 and name this file config.cfg: T2600G-28TS# copy startup-config tftp ip-address 192.168.0.148 filename config...
  • Page 213: Copy Tftp Startup-Config

    Backup the configuration files to TFTP server with the IP fe80::1234 and name this file config.cfg: T2600G-28TS# copy startup-config tftp ip-address fe80::1234 filename config copy tftp startup-config 26.16 Description The copy tftp startup-config command is used to download the configuration file to the switch from TFTP server.
  • Page 214: Boot Application

    Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the image2.bin as the startup image: T2600G-28TS(config)# boot application filename image2 startup remove backup-image 26.18 Description The remove backup-image command is used to delete the backup-image.
  • Page 215: Firmware Upgrade

    Upgrade the switch’s backup iamge file with the file firmware.bin in the TFTP server with the IP address 192.168.0.148, and reboot the switch with this firmware: T2600G-28TS# firmware upgrade ip-address 192.168.0.148 filename firmware.bin It will only upgrade the backup image. Continue? (Y/N):y...
  • Page 216: Ping

    If there is not any response after 8 times’ Ping test, the connection between the switch and the network device is failed to establish: T2600G-28TS# ping 192.168.0.131 –n 8 –l 512 To test the connectivity between the switch and the network device with the IP...
  • Page 217: Tracert

    If there is not any response after 8 times’ Ping test, the connection between the switch and the network device is failed to establish: T2600G-28TS# ping fe80::1234 –n 8 –l 512 tracert 26.21 Description The tracert command is used to test the connectivity of the gateways during its journey from the source to destination of the test data.
  • Page 218: Show System-Info

    Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the system information: T2600G-28TS# show system-info show image-info 26.23 Description The show image-info command is used to display the information of image files in the system.
  • Page 219: Show Boot

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the system boot configuration information: T2600G-28TS# show boot show running-config 26.25 Description The show running-config command is used to display the current operating configuration of the system or of a specified port.
  • Page 220: Show Startup-Config

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the saved configuration: T2600G-28TS# show startup-config show system-time 26.27 Description The show system-time command is used to display the time information of the switch.
  • Page 221: Show System-Time Dst

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DST time information of the switch T2600G-28TS# show system-time dst show system-time ntp 26.29 Description The show system-time ntp command is used to display the NTP mode configuration information.
  • Page 222: Show Cable-Diagnostics Interface Gigabitethernet

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Show the cable-diagnostics of port 3: T2600G-28TS# show cable-diagnostics interface gigabitEthernet 1/0/3 show cpu-utilization 26.31 Description The show cpu-utilization command is used to display the system’s CPU utilization in the last 5 seconds/1minute/5minutes.
  • Page 223: Show Memory-Utilization

    Example Display the CPU utilization information of the switch: T2600G-28TS# show cpu-utilization show memory-utilization 26.32 Description The show memory-utilization command is used to display the system’s memory utilization in the last 5 seconds/1minute/5minutes. Syntax show memory-utilization Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None.
  • Page 224: Chapter 27 Ipv6 Address Configuration Commands

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IPv6 function on the VLAN interface 1: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 enable ipv6 address autoconfig 27.2 Description This command is used to enable the automatic configuration of the ipv6 link-local address.
  • Page 225: Ipv6 Address Link-Local

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the automatic configuration of the ipv6 link-local address on VLAN interface 1: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 address autoconfig ipv6 address link-local 27.3 Description The ipv6 address link-local command is used to configure the ipv6 link-local address manually on a specified interface.
  • Page 226: Ipv6 Address Dhcp

    Example Configure the link-local address as fe80::1234 on the VLAN interface 1: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 address fe80::1234 link-local ipv6 address dhcp 27.4 Description The ipv6 address dhcp command is used to enable the DHCPv6 Client function. When this function is enabled, the Layer 3 interface will try to obtain IP from DHCPv6 server.
  • Page 227: Ipv6 Address Eui-64

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the automatic ipv6 address configuration function to obtain IPv6 address through the RA message on VLAN interface 1: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 address ra ipv6 address eui-64 27.6 Description This command is used to manually configure a global IPv6 address with an extended unique identifier (EUI) in the low-order 64 bits on the interface.
  • Page 228: Ipv6 Address

    Example Configure an EUI-64 global address on the interface with the network prefix 3ffe::/64: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 address 3ffe::/64 eui-64 ipv6 address 27.7 Description This command is used to manually configure a global IPv6 address on the interface.
  • Page 229 Syntax show ipv6 interface Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the ipv6 information of the management interface: T2600G-28TS(config)# show ipv6 interface...
  • Page 230: Chapter 28 Ethernet Configuration Commands

    Only Admin, Operator and Power User level users have access to these commands. Example To enter the Interface gigabitEthernet Configuration Mode and configure port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 interface range gigabitEthernet 28.2 Description The interface range gigabitEthernet command is used to enter the interface range gigabitEthernet Configuration Mode and configure multiple Gigabit Ethernet ports at the same time.
  • Page 231: Description

    Example To enter the Interface range gigabitEthernet Configuration Mode, and configure ports 1, 2, 3, 6, 7 and 9 at the same time by adding them to one port-list: T2600G-28TS(config)# interface range gigabitEthernet 1/0/1-3,1/0/6-7,1/0/9 description 28.3 Description The description command is used to add a description to the Ethernet port.
  • Page 232: Shutdown

    Example Add a description Port_5 to port 1/0/5: T2600G-28TS(config)# interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)# description Port_5 shutdown 28.4 Description The shutdown command is used to disable an Ethernet port. To enable this port again, please use no shutdown command. Syntax shutdown...
  • Page 233: Duplex

    / interface port-channel / interface range port-channel) Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the flow-control function for port 1/0/3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# flow-control duplex 28.6 Description The duplex command is used to configure the Duplex Mode for an Ethernet port.
  • Page 234: Jumbo

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Allow jumbo frame on port 1/0/3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# jumbo speed 28.8 Description The speed command is used to configure the Speed Mode for an Ethernet port.
  • Page 235: Storm-Control Pps

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the Speed Mode as 100Mbps for port 1/0/3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# speed 100 storm-control pps 28.9 Description The storm-control pps command is used to configure the storm control mode as pps(packets per second) on an interface.
  • Page 236: Storm-Control

    Before you configure the storm-control type as kbps or ratio, pelease ensure that the port is not in pps mode. Example Configure the broadcast storm control rate as 1000 kbps on port 1/0/5: T2600G-28TS(config)# interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)# storm-control broadcast kbps 1000...
  • Page 237: Bandwidth

    Example Configure the ingress-rate as 5120Kbps and egress-rate as 1024Kbps for port 1/0/5: T2600G-28TS(config)# interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)# bandwidth ingress 5120 egress 1024 clear counters 28.12 Description The clear counters command is used to clear the statistics information of all the Ethernet ports and port channels.
  • Page 238: Show Interface Status

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the connection status of all ports and port channels: T2600G-28TS(config)# show interface status Display the connection status of port 1/0/1: T2600G-28TS(config)# show interface status gigabitEthernet 1/0/1 show interface counters 28.14...
  • Page 239: Show Interface Configuration

    Example Display the statistics information of all Ethernet ports and port channels: T2600G-28TS(config)# show interface counters Display the statistics information of port 1/0/2: T2600G-28TS(config)# show interface counters gigabitEthernet 1/0/2 show interface configuration 28.15 Description The show interface configuration command is used to display the configurations of all ports and port channels, including Port-status, Flow Control, Negotiation Mode and Port-description.
  • Page 240: Show Storm-Control

    Example Display the configurations of all Ethernet ports and port channels: T2600G-28TS(config)# show interface configuration Display the configurations of port 1/0/2: T2600G-28TS(config)# show interface configuration gigabitEthernet 1/0/2 show storm-control 28.16 Description The show storm-control command is used to display the storm-control information of Ethernet ports.
  • Page 241 —— The list of Ethernet ports. port-list port-channel-id-list —— The list of port channels. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the bandwidth-limit information of port 1/0/4: T2600G-28TS(config)# show bandwidth interface gigabitEthernet 1/0/4...
  • Page 242: Chapter 29 Qos Commands

    CoS value of the ingress port and the mapping relation between the CoS and TC in IEEE 802.1P. Example Configure the priority of port 5 as 3: T2600G-28TS(config)# interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)# qos 3...
  • Page 243: Qos Dscp

    DSCP priority and CoS value. Example Enable the mapping relation between DSCP Priority and CoS value: T2600G-28TS(config)# qos dscp qos queue cos-map 29.3 Description The qos queue cos-map command is used to configure the mapping relation between IEEE 802.1P priority tag/IEEE 802.1Q tag, CoS value and the TC...
  • Page 244: Qos Queue Dscp-Map

    Among the priority levels TC0-TC7, the bigger value, the higher priority. Example Map CoS 5 to TC 2: T2600G-28TS(config)# qos queue cos-map 5 2 qos queue dscp-map 29.4 Description The qos queue dscp-map command is used to configure the mapping relation between DSCP Priority and the CoS value.
  • Page 245: Qos Queue Mode

    (0-7)-CoS 0, (8-15)-CoS 1, (16-23)-CoS 2, (24-31)-CoS 3, (32-39)-CoS 4, (40-47)-CoS 5, (48-55)-CoS 6, (56-63)-CoS 7. Example Map DSCP values 10-12 to CoS 2: T2600G-28TS(config)# qos queue dscp-map 10-12 2 qos queue mode 29.5 Description The qos queue mode command is used to configure the Schedule Mode. To return to the default Equal-Mode, please use no qos queue mode command.
  • Page 246: Qos Queue Weight

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the Schedule Mode as Weight Round Robin Mode: T2600G-28TS(config)# qos queue mode wrr qos queue weight 29.6 Description The qos queue weight command is used to configure weight value of each queue after the Schedule Mode is specified as WRR or SP+WRR.
  • Page 247 Specify the Schedule Mode as Weight Round Robin Mode, with the weight values of TC0, TC1, TC2 and TC3 as 4, 7, 15 and 24: T2600G-28TS(config)# qos queue mode wrr T2600G-28TS(config)# qos queue weight 0 4 T2600G-28TS(config)# qos queue weight 1 7 T2600G-28TS(config)# qos queue weight 2 15...
  • Page 248: Show Qos Interface

    Example Display the configuration of QoS for all ports and LAGs: T2600G-28TS# show qos interface Display the configuration of QoS for ports 1/0/1-4: T2600G-28TS# show qos interface gigabitEthernet 1/0/1-4 show qos cos-map 29.8 Description The show qos cos-map command is used to display the configuration of IEEE 802.1P Priority and the mapping relation between cos-id and tc-id.
  • Page 249: Show Qos Dscp-Map

    The show qos queue mode command is used to display the schedule rule of the egress queues. Syntax show qos queue mode Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the schedule rule of the egress queues: T2600G-28TS# show qos queue mode...
  • Page 250: Show Qos Status

    The show qos status command is used to display the status of IEEE 802.1P priority and DSCP priority. Syntax show qos status Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the status of IEEE 802.1P priority and DSCP priority: T2600G-28TS# show qos status...
  • Page 251: Chapter 30 Port Mirror Commands

    Create monitor session 1 and configure port 1/0/1 as the monitoring port: T2600G-28TS(config)# monitor session destination interface gigabitEthernet 1/0/1 Delete the monitoring port 1/0/2 from monitor session 1: T2600G-28TS(config)# no monitor session 1 destination interface gigabitEthernet 1/0/2 Delete the monitor session 1:...
  • Page 252: Monitor Session Source Interface

    T2600G-28TS(config)# no monitor session 1 monitor session source interface 30.2 Description The monitor session source interface command is used to configure the monitored port. To delete the corresponding monitored port, please use no monitor session source interface command. Syntax monitor session session_num source interface gigabitEthernet port-list...
  • Page 253: Show Monitor Session

    Example Create monitor session 1, then configure port 4, 5, 7 as monitored port and enable ingress monitoring: T2600G-28TS(config)# monitor session 1 source interface gigabitEthernet 1/0/4-5,1/0/7 rx Delete port 4 in monitor session 1 and its configuration: T2600G-28TS(config)# monitor session...
  • Page 254: Chapter 31 Port Isolation Commands

    / interface port-channel / interface range port-channel) Privilege Requirement Only Admin and Operator level users have access to these commands. Example Set port 1, 2, 4 and port channel 2 to the forward list of port 1/0/5: T2600G-28TS(config)# interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)# port isolation gi-forward-list...
  • Page 255: Show Port Isolation Interface

    Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the forward-list of port 1/0/2: T2600G-28TS# show port isolation interface gigabitEthernet 1/0/2 Display the forward-list of all Ethernet ports and port channels: T2600G-28TS# show port isolation interface...
  • Page 256: Chapter 32 Loopback Detection Commands

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the loopback detection function globally: T2600G-28TS(config)# loopback-detection loopback-detection interval 32.2 Description The loopback-detection interval command is used to define the interval of sending loopback detection packets from switch ports to network, aiming at detecting network loops periodically.
  • Page 257: Loopback-Detection Recovery-Time

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the interval-time as 50 seconds: T2600G-28TS(config)# loopback-detection interval 50 loopback-detection recovery-time 32.3 Description The loopback-detection recovery-time command is used to configure the time after which the blocked port would automatically recover to normal status.
  • Page 258: Loopback-Detection Config

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the loopback detection function of ports 1-3: T2600G-28TS(config)# interface range gigabitEthernet 1/0/1-3 T2600G-28TS(Config-if-range)# loopback-detection loopback-detection config 32.5 Description The loopback-detection config command is used to configure the process-mode and recovery-mode for the ports by which the switch copes with the detected loops.
  • Page 259: Loopback-Detection Recover

    Only Admin, Operator and Power User level users have access to these commands. Example Configure loopback detection process-mode port-based recovery-mode as manual for port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# loopback-detection config process-mode port-based recovery-mode manual loopback-detection recover 32.6 Description...
  • Page 260: Show Loopback-Detection Interface

    Privilege Requirement None. Example Display the configuration of loopback detection function and the status of all ports: T2600G-28TS# show loopback-detection interface Display the configuration of loopback detection function and the status of port 5: T2600G-28TS# show loopback-detection interface gigabitEthernet 1/0/5...
  • Page 261: Chapter 33 Acl Commands

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Add a time-range named tSeg1: T2600G-28TS(config)# time-range tSeg1 absolute 33.2 Description The absolute command is used to configure a time-range into an absoluteness mode. To delete the corresponding Absoluteness Mode time-range, please use...
  • Page 262: Periodic

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the time-range tSeg1 with time from May 5, 2012 to Oct. 5, 2012: T2600G-28TS(config)# time-range tSeg1 T2600G-28TS(config-time-range)# absolute start 05/05/2012 end 10/05/2012 periodic 33.3 Description The periodic command is used to configure the time-range into periodic mode.
  • Page 263: Holiday

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the time-range tSeg1 with time from 8:30 to 12:00 at weekend: T2600G-28TS(config)#time-range tSeg1 T2600G-28TS(config-time-range)#periodic week-date weekend time-slice1 08:30-12:00 holiday 33.4 Description The holiday command is used to configure the time-range into Holiday Mode under Time-range Create Configuration Mode.
  • Page 264: Holiday(Global)

    Example Define National Day, configuring the start date as October 1st, and the end date as October 3rd: T2600G-28TS(config)#holiday nationalday start-date 10/01 end-date 10/03 access-list create 33.6 Description The access-list create command is used to create standard-IP ACL, extend-IP ACL, combined ACL and IPv6 ACL.
  • Page 265: Mac Access-List

    Only Admin, Operator and Power User level users have access to these commands. Example Create a standard-IP ACL whose ID is 523: T2600G-28TS(config)# access-list create 523 mac access-list 33.7 Description The mac access-list command is used to create MAC ACL. To set the detailed configurations for a specified MAC ACL, please use mac access-list command to access Mac Access-list Configuration Mode.
  • Page 266: Access-List Standard

    access-list standard 33.8 Description The access-list standard command is used to add Standard-IP ACL rule. To delete the corresponding rule, please use no access-list standard command. Standard-IP ACLs analyze and process data packets based on a series of match conditions, which can be the source IP addresses and destination IP addresses carried in the packets.
  • Page 267: Access-List Extended

    T2600G-28TS(config)# access-list create 520 T2600G-28TS(config)# access-list standard 520 rule 10 permit sip 192.168.0.100 smask 255.255.255.0 tseg tSeg1 access-list extended 33.9 Description The access-list extended command is used to add Extended-IP ACL rule. To delete the corresponding rule, please use no access-list extended command.
  • Page 268: Access-List Combined

    255.255.255.0, the time-range for the rule to take effect is tSeg1, and the packets match this rule will be forwarded by the switch: T2600G-28TS(config)# access-list create 2220 T2600G-28TS(config)# access-list extended 2220 rule 10 permit sip 192.168.0.100 smask 255.255.255.0 tseg tSeg1 access-list combined 33.10...
  • Page 269 permit ——The operation to forward packets. It is the default value. source-mac —— The source MAC address contained in the rule. source-mac-mask —— The source MAC address mask. It is required if you typed the source MAC address. destination-mac —— The destination MAC address contained in the rule. destination-mac-mask ——...
  • Page 270: Access-List Ipv6

    255.255.255.0, the time-range for the rule to take effect is “tSeg1”, and the packets match this rule will be forwarded by the switch: T2600G-28TS(config)# access-list create 2700 T2600G-28TS(config)# access-list combined 2700 rule 10 permit smac 00:01:3F:48:16:23 smask 11:11:11:11:11:00 sip 192.168.0.100 sip-mask 255.255.255.0 tseg tSeg1 access-list ipv6 33.11...
  • Page 271: Rule

    “tSeg1”, and the packets match this rule will be forwarded by the switch: T2600G-28TS(config)# access-list create 3600 T2600G-28TS(config)# access-list ipv6 3600 rule 10 permit sip 3001::1 sip-mask ffff:ffff:ff00:00ff tseg tSeg1 rule 33.12 Description The rule command is used to configure MAC ACL rule.
  • Page 272: Access-List Policy Name

    11:11:11:11:11:00, VLAN ID is 2, the user priority is 5, the time-range for the rule to take effect is “tRange1”, and the packets match this rule will be forwarded by the switch: T2600G-28TS(config)# mac access-list 20 T2600G-28TS(config-mac-acl)# rule 10 permit smac 00:01:3F:48:16:23 smask 11:11:11:11:11:00 vid 2 pri 5 tseg tRange1 access-list policy name 33.13 Description The access-list policy name command is used to add Policy.
  • Page 273: Access-List Policy Action

    Only Admin, Operator and Power User level users have access to these commands. Example Add a Policy named policy1: T2600G-28TS(config)# access-list policy name policy1 access-list policy action 33.14 Description The access-list policy action command is used to add ACLs and create actions for the policy.
  • Page 274: Redirect Interface

    T2600G-28TS(config)# access-list policy action policy1 120 redirect interface 33.15 Description The redirect interface command is used to configure Direction function of policy action for specified ports. Syntax redirect interface { gigabitEthernet port } Parameter port —— The Destination Port of Redirect. The data packets matching the corresponding ACL will be forwarded to the specific port.
  • Page 275: S-Mirror

    Example Edit the actions for policy1. For the data packets matching ACL 120 in the policy, if the rate beyond 1000kbps, they will be discarded by the switch: T2600G-28TS(config)#access-list policy action policy1 120 T2600G-28TS(config-action)#s-condition rate 1000 osd discard s-mirror 33.17...
  • Page 276: Qos-Remark

    Example Edit the actions for policy1. For the data packets matching ACL 120, specify the DSCP region as 30 and local priority 2: T2600G-28TS(config)#access-list policy action policy1 120 T2600G-28TS(config-action)# qos-remark dscp 30 priority 2 access-list bind acl(interface) 33.19 Description The access-list bind acl command is used to bind an ACL to the specified port.
  • Page 277: Access-List Bind Acl(Vlan)

    Only Admin, Operator and Power User level users have access to these commands. Example Bind ACL 100 to port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# access-list bind acl 100 access-list bind acl(vlan) 33.20 Description The access-list bind acl command is used to bind an ACL to the specified VLAN.
  • Page 278: Access-List Bind(Interface)

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Bind policy1 to port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# access-list bind policy1 access-list bind(vlan) 33.22 Description The access-list bind command is used to bind a policy to a VLAN. To cancel the bind relation, please use no access-list bind command.
  • Page 279: Show Access-List

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Bind policy1 to VLAN 2: T2600G-28TS(config)# interface vlan 2 T2600G-28TS(config-if)# access-list bind policy1 show access-list 33.23 Description The show access-list command is used to display configuration of ACL.
  • Page 280: Show Access-List Bind

    Privilege Requirement None. Example Display the information of a policy named policy1: T2600G-28TS(config)# show access-list policy policy1 show access-list bind 33.25 Description The show access-list bind command is used to display the configuration of Policy bind. Syntax show access-list bind...
  • Page 281: Chapter 34 Mstp Commands

    Chapter 34 MSTP Commands MSTP (Multiple Spanning Tree Protocol), compatible with both STP and RSTP and subject to IEEE 802.1s, can disbranch a ring network. STP is to block redundant links and backup links as well as optimize paths. debug spanning-tree 34.1 Description The debug spanning-tree command is used to enable debuggning of...
  • Page 282: Spanning-Tree(Global)

    Privilege Requirement Only Admin level users have access to these commands. Example Display all the spanning-tree debug messages: T2600G-28TS# debug spanning-tree all spanning-tree(global) 34.2 Description The spanning-tree command is used to enable STP function globally. To disable the STP function, please use no spanning-tree command.
  • Page 283: Spanning-Tree Common-Config

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the STP function for port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree spanning-tree common-config 34.4 Description The spanning-tree common-config command is used to configure the parameters of the ports for comparison in the CIST and the common parameters of all instances.
  • Page 284: Spanning-Tree Mode

    Enable the STP function of port 1, and configure the Port Priority as 64, ExtPath Cost as 100, IntPath Cost as 100, and then enable Edge Port: T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)# spanning-tree common-config port-priority 64 ext-cost 100 int-cost 100 portfast enable point-to-point open spanning-tree mode 34.5...
  • Page 285: Spanning-Tree Mst Configuration

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the spanning-tree mode as mstp: T2600G-28TS(config)# spanning-tree mode mstp spanning-tree mst configuration 34.6 Description The spanning-tree mst configuration command is used to access MST Configuration Mode from Global Configuration Mode, as to configure the VLAN-Instance mapping, region name and revision level.
  • Page 286: Name

    T2600G-28TS(config)# spanning-tree mst configuration T2600G-28TS(config-mst)# no instance 1 Remove VLANs 1-50 in mapping VLANs 1-100 for Instance 1: T2600G-28TS(config)# spanning-tree mst configuration T2600G-28TS(config-mst)# no instance 1 vlan 1-50 name 34.8 Description The name command is used to configure the region name of MST instance.
  • Page 287: Revision

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the region name of MST as “region1”: T2600G-28TS(config)# spanning-tree mst configuration T2600G-28TS(config-mst)# name region1 revision 34.9 Description The revision command is used to configure the revision level of MST instance.
  • Page 288: Spanning-Tree Mst

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the MST Instance 1 and configure its priority as 4096: T2600G-28TS(config)# spanning-tree mst instance 1 priority 4096 spanning-tree mst 34.11 Description The spanning-tree mst command is used to configure MST Instance Port. To return to the default configuration of the corresponding Instance Port, please use no spanning-tree mst command.
  • Page 289: Spanning-Tree Priority

    Only Admin, Operator and Power User level users have access to these commands. Example Configure the priority of port 1 in MST Instance 1 as 64, and path cost as 2000: T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)# spanning-tree mst instance 1 port-priority 64 cost 2000 spanning-tree priority 34.12 Description The spanning-tree priority command is used to configure the bridge priority.
  • Page 290: Spanning-Tree Tc-Defend

    Only Admin, Operator and Power User level users have access to these commands. Example Configure TC Threshold as 30 packets and TC Protect Cycle as 10 seconds: T2600G-28TS(config)# spanning-tree tc-defend threshold 30 period 10 spanning-tree timer 34.14 Description The spanning-tree timer command is used to configure forward-time, hello-time and max-age of Spanning Tree.
  • Page 291: Spanning-Tree Hold-Count

    Only Admin, Operator and Power User level users have access to these commands. Example Configure forward-time, hello-time and max-age for Spanning Tree as 16 seconds, 3 seconds and 22 seconds respectively: T2600G-28TS(config)# spanning-tree timer forward-time 16 hello-time 3 max-age 22 spanning-tree hold-count 34.15 Description The spanning-tree hold-count command is used to configure the maximum number of BPDU packets transmitted per Hello Time interval.
  • Page 292: Spanning-Tree Max-Hops

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the hold-count of STP as 8pps: T2600G-28TS(config)# spanning-tree hold-count 8 spanning-tree max-hops 34.16 Description The spanning-tree max-hops command is used to configure the maximum number of hops that occur in a specific region before the BPDU is discarded.
  • Page 293: Spanning-Tree Bpduguard

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the BPDU filter function for port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree bpdufilter spanning-tree bpduguard 34.18 Description The spanning-tree bpduguard command is used to enable the BPDU protect function for a port.
  • Page 294: Spanning-Tree Guard Loop

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Loop Protect function for port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree guard loop spanning-tree guard root 34.20 Description The spanning-tree guard root command is used to enable the Root Protect function for a port.
  • Page 295: Spanning-Tree Guard Tc

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Root Protect function for port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree guard root spanning-tree guard tc 34.21 Description The spanning-tree guard tc command is used to enable the TC Protect of Spanning Tree function for a port.
  • Page 296: Spanning-Tree Mcheck

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable mcheck for port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree mcheck show spanning-tree active 34.23 Description The show spanning-tree active command is used to display the active information of spanning-tree.
  • Page 297: Show Spanning-Tree Bridge

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the bridge parameters: T2600G-28TS(config)# show spanning-tree bridge show spanning-tree interface 34.25 Description The show spanning-tree interface command is used to display the spanning-tree information of all ports or a specified port.
  • Page 298: Show Spanning-Tree Interface-Security

    T2600G-28TS(config)# show spanning-tree interface Display the spanning-tree information of port 1/0/2: T2600G-28TS(config)# show spanning-tree interface gigabitEthernet 1/0/2 Display the spanning-tree mode information of port 1/0/2: T2600G-28TS(config)# show spanning-tree interface gigabitEthernet 1/0/2 mode show spanning-tree interface-security 34.26 Description The show spanning-tree interface-security command is used to display the protect information of all ports or a specified port.
  • Page 299: Show Spanning-Tree Mst

    Display the region information and mapping information of VLAN and MST Instance: T2600G-28TS(config)#show spanning-tree mst configuration Display the related information of MST Instance 1: T2600G-28TS(config)#show spanning-tree mst instance 1 Display all the ports information of MST Instance 1: T2600G-28TS(config)#show spanning-tree mst instance 1 interface...
  • Page 300: Chapter 35 Ethernet Oam Commands

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the Ethernet OAM function for Gigabit Ethernet port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ethernet-oam ethernet-oam mode 35.2 Description The ethernet-oam mode command is used to configure the OAM mode for the desired port.
  • Page 301: Ethernet-Oam Link-Monitor Symbol-Period

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure Ethernet OAM client to operate in passive mode for Gigabit Ethernet port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ethernet-oam mode passive ethernet-oam link-monitor symbol-period 35.3 Description The ethernet-oam link-monitor symbol-period command is used to configure the parameters about one of the link events, error symbol period event.
  • Page 302: Ethernet-Oam Link-Monitor Frame

    Only Admin and Operator level users have access to these commands. Example For error symbol-period event, configure the error threshold as 5 and the event detection interval as 3 seconds on Gigabit Ethernet port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# ethernet-oam link-monitor...
  • Page 303: Ethernet-Oam Link-Monitor Frame-Period

    Example For error frame event, configure the error threshold as 6 and the event detection interval as 9 seconds on Gigabit Ethernet port 1/0/3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# ethernet-oam link-monitor frame threshold 6 window 90 ethernet-oam link-monitor frame-period 35.5...
  • Page 304: Ethernet-Oam Link-Monitor Frame-Seconds

    Only Admin and Operator level users have access to these commands. Example For error frame period event, configure the error threshold as 6 and the event detection interval as 150000 frames on Gigabit Ethernet port 1/0/4: T2600G-28TS(config)# interface gigabitEthernet 1/0/4 T2600G-28TS(config-if)# ethernet-oam link-monitor...
  • Page 305: Ethernet-Oam Remote-Failure

    Only Admin and Operator level users have access to these commands. Example For error frame seconds event, configure the error threshold as 8 and the event detection interval as 30 seconds on Gigabit Ethernet port 5: T2600G-28TS(config)# interface gigabitEthernet 1/0/5 T2600G-28TS(config-if)# ethernet-oam link-monitor...
  • Page 306: Ethernet-Oam Remote-Loopback Received-Remote- Loopback

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable the Dying Gasp link event notification on Gigabit Ethernet port 1/0/7: T2600G-28TS(config)# interface gigabitEthernet 1/0/7 T2600G-28TS(config-if)# ethernet-oam remote-failure dying-gasp notify disable ethernet-oam remote-loopback received-remote- 35.8 loopback...
  • Page 307: Ethernet-Oam Remote-Loopback

    T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)# ethernet-oam remote-loopback received -remote-loopback process ethernet-oam remote-loopback 35.9 Description The ethernet-oam remote-loopback command is used to request the remote peer to start or stop the Ethernet OAM remote loopback mode. Syntax ethernet-oam remote-loopback { start | stop } Parameter start ——...
  • Page 308: Clear Ethernet-Oam Event-Log

    Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Clear Ethernet OAM statistics of Gigabit Ethernet port 1/0/3: T2600G-28TS(config)# clear ethernet-oam statistics interface gigabit Ethernet 1/0/3 clear ethernet-oam event-log 35.11 Description The clear ethernet-oam event-log command is used to clear the Ethernet OAM event log.
  • Page 309: Show Ethernet-Oam Configuration

    T2600G-28TS(config)# clear ethernet-oam event-log interface gigabitEthernet 1/0/3 show ethernet-oam configuration 35.12 Description The show ethernet-oam configuration command is used to display Ethernet OAM configuration information. Syntax show ethernet-oam configuration [ interface gigabitEthernet port ] Parameter port —— The Gigabit Ethernet port number. By default, the Ethernet OAM configuration information of all ports is displayed.
  • Page 310: Show Ethernet-Oam Statistics

    Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Display Ethernet OAM event log of Gigabit Ethernet port 1/0/2: T2600G-28TS(config)# show ethernet-oam event-log interface gigabitEthernet 1/0/2 show ethernet-oam statistics 35.14...
  • Page 311: Show Ethernet-Oam Status

    Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Display Ethernet OAM status of Gigabit Ethernet port 1/0/2: T2600G-28TS(config)# show ethernet-oam status interface gigabitEthernet 1/0/2...
  • Page 312: Chapter 36 Dldp Commands

    Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the DLDP function globally: T2600G-28TS(config)# dldp dldp interval 36.2 Description The dldp interval command is used to define the interval of sending advertisement packets on ports that are in the advertisement state.
  • Page 313: Dldp Shut-Mode

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify the interval of sending advertisement packets as 10 seconds: T2600G-28TS(config)# dldp interval 10 dldp shut-mode 36.3 Description The dldp shut-mode command is used to configure the shutdown mode when a unidirectional link is detected.
  • Page 314: Dldp Reset(Global)

    Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the DLDP function of ports 1/0/2-4: T2600G-28TS (config)# interface range gigabitEthernet 1/0/2-4 T2600G-28TS (config-if-range)# dldp...
  • Page 315: Dldp Reset(Interface)

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Reset the DLDP function of ports 2-4: T2600G-28TS (config)# interface range gigabitEthernet 1/0/2-4 T2600G-28TS (config-if-range)# dldp reset show dldp 36.7 Description The show dldp command is used to display the global configuration of DLDP function such as DLDP global state, DLDP interval and shut mode.
  • Page 316: Show Dldp Interface

    —— The Gigabit Ethernet port number. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration and state of all ports: T2600G-28TS# show dldp interface Display the configuration and state of port 1/0/5: T2600G-28TS# show dldp interface gigabitEthernet 1/0/5...
  • Page 317: Chapter 37 Igmp Snooping Commands

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable IGMP Snooping function: T2600G-28TS(config)# ip igmp snooping ip igmp snooping(interface) 37.2 Description The ip igmp snooping command is used to enable the IGMP Snooping function for the desired port.
  • Page 318: Ip Igmp Snooping Rtime

    300 seconds. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify IGMP Snooping router port aging time as 100 seconds globally: T2600G-28TS(config)# ip igmp snooping rtime 100...
  • Page 319: Ip Igmp Snooping Mtime

    Only Admin, Operator and Power User level users have access to these commands. Example Specify IGMP Snooping member port aging time as 100 seconds globally: T2600G-28TS(config)# ip igmp snooping mtime 100 ip igmp snooping report-suppression 37.5 Description The ip igmp snooping report-suppression command is used enable the IGMP report suppression function.
  • Page 320: Ip Igmp Snooping Immediate-Leave

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP report suppression function: T2600G-28TS(config)# ip igmp snooping report-suppression ip igmp snooping immediate-leave 37.6 Description The ip igmp snooping immediate-leave command is used to configure the Fast Leave function for port.
  • Page 321: Ip Igmp Snooping Last-Listener Query-Inteval

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the interval of Specific Query Message to 3 seconds: T2600G-28TS(config)# ip igmp snooping last-listener query-inteval 3 ip igmp snooping last-listener query-count 37.9 Description The ip igmp snooping last-listener query-count command is used to specify...
  • Page 322: Ip Igmp Snooping Vlan-Config

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the number of Specific Query Message to 3: T2600G-28TS(config)# ip igmp snooping last-listener query-count 3 ip igmp snooping vlan-config 37.10 Description The ip igmp snooping vlan-config command is used to enable VLAN IGMP Snooping function or to modify IGMP Snooping parameters, and to create static multicast IP entry.
  • Page 323 Member Port Time as 200 seconds for VLAN 1-3, and set the router port as 1/0/1 for VLAN 1-2: T2600G-28TS(config)# ip igmp snooping vlan-config 1-3 rtime 300 T2600G-28TS(config)# ip igmp snooping vlan-config 1-3 mtime 200 T2600G-28TS(config)# ip igmp snooping vlan-config 1-2 rport interface gigabitEthernet 1/0/1 Add static multicast IP address 225.0.0.1, which corresponds to VLAN 2, and...
  • Page 324: Ip Igmp Snooping Vlan-Config (Router-Port-Forbidden)

    Only Admin, Operator and Power User level users have access to these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in VLAN 1 : T2600G-28TS(config)# ip igmp snooping vlan-config 1 router-port-forbidd interface gigabitEthernet 1/0/1-3 ip igmp snooping multi-vlan-config 37.12...
  • Page 325 Enable Multicast VLAN 3, and configure Router Port Time as 100 seconds, Member Port Time 100 seconds, and Static Router Port port 1/0/3: T2600G-28TS(config)# ip igmp snooping multi-vlan-config 3 rtime 100 T2600G-28TS(config)# ip igmp snooping multi-vlan-config 3 mtime 100 T2600G-28TS(config)# ip igmp snooping multi-vlan-config 3 rport...
  • Page 326: Ip Igmp Snooping Multi-Vlan-Config (Router-Port-Forbidden)

    Privilege Requirement Only Admin level users have access to these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in multicast VLAN 1 : T2600G-28TS(config)# ip igmp snooping multi-vlan-config 1 router-port-forbidd interface gigabitEthernet 1/0/1-3 ip igmp snooping multi-vlan-config 37.14...
  • Page 327: Ip Igmp Snooping Querier Vlan

    Only Admin level users have access to these commands. Example Replace the source IP address of the IGMP packets in multicast VLAN 1 as 192.168.0.112: T2600G-28TS(config)# ip igmp snooping multi-vlan-config 1 replace-sourceip 192.168.0.112 ip igmp snooping querier vlan 37.15 Description The ip igmp snooping querier vlan command is used to enable the IGMP Snooping Querier function of the VLAN(s).
  • Page 328: Ip Igmp Snooping Querier Vlan (General Query)

    Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP Snooping Querier function of VLAN 1: T2600G-28TS(config)#ip igmp snooping querier vlan 1 ip igmp snooping querier vlan (general query) 37.16 Description The ip igmp snooping querier vlan command is used to configure the parameters for IGMP Snooping Querier to send a general query frame.
  • Page 329: Ip Igmp Snooping Max-Groups

    T2600G-28TS(config)#ip igmp snooping querier vlan 2 query-interval 200 T2600G-28TS(config)#ip igmp snooping querier vlan 2 max-response-time ip igmp snooping max-groups 37.17 Description The ip igmp snooping max-groups command is used to configure the maximum number of groups that a port can join in. The ip igmp snooping...
  • Page 330: Ip Igmp Snooping Authentication

    Example Specify the maximum numbers of groups that ports 1/0/2-5 can join as 10, and configure the throttling action as replace: T2600G-28TS(config)#interface range gigabitEthernet 1/0/2-5 T2600G-28TS(config-if-range)#ip igmp snooping max-groups 10 T2600G-28TS(config-if-range)#ip igmp snooping max-groups action replace ip igmp snooping authentication 37.18...
  • Page 331: Ip Igmp Snooping Accounting

    Only Admin, Operator and Power User level users have access to these commands. Example Enable IGMP accounting globally: T2600G-28TS(config)# ip igmp snooping accounting ip igmp profile 37.20 Description The ip igmp profile command is used to create the configuration profile. To delete the corresponding profile, please use no ip igmp profile command.
  • Page 332: Deny

    Example Create the profile 1: T2600G-28TS(config)# ip igmp profile 1 deny 37.21 Description The deny command is used to configure the filtering mode of profile as deny. Syntax deny Command Mode Profile Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands.
  • Page 333: Range

    T2600G-28TS(config)# ip igmp profile 1 T2600G-28TS(config-igmp-profile)#permit range 37.23 Description The range command is used to configure the range of the profile’s filtering multicast address. To delete the corresponding filtering multicast address, please use no range command. A profile contains 16 filtering IP-range entries at most.
  • Page 334: Clear Ip Igmp Snooping Statistics

    Only Admin, Operator and Power User level users have access to these commands. Example Clear the statistics of the IGMP packets: T2600G-28TS(config)# clear ip igmp snooping statistics show ip igmp snooping 37.26 Description The show ip igmp snooping command is used to display the global configuration of IGMP snooping.
  • Page 335: Show Ip Igmp Snooping Interface

    Privilege Requirement None. Example Display the IGMP baisic configuration configuration of all ports and port channels: T2600G-28TS# show ip igmp snooping interface basic-config Display the IGMP basic configuration of port 1/0/2: T2600G-28TS# show ip igmp snooping interface gigabitEthernet 1/0/2 basic-config...
  • Page 336: Show Ip Igmp Snooping Vlan

    Display the IGMP packet statistics of ports 1/0/1-4: T2600G-28TS# show ip igmp snooping interface gigabitEthernet 1/0/1-4 packet-stat show ip igmp snooping vlan 37.28 Description The show ip igmp snooping vlan command is used to display the VLAN configuration of IGMP snooping.
  • Page 337: Show Ip Igmp Snooping Groups

    T2600G-28TS(config)#show ip igmp snooping groups vlan 5 Display the count of multicast entries in VLAN 5: T2600G-28TS(config)#show ip igmp snooping groups vlan 5 count Display the dynamic multicast groups of VLAN 5 T2600G-28TS(config)#show ip igmp snooping groups vlan 5 dynamic...
  • Page 338: Show Ip Igmp Snooping Querier

    T2600G-28TS(config)#show ip igmp snooping groups vlan 5 static Display the count of dynamic multicast entries of VLAN 5 T2600G-28TS(config)#show ip igmp snooping groups vlan 5 dynamic count Display the count of static multicast entries of VLAN 5 T2600G-28TS(config)#show ip igmp snooping groups vlan 5 static count show ip igmp snooping querier 37.31...
  • Page 339 Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of all profiles: T2600G-28TS(config)# show ip igmp profile...
  • Page 340: Chapter 38 Mld Snooping Commands

    Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable MLD Snooping: T2600G-28TS(config)# ipv6 mld snooping ipv6 mld snooping(interface) 38.2 Description The ipv6 mld snooping command is used to enable MLD Snooping function on the desired port.
  • Page 341: Ipv6 Mld Snooping Rtime

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify MLD Snooping router port aging time as 100 seconds globally: T2600G-28TS(config)# ipv6 mld snooping rtime 100 ipv6 mld snooping mtime 38.4 Description The ipv6 mld snooping mtime command is used to specify member port aging time globally.
  • Page 342: Ipv6 Mld Snooping Report-Suppression

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify MLD Snooping member port aging time as 100 seconds globally: T2600G-28TS(config)# ipv6 mld snooping mtime 100 ipv6 mld snooping report-suppression 38.5 Description The ipv6 mld snooping report-suppression command is used enable the MLD report suppression function.
  • Page 343: Ipv6 Mld Snooping Drop-Unknown

    Only Admin and Operator level users have access to these commands. Example Enable the Fast Leave function for port 1/0/3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# ipv6 mld snooping immediate-leave ipv6 mld snooping drop-unknown 38.7 Description The ipv6 mld snooping drop-unknown command is used to enable the unknown multicast packets filter function.
  • Page 344: Ipv6 Mld Snooping Last-Listener Query-Count

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify the interval of Specific Query Message to 3 seconds: T2600G-28TS(config)# ipv6 mld snooping last-listener query-inteval 3 ipv6 mld snooping last-listener query-count 38.9 Description The ipv6 mld snooping last-listener query-count command is used to specify the numbers of Specific Query Message to be sent.
  • Page 345: Ipv6 Mld Snooping Vlan-Config

    ipv6 mld snooping vlan-config 38.10 Description The ipv6 mld snooping vlan-config command is used to enable VLAN MLD Snooping function or to modify MLD Snooping parameters, and to create static multicast IP entry. To disable the VLAN MLD Snooping function, please use no ipv6 mld snooping vlan-config command.
  • Page 346: Ip Mld Snooping Vlan-Config (Router-Port-Forbidden)

    Member Port Time as 200 seconds for VLAN 1-3, and set the router port as 1/0/1 for VLAN 1-2: T2600G-28TS(config)# ipv6 mld snooping vlan-config 1-3 rtime 300 T2600G-28TS(config)# ipv6 mld snooping vlan-config 1-3 mtime 200 T2600G-28TS(config)# ipv6 mld snooping vlan-config 1-2 rport interface...
  • Page 347: Ipv6 Mld Snooping Multi-Vlan-Config

    Only Admin and Operator level users have access to these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in VLAN 1 : T2600G-28TS(config)# ipv6 mld snooping vlan-config 1 router-port-forbidd interface gigabitEthernet 1/0/1-3 ipv6 mld snooping multi-vlan-config 38.12...
  • Page 348: Ipv6 Mld Snooping Multi-Vlan-Config (Router-Port-Forbidden)

    Enable Multicast VLAN 3, and configure Router Port Time as 100 seconds, Member Port Time 100 seconds, and Static Router Port port 1/0/3: T2600G-28TS(config)# ipv6 mld snooping multi-vlan-config 3 rtime 100 T2600G-28TS(config)# ipv6 mld snooping multi-vlan-config 3 mtime 100 T2600G-28TS(config)# ipv6 mld snooping multi-vlan-config 3 rport...
  • Page 349: Ipv6 Mld Snooping Multi-Vlan-Config (Source-Ip-Replace)

    Privilege Requirement Only Admin level users have access to these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in multicast VLAN 1 : T2600G-28TS(config)# ipv6 mld snooping multi-vlan-config 1 router-port-forbidd interface gigabitEthernet 1/0/1-3 ipv6 mld snooping multi-vlan-config 38.14...
  • Page 350: Ipv6 Mld Snooping Querier Vlan

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable MLD Querier function on VLAN 2: T2600G-28TS(config)# ipv6 mld snooping querier vlan 2 ipv6 mld snooping querier vlan (general query) 38.16 Description The ipv6 mld snooping querier vlan command is used to configure the parameters for MLD Snooping Querier to send a general query frame.
  • Page 351: Ipv6 Mld Snooping Max-Groups

    Only Admin and Operator level users have access to these commands. Example For VLAN 2, specify its query-interval as 200 seconds, and the response-time as 20 seconds: T2600G-28TS(config)#ipv6 mld snooping querier vlan 2 query-interval 200 T2600G-28TS(config)#ipv6 mld snooping querier vlan 2 max-response-time 20 ipv6 mld snooping max-groups 38.17...
  • Page 352: Ipv6 Mld Profile

    Example Specify the maximum numbers of groups that ports 1/0/2-5 can join as 10, and configure the throttling action as replace: T2600G-28TS(config)#interface range gigabitEthernet 1/0/2-5 T2600G-28TS(config-if-range)#ipv6 mld snooping max-groups 10 T2600G-28TS(config-if-range)#ipv6 mld snooping max-groups action replace ipv6 mld profile 38.18 Description The ipv6 mld profile command is used to create the configuration profile.
  • Page 353: Deny

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Create the profile 1: T2600G-28TS(config)# ipv6 mld profile 1 deny 38.19 Description The deny command is used to configure the filtering mode of profile as deny.
  • Page 354: Range

    Example Configure the filtering mode of profile 1 as permit: T2600G-28TS(config)# ipv6 mld profile 1 T2600G-28TS(config-igmp-profile)#permit range 38.21 Description The range command is used to configure the range of the profile’s filtering multicast address. To delete the corresponding filtering multicast address, please use no range command.
  • Page 355: Clear Ipv6 Mld Snooping Statistics

    Only Admin, Operator and Power User level users have access to these commands. Example Clear the statistics of the MLD packets: T2600G-28TS(config)# clear ipv6 mld snooping statistics show ipv6 mld snooping 38.24 Description The show ipv6 mld snooping command is used to display the global configuration of MLD Snooping.
  • Page 356: Show Ipv6 Mld Snooping Interface

    Privilege Requirement None. Example Display the MLD baisic configuration configuration of all ports and port channels: T2600G-28TS# show ipv6 mld snooping interface basic-config Display the MLD basic configuration of port 1/0/2: T2600G-28TS# show ipv6 mld snooping interface gigabitEthernet 1/0/2 basic-config...
  • Page 357: Show Ipv6 Mld Snooping Vlan

    Display the MLD packet statistics of ports 1/0/1-4: T2600G-28TS# show ipv6 mld snooping interface gigabitEthernet 1/0/1-4 packet-stat show ipv6 mld snooping vlan 38.26 Description The show ipv6 mld snooping vlan command is used to display VLAN information of MLD Snooping.
  • Page 358: Show Ipv6 Mld Snooping Groups

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display all of the multicast groups: T2600G-28TS(config)# show ipv6 mld snooping groups show ipv6 mld snooping querier 38.29 Description The show ipv6 mld snooping querier command is used to display the Querier configuration of VLAN.
  • Page 359: Show Ipv6 Mld Profile

    Privilege Requirement None. Example Display all Querier information: T2600G-28TS(config)# show ipv6 mld snooping querier show ipv6 mld profile 38.30 Description The show ipv6 mld profile command is used to display the configuration information of all the profiles or a specific profile.
  • Page 360: Chapter 39 Snmp Commands

    Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the SNMP function: T2600G-28TS(config)# snmp-server snmp-server view 39.2 Description The snmp-server view command is used to add View. To delete the corresponding View, please use no snmp-server view command. The OID...
  • Page 361: Snmp-Server Group

    Only Admin level users have access to these commands. Example Add a View named view1, configuring the OID as 1.3.6.1.6.3.20, and this OID can be managed by the SNMP management station: T2600G-28TS(config)# snmp-server view view1 1.3.6.1.6.3.20 include snmp-server group 39.3 Description The snmp-server group command is used to manage and configure the SNMP group.
  • Page 362 View viewDefault as read-write, besides the notification messages sent by View viewDefault can be received by Management station: T2600G-28TS(config)# snmp-server group group1 smode v3 slev authNoPriv read viewDefault write viewDefault notify viewDefault Delete group 1: T2600G-28TS(config)# no snmp-server group group1 smode v3 slev authNoPriv...
  • Page 363: Snmp-Server User

    snmp-server user 39.4 Description The snmp-server user command is used to add User. To delete the corresponding User, please use no snmp-server user command. The User in an SNMP Group can manage the switch via the management station software. The User and its Group have the same security level and access right. Syntax snmp-server user name { local | remote } group-name [ smode { v1 | v2c | v3 }] [ slev { noAuthNoPriv | authNoPriv | authPriv }] [ cmode { none | MD5 | SHA }]...
  • Page 364: Snmp-Server Community

    MD5, the Authentication Password as 11111, the Privacy Mode as DES, and the Privacy Password as 22222: T2600G-28TS(config)# snmp-server user admin local group2 smode v3 slev authPriv cmode MD5 cpwd 11111 emode DES epwd 22222 snmp-server community 39.5...
  • Page 365: Snmp-Server Host

    Privilege Requirement Only Admin level users have access to these commands. Example Add community public, and the community has read-write management right to View viewDefault: T2600G-28TS(config)# snmp-server community public read-write viewDefault snmp-server host 39.6 Description The snmp-server host command is used to add Notification. To delete the corresponding Notification, please use no snmp-server host command.
  • Page 366 Security Model of the management station as v2c, the type of the notifications as inform, the maximum time for the switch to wait as 1000 seconds, and the retries time as 100: T2600G-28TS(config)# snmp-server host fe80::1234 162 admin smode v2c type inform retries 100 timeout 1000...
  • Page 367: Snmp-Server Engineid

    Privilege Requirement Only Admin level users have access to these commands. Example Specify the local engineID as 1234567890, and the remote engineID as abcdef123456: T2600G-28TS(config)# snmp-server engineID local 1234567890 remote abcdef123456 snmp-server traps snmp 39.8 Description The snmp-server traps snmp command is used to enable SNMP standard...
  • Page 368: Snmp-Server Traps Link-Status

    Privilege Requirement Only Admin level users have access to these commands. Example Enable SNMP standard linkup trap for the switch: T2600G-28TS(config)# snmp-server traps snmp linkup snmp-server traps link-status 39.9 Description The snmp-server traps link-status command is used to enable SNMP link status trap for the specified port.
  • Page 369: Snmp-Server Traps

    Privilege Requirement Only Admin level users have access to these commands. Example Enable SNMP link status trap for port 3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# snmp-server traps link-status snmp-server traps 39.10 Description The snmp-server traps command is used to enable SNMP extended traps. To disable the sending of SNMP extended traps, please use no snmp-server traps command.
  • Page 370: Snmp-Server Traps Vlan

    Privilege Requirement Only Admin level users have access to these commands. Example Enable SNMP extended bandwidth-control trap for the switch: T2600G-28TS(config)# snmp-server traps bandwidth-control snmp-server traps vlan 39.11 Description The snmp-server traps vlan command is used to enable SNMP extended VLAN-related traps which include two types: create and delete.
  • Page 371: Rmon History

    Privilege Requirement Only Admin level users have access to these commands. Example Configure the sample port as Gi1/0/2 and the sample interval as 100 seconds for the entry 1-3: T2600G-28TS(config)# rmon history 1-3 interface gigabitEthernet 1/0/2 interval 100 owner owner1...
  • Page 372: Rmon Event

    Configure the user name of entry 1, 2, 3 and 4 as user1, the description of the event as description1, the type of event as log and the owner of the event as owner1: T2600G-28TS(config)# rmon event 1-4 user user1 description description1 type log owner owner1...
  • Page 373: Rmon Alarm

    rmon alarm 39.14 Description The rmon alarm command is used to configure SNMP-RMON Alarm Management. To return to the default configuration, please use no rmon alarm command. Alarm Group is one of the commonly used RMON Groups. RMON alarm management allows monitoring the specific alarm variables. When the value of a monitored variable exceeds the threshold, an alarm event is generated, which triggers the switch to act in the set way.
  • Page 374: Rmon Statistics

    Only Admin level users have access to these commands. Example Configure rmon alarm entries 1-3 binding with statistics entry 2, the owners as owner1 and the alarm intervals as 100 seconds: T2600G-28TS(config)#rmon alarm 1-3 stats-index 2 owner owner1 interval rmon statistics 39.15 Description The rmon statistics command is used to configure the entries of SNMP-RMON statistics.
  • Page 375: Show Snmp-Server

    Only Admin level users have access to these commands. Example Configure the statistics entries 1-3 with the statistics port as 1/0/1, owner as owner1 and status as valid: T2600G-28TS(config)#rmon statistics 1-3 interface gigabitEthernet 1/0/1 owner owner1 status valid show snmp-server 39.16...
  • Page 376: Show Snmp-Server View

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the View table: T2600G-28TS# show snmp-server view show snmp-server group 39.18 Description The show snmp-server group command is used to display the Group table.
  • Page 377: Show Snmp-Server Community

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the User table: T2600G-28TS# show snmp-server user show snmp-server community 39.20 Description The show snmp-server community command is used to display the Community table.
  • Page 378: Show Snmp-Server Engineid

    Example Display the Host table: T2600G-28TS# show snmp-server host show snmp-server engineID 39.22 Description The show snmp-server engineID command is used to display the engineID of the SNMP. Syntax show snmp-server engineID Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands.
  • Page 379: Show Rmon Event

    Privilege Requirement Only Admin level users have access to these commands. Example Display the Event configuration of entry1-4: T2600G-28TS# show rmon event 1-4 show rmon alarm 39.25 Description The show rmon alarm command is used to display the configuration of the Alarm Management entry.
  • Page 380: Show Rmon Statistics

    Privilege Requirement Only Admin level users have access to these commands. Example Display the configuration of the Alarm Management entry 1-2: T2600G-28TS# show rmon alarm 1-2 show rmon statistics 39.26 Description The show rmon statistics command is used to display the configuration of the specified statistics entry.
  • Page 381: Chapter 40 Lldp Commands

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable LLDP function globally: T2600G-28TS(config)#lldp lldp hold-multiplier 40.2 Description The lldp hold-multiplier command is used to configure the Hold Multiplier parameter. The aging time of the local information in the neighbor device is determined by the actual TTL value used in the sending LLDPDU.
  • Page 382: Lldp Timer

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify Hold Multiplier as 5: T2600G-28TS(config)#lldp hold-multiplier 5 lldp timer 40.3 Description The lldp timer command is used to configure the parameters about transmission. To return to the default configuration, please use no lldp timer command.
  • Page 383: Lldp Receive

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the Transmit Interval of LLDPDU as 45 seconds and Trap message to NMS as 120 seconds: T2600G-28TS(config)#lldp timer tx-interval 45 T2600G-28TS(config)#lldp timer notify-interval 120 lldp receive 40.4 Description The lldp receive command is used to enable the designated port to receive LLDPDU.
  • Page 384: Lldp Transmit

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable Gigabit Ethernet port 1/0/1 to transmit LLDPDU: T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#lldp transmit lldp snmp-trap 40.6 Description The lldp snmp-trap command is used to enable the port’s SNMP notification. If enabled, the port will notify the trap event to network management system.
  • Page 385: Lldp Tlv-Select

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Exclude “management-address” and “port-vlan-id” TLVs in LLDPDU outgoing from Gigabit Ethernet port 1/0/1: T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)# no lldp tlv-select management-address port-vlan...
  • Page 386: Lldp Med-Fast-Count

    Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify Fast Start Count as 5: T2600G-28TS(config)# lldp med-fast-count 5 lldp med-status 40.9 Description The lldp med-status command is used to enable the LLDP-MED feature for the corresponding port.
  • Page 387: Lldp Med-Tlv-Select

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Exclude “network policy” and “inventory” TLVs in LLDPDU outgoing from port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# no lldp med-tlv-select network-policy inventory- management...
  • Page 388: Lldp Med-Location

    lldp med-location 40.11 Description The lldp med-location command is used to configure the Location Identification TLV's content in outgoing LLDPDU of the port. Syntax lldp med-location { emergency-number identifier | civic-address [ [ language language ] [ province-state province-state ] [ county county] [city city ] [ street street ] [ house-number house-number ] [name name ] [ postal-zipcode postal-zipcode ] [ room-number room-number ] [ post-office-box post-office-box ] [ additional additional ] [ country-code country-code ] [ what { dhcp-server |...
  • Page 389: Show Lldp

    [ gigabitEthernet port ] Parameters port —— The Ethernet port number Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the LLDP configuration of Gigabit Ethernet port 1/0/1: T2600G-28TS#show lldp interface gigabitEthernet 1/0/1...
  • Page 390: Show Lldp Local-Information Interface

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the LLDP information of Gigabit Ethernet port 1/0/1: T2600G-28TS#show lldp local-information interface gigabitEthernet 1/0/1 show lldp neighbor-information interface 40.15 Description The show lldp neighbor-information interface command is used to display the neighbor information of the corresponding port.
  • Page 391: Show Lldp Traffic Interface

    [ gigabitEthernet port ] Parameters port —— The Ethernet port number Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the LLDP statistic information of Gigabit Ethernet port 1/0/1: T2600G-28TS#show lldp traffic interface gigabitEthernet 1/0/1...
  • Page 392: Chapter 41 Sflow Commands

    IPv4. For example, you can set the switch’s management IP as the IP address of the sFlow agent. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the sFlow agent with the IP address as 192.168.0.1: T2600G-28TS(config)#sflow address 192.168.0.1...
  • Page 393: Sflow Enable

    A valid agent address should be assigned to the sFlow agent embedded in the switch before you enable the sFlow function. Example Enable sFlow function globally: T2600G-28TS(config)#sflow enable sflow collector collector-ID 41.3 Description The sflow collector collector-ID command is used to configure the parameters about the sFlow collector.
  • Page 394: Sflow Sampler

    Only Admin and Operator level users have access to these commands. Example Specify the ip of the sFlow collector 1 as 192.168.0.100, the port as 3000: T2600G-28TS(config)# sflow collector collector-ID 1 ip 192.168.0.100 T2600G-28TS(config)# sflow collector collector-ID 1 port 3000 sflow sampler 41.4...
  • Page 395: Show Sflow Global

    Only Admin and Operator level users have access to these commands. Example Configure Gigabit Ethernet port 1 as the sFlow sampler: specify the Collector-ID as 1, the ingress rate as 1024: T2600G-28TS(config)#interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#sflow sampler collector-ID 1 T2600G-28TS(config-if)#sflow sampler ingRate 1024 show sflow global 41.5 Description The show sflow global command is used to display the global configuration of sFlow.
  • Page 396: Show Sflow Collector

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of the sFlow collector: T2600G-28TS#show sflow collector show sflow sampler 41.7 Description The show sflow sampler command is used to display the global configuration of the sFlow sampler.
  • Page 397: Chapter 42 Static Routes Commands

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create the VLAN interface 2: T2600G-28TS(config)# interface vlan 2 interface loopback 42.2 Description This interface loopback command is used to create the loopback interface. To delete the specified loopback interface, please use the no interface loopback command.
  • Page 398: Switchport

    Only Admin, Operator and Power User level users have access to these commands. Example Create the loopback interface 1: T2600G-28TS(config)# interface loopback 1 switchport 42.3 Description This switchport command is used to switch the Layer 3 interface into the Layer 2 port.
  • Page 399: Description

    Only Admin, Operator and Power User level users have access to these commands. Example Create the port-channel interfaces 1,3,4 and 5: T2600G-28TS(config)# interface port-channel 1,3-5 description 42.5 Description This description command is used to add a description to the Layer 3 interface, including routed port, port-channel interface, loopback interface and VLAN interface.
  • Page 400: Shutdown

    T2600G-28TS(config)# interface gigabitEthernet 1/0/9 T2600G-28TS(config-if)# no switchport T2600G-28TS(config-if)# description system-if shutdown 42.6 Description This shutdown command is used to shut down the specified interface. The interface type include: routed port, port-channel interface, loopback interface and VLAN interface. To enable the specified interface, please use the no shutdown command.
  • Page 401: Ip Route

    Only Admin, Operator and Power User level users have access to these commands. Example Create the port-channel interface 1: T2600G-28TS(config)# interface port-channel 1 ip route 42.8 Description This ip route command is configure the static route. To clear the corresponding entry, please use the no ip route command.
  • Page 402: Ipv6 Routing

    T2600G-28TS(config)# ip route 192.168.2.0 255.255.255.0 192.168.0.2 ipv6 routing 42.9 Description This ipv6 routing command is enale the IPv6 routing feature globally. To diable IPv6 routing, please use the no ipv6 routing command. Syntax ipv6 routing no ipv6 routing Command Mode...
  • Page 403: Show Interface Vlan

    Example Create a static route with the destination network IP address as 3200::/64 and the next-hop address as 3100::1234: T2600G-28TS(config)# ipv6 route 3200::/64 3100::1234 show interface vlan 42.11 Description The show interface vlan command is used to display the information of the specified interface VLAN.
  • Page 404: Show Ip Interface Brief

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the detailed information of the VLAN interface 2: T2600G-28TS(config)# show ip interface vlan 2 show ip interface brief 42.13 Description This show ip interface brief command is used to display the summary information of the Layer 3 interfaces.
  • Page 405: Show Ip Route

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the static routes: T2600G-28TS(config)# show ip route static show ip route specify 42.15 Description This show ip route specify command is used to display the valid routing information to the specified IP address or network segments.
  • Page 406: Show Ip Route Summary

    T2600G-28TS(config)# show ip route specify 192.168.0.100 Look up the route entry with the destination as 192.168.0.0/24: T2600G-28TS(config)# show ip route specify 192.168.0.0 255.255.255.0 Display the routes to all the subnets that belongs to 192.168.0.0/16: T2600G-28TS(config)# show ip route specify 192.168.0.0 255.255.0.0...
  • Page 407: Show Ipv6 Route

    | connected —— Specify the route type. If not specified, all types of route entries will be displayed. static: The static routes. connected: The connected routes. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the IPv6 static routes: T2600G-28TS(config)# show ipv6 route static...
  • Page 408: Show Ipv6 Route Summary

    IPv6 route entries classified by their sources. Syntax show ipv6 route summary Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the summary information of IPv6 route entries: T2600G-28TS(config)# show ipv6 route summary...
  • Page 409: Chapter 43 Sdm Template Commands

    “enterpriseV4”. enterpriseV6 —— Specify the SDM template used in the switch as “enterpriseV6”. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Specify the SDM template as enterpriseV4: T2600G-28TS(config)# sdm prefer enterpriseV4...
  • Page 410: Show Sdm Prefer

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the resource allocation of the template currently in use, and the template that will become active after a reboot: T2600G-28TS(config)#show sdm prefer used...
  • Page 411: Chapter 44 Aaa Commands

    Chapter 44 AAA Commands AAA stands for authentication, authorization and accounting. This feature is used to authenticate users trying to log in to the switch or trying to access the administrative level privilege. Applicable Access Application  The authentication can be applied on the following access applications: Console, Telnet, SSH and HTTP.
  • Page 412: Tacacas-Server Host

    T2600G-28TS(config)# aaa enable tacacas-server host 44.2 Description The tacacs-server host command is used to configure a new TACACS+ server. To delete the specified TACACS+ server, please use no tacacs-server host command. Syntax tacacs-server host ip-address [ port port-id ] [ timeout time ] [ key { [ 0 ] string |...
  • Page 413: Show Tacacs-Server

    Example Configure a TACACS+ server with the IP address as 1.1.1.1, TCP port as 1500, timeout as 6 seconds, and the unencrypted key string as 12345. T2600G-28TS(config)# tacacs-server host 1.1.1.1 port 1500 timeout 6 key 12345 show tacacs-server 44.3 Description This show ip tacacs-server command is used to display the summary information of the TACACS+ servers.
  • Page 414 Configure a RADIUS server with the IP address as 1.1.1.1, authentication port as 1200, timeout as 6 seconds, retransmit times as 3, and the unencrypted key string as 12345. T2600G-28TS(config)# radius-server host 1.1.1.1 auth-port 1200 timeout 6 retransmit 3 key 12345...
  • Page 415: Show Radius-Server

    Privilege Requirement Only Admin level users have access to these commands. Example Display the information of all the RADIUS servers: T2600G-28TS(config)# show radius-server aaa group 44.6 Description This aaa group command is used to create AAA server groups to group existing TACACS+/RADIUS servers for authentication.
  • Page 416: Server

    Privilege Requirement Only Admin level users have access to these commands. Example Create a RADIUS server group with the name radius1: T2600G-28TS(config)# aaa group radius radius1 server 44.7 Description This server command is used to add the existing server in the defined server group.
  • Page 417: Aaa Authentication Login

    Privilege Requirement Only Admin level users have access to these commands. Example Display the information of all the server groups: T2600G-28TS(config)# show aaa group aaa authentication login 44.9 Description This aaa authentication login command is used to configure a login authentication method list.
  • Page 418: Aaa Authentication Enable

    Example Configure a login authentication method list “list1” with the priority1 method as radius and priority2 method as local: T2600G-28TS(config)# aaa authenticaiton login list1 radius local aaa authentication enable 44.10 Description This aaa authentication enable command is used to configure a privilege authentication method list.
  • Page 419: Aaa Authentication Dot1X Default

    By default the enable authentication method is “default” with “none” as method1. Example Configure a privilege authentication method list “list2” with the priority1 method as radius and priority2 method as local: T2600G-28TS(config)# aaa authenticaiton enable list2 radius local aaa authentication dot1x default 44.11 Description This aaa authentication dot1x default command is used to configure an 802.1X authentication method list.
  • Page 420: Aaa Accounting Dot1X Default

    Privilege Requirement Only Admin level users have access to these commands. Example Configure the default 802.1X accounting method as “radius1”: T2600G-28TS(config)# aaa accounting dot1x default radius1 show aaa authentication 44.13 Description This show aaa authentication command is used to display the summary information of the authentication login, enable and dot1x metheod list.
  • Page 421: Show Aaa Accounting

    Privilege Requirement Only Admin level users have access to these commands. Example Display the information of all the authentication method lists: T2600G-28TS(config)# show aaa authentication show aaa accounting 44.14 Description This show aaa accounting command is used to display the summary information of the accounting metheod list.
  • Page 422: Login Authentication(Console)

    “local”. Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the console port as “list1”: T2600G-28TS(config)# line console 0...
  • Page 423: Enable Authentication(Console)

    T2600G-28TS(config-line)# login authentication list1 enable authentication(console) 44.17 Description The enable authentication command is used to apply the privilege authentication method list to the console port. To restore to the default authentication method list, please use the no enable authentication command.
  • Page 424: Login Authentication(Telnet)

    “default” by default, which contains the method “local”. Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the telnet terminal line as “list1”: T2600G-28TS(config)#line telnet T2600G-28TS(config-line)# login authentication list1...
  • Page 425: Line Ssh

    Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enter the ssh terminal line configuration mode: T2600G-28TS(config)#line ssh login authentication(ssh) 44.21 Description The login authentication command is used to apply the login authentication method list to the ssh terminal line. To restore to the default authentication method list, please use the no login authentication command.
  • Page 426: Enable Authentication(Telnet)

    Example Configure the login authentication method list on the ssh terminal line as “list1”: T2600G-28TS(config)# line ssh T2600G-28TS(config-line)# login authentication list1 enable authentication(telnet) 44.22 Description The enable authentication command is used to apply the privilege authentication method list to the telnet terminal line. To restore to the default authentication method list, please use the no enable authentication command.
  • Page 427: Ip Http Login Authentication

    Only Admin level users have access to these commands. Example Configure the enable authentication method list on the ssh terminal line as “list2”: T2600G-28TS(config)# line ssh T2600G-28TS(config-line)# enable authentication list2 ip http login authentication 44.24 Description The ip http login authentication command is used to apply the login authentication method list to users accessing through HTTP.
  • Page 428: Ip Http Enable Authentication

    Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the HTTP access as “list1”: T2600G-28TS(config)# ip http login authentication list1 ip http enable authentication 44.25 Description The ip http enable authentication command is used to apply the privilege authentication method list to users accessing through HTTP.
  • Page 429 Syntax show aaa global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the AAA function’s global status and each application’s method list: T2600G-28TS(config)# show aaa global...
  • Page 430: Chapter 45 Dhcp Server Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable DHCP server service globally: T2600G-28TS(config)# service dhcp server ip dhcp server extend-option capwap-ac-ip 45.2 Description The ip dhcp server extend-option capwap-ac-ip command is used to configure the IP address of the remote DHCP server.
  • Page 431: Ip Dhcp Server Extend-Option Vendor-Class-Id

    Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Set the class ID of the DHCP packets from another network segment as 34: T2600G-28TS(config)# ip dhcp server extend-option vendor-class-id 34...
  • Page 432: Ip Dhcp Server Exclude-Address

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Set the reserved IP addresses from 192.168.1.1 to 192.168.1.9: T2600G-28TS(config)# ip dhcp server exclude-address 192.168.1.1 192.168.1.9 ip dhcp server pool 45.5 Description The ip dhcp server pool command is used to create the address pool of DHCP Server and enter the dhcp configuration mode.
  • Page 433: Ip Dhcp Server Ping Timeout

    Only Admin, Operator and Power User level users have access to these commands. Example Set the timeout of PING as 200ms: T2600G-28TS(config)# ip dhcp server ping timeout 200 ip dhcp server ping packets 45.7 Description The ip dhcp server ping packets command is used to specify the number of PING packets sent.
  • Page 434: Network

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the PING packets’ number as 2: T2600G-28TS(config)# ip dhcp server ping packets 2 network 45.8 Description The network command is used to specify the address and subnet of the network pool.
  • Page 435: Lease

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the lease time of address pool “product” as 10 minutes: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# lease 10 address hardware-address 45.10 Description The address hardware-address command is used to reserve the static address bound with hardware address in the address pool.
  • Page 436: Address Client-Identifier

    Example Reserve the IP address 192.168.0.10 in the address pool “product” for the device with the MAC address as 5e:4c:a6:31:24:01 and the hardware type as ethernet: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# address 192.168.0.10 hardware-address 5e:4c:a6:31:24:01 hardware-type ethernet address client-identifier 45.11...
  • Page 437: Default-Gateway

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the address pool product’s default gateways as 192.168.0.1 and 192.168.1.1: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(dhcp-config)# default-gateway 192.168.0.1,192.168.1.1 dns-server 45.13 Description The dns-server command is used to specify the DNS server of the address pool.
  • Page 438: Netbios-Name-Server

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the address pool’s DNS servers as 192.168.0.1 and 192.168.1.1: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# dns-server 192.168.0.1,192.168.1.1 netbios-name-server 45.14 Description The netbios-name-server command is used to specify the Netbios server’s IP address.
  • Page 439: Next-Server

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the address pool’s Netbios server type as b-node: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# netbios-node-type b-node next-server 45.16 Description The next-server command is used to specify the next DHCP server’s address during the DHCP boot process.
  • Page 440: Domain-Name

    Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the DHCP client’s domain name as edu: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# domain-name edu bootfile 45.18 Description The bootfilecommand is used to specify the name of the DHCP client’s bootfile.
  • Page 441: Show Ip Dhcp Server Status

    Example Specify the name of the DHCP client’s bootfile as boot1: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# bootfile boot1 show ip dhcp server status 45.19 Description The show ip dhcp server status command is used to display the status of the DHCP service.
  • Page 442: Show Ip Dhcp Server Extend-Option

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configurations of the remote DCHP servers: T2600G-28TS(config)# show ip dhcp server extend-option show ip dhcp server pool 45.22 Description The show ip dhcp server pool command is used to display the configuration of the address pool.
  • Page 443: Show Ip Dhcp Server Manual-Binding

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configured reserved addresses: T2600G-28TS(config)# show ip dhcp server excluded-address show ip dhcp server manual-binding 45.24 Description The show ip dhcp server manual-binding command is used to display the configuration of static binding address.
  • Page 444: Clear Ip Dhcp Server Statistics

    Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the address binding entries: T2600G-28TS(config)# show ip dhcp server binding clear ip dhcp server statistics 45.26 Description The clear ip dhcp server statistics command is used to clear the statistics information of DHCP packets.
  • Page 445 Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear all the binding addresses: T2600G-28TS(config)# clear ip dhcp server binding...
  • Page 446: Chapter 46 Dhcp Relay Commands

    Only Admin, Operator and Power User level users have access to these commands. Example Enable DHCP Relay function globally: T2600G-28TS(config)# service dhcp relay ip helper-address 46.2 Description The ip helper-address command is used to add DHCP Server address to the Layer 3 interface.
  • Page 447: Ip Dhcp Relay Information

    Only Admin, Operator and Power User level users have access to these commands. Example Enable option 82 support in DHCP Relay: T2600G-28TS(config)# ip dhcp relay information ip dhcp relay information policy 46.4 Description The ip dhcp relay information policy command is used to specify the operation for the Option 82 field of the DHCP request packets from the Host.
  • Page 448: Ip Dhcp Relay Information Custom

    Example Specify the option 82 policy as replace to replace the Option 82 field with the local parameter on receiving the DHCP request packet: T2600G-28TS(config)# ip dhcp relay information policy replace ip dhcp relay information custom 46.5 Description The ip dhcp relay information custom command is used to enable the switch to customize the option 82 field.
  • Page 449: Ip Dhcp Relay Information Circuit-Id

    Only Admin, Operator and Power User level users have access to these commands. Example Specify the circuit ID as “TP-LINK”: T2600G-28TS(config)# ip dhcp relay information circuit-id TP-LINK ip dhcp relay information remote-id 46.7 Description The ip dhcp relay information remote-id command is used to specify the custom remote ID when option 82 customization is enabled.
  • Page 450: Show Ip Dhcp Relay

    Example Specify the remote ID as “TP-LINK”: T2600G-28TS(config)# ip dhcp relay information remote-id TP-LINK show ip dhcp relay 46.8 Description The show ip dhcp relay command is used to display the global status and Option 82 configuration of DHCP Relay.

This manual is also suitable for:

T2600g-52ts

Table of Contents