The information in this publication has been carefully checked and is believed to be entirely accurate at the time of
publication. CTC Union Technologies assumes no responsibility, however, for possible errors or omissions, or for any
consequences resulting from the use of the information contained herein. CTC Union Technologies reserves the right
to make changes in its products or product specifications with the intent to improve function or design at any time
and without notice and is not required to update this documentation to reflect such changes.
CTC Union Technologies makes no warranty, representation, or guarantee regarding the suitability of its products for
any particular purpose, nor does CTC Union assume any liability arising out of the application or use of any product
and specifically disclaims any and all liability, including without limitation any consequential or incidental damages.
CTC Union products are not designed, intended, or authorized for use in systems or applications intended to support
or sustain life, or for any other application in which the failure of the product could create a situation where personal
injury or death may occur. Should the Buyer purchase or use a CTC Union product for any such unintended or
unauthorized application, the Buyer shall indemnify and hold CTC Union Technologies and its officers, employees,
subsidiaries, affiliates, and distributors harmless against all claims, costs, damages, expenses, and reasonable attorney
fees arising out of, either directly or indirectly, any claim of personal injury or death that may be associated with such
unintended or unauthorized use, even if such claim alleges that CTC Union Technologies was negligent regarding the
design or manufacture of said product.
TRADEMARKS:
Microsoft is a registered trademark of Microsoft Corp.
HyperTerminal™ is a registered trademark of Hilgraeve Inc.
WARNING:
This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of
the FCC Rules. These limits are designed to provide reasonable protection against harmful interference when the
equipment is operated in a commercial environment. This equipment generates, uses, and can radiate radio
frequency energy and if not installed and used in accordance with the instruction manual may cause harmful
interference in which case the user will be required to correct the interference at his own expense. NOTICE: (1) The
changes or modifications not expressively approved by the party responsible for compliance could void the user's
authority to operate the equipment. (2) Shielded interface cables and AC power cord, if any, must be used in order to
comply with the emission limits.
CISPR PUB.22 Class A COMPLIANCE:
This device complies with EMC directive of the European Community and meets or exceeds the following technical
standard. EN 55022 - Limits and Methods of Measurement of Radio Interference Characteristics of Information
Technology Equipment. This device complies with CISPR Class A.
WARNING:
This is a Class A product. In a domestic environment this product may cause radio interference in which case the user
may be required to take adequate measures.
CE NOTICE
Marking by the symbol CE indicates compliance of this equipment to the EMC directive of the European Community.
Such marking is indicative that this equipment meets or exceeds the following technical standards: EN
55022:2006+A1:2007, Class A, EN55024:2010, and EN60950-1:2006
2
Page 3
2016 CTC Union Technologies Co.,Ltd.
All Rights Reserved
The contents of this document are subject to change without any prior notice.
This manual supports the following models:
MSW-4424C
MSW-4424CS
This document is the current official release manual. Please check CTC Union's website for any updated manual or
contact us by E-mail at [email protected]. Please address any comments for improving this manual or to point out
omissions or errors to [email protected]. Thank you.
3.6.2 Enter Config Interface Mode ........................................................................................................................... 26
3.6.3 Save Configurations ......................................................................................................................................... 27
3.6.4 Restart the Device ............................................................................................................................................ 27
3.6.6 Show System and Software Information ......................................................................................................... 27
3.6.7 Show Running Configurations .......................................................................................................................... 28
3.6.8 Show History Commands ................................................................................................................................. 28
3.6.9 Help .................................................................................................................................................................. 29
3.7.6 > help ............................................................................................................................................................... 30
3.7.10 show commands ............................................................................................................................................ 31
3.8COMMANDS IN EXECMODE .............................................................................................................. 32
3.8.7 # clear ip arp .................................................................................................................................................... 33
3.8.8 # clear ip dhcp detailed statistics ..................................................................................................................... 33
3.8.9 # clear ip dhcp relay statistics .......................................................................................................................... 33
3.8.10 # clear ip dhcp server binding <ip> ................................................................................................................ 33
3.8.11 # clear ip dhcp server binding { automatic | manual | expired } ................................................................... 33
3.8.12 # clear ip dhcp server statistics ...................................................................................................................... 34
3.8.13 # clear ip dhcp snooping statistics ................................................................................................................. 34
4
Page 5
TABLE OF CONTENTS
3.8.14 # clear ip igmp snooping ................................................................................................................................ 34
3.8.15 # clear ip statistics .......................................................................................................................................... 34
3.8.30 # dir ................................................................................................................................................................ 37
3.8.36 # ip dhcp retry interface vlan ......................................................................................................................... 39
3.8.37 # more ............................................................................................................................................................ 39
3.8.38 # ping ip ......................................................................................................................................................... 39
3.8.48 # no port-security shutdown ......................................................................................................................... 42
3.8.49 show commands ............................................................................................................................................ 42
3.9COMMANDS IN CONFIG MODE ........................................................................................................... 42
3.9.4.2 (config-if)# aggregation group ......................................................................................................................................48
3.9.15 (config-if)# flowcontrol { on | off }................................................................................................................. 68
3.9.18.3 (config)# gvrp time .....................................................................................................................................................70
3.9.21 (config)# ip ..................................................................................................................................................... 72
3.9.21.1 (config)# ip arp inspection ..........................................................................................................................................72
3.9.21.2 (config)# ip arp inspection entry interface .................................................................................................................72
3.9.21.3 (config)# ip arp inspection translate ...........................................................................................................................73
3.9.21.4 (config)# ip arp inspection vlan ..................................................................................................................................73
3.9.21.5 (config)# ip arp inspection vlan <in_vlan_list> logging ...............................................................................................73
3.9.21.6 (config)# ip dhcp excluded-address ............................................................................................................................74
3.9.21.7 (config)# ip dhcp pool .................................................................................................................................................74
3.9.21.8 (config)# ip dhcp relay ................................................................................................................................................74
3.9.21.9 (config)# ip dhcp relay information circuit-id format .................................................................................................75
3.9.21.10 (config)# ip dhcp relay information option ...............................................................................................................75
3.9.21.11 (config)# ip dhcp relay information policy {drop | keep |replace} ...........................................................................76
3.9.21.12 (config)# ip dhcp relay information remote-id .........................................................................................................76
3.9.21.13 (config)# ip dhcp relay information remote-id format .............................................................................................76
3.9.21.14 (config)# ip dhcp server ............................................................................................................................................77
3.9.21.15 (config)# ip dhcp snooping .......................................................................................................................................77
3.9.21.16 (config)# ip dhcp snooping table get ........................................................................................................................77
3.9.21.17 (config)# ip dhcp snooping table interval .................................................................................................................78
3.9.21.18 (config)# ip dhcp snooping table put ........................................................................................................................78
3.9.21.19 (config)# ip dhcp snooping table retransmit ............................................................................................................78
3.9.21.20 (config)# ip dhcp snooping vlan ................................................................................................................................78
3.9.21.21 (config)# ip dns proxy ...............................................................................................................................................79
3.9.21.22 (config)# ip helper-address .......................................................................................................................................79
3.9.21.23 (config)# ip http secure-server .................................................................................................................................79
3.9.21.24 (config)# ip http secure-redirect ...............................................................................................................................80
3.9.21.25 (config)# ip igmp host-proxy.....................................................................................................................................80
3.9.21.26 (config)# ip igmp snooping .......................................................................................................................................80
3.9.21.27 (config)# ip igmp snooping vlan ................................................................................................................................81
3.9.21.28 (config)# ip igmp ssm-range .....................................................................................................................................81
3.9.21.29 (config)# ip igmp unknown-flooding ........................................................................................................................81
3.9.21.30 (config)# ip name-server ..........................................................................................................................................81
3.9.21.31 (config)# ip route ......................................................................................................................................................82
3.9.21.32 (config)# ip routing ...................................................................................................................................................82
3.9.21.33 (config)# ip source binding interface ........................................................................................................................83
3.9.21.34 (config)# ip ssh ..........................................................................................................................................................83
3.9.21.35 (config)# ip verify source ..........................................................................................................................................83
3.9.21.36 (config)# ip verify source translate ...........................................................................................................................84
3.9.21.37 (config-if)# ip arp inspection check-type ..................................................................................................................84
3.9.21.38 (config-if)# ip arp inspection check-vlan ...................................................................................................................84
3.9.21.39 (config-if)# ip arp inspection logging ........................................................................................................................84
3.9.21.40 (config-if)# ip arp inspection trust ............................................................................................................................85
3.9.21.41 (config-if)# ip dhcp snooping trust ...........................................................................................................................85
3.9.21.42 (config-if)# ip dhcp relay information subscriber-id <v_line63> ...............................................................................85
3.9.21.43 (config-if)# ip dhcp relay information subscriber-id { none | alias | configured } ....................................................85
3.9.21.44 (config-if)# ip dhcp snooping limit ............................................................................................................................86
3.9.21.45 (config-if)# ip dhcp snooping limit maximum ...........................................................................................................86
3.9.21.46 (config-if)# ip dhcp snooping trust ...........................................................................................................................86
3.9.21.47 (config-if)# ip igmp snooping filter ...........................................................................................................................87
3.9.21.48 (config-if)# ip igmp snooping immediate-leave ........................................................................................................87
3.9.21.49 (config-if)# ip igmp snooping max-groups ................................................................................................................87
3.9.21.50 (config-if)# ip igmp snooping mrouter ......................................................................................................................88
3.9.21.51 (config-if)# ip verify source .......................................................................................................................................88
3.9.21.52 (config-if)# ip verify source limit ...............................................................................................................................88
7
Page 8
TABLE OF CONTENTS
3.9.21.53 (config-if-vlan)# ip address .......................................................................................................................................88
3.9.21.54 (config-if-vlan)# ip dhcp server .................................................................................................................................89
3.9.21.55 (config-if-vlan)# ip igmp snooping ............................................................................................................................89
3.9.21.56 (config-if-vlan)# ip igmp snooping compatibility ......................................................................................................89
3.9.21.57 (config-if-vlan)# ip igmp snooping last-member-query-interval ...............................................................................90
3.9.21.58 (config-if-vlan)# ip igmp snooping priority ...............................................................................................................90
3.9.21.59 (config-if-vlan)# ip igmp snooping querier ...............................................................................................................90
3.9.21.60 (config-if-vlan)# ip igmp snooping query-interval ....................................................................................................90
3.9.21.61 (config-if-vlan)# ip igmp snooping query-max-response-time .................................................................................91
3.9.21.62 (config-if-vlan)# ip igmp snooping robustness-variable ...........................................................................................91
3.9.21.63 (config-if-vlan)# ip igmp snooping unsolicited-report-interval .................................................................................91
3.9.22.3 (config)# ipmc range ...................................................................................................................................................95
3.9.22.4 (config-ipmc-profile)# default range ..........................................................................................................................95
3.9.22.6 (config-ipmc-profile)# range .......................................................................................................................................96
3.9.24.5 (config-if)# lacp role { active | passive }....................................................................................................................103
3.9.24.6 (config-if)# lacp timeout { fast | slow } .....................................................................................................................103
3.9.25 (config)# line ................................................................................................................................................ 103
3.9.25.1 (config)# line .............................................................................................................................................................103
3.9.25.2 (config-line)# do .......................................................................................................................................................104
3.9.25.4 (config-line)# end .....................................................................................................................................................104
3.9.25.9 (config-line)# history size ..........................................................................................................................................106
3.9.26.5 (config)# lldp med datum .........................................................................................................................................110
3.9.26.6 (config)# lldp med fast ..............................................................................................................................................111
3.9.26.7 (config)# lldp med location-tlv altitude ....................................................................................................................111
3.9.26.8 (config)# lldp med location-tlv civic-addr .................................................................................................................112
3.9.26.9 (config)# lldp med location-tlv elin-addr ..................................................................................................................113
3.9.26.10 (config)# lldp med location-tlv latitude ..................................................................................................................113
3.9.26.11 (config)# lldp med location-tlv longitude ...............................................................................................................114
3.9.26.12 (config)# lldp med media-vlan-policy .....................................................................................................................114
3.9.26.14 (config-if)# lldp med media-vlan policy-list ............................................................................................................115
3.9.26.15 (config-if)# lldp med transmit-tlv............................................................................................................................115
3.9.27.1 (config)# logging on ..................................................................................................................................................116
3.9.29 (config)# mac ............................................................................................................................................... 120
3.9.29.1 (config)# mac address-table aging-time ...................................................................................................................120
3.9.29.2 (config)# mac address-table static ............................................................................................................................120
3.9.29.3 (config-if)# mac address-table learning ....................................................................................................................121
3.9.31 (config-if)# mtu ............................................................................................................................................ 121
3.9.34.16 (config-if)# mvr name .............................................................................................................................................140
3.9.35.2 (config)# ntp server ..................................................................................................................................................141
3.9.36.5 (config-if)# port-security maximum ..........................................................................................................................143
3.9.44.11 (config)# snmp-server user .....................................................................................................................................169
3.9.44.12 (config)# snmp-server version ................................................................................................................................170
3.9.44.17 (config-snmps-host)# version .................................................................................................................................172
3.9.52.5 (config)# voice vlan vid .............................................................................................................................................200
3.9.53 (config)# web privilege group ...................................................................................................................... 200
CHAPTER 4. WEB OPERATION & CONFIGURATION .................................................................. 201
4.2.1 Port Status ..................................................................................................................................................... 202
4.2.3 Help System ................................................................................................................................................... 202
4.3.1.1 System Information Configuration .............................................................................................................................203
4.3.1.2 Fan ..............................................................................................................................................................................204
4.3.1.3 System IP ....................................................................................................................................................................204
4.3.1.4 System NTP .................................................................................................................................................................205
4.3.1.5 System Time ...............................................................................................................................................................206
4.3.1.6 System Log Configuration ...........................................................................................................................................207
4.3.3.1 Server .........................................................................................................................................................................210
4.3.3.1.2 Excluded IP ..........................................................................................................................................................210
4.3.3.1.3 Pool .....................................................................................................................................................................211
4.3.4.1.7.1 SNMP System Configuration ........................................................................................................................221
4.3.4.1.7.3 SNMPv3 Community Configuration .............................................................................................................225
4.3.4.1.7.4 SNMPv3 User Configuration ........................................................................................................................225
4.3.4.1.7.5 SNMPv3 Group Configuration .....................................................................................................................226
4.3.4.1.8.2 RMON History Configuration .......................................................................................................................228
4.3.4.2.1 Limit Control .......................................................................................................................................................231
4.3.4.2.2 NAS ......................................................................................................................................................................232
4.3.4.2.3.3 Access Control List .......................................................................................................................................237
4.3.4.2.4 IP Source Guard ..................................................................................................................................................241
4.3.4.2.5.1 Port Configuration .......................................................................................................................................243
4.3.6 Link OAM ....................................................................................................................................................... 250
4.3.6.1 Port Settings ...............................................................................................................................................................250
4.3.8 Spanning Tree ................................................................................................................................................ 253
4.3.11.1.3 Port Filtering Profile ..........................................................................................................................................265
4.3.11.2.3 Port Filtering Profile ..........................................................................................................................................268
4.3.17 MAC Table .................................................................................................................................................... 287
4.3.18.1 Port to Group Mapping ............................................................................................................................................289
4.3.18.2 VID Translation Mapping ..........................................................................................................................................289
4.3.20.1 Global Config ............................................................................................................................................................293
4.3.20.2 Port Config ................................................................................................................................................................294
4.3.21.2 Port Isolation ............................................................................................................................................................295
4.3.22.2.1 Protocol to Group .............................................................................................................................................296
4.3.22.2.2 Group to VLAN ..................................................................................................................................................297
4.3.22.3 IP Subnet-based VLAN ..............................................................................................................................................298
4.3.25.1.1 Port Classification ..............................................................................................................................................309
4.3.25.1.2 Port Shaping ......................................................................................................................................................310
4.2.25.1.3 Port Policing ......................................................................................................................................................311
4.3.25.2.1 Port Scheduler ...................................................................................................................................................313
4.3.25.2.2 Port Shaping ......................................................................................................................................................315
4.3.25.2.3 Port Tag Remarking ...........................................................................................................................................316
4.3.25.3 Port DSCP..................................................................................................................................................................317
4.3.25.7 QoS Control List ........................................................................................................................................................320
4.3.25.8 Storm Control ...........................................................................................................................................................323
4.4.1.1 System Information ....................................................................................................................................................330
4.4.1.2 Power & Fan ...............................................................................................................................................................331
4.4.1.3 System CPU Load ........................................................................................................................................................331
4.4.1.4 System IP Status .........................................................................................................................................................332
4.4.1.5 System Log Information..............................................................................................................................................332
4.4.1.6 System Detailed Log ...................................................................................................................................................333
4.4.2.1 State ...........................................................................................................................................................................333
4.4.2.5 QCL Status ..................................................................................................................................................................335
4.4.3 Link OAM ....................................................................................................................................................... 338
4.4.3.2 Port Status ..................................................................................................................................................................339
4.4.3.3 Event Status ................................................................................................................................................................340
4.4.4.1 Server .........................................................................................................................................................................342
4.4.4.1.3 Declined IP ..........................................................................................................................................................343
4.4.5.2.1 Port Security ........................................................................................................................................................347
4.4.5.2.1.2 Port Status ...................................................................................................................................................348
4.4.5.2.2 NAS ......................................................................................................................................................................349
4.4.5.2.2.2 Port ..............................................................................................................................................................349
4.4.5.2.3 ACL Status ...........................................................................................................................................................350
4.4.5.4.1.2 RMON History Overview ..............................................................................................................................356
4.4.6.1 System Status .............................................................................................................................................................357
4.4.6.2 Port Status ..................................................................................................................................................................358
4.4.6.3 Port Statistics ..............................................................................................................................................................359
4.4.8 Spanning Tree ................................................................................................................................................ 360
4.4.8.1 Bridge Status ..............................................................................................................................................................360
4.4.8.2 Port Status ..................................................................................................................................................................362
4.4.8.3 Port Statistics ..............................................................................................................................................................363
4.4.9.2 MVR Channel Groups .................................................................................................................................................364
4.4.9.3 MVR SFM Information ................................................................................................................................................364
4.4.10.1.1 Status ................................................................................................................................................................365
4.4.10.1.2 Groups Information ...........................................................................................................................................366
4.4.10.2.1 Status ................................................................................................................................................................367
4.4.10.2.2 Groups Information ...........................................................................................................................................368
4.4.11.3 Port Statistics ............................................................................................................................................................370
4.4.14 MAC Table .................................................................................................................................................... 372
4.5.2 Link OAM ....................................................................................................................................................... 375
4.6.4.1 Save ............................................................................................................................................................................377
Thank you for purchasing this product from CTC Union. We hope this product is everything you wanted
and more. Our Product Managers and R&D team have placed a "quality first" motto in our development of
this series of Ethernet switches with the desire of providing a highly stable and reliable product that will
give years of trouble-free operation.
In this chapter we will introduce hardware features of MSW-4424C & MSW-4424CS. In chapter 2,
power installation and bracket installation methods will also be provided. MSW-4424C(S) also offer a wide
range of software features that can be managed using serial console and CLI (command line interface),
Telnet, SSH, HTTP (Web GUI) or SNMP (Simple Network Management Protocol). Chapter 4 will detail all of
the configuration settings by using an easy to point and click Web interface which can be accessed from any
available web browser.
1.1 Product Description
MSW-4424C(S) Series are layer 2+ managed Gigabit Ethernet switches that provide stable and reliable
Ethernet transmission for Carrier Ethernet access switch solution. MSW-4424C(S) are designed in standard
1U 19-inch size and can be mountable in standard 19-inch rack. To offer the best flexibility and scalability
for network deployment, MSW-4424C(S) are equipped with 20 SFP-based 100/1000Mbps dual speed
optical ports, 4 Combo (10/100/1000Mbps RJ-45 or 100/1000Mbps SFP) ports and 4 1/10Gbps dual speed
SFP+ uplink ports
MSW-4424C(S) series optionally incorporates redundant power modules. The supply derives its power
from either an AC power source and/or DC power source. When two modules are installed, they provide
for power redundancy. Fans are located on the rear panel of the device. The immediate fan condition can
be observed via FAN LED on the front panel (See page 13) or via Web management (See page 18).
1.2 Panels
The front of the MSW-4424C(S) contains two power slots. Built-in power module or modules from
factory are varied based on the user’s order. You can have one AC power, one DC power, one AC and one
DC power, two AC power supplies or two DC power supplies. Next to power supplies, 20 SFP-based slots, 4
Combo ports, 4 SFP+ uplink ports, one MGMT (management) port and one console port are provided.
MSW-4424CS also provide additional two ports (1PPS/TOD) for time synchronization function. SFP-based
slots are numbered 1 through 28, from left to right as viewed from the front. The device can be configured
via the MGMT or console port. Right next to the power module on the left is the protective earth grounding
terminal. It is highly recommended that a stable ground be attached to this device so that any surges on
power via LAN ports can be properly and safely shunted to ground.
The MSW-4424C(S) are designed to be placed on the flat desktop or to be mounted in a standardized 19-inch
rack for rack-mount placement. The switch you purchase should come with rack-mounting brackets from the factory
and these brackets are used for rack-mounting installation.
Besides, MSW-4424C(S) are equipped with built-in power and fan modules. Types of power modules available are
AC, DC, AC+DC, two AC and two DC power modules. Fans which are not removable are located on the rear panel of
the device. If you need to repair fan modules, please contact your sales representatives.
In this section, we will provide necessary information about fiber connections, console connection, power
connection and wall-mounting installation. Definitions of LED indicators are also provided at the end of this section.
2.1 Fiber Connections
The MSW-4424C(S) Series utilize SFP modules for fiber transmissions. Each of the fiber ports has an associated
status LED to indicate the presence or absence of fiber link and will also flash when there is Ethernet activity on the
port. For port 1 to port 20, each of SFP cages may insert any standard SFP module and be configured for 100M or
1000M operation. For port 21 to port 24, they are dual media combo ports meaning that you can either use
10/100/1000M RJ-45 or 100/1000M SFP for service connection. For port 25 to port 28, each of SFP cages may insert
any SFP+ module that supports 1/10G Ethernet connectivity. Having SFP+ option for uplink connectivity offers
customers a wide variety of applications for data center, enterprise wiring closet and service provider transport.
Figure 3. Fiber Connections
2.2 MGMT Port Connection
The MSW-4424C(S) have a MGMT (Management) port for in-band management via TCP/IP connectivity. The
MGMT port allows you to access Command Line Interface (CLI) using Telnet or Web management over TCP/IP using
standard web browsers.
When you use the switch for the first time or restore the switch to the factory defaults, you can use RJ-45 cable
to directly connect MGMT port to your management PC. Then, run a Telnet facility or web browser to communicate
with the device over a TCP/IP network using the default IP address 10.1.1.1. For Telnet connection, up to four active
Telnet sessions can access the Switch concurrently. After you successfully login to the switch, you can change the IP
address to the desired one (See Chapter 3 & 4 for setting up new IP address).
Figure 4. MGMT Port Connection
2.3 Console Port Connection
The MSW-4424C(S) have an asynchronous terminal console port for local management via a serial terminal. The
terminal provides management via a CLI (Command Line Interface) which will be familiar to many networking
engineers. For most users, the CLI can be used to initially configure TCP/IP access so that further configuration can be
completed via the GUI (Graphical User Interface) and any web browser.
20
Page 21
CHAPTER 2
INSTALLATION
Pin
Ref.
Definition
Direction
3
RxD
Receive Data
Out towards DTE
6
TxD
Transmit Data
In from DTE
4
SG
Signal Ground
N/A
Pins
DB9
RJ-45
Ref.
Definition
Direction
2 3 RxD
Receive Data
Out MSW-4424C(S) towards DTE
3 6 TxD
Transmit Data
In MSW-4424C from DTE
5 4 SG
Signal Ground
na
8
1
CONSOLE
to PC COM Port
Left: Live line
Right: Neutral line
Middle: Ground
Left: -V
Right: +V
Middle: Frame Ground
Figure 5. Console Port Connection
2.3.1 RJ-45 Pin Assignment
This RJ-45 connector provides an RS-232 DCE (data communication equipment) asynchronous serial connection
for local management.
2.3.2 Accessory Cable
This DB9F to RJ-45 cable provides a connection for the RS-232. This cable is used between the MSW-4424C(S) and
the serial port of terminal.
2.4 Electrical Installation
AC power module is supplied to the MSW-4424C through a standard IEC C14 3-prong receptacle, located on the
front of the module. Any national power cord with IEC C13 line plug may be used to connect AC power to the power
module.
Figure 6. IEC (AC) Power Connector Pin Assignment
MSW-4424C(S) switches also provide DC module for power connection. The user must connect the device only to
DC input source that has an input supply voltage from -36 to -60 VDC. If the power you use is not in this range, the
device might not operate properly and there is great possibility that the device might be damaged.
Figure 7. Terminal Block (DC) Power Connector Pin Assignment
21
Page 22
CHAPTER 2
INSTALLATION
2.5 Rack Mounting
When installing the rack mount brackets, be sure to correctly align the orientation pin. Use the screws provided
in the rack-mounting kit to securely fasten the brackets.
Figure 8. Attaching Rack-Mounting Brackets
Figure 9. The Switch with Rack-Mounting Brackets
Figure 10. Mounting in Rack
22
Page 23
CHAPTER 2
INSTALLATION
LED
Color
Status
Meaning
ACT
Green
On
The switch is active.
Red
On
Alert
Off
The switch does not receive power.
PWR 1
Green
On
Power 1 module is working.
Off
Power 1 module is off.
PWR 2
Green
On
Power 2 module is working.
Off
Power 2 module is off.
FAN
Green
On
Fan is working normally.
Red
On
Fan is working abnormally. This indicates Fan alarm status.
Off
Fan module is off.
1~20
Green
On
Port link is up and works in 100Mbps.
Blinking
Traffic is present.
Off
Port link is down or has no link.
Yellow
On
Port link is up and works in 1000Mbps.
Blinking
Traffic is present.
Off
Port link is down or has no link.
21~24
SFP
Green
On
Port link is up and works in 100Mbps.
Blinking
Traffic is present.
Off
Port link is down or has no link.
Yellow
On
Port link is up and works in 1000Mbps.
Blinking
Traffic is present.
Off
Port link is down or has no link.
21~24
RJ-45
Green
On
Port link is up and works in 100Mbps.
Yellow
On
Port link is up and works in 1000Mbps.
Green
Blinking
Traffic is present.
Green/Yellow
Off
Port link is down or has no link.
25~28
Orange
On
Port link is up and works in 1Gbps.
Blinking
Traffic is present.
Off
Port link is down or has no link.
Blue
On
Port link is up and works in 10Gbps.
Blinking
Traffic is present.
Off
Port link is down or has no link.
Reset to default button
Press and hold the button for 7 seconds and then release to reset
the device to factory default settings.
2.6 LED Indicators & Reset to Default Button
23
Page 24
CHAPTER 3
INTRODUCTION TO CLI
Speed:
115,200
Data:
8 bits
Parity:
None
Stop bits:
1
Flow control:
None
Platform: VCore-III (MIPS32 24KEc) JAGUAR
RAM: 0x80000000-0x88000000 [0x80021798-0x87fe0000 available]
FLASH: 0x40000000-0x40ffffff, 256 x 0x10000 blocks
== Executing boot script in 2.000 seconds - enter ^C to abort
RedBoot> fi lo -a -f managed
Image loaded from 0x80040000-0x80b7c61c
RedBoot> go
Press ENTER to get started
Username: admin
Password:
#
CHAPTER 3. INTRODUCTION TO CLI
3.1 Introduction
The MSW-4424C(S) Series of L2+ Carrier Gigabit Ethernet switches provide a number of
configuration/management methods. The first and very basic is serial console access. This method is also called outof-band management and is only available when a terminal or administrator PC can be physically connected to the
local MSW-4424C(S) Series switch at the CONSOLE port using RJ45 to RS-232 console cable. Accessing the switch via
CONSOLE port allows the user to use CLI (Command Line Interface) to manage and configure the device. The out-ofband management is relatively useful when you lose the network connection to the device.
On the other hand, in-band management enables you to manage the device remotely using the device’s IP
address. Using in-band management enables you to use Telnet console (CLI) or web browser (GUI) to access the
device. If you plan on using in-band management, you need to configure the device’s IP address first before it can be
accessed via a LAN port.
The out-of-band management via console access, using a command line (CLI), is familiar to most network
engineers. For engineers that are not comfortable using CLI, this device can also be managed using any standard Web
Browser in a more user friendly 'point-and-click' method. Therefore, in most configuration scenarios, the console will
only be used to initially configure the IP address, so that the device may be accessed via the other methods which
require working TCP/IP.
After the device has been properly configured for the application and placed into service, a third method of
configuration/management can be employed using Simple Network Management Protocol (SNMP). The operator will
use SNMP management software to manage and monitor the MSW-4424C(S) Series switches on a network. This
requires some configuration of the device to allow SNMP management. In addition, the network management
platform will need to import and compile the proprietary MIB (management information base) file so that the
manager knows "how" to manage the MSW-4424C(S).
3.2 CONSOLE Operation
Use the provided accessory cable to connect the "CONSOLE" port (RJ-45) to the PC terminal communications port
(DB9). Run any terminal emulation program (HyperTerminal, PuTTY, TeraTerm Pro, etc.) and configure the
communication parameters as follows:
From a cold start, the following screen will be displayed. At the "Username" prompt, enter 'admin' with no password.
24
Page 25
CHAPTER 3
INTRODUCTION TO CLI
Mode
Prompt
Enter Method
Exit Method
User mode
>
enable
disable
EXEC mode
#
Enter authorized
username and
password
Exit, logout
Global Config
Mode
(config)#
Enter “configure
terminal” after “#”
End, exit, do logout
Config Interface
Mode
(config-if)#
Specify interface,
interface type and
number after
(config)#
End, exit, do logout
Keyboard
Action
?
Issue “?” to get a list of commands available in the current
mode.
At least specify one option
to complete the command.
3.3 CLI Modes
The Command Line Interface (CLI) is mainly divided into four basic modes; these are User mode, EXEC mode,
Config mode and Config Interface mode. After entering the username and password, you start from the EXEC mode
(prompted with “#”). The commands available in User mode and EXEC mode are limited. For more advanced
configurations, you must enter Config mode or Config Interface mode. In each mode, a question mark (?) at the
system prompt can be issued to obtain a list of commands available for each command mode. The following table
provides a brief overview of modes available in this device.
3.4 Quick Keys
There are several useful quick keys you can use when editing command lines.
3.5 Command Syntax
Commands introduced in this user manual are written using the coherent symbols and easy-to-understand syntax
and style. Although users can issue Help command to complete a desired command in CLI, it is useful to understand
frequently-used symbols and syntax conventions. The following table lists the syntax conventions used in this user
manual together with an example.
This section introduces users how to change the default IP address to the desired one and save the current
running configurations to startup configurations. For detailed introductions to commands, please see section 3.7, 3.8,
3.9.
3.6.1 Configuring IPv4 Address
IP address: 192.168.0. 101
Subnet mask: 255.255.255.0
3.6.2 Enter Config Interface Mode
Enter Port 3’s Config Interface mode.
Note: 1/3 means Ethernet Interface 1, Port 3.
Enter Port 1~3’s Config Interface mode.
Note: 1/1-3 means Ethernet Interface 1, Port 1 to Port 3.
Enter Port 1~3 & Port 5’s Config Interface mode.
Note: 1/1-3,5 means Ethernet Interface 1, Port 1 to Port 3 and Port 5.
26
Page 27
CHAPTER 3
INTRODUCTION TO CLI
# copy running-config startup-config
Building configuration...
% Saving 1469 bytes to flash:startup-config
#
# reload cold
% Cold reload in progress, please stand by.
#
Copyright (C) 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007, 2008, 2009
Free Software Foundation, Inc.
RedBoot is free software, covered by the eCos license, derived from the
GNU General Public License. You are welcome to change it and/or distribute
copies of it under certain conditions. Under the license terms, RedBoot's
source code and full license terms must have been made available to you.
Redboot comes with ABSOLUTELY NO WARRANTY.
RedBoot> fi lo -d managed
Image loaded from 0x80040000-0x80ae54cc
RedBoot> go
Press ENTER to get started
# reload defaults
% Reloading defaults. Please stand by.
# reload defaults keep-ip
% Reloading defaults, attempting to keep VLAN 1 IP address. Please stand by.
# show version
MEMORY
MAC Address
Previous Restart
System Contact
System Name
System Location
System Time
System Uptime
# show running-config
Building configuration...
username admin privilege 15 password none
!
vlan 1
!
!
!
no smtp server
spanning-tree mst name 00-02-ab-00-00-01 revision 0
!
interface GigabitEthernet 1/1
no spanning-tree
!
interface GigabitEthernet 1/2
no spanning-tree
!
interface GigabitEthernet 1/3
no spanning-tree
!
interface GigabitEthernet 1/4
no spanning-tree
!
-- more --, next page: Space, continue: g, quit: ^C
# show history
config t
exit
config t
ip arp ex
exit
> show history
config t
interface GigabitEthernet 1/3
exit
3.6.7 Show Running Configurations
3.6.8 Show History Commands
28
Page 29
CHAPTER 3
INTRODUCTION TO CLI
interface GigabitEthernet 1/1-5
exit
interface GigabitEthernet 1/1-3,5,7
flowcontrol on
exit
show interface * status
disable
show clock detail
show dot1x
show history
# help
Help may be requested at any point in a command by entering
a question mark '?'. If nothing matches, the help list will
be empty and you must backup until entering a '?' shows the
available options.
Two styles of help are provided:
1. Full help is available when you are ready to enter a
command argument (e.g. 'show ?') and describes each possible
argument.
2. Partial help is provided when an abbreviated argument is entered
and you want to know what arguments match the input
(e.g. 'show pr?'.)
(config)# exit
# logout
Press ENTER to get started
# disable
> logout
Press ENTER to get started
Username: admin
Password:
#
# disable
>
3.6.9 Help
Help command can be issued in User, Exec, and Global Config mode to get a hint message describing how to use
“show” command to get help from CLI.
3.6.10 Logout
To close an active terminal session, issue the “logout” command in User or EXEC mode.
3.7 Commands in User Mode
When you successfully login in Command Line Interface, you are in EXEC Mode (prompted with “#”). To enter
User mode, issue “disable” command after # prompt. Then you will be directed to User mode with “>” prompt.
29
Page 30
CHAPTER 3
INTRODUCTION TO CLI
In User mode, only limited commands are available. These commands are used for clearing statistics, entering
Exec mode and pinging the specified destination. To configure a function, you should enter Config mode or Config
Interface mode.
<v_ipv6_addr>: Specify IPv6 address that you want to ping.
[ repeat <count> ]: The number of packets that are sent to the destination IP or host.
[ size <size> ]: The size of the ping packet.
[ interval <seconds> ]: Timeout interval. The ping test is successful only when it receives echo reply from the
destination IP or host within the time specified here.
[ interface vlan <v_vlan_id> ]:
Explanation: To carry out ping tests on the specified destination IPv6 address or host.
3.7.10 show commands
In User mode, “show” commands can be issued to display current status or settings of a certain command. They
will be introduced in Section 3.9 “Commands in Config Mode”.
<0-32>: Specify the current history size. “0” means to disable.
Explanation: Set up terminal history size.
Show: > show terminal
# show terminal
Negation: # no terminal history size
3.8.46 # terminal length
Syntax: # terminal length <0 or 3-512>
Parameters:
<0 or 3-512>: Specify the lines displayed on the screen. “0” means no pausing.
Explanation: Set up terminal length.
Show: > show terminal
# show terminal
Negation: # no terminal length
41
Page 42
CHAPTER 3
INTRODUCTION TO CLI
3.8.47 # terminal width
Syntax: # terminal width <0 or 40-512>
Parameters:
<0 or 40-512>: Specify the width displayed on the screen. “0” means unlimited width.
Explanation: Set up terminal display width.
Show: > show terminal
# show terminal
Negation: # no terminal width
3.8.48 # no port-security shutdown
Syntax: # no port-security shutdown [interface (<port_type>[<v_port_type_list>])]
Explanation: Reopen ports that are shutdown or disabled by Port Security function.
Parameters:
[interface (<port_type>[<v_port_type_list>])]: Specify the port type and port numbers that you want to reopen.
3.8.49 show commands
In Exec mode, “show” commands can be issued to display current status or settings of a certain command. They
will be introduced in Section 3.9 “Commands in Config Mode”.
Explanation: Configure the authentication method for the client.
Parameters:
{ console | telnet | ssh | http }: Specify one of the authentication clients.
{ { local | radius | tacacs } [ { local | radius | tacacs } [ { local | radius | tacacs } ] ] }: Specify one of the
authentication methods for the specified client. At least one method needs to be specified. Users can specify
three methods at most.
local: Use the local user database on the switch for authentication.
radius: Use remote RADIUS server(s) for authentication.
42
Page 43
CHAPTER 3
INTRODUCTION TO CLI
NOTE: Methods that involve remote servers will time out if the remote servers are offline. In this case the next method
is tried. Each method is tried and continues until a method either approves or rejects a user. If a remote server is used
for primary authentication it is recommended to configure secondary authentication as 'local'. This will enable the
management client to login via the local user database if none of the configured authentication servers are alive.
# config t
(config)# access management 1 1 192.168.0.1 to 192.168.0.10 all
# config t
(config)# aaa authentication login console radius
tacacs: Use remote TACACS+ server(s) for authentication.
Example: Set the Console client to use remote RADIUS server(s) for authentication.
Explanation: Configure daylight saving time. This is used to set the clock forward or backward according to the
configurations set for a defined Daylight Saving Time duration. “Recurring” command is used to repeat the
configuration every year.
Parameters:
summer-time <word16>: Specify a description for this day-light setting.
date [ <start_month_var> <start_date_var> <start_year_var> <start_hour_var> <end_month_var>
Explanation: Configure daylight saving time. This is used to set the clock forward or backward according to the
configurations set for a defined Daylight Saving Time duration. “Recurring” command is used to repeat the
configuration every year.
Parameters:
summer-time <word16>: Specify a description for this day-light setting.
Explanation: The time after an EAP Failure indication or RADIUS timeout that a client is not allowed access. This
setting applies to ports running Single 802.1X, Multi 802.1X, or MAC-based authentication. By default, hold time is set
to 10 seconds. The allowed range is 10 - 1000000 seconds.
Parameters:
<10-1000000>: Specify a value between 10 and 1000000 (seconds).
[guest-vlan]: Enable guest VLAN. A Guest VLAN is a special VLAN typically with limited network access.
When checked, the individual ports' ditto setting determines whether the port can be moved into Guest
VLAN. When unchecked, the ability to move to the Guest VLAN is disabled on all ports.
[radius-qos]: Enable RADIUS assigned QoS.
[radius-vlan]: Enable RADIUS VLAN. RADIUS-assigned VLAN provides a means to centrally control the VLAN
on which a successfully authenticated supplicant is placed on the switch. Incoming traffic will be classified to
and switched on the RADIUS-assigned VLAN. The RADIUS server must be configured to transmit special
RADIUS attributes to take advantage of this feature.
<value:1-4095>: Specify the guest VLAN ID. The allowed VLAN ID range is from 1 to 4095.
Negation: (config)# no dot1x guest-vlan
3.9.8.9 (config)# dot1x guest-vlan supplicant
Syntax: (config)# dot1x guest-vlan supplicant
Explanation: Enable Guest VLAN supplicant function. The switch remembers if an EAPOL frame has been received on
the port for the life-time of the port. Once the switch considers whether to enter the Guest VLAN, it will first check if
this option is enabled or disabled. When enabled, the switch does not maintain the EAPOL packet history and allows
clients that fail authentication to access the guest VLAN, regardless of whether EAPOL packets had been detected on
the interface. Clients that fail authentication can access the guest VLAN.
Negation: (config)# no dot1x guest-vlan supplicant
3.9.8.10 (config)# dot1x max-requth-req
Syntax: (config)# dot1x max-reauth-req <value>
54
Page 55
CHAPTER 3
INTRODUCTION TO CLI
# config t
(config)# interface gigabitethernet 1/1-10
(config-if)# dot1x port-control auto
Explanation: The maximum number of times the switch transmits an EAPOL Request Identity frame without receiving
a response before adding a port to the Guest VLAN. The value can only be changed when the Guest VLAN option is
globally enabled. The range is 1 – 255.
Parameters:
<value:1-255>: Specify a value between 1 and 255.
Negation: (config)# no dot1x max-reauth-req
3.9.8.11 (config-if)# dot1x port-control
Syntax: (config-if)# dot1x port-control { force-authorized | force-unauthorized | auto | single | multi | mac-based }
Parameters:
{ force-authorized | force-unauthorized | auto | single | multi | mac-based }: Specify one of the authentication
modes on the selected interfaces. This setting works only when NAS is globally enabled. The following modes are
available:
force-authorized: In this mode, the switch will send one EAPOL Success frame when the port link comes up,
and any client on the port will be allowed network access without authentication.
force unauthorized: In this mode, the switch will send one EAPOL Failure frame when the port link comes
up, and any client on the port will be disallowed network access.
auto (Port-Based 802.1X): This mode requires a dot1x-aware client to be authorized by the authentication
server. Clients that are not dot1x-aware will be denied access.
single (802.1X): In Single 802.1X, at most one supplicant can get authenticated on the port at a time. Normal
EAPOL frames are used in the communication between the supplicant and the switch. If more than one
supplicant is connected to a port, the one that comes first when the port's link comes up will be the first one
considered. If that supplicant doesn't provide valid credentials within a certain amount of time, another
supplicant will get a chance. Once a supplicant is successfully authenticated, only that supplicant will be
allowed access. This is the most secure of all the supported modes. In this mode, the “Port Security” module
is used to secure a supplicant's MAC address once successfully authenticated.
multi (802.1X): In Multi 802.1X, one or more supplicants can get authenticated on the same port at the
same time. Each supplicant is authenticated individually and secured in the MAC table using the “Port Security” module.
mac-based: Unlike port-based 802.1X, MAC-based authentication do not transmit or receive EAPOL frames.
In MAC-based authentication, the switch acts as the supplicant on behalf of clients. The initial frame (any
kind of frame) sent by a client is snooped by the switch, which in turn uses the client's MAC address as both
username and password in the subsequent EAP exchange with the RADIUS server. The 6-byte MAC address
is converted to a string on the following form "xx-xx-xx-xx-xx-xx", that is, a dash (-) is used as separator
between the lower-cased hexadecimal digits. The switch only supports the MD5-Challenge authentication
method, so the RADIUS server must be configured accordingly.
Example: Set Gigabit Ethernt port 1-10’s admin state to “auto”
55
Page 56
CHAPTER 3
INTRODUCTION TO CLI
# config t
(config)# interface gigabitethernet 1/1-10
(config-if)# dot1x radius-vlan
# config t
(config)# interface gigabitethernet 1/1-10
(config-if)# dot1x radius-qos
# config t
(config)# interface gigabitethernet 1/1-10
(config-if)# dot1x guest-vlan
Negation: (config-if)# no dot1x port-control
3.9.8.12 (config-if)# dot1x guest-vlan
Syntax: (config-if)# dot1x guest-vlan
Explanation: Enable the guest VLAN on the selected interfaces.
Parameters: None.
Example: Enable guest VLAN on port 1-10.
Negation: (config-if)# no dot1x guest-vlan
3.9.8.13 (config-if)# dot1x radius-qos
Syntax: (config-if)# dot1x radius-qos
Explanation: Enable RADIUS Assigned QoS on the selected interfaces.
Parameters: None.
Example: Enable RADIUS Assigned QoS on port 1-10.
Negation: (config-if)# no dot1x radius-qos
3.9.8.14 (config-if)# dot1x radius-vlan
Syntax: (config-if)# dot1x radius-vlan
Explanation: Enable RADIUS Assigned VLAN on the selected interfaces.
Parameters: None.
Example: Enable RADIUS Assigned VLAN on port 1-10.
56
Page 57
CHAPTER 3
INTRODUCTION TO CLI
# config t
(config)# interface gigabitethernet 1/1-10
(config-if)# duplex auto
Negation: (config-if)# no dot1x radius-vlan
3.9.8.15 (config-if)# dot1x re-authenticate
Syntax: (config-if)# dot1x re-authenticate
Explanation: Schedules reauthentication to whenever the quiet-period of the port runs out (EAPOL-based
authentication). For MAC-based authentication, reauthentication will be attempted immediately. This command only
has effect for successfully authenticated clients on the port and will not cause the clients to get temporarily
unauthorized.
Syntax: (config)# ip dhcp snooping table get <url>
<url>: Specify the location of tftp server.
Explanation: Get the DHCP Snooping table via the specified TFTP URL.
77
Page 78
CHAPTER 3
INTRODUCTION TO CLI
Show: > show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping table
3.9.21.17 (config)# ip dhcp snooping table interval
Syntax: (config)# ip dhcp snooping table interval <seconds>
<seconds>: Specify check interval in seconds. The allowed range is from 10 to 86400 seconds.
Explanation: Use this command to configure the interval that is used to check the DHCP Snooping table. The switch
checks dynamic entries at the specified intervals and deletes the dynamic entries that the IP address is expired in.
Show: > show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping table
3.9.21.18 (config)# ip dhcp snooping table put
Syntax: (config)# ip dhcp snooping table put <url>
<url>: Backup DHCP Snooping table to the specified location of tftp server.
Explanation: Backup DHCP Snooping table to the specified location of tftp server.
Show: > show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping table
3.9.21.19 (config)# ip dhcp snooping table retransmit
Syntax: (config)# ip dhcp snooping table retransmit <times>
<times>: Specify retry times for sending DHCP Snooping Table to a server. The allowed value is 1 to 5.
Explanation: This command is used to configure retry times for sending DHCP Snooping Table to a server.
Show: > show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping table
3.9.21.20 (config)# ip dhcp snooping vlan
Syntax: (config)# ip dhcp snooping vlan { all | none | [ add | remove | except ] <vlan_list> }
{ all | none | [ add | remove | except ] <vlan_list> }: A single VLAN or a range of VLANs specified here will be
treated as authorized and secure VLANs. Packets from specified VLANs are forwarded normally.
78
Page 79
CHAPTER 3
INTRODUCTION TO CLI
# config t
(config)# ip http secure-server
# config t
(config)# ip dns proxy
Explanation: Configure the allowed VLAN when DHCP Snooping is enabled.
Show: > show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping [ interface ( <port_type> [ <in_port_list> ] ) ]
# show ip dhcp snooping table
3.9.21.21 (config)# ip dns proxy
Syntax: (config)# ip dns proxy
Explanation: Enable DNS (Domain Name System) proxy function.
Example:Enable DNS (Domain Name System) proxy function.
Negation: (config)# no ip dns proxy
3.9.21.22 (config)# ip helper-address
Syntax: (config)# ip helper-address <v_ipv4_ucast>
Explanation: Configure DHCP Relay server IPv4 address.
Parameters:
<v_ipv4_ucast>: Specify DHCP Relay server IPv4 address that is used by the switch’s DHCP relay agent
Negation: (config)# no ip helper-address
3.9.21.23 (config)# ip http secure-server
Syntax: (config)# ip http secure-server
Explanation: Enable the HTTPS operation mode. When the current connection is HTTPS and HTTPS mode operation is
disabled, web browser will automatically redirect to an HTTP connection.
Example: Enable the HTTPS operation mode.
Negation: (config)# no ip http secure-server
Show: # show ip http server secure status
79
Page 80
CHAPTER 3
INTRODUCTION TO CLI
# config t
(config)# ip http secure-redirect
3.9.21.24 (config)# ip http secure-redirect
Syntax: (config)# ip http secure-redirect
Explanation: Enable the HTTPS redirect mode operation. It applies only if HTTPS mode is "Enabled". Automatically
redirects HTTP of web browser to an HTTPS connection when both HTTPS mode and Automatic Redirect are enabled.
Example: Enable HTTPs automatic redirect mode.
Negation: (config)# no ip http secure-redirect
Show: # show ip http server secure status
3.9.21.25 (config)# ip igmp host-proxy
Syntax: (config)# ip igmp host-proxy [ leave-proxy ]
Explanation: When enabled, the switch suppresses leave messages unless received from the last member port in the
group. IGMP leave proxy suppresses all unnecessary IGMP leave messages so that a non-querier switch forwards an
IGMP leave packet only when the last dynamic member port leaves a multicast group.
Parameters:
[leave-proxy]: The parameter is optional. Enable leave-proxy function.
Negation: (config)# no ip igmp host-proxy [leave-proxy]
Show: # show ip igmp snooping detail
3.9.21.26 (config)# ip igmp snooping
Syntax: (config)# ip igmp snooping
Explanation: Globally enable IGMP Snooping feature. When enabled, this device will monitor network traffic and
determine which hosts will receive multicast traffic. The switch can passively monitor or snoop on IGMP Query and
Report packets transferred between IP multicast routers and IP multicast service subscribers to identify the multicast
group members. The switch simply monitors the IGMP packets passing through it, picks out the group registration
information and configures the multicast filters accordingly.
Negation: (config)# no ip igmp snooping
Show: # show ip igmp snooping [ vlan <v_vlan_list> ] [ group-database [ interface ( <port_type>
Explanation: Set up DNS IP address manually or obtain DNS IP address via specific VLAN DHCP server.
Parameters:
<v_ipv4_ucast>: Manually specify unicast IPv4 name server address.
81
Page 82
CHAPTER 3
INTRODUCTION TO CLI
# config t
(config)# ip routing
# config t
(config)# ip route 192.168.1.240 255.255.255.0 192.168.1.254
dhcp [ interface vlan <v_vlan_id> ]: Configure DNS IP address via specific VLAN DHCP server.
Negation: (config)# no ip name-server
Show: > show ip name-server
# show ip name-server
3.9.21.31 (config)# ip route
Syntax: (config)# ip route <v_ipv4_addr> <v_ipv4_netmask> <v_ipv4_gw>
Explanation: Configure a static IP route.
Parameters:
<v_ipv4_addr>: Specify IPv4 address. The IP route is the destination IP network or host address of this route.
Valid format is dotted decimal notation.
<v_ipv4_netmask>: The route mask is a destination IP network or host mask, in number of bits (prefix length). It
defines how much of a network address that must match, in order to qualify for this route. Only a default route
will have a mask length of 0 (as it will match anything).
<v_ipv4_gw>: This is the IP address of the gateway. Valid format is dotted decimal notation. Gateway and
Network must be of the same type.
Example: Add a new ip route with the following settings.
Negation: (config)# no ip route <v_ipv4_addr> <v_ipv4_netmask> <v_ipv4_gw>
Show: > show ip route
# show ip route
3.9.21.32 (config)# ip routing
Syntax: (config)# ip routing
Explanation: Enable IPv4 and IPv6 routing.
Example: Enable IPv4 and IPv6 routing.
Negation: (config)# no ip routing
Show: > show ip route
> show ipv6 route [interface vlan <vlan_list>]
# show ip route
82
Page 83
CHAPTER 3
INTRODUCTION TO CLI
NOTE: SSH is preferred to Telnet, unless the management network is trusted. Telnet passes authentication credentials
in plain text, making those credentials susceptible to packet capture and analysis. SSH provides a secure authentication
method. The SSH in this device uses version 2 of SSH protocol.
# config t
(config)# ip ssh
# show ip route
127.0.0.1/32 via 127.0.0.1 <UP HOST>
224.0.0.0/4 via 127.0.0.1 <UP>
# show ipv6 route interface vlan 1
::1/128 via ::1 <UP HOST>
Explanation: Set this interface to Router port. If IGMP snooping cannot locate the IGMP querier, you can manually
designate a port which is connected to a known IGMP querier (i.e., a multicast router/switch). This interface will then
join all the current multicast groups supported by the attached router/switch to ensure that multicast traffic is passed
to all appropriate interfaces within the switch.
Negation: (config-if)# no ip igmp snooping mrouter
Show: > show ip igmp snooping mrouter [ detail ]
# show ip igmp snooping mrouter [ detail ]
3.9.21.51 (config-if)# ip verify source
Syntax: (config-if)# ip verify source
Explanation: Enable IP Source Guard on this interface
Negation: (config-if)# no ip verify source
Show: > show ip verify source [ interface ( <port_type> [ <in_port_type_list> ] ) ]
# show ip verify source [ interface ( <port_type> [ <in_port_type_list> ] ) ]
3.9.21.52 (config-if)# ip verify source limit
Syntax: (config-if)# ip verify source limit <0-2>
Explanation: Specify the maximum number of dynamic clients that can be learned on a port. The available options are
0, 1, 2. If the port mode is enabled and the maximum number of dynamic clients is equal 0, the switch will only
forward IP packets that are matched in static entries for a given port.
Parameters:
<0-2>: Specify the maximum number of dynamic clients that can be learned on a port.
Negation: (config-if)# no ip verify source limit
Show: > show ip verify source [ interface ( <port_type> [ <in_port_type_list> ] ) ]
# show ip verify source [ interface ( <port_type> [ <in_port_type_list> ] ) ]
Explanation: Eanble DHCP server on this specific VLAN.
Negation: (config-if-vlan)# no ip dhcp server
Show: > show ip dhcp server
# show ip dhcp server
3.9.21.55 (config-if-vlan)# ip igmp snooping
Syntax: (config-if-vlan)# ip igmp snooping
Explanation: Eanble IGMP Snooping on this specific VLAN.
Negation: (config-if-vlan)# no ip igmp snooping
Show: > show ip statistics [ system ] [ interface vlan <v_vlan_list> ] [ icmp ] [ icmp-msg <type> ]
# show ip statistics [ system ] [ interface vlan <v_vlan_list> ] [ icmp ] [ icmp-msg <type> ]
3.9.21.56 (config-if-vlan)# ip igmp snooping compatibility
Syntax: (config-if-vlan)# ip igmp snooping compatibility { auto | v1 | v2 | v3 }
Explanation: Configure IGMP Snooping version used for this specific VLAN.
Parameters:
{ auto | v1 | v2 | v3 }: Specify one of the IGMP Snooping options.
auto: Compatible with Version 1, Version 2, and Version 3.
v1: Compatible with IGMP version 1.
v2: Compatible with IGMP version 2.
89
Page 90
CHAPTER 3
INTRODUCTION TO CLI
v3: Compatible with IGMP version 3.
Negation: (config-if-vlan)# no ip igmp snooping compatibility
3.9.21.57 (config-if-vlan)# ip igmp snooping last-member-query-interval
Syntax: (config-if-vlan)# ip igmp snooping last-member-query-interval <ipmc_lmqi>
Explanation: LMQI stands for Last Member Query Interval and is to configure the maximum time to wait for
IGMP/MLD report memberships on a receiver port before removing the port from multicast group membership. The
allowed range is 0~31744 tenths of a second.
Parameters:
<ipmc_lmqi: 0-31744>: Specify LMQI (Last Member Query Interval) value.
Negation: (config-if-vlan)# no ip igmp snooping last-member-query-interval
3.9.21.58 (config-if-vlan)# ip igmp snooping priority
Syntax: (config-if-vlan)# ip igmp snooping priority <cos_priority>
Explanation: Specify the priority for transmitting IGMP/MLD control frames. By default, priority is set to 0. Allowed
priority values is 0 -7.
Parameters:
<cos_priority: 0-7>: Specify COS for this specific VLAN. The valid range is 0 to 7.
Negation: (config-if-vlan)# no ip igmp snooping priority
3.9.21.59 (config-if-vlan)# ip igmp snooping querier
{ election | address <v_ipv4_ucast> }: Elect the IGMP Snooping querier or use the specified IPv4 unicast address
as a querier.
Explanation: Elect or specify IGMP Snooping querier IP address.
Negation: (config-if-vlan)# no ip igmp snooping querier { election | address }
3.9.21.60 (config-if-vlan)# ip igmp snooping query-interval
Syntax: (config-if-vlan)# ip igmp snooping query-interval <ipmc_qi>
Explanation: Specify IPMC Query interval value.
90
Page 91
CHAPTER 3
INTRODUCTION TO CLI
Parameters:
<ipmc_qi: 1-31744>: Specify IPMC Query interval value. The valid value is 1~31744.
Negation: (config-if-vlan)# no ip igmp snooping query-interval
3.9.21.61 (config-if-vlan)# ip igmp snooping query-max-response-time
Syntax: (config-if-vlan)# ip igmp snooping query-max-response-time <ipmc_qri>
Explanation: Specify IPMC Query Response time value.
Parameters:
<ipmc_qri>: Specify IPMC Query Response time value. The valid value is 1~31744.
Negation: (config-if-vlan)# no ip igmp snooping query-max-response-time
3.9.21.62 (config-if-vlan)# ip igmp snooping robustness-variable
Syntax: (config-if-vlan)# ip igmp snooping robustness-variable <ipmc_rv>
Explanation: The robustness variable (RV) allows tuning for the expected packet loss on a subnet. If a subnet is
susceptible to packet loss, this value can be increased. The RV value must not be zero and should not be one. The
value should be 2 or greater. By default, it is set to 2.
Parameters:
<ipmc_rv: 1-255>: Specify IPMC Robustness Variable value. The valid value is 1~255.
Negation: (config-if-vlan)# no ip igmp snooping robustness-variable
3.9.21.63 (config-if-vlan)# ip igmp snooping unsolicited-report-interval
Syntax: (config-if-vlan)# ip igmp snooping unsolicited-report-interval <ipmc_uri>
Explanation: The Unsolicited Report Interval is the amount of time that the upstream interface should transmit
unsolicited IGMP reports when report suppression/proxy reporting is enabled. The allowed range for URI is 0 -31744
seconds.
Parameters:
<ipmc_uri: 0-31744>: Specify Unsolicited Report Interval value. The valid value is 0~31744.
Negation: (config-if-vlan)# no ip igmp snooping unsolicited-report-interval
91
Page 92
CHAPTER 3
INTRODUCTION TO CLI
3.9.21.64 (config-if-vlan)# ipv6 address
Syntax: (config-if-vlan)# ipv6 address <subnet>
Explanation: Configure IPv6 address for this VLAN interface.
Parameters:
<subnet>: Specify IPv6 address in X:X:X:X::X/<0-128> format.
Negation: (config-if-vlan)# no ipv6 address [ <ipv6_subnet> ]
Show: > show ip interface brief
> show ipv6 interface [ vlan <v_vlan_list> { brief | statistics } ]
# show ip interface brief
# show ipv6 interface [ vlan <v_vlan_list> { brief | statistics } ]
3.9.21.65 (config-if-vlan)# ipv6 mld snooping
Syntax: (config-if-vlan)# ipv6 mld snooping
Explanation: Eanble MLD (Multicast Listener Discovery) Snooping on this specific VLAN.
Negation: (config-if-vlan)# no ipv6 mld snooping
Show: > show ipv6 statistics [ system ] [ interface vlan <v_vlan_list> ] [ icmp ] [ icmp-msg <type> ]
# show ipv6 statistics [ system ] [ interface vlan <v_vlan_list> ] [ icmp ] [ icmp-msg <type> ]
Explanation: LMQI stands for Last Member Query Interval and is to configure the maximum time to wait for
IGMP/MLD report memberships on a receiver port before removing the port from multicast group membership. The
allowed range is 0~31744 tenths of a second.
Parameters:
<ipmc_lmqi: 0-31744>: Specify LMQI (Last Member Query Interval) value.
Negation: (config-if-vlan)# no ipv6 mld snooping last-member-query-interval
Explanation: The robustness variable (RV) allows tuning for the expected packet loss on a subnet. If a subnet is
susceptible to packet loss, this value can be increased. The RV value must not be zero and should not be one. The
value should be 2 or greater. By default, it is set to 2.
Parameters:
<ipmc_rv: 1-255>: Specify IPMC Robustness Variable value. The valid value is 1~255.
Negation: (config-if-vlan)# no ipv6 mld snooping robustness-variable
<profile_desc: line 64>: Additional description for the designated profile in 64 characters.
Explanation: Specify descriptive information for the designated profile.
Example: Provide descriptive information for IPMC profile goldpass.
Negation: (config-ipmc-profile)# no description
Show: #show ipmc profile
#show ipmc profile [ <profile_name> ] [ detail ]
3.9.22.6 (config-ipmc-profile)# range
Syntax: (config-ipmc-profile)# range <entry_name> { permit | deny } [ log ] [ next <next_entry> ]
Parameters:
<entry_name>: Specify an entry name.
{ permit | deny }: Specify the action taken upon receiving the Join/Report frame that has the group address
matches the address range of the rule.
Permit: Group address matches the range specified in the rule will be learned.
Deny: Group address matches the range specified in the rule will be dropped.
[ log ]: Log when matching
[ next <next_entry> ]: Specify next entry used in profile
Explanation: To set action of an entry for a specific IPMC profile.
96
Page 97
CHAPTER 3
INTRODUCTION TO CLI
# config t
(config)# ipv6 mld host-proxy leave-proxy
(config)#
# config t
(config)# ipv6 mld host-proxy
(config)#
Negation: (config-ipmc-profile)# no range <entry_name>
Show: #show ipmc profile
#show ipmc profile [ <profile_name> ] [ detail ]
3.9.23 (config)# ipv6 mld host-proxy
3.9.23.1 (config)# ipv6 mld host-proxy
Syntax: (config)# ipv6 mld host-proxy
Explanation: Enable IPv6 MLD proxy. When MLD proxy is enabled, the switch exchanges MLD messages with the
router on its upstream interface, and performs the host portion of the MLD task on the upstream interface as follows:
When queried, it sends multicast listener reports to the group.
When a host joins a multicast group to which no other host belongs, it sends unsolicited multicast listener
reports to that group.
When the last host in a particular multicast group leaves, it sends an unsolicited multicast listener done
report to the all-routers address (FF02::2) for MLDv1.
Explanation: Enable IPv6 MLD leave proxy. To prevent multicast router from becoming overloaded with leave
messages, MLD snooping suppresses leave messages unless received from the last member port in the group. When
the switch acts as the querier, the leave proxy feature will not function.
Example: Enable IPv6 MLD leave proxy.
Negation: (config)# no ipv6 mld host-proxy leave-proxy
Explanation: Enable MLD Snooping feature globally. When enabled, this device will monitor network traffic and
determine which hosts would like to receive multicast traffic. The switch can passively monitor or snoop on MLD
Listener Query and Report packets transferred between IP multicast routers and IP multicast service subscribers to
identify the multicast group members. The switch simply monitors the IGMP packets passing through it, picks out the
group registration information and configures the multicast filters accordingly.
<ipv6_prefix_length>: Specify prefix length range from 8 to 128.
Explanation: Specify SSM (Source-Specific Multicast) Range. This setting allows the SSM-aware hosts and routers run
the SSM service model for the groups in the address range.
Example: Configure MLD SSM with the ff3e::7728/128 settings.