This document contains proprietary information, which is protected by
copyright. No part of this document may be photocopied, re produced,
or translated into another language without the prior written consent of
Hewlett-Packard.
Microsoft and Windows are U.S. registered trademarks of Microsoft
Corporation. CompactFlash is a U.S. registered trademark of the
CompactFlash Association. AOL Instant Messenger (AIM) is a U.S.
registered trademark of American Online, Inc. Quake is a U.S.
registered trademark of id Software, Inc. ICQ is a U.S. registered
trademark of ICQ, Inc. pcAnywhere is a U.S. trademark of Synamtec
Corporation.
Disclaimer
HEWLETT- PACKARD COMPANY MAKES NO WARRANTY OF
ANY KIND WITH REGARD TO THIS MATERIAL, INCLUDING,
BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PA RTICULAR
PURPOSE. Hewlett-Packard shall not be liable for errors contained
herein or for incidental or consequential damages in connection with
the furnishing, performance, or use of this material.
The only warranties for HP products and services are set forth in the
express warranty statements accompanying such products and services.
Nothing herein should be construed as constituting an additional
warranty. HP shall not be liable for technical or editorial errors or
omissions contained herein.
Hewlett-Packard assumes no responsibility for the use or reliability of
its software on equipment that is not furnished by Hewlett-Packard.
Warranty
See the Customer Support/W arranty booklet included with the product.
A copy of the specific warranty terms applicable to your Hewlett-
Packard products and replacement parts can be obtained from your HP
Sales and Service Office or authorized dealer.
SROS Command Line Interface Reference GuideCLI Introduction
REFERENCE GUIDE INTRODUCTION
This manual provides information about the commands that are available with all of the ProCurve Secure
routers.
If you are new to the SROS Command Line Interface (CLI), take a few moments to review the information
provided in the section which follows (CLI Introduction).
If you are already familiar with the CLI and you need information on a specific command or group of
commands, proceed to Command Descriptions on page 10 of this guide.
CLI INTRODUCTION
This portion of the Command Reference Guide is designed to introduce you to the basic concepts and
strategies associated with using the SROS Command Line Interface (CLI).
Accessing the CLI from your PC
All products using the SROS are initially accessed by connecting a VT100 terminal (or terminal emulator)
CONSOLE port located on the front of the unit using a standard DB-9 (male) to DB-9 (female) serial
to the
cable. Configure the VT100 terminal or terminal emulation software to the following settings:
•9600 baud
•8 data bits
•No parity
•1 stop bit
•No flow control
Note
For more details on connecting to your unit, refer to the Quick Configuration Guides and
Quick Start Guides located on the Secure Router OS Documentation CD provided with
your unit.
Understanding Command Security Levels
The SROS has two command security levels — Basic and Enable. Both levels support a specific set of
commands. For example, all interface configuration commands are accessible only through the Enable
security level. The following table contains a brief description of each level.
SROS Command Line Interface Reference GuideUnderstanding Configuration Modes
LevelAccess by...PromptWith this level you can...
Enable
Note
entering
Basic command security level
as follows:
>
enable
enable
while in the
ProCurve#
To pr event unauthorized users from accessing the configuration functions of your product,
•manage the startup and running
configurations
•use the debug commands
•enter any of the configuration modes
immediately install an Enable-level password. Refer to the Quick Configuration Guides
and Quick Start Guides located on the Secure Router OS Documentation CD provided
with your unit for more information on configuring a password.
Understanding Configuration Modes
The SROS has four configuration modes to organize the configuration commands – Global, Line, Router,
and Interface. Each configuration mode supports a set of commands specific to the configurable
parameters for the mode. For example, all Frame Relay configuration commands are accessible only
through the Interface Configuration mode (for the virtual Frame Relay interface). The following table
contains a brief description of each level.
ModeAccess by...Sample Prompt With this mode you
can...
Global
entering
command security level prompt.
For example:
config
while at the Enable
>enable
config term
#
ProCurve(config)#
•set the system’s
Enable-level
password(s)
•configure the
system global IP
parameters
•configure the SNMP
parameters
•enter any of the
other configuration
modes
Linespecifying a line (console or Telnet)
while at the Global Configuration
mode prompt.
For example:
•Obtain syntax help for a specific command by entering the command, a space, and then
a question mark (?). The CLI displays the range of values and a brief description of the
next parameter expected for that particular command. For example:
SROS Command Line Interface Reference GuidePerforming Common CLI Functions
ShortcutDescription
<Ctrl> + AJump to the beginning of the displayed command line. This shortcut is helpful when using the
no
form of commands (when available). For example, pressing <Ctrl + A> at the following
prompt will place the cursor directly after the
ProCurve(config-eth 0/1)#
<Ctrl> + EJump to the end of the displayed command line. For example, pressing <Ctrl + E> at the
following prompt will place the cursor directly after the
ProCurve(config-eth 0/1)#
<Ctrl> + UClears the current displayed command line. The following provides an example of the
<Ctrl + U> feature:
ProCurve(config-eth 0/1)#
here)
#
:
ip address 192.168.55.6
6
:
ip address 192.168.55.6
ip address 192.168.55.6
(Press <Ctrl + U>
ProCurve(config-eth 0/1)#
auto finishYou need only enter enough letters to identify a command as unique. For example, entering
int t1 1/1
parameters for the specified T1 interface. Entering
but is not necessary.
at the Global configuration prompt provides you access to the configuration
interface t1 1/1
would work as well,
Performing Common CLI Functions
The following table contains descriptions of common CLI commands.
CommandDescription
do
no
copy running-config startup-config
The do command provides a way to execute commands in
other command sets without taking the time to exit the
current and enter the desired one. The following example
shows the
interface configuration while currently in the T1 interface
command set:
do
command used to view the Frame Relay
ProCurve(config)#
ProCurve(config-t1 1/1)#
interfaces fr 7
To undo an issued command or to disable a feature, enter
no
before the command.
For example:
no shutdown t1 1/1
When you are ready to save the changes made to the
configuration, enter this command. This copies your
changes to the unit’s nonvolatile random access memory
(NVRAM). Once the save is complete, the changes are
retained even if the unit is shut down or suffers a power
outage.
SROS Command Line Interface Reference GuideUnderstanding CLI Error Messages
CommandDescription
show running config
debug
undebug all
Caution
The overhead associated with the debug command takes up a large portion of your
Displays the current configuration.
Use the
may be experiencing on your network. These commands
provide additional information to help you better interpret
possible problems. For information on specific debug
commands, refer to the section
Set
To turn off any active debug commands, enter this
command.
debug
on page 20.
command to troubleshoot problems you
Enable Mode Command
product’s resources and at times can halt other processes. It is best to only use the debug
command during times when the network resources are in low demand (non-peak hours,
weekends, etc.).
Understanding CLI Error Messages
The following table lists and defines some of the more common error messages given in the CLI.
MessageHelpful Hints
%Ambiguous command
%Unrecognized Command
%Invalid or incomplete
command
%Invalid input
detected at “^" marker
The command may not be valid in the current command mode, or you may
not have entered enough correct characters for the command to be
recognized. Try using the “?” command to determine your error. See
CLI Shortcuts
The command may not be valid in the current command mode, or you may
not have entered all of the pertinent information required to make the
command valid. Try using the “?” command to determine your error. See
Using CLI Shortcuts
The error in command entry is located where the caret (^) mark appears.
Enter a question mark at the prompt. The system will display a list of
applicable commands or will give syntax information for the entry.
SROS Command Line Interface Reference GuideCommand Descriptions
COMMAND DESCRIPTIONS
This portion of the guide provides a detailed listing of all available commands for the SROS CLI
(organized by command set). Each command listing contains pertinent information including the default
value, a description of all sub-command parameters, functional notes for using the command, and a brief
technology review. To search for a particular command alphabetically, use the Index. To search for
information on a group of commands within a particular command set, use the linked references given
below:
Basic Mode Command Set on page 12
Enable Mode Command Set on page 20
Global Configuration Mode Command Set on page 299
Line (Console) Interface Config Command Set on page 534
Line (Telnet) Interface Config Command Set on page 550
Line (SSH) Interface Config Command Set on page 561
ADSL Interface Config Command Set on page 570
BRI Interface Configuration Command set on page 575
DSX-1 Interface Configuration Command Set on page 591
E1 Interface Configuration Command Set on page 601
Ethernet Interface Configuration Command Set on page 616
G.703 Interface Configuration Command set on page 678
Serial Interface Configuration Command Set on page 685
Modem Interface Configuration Command Set on page 694
T1 Interface Configuration Command Set on page 699
ATM Interface Config Command Set on page 714
ATM Sub-Interface Config Command Set on page 717
BVI Interface Config Command Set on page 786
Frame Relay Interface Config Command Set on page 877
Frame Relay Sub-Interface Config Command Set on page 898
HDLC Command Set on page 969
Loopback Interface Configuration Command Set on page 1031
PPP Interface Configuration Command Set on page 1066
Tunnel Configuration Command Set on page 1144
ISDN Group Config Command Set on page 1204
CA Profile Configuration Command Set on page 1212
Certificate Configuration Command Set on page 1223
Crypto Map IKE Command Set on page 1227
Crypto Map Manual Command Set on page 1239
IKE Client Command Set on page 1250
IKE Policy Attributes Command Set on page 1254
IKE Policy Command Set on page 1260
AS Path List Command Set on page 1271
Route Map Command Set on page 1274
BGP Configuration Command Set on page 1300
BGP Neighbor Configuration Command Set on page 1313
SROS Command Line Interface Reference GuideCommand Descriptions
Community List Command Set on page 1327
Router (RIP) Configuration Command Set on page 1379
Router (OSPF) Configuration Command Set on page 1360
Router (PIM Sparse) Configuration Command Set on page 1375
Quality of Service (QoS) Map Commands on page 1391
DHCP Pool Command Set on page 1406
Radius Group Command Set on page 1425
TACACS+ Group Configuration Command Set on page 1427
Common Commands on page 1429
SROS Command Line Interface Reference GuideBasic Mode Command Set
BASIC MODE COMMAND SET
To activate the Basic mode, simply log in to the unit. After connecting the unit to a VT100 terminal (or
terminal emulator) and activating a terminal session, the following prompt displays:
ProCurve>
The following command is common to multiple command sets and is covered in a centralized section of
this guide. For more information, refer to the section listed below:
exit on page 1437
ping <address> on page 1438
All other commands for this command set are described in this section in alphabetical order.
enable on page 13
logout on page 14
show clock on page 15
show snmp on page 16
show version on page 17
telnet <address> on page 18
traceroute <address> on page 19
SROS Command Line Interface Reference GuideBasic Mode Command Set
enable
Use the enable command (at the Basic Command mode prompt) to enter the Enable Command mode. Use
the disable command to exit the Enable Command mode.
Syntax Description
No subcommands.
Default Values
No default value necessary for this command.
Functional Notes
The Enable Command mode provides access to operating and configuration parameters and should be
password protected to prevent unauthorized use. Use the
Configuration mode) to specify an Enable Command mode password. If the password is set, access to the
Enable Commands (and all other “privileged” commands) is only granted when the correct password is entered.
Refer to
crypto ca authenticate <name>
on page 337 for more information.
enable password
command (found in the Global
Usage Examples
The following example enters the Enable Command mode and defines an Enable Command mode password:
ProCurve>
ProCurve#
ProCurve(config)#
At the next login, the following sequence must occur:
SROS Command Line Interface Reference GuideBasic Mode Command Set
show clock
Use the show clock command to display the sys t em time and date entered using the clock set command.
Refer to clock set <time> <day> <month> <year> on page 63 for more information.
Syntax Description
No subcommands.
Default Values
No default value necessary for this command.
Usage Examples
The following example displays the current time and data from the system clock:
SROS Command Line Interface Reference GuideBasic Mode Command Set
show version
Use the show version command to display the current SROS version information.
Syntax Description
No subcommands.
Default Values
No default value necessary for this command.
Usage Examples
The following is a sample
ProCurve>
ProCurve Secure Router 7203dl
SROS Version: J03.01
Checksum: 4F8DCF96, built on: Tue Dec 21 08:32:18 2004
Boot ROM version J03.01
Checksum: B133, built on: Tue Dec 21 08:32:25 2004
Copyright (c) 2004-2005, Hewlett-Packard, Co.
Platform: ProCurve Secure Router 7203dl
Serial number US449TS058
Flash: 33554432 bytes DRAM: 268435455 bytes
System uptime is 0 days, 0 hours, 22 minutes, 42 seconds
Current system image file:"CFLASH:/SROS.BIZ
Current configuration-file:CFLASH:/startup-config”
Configured system image path:
Primary:"CFLASH:/SROS.BIZ”
Backup:“NONVOL:/SROS.BIZ”
Configured configuration-file path:
Primary:"CFLASH:/startup-config”
Backup:“NONVOL:/startup-config”
SROS Command Line Interface Reference GuideEnable Mode Command Set
ENABLE MODE COMMAND SET
To activate the Enable mode, enter the enable command at the Basic mode prompt. (If an enable password
has been configured, a password prompt will display.) For example:
ProCurve>enable
Password: XXXXXXX
ProCurve#
The following commands are common to multiple command sets and are covered in a centralized section
of this guide. For more information, refer to the section listed below:
exit on page 1437
ping <address> on page 1438
show running-config on page 1440
All other commands for this command set are described in this section in alphabetical order.
autosynch on page 22
clear commands begin on page 24
clock [auto-correct-dst | no-auto-correct-dst] on page 62
clock set <time> <day> <month> <year> on page 63
clock timezone <text> on page 64
configure on page 66
copy commands begin on pa ge 67
debug commands begin on page 80
dir [ * ] on page 147
dir [cflash | flash] [ * ] on page 148
disable on page 149
enable on page 150
erase on page 151
erase file-system cflash on page 152
events on page 153
exception report generate on page 154
logout on page 156
reload [cancel | in <delay>] on page 157
show commands begin on page 158
sip check-sync on page 292
telnet <address> on page 293
terminal length <lines> on page 294
SROS Command Line Interface Reference GuideEnable Mode Command Set
autosynch
Use the autosynch command to force a synchronization of the SROS.BIZ and startup-config files
located in system flash and compact flash memory.
Syntax Description
No subcommands.
Default Values
No default value necessary for this command.
Functional Notes
The AutoSynchTM features configures the system to synchronize the startup-config and SROS.BIZ files
located in the system flash memory and the compact flash card. When ena ble d, the system compares the
two files in the two locations and replaces the files located in the system flash memory with the ones from
the compact flash card (regardless of which set of files is more current). This allows the customer to
maintain the version of the operating system, and the configuration for that operating system, at the
desired level. To accomplish this, a synchronization check is performed on the system any time there is a
change in startup-config or SROS.BIZ on the compact flash card.
The AutoSynch
card containing the desired software (must be renamed from the desired operating system software, such
as J03.01.biz to SROS.BIZ) and startup configuration file (must be named startup-config) into a router
with AutoSynch
secondarily from internal flash). After booting, with AutoSynch
files in system flash memory with the desired files from compact flash.
Caution
TM
feature allows for quick installation and updates of routers by inserting a compact flash
TM
enabled. The ProCurve Secure Routers automatically boot from the compact flash (and
TM
enabled, the router will synchronize the
Deleting the SROS.BIZ and startup-config files from the compact flash card (using the
erase command) deletes the files from the system flash memory as well.
TM
Status commands associated with the AutoSynch
show autosynch-status.
The show version flash SROS.BIZ command opens the specified .biz file and returns the current SROS
version information.
ProCurve>enable
ProCurve#show version flash SROS.BIZ
SROS Command Line Interface Reference GuideEnable Mode Command Set
The show autosynch-status command displays the current AutoSynchTM configuration and the statistics
for the SROS.BIZ and startup-config files (if AutoSynch
TM
is enabled).
ProCurve>enable
ProCurve#show autosynch-status
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear crypto ike sa [policy <policy priority> | remote-id <remote-id>]
Use the clear crypto ike sa command to clear existing IKE security associations (SAs), including active
ones. Use the policy and remote-id options to remove specific SAs.
Syntax Description
policy <policy priority>
remote-id <remote-id>
Removes all IKE SAs associated with the specified policy priority. The policy
priority is assigned using
Removes all IKE SAs associated with the specified IKE remote ID.
payload is sent to the peers prior to deletion of the SA. This command is
preferred to the
<remote-id>]
the same IKE policy but the user wants to delete only the SA to a unique
peer.
clear crypto ike sa [policy <policy priority> | remote-id
command when multiple unique SAs have been created on
crypto ike on page 344
.
Default Values
No default value necessary for this command.
Usage Examples
The following example clears the entire database of IKE SAs (including the active associations):
ProCurve>enable
ProCurve#clear crypto ike sa
The following example clears IKE SAs associated with policy 101:
A delete
ProCurve>enable
ProCurve#clear crypto ike sa policy 101
The following example clears an IKE SA associated with remote-id procurve:
ProCurve>enable
ProCurve#clear crypto ike sa remote-id procurve
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear crypto ipsec sa
Use the clear crypto ipsec sa command to clear existing IPSec security associations (SAs), including
active ones. Variations of this command include the following:
clear crypto ipsec sa
clear crypto ipsec sa entry <ip address> ah <SPI>
clear crypto ipsec sa entry <ip address> esp <SPI>
clear crypto ipsec sa map <map name>
clear crypto ipsec sa peer <ip address>
clear crypto ipsec sa remote-id <remote-id>
Syntax Description
entry
<ip address>
ah
<SPI>
esp
<SPI>
<map name>
map
peer
<ip address>
remote-id <remote id>
Clears only the SAs related to a certain destination IP address.
Clears only a portion of the SAs by specifying the AH (authentication header)
protocol and a security parameter index (SPI). You can determine the correct SPI
value using the
Clears only a portion of the SAs by specifying the ESP (encapsulating security
payload) protocol and a security parameter index (SPI). You can determine the
correct SPI value using the
Clears only the SAs associated with the crypto map name given.
Clears only the SAs associated with the far-end peer IP address given.
Removes all IPSec SAs associated with the specified IPSec remote ID.
show crypto ipsec command.
show crypto ipsec command.
Default Values
No default value necessary for this command.
Usage Examples
The following example clears all IPSec SAs:
ProCurve> enable
ProCurve#clear crypto ipsec sa
The following example clears the IPSec SA used for ESP traffic with the SPI of 300 to IP address
172.27.45.57:
ProCurve> enable
ProCurve#clear crypto ipsec sa entry 172.27.45.57 esp 300
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear dump-core
The clear dump-core command clears diagnostic information appended to the output of the show version
command. This information results from an unexpected unit reboot.
Syntax Description
No subcommands.
Default Values
No default value necessary for this command.
Usage Examples
The following example clears the entire database of IKE SAs (including the active associations):
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear ip bgp [* | <as-number> | <ip address>] [in | out | soft]
Use the clear ip bgp command to clear BGP neighbors as specified.
Syntax Description
*Clears all BGP neighbors.
<as-number>Clears all BGP neighbors with the specified AS number (Range: 1 to 65,535).
<ip address>Clears the BGP neighbor with the specified IP address.
inCauses a “soft” reset inbound with a neighbor, reprocessing routes advertised by
that neighbor.
outCauses a “soft” reset outbound with a neighb or, re-sending advertised routes to
that neighbor.
softCauses a “soft” reset both inbound and outbound.
Default Values
No default value necessary for this command.
Functional Notes
The clear ip bgp command must be issued to re-initialize the BGP process between the peers matching
the given arguments. Most neighbor changes, includ ing changes to prefix-l ist filters, do not take ef fect until
the clear command is issued. A hard reset clears the TCP connection with the specified peers, which
results in clearing the table. This method of clear ing is disruptive and causes peer routers to record a route
flap for each route.
The out version of this command provides a soft reset ou t to occur by causing all routes to be re-sent to
the specified peer(s). TCP connections are not torn down, so this method is less disruptive. Output
filters/policies are re-applied before sending the update.
The in version of this command provides a soft reset in to occur by allowing the router to receive an
updated table from a peer without tearing down the TCP connection. This method is less disruptive and
does not count as a route flap. Currently, all of the peer's routes are stored permanently, even if they are
filtered by a prefix list. The command causes the peer's routes to be reprocessed with any new
parameters.
Usage Examples
The following example clears the information for all peers with an AS number of 101:
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear ip dhcp-server binding [* | <ip address>]
Use the clear ip dhcp-server binding command to clear Dynamic Host Configuration Protocol (DHCP)
server binding entries from the database.
Syntax Description
*Clears all automatic binding entries.
<ip address>Clears a specific binding entry. Enter the source IP address (format is A.B.C.D).
Default Values
No default value necessary for this command.
Functional Notes
A DHCP server binding represents an association betwe en a MAC address and an IP address that was
offered by the unit to a DHCP client (i.e., most often a PC). Clearing a binding allows the unit to offer that
IP address again, should a request be made for one.
Usage Examples
The following example clears a DHCP server binding for the IP address 192.168.47.4:
ProCurve>enable
ProCurve#clear ip dhcp-server binding 192.168.47.4
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear ip igmp group [<group-address> | <interface>]
Use the clear ip igmp group command to clear entries from the Internet Group Management Protocol
(IGMP) tables. If no address or interface is specified, all non-static IGMP groups are cleared with this
command.
Syntax Description
<group-address>Optional.
<interface>Optional.
type slot/port
Specifies the multicast IP address of the multicast group.
Designates the clearing of parameters for a specific interface (in the format
). For example:
eth 0/1
.
Default Values
No default value necessary for this command.
Usage Examples
The following example shows output for the show igmp groups command before and after a
clear ip igmp group command is issued. This example clears the IGMP entry that was registered
dynamically by a host. Interfaces that are statically joined are not cleared:
ProCurve>enable
ProCurve#show ip igmp group s
Group AddressInterfaceUptimeExpiresLast Reporter
172.16.1.50Loopback10001:22:5900:02:46172.23.23.1
172.21.1.1Ethernet0/100:00:1400:02:451.1.1.2
172.31.1.1Loopback10001:22:5900:02:46172.23.23.1
ProCurve#clear ip igmp group
ProCurve#show ip igmp group s
Group AddressInterfaceUptimeExpiresLast Reporter
This version of the command clears all dynamic groups that have the specified output inter face
(Ethernet 0/1):
ProCurve#clear ip igmp group ethernet 0/1
This version of the command clears the specified group on a ll interfaces wher e it is dynamica lly registered:
ProCurve#clear ip igmp group 172.21.1.1
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear ip policy-sessions
Use the clear ip policy-sessions command to clear policy class sessions. You may clear all the sessions or
a specific session. Refer to the show ip policy-sessions for a current session listing. The following lists the
complete syntax for the clear ip policy-sessions commands:
clear ip policy-sessions
clear ip policy-sessions <classname> [ahp | esp | gre | icmp | tcp | udp | <protocol>] <source ip>
<source port><dest ip><dest port>
clear ip policy-sessions <classname> [ahp | esp | gre | icmp | tcp | udp | <protocol>] <source ip>
<classname>Alphanumeric descriptor for identifying the configured access policy (access
policy descriptors are not case-sensitive).
ahp Specifies authentication header protocol (AHP).
esp Specifies encapsulating security payload protocol (ESP).
gre Specifies general routing encapsulation protocol (GRE).
icmp Specifies Internet control message protocol (ICMP) protocol.
tcp Specifies transmission control protocol (TCP).
udp Specifies universal datagram protocol (UDP).
<protocol>Specifies protocol ( va lid range: 0 to 255).
<source ip>Specifies the source IP address (format is A.B.C.D).
<source port>Specifies the source port (in hex format AHP, ESP, and GRE; decimal for all other
protocols).
<dest ip>Specifies the destination IP address (format is A.B.C.D).
<dest port>Specifies the destination port (in hex format for AHP, ESP, and GRE; decimal for
all other protocols).
[destination | source] For NAT sessions, this specifies whether to select a NAT sour ce or NAT
destination session.
<nat ip>For NAT sessions, this specifies the NAT IP address (format is A.B.C.D).
<nat port>For NAT sessions, this specifies the NAT port (in hex format for AHP, ESP, and
GRE; decimal for all other protocols).
Default Values
No default value necessary for this command.
Functional Notes
The second half of this command, beginning with the source IP address may be copied and p asted from a
row in the show ip policy-sessions table for easier use.
SROS Command Line Interface Reference GuideEnable Mode Command Set
Usage Examples
The following example clears the Telnet association (TCP port 23) for policy class pclass1 with source IP
address 172.22.71.50 and destination 172.22.71.130:
ProCurve>enable
ProCurve#clear ip policy-sessions pclass1 tcp 172.22.71.50 23 172.22.71.130 23
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear ip prefix-list <listname>
Use the clear ip prefix-list command to clear the IP prefix list hit count shown in the show ip prefix-list
detail command output. See show ip prefix-list [detail | summary] <listname> on page 235.
Syntax Description
<listname>Specifies hit count statistics of the IP prefix list to clear.
Default Values
No default value necessary for this command.
Usage Examples
The following example clears the hit count statistics for prefix list test:
ProCurve>enable
ProCurve#clear ip prefix-list test
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear ip route [** | <ip address> <subnet mask>]
Use the clear ip route command to remove all learned routes from the IP route table. Static and connec ted
routes are not cleared by this command.
Syntax Description
**Deletes all destination routes.
<ip address>Specifies the IP address of the destination routes to be deleted.
<subnet mask>Specifies the subnet mask of the destina tio n ro ut es to be de let ed
Default Values
No default value necessary for this command.
Usage Examples
The following example removes all learned routes from the route table:
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear lldp neighbors
Use the clear lldp neighbors command to remove all neighbors from this unit’s database. As new local
loop demarcation point (LLDP) packets are received, the database will contain information about
neighbors included in those frames.
Syntax Description
No subcommands.
Default Values
There are no default settings for this command.
Functional Notes
This command generates output indicating the names of any neighbors del eted from the data base and the
name of the interface on which the neighbor was learned.
Usage Examples
The following example clears LLDP neighbor Switch_1 from the Ethernet interface 0/1:
ProCurve>enable
ProCurve#clear lldp neighbors
LLDP: Deleted neighbor “Switch_1” on interface eth 0/1
ProCurve#
<map name>Specifies the name of a defined QoS map.
<sequence number>Specifies one of the map’s defined sequence numbers.
<interface>Specifies an interface for which to clear Qo S map statistics (for just that interface).
Type clear cos map ? for a complete list of applicable interfaces.
Default Values
No default value necessary for this command.
Usage Examples
The following example clears statistics for all defined QoS maps:
ProCurve#clear qos map
The following example clears statistics for all entries in the priority QoS map:
ProCurve#clear qos map priority
The following example clears statistics in entry 10 of the priority QoS map:
ProCurve#clear qos map priority 10
The following example clears QoS statistics for a specified interface:
ProCurve#clear qos map interface frame-relay 1
Note
The clear counters command clears ALL interface statistics (including QoS map interface
statistics).
Use the clear spanning-tree detected-protocols command to restart the protocol migration process.
Syntax Description
interfaceOptional.
<interface id>Optional.
Choose the Ethernet interface.
Enter a valid interface ID (e.g.,
0/1
for Ethernet 0/1).
Default Values
No default value necessary for this command.
Functional Notes
The ProCurve Secure Router has the ability to operate using the rapid spanning-tree protocol or the legacy
802.1D version of spanning-tree. When a BPDU (bridge protocol data unit) of the legacy version is
detected on an interface, the ProCurve Secure Router automatically regresses to using the 802.1D
spanning-tree protocol for that interface. Issue the clear spanning-tree detected-protocols command to
return to rapid spanning-tree operation.
Usage Examples
The following example re-initiates the protocol migration process on eth 0/2:
ProCurve>enable
ProCurve#clear spanning-tree det ected-protocols interface ethernet 0/2
The following example re-initiates the protocol migration process on all interfaces:
SROS Command Line Interface Reference GuideEnable Mode Command Set
clear user [console <user number> | ssh <user number> |
telnet <user number>]
Use the clear user command to detach a user from a given line.
Syntax Description
console <user number> Detaches a specific console user. Valid range is 0 to 1.
ssh <user number>Detaches a specific secure shell (SSH) user. Valid range is 0 to 4.
telnet <user number>Detaches a specific Telnet user. Valid range is 0 to 5.
Default Values
No default value necessary for this command.
Usage Examples
The following example detaches the console 1 user:
SROS Command Line Interface Reference GuideEnable Mode Command Set
clock [auto-correct-dst | no-auto-correct-dst]
The clock auto-correct-dst command allows the unit to automatically correct for Daylight Saving Time
(DST). Use the clock no-auto-correct-dst command to disable this feature.
Syntax Description
auto-correct-DSTConfigures the unit to automatically correct for DST.
no-auto-correct-DSTDisables
Default Values
By default DST correction takes place automatically.
Functional Notes
Depending on the clock timezone chosen (see clock timezone <text> on page 64 for more information)
one-hour DST correction may be enabled automatically. You may override this default using this
command.
DST correction.
Usage Examples
The following example allows for automatic DST correction:
ProCurve>enable
ProCurve#clock auto-correct-dst
The following example overrides the one-hour offset for DST:
ProCurve>enable
ProCurve#clock no-auto-correct-dst
SROS Command Line Interface Reference GuideEnable Mode Command Set
clock set <time> <day> <month> <year>
Use the clock set command to configure the system software clock. For the command to be valid, all fields
must be entered. See the Usage Example below for an example.
Syntax Description
<time>Sets the time (in 24-hr format) of the system software clock in the format
HH:MM:SS (hours:minutes:seconds).
<day>Sets the current day of the month (Range: 1 to 31).
<month>Sets the current month (Range: January to December). You need only enter
enough characters to make the entry unique. This entry is not case-sensitive.
<year>Sets the current year (Range: 2000 to 2100).
Default Values
No default value necessary for this command.
Usage Examples
The following example sets the system software clock for 3:42 pm, August 22 2004:
ProCurve>enable
ProCurve#clock set 11:22:00 07 Au 2005
SROS Command Line Interface Reference GuideEnable Mode Command Set
clock timezone <text>
The clock timezone command sets the unit’s internal clock to the timezone of your choice. This setting is
based on the difference in time (in hours) between Greenwich Mean Time (GMT) or Central Standard
Time (CST) and the timezone for which you are setting up the unit. Use the no form of this command to
disable this feature.
Syntax Description
<text> Specifies the difference in time (in hours) between Greenwich Mean Time (GMT)
or Central Standard Time (CST) and the timezone for which you are setting up the
unit.
Default Values
No default value is necessary for this command.
Note
Depending on the clock timezone chosen, one-hour Daylight Savings Time (DST)
correction may be enabled automatically. See clock [auto-correct-dst |
no-auto-correct-dst] on page 62 for more information.
Functional Notes
The following list shows sample cities and their timezone codes.
SROS Command Line Interface Reference GuideEnable Mode Command Set
configure
Use the configure command to enter the Global Configuration mode or to configure the system from
memory. See Global Configuration Mode Command Set on page 299 for more information.
Syntax Description
terminalEnters the Global Configuration mode.
memoryConfigures the active system with the commands located in the default
configuration file stored in flash memory.
networkConfigures the system from a TFTP network host.
overwrite-networkOverwrites flash memory from a TFTP network host.
Default Values
No default value necessary for this command.
Usage Examples
The following example enters the Global Configuration mode from the Enable Command mode:
SROS Command Line Interface Reference GuideEnable Mode Command Set
copy [cflash | flash] <filename> boot
Use the copy boot commands to copy the specified file (located in flash memory or on the compact flash
card) to the Boot ROM.
Syntax Description
cflashSpecifies the memory location for the file to copy as compact flash memory.
flashSpecifies the memory location for the file to copy as flash memory.
<filename>Specifies the name of the source file to copy.
bootSpecifies the destination memory location for the file copy as the Boot ROM.
Default Values
No default value necessary for this command.
Functional Notes
Updates to the Boot ROM are required periodically to enhance and expand the router’s operation. The
Boot Code can now be updated from within the Command Line Interfa ce (CLI) (beginning with software
release J03.01) using the copy boot command.
Usage Examples
The following example copies the file J03_01-boot.biz (located on the compact flash card) to the
Boot ROM:
Upgrading boot code is a critical process that cannot be interrupted. If
something were to happen and the process was not able to be completed, it
would render your unit inoperable. It is for this reason that during a
bootcode upgrade, all other system tasks will be halted. This means packets
will not be routed, and all console sessions will not respond during the
upgrade process. Once the process finishes, the system will function as it
did before. This process will take approximately 20 seconds. DO NOT REMOVE
COMPACT FLASH DURING THIS OPERATION!!
Do you want to proceed? [yes/no]y
WARNING!! A bootcode upgrade has been initiated. Your session will become
nonresponsive for the duration of the upgrade (approx. 20 seconds) . A message
will be sent when the upgrade is completed.
Bootcode upgrade process done. Your session should function normally.
Reading 318189 bytes of code, stand by...
Image is compressed, inflating......................................
<filename>S pecifies the na me of the file (located on the comp act flash card) to copy. The
asterisk (*) can be used as a wildcard to specify a pattern for erasing multiple
files. When a wildcard is specified, only files matching the listed pattern are
copied. When using a wildcard, leave the destination filename blank because
the source files are copied identically (including the filename) to the
destination. You cannot use a wildcard when the destination is
startup-config.
cflash <filename>Specifies the destination memory location for the file copy as compact flash
memory and specifies the filename.
flash <filename>Specifies the destination memory location for the file copy as flash memory
and specifies the filename.
startup-configReplaces the prima ry startup-co nfiguration file with a copy of the specified file.
tftpSpecifies sending the file using the trivial file transfer protocol (TFTP). After
entering copy cflash XXXX tftp, the SROS prompts for the following
information:
Address of remote host:Specifies the IP address of the TFTP server.
Destination filename:Specifies the filename to use when storing the
copied file on the TFTP server. (The file will be
placed in the default directory established by
the TFTP server.)
xmodemSends the specified file (using the XMODEM protocol) to the terminal
connected to the Console port.
Default Values
No default value necessary for this command.
Usage Examples
The following example copies the file myfile.biz (located on the compact flash card) to flash memory
(naming the new file newfile.biz):
SROS Command Line Interface Reference GuideEnable Mode Command Set
The following example creates a copy of the file myfile.biz (located on the compact flash card), names the
new file newfile.biz, and places the new file on the installed compact flash card:
The following example copies the file myfile.biz (located on the compact flash card) to the specified TFTP
server:
ProCurve>enable
ProCurve#copy cflash tftp
Address of remote host?10.200.2.4
Source filename myfile.biz
Destination filename myfile.biz
Initiating TFTP transfer ...
Received 45647 bytes.
Transfer Complete!
The following example copies the file myfile.biz (located on the compact flash card) to the connected
terminal using XMODEM protocol:
ProCurve>enable
ProCurve#copy cflash xmodem
Source filename myfile.biz
Begin the Xmodem transfer now...
Press CTRL+X twice to cancel
CCCCCC
The SROS is now ready to transmit the file on the CONSOLE port (using the XMODEM protocol). The next
step in the process may differ depending on the type of terminal emulation software you are using. For
HyperTerminal, you will now select Transfer > Receive File and select the destination. Once the transfer
is complete, information similar to the following is displayed:
SROS Command Line Interface Reference GuideEnable Mode Command Set
copy console flash <filename>
Use the copy console command to copy the console’s input to a text file. To end copying to the text file,
type <Ctrl+D>. The file will be saved in the SROS root directory.
Syntax Description
<filename>Specifies the destination file (located in flash memory) for console input.
Default Values
No default is necessary for this command.
Functional Notes
The copy console command works much like a line editor. Prior to pressing <Enter>, changes can be
made to the text on the line. Changes can be made using <Delete> and <Backspace> keys. The text can
be traversed using the arrow keys, <Ctrl+A> (to go to the beginning of a line), and <Ctrl+E> (to go to the
end of a line). To end copying to the text file, type <Ctrl+D>. The file will be saved in the SROS root
directory. Use the dir command to see a list of files in the root directory.
Usage Examples
The following example copies the console input into the file config.txt (located in the SROS root directory):
<filename>Specifies the name of the file (located on the compact flash card) to copy.
The asterisk (*) can be used as a wildcard to specify a pattern for e rasing
multiple files. When a wildcard is specified, only files matching the listed
pattern are copied. When using a wildcard, leave the destination filename
blank because the source files are copied identically (including the
filename) to the destination. You cannot use a wildcard when the
destination is startup-config.
cflash <filename>Specifies the destination memory location for the file copy as compact
flash memory and the filename.
flash <filename>Specifies the destination memory location for the file copy as flash
memory and the filename.
interface <type> <slot/port>Specifies copying a software file to a specified interface. This command is
only valid for modules that contain module-specific software that is
independent of the system software. Enter copy flash XXXX interface ?
to display a list of all available module types.
startup-configReplaces the primary startup- configuration file with a copy of the specified
file.
tftpSpecifies sending the file using the trivial file transfer protocol (TFTP).
After entering copy flash XXXX tf t p, the SROS prompts for the following
information:
Address of remote host:Specifies the IP address of the TFTP server.
Destination filename:Specifies the filename to use when storing the
copied file on the TFTP server. (The file will be
placed in the default directory established by
the TFTP server.)
xmodemSends the specified file (using the XMODEM protocol) to the terminal
SROS Command Line Interface Reference GuideEnable Mode Command Set
Usage Examples
The following example creates a copy of the file myfile.biz (located in flash memory), names the new file
newfile.biz, and places the new file in flash memory:
The following example copies the software file J03_01.biz located in flash memory to a TFTP server:
ProCurve>enable
ProCurve#copy flash tftp
Address of remote host?10.200.2.4
Source filename J03_01.biz
Destination filename J03_01.biz
Initiating TFTP transfer ...
Sent 769060 bytes.
Transfer Complete!
The following example updates the ADSL interface with the software file J8459A_02_01_01.biz:
SROS Command Line Interface Reference GuideEnable Mode Command Set
The following example copies the software file J03_01.biz (located in flash memory) to the connected
terminal using XMODEM protocol:
ProCurve>enable
ProCurve#copy flash xmodem
Source filename J03_01.biz
Begin the Xmodem transfer now...
Press CTRL+X twice to cancel
CCCCCC
The SROS is now ready to transmit the file on the CONSOLE port (using the XMODEM protocol). The next
step in the process may differ depending on the type of terminal emulation software you are using. For
HyperTerminal, you will now select Transfer > Receive File and select the destination. Once the transfer
is complete, information similar to the following is displayed:
SROS Command Line Interface Reference GuideEnable Mode Command Set
copy running-config
Use the copy running-config command to create a copy of the current running-configuration and replace
the current startup-configuration or save it to a specified memory location (compact flash or system flash).
Variations of this command include:
Begin the Xmodem transfer now...
Press CTRL+X twice to cancel
CCCCCC
The SROS is now ready to transmit the file on the CONSOLE port (using the XMODEM protocol). The next
step in the process may differ depending on the type of terminal emulation software you are using. For
HyperTerminal, you will now select Transfer > Receive File and select the destination. Once the transfer
is complete, information similar to the following is displayed:
SROS Command Line Interface Reference GuideEnable Mode Command Set
copy startup-config
Use the copy startup-config command to create a copy of the current startup-configuration and replace the
current running-configuration or save it to a specified memory location (compact flash or system flash).
Variations of this command include:
tftpSpecifies sending the file using the trivial file transfer protocol (TFTP). After
entering copy startup-config tftp, the SROS prompts for the following
information:
Address of remote host:Specifies the IP address of the TFTP server.
Destination filename:Specifies the filename to use when storing the copie d
file on the TFTP server. (The file will be placed in the
default directory established by the TFTP server.)
xmodemSends the current startup-configuration file (using the XMODEM protocol) to the
terminal connected to the Console port.
cflash <filename>Specifies the destination memory location for the copied file as compact flash
and specifies the filename for the copied file.
flash <filename>Specifies the destination memory location for the copied file as system flash
memory and specifies the filename for the copied file.
running-configReplaces the current running configuration file with the primary
startup-configuration.
Default Values
No default value necessary for this command.
Usage Examples
The following example copies the primary startup-configuration file to the current running-configuration:
ProCurve>enable
ProCurve#copy startup-config running-config
Opening and applying file...
Note
Any changes made to the current running configuration of the router that have not been
saved to the startup configuration file (using the write command) will be lost when the copy startup-config running-config command is entered.
Begin the Xmodem transfer now...
Press CTRL+X twice to cancel
CCCCCC
The SROS is now ready to transmit the file on the CONSOLE port (using the XMODEM protocol). The next
step in the process may differ depending on the type of terminal emulation software you are using. For
HyperTerminal, you will now select Transfer > Receive File and select the destination. Once the transfer
is complete, information similar to the following is displayed:
SROS Command Line Interface Reference GuideEnable Mode Command Set
copy tftp <destination>
Use the copy tftp command to copy a file located on a network Trivial File Transfer Protocol (TFTP)
server to a specified destination.
Syntax Description
<destination>Specifies the destination of the file copied from the TFTP server.
Valid destinations include: cflash (installed compact flash card), flash (flash
memory), startup-config (the primary configuration file), or running-config
(the current running configuration file).
After entering copy tftp and specifying a destination, the SROS prompts for
the following information:
Address of remote host:Specifies the IP address of the TFTP server.
Source filename:Specifies the Name of the file to copy from the TFTP server.
Destination filename:Specifies the filename to use when storing the copied file to flash memory.
(Valid only for the copy tftp cflash and copy tftp flash commands.)
Default Values
No default value necessary for this command.
Usage Examples
The following example replaces the current running-configuration file with new_config.txt from the TFTP
server (10.200.2.4):
ProCurve#copy tftp running-config
Address of remote host?10.200.2.4
Source filename new_config.txt
Initiating TFTP transfer ...
Received 4562 bytes.
Transfer Complete!
ProCurve#
The following example copies the file J03_01.biz from the TFTP server (10.200.2.4) and saves it compact
flash memory (naming the copy SROS.BIZ):
ProCurve#copy tftp cflash
Address of remote host?10.200.2.4
Source filename J03_01.biz
Destination filename SROS.BIZ
Initiating TFTP transfer ...
Received 45647 bytes.
Transfer Complete!
ProCurve#
SROS Command Line Interface Reference GuideEnable Mode Command Set
copy xmodem <destination>
Use the copy xmodem command to copy a file (using the XMODEM protocol) to a specified destination.
XMODEM capability is provided in terminal emulation software such as HyperTerminal™.
Syntax Description
<destination>Specifies the destination of the copied file.
Valid destinations include: cflash (installed compact flash card), flash (flash
memory), startup-config (the configuration file stored in flash memory), or running-config (the current running configuration file).
After entering copy xmodem and specifying a destination, the SROS prompts for
the following information:
Destination filename:Specifies the filename to use when storing the copied file to flash memory. (Valid
only for the copy cflash and copy flash commands.)
Default Values
No default value necessary for this command.
Usage Examples
The following example copies a software file (J03_01.biz) to flash memory and labels it SROS.BIZ:
ProCurve#copy xmodem flash
Destination filename SROS.BIZ
Begin the Xmodem transfer now...
Press CTRL+X twice to cancel
CCCCCC
The SROS is now ready to accept the file on the CONSOLE port (using the XMODEM protocol). The next
step in the process may differ depending on the type of terminal emulation software you are using. For
HyperTerminal, you will now select Transfer > Send File and browse to the file you wish to copy
(J03_01.biz). Once the transfer is complete, information similar to the following is displayed:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug aaa
Use the debug aaa command to activate debug messages associated with authentication from the AAA
subsystem. Debug messages are displayed (real-time) on the terminal (or Telnet) screen. Use the no form
of this command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Functional Notes
The debug aaa events include connection notices, login attempts, and session tracking.
Usage Examples
The following is sample output for this command:
ProCurve>enable
ProCurve#debug aaa
AAA: New Session on portal 'TELNET 0 (172.22.12.60:4867)'.
AAA: No list mapped to 'TELNET 0'. Using 'default'.
AAA: Attempting authentication (username/password).
AAA: RADIUS authentication failed.
AAA: Authentication failed.
AAA: Closing Session on portal 'TELNET 0 (172.22.12.60:4867)'.
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug access-list <listname>
Use the debug access-list command to activate debug messages (for a specified list) associated with access
list operation. Debug messages are displayed (real-time) on the terminal (or Telnet) screen. Use the no
form of this command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
<listname>Specifies a configured access list
Default Values
By default, all debug messages in the SROS are disabled.
Functional Notes
The debug access-list command provides debug messages to aid in troubleshooting access list issues.
Usage Examples
The following example activates debug messages for the access list labeled MatchAll:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug arp
Use the debug arp command to activate debug messages associated with IP Address Resolution Protocol
(ARP) transactions. Debug messages are displayed (real-time) on the terminal (or Telnet) screen. Use the
no form of this command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates debug messages associated with ARP transactions:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug atm events
Use the debug atm events command to display events on all ATM ports and all virtual circuits. Debug
messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no form of this command to
disable debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates ATM event messages:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug atm oam
Use the debug atm oam command to display Op eration, Administration, and Maintenance (OAM) packets
for an ATM virtual circuit descriptor (VCD). Debug messages are displayed (real-time) to the terminal (or
Telnet) screen. Use the no form of this command to disable debug messages. Variations of this command
include the following:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug atm packet
Use the debug atm packet command to activate debug messages associated with packets on ATM ports
and virtual circuits. Debug messages are displayed (real-time) to the terminal (or Telnet) screen. Use the
no form of this command to disable the debug messages. Variations of this command include the
following:
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
interface atm <port id>Shows packets on a specific ATM port and on all virtual circuits.
vc <VPI/VCI>Shows packets on a specific virtual circuit identified by the virtual path
identifier and virtual channel identifier (VPI/VCI).
vcd <vcd number>Shows packets on specific virtual circuit descriptors (VCD).
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates debug ATM packet debug messages on ATM port 1:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug backup
Use the debug backup command to activate debug messages associated with backup operation. Debug
messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no form of this command to
disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Functional Notes
The debug backup command activates debug messages to aid in the troubleshooting of backup links.
Usage Examples
The following example activates debug messages for backup operation:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug bridge
Use the debug bridge command to display messages associated with bridge events. Debug messages are
displayed (real-time) to the terminal (or Telnet) screen. Use the no form of this command to disable debug
messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates bridge debug messages:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug chat-interfaces <chat interface>
Use the debug chat-interfaces command to activate debug messages associated with chat AT command
driven interfaces. Debug messages are displayed (real-time) on the terminal (or Telnet) screen. Use the no
form of this command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
<chat interface>Specifies the chat interface to debug in slot/port format.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates debug messages for the chat interface 0/1:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug crypto [ike | ike negotiation | ike client authentication |
ike client configuration | ipsec | pki]
Use the debug crypto command to activate debug messages associated with IKE and IPSec functions.
Debug messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no form of this
command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
ike Displays all IKE debug messages.
ike negotiationDisplays only IKE key management debug messages (e.g., handshaking).
ike client authenticationDisplays IKE client authentication messages as they occur.
ike client configurationDisplays mode-config exchanges as they take place over the IKE SA. It is
enabled independently from the ike negotiation debug described previously.
ipsecDisplays all IPSec debug messages.
pkiDisplays all PKI (public key infrastructure) debug messages.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates the IPSec debug messages:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug data-call
Use the debug data-call command to activate debug messages associated with data call errors and events.
Debug messages are displayed (real-time) on the terminal (or Telnet) screen. Use the no form of this
command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates debug messages associated with data call errors and events:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug demand-routing
Use the debug demand-routing command to activate debug messages associated with demand routing
errors and events. Debug messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no
form of this command to disable debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates demand routing error and event messages:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug dialup-interfaces
Use the debug dialup-interfaces command to generate debug messages used to aid in troubleshooting
problems with all dialup interfaces such as the modem or the BRI cards. Use the no version of this
command to disable it.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Functional Notes
When enabled, these messages provide status information on incoming calls, dialing and answering
progress, etc. These messages also give information on why certain calls are dropped or rejected. It is
beneficial to use this command when troubleshooting backup (in addition to the debug backup
command).
Usage Examples
The following example activates the debug messages for dialup interfaces:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug dynamic-dns [verbose]
Use the debug dynamic-dns command to display debug messages associated with dynamic DNS. Debug
messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no form of this command to
disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
verboseTurns on verbose messaging.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates dynamic DNS debug messages:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug firewall
Use the debug firewall command to activate debug messages associated with the SROS firewall
operation. Debug messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no form of
this command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
No subcommands.
Default Values
By default, all debug messages in the SROS are disabled.
Functional Notes
The debug firewall command activates de bug messages to provide real-time information about the SROS
stateful inspection firewall operation.
Usage Examples
The following example activates the debug messages for the SROS stateful inspection firewall:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug firewall alg sip [verbose]
Use the debug firewall alg sip command to activate debug messages associated with Session Initiation
Protocol (SIP) information with SROS firewall operation. Debug messages are displayed
(real-time) on the terminal (or Telnet) screen. Use the no form of this command to disable the debug
messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
verboseEnables detailed debug messages.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates debug messages associated with SIP information with SROS firewall
operation:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug frame-relay [events | llc2 | lmi]
Use the debug frame-relay command to activate debug messages associated with the Frame Relay
operation. Debug messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no form of
this command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
eventsActivates debug messages for generic Frame Relay event s (such as Frame Relay
interface state).
llc2Activates debug messages for the logical link control layer.
lmiActivates debug messages for the local management interface (such as DLCI
status signaling state, etc.).
Default Values
By default, all debug messages in the SROS are disabled.
Functional Notes
The debug frame- relay command activates deb ug messages to aid in the troubles hooting of Frame Relay
links.
Usage Examples
The following example activates all possible debug messages associated with Frame Relay operation:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug frame-relay multilink <interface>
Use the debug frame-relay multilink command to activate debug messages associated with Frame Relay
multilink operation. Debug messages are displayed (real-time) to the terminal (or Telnet) screen. Use the
no form of this command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
<interface>Optional. Activates debug messages for the specified interface. Type debug
frame-relay multilink ? for a complete list of applicable interfaces.
Default Values
By default, all debug messages in the SROS are disabled.
Usage Examples
The following example activates debug messages associated with multilink operation for all Frame Relay
interfaces:
SROS Command Line Interface Reference GuideEnable Mode Command Set
debug interface <interface>
Use the debug interface command to activate debug messages associated with the specified interface.
Debug messages are displayed (real-time) to the terminal (or Telnet) screen. Use the no form of this
command to disable the debug messages.
Note
Turning on a large amount of debug information can adversely affect the performance of
your unit.
Syntax Description
< interface >Activates debug messages for the specified interface. Type debug interface ? for
a complete list of applicable interfaces.
Default Values
By default, all debug messages in the SROS are disabled.
Functional Notes
The debug interface command activates debug messages to aid in the troubleshooting of physical
interfaces.
Usage Examples
The following example activates all possible debug messages associated with the Ethernet port: