Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks,
go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner
does not imply a partnership relationship between Cisco and any other company. (1110R)
Contents
Chapter 1: Introduction22
Overview22
User (Privilege) Levels23
CLI Command Modes24
User EXEC Mode24
Privileged EXEC Mode25
Global Configuration Mode25
Global Configuration Submodes26
Accessing the CLI27
Using HyperTerminal over the Console Interface28
Using Telnet over an Ethernet Interface30
CLI Command Conventions30
Editing Features31
Entering Commands31
Terminal Command Buffer32
Negating the Effect of Commands32
Command Completion33
Keyboard Shortcuts33
Copying and Pasting Text33
Interface Naming Conventions34
Interface ID34
Interface Range35
Interface List35
Chapter 2: 802.1X Commands36
dot1x guest-vlan enable36
dot1x guest-vlan enable (Interface)37
dot1x max-req38
dot1x port-control39
dot1x reauthentication40
dot1x system-auth-control41
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x1
Contents
dot1x timeout quiet-period41
dot1x timeout reauth-period42
dot1x timeout supp-timeout43
show dot1x44
show dot1x authenticated-hosts45
show dot1x guest-vlan46
show dot1x interfaces48
Chapter 3: AAA Commands50
aaa authentication enable50
aaa authentication login52
enable authentication53
enable password54
ip http authentication56
login authentication57
passwords aging58
passwords complexity <attributes>59
passwords complexity enable60
show aaa authentication lists62
show line lists62
show passwords configuration63
show username64
username65
Chapter 4: ACL Commands67
deny (MAC)67
deny (IP)68
deny (IPv6)71
ip access-group in73
ip access-list extended74
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x2
ipv6 access-group in75
ipv6 access-list75
mac access-group in77
mac access-list extended77
no sequence78
permit (IP)79
permit (IPv6)81
permit (MAC)84
show access-lists85
show access-lists86
show access-lists utilization86
Contents
Chapter 5: Address Table Commands88
bridge multicast reserved-address88
clear mac address-table89
mac address-table aging-time90
mac address-table static90
show bridge multicast reserved-address93
show mac address-table94
show mac address-table aging-time95
show port-security96
switchport port-security97
switchport port-security mode maximum98
Chapter 6: Bonjour Commands101
bonjour enable101
show bonjour102
Chapter 7: CDP Commands103
cdp advertise-v2103
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x3
Contents
cdp appliance-vlan enable104
cdp device-id format105
cdp enable105
cdp holdtime106
cdp log mismatch duplex107
cdp log mismatch native108
cdp log mismatch voip109
cdp mandatory-tlvs validation110
cdp pdu110
cdp run111
cdp timer112
clear cdp counter113
clear cdp table114
show cdp114
show cdp entry115
show cdp interfaces116
show cdp neighbor116
show cdp tlv118
show cdp traffic global118
show cdp traffic (Interface)120
Chapter 8: Clock Commands124
clock set124
clock source125
clock summer-time125
clock timezone127
show clock128
show sntp configuration129
sntp server129
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x4
Contents
Chapter 9: Configuration and Image File Commands131
boot host auto-config131
boot system132
copy133
delete backup-config 135
delete startup-config136
dir136
ip dhcp tftp-server file137
ip dhcp tftp-server ip address138
management vlan ipv6 dhcp client information refresh139
management vlan ipv6 dhcp client stateless140
renew dhcp force-autoconfig141
show backup-config142
show boot144
show bootvar145
show ip dhcp tftp-server146
show running-config147
show startup-config150
write152
Chapter 10: EEE Commands154
eee enable (Interface)154
Chapter 11: Ethernet Configuration Commands155
clear counters155
clear etherlike statistics156
default interface156
description157
duplex158
errdisable recovery158
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x5
Contents
flowcontrol160
interface161
interface range162
jumbo-frame162
show errdisable recovery163
show interface status164
show storm-control165
shutdown167
speed168
storm-control action169
storm-control broadcast170
storm-control broadcast level171
storm-control enable172
storm-control ifg173
storm-control unit173
storm-control unknown-multicast174
storm-control unknown-multicast level175
storm-control unknown-unicast176
storm-control unknown-unicast level176
Chapter 12: GVRP Commands178
clear gvrp statistics178
gvrp enable (Global)179
gvrp enable (Interface)179
gvrp registration-mode180
gvrp vlan-creation-forbid181
show gvrp182
show gvrp configuration182
show gvrp error-statictics184
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x6
Contents
show gvrp statistics185
Chapter 13: IGMP Snooping Commands196
clear ip igmp snooping groups196
clear ip igmp snooping statistics196
ip igmp filter197
ip igmp max-groups198
ip igmp profile199
ip igmp snooping200
ip igmp snooping version201
ip igmp snooping report-suppression201
ip igmp snooping unknown-multicast action202
ip igmp snooping vlan203
ip igmp snooping vlan immediate-leave204
ip igmp snooping vlan forbidden mrouter205
ip igmp snooping vlan forbidden forward-all206
ip igmp snooping vlan last-member-query-count207
ip igmp snooping vlan last-member-query-interval207
ip igmp snooping vlan mrouter208
ip igmp snooping vlan querier209
ip igmp snooping vlan querier version210
ip igmp snooping vlan query-interval211
ip igmp snooping vlan response-time212
ip igmp snooping vlan robustness-variable212
ip igmp snooping vlan static213
ip igmp snooping vlan mrouter214
ip igmp snooping vlan forward-all215
profile range216
show ip igmp filter217
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x7
Contents
show ip igmp max-group218
show ip igmp max-group action219
show ip igmp profile219
show ip igmp snooping220
show ip igmp snooping forward-all221
show ip igmp snooping groups222
show ip igmp snooping mrouter223
show ip igmp snooping querier224
show ip igmp snooping vlan224
Chapter 14: IP Addressing Commands226
clear arp-cache226
ip default-gateway226
ip domain lookup227
ip domain name228
ip host229
ip name-server230
management vlan ip-address231
management vlan ip dhcp client232
show arp233
show hosts233
show ip234
show ip dhcp 235
Chapter 15: IP ARP Inspection Commands236
clear ip arp inspection statistics vlan236
ip arp inspection236
ip arp inspection limit rate237
ip arp inspection trust239
ip arp inspection validate240
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x8
Contents
ip arp inspection vlan241
show ip arp inspection242
show ip arp inspection interfaces243
show ip arp inspection statistics244
Chapter 16: IP DHCP Snooping Commands246
clear ip dhcp snooping binding246
clear ip dhcp snooping binding interface246
clear ip dhcp snooping binding vlan247
clear ip dhcp snooping database statistics248
clear ip dhcp snooping interfaces statistics248
ip dhcp snooping249
ip dhcp snooping database249
ip dhcp snooping information option251
ip dhcp snooping information option allow-untrusted252
ip dhcp snooping limit rate253
ip dhcp snooping trust254
ip dhcp snooping verify mac-address255
ip dhcp snooping vlan256
ip dhcp snooping vlan information option circuit-id257
renew ip dhcp snooping database258
show ip dhcp snooping259
show ip dhcp snooping binding259
show ip dhcp snooping database260
show ip dhcp snooping information option format remote-id261
show ip dhcp snooping interfaces261
show ip dhcp snooping interfaces statistics262
Chapter 17: IP Source Guard Commands264
ip source binding264
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x9
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x10
Contents
ipv6 mld snooping vlan robustness-variable290
ipv6 mld snooping vlan static interface291
ipv6 mld snooping vlan mrouter292
ipv6 mld snooping vlan forward-all293
profile range294
show ipv6 mld filter295
show ipv6 mld max-group296
show ipv6 mld max-group action297
show ipv6 mld profile297
show ipv6 mld snooping298
show ipv6 mld snooping forward-all299
show ipv6 mld snooping groups300
show ipv6 mld snooping mrouter301
show ipv6 mld snooping vlan302
Chapter 20: LACP Commands303
lacp port-priority303
lacp system-priority304
lacp timeout304
show lacp305
Chapter 21: Line Commands311
clear line311
exec-timeout311
line312
password-thresh313
show line314
silent-time315
speed315
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x11
Contents
Chapter 22: LLDP Commands317
clear lldp statistics317
lldp holdtime-multiplier317
lldp lldpdu319
lldp med320
lldp med fast-start-repeat-count321
lldp med location321
lldp med network-policy voice auto322
lldp med network-policy (Global)323
lldp med network-policy (Interface)325
lldp med tlv-select326
lldp receive327
lldp reinit328
lldp run328
lldp tlv-select 802.1329
lldp tlv-select TLV330
lldp transmit331
lldp tx-delay332
lldp timer332
show lldp 333
show lldp interfaces337
show lldp interfaces tlvs-overloading338
show lldp local-device339
show lldp med340
show lldp neighbor341
show lldp statistics343
Chapter 23: Management ACL Commands345
deny (Management)345
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x12
management access-class346
management access-list347
no sequence (Management)348
permit (Management)349
show management access-class350
show management access-list351
Contents
Chapter 24: PHY Diagnostics Commands352
show cable-diagnostics cable-length352
show fiber-ports optical-transceiver355
Chapter 25: Power over Ethernet (PoE) Commands357
power inline357
power inline legacy enable358
power inline limit358
power inline limit-mode359
power inline priority360
power inline traps enable361
power inline usage-threshold361
show env all362
show power inline363
show power inline consumption367
Chapter 26: Port Channel Commands368
channel-group368
port-channel load-balance369
show etherchannel summary370
Chapter 27: Port Monitor Commands371
monitor session destination interface371
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x13
Contents
monitor session destination remote-span372
monitor session source interfaces373
monitor session source remote-span374
no monitor session375
remote-span376
show monitor377
show vlan remote-span378
Chapter 28: QoS Commands379
class379
class-map380
match381
police382
police aggregate383
policy-map384
priority-queue out num-of-queues386
qos387
qos advanced-mode trust388
qos aggregate-policer389
qos cos391
qos map cos-queue391
qos map dscp-queue392
qos map precedence-queue393
qos map queue-cos394
qos map queue-dscp395
qos map queue-precedence395
qos remark396
qos trust (Global)397
qos trust (Interface)398
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x14
Contents
service-policy399
set400
show class-map401
show policy-map401
show policy-map interface402
show qos403
show qos aggregate-policer404
show qos interfaces404
show qos map405
show qos queueing407
show rate-limit vlan407
traffic-shape408
trust-shape (Interface)409
traffic-shape queue410
trust410
rate-limit (Interface)412
rate-limit (VLAN)413
wrr-queue bandwidth414
Chapter 29: RADIUS Commands416
radius-server default-param416
radius-server host417
show radius-server419
show radius-server default-param420
Chapter 30: RMON Commands422
clear rmon statistics422
rmon alarm422
rmon event425
rmon history426
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x15
Contents
show rmon alarm427
show rmon event429
show rmon event log430
show rmon history431
show rmon statistics interfaces432
Chapter 31: Security DoS Commands436
security-suite dos (Global)436
security-suite dos (Interface)438
security-suite dos ip gratuitous-arps439
show security-suite dos439
show security-suite dos interfaces440
Chapter 32: SNMP Commands442
show snmp-server442
show snmp-server community443
show snmp-server engineid444
show snmp-server group445
show snmp-server host446
show snmp-server trap447
show snmp-server view448
show snmp-server user449
snmp-server451
snmp-server community451
snmp-server contact453
snmp-server engineid 454
snmp-server engineid remote454
snmp-server group455
snmp-server host456
snmp-server location458
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x16
Contents
snmp-server trap459
snmp-server user459
snmp-server view461
Chapter 33: STP Commands463
clear spanning-tree detected-protocols463
instance (MST)464
name (MST)465
revision (MST)465
show spanning-tree466
show spanning-tree interfaces467
show spanning-tree mst468
show spanning-tree mst configuration469
show spanning-tree mst interfaces470
spanning-tree471
spanning-tree bpdu (Global)471
spanning-tree bpdu-filter (Interface)472
spanning-tree bpdu-guard (Interface)473
spanning-tree cost (Interface)474
spanning-tree forward-time475
spanning-tree hello-time475
spanning-tree link-type (Interface)476
spanning-tree mst port-priority477
spanning-tree max-hops478
spanning-tree max-age479
spanning-tree mode480
spanning-tree mst configuration480
spanning-tree mst cost481
spanning-tree mst priority482
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x17
spanning-tree pathcost method483
spanning-tree portfast484
spanning-tree port-priority485
spanning-tree priority485
spanning-tree tx-hold-count486
Contents
Chapter 34: SYN Protection Commands488
security-suite syn protection mode488
security-suite syn protection recovery489
security-suite syn protection threshold489
show security-suite syn protection490
Chapter 35: Syslog Commands492
clear logging492
logging host492
logging on494
logging severity495
show logging 496
Chapter 36: System Management Commands499
hostname499
ping499
reload501
show cpu input rate501
show cpu utilization502
show memory statistics503
show services tcp-udp504
show system languages505
show tech-support506
show username509
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x18
show users510
show version511
traceroute512
Contents
Chapter 37: TACACS+ Commands514
show tacacs default-config514
show tacacs515
tacacs-server default-param516
tacacs-server host517
Chapter 38: Telnet and SSH Commands519
crypto certificate generate519
crypto key generate520
ip ssh server521
ip telnet server522
Chapter 39: User Interface Commands524
banner exec524
banner login525
configure527
do527
disable528
end529
enable529
exit (Configuration)530
exit (EXEC)531
history531
show banner532
show history533
show privilege534
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x19
Contents
terminal length535
Chapter 40: Voice VLAN Commands537
show voice vlan537
voice vlan enable539
voice vlan aging-timeout539
voice vlan cos540
voice vlan cos mode541
voice vlan dscp542
voice vlan mode542
voice vlan oui-table543
voice vlan state545
voice vlan id546
voice vlan vpt546
Chapter 41: VLAN Commands548
name (vlan)548
management-vlan 549
show interfaces protected-ports549
show interfaces switchport550
show management-vlan 552
show vlan553
show vlan default-vlan554
switchport access vlan554
switchport default-vlan tagged555
switchport dot1q-tunnel vlan557
switchport forbidden default-vlan558
switchport forbidden vlan559
switchport general acceptable-frame-type559
switchport general allowed vlan560
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x20
Contents
switchport general ingress-filtering disable562
switchport general pvid562
switchport mode564
switchport mode trunk uplink565
switchport protected566
switchport trunk allowed vlan567
switchport trunk native vlan568
switchport vlan tpid 569
vlan569
vlan default-vlan570
Chapter 42: Web Server Commands572
ip http secure-server572
ip http server573
ip http timeout-policy573
show ip http574
show ip https575
show services tcp-udp576
Appendix A: Where to Go From Here579
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x21
Introduction
The command-line interface (CLI) provides a text-based method for managing and
monitoring the switch. You can access the command-line interface using a
physical serial connection or a remote logical connection with Telnet.
This chapter describes how to use the command-line interface and contains the
following topics:
1
•Overview
•User (Privilege) Levels
•CLI Command Modes
•Accessing the CLI
Overview
•CLI Command Conventions
•Editing Features
•Interface Naming Conventions
The command-line interface is divided into various modes. Each mode has a group
of commands available in it. These modes are described in the CLI Command
Modes section.
Users are assigned privilege levels. Each privilege level can access the CLI modes
permitted to that level. User privilege levels are described in the User (Privilege)
Levels section.
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x22
Introduction
User (Privilege) Levels
User (Privilege) Levels
Users may be created with one of the following user levels:
•Level 1—Users with this level can only run the User EXEC mode commands.
Users at this level cannot access the web-based interface.
•Level 15—Users with this level can run all commands. Only users at this
level can access the web-based interface.
A system administrator (user with level 15) can create passwords that allow a
lower-level user to temporarily become a higher-level user. For example, the user
may go from level 1 to 15.
Users with a lower level can raise their level by entering the enable command and
the password for level 15. The higher level holds only for the current session.
1
The disable command returns the user to a lower level.
To create a user and assign a user level, use the username command. Only users
with privilege level 15 can create users at this level.
Example 1—The following example creates the password for level 15 (by the
administrator):
Example 2—The following example creates a user with privilege level 1:
switchxxxxxx# configure
switchxxxxxx(config)# username john privilege 1 secret John1234
Example 3—The following example switches between level 1 to level 15. The user
must know the password for level 15.
switchxxxxxx# exit
switchxxxxxx> enable 15
Password: ****** (this is the password for level 15)
switchxxxxxx#
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x23
Introduction
CLI Command Modes
NOTE If the authentication of passwords is performed on the RADIUS or TACACS+
servers, the passwords assigned to user level 15 must be configured on the
external server and associated with the $enab15$ username. See the AAA
Commands chapter for details.
CLI Command Modes
The command-line interface is divided into four command modes. These are the
command modes in the order in which they are accessed:
•User EXEC Mode
•Privileged EXEC Mode
•Global Configuration Mode
1
•Global Configuration Submodes
Each command mode has its own unique console prompt and set of CLI
commands. Entering a question mark at the console prompt displays a list of
available commands for the current mode and for the level of the user. Specific
commands are used to switch from one mode to another.
Users are assigned privilege levels that determine the modes and commands
available to them. User levels are described in the User (Privilege) Levels section.
User EXEC Mode
Users with level 1 initially log into the User EXEC mode. The User EXEC mode is
used for tasks that do not change the configuration, such as performing basic tests
and listing system information.
The user-level prompt consists of the switch hostname followed by a >. The
default hostname is switchxxxxxx where xxxxxx is the last six digits of the
switch’s MAC address, as shown here:
switchxxxxxx>
The default hostname can be changed by using the hostname Global
Configuration mode command.
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x24
Introduction
CLI Command Modes
1
Privileged EXEC Mode
A user with level 15 automatically logs into the Privileged EXEC mode.
The user-level prompt consists of the switch hostname followed by a #. The
default hostname is switchxxxxxx where xxxxxx is the last six digits of the
switch’s MAC address, as shown here:
switchxxxxxx#
Users with level 1 can enter the Privileged EXEC mode by entering the enable
command, and when prompted, the password for level 15.
To return from the Privileged EXEC mode to the User EXEC mode, use the disable
command.
Global Configuration Mode
The Global Configuration mode is used to run the commands that configure the
features at the system level, as opposed to the interface level.
Only users with command level 15 can access this mode.
To access the Global Configuration mode from the Privileged EXEC mode, enter
the configure command at the Privileged EXEC mode prompt and press Enter. The
Global Configuration mode prompt, consisting of the switch hostname followed by
(config)#, is displayed:
switchxxxxxx(config)#
Use any of the following commands to return from the Global Configuration mode
to the Privileged EXEC mode:
•exit
•end
•Ctrl+Z
The following example shows how to access the Global Configuration mode and
return to the Privileged EXEC mode:
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x25
Introduction
CLI Command Modes
1
Global Configuration Submodes
Various submodes may be entered from the Global Configuration mode. These
submodes enable performing commands on a group of interfaces or lines,
defining conditions required to allow traffic based on IPv4, IPv6, and MAC
addresses, or defining the settings for management ACL, IGMP profiles, and MLD
profiles.
For instance, to perform several operations on a specific interface, you can enter
the Interface Configuration mode for that interface.
The following example enters the Interface Configuration mode for fa1-5 and then
sets their speeds:
The exit command returns to the Global Configuration mode.
The following submodes are available:
•Interface—Contains commands that configure a specific interface (port or
port channel) or a range of interfaces. The interface Global Configuration
mode command is used to enter the Interface Configuration mode.
•Port Channel—Contains commands used to configure port channels; for
example, assigning ports to a port channel. Most of these commands are
the same as the commands in the Ethernet Interface Configuration mode,
and are used to manage the member ports as a single entity. The interface
Port-Channel Global Configuration mode command is used to enter the Port
Channel Interface Configuration mode.
•IP Access-List—Configures conditions required to allow traffic based on IP
addresses. The ip access-list Global Configuration mode command is used
to enter the IP Access-List Configuration mode.
•IPv6 Access-List—Configures conditions required to allow traffic based on
IPv6 addresses. The ipv6 access-list Global Configuration mode command
is used to enter the IPv6 Access-List Configuration mode.
•Line Interface—Contains commands used to configure the management
connections for the console, Telnet, and SSH. These commands configure
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x26
Introduction
Accessing the CLI
1
connection operations such as line timeout settings. The line Global
Configuration command is used to enter the Line Configuration mode.
•MAC Access-List—Configures conditions required to allow traffic based on
MAC addresses. The mac access-list Global Configuration mode command
is used to enter the MAC Access-List Configuration mode.
•Management Access-List—Contains commands used to define
management access-lists. The management access-list Global
Configuration mode command is used to enter the Management AccessList Configuration mode.
•IGMP Profile—Contains commands used to define the settings of IGMP
profiles. The ip igmp profile Global Configuration mode command is used to
enter the IGMP Profile Configuration mode.
•MLD Profile—Contains commands used to define the settings of MLD
profiles. The ipv6 mld profile Global Configuration mode command is used
to enter the MLD Profile Configuration mode.
To return from any Interface Configuration mode to the Global Configuration mode,
use the exit command.
Accessing the CLI
The command-line interface can be accessed from a terminal or computer by
performing one of the following tasks:
•Running a terminal application, such as HyperTerminal, on a computer that is
•Running a Telnet session from a command prompt on a computer with a
•Using SSH.
NOTE Telnet and SSH are disabled by default on the switch.
If the access is through a Telnet connection, ensure that the following conditions
are met before using CLI commands:
directly connected to the switch’s console port.
network connection to the switch.
•The switch has a defined IP address.
•Corresponding management access is granted.
Cisco 220 Series Smart Plus Switches Command Line Interface Reference Guide Release 1.0.0.x27
Introduction
Accessing the CLI
1
•An IP path is available so that the computer and the switch can reach each
other.
Using HyperTerminal over the Console Interface
The switch’s serial console port provides a direct connection to a computer’s
serial port using a standard DB-9 null modem or crossover cable. Once the
computer and the switch are connected, run a terminal application to access the
command-line interface.
To access the command-line interface using the HyperTerminal application,
perform the following steps: