Cisco Small Business 200E Series Advanced Smart Switch Command Reference2
show cablestatus35
show fiber-ports optical-transceiver37
Page 3
lldp med transmit-tlv38
lldp med transmit-tlv all40
poe41
poe power limit42
poe power management44
poe powered-device describe46
poe priority47
poe reset48
poe usagethreshold49
show poe50
show poe port configuration51
show poe port info52
show poe port statistics54
Contents
Switch Management Access Control55
Authentication Methods55
ip http authentication55
login authentication57
show authentication methods58
User Logins and Passwords59
password59
passwords aging59
passwords min-length60
passwords strength-check61
passwords strength check-username62
passwords strength exclude-keyword63
passwords strength maximum repeated-characters64
show loginsession65
show passwords configuration66
show user accounts67
show users68
show users login-history69
username70
Management Access—General72
network mgmt_vlan72
show network72
HTTP Access73
ip http port73
ip http server74
ip http session soft-timeout75
Cisco Small Business 200E Series Advanced Smart Switch Command Reference3
Page 4
show ip http75
Contents
Telnet Access76
ip telnet server enable76
telnet77
telnetcon timeout78
show telnetcon79
SSH Access80
copy nvram:sshkey-dsa80
copy nvram:sshkey-rsa180
copy nvram:sshkey-rsa281
crypto key generate dsa81
crypto key generate rsa82
ip ssh protocol83
ip ssh server enable83
sshcon maxsessions84
sshcon timeout85
show ip ssh86
Console Access86
line console86
serial baudrate87
serial databits88
serial parity88
serial stopbits89
serial timeout90
show serial90
Management Access Lists91
deny91
management access-class93
management access-list94
permit95
show management access-list96
show management access-class97
Cisco Small Business 200E Series Advanced Smart Switch Command Reference4
Page 5
clock timezone config dhcp103
show clock104
Contents
SNTP Commands105
sntp authenticate105
sntp authentication-key106
sntp broadcast client poll interval107
sntp client mode108
sntp client port109
sntp server110
sntp trusted-key111
sntp unicast client poll-interval112
show sntp113
show sntp client114
show sntp configuration115
show sntp server116
System Software and Configuration Management117
copy117
delete121
set contact122
set hostname122
set location123
reload124
reset factory default125
write memory125
show config-file126
show config-file list127
show running-config128
show language-packs detail130
show language-packs summary131
show sysinfo132
Cisco Small Business 200E Series Advanced Smart Switch Command Reference5
Page 6
logging host141
logging host remove143
logging persistent enable144
logging persistent severity144
logging persistent size146
logging syslog enable146
logging syslog facility147
logging syslog port148
show logging149
show logging buffered151
show logging hosts151
show logging persistent152
show logging traplogs154
Contents
RMON155
rmon alarm155
rmon collection history157
rmon event159
show environment160
show process cpu161
show rmon alarm162
show rmon alarm-table163
show rmon collection history164
show rmon events165
show rmon history166
show rmon log169
show rmon statistics170
Chapter 3: Port Management173
Switch Ports173
Cisco Small Business 200E Series Advanced Smart Switch Command Reference6
auto-negotiate173
auto-negotiate all174
mtu175
shutdown176
shutdown all176
speed177
speed all178
show interface advertise179
show interface ethernet180
show port183
addport200
deleteport (Interface Config)200
deleteport (Global Config)201
port lacpmode202
port lacpmode all203
port lacptimeout (Interface Config)203
port lacptimeout (Global Config)204
port-channel adminmode205
port-channel load-balance206
port-channel static208
show lacp actor208
show lacp partner211
show port-channel213
show port-channel brief214
show port-channel system priority215
Chapter 4: VLAN Management217
VLAN217
Cisco Small Business 200E Series Advanced Smart Switch Command Reference7
switchport general acceptable-frame-type tagged-only220
switchport general allowed vlan221
switchport general pvid222
switchport general ingress-filtering disable223
switchport trunk allowed vlan223
switchport mode224
switchport trunk native-vlan226
show interfaces switchport226
Contents
LLDP-MED228
lldp med228
lldp med all228
lldp med confignotification229
lldp med confignotification all229
lldp med inventory-tlv asset-id230
lldp med location-tlv co-ordinate231
lldp med location-tlv civic-addr231
lldp med location-tlv elin-addr233
lldp med location-tlv type234
lldp med transmit-tlv235
lldp med transmit-tlv all236
show lldp med237
show lldp med location-tlv237
show lldp med local-device detail238
show lldp med remote-device240
show lldp med remote-device detail241
Auto-VoIP242
Media VLAN252
Cisco Small Business 200E Series Advanced Smart Switch Command Reference8
auto-voip oui243
auto-voip oui-based243
auto-voip oui-based all244
auto-voip oui-priority245
auto-voip oui-vlan246
auto-voip protocol-based247
auto-voip protocol-based all247
show auto-voip oui-based interface248
show auto-voip oui-table249
show auto-voip protocol-based interface250
show auto-voip sessions251
media-vlan (Global Config)252
Page 9
media-vlan (Interface Config)253
show media-vlan255
Contents
Chapter 5: Spanning Tree Protocol257
spanning-tree257
spanning tree auto edge258
spanning-tree bpdufilter258
spanning-tree bpdufilter default259
spanning-tree bpdumigrationcheck260
spanning-tree bpdu flood260
spanning-tree bpdu flooding261
spanning-tree configuration name262
spanning-tree configuration revision263
spanning-tree edgeport264
spanning-tree forward-time265
spanning-tree max-age266
spanning-tree mode267
spanning-tree mst267
spanning-tree mst instance270
spanning-tree mst priority271
spanning-tree mst vlan272
spanning-tree port mode273
spanning-tree port mode all274
spanning-tree priority274
show spanning-tree275
show spanning-tree brief276
show spanning-tree interface277
show spanning-tree mst port detailed278
show spanning-tree mst port summary280
show spanning-tree mst summary282
show spanning-tree vlan283
Chapter 6: MAC Address Tables285
Cisco Small Business 200E Series Advanced Smart Switch Command Reference9
bridge address285
bridge aging-time286
clear mac-addr-table287
show mac-addr-table287
show mac-addr-table dynamic290
show mac-addr-table static291
Page 10
Contents
Chapter 7: Multicast293
Multicast Forwarding and MAC Filtering293
macfilter293
macfilter adddest294
macfilter adddest all295
set multicast filter-unregistered296
set multicast forward-all297
set multicast forward-unregistered298
show mac-address-table multicast299
show mac-address-table staticfiltering300
show multicast filtering301
IGMP Snooping302
set igmp302
set igmp fast-leave303
set igmp groupmembership-interval304
set igmp maxresponse305
set igmp mcrtrexpiretime306
set igmp mrouter307
set igmp mrouter interface308
show igmpsnooping308
show igmpsnooping mrouter interface311
show igmpsnooping mrouter vlan311
show mac-address-table igmpsnooping312
MLD Snooping314
set mld314
set mld fast-leave315
set mld groupmembership-interval316
set mld maxresponse316
set mld mcrtrexpiretime317
set mld mrouter318
set mld mrouter interface319
show mac-address-table mldsnooping320
show mldsnooping321
show mldsnooping mrouter interface323
show mldsnooping mrouter vlan324
Chapter 8: Security326
General326
show net connections326
Cisco Small Business 200E Series Advanced Smart Switch Command Reference10
Page 11
Contents
RADIUS327
radius server attribute nas-ip-addr327
radius server deadtime328
radius server host329
radius server key331
radius server msgauth332
radius server priority333
radius server retransmit334
radius server timeout335
show radius336
show radius servers337
show radius statistics340
Cisco Small Business 200E Series Advanced Smart Switch Command Reference13
Page 14
Using the Command Line Interface
The command-line interface (CLI) provides a text-based way to manage and
monitor the system. You can access the CLI using a physical serial connection or a
remote logical connection with telnet.
This chapter describes the CLI syntax, conventions, and modes. It contains the
following sections:
•Command Syntax
•Command Conventions
•Interface Naming Convention
•Using the No Form of a Command
1
•Command Modes
•Command Completion and Abbreviation
•CLI Error Messages
•Command Organization in this Document
Cisco Small Business 200E Series Advanced Smart Switch Command Reference14
Page 15
Using the Command Line Interface
Command Syntax
Command Syntax
A command is one or more words that might include one or more parameters.
Parameters might be required or optional values.
1
Some commands, such as
Other commands, such as
command. You must type the parameter values in a specific order. Optional
parameters follow required parameters. The following example describes the
network parms command syntax:
network parms ip-address netmask[gateway]
•network parms is the command name.
ip-address and netmask are mandatory parameters that you must replace with
•
the actual value.
gateway is an optional parameter that you can replace with text.
•
This reference lists each command by the command name and provides the
following information where applicable:
•Syntax Descriptions—describes each keyword and parameter.
•Defaults—describe any default values for the command parameters.
•Command Modes—identifies the CLI command modes in which you can
execute the command.
show network or clear vlan, do not require parameters.
network parms, require that you supply a value after the
•Examples—one or more examples of the command string, the output, and
descriptions of the output fields, if applicable.
•Related Commands—other commands you can use in conjunction with the
primary command.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference15
Page 16
Using the Command Line Interface
Command Conventions
Command Conventions
In this document the command elements include command key words and
parameters. Key words are entered as shown in the command. Parameters are
shown in italics and represent variable text. You must replace the parameter name
with an appropriate value, which might be an alphabetic, numeric, or alphanumeric
value. Parameters are order-dependent.
Keywords and parameters could be mandatory or optional, and might be one of
several choices. The following table describes the conventions this document
uses to distinguish command elements.
SymbolExamplesDescription
1
No bracketsspanning-tree
ip-address
[ ] square brackets[encrypted]
[ip-address]
[level0-100]
Mandatory parameter that is not in
italics. The command element is a
keyword. Enter it as shown.
When in italics, the command
element is a variable (placeholder
text). Enter your own text to replace
it.
A parameter in italics is a variable
(placeholder text). Enter the
command, replacing the variable in
the command with a value. For
example, the
be replaced by
Optional parameter entered as
show.
Optional variable that can be
replaced by a value.
Optional parameter with a range of
values.
ip-address variable might
192.168.10.254.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference16
Page 17
Using the Command Line Interface
Interface Naming Convention
SymbolExamplesDescription
1
{} curly braces{drop | forward}
{ip-address | hostname}
[{}] Braces within
square brackets
{source interface
interface [{rx | tx}]
Interface Naming Convention
Fast Ethernet switch ports are represented in the CLI as e1 for port 1, e2 for port 2,
e3 for port 3, and so forth.
A list of parameter choices, each
separated by a vertical bar, to be
entered as shown.
A list of parameter choices, each
separated by a vertical bar. The
chosen variable is replaced by the
appropriate value.
A required choice within an optional
element. In the example, if you chose
to enter
enter a value for the
parameter, and you can optionally
chose the
source interface, you must
interface
rx or the tx parameter.
The gigabit Ethernet switch ports are represented as g1 and g2.
Link aggregation groups (LAGs) are configurable as logical interfaces and are
represented in the CLI as ch1, ch2, ch3, and so forth.
Using the No Form of a Command
The no keyword is a specific form of an existing configuration command and does
not represent a new or distinct command. Almost every configuration command
has a no form. In general, use the no form of the command to reverse the action of
a command or reset it to the default value. Example:
#no shutdown
Reverses the shutdown command to bring up the interface.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference17
Page 18
Using the Command Line Interface
Using a Space in a Command
Using a Space in a Command
To include a space in a string, enclose the string in quotes, such as "string space".
Example:
#set contact "Thom Dobro"
Command Modes
Modes group commands according to the function of each command. The
commands in a particular mode are not available until you change to that mode.
The command prompt changes in each command mode to identify the current
mode. The following table describes the command modes and the prompts for
that mode.
1
NOTE In the following table, the word switch in the prompt represents the switch
hostname. By default, the hostname is switch<
You can use the set hostname command to configure a different hostname that will
display in the CLI prompt.
Command ModePromptDescription
Privileged EXECswitch#The show commands that
Global Configswitch (Config)# General setup commands and
display status and statistics,
some configuration commands,
and access to the Global
Config and VLAN Config
modes.
modifications to the running
configuration.
Manage the interfaces.
Access List Configswitch(config-macal)#Switch management access list
Cisco Small Business 200E Series Advanced Smart Switch Command Reference18
configuration commands.
Page 19
Using the Command Line Interface
Command Modes
Command ModePromptDescription
1
Line Console
Config
Line SSH Configswitch (config-ssh)#SSH login and authentication
Line Telnet Configswitch (config-telnet)#Telnet login and authentication
The following table explains how to enter and exit each mode.
ModeTo EnterTo Exit
Privileged EXECUsers enter this mode
Global ConfigFrom the Privileged
switch (config-line)#Outbound telnet settings and
console interface settings,
including console login and
authentication information.
information.
information.
To log out of the CLI session, enter
when they log in.
EXEC mode, enter
configure or config.
quit.
To exit to the Privileged EXEC
mode, enter exit, or press Ctrl-Z.
VLAN ConfigFrom the Privileged
EXEC mode, enter
vlan database.
Interface ConfigFrom the Global
Config mode, enter
interface interface
Access List
Config
Line ConsoleFrom the Global
Line SSHFrom the Global
From the Global
Config mode, enter
management
access-list listname
Config mode, enter
line console.
Config mode, enter
line ssh.
To exit to the Privileged EXEC
mode, enter exit or press Ctrl-Z.
To exit to the Global Config mode,
enter exit. To return to Privileged
EXEC mode, enter Ctrl-Z.
To exit to the Global Config mode,
enter exit. To return to Privileged
EXEC mode, enter Ctrl-Z.
To exit to the Global Config mode,
enter exit. To return to Privileged
EXEC mode, enter Ctrl-Z.
To exit to the Global Config mode,
enter exit. To return to Privileged
EXEC mode, enter Ctrl-Z.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference19
Page 20
Using the Command Line Interface
Command Completion and Abbreviation
ModeTo EnterTo Exit
1
Line telnetFrom the Global
Config mode, enter
line telnet.
Command Completion and Abbreviation
The command completion feature finishes spelling the keyword when you type
enough letters of a command to uniquely identify the command keyword. After
you have entered enough letters, press the spacebar or Tab key to complete the
keyword.
The command abbreviation feature allows you to execute a command when you
have entered enough letters to uniquely identify the command. You must enter all
of the required keywords and parameters, however.
CLI Error Messages
To exit to the Global Config mode,
enter exit. To return to Privileged
EXEC mode, enter Ctrl-Z.
Using CLI Help
If you enter a command and the system is unable to execute it, an error message
appears. The most common CLI error messages are:
•% Invalid input detected at '^' marker—You entered an
incorrect or unavailable command. The carat (^) shows where the invalid
text is detected. This message also appears if any of the parameters or
values are not recognized.
•Command not found / Incomplete command. Use ? to list
commands—You did not enter the required keywords or values.
•Ambiguous command—You did not enter enough letters to uniquely
identify the command.
Enter a question mark (?) at the command prompt to display the commands
available in the current mode.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference20
Page 21
Using the Command Line Interface
Command Organization in this Document
Command Organization in this Document
This document is divided into chapters, such as Administration and Port
Management chapters, based on general CLI functions. Chapters are divided into
sections, such as the Port Mirroring and Cable Diagnostics sections, where all
commands related to those features are listed. Commands that configure the
feature are listed first in each section, in alphabetical order, followed by
commands that display status and statistics information (show commands), in
alphabetical order.
1
Cisco Small Business 200E Series Advanced Smart Switch Command Reference21
Page 22
Administration
This chapter describes how to configure global system settings and perform
diagnostics.
It contains the following topics:
•Control Packet Handling
•Auto Configuration
•Bonjour
•Port Mirroring
•Cable Diagnostics
2
•PoE
•Switch Management Access Control
•SNTP and Time Settings
•System Software and Configuration Management
•Syslog
•RMON
Cisco Small Business 200E Series Advanced Smart Switch Command Reference22
Page 23
Administration
Control Packet Handling
Control Packet Handling
You can use the commands described in this section to control how the switch
handles packets of the Cisco Discovery Protocol (CDP), Link Layer Discovery
Protocol (LLDP), or 802.1X protocol.
protocol cdp
Use this command to drop or forward Cisco Discovery Protocol (CDP) packets.
CDP enables directly connected devices to share information such as their IP
addresses, capabilities, and software versions. Although the switch does not use
CDP to share its own information, by default it forwards CDP packets on behalf of
connected devices within a VLAN.
protocol cdp {drop | forward}
2
Syntax Descriptions
ParameterDescription
dropThe switch drops all CDP packets.
forwardThe switch forwards all CDP packets.
Default
CDP packets are forwarded.
Command Modes
Global Config
protocol {lldp | dot1x}
Use this command to drop, forward, or terminate Link Layer Discovery Protocol
(LLDP) or IEEE 802.1X Extensible Authentication Protocol over LAN (EAPOL)
packets.
protocol cpdConfigures the switch to drop or forward CDP packets.
protocol {lldp |
dot1x}
Auto Configuration
The following commands configure the Auto Configuration file download feature.
When enabled, the switch automatically downloads a network configuration file if
no file is found in flash memory when the switch reboots. The switch uses
information obtained through DHCP to identify the TFTP server and file name to
use in the download.
boot autoinstall
Use this command to enable DHCP Auto Configuration on the switch. Use the no
form of the command to disable this feature.
Configures the switch to drop, forward, or terminate LLDP
or 802.1X packets.
boot autoinstall
no boot autoinstall
Cisco Small Business 200E Series Advanced Smart Switch Command Reference25
Page 26
Administration
Auto Configuration
2
Default
DHCP Auto Configuration is enabled.
Command Modes
Privileged Exec
Usage Guidelines
The Auto Configuration feature depends upon the proper configuration of other
devices in the network, including a DHCP or BOOTP server, a TFTP server, and, if
necessary, a DNS server.
Related Commands
CommandDescription
boot autoinstall
default-config
show autoinstallDisplays Auto Configuration status information.
boot autoinstall
backup-tftp
boot autoinstall
backup-bootfile
Enables the switch to look for and download a default
network configuration file upon startup when no hostspecific configuration file is found.
Configures the address of a backup TFTP server to be
used when the Auto Configuration process cannot locate
the primary server or network configuration file name
provided by the DHCP server at startup.
Configures a backup configuration file name to be used
when the Auto Configuration process cannot locate the
primary server or network configuration file name
provided by the DHCP server at startup.
boot autoinstall backup-bootfile
Use this command to configure a backup configuration file name to be used when
the Auto Configuration process cannot locate the primary server or configuration
file name provided by a DHCP server at startup.
boot autoinstall backup-bootfile filename
no boot autoinstall backup-bootfile
Cisco Small Business 200E Series Advanced Smart Switch Command Reference26
Page 27
Administration
Auto Configuration
2
Syntax Descriptions
ParameterDescription
filenameThe name of the network configuration file on the backup
TFTP server.
Default
No backup file name is configured.
Command Modes
Privileged Exec
Related Commands
CommandDescription
boot autoinstallEnables or disables the Auto Configuration feature.
boot autoinstall
backup-tftp
show autoinstallDisplays Auto Configuration status information.
Configures the address of a backup TFTP server to be
used when the Auto Configuration process cannot locate
the server or network configuration file name provided by
the DHCP server at startup.
boot autoinstall backup-tftp
Use this command to configure the address of a backup TFTP server to be used
when the Auto Configuration process cannot locate the primary server or
configuration file name provided by the DHCP server at startup. Use the no form of
this command to delete the backup server address.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference27
Page 28
Administration
Auto Configuration
2
Syntax Descriptions
ParameterDescription
server ipThe IP address of a TFTP server.
hostnameThe hostname of the backup TFTP server. The switch must
be configured to use a DNS server if a hostname is
specified.
Default
No backup TFTP server address is configured.
Command Modes
Privileged Exec
Related Commands
CommandDescription
boot autoinstallEnables and disables the Auto Configuration feature.
boot autoinstall
backup-bootfile
show autoinstallDisplays Auto Configuration status information.
Configures a backup configuration file name to be used
when the Auto Configuration process cannot locate the
server or network configuration file name provided by the
DHCP server at startup.
boot autoinstall default-config
Use this command to enable the switch to attempt to download a default network
configuration file when no host-specific configuration file is found during bootup.
Use the no form of this command to disable it.
boot autoinstall default-config
no boot autoinstall default-config
Default
This feature is enabled.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference28
Page 29
Administration
Auto Configuration
2
Command Modes
Privileged Exec
Usage Guidelines
The Auto Configuration feature must be enabled on the switch for this feature to be
operational. See the boot autoinstall command.
Related Commands
CommandDescription
boot autoinstallEnables and disables the Auto Configuration feature.
show autoinstallDisplays Auto Configuration status information.
show autoinstall
Use this command to display the status of the Auto Configuration feature.
show autoinstall
Command Modes
Privileged Exec
Examples
The following shows sample output for the command:
(Switch) #show autoinstall
AutoInstall Mode............................... Started
AutoInstall Backup TFTP Server Address......... Not configured
AutoInstall Backup Boot Filename............... Not configured
AutoInstall State.............................. Waiting for boot options
Related Commands
CommandDescription
boot autoinstallEnables and disables the autoinstall feature.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference29
Page 30
Administration
Bonjour
2
CommandDescription
Bonjour
boot autoinstall
default-config
boot autoinstall
backup-tftp
boot autoinstall
backup-bootfile
Bonjour enables the switch and its services to be discovered by using multicast
DNS (mDNS). Bonjour advertises switch services to the network and answers
queries for service types it supports, simplifying network configuration in small
business environments.
Enables the switch to look for and download a default
network configuration file upon startup when no hostspecific configuration file is found.
Configures the address of a backup TFTP server to be
used when the Auto Configuration process cannot locate
the server or network configuration file name provided by
the DHCP server at startup.
Configures a backup configuration file name to be used
when the Auto Configuration process cannot locate the
server or network configuration file name provided by the
DHCP server at startup.
bonjour run
Use this command to enable Bonjour on the switch. Use the no form of the
command to disable it.
bonjour run
no bonjour run
Default
Bonjour is enabled.
Command Modes
Global Config
Cisco Small Business 200E Series Advanced Smart Switch Command Reference30
Page 31
Administration
Bonjour
2
Usage Guidelines
When bonjour is enabled, the switch advertises the following service types:
•Cisco-specific device description (csco-sb)—This service enables clients to
discover Cisco switches and other products deployed in small business
networks.
•Management user interfaces—This service identifies the management
interfaces available on the switch (HTTP, Telnet, or SSH).
When a Bonjour-enabled switch is attached to a network, any Bonjour client can
discover and get access to the management interface without prior configuration.
A system administrator can use an installed Internet Explorer plug-in to discover
the switch. The web-based interface for this switch shows up as a tab in the
browser.
Bonjour works in both IPv4 and IPv6 networks.
Related Commands
CommandDescription
show bonjourDisplays Bonjour configuration details.
show bonjour
Use this command to show all the info related to Bonjour like on/off Bonjour, RR
TTL, and all the available service types.
show bonjour
Command Modes
Privileged Exec
Examples
The following example shows the output of the show bonjour command.
Port Mirroring enables you to monitor and analyze network traffic on a port or
VLAN by using a network analyzer.
A mirroring session consist of a destination probe port and at least one source
port or VLAN. The external network analyzer can use any of the Ethernet ports as a
probe port. The probe port transmits a mirror copy of the probed traffic to the
network analyzer.
A port configured as a destination port acts as a mirroring port when the session
is operationally active. When the session is not active, the port acts as a normal
port with respect to transmitting traffic.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference32
Page 33
Administration
Port Mirroring
2
monitor session
This command adds a mirrored port (source port) or probe port (destination port)
to a mirroring session. This command can also be used to disable the
administrative mode of the session. The no form of this command removes all the
configuration of this session, including the source and destinations interfaces and
VLAN.
1- 4Four port mirroring sessions can be configured, numbered
1 to 4.
source interfaceThe port or LAG to be mirrored.
rx | txIf the source interface parameter is specified, option rx
can be used to monitor only ingress packets. Option tx can
be used to monitor only egress packets. If no option is
specified, both ingress and egress packets are monitored.
vlan-idThe VLAN ID of the traffic to be monitored.
destination
interface
modeEnables the mirroring session. Use the no form of the
Default
No port is configured to perform mirroring.
The port where data from the monitored port will be
copied to.
command with the mode keyword to disable the session
while leaving all other configured values intact.
Command Modes
Global Config
Usage Guidelines
VLAN mirroring mirrors only the ingress (Rx) traffic only.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference33
Page 34
Administration
Port Mirroring
2
Examples
The following commands configure a mirroring session that copies VLAN 30 traffic
received on port e7 to port e8:
Cable StatusOne of the following states is returned:
•Normal—The cable is working correctly.
•Open—The cable is disconnected or there is a faulty
connector.
•Short—There is an electrical short in the cable.
•Cable Test Failed—The cable status could not be
determined. The cable might be working.
Cable LengthIf this feature is supported by the PHY for the current link
speed, the cable length is displayed as a range between
the shortest estimated length and the longest estimated
length. Note that if the link is down and a cable is attached to
a 10/100 Ethernet adapter, the cable status might display as
Open or Short because some Ethernet adapters leave
unused wire pairs unterminated or grounded. Unknown is
displayed if the cable length could not be determined.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference36
Page 37
Administration
Cable Diagnostics
2
Failure LocationThe estimated distance in meters from end of the cable to
the failure location. The failure location is valid only if the
cable status is Open or Short.
Related Commands
CommandDescription
show fiber-ports
Displays diagnostic information for optical transceivers.
optical
transceiver
show fiber-ports optical-transceiver
Use this command to display diagnostics for optical transceivers.
show fiber-ports optical-transceiver [interface]
Syntax Descriptions
ParameterDescription
interfaceThe port number.
Command Modes
Privileged Exec
Examples
The following example shows output for the command when no port is specified.
Temp - Internally measured transceiver temperatures.
Voltage - Internally measured supply voltage.
Current - Measured TX bias current.
Output Power - Measured optical output power relative to 1mW.
Input Power - Measured optical power received relative to 1mW.
TX Fault - Transmitter fault.
LOS - Loss of signal.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference37
[C][Volt][mA][dBm][dBm]Fault
Page 38
Administration
PoE
2
TEMPInternally measured transceiver temperature.
VoltageInternally measured supply voltage.
CurrentMeasured TX bias current.
Output PowerMeasured TX output power in milliwatts.
Input PowerMeasured RX received power in milliwatts.
TX FaultTransmitter fault.
LOSLoss of signal.
Related Commands
PoE
CommandDescription
show cablestatusDisplays the cable connection status on a selected port.
The following commands configure the Power-over-Ethernet functionality on the
switch.
NOTE These commands are valid only for the SF 200E-24P and SF 200E-48P switches.
lldp med transmit-tlv
Use this command to specify the optional Type Length Values (TLVs) in the LLDP
MED set transmitted in the Link Layer Discovery Protocol Data Units (LLDPDUs) on
a specific port. Use the no form of the command to exclude the specified TLV for
the specified port.
lldp med transmit-tlv [capabilities] [ex-pse] [inventory] [location] [network-policy]
no lldp med transmit-tlv [capabilities] [ex-pse] [inventory] [location] [network-
policy]
Cisco Small Business 200E Series Advanced Smart Switch Command Reference38
Page 39
Administration
PoE
2
Syntax Descriptions
ParameterDescription
capabilitiesIncludes the switch capabilities TLV in LLDP
advertisements.
ex-pseIncludes the extended power sourcing equipment TLV in
LLDP advertisements. This keyword is available only on
switches that support PoE.
inventoryIncludes the switch inventory TLV in LLDP advertisements.
locationIncludes the switch location TLV in LLDP advertisements.
network-policyIncludes the switch network policy TLV in LLDP
advertisements.
Default
No LLDP capabilities are advertised.
Command Modes
Interface Config
Examples
The following example includes the network policy TLV in LLDP advertisements on
port e7.
(Switch) (Interface e7)#lldp med transmit-tlv network-policy
Related Commands
CommandDescription
lldp med
transmit-tlv
Specifies the optional Type Length Values (TLVs) in the
LLDP MED set that are transmitted in the Link Layer
Discovery Protocol Data Units (LLDPDUs) on all ports.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference39
Page 40
Administration
PoE
2
lldp med transmit-tlv all
Use this command to specify the optional Type Length Values (TLVs) in the LLDP
MED set transmitted in the Link Layer Discovery Protocol Data Units (LLDPDUs) for
all ports. Use the no form of the command to exclude the specified TLV for all the
ports.
lldp med transmit-tlv all [capabilities] [ex-pse] [inventory] [location] [network-
policy]
no lldp med transmit-tlv all [capabilities] [ex-pse] [inventory] [location] [network-
policy]
Syntax Descriptions
ParameterDescription
capabilitiesIncludes the switch capabilities TLV in LLDP
advertisements.
ex-pseIncludes the extended power sourcing equipment TLV in
LLDP advertisements. This keyword is available only on
switches that support PoE.
inventoryIncludes the switch inventory TLV in LLDP advertisements.
locationIncludes the switch location TLV in LLDP advertisements.
network-policyIncludes the switch network policy TLV in LLDP
advertisements.
Default
No LLDP capabilities are advertised.
Command Modes
Global Config
Examples
The following example includes the network policy TLV in LLDP advertisements on
all ports.
(Switch) (Config)#lldp med transmit-tlv all network-policy
Cisco Small Business 200E Series Advanced Smart Switch Command Reference40
Page 41
Administration
PoE
2
Related Commands
CommandDescription
lldp med
transmit-tlv
show lldp medDisplays a summary of the current LLDP-MED
Specifies the optional TLVs in the LLDP MED set
transmitted in the Link Layer Discovery Protocol Data Units
(LLDPDUs) on a specific port.
configuration.
poe
Use this command to configure the port as a Power-Sourcing Equipment (PSE)capable interface. Use the no form of the command to configure as a non-PSE
interface.
poe
no poe
Default
PoE is enabled on PoE-capable ports (not applicable to non-PoE ports).
Command Modes
Global Config
Interface Config
Usage Guidelines
Use the command in Global Config mode to enable PSE functionality on all PSEcapable ports. Use the command in Interface Config mode to configure PSE
functionality on a specific port.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference41
Page 42
Administration
PoE
2
Related Commands
CommandDescription
lldp med
transmit-tlv
lldp med
transmit-tlv all
poe power
management
poe power limitSets the method for power management.
poe priorityConfigures the port priority level for the delivery of power
poe
usagethreshold
poe resetConfigures the PoE functionality to reinitialize
poe powereddevice describe
Specifies the TLVs in the LLDP MED set transmitted in the
Link Layer Discovery Protocol Data Units (LLDPDUs) on a
specific port or on all ports.
Sets the power management as dynamic or static.
to an attached device.
Configures the system power usage threshold level at
which a trap is generated and a message is logged.
automatically on encountering a fault condition.
Adds a comment or description of the powered device
type to enable the operator to remember what is attached
to the interface.
show poeDisplays the global configuration, and information about
each device connected to the PSE port(s).
show poe port
configuration
show poe portDisplays per-port PoE status.
Displays per-port PoE configuration.
poe power limit
Use this command to set the power management method. Use the no form of the
command to reset the method to the default.
poe power limit {{dot3af | user-def 3000-16200}} | [lldp-med]}
no poe power limit
Cisco Small Business 200E Series Advanced Smart Switch Command Reference42
Page 43
Administration
PoE
2
Syntax Descriptions
ParameterDescription
dot3afThe maximum power that can be delivered by the PSE
port is limited by the detected IEEE 802.3af class.
user-defThe maximum power that can be delivered by the PSE
port is specified by the user. The value can be in the range
of 3W (3000) to 16.2W (16200).
lldp-medThe maximum power that can be delivered by the PSE
port is limited by the value in LLDP-MED TLVs received
from a powered device. The value specified by the
powered device should be in the range of 3–16.2 watts. If
it is not in the range, then the default value of 16.2 watts is
configured, unless the dot3af is specified or a different
user-defined value is configured.
Modes
Global Config
Interface Config
Default
PoE power is limit by the port. The value is 16.2 watts.
Usage Guidelines
The keywords lldp-med and dot3af, and the keywords lldp-med and user-def,
can be enabled simultaneously. If an LLDP-MED TLV is received from the powered
device, that value is given priority over a dot3af or user-defined value.
If only lldp-med is enabled, and no LLDP-MED TLV is received from the powered
device, then the default value of 16.2 watts is configured.
Related Commands
CommandDescription
poe power
management
Cisco Small Business 200E Series Advanced Smart Switch Command Reference43
Sets the power management as dynamic or static.
Page 44
Administration
PoE
2
CommandDescription
poe power limitSets the method for power management.
poe priorityConfigures the port priority level for the delivery of power
to an attached device.
poe
usagethreshold
show poeDisplays the global configuration, and information about
show poe port
configuration
show poe portDisplays per-port PoE status.
Configures the system power usage threshold level at
which a trap is generated and a message is logged.
each device connected to the PSE port(s).
Displays per-port PoE configuration.
poe power management
Use this command to set the power management as dynamic or static. Use the no
form of the command to reset it to its default value.
poe power management {dynamic-with-priority | static- with-priority}
no poe power management
Syntax Descriptions
ParameterDescription
dynamic-withpriority
Cisco Small Business 200E Series Advanced Smart Switch Command Reference44
Power management is done by the PoE controller. Power
is supplied to devices as long as the consumption is within
the configured limit and priority. There is no pre-allocation
of power. A port with a higher port priority is given
preference when the switch supplies power to multiple
ports. If two or more port priorities are equal, the port with
the lower port number is given preference.
Page 45
Administration
PoE
2
ParameterDescription
static-withpriority
Default
Dynamic-with-priority power management is enabled.
Command Modes
Global Config
Interface Config
Related Commands
CommandDescription
Power management is done by the PoE controller. The
switch pre-allocates power based on the configured
power limit and the priority of the port. A port with a higher
port priority is given preference when the switch supplies
power to multiple ports. If two or more port priorities are
equal, the port with the lower port number is given
preference.
poe power limitSets the method for power management.
poe priorityConfigures the port priority level for the delivery of power
to an attached device.
poe
usagethreshold
show poeDisplays the global configuration, and information about
show poe port
configuration
show poe portDisplays per-port PoE status.
Configures the system power usage threshold level at
which a trap is generated and a message is logged.
each device connected to the PSE port(s).
Displays per-port PoE configuration.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference45
Page 46
Administration
PoE
2
poe powered-device describe
Use this command to add a comment or description of the powered device type
to enable the operator to remember what is attached to the interface. To remove
the description, use the no form of this command. This is applicable to powered
devices attached to the PSE ports on the switch.
NOTE The command can be used in Global Config mode to configure all ports and can be
used in Interface mode to configure a specific port.
poe powered-device describe pd-type
no poe powered-device describe
Syntax Descriptions
ParameterDescription
pd-typeThe type of powered device attached to the interface. The
range is 1–24 characters.
Modes
Global Config
Interface Config
Examples
The following example shows entering into Interface Config mode and adding a
description for port e1.
show poeDisplays the global configuration, and information about
each device connected to the PSE port(s).
show poe port
configuration
Cisco Small Business 200E Series Advanced Smart Switch Command Reference46
Displays per-port PoE configuration.
Page 47
Administration
PoE
2
poe priority
The switch might not be able to supply power to all connected PoE devices. Port
priority determines which ports supply power when adequate power capacity is
not available for all enabled ports. Use this command to configure the port priority
level for the delivery of power to an attached device. Use the no form of the
command to reset the priority value to the default.
NOTE The command can be used in Global Config mode to configure all ports and can be
used in Interface mode to configure a specific port.
poe priority {critical | high | low}
no poe priority
Syntax Descriptions
ParameterDescription
criticalThe port is assigned the highest prioritized when PoE
power requests exceed the available supply.
highThe port is assigned a high priority when PoE power
requests exceed the available supply.
lowThe port is assigned a low priority when PoE power
requests exceed the available supply.
Command Modes
Global Config
Interface Config
Usage Guidelines
For ports that have the same priority level, the lower-numbered port is given
higher priority. For a system delivering peak power to a certain number of devices,
if a new device is attached on a higher-priority port, power to a device on a lowerpriority port is shut down.
Default
All ports are configured with low priority.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference47
Page 48
Administration
PoE
2
CommandDescription
poe power
management
poe power limitSets the method for power management.
poe priorityConfigures the port priority level for the delivery of power
poe
usagethreshold
show poeDisplays the global configuration, and information about
show poe port
configuration
show poe portDisplays per-port PoE status.
Sets the power management as dynamic or static.
to an attached device.
Configures the system power usage threshold level at
which a trap is generated and a message is logged.
each device connected to the PSE port(s).
Displays per-port PoE configuration.
poe reset
Use this command to enable PoE to reinitialize automatically upon encountering a
fault condition. If this is disabled, then administrator intervention is required to
reinitialize the port. A fault condition is reported by the PoE controller in PSE Port
Detection Status parameter. The possible fault conditions are Fault and Other
Fault. Use the no form of the command to remove automatic reinitialization on a
port.
NOTE The command can be used in Global Config mode to configure all ports and can be
used in Interface mode to configure a specific port.
poe reset
no poe reset
Modes
Global Config
Interface Config
Default
PoE auto-reset is enabled.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference48
Page 49
Administration
PoE
2
CommandDescription
show poeDisplays the global configuration, and information about
each device connected to the PSE port(s).
show poe port
configuration
show poe portDisplays per-port PoE status.
Displays per-port PoE configuration.
poe usagethreshold
Use this command to configure the system power usage threshold level at which a
trap is generated and a message is logged.
poe usagethreshold 1-100
no poe usagethreshold
Syntax Descriptions
ParameterDescription
1-100The power threshold percentage of total available system
power.
Default
•PoE usage threshold level is 95%
Command Modes
Global Config
Related Commands
CommandDescription
poe power
management
poe power limitSets the method for power management.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference49
Sets the power management as dynamic or static.
Page 50
Administration
PoE
2
CommandDescription
poe thresholdConfigures the system power usage threshold level at
which a trap is generated and a message is logged.
show poeDisplays the global configuration, and information about
each device connected to the PSE port(s).
show poe port
Displays per-port PoE configuration.
configuration
show poe portDisplays per-port PoE status.
show poe
Use this command to display the global configuration of the switch, and
information about each device connected to the PSE port(s).
show poe
Command Modes
Privileged Exec
Examples
The following shows sample output for the command.
show poeDisplays the global configuration, and information about
Cisco Small Business 200E Series Advanced Smart Switch Command Reference54
each device connected to the PSE port(s).
Page 55
Administration
Switch Management Access Control
CommandDescription
2
show poe port
configuration
show poe port
info
Displays PoE configuration for a specific port or all ports.
Displays PoE status for a specific port or all ports.
Switch Management Access Control
The following commands configure user login information and access settings for
the switch management interfaces. Switch management can be performed
through the web-based interface, a command line interface (CLI), or SNMP.
This section contains the following subsections:
•Authentication Methods
•User Logins and Passwords
•Management Access—General
•HTTP Access
•Telnet Access
•SSH Access
•Console Access
•Management Access Lists
Authentication Methods
ip http authentication
Use this command to specify authentication methods for HTTP server users. To
return to the default, use the no form of this command. The supported methods
are local or RADIUS.
ip http authentication method1 [method2]
no ip http authentication
Cisco Small Business 200E Series Advanced Smart Switch Command Reference55
Page 56
Administration
Switch Management Access Control
Syntax Descriptions
ParameterDescription
method1The primary authentication method to use, local or
method2The secondary authentication method to use if the primary
Default
method1—local authentication
Command Modes
2
RADIUS.
method returns an error, local or RADIUS.
Global Config
Examples
The following example configures HTTP authentication using a RADIUS server
and, if the RADIUS server is not available, using a locally administered user names
and passwords.
(switch) (Config)#ip http authentication radius
Related Commands
CommandDescription
radius server hostConfigures the IP address or DNS for a RADIUS server.
show
authentication
methods
Displays information about the authentication methods.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference56
Page 57
Administration
Switch Management Access Control
login authentication
Use this command to specify the login authentication method for a line (console
and Telnet) access mode. To return to the default list configuration, use the no form
of this command. The supported methods are local, RADIUS, or none.
If two methods of authentication are defined, then the second method is used only
if the first method returns an error—not if there is an authentication denial from the
first method.
login authentication method1 [method2]
no login authentication
Syntax Descriptions
2
ParameterDescription
method1The primary authentication method to use, which can be
local, RADIUS, or none.
method2The secondary authentication method to use if the primary
method returns an error.
Default
method1—local authentication
Command Modes
Line Console Config
Line Telnet Config
Examples
The following example specifies the default authentication method for console
access.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference58
Specifies authentication methods for HTTP server users.
Specifies the login authentication method list for a line
(console and Telnet) access mode.
Page 59
Administration
Switch Management Access Control
User Logins and Passwords
password
The currently logged-in user can use this command to change the password. This
command can be used after the password has aged-out or at any time to change
the user’s password. The user is prompted to enter the old password and the new
password. The change is effective upon the next log-in.
password
Command Modes
Privileged Exec
Related Commands
2
CommandDescription
passwords minlength
passwords agingImplement aging on passwords for local users.
show passwords
configuration
Enforces a minimum password length for local users.
Displays the configured password management settings.
passwords aging
Use this command to implement aging on passwords for local users. When a
user's password expires, the user is prompted to change it before logging in again.
Use the no form of the command to reset it to the default value (180 days). If it is
set to 0, password aging is disabled.
passwords aging 0-365
no passwords aging
Syntax Descriptions
ParameterDescription
0-365The number of days. The range is 0–365.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference59
Page 60
Administration
Switch Management Access Control
Default
aging—180 days
Command Modes
Global Config
Related Commands
CommandDescription
2
passwords minlength
passwordAllows a user to change their password after it has
show passwords
configuration
Enforces a minimum password length for local users.
expired.
Displays the configured password management settings.
passwords min-length
Use this command to enforce a minimum password length for local users. Use the
no form of the command to reset it to its default value.
passwords min-length min-length
no passwords min-length
Syntax Descriptions
ParameterDescription
min-lengthThe minimum number of characters that a password must
Default
min length—8 characters
Command Modes
Global Config
Cisco Small Business 200E Series Advanced Smart Switch Command Reference60
have. The range is 8-64.
Page 61
Administration
Switch Management Access Control
Related Commands
CommandDescription
passwords agingImplement aging on passwords for local users.
passwordAllows a user to change their password after it has
2
expired.
show passwords
configuration
Displays the configured password management settings.
passwords strength-check
Use this command to enable the switch to perform the configured password
strength checks when users log in. The strength checks are configured separately
(see Related Commands). Use the no form of this command to disable password
strength checking.
passwords strength-check
no passwords strength-check
Default
This feature is enabled.
Command Modes
Global Config
Related Commands
CommandDescription
passwords
strength checkusername
passwords
strength excludekeyword
Cisco Small Business 200E Series Advanced Smart Switch Command Reference61
Configures the switch to prevent users from including their
user names in their passwords when they create or
change their password.
Configures the switch to check whether preconfigured
keywords are used in a password when a user attempts to
create or change the password.
Page 62
Administration
Switch Management Access Control
CommandDescription
2
passwords
strength
maximum
repeatedcharacters
Configures the switch to check whether any character in
the password is repeated more that three consecutive
times.
passwords strength check-username
Use this command to prevent users from including their user names in their
passwords when they create or change them.
This security check is enforced only when the passwords strength check feature
is enabled (see the passwords strength-check command).
Use the no form of this command to disable checking for user names in
passwords.
passwords strength check-username
no password strength check-username
Default
This feature is enabled.
Command Modes
Global Config
Usage Guidelines
When you enable this feature, the following warning displays if one or more
currently configured users violates the user name condition.
Warning: Not all user(s) passwords comply with the current password strength
restriction(s).
Related Commands
CommandDescription
passwords
strength excludekeyword
Configures the switch to check whether preconfigured
keywords cisco and ocsic are used in a password
when a user attempts to create or change the password.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference62
Page 63
Administration
Switch Management Access Control
CommandDescription
2
passwords
strength
maximum
repeatedcharacters
passwords
strength-check
Configures the switch to check whether any character in
the password is repeated consecutively more than three
times.
Enables the switch to perform the configured password
strength checks when users log in.
passwords strength exclude-keyword
Configures the switch to check whether preconfigured keywords are used in a
password when a user attempts to create or change the password. The
preconfigured keywords are cisco and ocsic.
This security check is enforced only when the passwords strength check feature
is enabled (see the passwords strength-check command).
Use the no form of this command to disable checking for keyword usage in
passwords.
password strength exclude-keyword
no password strength exclude-keyword
Default
This feature is disabled.
Command Modes
Global Config
Usage Guidelines
When you enable this feature, the following warning displays if one or more
currently configured users violates the keyword strength setting.
Warning: Not all user(s) passwords comply with the current password strength
restriction(s).
Cisco Small Business 200E Series Advanced Smart Switch Command Reference63
Page 64
Administration
Switch Management Access Control
Related Commands
CommandDescription
2
passwords
strength checkusername
passwords
strength
maximum
repeatedcharacters
passwords
strength-check
Configures the switch to prevent users from including their
user names in their passwords when they create or
change them.
Configures the switch to check whether any character in
the password is repeated consecutively more than three
times.
Enables the switch to perform the configured password
strength checks when users log in.
passwords strength maximum repeated-characters
Use this command to configure the switch to check whether any character in the
password is repeated consecutively more than three times.
This security check is enforced only when the passwords strength check feature
is enabled (see the passwords strength-check command).
Use the no form of this command to disable checking for repeated characters in
passwords.
password strength maximum repeated-characters
no password strength maximum repeated-characters
Default
This feature is disabled.
Command Modes
Global Config
Usage Guidelines
When you enable this feature, the following warning displays if one or more
currently configured users violates the maximum repeated characters setting.
Warning: Not all user(s) passwords comply with the current password strength
restriction(s).
Cisco Small Business 200E Series Advanced Smart Switch Command Reference64
Page 65
Administration
Switch Management Access Control
Related Commands
CommandDescription
2
passwords
strength checkusername
passwords
strength excludekeyword
passwords
strength-check
Configures the switch to prevent users from including their
user names in their passwords when they create or
change them.
Configures the switch to check whether preconfigured
keywords are used in a password when a user attempts to
create or change the password.
Enables the switch to perform the configured password
strength checks when users log in.
show loginsession
Use this command to display the current login sessions to the to the switch.
show loginsession {long}
Syntax Descriptions
ParameterDescription
longUse the long parameter to display full-length usernames.
Without this keyword, the usernames are truncated in the
output.
Command Modes
Global Config
Examples
In version 1.0.1.nn:
(switch121D4E)#show loginsession
IDUser NameConnection FromIdle Time Session Time Session Type
-- ------------- -------------------------------- ------------ -----------00 cisco EIA-23200:00:0000:03:49 Serial Port
In version 1.0.2.nn and higher:
(switch122D4E) #
Cisco Small Business 200E Series Advanced Smart Switch Command Reference65
Page 66
Administration
Switch Management Access Control
(switch122D4E) #show loginsession
ID User Name Connection From Idle Time Session Time Session Type Auth Method
PrivilegeThe privilege level of the users. All users are assigned the
Password Aging The number of days before the password expires.
2
AgingExpiry date
highest privilege level (15) by default.
Password
Expiry date
Lockout Indicates True if the user is currently locked out due to an
Related Commands
CommandDescription
show usersDisplays the configured user names and their settings.
The date when the password is scheduled to expire.
aged-out password or False if not locked out.
show users
Use this command to display the management users that are currently accessing
the switch through one of the user interfaces (serial console, Telnet, web, or
SNMP).
show users [long]
Cisco Small Business 200E Series Advanced Smart Switch Command Reference68
Page 69
Administration
Switch Management Access Control
Syntax Descriptions
ParameterDescription
longDisplays the complete user names. Without this keyword,
Command Modes
Privileged EXEC
Examples
The following shows sample output for the command.
Specifies that the password will not be checked to meet
any password criteria configured using the passwords
strength-check commands.
Related Commands
CommandDescription
passwords minlength
passwords agingImplement aging on passwords for local users.
passwordAllows a user to change their password after it has
show usersDisplays the configured user names and their settings.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference71
Enforces a minimum password length for local users.
expired.
Page 72
Administration
Switch Management Access Control
Management Access—General
network mgmt_vlan
Use this command to the configure management VLAN ID. Use the no form of the
command to reset it to the default value (VLAN 1).
network mgmt_vlan 1-4094
no network mgmt_vlan
Syntax Descriptions
ParameterDescription
1-4094The VLAN ID. Access to the management interfaces is
2
restricted to the specified VLAN.
Default
The default VLAN ID for management access is1.
Command Modes
Privileged EXEC
Related Commands
CommandDescription
show networkDisplays configuration settings associated with the
switch's management interface.
show network
Use this command to display configuration settings associated with the switch
management interface.
show network
Command Modes
Privileged Exec
Cisco Small Business 200E Series Advanced Smart Switch Command Reference72
Page 73
Administration
Switch Management Access Control
Usage Guidelines
The management interface is the logical interface used for in-band connectivity
with the switch via any of the front panel ports. The configuration parameters
associated with the switch management interface do not affect the configuration
of the front panel ports through which traffic is switched. The management
interface is always considered to be up, whether or not any member ports are up;
therefore, the show network command will always show Interface Status as Up.
Examples
The following shows sample output for the command
(switch) #show network
Interface Status............................... Always Up
IP Address..................................... 10.131.12.78
The following commands configure user access to the management interface
through HTTP.
ip http port
Use this command to specify the TCP port for use by a web browser to configure
the switch. To use the default TCP port, use the no form of this command.
ip http port 1025-65535
no ip http port
Syntax Descriptions
ParameterDescription
1025-65535The HTTP protocol port number.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference73
Page 74
Administration
Switch Management Access Control
Default
port—80
Command Modes
Privileged Exec
Related Commands
CommandDescription
show ip httpDisplays the HTTP server configuration.
show networkDisplays configuration settings associated with the
2
switch's management interface.
ip http server
Use this command to enable the switch to be configured, monitored, or modified
from a browser. To disable this function use the no form of this command.
ip http server
no ip http server
Default
HTTP access is enabled.
Command Modes
Privileged Exec
Related Commands
CommandDescription
show ip httpDisplays the HTTP server configuration.
show networkDisplays configuration settings associated with the
Cisco Small Business 200E Series Advanced Smart Switch Command Reference74
switch's management interface.
Page 75
Administration
Switch Management Access Control
ip http session soft-timeout
Use this command to configure the soft timeout for HTTP sessions. When this
timeout expires the user will be forced to reauthenticate. This timer begins on
initiation of the web session and is restarted with each access to the switch. Use
the no form of this command to reset the timeout to the defaults.
ip http session soft-timeout 1-60
no ip http session soft-timeout
Syntax Descriptions
ParameterDescription
1- 60The timeout in minutes.
2
Default
timeout—10 minutes
Command Modes
Privileged Exec
Related Commands
CommandDescription
ip http serverEnables the switch to be configured, monitored, or
modified from a browser.
show ip httpDisplays the HTTP server configuration.
show ip http
Use this command to display the HTTP server configuration.
show ip http
Command Modes
Privileged Exec
Cisco Small Business 200E Series Advanced Smart Switch Command Reference75
Page 76
Administration
Switch Management Access Control
Examples
The following shows sample output for the command.
ip http serverEnables the switch to be configured, monitored, or
2
modified from a browser.
ip http session
soft-timeout
Configures the soft timeout for HTTP sessions.
Telnet Access
The following commands configure user access to the management interface and
outbound connections through Telnet.
ip telnet server enable
Use this command to enable the Telnet Server Admin Mode, in which the telnet
command can be used to establish a telnet connection to a remote host.
Use the no form of command to disable the Telnet Server Admin Mode and close
any existing telnet connections to remote hosts.
ip telnet server enable
no ip telnet server enable
Default
Telnet Server Admin Mode is disabled.
Command Modes
Privileged Exec
Cisco Small Business 200E Series Advanced Smart Switch Command Reference76
Page 77
Administration
Switch Management Access Control
Related Commands
CommandDescription
telnetEstablishes a new outbound Telnet connection to a remote
show networkDisplays configuration settings associated with the
show telnetconDisplays Telnet configuration and status information.
telnet
Use this command to establish a new outbound Telnet connection to a remote
host.
2
host.
switch's management interface.
telnet {ip-address | hostname} port [debug] [line] [localecho]
Syntax Descriptions
ParameterDescription
ip addressThe IP address of the Telnet server.
hostnameThe hostname of the Telnet server. Ensure that a DNS
server is configured if a hostname is specified.
portThe logical port number for Telnet communications in the
range of 1025 to 65535.
debug
line
localecho
Displays the currently enabled Telnet options.
Sets the outbound Telnet operational mode as line mode.
By default, the operational mode is character mode.
Enables keystrokes entered on the local device to be
echoed back to the screen immediately.
Defaults
•No ip address or hostname.
•Port—23
Cisco Small Business 200E Series Advanced Smart Switch Command Reference77
Page 78
Administration
Switch Management Access Control
•line—Character mode
•noecho—Disabled
Command Modes
Privileged Exec
Related Commands
CommandDescription
2
ip telnet server
enable
show networkDisplays configuration settings associated with the
show telnetconDisplays Telnet configuration and status information.
Enables Telnet connections to the system and enables the
Telnet Server Admin Mode.
switch's management interface.
telnetcon timeout
Use this command to set the Telnet connection session timeout value in minutes. A
session is active as long as the session has not been idle for the value set. Use the
no form of this command to reset the timeout to the default.
telnetcon timeout 1-160
no telnetcon timeout
Syntax Descriptions
ParameterDescription
1-160The timeout value in minutes.
Default
timeout—5 minutes
Command Modes
Privileged Exec
Cisco Small Business 200E Series Advanced Smart Switch Command Reference78
Page 79
Administration
Switch Management Access Control
Usage Guidelines
When the timeout value is changed, the new value is applied to all active and
inactive sessions immediately. Any sessions that have been idle longer than the
new timeout value are disconnected immediately.
Related Commands
CommandDescription
2
ip telnet server
enable
telnetEstablishes a new outbound Telnet connection to a remote
show networkDisplays configuration settings associated with the
show telnetconDisplays Telnet configuration and status information.
Enables Telnet connections to the system and enables the
Telnet Server Admin Mode.
host.
switch's management interface.
show telnetcon
Use this command to display Telnet configuration and status information, such as
the configured timeout, the number of allowed sessions, and the administrative
mode for making outbound Telnet connections from the switch.
show telnetcon
Command Modes
Privileged Exec
Examples
The following shows sample output for the command.
(Switch) #show telnetcon
Remote Connection Login Timeout (minutes)...... 5
Maximum Number of Remote Connection Sessions... 2
Allow New Telnet Sessions...................... Yes
Telnet Server Admin Mode....................... Disable
Cisco Small Business 200E Series Advanced Smart Switch Command Reference79
Page 80
Administration
Switch Management Access Control
Related Commands
CommandDescription
2
ip telnet server
enable
telnetEstablishes a new outbound Telnet connection to a remote
show networkDisplays configuration settings associated with the
Enables Telnet connections to the system and enables the
Telnet Server Admin Mode.
host.
switch's management interface.
SSH Access
The following commands configure user access to the management interface
through SSH.
copy nvram:sshkey-dsa
Use this command to download a DSA SSH host key. A key cannot be
downloaded while SSH is enabled or sessions are active.
copy url nvram:sshkey-dsa
Command Modes
Privileged EXEC
Related Commands
CommandDescription
crypto key
generate dsa
Generates a DSA key pair for SSH.
copy nvram:sshkey-rsa1
Use this command to download an RSA1 SSH host key. A key cannot be
downloaded while SSH is enabled or sessions are active.
copy url nvram:sshkey-rsa1
Cisco Small Business 200E Series Advanced Smart Switch Command Reference80
Page 81
Administration
Switch Management Access Control
Command Modes
Privileged EXEC
Related Commands
CommandDescription
2
copy
nvram:sshkeyrsa2
crypto key
generate rsa
Downloads an RSA2 SSH host key.
Generates an RSA key pair for SSH.
copy nvram:sshkey-rsa2
Use this command to download an RSA2 SSH host key. A key cannot be
downloaded while SSH is enabled or sessions are active.
copy url nvram:sshkey-rsa2
Command Modes
Privileged EXEC
Related Commands
CommandDescription
copy
nvram:sshkeyrsa1
crypto key
generate rsa
crypto key generate dsa
Use this command to generate a DSA key pair for SSH. The new key files
overwrite any existing generated or downloaded DSA key files. Use the no form of
this command to delete the DSA key files from the device.
crypto key generate dsa
Cisco Small Business 200E Series Advanced Smart Switch Command Reference81
Downloads an RSA1 SSH host key.
Generates an RSA key pair for SSH.
Page 82
Administration
Switch Management Access Control
no crypto key generate dsa
Command Modes
Global Config
Related Commands
CommandDescription
2
copy
nvram:sshkeydsa
Downloads a DSA SSH host key.
crypto key generate rsa
Use this command to generate an RSA key pair for SSH. The new key files
overwrite any existing generated or downloaded RSA key files. Use the no form of
the command to delete the RSA key files from the device.
crypto key generate rsa
no crypto key generate rsa
Command Modes
Global Config
Related Commands
CommandDescription
copy
nvram:sshkeyrsa1
copy
nvram:sshkeyrsa2
Cisco Small Business 200E Series Advanced Smart Switch Command Reference82
Downloads an RSA1 SSH host key.
Downloads an RSA2 SSH host key.
Page 83
Administration
Switch Management Access Control
ip ssh protocol
Use this command to set the available protocol levels (versions) for SSH. SSH
version 1, version 2, or both can be set. The specified level(s) are enabled and any
unspecified level is disabled.
ssh protocol {{1 | 2} | {1 2}}
Default
Version 1 and 2 are set.
Command Modes
Privileged EXEC
Examples
The following example sets protocol level 1 (and unsets level 2 if it was previously
set).
2
(switch) #ip ssh protocol 1
The following example sets both levels:
(switch) #ip ssh protocol 1 2
Related Commands
CommandDescription
ip ssh server
enable
sshcon
maxsessions
sshcon timeoutConfigures the SSH Login Inactivity Timeout in minutes.
show ip sshShows SSH configuration information.
Enables management access through SSH.
Configures the number of remote SSH connections
allowed.
ip ssh server enable
Use this command to enable management access through SSH. Use the no form
of this command to disable access through SSH.
ip ssh server enable
no ip ssh server enable
Cisco Small Business 200E Series Advanced Smart Switch Command Reference83
Page 84
Administration
Switch Management Access Control
Default
SSH access is disabled.
Command Modes
Privileged EXEC
Related Commands
CommandDescription
ip ssh protocolSets or removes protocol levels (versions) for SSH.
2
sshcon
maxsessions
sshcon timeoutConfigures the SSH Login Inactivity Timeout in minutes.
show ip sshShows SSH configuration information.
Configures the number of remote SSH connections
allowed.
sshcon maxsessions
Use this command to configure the number of remote SSH connections allowed.
Use the no form of the command to return the maximum to the default (2 sessions).
sshcon maxsessions 0-2
no sshcon maxsessions
Default
maxsessions—2
Command Modes
Privileged EXEC
Related Commands
CommandDescription
ip ssh server
enable
ip ssh protocolSets or removes protocol levels (versions) for SSH.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference84
Enables management access through SSH.
Page 85
Administration
Switch Management Access Control
CommandDescription
sshcon timeoutConfigures the SSH Login Inactivity Timeout in minutes.
show ip sshShows SSH configuration information.
sshcon timeout
Use this command to set the SSH connection timeout value in minutes. A session
is active as long as the session has not been idle for the value set. Use the no form
of this command to reset the timeout to the default.
sshcon timeout 1-160
no sshcon timeout
Syntax Descriptions
2
ParameterDescription
1-160The timeout value in minutes.
Default
timeout—10 minutes
Command Modes
Privileged Exec
Usage Guidelines
When the timeout value is changed, the new value is applied to all active and
inactive sessions immediately. Any sessions that have been idle longer than the
new timeout value are disconnected immediately.
Related Commands
CommandDescription
ip ssh server
enable
ip ssh protocolSets or removes protocol levels (versions) for SSH.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference85
Enables management access through SSH.
Page 86
Administration
Switch Management Access Control
CommandDescription
2
sshcon
maxsessions
show ip sshShows SSH configuration information.
Configures the number of remote SSH connections
allowed.
show ip ssh
Use this command to display SSH settings.
show ip ssh
Command Modes
Privileged Exec
Examples
The following shows sample output for the command.
Key Generation In Progress: ................... None
Console Access
This section describes the commands you use to configure properties for the
console connection to the switch CLI.
line console
Use this command in Global Config mode to enter the Line (Console) Config Mode,
where you set properties of the console port.
line console
Command Modes
Global Mode
Cisco Small Business 200E Series Advanced Smart Switch Command Reference86
Page 87
Administration
Switch Management Access Control
Related Commands
CommandDescription
serial baudrateSpecifies the communication rate of the console port.
serial databitsSpecifies the number of data bits per character for the
serial paritySets the parity for the console connection.
serial stopbitsSets the number of stop bits for the console connection.
show serialDisplays serial port communication settings.
serial baudrate
2
console connection.
Use this command to specify the communication rate of the console port. The
supported rates are 9600, 38400, and 115200. Use the no form of the command to
reset it to the default value.
serial baudrate {9600 | 38400 | 115200}
no serial baudrate
Default
baud rate—115200
Command Modes
Line (Console) Config Mode
Related Commands
CommandDescription
serial databitsSpecifies the number of data bits per character for the
console connection.
serial paritySets the parity for the console connection.
serial stopbitsSets the number of stop bits for the console connection.
show serialDisplays serial port communication settings.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference87
Page 88
Administration
Switch Management Access Control
serial databits
Use this command to specify the number of data bits per character for the console
connection. Use the no form of the command to reset it to the default value.
serial databits {7 | 8}
no serial databits
Default
Eight data bits per character
Command Modes
Line (Console) Config Mode
Related Commands
2
CommandDescription
serial baudrateSpecifies the communication rate of the console port.
serial paritySets the parity for the console connection.
serial stopbitsSets the number of stop bits for the console connection.
show serialDisplays serial port communication settings.
serial parity
Use this command to set the parity for the console connection. Use the no form of
the command to remove the parity setting.
serial parity {even | odd | none}
no serial parity
Default
parity bits—none
Command Modes
Line (Console) Config Mode
Cisco Small Business 200E Series Advanced Smart Switch Command Reference88
Page 89
Administration
Switch Management Access Control
Related Commands
CommandDescription
serial databitsSpecifies the number of data bits per character for the
serial baudrateSpecifies the communication rate of the console port.
serial stopbitsSets the number of stop bits for the console connection.
show serialDisplays serial port communication settings.
serial stopbits
Use this command to set the number of stop bits for the console connection. Use
the no form of the command to reset it to its default value (1).
2
console connection.
serial stopbits {1 | 2}
no serial stopbits
Default
stop bits—1
Command Modes
Line (Console) Config Mode
Related Commands
CommandDescription
serial databitsSpecifies the number of data bits per character for the
console connection.
serial baudrateSpecifies the communication rate of the console port.
serial paritySets the parity for the console connection.
show serialDisplays serial port communication settings.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference89
Page 90
Administration
Switch Management Access Control
serial timeout
Use this command to specify the maximum time (in minutes) the system waits for
without console activity. A value of 0 indicates that a console can be connected
indefinitely. Use the no form of this command to reset the timeout to the default.
serial timeout 0-160
no serial timeout
Syntax Descriptions
ParameterDescription
1-160The timeout in minutes.
2
Default
timeout—5 minutes
Command Modes
Line Config
Related Commands
CommandDescription
show networkDisplays configuration settings associated with the switch
management interface.
show serialDisplays serial port communication settings.
show serial
Use this command to display serial port communication settings.
show serial
Command Modes
Privileged Exec
Cisco Small Business 200E Series Advanced Smart Switch Command Reference90
Page 91
Administration
Switch Management Access Control
Examples
The following shows sample output for the command:
serviceThe service type: telnet, http, tftp, ssh, or snmp.
priorityPriority for the rule. The range is 1–16.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference91
Page 92
Administration
Switch Management Access Control
ParameterDescription
ip-addressThe source IP address to deny.
maskThe network mask of the source IP address.
prefix-lengthThe number of bits that comprise the source IP address
usernameThe name of a management user.
Default
No users are denied access.
Command Modes
2
prefix. The prefix length must be preceded by a forward
slash (/). The range is 0–32 bits.
Access List Config
User Guidelines
Management access must be retained on at least one interface; i.e., if you deny
management access to all but one interface, you cannot deny access on the last
interface.
Examples
The following example uses the command to allow management access on all the
interfaces except for e1 and e2:
Restricts management access to the serial (console)
interface.
access-list-nameRestricts management access to the specified access list
name.
Default
Management access is not restricted.
Command Modes
Global Config
Examples
The following example uses the management access-class command to restrict
access to an access list named mlist after the access list has been defined:
Cisco Small Business 200E Series Advanced Smart Switch Command Reference93
Page 94
Administration
Switch Management Access Control
Related Commands
CommandDescription
2
management
access-list
deny
permit
show
management
access-list
Defines an access list for management and enters the
access-list configuration mode.
Sets conditions for the management access list.
Displays information about the configured management
access list.
management access-list
Use this command to define an access list for management and to enter the
Access List Config mode. In Access List Config mode, you can configure the
denied or permitted access conditions using the deny and permit commands. To
remove an access list, use the no form of this command.
management access-list access-list-name
no management access-list
Syntax Descriptions
ParameterDescription
access-list-nameThe user-defined name of the access list.
Default
No access list.
Command Modes
Global Config
Cisco Small Business 200E Series Advanced Smart Switch Command Reference94
Page 95
Administration
Switch Management Access Control
Usage Guidelines
This command enters the access-list configuration mode, where the denied or
permitted access conditions with the deny and permit commands must be
defined. If no match criteria are defined, the default is to permit access. If reentering to an access-list context, the new rules are entered at the end of the
access-list. Use the management access-class command to select the active
access-list. The active management list cannot be updated or removed.
Related Commands
CommandDescription
2
management
access-class
deny
permit
Restrict management connections.
Sets conditions for the management access list.
permit
Use this command in Management Access-List Configuration mode to set
conditions for the management access list.
denySets conditions for the management access list.
Restrict management connections.
Defines an access list for management and enters the
access-list configuration mode.
show management access-list
Use this command to display information about the configured management
access list.
show management access-list
Cisco Small Business 200E Series Advanced Smart Switch Command Reference96
Page 97
Administration
Switch Management Access Control
Command Modes
Privileged Exec
Examples
The following example displays the active management access list.
switch#show management access-list a1
--deny interface e5 priority 1
! (Note: all other access implicitly permitted)
Related Commands
CommandDescription
2
management
access-list
Defines an access list for management and enters the
access-list configuration mode.
show management access-class
Use this command to display information about the active management access
list.
show management access-class
Command Modes
Privileged Exec
Examples
The following example displays the management access-list information.
switch#show management access-class
Management access-class is enabled, using access list mlist
Related Commands
CommandDescription
management
access-class
Cisco Small Business 200E Series Advanced Smart Switch Command Reference97
Restrict management connections.
Page 98
Administration
SNTP and Time Settings
SNTP and Time Settings
A system clock is used to provide a network-synchronized time-stamping service
for switch software events such as message logs. You can configure the system
clock manually or configure the switch as an SNTP client that obtains the clock
from a server. This section describes the SNTP and time commands.
This section contains the following subsections:
•Clock Commands
•SNTP Commands
Clock Commands
Use the commands described in this section to view and configure clock settings
when the SNTP feature is not used.
2
clock date
Use this command to set the date and time manually.
clock date dd/mm/yyyy time hh:mm:ss
Syntax Descriptions
ParameterDescription
dd/mm/yyyyThe current date in day:month:year format.
hh:mm:ssThe time in hours:minutes:seconds format.
Defaults
The switch clock initiates with the following values:
•date—01/01/1970
•time—00:00:00
Command Modes
Global Config
Cisco Small Business 200E Series Advanced Smart Switch Command Reference98
Page 99
Administration
SNTP and Time Settings
2
Related Commands
CommandDescription
clock timezoneSets the offset to Coordinated Universal Time (UTC).
show clockDisplays the time and date from the system clock.
clock summer-time
Use this command to enable daylight savings time (DST). Use the no form of the
command to remove the DST configuration.
clock summer-time
no clock summer-time
Default
DST is not configured by default.
Command Modes
Global Config
Related Commands
CommandDescription
clock
summertime date
show clockDisplays the time and date from the system clock.
Sets the summertime offset from the universal
coordinated time (UTC).
clock summertime date
Use this command to set the summertime offset to the UTC. Use the no form of the
command to delete the summertime configuration.
clock summer-time date start-date start-month start-year start-minutes end-date end-
Cisco Small Business 200E Series Advanced Smart Switch Command Reference99
Page 100
Administration
SNTP and Time Settings
2
Syntax Descriptions
ParameterDescription
dateThe day of the month when DST begins. The range is 1–31.
monthThe month when DST begins, specified as the first three
letters by name. For example, enter jan for January.
year The current year. The range is 2000–2097.
hh:mmThe time in hours and minutes. The range for hh is 0–23
and the range for mm is 0–59.
offsetNumber of minutes to add during the summertime. The
range is 1–1440 minutes.
zone acronymAn acronym for the local timezone during DST, up to four
characters. The acronym is for display purposes only.
Default
No summertime offset is configured.
Command Modes
Global Config
Examples
The following example configures a summertime date starting on March 14, 2010
at 2:00 A.M, with an offset of 1 hour, ending on November 7, 2010 at 2:00 A.M. This
example also names this timezone EDT.
(Switch) (Config)#clock summer-time date 14 mar 2010 02:00 7 nov 2010 02:00
offset 60 zone EDT
Related Commands
CommandDescription
clock
summertime
recurring
show clockDisplays the time and date from the system clock.
Cisco Small Business 200E Series Advanced Smart Switch Command Reference100
Sets the summertime offset to UTC recursively every year.
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.