TP-Link JetStream TL-SL5428E Cli Reference Manual

24-port 10/100mbps + 4-port gigabit jetstream l2 managed switch
Hide thumbs Also See for JetStream TL-SL5428E:
Table of Contents

Advertisement

TL-SL5428E
24-Port 10/100Mbps + 4-Port Gigabit
JetStream L2 Managed Switch
REV1.3.0
1910010726

Advertisement

Table of Contents
loading

Summary of Contents for TP-Link JetStream TL-SL5428E

  • Page 1 TL-SL5428E 24-Port 10/100Mbps + 4-Port Gigabit JetStream L2 Managed Switch REV1.3.0 1910010726...
  • Page 2 Specifications are subject to change without notice. is a registered trademark of TP-LINK TECHNOLOGIES CO., LTD. Other brands and product names are trademarks or registered trademarks of their respective holders. No part of the specifications may be reproduced in any form or by any means or used to make any derivative such as translation, transformation, or adaptation without permission from TP-LINK TECHNOLOGIES CO., LTD.
  • Page 3: Table Of Contents

    CONTENTS Preface ......................1 Chapter 1 Using the CLI ..................4 1.1 Accessing the CLI ......................4 1.1.1 Logon by a console port ..................4 1.1.2 Logon by Telnet ....................6 1.2 CLI Command Modes ....................10 1.3 Security Levels ......................13 1.4 Conventions ........................13 1.4.1 Format Conventions ...................13 1.4.2 Special Characters....................13 1.4.3 Parameter Format....................14...
  • Page 4 show mac-vlan ........................26 show mac-vlan interface......................27 Chapter 5 Protocol-based VLAN Commands ........... 28 protocol-vlan template ......................28 protocol-vlan vlan ........................29 protocol-vlan..........................29 show protocol-vlan template....................30 show protocol-vlan vlan ......................30 show protocol-vlan interface....................31 Chapter 6 VLAN-VPN Commands..............32 dot1q-tunnel ..........................32 dot1q-tunnel tpid........................32 dot1q-tunnel mapping......................33 switchport dot1q-tunnel mapping...................34 switchport dot1q-tunnel mode uplink ..................34 show dot1q-tunnel .........................35...
  • Page 5 switchport private-vlan mapping ....................46 show vlan private-vlan ......................46 Chapter 9 GVRP Commands................48 gvrp ............................48 gvrp (interface) ........................48 gvrp registration........................49 gvrp timer ..........................49 show gvrp global ........................50 show gvrp interface .......................51 Chapter 10 Etherchannel Commands ..............52 channel-group ........................52 port-channel load-balance .....................53 lacp system-priority .......................53 lacp port-priority........................54 show etherchannel ........................54...
  • Page 6 ip dhcp snooping information option ..................68 ip dhcp snooping information strategy ...................68 ip dhcp snooping information remote-id.................69 ip dhcp snooping information circuit-id ..................69 ip dhcp snooping trust ......................70 ip dhcp snooping mac-verify....................71 ip dhcp snooping limit rate.....................71 ip dhcp snooping decline .......................72 show ip source binding ......................72 show ip dhcp snooping ......................73 show ip dhcp snooping information ..................73...
  • Page 7 dot1x auth-method ........................87 dot1x guest-vlan(global) ......................88 dot1x quiet-period........................89 dot1x timeout.........................89 dot1x max-reauth-req ......................90 dot1x............................90 dot1x guest-vlan(interface) ....................91 dot1x port-control ........................91 dot1x port-method .........................92 radius.............................93 radius server-account ......................94 show dot1x global........................94 show dot1x interface ......................95 show radius accounting ......................95 show radius authentication ....................96 Chapter 17 System Log Commands..............
  • Page 8 Chapter 20 MAC Address Commands..............109 mac address-table static......................109 mac address-table aging-time ..................... 110 mac address-table filtering ....................110 mac address-table max-mac-count ..................111 show mac address-table address ..................112 show mac address-table aging-time ..................112 show mac address-table max-mac-count interface ............. 113 show mac address-table interface ..................
  • Page 9 interface fastEthernet ......................130 interface range fastEthernet ....................130 interface gigabitEthernet......................131 interface range gigabitEthernet ...................131 description ...........................132 shutdown ..........................133 flow-control ..........................133 duplex..........................134 speed...........................134 storm-control broadcast.......................135 storm-control multicast ......................135 storm-control unicast ......................136 bandwidth ..........................137 clear counters........................137 show interface status......................138 show interface counters.......................138 show interface description ....................139 show interface flowcontrol ....................139 show interface configuration....................140 show storm-control ......................140...
  • Page 10 show monitor session ......................151 Chapter 25 Port isolation Commands ..............152 port isolation ........................152 show port isolation.......................153 Chapter 26 Loopback Detection Commands.............154 loopback-detection(global) ....................154 loopback-detection interval....................154 loopback-detection recovery-time..................155 loopback-detection(interface) ....................155 loopback-detection config....................156 loopback-detection recover ....................156 show loopback-detection global ..................157 show loopback-detection interface ..................157 Chapter 27 ACL Commands................159 time-range ...........................159 absolute..........................159...
  • Page 11 show access-list policy ......................173 show access-list bind ......................173 Chapter 28 MSTP Commands ................174 spanning-tree(global)......................174 spanning-tree(interface) ......................174 spanning-tree common-config .....................175 spanning-tree mode......................176 spanning-tree mst configuration ..................176 instantce ..........................177 name ...........................178 revision ..........................178 spanning-tree mst instance ....................179 spanning-tree mst........................179 spanning-tree priority......................180 spanning-tree tc-defend.......................181 spanning-tree timer......................181 spanning-tree hold-count.....................182 spanning-tree max-hops ......................183...
  • Page 12 ip igmp snooping filter add-id....................194 ip igmp snooping filter(global)....................195 ip igmp snooping filter(interface) ..................195 ip igmp snooping filter maxgroup..................196 ip igmp snooping filter mode....................196 show ip igmp snooping ......................197 show ip igmp snooping interface ..................197 show ip igmp snooping vlan ....................198 show ip igmp snooping multi-vlan..................198 show ip igmp snooping groups ....................199 show ip igmp snooping filter ....................199...
  • Page 13 lldp receive ..........................218 lldp transmit .........................218 lldp snmp-trap........................219 lldp tlv-select........................219 show lldp ..........................220 show lldp interface.......................221 show lldp local-information interface..................221 show lldp neighbor-information interface ................222 show lldp traffic interface .....................222 Chapter 32 Cluster Commands................224 cluster ndp...........................224 cluster ntdp ..........................225 cluster explore ........................226 cluster..........................226 cluster ip pool ........................227 cluster commander ......................227...
  • Page 14: Preface

    JetStream L2 Managed Switch CLI Guide Preface This Guide is intended for network administrator to provide referenced information about CLI (Command Line Interface). The device mentioned in this Guide stands for TL-SL5428E JetStream L2 Managed Switch. Overview of this Guide...
  • Page 15 TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 12: Binding Table Commands Provide information about the commands used for binding the IP address, MAC address, VLAN and the connected Port number of the Host together. Besides it also provide information about the...
  • Page 16 TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 23: QoS Commands Provide information about the commands used for configuring the QoS function. Chapter 24: Port Mirror Commands Provide information about the commands used for configuring the Port Mirror function. Chapter 25: Port isolation Commands Provide information about the commands used for configuring the Port isolation function.
  • Page 17: Chapter 1 Using The Cli

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 1 Using the CLI 1.1 Accessing the CLI You can log on to the switch and access the CLI by the following two methods: Log on to the switch by the console port on the switch.
  • Page 18 TL-SL5428E JetStream L2 Managed Switch CLI Guide Figure 1-2 Connection Description Select the port to connect in Figure 1-3, and click OK. Figure 1-3 Select the port to connect Configure the port selected in the step above as the following Figure 1-4 shown. Configure Bits per second as 38400, Data bits as 8, Parity as None, Stop bits as 1, Flow control as None, and then click OK.
  • Page 19: 1.1.2 Logon By Telnet

    TL-SL5428E JetStream L2 Managed Switch CLI Guide The DOS prompt” TL-SL5428E>” will appear after pressing the Enter button as Figure 1-5 shown. It indicates that you can use the CLI now. Figure 1-5 Log in the Switch 1.1.2 Logon by Telnet...
  • Page 20 TL-SL5428E JetStream L2 Managed Switch CLI Guide Figure 1-6 Configure login local mode Now, you can logon by Telnet in login local mode. Make sure the switch and the PC are in the same LAN. Click Start → Run to open the Run window and type cmd in the prompt Run window as Figure 1-7 and click OK.
  • Page 21 TL-SL5428E JetStream L2 Managed Switch CLI Guide Type the default user name and password admin/admin, then press the Enter button so as to enter User EXEC Mode. Figure 1-9 Enter into the User EXEC Mode Now you can manage your switch with CLI commands through Telnet connection.
  • Page 22 TL-SL5428E JetStream L2 Managed Switch CLI Guide Figure 1-11 Configure login mode Now, you can logon by Telnet in login mode: Open Telnet, then type telnet 192.168.0.1 in the command prompt shown as Figure 1-12, and press the Enter button.
  • Page 23: 1.2 Cli Command Modes

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Figure 1-13 Enter into the User EXEC Mode When entering enable command to access Privileged EXEC Mode, you are required to give the password 123 you have set through Console port connection. Figure 1-14 Enter into the Privileged EXEC Mode Now you can manage your switch with CLI commands through Telnet connection.
  • Page 24 Console port). enable Privileged command to enter this Enter the disable command to return to TL-SL5428E # EXEC Mode mode from User EXEC User EXEC mode. mode. Enter configure command to access Global Configuration mode.
  • Page 25 TL-SL5428E JetStream L2 Managed Switch CLI Guide interface Use the end command or press Ctrl+Z to fastEthernet/gigabitEth return to Privileged EXEC mode. TL-SL5428E(config-if)# ernet port or interface Interface Enter exit or # command to return to range fastEthernet/ Configuration Global Configuration mode.
  • Page 26: 1.3 Security Levels

    TL-SL5428E JetStream L2 Managed Switch CLI Guide history: Displays the commands history.  1.3 Security Levels This switch’s security is divided into two levels: User level and Admin level. User level only allows users to do some simple operations in User EXEC Mode; Admin level allows you to monitor, configure and manage the switch in Privileged EXEC Mode, Global Configuration Mode, Interface Configuration Mode and VLAN Configuration Mode.
  • Page 27: 1.4.3 Parameter Format

    TL-SL5428E JetStream L2 Managed Switch CLI Guide If a blank is contained in a character string, single or double quotation marks should be used,  for example ’hello world’, ”hello world”, and the words in the quotation marks will be identified as a string.
  • Page 28: Chapter 2 User Interface

    —— super password , which contains 16 characters at most, composing digits, English letters and underdashes only. By default, it is empty. Command Mode Global Configuration Mode Example Set the super password as “admin” to access Privileged EXEC Mode from User EXEC Mode: TL-SL5428E(config)#enable password admin...
  • Page 29: Disable

    TL-SL5428E JetStream L2 Managed Switch CLI Guide disable Description The disable command is used to return to User EXEC Mode from Privileged EXEC Mode. Syntax disable Command Mode Privileged EXEC Mode Example Return to User EXEC Mode from Privileged EXEC Mode: TL-SL5428E#disable TL-SL5428E>...
  • Page 30: End

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Syntax exit Command Mode Any Configuration Mode Example Return to Global Configuration Mode from Interface Configuration Mode, and then return to Privileged EXEC Mode: TL-SL5428E(config-if)#exit TL-SL5428E(config)#exit TL-SL5428E# Description The end command is used to return to Privileged EXEC Mode.
  • Page 31: Chapter 3 Ieee 802.1Q Vlan Commands

    —— VLAN ID list, ranging from 2 to 4094, in the format of 2-3, 5. It is multi-optional. Command Mode Global Configuration Mode Example Create VLAN 2-10 and VLAN 100: TL-SL5428E(config)#vlan 2-10,100 Delete VLAN 2: TL-SL5428E(config)#no vlan 2 interface vlan Description The interface vlan command is used to create VLAN Interface hereafter to...
  • Page 32: Name

    —— Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. Command Mode Global Configuration Mode Example Create VLAN Interface 2: TL-SL5428E(config)#interface vlan 2 name Description The name command is used to assign a description string to a VLAN. To clear the description, please use no name command.
  • Page 33: Switchport Mode

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Specify the Link Type of Fast Ethernet port 3 as “trunk”: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#switchport mode trunk switchport access vlan Description The switchport access vlan command is used to add the desired Access port to IEEE 802.1Q VLAN, or to remove a port from the corresponding VLAN.
  • Page 34: Switchport Trunk Allowed Vlan

    Configure Fast Ethernet port 2 whose link type is “trunk” to VLAN 2: TL-SL5428E(config)#interface fastEthernet 1/0/2 TL-SL5428E(config-if)#switchport mode trunk TL-SL5428E(config-if)#switchport trunk allowed vlan 2 switchport general allowed vlan Description The switchport general allowed vlan command is used to add the desired...
  • Page 35: Switchport Pvid

    Configure Fast Ethernet port 4 whose link type is “general” to VLAN 2 and its egress-rule as “tagged”: TL-SL5428E(config)#interface fastEthernet 1/0/4 TL-SL5428E(config-if)#switchport mode general TL-SL5428E(config-if)#switchport general allowed vlan 2 tagged switchport pvid Description The switchport pvid command is used to configure the PVID for the switch ports.
  • Page 36: Show Vlan Summary

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Example Specify the PVID of Fast Ethernet port 3 as 1: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#switchport pvid 1 show vlan summary Description The show vlan summary command is used to display the summarized information of IEEE 802.1Q VLAN.
  • Page 37: Show Vlan

    Syntax show vlan [id vlan-id] Parameter vlan-id —— Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the detailed information of VLAN 2-10: TL-SL5428E(config)#show vlan id 2-10...
  • Page 38: Chapter 4 Mac-Based Vlan Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 4 MAC-based VLAN Commands MAC VLAN (Virtual Local Area Network) is the way to classify the VLANs based on MAC Address. A MAC address is relative to a single VLAN ID. The untagged packets and the priority-tagged packets coming from the MAC address will be tagged with this VLAN ID.
  • Page 39: Show Mac-Vlan

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the Fast Ethernet port 3 for the MAC-based VLAN feature: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#mac-vlan show mac-vlan Description The show mac-vlan command is used to display the information of the MAC-based VLAN entry.
  • Page 40: Show Mac-Vlan Interface

    The show mac-vlan interface command is used to display the port state of MAC-based VLAN. Syntax show mac-vlan interface Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the enable state of all the ports: TL-SL5428E(config)#show mac-vlan interface...
  • Page 41: Chapter 5 Protocol-Based Vlan Commands

    —— The number of the Protocol-based VLAN Template. You can get the template corresponding to the number by the show protocol-vlan template command. Command Mode Global Configuration Mode Example Create a Protocol-based VLAN template named “TP” whose Ethernet protocol type is 0x2024: TL-SL5428E(config)#protocol-vlan template name TP ether-type 2024...
  • Page 42: Protocol-Vlan Vlan

    Command Mode Global Configuration Mode Example Create Protocol-based VLAN 2 and bind it with Protocol-based VLAN Template 3: TL-SL5428E(config)#protocol-vlan vlan 2 template 3 protocol-vlan Description The protocol-vlan command is used to enable the Protocol-based VLAN feature for a specified port. To disable the Protocol-based VLAN feature of this port, please use no protocol-vlan command.
  • Page 43: Show Protocol-Vlan Template

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the Protocol-based VLAN feature for the Gigabit Ethernet port 25: TL-SL5428E(config)#interface gigabitEthernet 1/0/25 TL-SL5428E(config-if)#protocol-vlan show protocol-vlan template Description The show protocol-vlan template command is used to display the information of the Protocol-based VLAN templates.
  • Page 44: Show Protocol-Vlan Interface

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display information of the Protocol-based VLAN entry: TL-SL5428E(config)#show protocol-vlan vlan show protocol-vlan interface Description The show protocol-vlan interface command is used to display port state and of Protocol-based VLAN interface.
  • Page 45: Chapter 6 Vlan-Vpn Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 6 VLAN-VPN Commands VLAN-VPN (Virtual Private Network) function, the implement of a simple and flexible Layer 2 VPN technology, allows the packets with VLAN tags of private networks to be encapsulated with VLAN tags of public networks at the network access terminal of the Internet Service Provider.
  • Page 46: Dot1Q-Tunnel Mapping

    —— Give a description to the VLAN Mapping entry, which contains 15 characters at most. Command Mode Global Configuration Mode Example Add a VLAN Mapping entry named “TP” with the C-VLAN being 2 and the SP-VLAN being 10: TL-SL5428E(config)#dot1q-tunnel mapping 2 10 TP...
  • Page 47: Switchport Dot1Q-Tunnel Mapping

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the VLAN Mapping feature for the Fast Ethernet port 3: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#switchport dot1q-tunnel mapping switchport dot1q-tunnel mode uplink Description The switchport dot1q-tunnel mode uplink command is used to configure a specified port as the VPN Up-link port.
  • Page 48: Show Dot1Q-Tunnel

    JetStream L2 Managed Switch CLI Guide Example Configure the Fast Ethernet port 3 as the VPN Up-link ports: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#switchport dot1q-tunnel mode uplink show dot1q-tunnel Description The show dot1q-tunnel command is used to display the global configuration information of the VLAN VPN.
  • Page 49: Show Dot1Q-Tunnel Mapping Interface

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the enable state of all VLAN Mapping ports: TL-SL5428E(config)#show dot1q-tunnel mapping interface show dot1q-tunnel uplink Description The show dot1q-tunnel uplink command is used to display the configuration information of the VLAN VPN Up-link ports.
  • Page 50: Chapter 7 Voice Vlan Commands

    Command Mode Global Configuration Mode Example Enable the Voice VLAN function for VLAN 10: TL-SL5428E(config)#voice vlan 10 voice vlan aging time Description The voice vlan aging time command is used to set the aging time for a voice VLAN. To restore to the default aging time for the Voice VLAN, please use no voice vlan aging time command.
  • Page 51: Voice Vlan Priority

    Command Mode Global Configuration Mode Example Set the aging time for the Voice VLAN as 1 minute: TL-SL5428E(config)#voice vlan aging time 1 voice vlan priority Description The voice vlan priority command is used to configure the priority for the Voice VLAN.
  • Page 52: Switchport Voice Vlan Mode

    TL-SL5428E JetStream L2 Managed Switch CLI Guide The voice vlan mac-address command is used to create Voice VLAN OUI. To delete the specified Voice VLAN OUI, please use no voice vlan mac-address command. Syntax voice vlan mac-address mac-addr mask mask [description descript]...
  • Page 53: Switchport Voice Vlan Security

    Example Configure the Fast Ethernet port 3 to operate in the auto voice VLAN mode: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#switchport voice vlan mode auto switchport voice vlan security Description The switchport voice vlan security command is used to enable the Voice VLAN security feature.
  • Page 54: Show Voice Vlan Oui

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the configuration information of Voice VLAN OUI: TL-SL5428E(config)#show voice vlan oui show voice vlan switchport Description The show voice vlan switchport command is used to display the configuration information of all the ports or one specified port in the Voice VLAN.
  • Page 55 Privileged EXEC Mode and Any Configuration Mode Example Display the configuration information of Fast Ethernet port 1 in the Voice VLAN: TL-SL5428E(config)#show voice vlan switchport fastEthernet 1/0/1 Display the configuration information of all the ports in the Voice VLAN: TL-SL5428E(config)#show voice vlan switchport...
  • Page 56: Chapter 8 Private Vlan Commands

    Command Mode VLAN Configuration Mode (VLAN) Example Configure the VLAN 3 as the primary VLAN of the private VLAN: TL-SL5428E(config)#vlan 3 TL-SL5428E(config-vlan)#private-vlan primary private-vlan community Description The private-vlan community command is used to configure the designated VLAN as the community VLAN of the Private VLAN. To invalid the currently community VLAN, please use no private-vlan community command.
  • Page 57: Private-Vlan Association

    VLAN Configuration Mode (VLAN) Example Associate primary VLAN 3 with community VLAN 4 as a private VLAN: TL-SL5428E(config)#vlan 3 TL-SL5428E(config-vlan)#private-vlan association 4 switchport private-vlan Description The switchport private-vlan command is used to configure the private VLAN mode for the switchport. To invalid the configuration, please use no switchport...
  • Page 58: Switchport Private-Vlan Host-Association

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure Fast Ethernet port 3 as “host”: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#switchport private-vlan host switchport private-vlan host-association Description The switchport private-vlan host-association command is used to add host type port to private VLAN.
  • Page 59: Switchport Private-Vlan Mapping

    Configure host type Fast Ethernet port 3 as a member of primary VLAN 3 and secondary VLAN 4: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#switchport private-vlan host-association 3 4 switchport private-vlan mapping Description The switchport private-vlan mapping command is used to add promiscuous type port to private VLAN.
  • Page 60 TL-SL5428E JetStream L2 Managed Switch CLI Guide Syntax show vlan private-vlan Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the configuration information of all Private VLAN: TL-SL5428E(config)#show vlan private-vlan...
  • Page 61: Chapter 9 Gvrp Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 9 GVRP Commands GVRP (GARP VLAN registration protocol) is an implementation of GARP (generic attribute registration protocol). GVRP allows the switch to automatically add or remove the VLANs via the dynamic VLAN registration information and propagate the local VLAN registration information to other switches, without having to individually configure each VLAN.
  • Page 62: Gvrp Registration

    JetStream L2 Managed Switch CLI Guide fastEthernet / interface gigabitEthernet / interface range gigabitEhternet) Example Enable the GVRP function for Fast Ethernet ports 2-6: TL-SL5428E(config)#interface range fastEthernet 1/0/2-6 TL-SL5428E(config-if-range)#gvrp gvrp registration Description The gvrp registration command is used to configure the GVRP registration type for the desired port.
  • Page 63: Show Gvrp Global

    Example Set the GARP leaveall timer of Fast Ethernet port 6 as 2000 centiseconds and restore the join timer of it to the default value: TL-SL5428E(config)#interface fastEthernet 1/0/6 TL-SL5428E(config-if)#gvrp timer leaveall 2000 TL-SL5428E(config-if)#no gvrp timer join show gvrp global Description...
  • Page 64: Show Gvrp Interface

    Ethernet ports is displayed. Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the GVRP configuration information of Fast Ethernet port 1: TL-SL5428E(config)#show gvrp interface fastEthernet 1/0/1 Display the GVRP configuration information of all Ethernet ports: TL-SL5428E(config)#show gvrp interface...
  • Page 65: Chapter 10 Etherchannel Commands

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEhternet) Example Add the Fast Ethernet port 2-4 to EtherChannel Group 1 and enable the static LAG: TL-SL5428E(config)#interface range fastEthernet 1/0/2-4 TL-SL5428E(config-if-range)#channel-group 1 mode on...
  • Page 66: Port-Channel Load-Balance

    Command Mode Global Configuration Mode Example Configure the Aggregate Arithmetic for LAG as “src-dst-mac”: TL-SL5428E(config)#port-channel load-balance src-dst-mac lacp system-priority Description The lacp system-priority command is used to configure the LACP system priority globally. To return to the default configurations, please use no lacp system-priority command.
  • Page 67: Lacp Port-Priority

    Command Mode Global Configuration Mode Example Configure the LACP system priority as 1024 globally: TL-SL5428E(config)#lacp system-priority 1024 lacp port-priority Description The lacp port-priority command is used to configure the LACP system priority globally. To return to the default configurations, please use no lacp port-priority command.
  • Page 68: Show Etherchannel Load-Balance

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the detailed information of EtherChannel Group 1: TL-SL5428E(config)#show etherchannel 1 detail show etherchannel load-balance Description The show etherchannel load-balance command is used to display the Aggregate Arithmetic of LAG.
  • Page 69: Show Lacp Sys-Id

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the internal LACP information of EtherChannel Group 1: TL-SL5428E(config)#show lacp 1 internal show lacp sys-id Description The show lacp sys-id command is used to display the LACP system priority globally.
  • Page 70: Chapter 11 User Manage Commands

    | enable ——Enable/disable the user. The new added user is “enable” by default. Command Mode Global Configuration Mode Example Add and enable a new admin user named “tplink”, of which the password is “password”: TL-SL5428E(config)#user tplink password password type admin status enable...
  • Page 71: User Access-Control Ip-Based

    Global Configuration Mode Example Configure that only the user with the IP address 192.168.0.148 is allowed to login: TL-SL5428E(config)#user access-control ip-based 192.168.0.148 255.255.255.255 user access-control mac-based Description The user access-control mac-based command is used to limit the MAC Address of the users for login. Only the user with this MAC Address you set here is allowed to login.
  • Page 72: User Access-Control Port-Based

    ——The list group of Ethernet ports. You can appoint 5 ports at most. Command Mode Global Configuration Mode Example Configure that only the users connected to Fast Ethernet ports 2-6 are allowed to login: TL-SL5428E(config)#user access-control port-based interface range fastEthernet 1/0/2-6...
  • Page 73: User Max-Number

    Command Mode Global Configuration Mode Example Configure the maximum number of users’ login as Admin and Guest as 5 and 3: TL-SL5428E(config)#user max-num 5 3 user idle-timeout Description The user idle-timeout command is used to configure the timeout time of the switch.
  • Page 74: Line

    Enter the Console port configuration mode and configure the console port 0: TL-SL5428E(config)#line console 0 Enter the Virtual Terminal configuration mode so as to prepare further configurations such as password and login mode for virtual terminal 0 to 5: TL-SL5428E(config)#line vty 0 5...
  • Page 75: Password

    Configure the connection password of Console port connection 0 as “tplink”: TL-SL5428E(config)#line console 0 TL-SL5428E(config-line)#password tplink Configure the connection password of virtual terminal connection 0-5 as “tplink”: TL-SL5428E(config)#line vty 0 5 TL-SL5428E(config-line)#password tplink login Description The login command is used to configure the login of a switch not to use the default user name and password.
  • Page 76: Login Local

    Configure the login of Console port connection 0 as login mode: TL-SL5428E(config)#line console 0 TL-SL5428E(config-line)#login Configure the login of virtual terminal connection 0-5 as login mode: TL-SL5428E(config)#line vty 0 5 TL-SL5428E(config-line)#login login local Description The login local command is used to configure the login of a switch with the default user name and password “admin/admin”.
  • Page 77: Show User Configuration

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the information of the current users: TL-SL5428E(config)#show user account-list show user configuration Description The user configuration command is used to display the security configuration information of the users, including access-control, max-number and the idle-timeout, etc.
  • Page 78: Chapter 12 Binding Table Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 12 Binding Table Commands You can bind the IP address, MAC address, VLAN and the connected Port number of the Host together, which can be the condition for the ARP Inspection and IP verify source to filter the packets.
  • Page 79: Ip Dhcp Snooping

    Port number 5 manually. And then enable the entry for the ARP detection and IP filter function: TL-SL5428E(config)#ip source binding host1 192.168.0.1 00:00:00:00:00:01 vlan 2 interface fastEthernet 1/0/5 both Delete the IP-MAC –VID-PORT entry with the index 5:...
  • Page 80: Ip Dhcp Snooping Global

    5/10/15/20/25/30 (packet/second). By default, it is 5. Command Mode Global Configuration Mode Example Configure the Global Flow Control as 30pps, the Decline Threshold as 20 pps, and decline Flow Control as 20 pps for DHCP Snooping: TL-SL5428E(config)#ip dhcp snooping global global-rate 30 dec-threshold 20 dec-rate 20...
  • Page 81: Ip Dhcp Snooping Information Option

    Command Mode Global Configuration Mode Example Enable the Option 82 function of DHCP Snooping: TL-SL5428E(config)#ip dhcp snooping information option ip dhcp snooping information strategy Description The ip dhcp snooping information strategy command is used to select the operation for the Option 82 field of the DHCP request packets from the Host. To restore to the default option, please use no ip dhcp snooping information strategy command.
  • Page 82: Ip Dhcp Snooping Information Remote-Id

    Example Replace the Option 82 field of the packets with the switch defined one and then send out: TL-SL5428E(config)#ip dhcp snooping information strategy replace ip dhcp snooping information remote-id Description The ip dhcp snooping information remote-id command is used to enable and configure the customized sub-option Remote ID for the Option 82.
  • Page 83: Ip Dhcp Snooping Trust

    Example Enable and configure the customized sub-option Circuit ID for the Option 82 as “tplink”: TL-SL5428E(config)#ip dhcp snooping information circuit-id tplink ip dhcp snooping trust Description The ip dhcp snooping trust command is used to configure a port to be a Trusted Port.
  • Page 84: Ip Dhcp Snooping Mac-Verify

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config-if)#ip dhcp snooping trust ip dhcp snooping mac-verify Description The ip dhcp snooping mac-verify command is used to enable the MAC Verify feature. To disable the MAC Verify feature, please use no ip dhcp snooping mac-verify command.
  • Page 85: Ip Dhcp Snooping Decline

    Example Set the Flow Control of Fast Ethernet port 2 as 20 pps: TL-SL5428E(config)#interface fastEthernet 1/0/2 TL-SL5428E(config-if)#ip dhcp snooping limit rate 20 ip dhcp snooping decline Description The ip dhcp snooping decline command is used to enable the Decline Protect feature.
  • Page 86: Show Ip Dhcp Snooping

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the IP-MAC-VID-PORT binding table: TL-SL5428E(config)#show ip source binding show ip dhcp snooping Description The show ip dhcp snooping command is used to display the running status of DHCP-Snooping.
  • Page 87: Show Ip Dhcp Snooping Interface

    ——The Fast/Gigabit Ethernet port number. Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the DHCP-Snooping configuration of all Ethernet ports: TL-SL5428E#show ip dhcp snooping interface Display the DHCP-Snooping configuration of Fast Ethernet port 5: TL-SL5428E#show ip dhcp snooping interface fastEthernet 1/0/5...
  • Page 88: Chapter 13 Arp Inspection Commands

    Command Mode Global Configuration Mode Example Enable the ARP Detection function globally: TL-SL5428E(config)#ip arp inspection ip arp inspection trust Description The ip arp inspection trust command is used to configure the port for which the ARP Detect function is unnecessary as the Trusted Port. To clear the Trusted Port list, please use no ip arp detection trust command .The specific...
  • Page 89: Ip Arp Inspection(Interface)

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEhternet) Example Configure the Fast Ethernet ports 2-5 as the Trusted Port: TL-SL5428E(config)#interface range fastEthernet 1/0/2-5 TL-SL5428E(config-if-range)#ip arp inspection trust ip arp inspection(interface) Description The ip arp inspection command is used to enable the ARP Defend function. To disable the ARP detection function, please use no ip arp inspection command.
  • Page 90: Ip Arp Inspection Recover

    Configure the maximum amount of the received ARP packets per second as 50 pps for Fast Ethernet port 5: TL-SL5428E(config)#interface fastEthernet 1/0/5 TL-SL5428E(config-if)#ip arp inspection limit-rate 50 ip arp inspection recover Description The ip arp inspection recover command is used to restore a port to the ARP transmit status from the ARP filter status.
  • Page 91: Show Ip Arp Inspection

    [ fastEthernet port | gigabitEthernet port] Parameter port ——The Fast/Gigabit Ethernet port number. Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the configuration of Fast Ethernet port 1: TL-SL5428E(config)#show ip arp inspection interface fastEthernet 1/0/1...
  • Page 92: Show Ip Arp Inspection Statistics

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Display the configuration of all Ethernet ports: TL-SL5428E(config)#show ip arp inspection interface show ip arp inspection statistics Description The show ip arp inspection statistics command is used to display the number of the illegal ARP packets received.
  • Page 93: Chapter 14 Ip Verify Source Commands

    Enable the IP Verify Source function for Fast Ethernet ports 5-10. Configure that only the packets with its source IP address, source MAC address and port number matched to the IP-MAC binding rules can be processed: TL-SL5428E(config)#interface range fastEthernet 1/0/5-10 TL-SL5428E(config-if-range)#ip verify source sip+mac show ip verify source...
  • Page 94 The show ip verify source command is used to display the IP Verify Source configuration information. Syntax show ip verify source Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the IP Verify Source configuration information: TL-SL5428E(config)#show ip verify source...
  • Page 95: Chapter 15 Dos Defend Command

    Command Mode Global Configuration Mode Example Enable the DoS defend function globally: TL-SL5428E(config)#ip dos-prevent ip dos-prevent ping-rate Description The ip dos-prevent ping-rate command is used to configure the transmission rate of the Ping packets. To restore to default, please use no ip dos-prevent ping-rate command.
  • Page 96: Ip Dos-Prevent Syn-Rate

    Command Mode Global Configuration Mode Example Specify the transmission rate of the Ping packets as 256k: TL-SL5428E(config)#ip dos-prevent ping-rate 256k ip dos-prevent syn-rate Description The ip dos-prevent syn-rate command is used to configure the transmission rate of the SYN/SYN-ACK packets. To restore to default, please use no ip dos-prevent syn-rate command.
  • Page 97: Ip Dos-Prevent Detect

    Command Mode Global Configuration Mode Example Enable four DoS Defend Types named Land attack: TL-SL5428E(config)#ip dos-prevent type land ip dos-prevent detect Description The ip dos-prevent detect command is used to configure the detect time for each DoS attack type except the flooding attack type.
  • Page 98: Clear Ip Dos-Prevent Detect Statistics

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Clear the information statistic of the detected DoS attack: TL-SL5428E(config)#clear ip dos-prevent detect statistics show ip dos-prevent Description The show ip dos-prevent command is used to display the DoS information of the detected DoS attack, including enable/disable status, the DoS Defend Type, the count of the attack, etc.
  • Page 99 TL-SL5428E JetStream L2 Managed Switch CLI Guide Syntax show ip dos-prevent Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the DoS information of the detected DoS attack globally: TL-SL5428E(config)#show ip dos-prevent...
  • Page 100: Chapter 16 Ieee 802.1X Commands

    Command Mode Global Configuration Mode Example Enable the IEEE 802.1X function: TL-SL5428E(config)#dot1x system-auth-control dot1x auth-method Description The dot1x auth-method command is used to configure the Authentication Method of IEEE 802.1X and the default 802.1x authentication method is “eap-md5”.
  • Page 101: Dot1X Guest-Vlan(Global)

    Command Mode Global Configuration Mode Example Configure the Authentication Method of IEEE 802.1X as “pap”: TL-SL5428E(config)#dot1x auth-method pap dot1x guest-vlan(global) Description The dot1x guest-vlan command is used to enable the Guest VLAN function globally. To disable the Guest VLAN function, please use no dot1x guest-vlan command.
  • Page 102: Dot1X Quiet-Period

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config)#dot1x guest-vlan 5 dot1x quiet-period Description The dot1x quiet-period command is used to enable the quiet-period function. To disable the function, please use no dot1x quiet-period command. Syntax dot1x quiet-period no dot1x quiet-period...
  • Page 103: Dot1X Max-Reauth-Req

    Command Mode Global Configuration Mode Example Configure the quiet period as 100 seconds: TL-SL5428E(config)#dot1x timeout quiet-period 100 dot1x max-reauth-req Description The dot1x max-reauth-req command is used to configure the maximum transfer times of the repeated authentication request when the server cannot be connected.
  • Page 104: Dot1X Guest-Vlan(Interface)

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the IEEE 802.1X function for the Fast Ethernet port 1: TL-SL5428E(config)#interface fastEthernet 1/0/1 TL-SL5428E(config-if)#dot1x dot1x guest-vlan(interface) Description The dot1x guest-vlan command is used to enable the guest VLAN function for a specified port.
  • Page 105: Dot1X Port-Method

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure the Control Mode for Gigabit Ethernet port 25 as “authorized-force”: TL-SL5428E(config)#interface gigabitEthernet 1/0/25 TL-SL5428E(config-if)#dot1x port-control authorized-force dot1x port-method Description The dot1x port-method command is used to configure the control type of IEEE 802.1X for the specified port.
  • Page 106: Radius

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure the Control Type for Gigabit Ethernet port 25 as “port-based”: TL-SL5428E(config)#interface gigabitEthernet 1/0/25 TL-SL5428E(config-if)#dot1x port-method port-based radius Description The radius command is used to configure the parameters of radius.
  • Page 107: Radius Server-Account

    Global Configuration Mode Example Configure the IP address of the accounting server as 10.20.1.100 and password as tplink: TL-SL5428E(config)#radius auth-pri 10.20.1.100 auth-key tplink radius server-account Description The radius server-account command is used to enable the accounting feature. To disable the accounting feature, please use no radius server-account command.
  • Page 108: Show Dot1X Interface

    Privileged EXEC Mode and Any Configuration Mode Example Display the configuration information of 801.X for Gigabit Ethernet port 25: TL-SL5428E(config)#show dot1x interface gigabitEthernet 1/0/25 Display the configuration information of 801.X for all Ethernet ports: TL-SL5428E(config)#show dot1x interface show radius accounting...
  • Page 109: Show Radius Authentication

    Command Mode Privileged EXEC Mode and Any Configuration Modes Example Display the configuration of the accounting server: TL-SL5428E(config)#show radius accounting show radius authentication Description The show radius authentication command is used to display the configuration of the RADIUS authentication server.
  • Page 110: Chapter 17 System Log Commands

    Only the log with the same or smaller severity level value will be output. By default, it is 7 indicating that all the log information will be saved in the log buffer. Command Mode Global Configuration Mode Example Set the severity level as 6: TL-SL5428E(config)#logging buffer 6 logging file flash Description...
  • Page 111: Clear Logging

    Command Mode Global Configuration Mode Example Enable the log file function and set the severity as 7: TL-SL5428E(config)#logging file flash 7 clear logging Description The clear logging command is used to clear the information in the log buffer and log file.
  • Page 112: Logging Host Index

    0~6 will be sent to the log host. Command Mode Global Configuration Mode Example Set the IP address as 192.168.0.148, the level 5: TL-SL5428E(config)#logging host index 2 192.168.0.148 5 show logging local-config Description The show logging local-config command is used to display the configuration...
  • Page 113: Show Logging Loghost

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the configuration of the log host 2: TL-SL5428E(config)#show logging loghost 2 show logging buffer Description The show logging buffer command is used to display the log information in the...
  • Page 114: Show Logging Flash

    Privileged EXEC Mode and Any Configuration Mode Example Display the log information from level 0 to level 5 in the log buffer: TL-SL5428E(config)#show logging buffer level 5 show logging flash Description The show logging flash command is used to display the log information in the log file according to the severity level.
  • Page 115: Chapter 18 Ssh Commands

    Command Mode Global Configuration Mode Example Enable the SSH function: TL-SL5428E(config)#ip ssh server ip ssh version Description The ip ssh version command is used to enable the SSH protocol version. To disable the protocol version, please use no ip ssh version command.
  • Page 116: Ip Ssh Timeout

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Example Enable SSH v2: TL-SL5428E(config)#ip ssh version v2 ip ssh timeout Description The ip ssh timeout command is used to specify the idle-timeout time of SSH. To restore to the factory defaults, please use ip ssh timeout command.
  • Page 117: Ip Ssh Download

    Example Download a SSH-1 type key file named ssh-key from TFTP server with the IP Address 192.168.0.148: TL-SL5428E(config)#ip ssh download v1 ssh-key ip-address 192.168.0.148 show ip ssh Description The show ip ssh command is used to display the global configuration of SSH.
  • Page 118 TL-SL5428E JetStream L2 Managed Switch CLI Guide Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the global configuration of SSH: TL-SL5428E(config)#show ip ssh...
  • Page 119: Chapter 19 Ssl Commands

    Command Mode Global Configuration Mode Example Enable the SSL function: TL-SL5428E(config)#ip http secure-server ip http secure-server download certificate Description The ip http secure-server download certificate command is used to download a certificate to the switch from TFTP server.
  • Page 120: Ip Http Secure-Server Download Key

    BASE64 encoded. ip-addr —— The IP address of the TFTP server. Command Mode Global Configuration Mode Example Download a SSL Key named ssl-key from TFTP server with the IP Address of 192.168.0.146: TL-SL5428E(config)#ip http secure-server download key ssl-key ip-address 192.168.0.146...
  • Page 121: Show Ip Http Secure-Server

    The show ip http secure-server command is used to display the global configuration of SSL. Syntax show ip http secure-server Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the global configuration of SSL: TL-SL5428E(config)#show ip http secure-server...
  • Page 122: Chapter 20 Mac Address Commands

    Example Add a static Mac address entry to bind the MAC address 00:02:58:4f:6c:23, VLAN1 and Fast Ethernet port 1 together: TL-SL5428E(config)#mac address-table static mac 00:02:58:4f:6c:23 vid 1 interface fastEthernet 1/0/1 Delete the static address entry whose VLAN id is 1:...
  • Page 123: Mac Address-Table Aging-Time

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config)#no mac address-table static mac 00:02:58:4f:6c:23 mac address-table aging-time Description The mac address-table aging-time command is used to configure aging time for the dynamic address. To return to the default configuration, please use no mac address-table aging-time command.
  • Page 124: Mac Address-Table Max-Mac-Count

    Global Configuration Mode Example Add a filtering address entry of which VLAN ID is 1 and MAC address is 00:1e:4b:04:01:5d: TL-SL5428E(config)#mac address-table filtering mac 00:1e:4b:04:01:5d vid 1 mac address-table max-mac-count Description The mac address-table max-mac-count command is used to configure the Port Security.
  • Page 125: Show Mac Address-Table Address

    Enable Port Security function for Fast Ethernet port 1, select Static mode as the learn mode, and specify the maximum number of MAC addresses that can be learned on this port as 30: TL-SL5428E(config)#interface fastEthernet 1/0/1 TL-SL5428E(config-if)#mac address-table max-mac-count max-number 30 mode static status enable show mac address-table address Description The show mac address-table address command is used to display the information of all Address entries.
  • Page 126: Show Mac Address-Table Max-Mac-Count Interface

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the security configuration of all Gigabit Ethernet ports: TL-SL5428E(config)#show mac address-table max-mac-count interface gigabitEthernet Display the security configuration of Gigabit Ethernet port 25: TL-SL5428E(config)#show mac address-table max-mac-count interface gigabitEthernet 1/0/25...
  • Page 127: Show Mac Address-Table Mac-Num

    Privileged EXEC Mode and Any Configuration Mode Example Display the address configuration of Fast Ethernet port 1: TL-SL5428E(config)#show mac address-table interface fastEthernet 1/0/1 show mac address-table mac-num Description The show mac address-table mac-num command is used to display the total amount of MAC address table.
  • Page 128: Show Mac Address-Table Vlan

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the information of the MAC address 00:00:00:00:23:00:00: TL-SL5428E(config)#show mac address-table mac 00:00:00:00:23:00:00: show mac address-table vlan Description The show mac address-table vlan command is used to display the MAC address configuration of the specified vlan.
  • Page 129: Chapter 21 System Configuration Commands

    Command Mode Global Configuration Mode Example Configure the system time as 02/14/2012-12:30:00: TL-SL5428E(config)#system-time manual 02/14/2012-12:30:00 system-time ntp Description The system-time ntp command is used to configure the time zone and the IP Address for the NTP Server. The switch will get GMT automatically if it has connected to a NTP Server.
  • Page 130 Global Configuration Mode Example Configure the system time mode as NTP, the time zone is GMT-12, the primary NTP server is 133.100.9.2 and the secondary NTP server is 139.78.100.163, the fetching-rate is 11 hours: TL-SL5428E(config)#system-time ntp GMT-12 133.100.9.2 139.79.100.163 11...
  • Page 131: System-Time Dst Predefined

    Command Mode Global Configuration Mode Example Configure the DST period of the switch as European: TL-SL5428E(config)#system-time dst predefined European system-time dst date Description The system-time dst date command is used to specify the DST configuration in Date mode. This configuration is one-off in use. By default, the current year is used as the starting time.
  • Page 132: System-Time Dst Recurring

    , the end time as 00:00 am on October 1 and the offset as 30 minutes: TL-SL5428E(config)#system-time dst date Apr 1 00:00 Oct 1 00:00 30 system-time dst recurring Description The system-time dst recurring command is used to specify the DST configuration in recurring mode.
  • Page 133: Hostname

    Specify the DST start time of the switch as 2:00 am on the first Sunday in May, the end time as 2:00 am on the last Sunday in October and the offset as 45 minutes: TL-SL5428E(config)#system-time dst recurring first Sun May 02:00 last Sun Oct 02:00 45 hostname Description The hostname command is used to configure the system name.
  • Page 134: Location

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config)#hostname TPLINK location Description The location command is used to configure the system location. To clear the system location information, please use no location command. Syntax location location no location location Parameter location —— Device Location. It consists of 32 characters at most. It is SHENZHEN by default.
  • Page 135: Reset

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Configure the system contact information as www.tp-link.com: TL-SL5428E(config)#contact-info www.tp-link.com reset Description The reset command is used to reset the switch’s software. After resetting, all configuration of the switch will restore to the factory defaults and your current settings will be lost.
  • Page 136: Copy Startup-Config Tftp

    — — Specify the name for the configuration file which would be backuped. Command Mode Privileged EXEC Mode Example Backup the configuration files from TFTP server with the IP 192.168.0.148 and name this file config.cfg: TL-SL5428E# copy startup-config tftp ip-address 192.168.0.148 filename config.cfg copy tftp startup-config Description...
  • Page 137: Firmware Upgrade

    Privileged EXEC Mode Example Download the configuration file named as config.cfg to the switch from TFTP server with the IP 192.168.0.148: TL-SL5428E# copy startup-config tftp ip-address 192.168.0.148 filename config.cfg firmware upgrade Description The firmware upgrade command is used to upgrade the switch system file via the TFTP server.
  • Page 138: Ping

    192.168.0.131, please specify the count (-l) as 512 bytes and count (-i) as 1000 milliseconds. If there is not any response after 8 times’ Ping test, the connection between the switch and the network device is failed to establish: TL-SL5428E#ping 192.168.0.131 –n 8 –l 512 tracert Description The tracert command is used to test the connectivity of the gateways during its journey from the source to destination of the test data.
  • Page 139: Loopback Interface

    User EXEC Mode and Privileged EXEC Mode Example Do an internal-type loopback test for Gigabit Ethernet port 25: TL-SL5428E# loopback interface gigabitEthernet 1/0/25 internal Do an external-type loopback test for Gigabit Ethernet port 25: TL-SL5428E# loopback interface gigabitEthernet 1/0/25 external...
  • Page 140: Show System-Time Dst

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the DST time information of the switch TL-SL5428E#show system-time dst show system-time ntp Description The show system-time ntp command is used to display the NTP mode configuration information.
  • Page 141: Show System-Info

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the NTP mode configuration information of the switch: TL-SL5428E#show system-time ntp show system-info Description The show system-info command is used to display system description, system name, device location, system contact, hardware version, firmware version, system time, run time and so on.
  • Page 142 TL-SL5428E JetStream L2 Managed Switch CLI Guide Example Show the cable-diagnostics of Gigabit Ethernet port 25: TL-SL5428E#show cable-diagnostics interface gigabitEthernet 1/0/25...
  • Page 143: Chapter 22 Ethernet Configuration Commands

    Global Configuration Mode Example To enter the Interface fastEthernet Configuration Mode and configure Fast Ethernet port 2: TL-SL5428E(config)#interface fastEthernet 1/0/2 interface range fastEthernet Description The interface range fastEthernet command is used to enter the interface range fastEthernet Configuration Mode and configure multiple Fast Ethernet ports at the same time.
  • Page 144: Interface Gigabitethernet

    Example To enter the Interface Range fastEthernet Configuration Mode, and configure ports 1, 2, 3, 6, 7 and 9 at the same time by adding them to one port-list: TL-SL5428E(config)#interface range fastEthernet 1/0/1-3,1/0/6-7,1/0/9 interface gigabitEthernet Description The interface gigabitEthernet command is used to enter the interface gigabitEthernet Configuration Mode and configure the corresponding Gigabit Ethernet port.
  • Page 145: Description

    To enter the Interface Range gigabitEthernet Configuration Mode, and configure Gigabit Ethernet ports 25, 26 and 28 at the same time by adding them to one port-list: TL-SL5428E(config)# interface range gigabitEthernet 1/0/25-26,1/0/28 description Description The description command is used to add a description to the Ethernet port. To clear the description of the corresponding port, please use no description command.
  • Page 146: Shutdown

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Disable Gigabit Ethernet port 25: TL-SL5428E(config)#interface gigabitEthernet 1/0/25 TL-SL5428E(config-if)#shutdown flow-control Description The flow-control command is used to enable the flow-control function for a port.
  • Page 147: Duplex

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure the Duplex Mode as full-duplex for Gigabit Ethernet port 25: TL-SL5428E(config)#interface gigabitEthernet 1/0/25 TL-SL5428E(config-if)#duplex full speed Description The speed command is used to configure the Speed Mode for an Ethernet port.
  • Page 148: Storm-Control Broadcast

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Example Configure the Speed Mode as 100Mbps for Gigabit Ethernet port 25: TL-SL5428E(config)#interface gigabitEthernet 1/0/25 TL-SL5428E(config-if)#speed 100 storm-control broadcast Description The storm-control broadcast command is used to enable the broadcast control function. To disable the broadcast control function, please use no storm-control broadcast command.
  • Page 149: Storm-Control Unicast

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the multicast control function for Fast Ethernet port 5: TL-SL5428E(config)#interface fastEthernet 1/0/5 TL-SL5428E(config-if)#storm-control multicast storm-control unicast Description The storm-control unicast command is used to enbale the unicast control function.
  • Page 150: Bandwidth

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure the ingress-rate as 5120Kbps and egress-rate as 1024Kbps for Fast Ethernet port 5: TL-SL5428E(config)#interface fastEthernet 1/0/5 TL-SL5428E(config-if)#bandwidth ingress 5120 egress 1024 clear counters Description...
  • Page 151: Show Interface Status

    Example Display the connective-status of all Ethernet ports: TL-SL5428E(config)#show interface status Display the connective-status of Fast Ethernet port 1: TL-SL5428E(config)#show interface fastEthernet 1/0/1 status show interface counters Description The show interface counters command is used to display the statistic information of an Ethernet port.
  • Page 152: Show Interface Description

    Display the statistic information of all Ethernet ports: TL-SL5428E(config)#show interface counters Display the statistic information of Gigabit Ethernet port 25: TL-SL5428E(config)#show interface gigabitEthernet 1/0/25 counters show interface description Description The show interface description command is used to display the description of all ports or an Ethernet port.
  • Page 153: Show Interface Configuration

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the flow-control information of all Ethernet ports: TL-SL5428E#show interface flowcontrol show interface configuration Description The show interface configuration command is used to display the configurations of an Ethernet port, including Port-status, Flow Control, Negotiation Mode and Port-description.
  • Page 154: Show Bandwidth

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the storm-control information of port Gigabit Ethernet port 25: TL-SL5428E(config)#show storm-control interface gigabitEthernet 1/0/25 Display the storm-control information of port Fast Ethernet ports 4,5,6,7: TL-SL5428E(config)#show storm-control interface range fastEthernet 1/0/4-7...
  • Page 155: Chapter 23 Qos Commands

    CoS value of the ingress port and the mapping relation between the CoS and TC in IEEE 802.1P. Example Configure the priority of port 5 as 3: TL-SL5428E(config)#interface gigabitEthernet 1/0/5 TL-SL5428E(config-if)#qos 3 qos cos Description The qos cos command is used to enable the mapping relation between IEEE802.1P Priority and TC egress queue.
  • Page 156: Qos Dscp

    Example Enable the mapping relation between IEEE 802.1P Priority and egress queue: TL-SL5428E(config)#qos cos qos dscp Description The qos dscp command is used to enable the mapping relation between DSCP Priority and TC egress queue.
  • Page 157: Qos Queue Cos-Map

    Among the priority levels TC0-TC3, the bigger value, the higher priority. Example Map CoS 5 to TC 2.: TL-SL5428E(config)#qos queue cos-map 5 2 qos queue dscp-map Description The qos queue dscp-map command is used to configure the mapping relation between DSCP Priority and the TC egress queue. To return to the default configuration, please use no qos queue dscp-map command.
  • Page 158: Qos Queue Mode

    Among the priority levels TC0-TC3, the bigger value, the higher priority. Example Map DSCP values 10-12 to TC 2: TL-SL5428E(config)#qos queue dscp-map 10-12 2 qos queue mode Description The qos queue mode command is used to configure the Schedule Mode. To return to the default configuration, please use no qos queue mode command.
  • Page 159: Show Qos Interface

    Command Mode Global Configuration Mode Example Specify the Schedule Mode as Weight Round Robin Mode: TL-SL5428E(config)#qos queue mode wrr show qos interface Description The show qos interface command is used to display the configuration of QoS based on port priority.
  • Page 160: Show Qos Cos-Map

    Display the configuration of QoS for Fast Ethernet port 5: TL-SL5428E#show qos interface fastEthernet 1/0/5 Display the configuration of QoS for Fast Ethernet ports 7 to 16: TL-SL5428E#show qos interface range fastEthernet 1/0/7-16 show qos cos-map Description The show qos cos-map command is used to display the configuration of IEEE802.1P Priority and the mapping relation between cos-id and tc-id.
  • Page 161: Show Qos Queue Mode

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the schedule rule of the egress queues: TL-SL5428E#show qos queue mode show qos status Description The show qos status command is used to display the status of IEEE 802.1P priority and DSCP priority.
  • Page 162: Chapter 24 Port Mirror Commands

    Command Mode Global Configuration Mode Example Create monitor session 1 and configure Fast Ethernet port 1 as the monitoring port: TL-SL5428E(config)#monitor session 1 destination interface fastEthernet 1/0/1 Delete the monitor session 1: TL-SL5428E(config)#no monitor session 1 monitor session source interface...
  • Page 163 The monitoring port and monitored ports cannot be link-aggregation member. Example Create monitor session 1, then configure Fast Ethernet port 4, 5, 7 as monitored ports and enable ingress monitoring: TL-SL5428E(config)#monitor session 1 source interface fastEthernet 1/0/4-5,1/0/7 rx...
  • Page 164: Show Monitor Session

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Delete the Fast Ethernet port 4 in monitor session 1 and its configuration: TL-SL5428E(config)#no monitor session 1 source interface fastEthernet 1/0/4 rx show monitor session Description The show monitor session command is used to display the configuration of port monitoring.
  • Page 165: Chapter 25 Port Isolation Commands

    / interface gigabitEthernet / interface range gigabitEthernet) Example Set Gigabit Ethernet ports 25-27 to the forward port list of Gigabit Ethernet 28: TL-SL5428E(config)#interface range gigabitEthernet 1/0/28 TL-SL5428E(config-if-range)#port isolation gi-forward-list 1/0/25-27 Set all the Ethernet ports to forward port list of Fast Ethernet port 2, namely...
  • Page 166: Show Port Isolation

    The number of Ethernet port you want to show its forward port list, in the format of 1/0/2. Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the forward-list of Fast Ethernet port 3: TL-SL5428E#show port isolation interface fastEthernet 1/0/3 Display the forward-list of all Ethernet ports: TL-SL5428E#show port isolation interface...
  • Page 167: Chapter 26 Loopback Detection Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 26 Loopback Detection Commands With loopback detection feature enabled, the switch can detect loops using loopback detection packets. When a loop is detected, the switch will display an alert or further block the corresponding port according to the configuration.
  • Page 168: Loopback-Detection Recovery-Time

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Example Specify the interval-time as 50 seconds: TL-SL5428E(config)#loopback-detection interval 50 loopback-detection recovery-time Description The loopback-detection recovery-time command is used to configure the time after which the blocked port would automatically recover to normal status.
  • Page 169: Loopback-Detection Config

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Enable the loopback detection function of Gigabit Ethernet ports 25-27: TL-SL5428E(config)#interface range gigabitEthernet 1/0/25-27 TL-SL5428E(Config-if-range)#loopback-detection loopback-detection config Description The loopback-detection config command is used to configure the process-mode and recovery-mode for the ports by which the switch copes with the detected loops.
  • Page 170: Show Loopback-Detection Global

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Recover the blocked Gigabit Ethernet port 25 to normal status: TL-SL5428E(config)#interface gigabitEthernet 1/0/25 TL-SL5428E(config-if)#loopback-detection recover show loopback-detection global Description The show loopback-detection global command is used to display the global configuration of loopback detection function such as loopback detection global status, loopback detection interval and loopback detection recovery time.
  • Page 171 Privileged EXEC Mode and Any Configuration Mode Example Display the configuration of loopback detection function and the status of Fast Ethernet port 5: TL-SL5428E#show loopback-detection interface fastEthernet 1/0/5 Display the configuration of loopback detection function and the status of all ports: TL-SL5428E#show loopback-detection interface...
  • Page 172: Chapter 27 Acl Commands

    —— The Time-Range name, ranging from 1 to 16 characters. Command Mode Global Configuration Mode Example Add a time-range named tSeg1: TL-SL5428E(config)# time-range tSeg1 absolute Description The absolute command is used to configure a time-range into an absoluteness mode. To delete the corresponding Absoluteness Mode time-range, please use no absolute command.
  • Page 173: Periodic

    Time-range Create Configuration Mode Example Configure the time-range tSeg1 with time from May 5, 2012 to Oct. 5, 2012: TL-SL5428E(config)# time-range tSeg1 TL-SL5428E(config-time-range)# absolute start 05/05/2012 end 10/05/2012 periodic Description The periodic command is used to configure the time-range into periodic mode.
  • Page 174: Holiday

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config)#time-range tSeg1 TL-SL5428E(config-time-range)#periodic week-date off-day time-slice1 08:30-12:00 holiday Description The holiday command is used to configure the time-range into Holiday Mode under Time-range Create Configuration Mode. To delete the corresponding Holiday Mode time-range, please use no holiday command.
  • Page 175: Access-List Create

    Global Configuration Mode Example Define National Day, configuring the start date as October 1st, and the end date as October 3rd: TL-SL5428E(config)#holiday nationalday start-date 10/01 end-date 10/03 access-list create Description The access-list create command is used to create standard-IP ACL and extend-IP ACL.
  • Page 176: Access-List Standard

    Command Mode Global Configuration Mode Example Create a MAC ACL whose ID is 23: TL-SL5428E(config)#mac access-list 23 access-list standard Description The access-list standard command is used to add Standard-IP ACL rule. To delete the corresponding rule, please use no access-list standard command.
  • Page 177: Access-List Extended

    255.255.255.0, the time-range for the rule to take effect is tSeg1, and the packets match this rule will be forwarded by the switch: TL-SL5428E(config)#access-list create 120 TL-SL5428E(config)#access-list standard 120 rule 10 permit sip 192.168.0.100 smask 255.255.255.0 tseg tSeg1 access-list extended Description The access-list extended command is used to add Extended-IP ACL rule.
  • Page 178: Rule

    255.255.255.0, the time-range for the rule to take effect is tSeg1, and the packets match this rule will be forwarded by the switch: TL-SL5428E(config)#access-list create 220 TL-SL5428E(config)#access-list extended 220 rule 10 permit sip 192.168.0.100 smask 255.255.255.0 tseg tSeg1 rule Description The rule command is used to configure MAC ACL rule.
  • Page 179: Command Mode

    11:11:11:11:11:00, VLAN ID is 2, the user priority is 5, the time-range for the rule to take effect is tSeg1, and the packets match this rule will be forwarded by the switch: TL-SL5428E(config)#mac access-list 20 TL-SL5428E(config-mac-acl)#rule 10 permit smac 00:01:3F:48:16:23 smask 11:11:11:11:11:00 vid 2 pri 5 tseg tSeg1...
  • Page 180: Access-List Policy Name

    Command Mode Global Configuration Mode Example Add a Policy named policy1: TL-SL5428E(config)#access-list policy name policy1 access-list policy action Description The access-list policy action command is used to add ACLs and create actions for the policy. To set the detailed configuration of actions for a policy, please use access-list policy action command to access Action Configuration Mode.
  • Page 181: Redirect Interface

    JetStream L2 Managed Switch CLI Guide Global Configuration Mode Example Add ACL whose ID is 120 to policy1 and create an action for them: TL-SL5428E(config)#access-list policy action policy1 120 redirect interface Description The redirect interface command is used to configure Direction function of policy action for specified ports.
  • Page 182: S-Condition

    Action Configuration Mode Example Edit the actions for policy1. Forward the data packets matching ACL 120 in the policy to Fast Ethernet VLAN 1: TL-SL5428E(config)#access-list policy action policy1 120 TL-SL5428E(config-action)#redirect vlan 1 s-condition Description The s-condition command is used to configure Stream Condition function of policy action.
  • Page 183: Qos-Remark

    ACL. Local Priority ranges from 0 to 3. Command Mode Action Configuration Mode Example Edit the actions for policy1. For the data packets matching ACL 120, specify the DSCP region as 30 and local priority 2: TL-SL5428E(config)#access-list policy action policy1 120 TL-SL5428E(config-action)# qos-remark dscp 30 priority 2...
  • Page 184: Access-List Bind(Interface)

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Bind policy1 to Fast Ethernet port 2: TL-SL5428E(config)#interface fastEthernet 1/0/2 TL-SL5428E(config-if)#access-list bind policy1 access-list bind(vlan) Description The access-list bind command is used to bind a policy to a VLAN. To cancel the bind relation, please use no access-list bind command.
  • Page 185: Show Time-Range

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config-if)#access-list bind policy1 show time-range Description The show time-range command is used to display the configuration of time-range. Syntax show time-range Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the configuration of Time-Range:...
  • Page 186: Show Access-List Policy

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the information of a policy named policy1: TL-SL5428E#show access-list policy policy1 show access-list bind Description The show access-list bind command is used to display the configuration of Policy bind.
  • Page 187: Chapter 28 Mstp Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 28 MSTP Commands MSTP (Multiple Spanning Tree Protocol), compatible with both STP and RSTP and subject to IEEE 802.1s, can disbranch a ring network. STP is to block redundant links and backup links as well as optimize paths.
  • Page 188: Spanning-Tree Common-Config

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config)#interface fastEthernet 1/0/2 TL-SL5428E(config-if)#spanning-tree spanning-tree common-config Description The spanning-tree common-config command is used to configure the parameters of the ports for comparison in the CIST and the common parameters of all instances. To return to the default configuration, please use no spanning-tree common-config command.
  • Page 189: Spanning-Tree Mode

    / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the STP function of Fast Ethernet port 1, and configure the Port Priority as 64, ExtPath Cost as 100, IntPath Cost as 100, and then enable Edge Port: TL-SL5428E(config)#interface fastEthernet 1/0/1 TL-SL5428E(config-if)#spanning-tree common-config port-priority...
  • Page 190: Instantce

    Command Mode Global Configuration Mode Example Enter into the MST Configuration Mode: TL-SL5428E(config)#spanning-tree mst configuration TL-SL5428E(config-mst)# instantce Description The instance command is used to configure the VLAN-Instance mapping. To remove the VLAN-instance mapping or disable the corresponding instance, please use no instance command.
  • Page 191: Name

    TL-SL5428E(config)#spanning-tree mst configuration TL-SL5428E(config-mst)#no instance 1 Remove VLANs 1-50 in maping VLANs 1-100 for Instance 1: TL-SL5428E(config)#spanning-tree mst configuration TL-SL5428E(config-mst)#no instance 1 vlan 1-50 name Description The name command is used to configure the region name of MST instance. Syntax...
  • Page 192: Spanning-Tree Mst Instance

    Command Mode Global Configuration Mode Example Enable the MST Instance 1 and configure its priority as 4096: TL-SL5428E(config)#spanning-tree mst instance 1 priority 4096 spanning-tree mst Description The spanning-tree mst command is used to configure MST Instance Port. To return to the default configuration of the corresponding Instance Port, please use no spanning-tree mst command.
  • Page 193: Spanning-Tree Priority

    Example Configure the priority of Fast Ethernet port 1 in MST Instance 1 as 64, and path cost as 2000: TL-SL5428E(config)#interface fastEthernet 1/0/1 TL-SL5428E(config-if)#spanning-tree mst instance 1 port-priority 64 cost 2000 spanning-tree priority Description The spanning-tree priority command is used to configure the bridge priority. To return to the default value of bridge priority, please use no spanning-tree priority command.
  • Page 194: Spanning-Tree Tc-Defend

    Command Mode Global Configuration Mode Example Configure TC Threshold as 30 packets and TC Protect Cycle as 10 seconds: TL-SL5428E(config)#spanning-tree tc-defend threshold 30 period 10 spanning-tree timer Description The spanning-tree timer command is used to configure forward-time, hello-time and max-age of Spanning Tree. To return to the default configurations,...
  • Page 195: Spanning-Tree Hold-Count

    Global Configuration Mode Example Configure forward-time, hello-time and max-age for Spanning Tree as 16 seconds, 3 seconds and 22 seconds respectively: TL-SL5428E(config)#spanning-tree timer forward-time 16 hello-time 3 max-age 22 spanning-tree hold-count Description The spanning-tree hold-count command is used to configure the maximum number of BPDU packets transmitted per Hello Time interval.
  • Page 196: Spanning-Tree Max-Hops

    Command Mode Global Configuration Mode Example Configure the hold-count of STP as 8pps: TL-SL5428E(config)#spanning-tree hold-count 8 spanning-tree max-hops Description The spanning-tree max-hops command is used to configure the maximum number of hops that occur in a specific region before the BPDU is discarded. To return to the default configurations, please use no spanning-tree max-hops command.
  • Page 197: Spanning-Tree Bpduguard

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the BPDU filter function for Fast Ethernet port 2: TL-SL5428E(config)#interface fastEthernet 1/0/2 TL-SL5428E(config-if)#spanning-tree bpdufilter spanning-tree bpduguard Description The spanning-tree bpduguard command is used to enable the BPDU protect function for a port.
  • Page 198: Spanning-Tree Guard Root

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the Loop Protect function for Fast Ethernet port 2: TL-SL5428E(config)#interface fastEthernet 1/0/2 TL-SL5428E(config-if)#spanning-tree guard loop spanning-tree guard root Description The spanning-tree guard root command is used to enable the Root Protect function for a port.
  • Page 199: Spanning-Tree Guard Tc

    Command Mode Global Configuration Mode Example Enable the TC Protect of Spanning Tree for Fast Ethernet port 2: TL-SL5428E(config)#interface fastEthernet 1/0/2 TL-SL5428E(config-if)#spanning-tree guard tc spanning-tree mcheck Description The spanning-tree mcheck command is used to enable MCheck.
  • Page 200: Show Spanning-Tree Active

    Syntax show spanning-tree active Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the active information of spanning-tree: TL-SL5428E(config)#show spanning-tree active show spanning-tree bridge Description The show spanning-tree bridge command is used to display the bridge parameters. Syntax...
  • Page 201: Show Spanning-Tree Interface-Security

    Display the spanning-tree information of all ports: TL-SL5428E(config)#show spanning-tree interface Display the spanning-tree information of Gigabit Ethernet port 25: TL-SL5428E(config)#show spanning-tree interface gigabitEthernet 1/0/25 Display the spanning-tree mode information of Gigabit Ethernet port 25: TL-SL5428E(config)#show spanning-tree interface gigabitEthernet 1/0/25 mode...
  • Page 202: Show Spanning-Tree Mst

    Display the region information and mapping information of VLAN and MST Instance: TL-SL5428E(config)#show spanning-tree mst configuration Display the related information of MST Instance 1: TL-SL5428E(config)#show spanning-tree mst instance 1 Display all the ports information of MST Instance 1: TL-SL5428E(config)#show spanning-tree mst instance 1 interface...
  • Page 203: Chapter 29 Igmp Commands

    Command Mode Global Configuration Mode Example Enable IGMP Snooping function: TL-SL5428E(config)#ip igmp snooping ip igmp snooping(interface) Description The ip igmp snooping command is used to enable the IGMP Snooping function for the desired port. To disable the IGMP Snooping function, please use no ip igmp snooping command.
  • Page 204: Ip Igmp Snooping Immediate-Leave

    / interface gigabitEthernet / interface range gigabitEthernet) Example Enable the Fast Leave function for Fast Ethernet port 3: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#ip igmp snooping immediate-leave ip igmp snooping drop-unknown Description The ip igmp snooping drop-unknown command is used to process the unknown multicast as “discard”.
  • Page 205: Ip Igmp Snooping Vlan-Config

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Example Specify the operation of processing unknown multicast as “discard”: TL-SL5428E(config)#ip igmp snooping drop-unknown ip igmp snooping vlan-config Description The ip igmp snooping vlan-config command is used to enable VLAN IGMP Snooping function or to modify IGMP Snooping parameters, and to create static multicast IP entry.
  • Page 206: Ip Igmp Snooping Multi-Vlan-Config

    Global Configuration Mode Example Enable the IGMP Snooping function and modify Member Port Time as 200 seconds for VLAN1-3: TL-SL5428E(config)#ip igmp snooping vlan-config 1-3 mtime 200 ip igmp snooping multi-vlan-config Description The ip igmp snooping multi-vlan-config command is used to create and configure a Multicast VLAN.
  • Page 207: Ip Igmp Snooping Filter Add-Id

    Global Configuration Mode Example Enable Multicast VLAN 3, and configure Router Port Time as 100 seconds: TL-SL5428E(config)#ip igmp snooping multi-vlan-config 3 rtime 100 ip igmp snooping filter add-id Description The ip igmp snooping filter add-id command is used to configure the multicast IP-range desired to filter.
  • Page 208: Ip Igmp Snooping Filter(Global)

    Global Configuration Mode Example Modify the multicast IP-range whose ID is 3 as 225.1.1.1~226.3.2.1: TL-SL5428E(config)#ip igmp snooping filter 3 225.1.1.1 226.3.2.1 ip igmp snooping filter(interface) Description The ip igmp snooping filter command is used to configure Port Filter. To return to the default configuration, please use no igmp snooping filter command.
  • Page 209: Ip Igmp Snooping Filter Maxgroup

    Specify the maximum number of multicast groups for Fast Ethernet ports 2-5 to join in as 10: TL-SL5428E(config)#interface range fastEthernet 1/0/2-5 TL-SL5428E(config-if-range)#ip igmp snooping filter maxgroup 10 ip igmp snooping filter mode Description The ip igmp snooping filter mode command is used to configure the Action mode for the desired port.
  • Page 210: Show Ip Igmp Snooping

    / interface gigabitEthernet / interface range gigabitEthernet) Example Specify the Action Mode as “accept” for Fast Ethernet port 3: TL-SL5428E(config)#interface fastEthernet 1/0/3 TL-SL5428E(config-if)#ip igmp snooping filter mode accept show ip igmp snooping Description The show ip igmp snooping command is used to display the global configuration of IGMP Snooping.
  • Page 211: Show Ip Igmp Snooping Vlan

    Privileged EXEC Mode and Any Configuration Mode Example Display the IGMP basic configuration of Fast Ethernet port 2: TL-SL5428E#show ip igmp snooping interface fastEthernet 1/0/2 basic-config Display the IGMP filter configuration of Fast Ethernet ports 2-4: TL-SL5428E#show ip igmp snooping interface fastEthernet 1/0/2-4 filter...
  • Page 212: Show Ip Igmp Snooping Groups

    TL-SL5428E#show ip igmp snooping groups Display all the multicast entries in VLAN 5: TL-SL5428E(config)#show ip igmp snooping groups vlan 5 Display the count of multicast entries in VLAN 5: TL-SL5428E(config)#show ip igmp snooping groups vlan 5 count show ip igmp snooping filter Description...
  • Page 213 [filter-addr-id-list] Parameter filter-addr-id-list ——The multicast ID selected to display the multicast filter address information. It is optional. Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display all the multicast filter address information: TL-SL5428E(config)#show ip igmp snooping filter...
  • Page 214: Chapter 30 Snmp Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 30 SNMP Commands SNMP (Simple Network Management Protocol) functions are used to manage the network devices for a smooth communication, which can facilitate the network administrators to monitor the network nodes and implement the proper operation.
  • Page 215: Snmp-Server Group

    Example Add a View named view1, configuring the OID as 1.3.6.1.6.3.20, and this OID can be managed by the SNMP management station: TL-SL5428E(config)#snmp-server view view1 1.3.6.1.6.3.20 include snmp-server group Description The snmp-server group command is used to manage and configure the SNMP group.
  • Page 216: Snmp-Server User

    TL-SL5428E(config)#snmp-server group group1 smode v3 slev authNoPriv read viewDefault write viewDefault notify viewDefault Delete Group group 1: TL-SL5428E(config)#no snmp-server group group1 smode v3 slev authNoPriv snmp-server user Description The snmp-server user command is used to add User. To delete the corresponding User, please use no snmp-server user command.
  • Page 217 Security Level of the group as authPriv, the Authentication Mode of the user as MD5, the Authentication Password as 11111, the Privacy Mode as DES, and the Privacy Password as 22222: TL-SL5428E(config)#snmp-server user admin local group2 smode v3 slev authPriv cmode MD5 cpwd 11111 emode DES epwd 22222...
  • Page 218: Snmp-Server Community

    Global Configuration Mode Example Add community public, and the community has read-write management right to View viewDefault: TL-SL5428E(config)#snmp-server community public read-write viewDefault snmp-server host Description The snmp-server host command is used to add Notification. To delete the corresponding Notification, please use no snmp-server host command. With...
  • Page 219 Security Model of the management station as v2c, the type of the notifications as inform, the maximum time for the switch to wait as 1000 seconds, and the retries time as 100: TL-SL5428E(config)#snmp-server host 192.168.0.146 162 admin smode v2c type inform retries 100 timeout 1000...
  • Page 220: Snmp-Server Engineid

    Command Mode Global Configuration Mode Example Specify the local engineID as 1234567890, and the remote engineID as abcdef123456: TL-SL5428E(config)#snmp-server engineID local 1234567890 remote abcdef123456 rmon history Description The rmon history command is used to configure the history sample entry. To return to the default configuration, please use no rmon history command.
  • Page 221: Rmon Event

    Global Configuration Mode Example Configure the sample port as 2 and the sample interval as 100 seconds for the entry 1-3: TL-SL5428E(config)#rmon history 1-3 interface fastEthernet 1/0/2 interval 100 owner owner1 rmon event Description The rmon event command is used to configure the entries of SNMP-RMON Event.
  • Page 222: Rmon Alarm

    Configure the user name of entry 1, 2, 3 and 4 as user1, the description of the event as “description1”, the type of event as log and the owner of the event as “owner1”: TL-SL5428E(config)#rmon event 1-4 user user1 description description1 type log owner owner1 rmon alarm...
  • Page 223 TL-SL5428E JetStream L2 Managed Switch CLI Guide f-event] [ a-type {rise | fall | all} ] [ owner owner-name ] [ interval interval] no rmon alarm index Parameter index —— The index number of the Alarm Management entry, ranging from 1 to 12, in the format of 1-3,5.
  • Page 224: Show Snmp-Server

    JetStream L2 Managed Switch CLI Guide Example Configure the ports of entries of 1-3 as Gi1/0/2, the owners as owner1 and the alarm intervals as 100 seconds: TL-SL5428E(config)#rmon alarm 1-3 interface fastEthernet 1/0/2 owner owner1 interval 100 show snmp-server Description The show snmp-server command is used to display SNMP configuration globally.
  • Page 225: Show Snmp-Server User

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the Group table: TL-SL5428E#show snmp-server group show snmp-server user Description The show snmp-server user command is used to display the User table. Syntax show snmp-server user...
  • Page 226: Show Snmp-Server Host

    Syntax show snmp-server host Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the Host table: TL-SL5428E#show snmp-server host show snmp-server engineID Description The show snmp-server engineID command is used to display the engineID of the SNMP. Syntax...
  • Page 227: Show Rmon Event

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the Event configuration of entry1-4: TL-SL5428E#show rmon event 1-4 show rmon alarm Description The show rmon alarm command is used to display the configuration of the Alarm Management entry.
  • Page 228 1 to 12, in the format of 1-3, 5. You can select more than one entry for each command. By default, the configuration of all Alarm Management entries is displayed. Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the configuration of the Alarm Management entry 1-2: TL-SL5428E#show rmon alarm 1-2...
  • Page 229: Chapter 31 Lldp Commands

    TL-SL5428E JetStream L2 Managed Switch CLI Guide Chapter 31 LLDP Commands LLDP function enables network devices to advertise their own device information periodically to neighbors on the same LAN. The information of the LLDP devices in the LAN can be stored by its neighbor in a standard MIB, so it is possible for the information to be accessed by a Network Management System (NMS) using SNMP.
  • Page 230: Lldp Timer

    Command Mode Global Configuration Mode Example Specify Hold Multiplier as 5: TL-SL5428E(config)#lldp hold-multiplier 5 lldp timer Description The lldp timer command is used to configure the parameters about transmission. To return to the default configuration, please use no lldp timer command.
  • Page 231: Lldp Receive

    Global Configuration Mode Example Specify the Transmit Interval of LLDPDU as 45 seconds and Trap message to NMS as 120 seconds: TL-SL5428E(config)#lldp timer tx-interval 45 TL-SL5428E(config)#lldp timer notify-interval 120 lldp receive Description The lldp receive command is used to enable the designated port to receive LLDPDU.
  • Page 232: Lldp Snmp-Trap

    Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Enable Fast Ethernet port 1 to transmit LLDPDU: TL-SL5428E(config)# interface fastEthernet 1/0/1 TL-SL5428E(config-if)#lldp transmit lldp snmp-trap Description The lldp snmp-trap command is used to enable the port’s SNMP notification. If enabled, the port will notify the trap event to network management system.
  • Page 233: Show Lldp

    Example Exclude “management-address” and “port-vlan-id” TLVs in LLDPDU outgoing from Fast Ethernet port 1: TL-SL5428E(config)# interface fastEthernet 1/0/1 TL-SL5428E(config-if)# no lldp tlv-select management-address port-vlan show lldp Description The show lldp command is used to display the global configuration of LLDP.
  • Page 234: Show Lldp Interface

    Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the LLDP configuration of Fast Ethernet port 1: TL-SL5428E#show lldp interface fastEthernet 1/0/1 show lldp local-information interface Description The show lldp local-information interface command is used to display the LLDP information of the corresponding port.
  • Page 235: Show Lldp Neighbor-Information Interface

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E#show lldp local-information interface fastEthernet 1/0/1 show lldp neighbor-information interface Description The show lldp neighbor-information interface command is used to display the neighbor information of the corresponding port. By default, the neighbor information of all the ports will be displayed.
  • Page 236 TL-SL5428E JetStream L2 Managed Switch CLI Guide Example Display the LLDP statistic information of Fast Ethernet port 1: TL-SL5428E#show lldp traffic interface fastEthernet 1/0/1...
  • Page 237: Chapter 32 Cluster Commands

    NDP packets from this switch. Aging Time ranges from 5 to 255 in seconds. By default, it is 180. Command Mode Global Configuration Mode Example Enable NDP function globally, and configure Aging Time as 120 seconds, Hello Time as 50 seconds: TL-SL5428E(config)#cluster ndp...
  • Page 238: Cluster Ntdp

    TL-SL5428E JetStream L2 Managed Switch CLI Guide TL-SL5428E(config)#cluster ndp timer hello 50 aging 120 cluster ntdp Description The cluster ntdp command is used to configure NTDP globally. To return to the default configuration, please use no cluster ntdp command. NTDP (Neighbor Topology Discovery Protocol) is used to collect the NDP information and neighboring connection information of each device in a specific network range.
  • Page 239: Cluster Explore

    Example Enable NTDP function globally, and specify NTDP Hops as 5, NTDP Interval Time as 30 minutes: TL-SL5428E(config)#cluster ntdp TL-SL5428E(config)#cluster ntdp timer interval-timer 30 TL-SL5428E(config)#cluster ntdp hop 5 cluster explore Description The cluster explore command is used to enable the topology information collecting function manually.
  • Page 240: Cluster Ip Pool

    / interface gigabitEthernet / interface range gigabitEthernet) Example Enable NDP and NTDP function for Fast Ethernet port 5: TL-SL5428E(config)#interface fastEthernet 1/0/5 TL-SL5428E(config-if)#cluster ndp enable ntdp enable cluster ip pool Description The cluster ip pool command is used to create a new cluster. If no specified cluster name is set through cluster commander command, the newly created cluster will enjoy the system default name “tplink-cluster”.
  • Page 241: Cluster Manage

    Command Mode Global Configuration Mode Example Specify the Hold Time and Interval Time of the cluster as 50 seconds: TL-SL5428E(config)#cluster manage holdtime 50 TL-SL5428E(config)#cluster manage timer 50 cluster member Description The cluster member command is used to add member switch. To delete the...
  • Page 242: Cluster Candidate

    Command Mode Global Configuration Mode Example Add the switch whose MAC address is 0e-3f-4g-5e-6d-7b to the cluster: TL-SL5428E(config)#cluster member mac address 0e-3f-4g-5e-6d-7b cluster candidate Description The cluster candidate command is used to specify the current switch as candidate switch.
  • Page 243: Show Cluster Ndp

    Display the NDP configuration of all Ethernet ports: TL-SL5428E#show cluster ndp interface Display the NDP configuration of Fast Ethernet port 2: TL-SL5428E#show cluster ndp interface fastEthernet 1/0/2 show cluster neighbour Description The show cluster neighbour command is used to display the cluster...
  • Page 244: Show Cluster Ntdp

    Privileged EXEC Mode and Any Configuration Mode Example Display the global information of NTDP: TL-SL5428E#show cluster ntdp Display the NTDP configuration of all Ethernet ports: TL-SL5428E#show cluster ntdp interface Display the device table of NTDP: TL-SL5428E#show cluster ntdp device-list show cluster Description...
  • Page 245: Show Cluster Member

    The show cluster manage role command is used to display the role of the current switch. Syntax show cluster manage role Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the role of the current switch: TL-SL5428E(config)#show cluster manage role...

Table of Contents