This section contains the following information about this document:
• “Purpose and Audience” on page 26
• “Document Organization” on page 26
• “Document Organization” on page 26
• “Products and Models” on page 26
• “Related Documents” on page 26
• “Typographical Conventions” on page 27
About This DocumentEdgeSwitch CLI Command Reference
Ubiquiti Networks, Inc.
25
Page 26
About This DocumentEdgeSwitch CLI Command Reference
Purpose and Audience
This reference lists the commands to configure the EdgeSwitch software features using the EdgeSwitch
command line interface (CLI). The information in this reference is intended for system administrators who are
responsible for configuring and operating a network using EdgeSwitch devices.
To obtain the greatest benefit from this reference, you should have an understanding of the base software
and should have read the specification for your networking device platform. You should also have basic
knowledge of Ethernet and networking concepts.
Document Organization
This guide contains the following sections:
• “Chapter 1: Using the Command Line Interface” on page 28
• “Chapter 2: Management Commands” on page 37
• “Chapter 3: Utility Commands” on page 100
• “Chapter 4: Switching Commands” on page 196
• “Chapter 5: Routing Commands” on page 315
• “Chapter 6: IPv6 Management Commands” on page 360
• “Chapter 7: Quality of Service Commands” on page 365
• “Chapter 8: Power over Ethernet (PoE) Commands” on page 414
• “Appendix A: Log Messages” on page 417
• “Appendix B: Contact Information” on page 435
Products and Models
This document covers the following Ubiquiti products and models:
Table 1. Affected Products
NameDescriptionPart Number
EdgeSwitch 48-port 750WManaged PoE+ Gigabit Switch with SFP+ES-48-750W
EdgeSwitch 48-port 500WManaged PoE+ Gigabit Switch with SFP+ES-48-500W
EdgeSwitch 24-port 500WManaged PoE+ Gigabit Switch with SFPES-24-500W
EdgeSwitch 24-port 250WManaged PoE+ Gigabit Switch with SFPES-24-250W
Related Documents
Related documents for EdgeSwitch products include the following:
• EdgeSwitch Administration Guide
• EdgeSwitch ES-24 Quick Start Guide
• EdgeSwitch ES-48 Quick Start Guide
To download EdgeSwitch documents:
1. Go to the Downloads page on the Ubiquiti website: http://www.ubnt.com/download/
2. Select EdgeMAX from the Platform drop-down box.
3. Select EdgeSwitch from the Product Group drop-down box.
4. Select your EdgeSwitch model from the Model drop-down box.
5. Scroll down to Documentation PDFs and click the document to download.
For additional information, refer to the EdgeSwitch community web site: community.ubnt.com/edgemax
Ubiquiti Networks, Inc.
26
Page 27
About This DocumentEdgeSwitch CLI Command Reference
Typographical Conventions
Table 2 lists typographical conventions used throughout this document.
Table 2. Typographical Conventions
ConventionIndicatesExample
BoldUser selection
User-entered text
ItalicName of a field
Name of UI page, dialog box, window, etc.
>Order of navigation selections to access a pageTo access the Session page, click System > Users > Session
Courier font
CLI commands and their output
Select VLAN 2 from the VLAN ID list; Click Submit
enter 3 to assign VLAN 3 as the default VLAN
delete the existing name in the Username field
Use the IP Address Conflict Detection page
show network
Ubiquiti Networks, Inc.
27
Page 28
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
Chapter 1: Using the Command Line Interface
The command line interface (CLI) is a text-based way to manage and monitor the system. You can access the
CLI by using a direct serial connection or by using a remote logical connection with telnet or SSH.
This chapter describes the CLI syntax, conventions, and modes. It contains the following sections:
• “Command Syntax” on page 29
• “Command Conventions” on page 29
• “Common Parameter Values” on page 29
• “slot/port Naming Convention” on page 30
• “Using the “no” Form of a Command” on page 30
• “Executing “show” Commands” on page 31
• “CLI Output Filtering” on page 31
• “EdgeSwitch Modules” on page 32
• “Command Modes” on page 32
• “Command Completion and Abbreviation” on page 34
• “CLI Error Messages” on page 34
• “CLI Line-Editing Conventions” on page 35
• “Using CLI Help” on page 35
• “Accessing the CLI” on page 36
Ubiquiti Networks, Inc.
28
Page 29
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
Command Syntax
A command is one or more words that might be followed by one or more parameters. Parameters can be
required or optional values.
Some commands, such as show network or clear vlan, do not require parameters. Other commands, such as
network parms, require that you supply a value after the command. You must type the parameter values in
a specific order, and optional parameters follow required parameters. The following example describes the
network parms command syntax:
network parms ipaddr netmask [gateway]
• network parms is the command name.
• ipaddr and netmask are parameters and represent required values that you must enter after you
type the command keywords.
• [gateway] is an optional parameter; you are not required to enter a value in place of the parameter.
The CLI Command Reference lists each command by the command name and provides a brief description of
the command. Each command reference also contains the following information:
• Format shows the command keywords and the required and optional parameters.
• Mode identifies the command mode you must be in to access the command.
• Default shows the default value, if any, of a configurable setting on the device.
The show commands also contain a description of the information that the command shows.
Command Conventions
The parameters for a command might include mandatory values, optional values, or keyword choices.
Parameters are order-dependent. Table 3 describes the conventions this document uses to distinguish
between value types.
Table 3. Parameter Conventions
SymbolExampleDescription
[ ] square brackets
italic fontvalue or [value]Indicates a variable value. Specify an appropriate value (name or number).
{ } curly braces
| vertical bar
[ { } ] braces within
square brackets
[value]
{choice1 | choice2}
choice1 | choice2
[{choice1 | choice2}]
Indicates an optional parameter
Indicates that you must select a parameter from the list of choices
Separates mutually exclusive choices
Indicates a choice within an optional element
Common Parameter Values
Parameter values might be names (strings) or numbers. To use spaces as part of a name parameter, enclose
the name value in double quotes. For example, the expression “System Name with Spaces” forces the
system to accept the spaces. Empty strings (““) are not valid user-defined strings. Table 4 describes common
parameter values and value formatting.
Table 4. Parameter Descriptions
ParameterDescription
ipaddrThis parameter is a valid IP address. You can enter the IP address in the following formats:
In addition to these formats, the CLI accepts decimal, hexadecimal and octal formats through the following
input formats (where n is any valid hexadecimal, octal or decimal number):
0xn (CLI assumes hexadecimal format)
0n (CLI assumes octal format with leading zeros)
n (CLI assumes decimal format)
Ubiquiti Networks, Inc.
29
Page 30
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
Table 4. Parameter Descriptions (Continued)
ParameterDescription
ipv6-addressFE80:0000:0000:0000:020F:24FF:FEBF:DBCB, or
Interface or slot/portValid slot and port number separated by a forward slash. For example, 0/1 represents slot 0 and port 1.
Logical InterfaceRepresents a logical slot and port number. This is applicable in the case of a port-channel (LAG). You can use
Character stringsUse double quotation marks to identify character strings, for example, “System Name with Spaces”. An
FE80:0:0:0:20F:24FF:FEBF:DBCB, or
FE80::20F24FF:FEBF:DBCB, or
FE80:0:0:0:20F:24FF:128:141:49:32
For additional information, refer to RFC 3513.
the logical slot/port to configure the port-channel.
empty string (“”) is not valid.
slot/port Naming Convention
The EdgeSwitch software references physical entities such as cards and ports using a slot/port naming
convention. The software also uses this convention to identify certain logical entities, such as Port-Channel
interfaces.
The slot number has two uses. In the case of physical ports, it identifies the card containing the ports. In the
case of logical and CPU ports it also identifies the type of interface or port.
Table 5. Types of Slots
ParameterDescription
Physical slot numbersPhysical slot numbers begin with zero, and are allocated up to the maximum number of physical slots.
Logical slot numbers
CPU slot numbersThe CPU slots immediately follow the logical slots.
Logical InterfaceRepresents a logical slot and port number. This is applicable in the case of a port-channel (LAG). You can use
Character stringsUse double quotation marks to identify character strings, for example, “System Name with Spaces”. An
Logical slots immediately follow physical slots and identify port-channel (LAG) or router interfaces. The value
of logical slot numbers depend on the type of logical interface and can vary from platform to platform.
the logical slot/port to configure the port-channel.
empty string (“”) is not valid.
The port identifies the specific physical port or logical interface being managed on a given slot.
Table 6. Types of Ports
ParameterDescription
Physical PortsThe physical ports for each slot are numbered sequentially starting from one.
For example, port 1 on slot 0 (an internal port) for a standalone switch is 0/1, port 2 is 0/2, port 3 is 0/3, etc.
Logical Interfaces
CPU portsCPU ports are handled by the driver as one or more physical entities located on physical slots.
Port-channel or Link Aggregation Group (LAG) interfaces are logical interfaces only used for bridging functions.
• VLAN routing interfaces are only used for routing functions.
• Loopback interfaces are logical interfaces that are always up.
• Tunnel interfaces are logical point-to-point links that carry encapsulated packets.
Note: In the CLI, loopback and tunnel interfaces do not use the slot/port format. To specify a loopback
interface, you use the loopback ID. To specify a tunnel interface, you use the tunnel ID.
Using the “no” Form of a Command
The no keyword is a specific form of an existing command and does not represent a new or distinct
command. Only configuration commands have an available no form. Almost every configuration command
has a no form. In general, use the no form to reverse the action of a command or reset a value back to its
default. For example, the no shutdown configuration command reverses the shutdown of an interface.
Use the command without no to re-enable a disabled feature or to enable a feature that is disabled by default.
Ubiquiti Networks, Inc.
30
Page 31
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
Executing “show” Commands
All show commands can be issued from any configuration mode (Global Configuration, Interface
Configuration, VLAN Configuration, etc.). The show commands provide information about system and
feature-specific configuration, status, and statistics. Previously, show commands could be issued only in
User EXEC or Privileged EXEC modes.
CLI Output Filtering
Many CLI show commands include considerable content to display to the user. This can make output
confusing and cumbersome to parse through to find the information of desired importance. The CLI
Output Filtering feature allows the user, when executing CLI show display commands, to optionally specify
arguments to filter the CLI output to display only desired information. The result is to simplify the display and
make it easier for the user to find the information the user is interested in.
The main functions of the CLI Output Filtering feature are:
• Pagination Control
• Supports enabling/disabling paginated output for all show CLI commands. When disabled, output
is displayed in its entirety. When enabled, output is displayed page-by-page such that content does
not scroll off the terminal screen until the user presses a key to continue. --More-- or (q)uit is
displayed at the end of each page.
• When pagination is enabled, press the return key to advance a single line, press q or Q to stop
pagination, or press any other key to advance a whole page. These keys are not configurable.
Note: Although some EdgeSwitch show commands already support pagination, the implementation
is unique per command and not generic to all commands.
• Output Filtering
• “Grep”-like control for modifying the displayed output to only show the user-desired content.
• Filter-displayed output to only include lines containing a specified string match.
• Filter-displayed output to exclude lines containing a specified string match.
• Filter-displayed output to only include lines including and following a specified string match.
• Filter-displayed output to only include a specified section of the content (e.g. “interface 0/1”) with a
configurable end-of-section delimiter.
• String matching should be case-insensitive.
• Pagination, when enabled, also applies to filtered output.
Example: The following shows an example of the extensions made to the CLI show commands for the
Output Filtering feature.
(UBNT EdgeSwitch) #show running-config ?
<cr> Press enter to execute the command.
| Output filter options.
<scriptname> Script file name for writing active configuration.
all Show all the running configuration on the switch.
interface Display the running configuration for specificed interface on the
switch.
(UBNT EdgeSwitch) #show running-config | ?
begin Begin with the line that matches
exclude Exclude lines that matches
include Include lines that matches
section Display portion of lines
Ubiquiti Networks, Inc.
31
Page 32
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
EdgeSwitch Modules
The EdgeSwitch software consists of flexible modules that can be applied in various combinations to
develop advanced products for Layer 2 and above. The commands and command modes available on your
switch depend on the installed modules. Additionally, for some show commands, the output fields might
change based on the modules included in the EdgeSwitch software.
The EdgeSwitch software suite includes the following modules:
• Switching (Layer 2)
• Routing (Layer 3)
Note: Only static routing is available. Dynamic routing protocols are not available in the EdgeSwitch
software.
• Quality of Service
• Management (CLI, browser-based UI, and SNMP)
• IPv6 Management—Allows management of the EdgeSwitch device through an IPv6 through an IPv6
address without requiring the IPv6 Routing package in the system. The management address can be
associated with the network port (front-panel switch ports), a routine interface (port or VLAN) and the
Service port.
• Secure Management
Not all modules are available for all platforms or software releases.
Command Modes
The CLI groups commands into modes according to the command function. Each of the command modes
supports specific EdgeSwitch software commands. The commands in one mode are not available until you
switch to that particular mode, with the exception of the User EXEC mode commands. You can execute the
User EXEC mode commands in the Privileged EXEC mode.
The command prompt changes in each command mode to help you identify the current mode. Table 7
describes the command modes and the prompts visible in that mode.
Note: The command modes available on your switch depend on the software modules that are
Contains a limited set of commands to view basic
system information.
Allows you to issue any EXEC command, enter the
VLAN mode, or enter the Global Configuration mode.
Groups general setup commands and permits you to
make modifications to the running configuration.
Groups all the VLAN commands.
Manages the operation of an interface and provides
access to the router interface configuration commands.
Use this mode to set up a physical port for a specific
logical connection operation.
Use this mode to manage a range of interfaces. For
example: Switch (Interface 0/1-0/4) #
Enters LAG Interface configuration mode for the
specified LAG.
Enters VLAN routing interface configuration mode for
the specified VLAN ID.
Ubiquiti Networks, Inc.
32
Page 33
Table 7. CLI Command Modes (Continued)
SymbolExampleDescription
Line SSH
Line Telnet
AAA IAS User
Config
Mail Server Config
Policy Map Config
Policy Class
Config
Class Map Config
MAC Access-list
Config
TACACS Config
DHCP Pool Config
Support Mode
Switch (config-ssh)#
Switch (config-telnet)#
Switch (Config-IAS-User)#
Switch (Mail-Server)#
Switch (Config-policy-map)#
Switch (Config-policy-class-map)#
Switch (Config-class-map)#
Switch (Config-mac-access-list)#
Switch (Tacacs)#
Switch (Config dhcp-pool)#
Switch (Support)#
Contains commands to configure SSH login/enable
authentication.
Contains commands to configure telnet login/enable
authentication.
Allows password configuration for a user in the IAS
database.
Allows configuration of the email server.
Contains the QoS Policy-Map configuration
commands.
Consists of class creation, deletion, and matching
commands. The class match commands specify Layer
2, Layer 3, and general match criteria.
Contains the QoS class map configuration commands.
Allows you to create a MAC Access-List and to enter
the mode containing MAC Access-List configuration
commands.
Contains commands to configure properties for the
TACACS servers.
Contains the DHCP server IP address pool
configuration commands.
Allows access to the support commands, which should
only be used by the manufacturer’s technical support
personnel as improper use could cause unexpected
system behavior and/or invalidate product warranty.
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
Table 8 explains how to enter or exit each mode.
Table 8. CLI Mode Access and Exit
Command ModeAccess MethodExit or Access Previous Mode
User EXECThis is the first level of access.To exit, enter logout.
Privileged EXECFrom User EXEC mode, enter:
enable
Global ConfigFrom Privileged EXEC mode, enter:
configure
VLAN ConfigFrom Privileged EXEC mode, enter:
vlan database
Interface ConfigFrom Global Config mode, enter one of the
Line SSHFrom Global Config mode, enter:
Line TelnetFrom Global Config mode, enter:
AAA IAS User
Config
Mail Server Config From Global Config mode, enter:
following:
interface slot/port
interface loopback id
interface tunnel id
interface slot/port-slot/port
interface lag lag-intf-num
interface vlan vlan-id
line ssh
line telnet
From Global Config mode, enter:
aaa ias-user username name
mail-server address
To exit to User EXEC mode, enter exit or press Ctrl-Z.
To exit to Privileged EXEC mode, enter exit or press Ctrl-Z.
To exit to Privileged EXEC mode, enter exit or press Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to the Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
Ubiquiti Networks, Inc.
33
Page 34
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
Table 8. CLI Mode Access and Exit (Continued)
Command ModeAccess MethodExit or Return to Previous Mode
Policy-Map Config From Global Config mode, enter:
policy-map
Policy-Class-Map
Config
Class-Map ConfigFrom Global Config mode, enter:
MAC Access-list
Config
TACACS ConfigFrom Global Config mode, enter:
DHCP Pool Config From Global Config mode, enter:
SupportFrom Privileged EXEC mode, enter:
From Policy Map Config mode enter:
class
class-map
(see “class-map” on page 373)
From Global Config mode, enter:
mac access-list extended name
tacacs-server host ip-addr
where ip-addr is the IP address of the TACACS
server on your network.
ip dhcp pool pool-name
support
Note: The support command is available only
if the techsupport enable command has
been issued.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Policy Map Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Global Config mode, enter exit.
To return to Privileged EXEC mode, enter Ctrl-Z.
To exit to Privileged EXEC mode, enter exit or press Ctrl-Z.
Command Completion and Abbreviation
Command completion finishes spelling the command when you type enough letters of a command to
uniquely identify the command keyword. Once you have entered enough letters, press the SPACEBAR or TAB
key to complete the word.
Command abbreviation allows you to execute a command when you have entered there are enough letters
to uniquely identify the command. You must enter all of the required keywords and parameters before you
enter the command.
CLI Error Messages
If you enter a command and the system is unable to execute it, an error message appears. Table 9 describes
the most common CLI error messages.
Table 9. CLI Error Messages
Message TextDescription
% Invalid input detected at ‘^’ marker.
Command not found /
Incomplete command. Use ? to list commands.
Ambiguous command
Indicates that you entered an incorrect or unavailable command. The carat
(^) shows where the invalid text is detected. This message also appears if
any of the parameters or values are not recognized.
Indicates that you did not enter the required keywords or values.
Indicates that you did not enter enough letters to uniquely identify the
command.
Ubiquiti Networks, Inc.
34
Page 35
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
CLI Line-Editing Conventions
Table 10 describes the key combinations you can use to edit commands or increase the speed of command
entry. You can access this list from the CLI by entering help from the User or Privileged EXEC modes.
Table 10. CLI Editing Conventions
Key SequenceDescription
DEL or backspaceDelete previous character
Ctrl-AGo to beginning of line
Ctrl-EGo to end of line
Ctrl-FGo forward one character
Ctrl-BGo backward one character
Ctrl-DDelete current character
Ctrl-U, XDelete to beginning of line
Ctrl-KDelete to end of line
Ctrl-WDelete previous word.
Ctrl-TTranspose previous character.
Ctrl-PGo to previous line in history buffer.
Ctrl-RRewrites or pastes the line.
Ctrl-NGo to next line in history buffer.
Ctrl-YPrints last deleted character.
Ctrl-QEnables serial flow.
Ctrl-SDisables serial flow.
Ctrl-Z Return to root command prompt.
Tab, <SPACE>Command-line completion.
ExitGo to next lower command prompt.
?List available commands, keywords, or parameters.
Using CLI Help
Enter a question mark (?) at the command prompt to display the commands available in the current mode.
(UBNT EdgeSwitch) >?
enable Enter into user privilege mode.
help Display help for various special keys.
logout Exit this session. Any unsaved changes are lost.
password Change an existing user’s password.
ping Send ICMP echo packets to a specified IP address.
quit Exit this session. Any unsaved changes are lost.
show Display Switch Options and Settings.
telnet Telnet to a remote host.
Enter a question mark (?) after each word you enter to display available command keywords or parameters.
(UBNT EdgeSwitch) #network ?
ipv6 Configure IPv6 parameters for system network.
javamode Enable/Disable.
mac-address Configure MAC Address.
mac-type Select the locally administered or burned-in MAC address.
mgmt_vlan Configure the Management VLAN ID of the switch.
parms Configure Network Parameters of the device.
protocol Select DHCP, BootP, or None as the network config protocol.
Ubiquiti Networks, Inc.
35
Page 36
Using the Command Line InterfaceEdgeSwitch CLI Command Reference
If the help output shows a parameter in angle brackets, you must replace the parameter with a value.
(UBNT EdgeSwitch) #network parms ?
<ipaddr> Enter the IP Address.
none Reset IP address and gateway on management interface
If there are no additional command keywords or parameters, or if additional parameters are optional, the
following message appears in the output:
<cr> Press Enter to execute the command
You can also enter a question mark (?) after typing one or more characters of a word to list the available
command or parameters that begin with the letters, as shown in the following example:
(UBNT EdgeSwitch) #show m?
mac mac-addr-table mac-address-table
mail-server mbuf monitor
Accessing the CLI
After you have connected the EdgeSwitch to your network, you can access the CLI using a telnet or SSH
connection from a remote management host.
For on how to connect the switch to your network, refer to the Quick Start Guide that came with the
EdgeSwitch.
Ubiquiti Networks, Inc.
36
Page 37
Chapter 2: Management Commands
This chapter describes the management commands available in the EdgeSwitch CLI.
The chapter contains the following sections:
• “Network Interface Commands” on page 38
• “Telnet Commands” on page 42
• “Secure Shell Commands” on page 44
• “Management Security Commands” on page 46
• “Hypertext Transfer Protocol Commands” on page 47
• “Access Commands” on page 52
• “User Account Commands” on page 53
• “SNMP Commands” on page 72
• “RADIUS Commands” on page 82
• “TACACS+ Commands” on page 92
• “Configuration Scripting Commands” on page 96
• “Prelogin Banner, System Prompt, and Host Name Commands” on page 98
Note: The commands in this chapter consist of three functional groups:
• Show commands display switch settings, statistics, and other information.
• Configuration commands configure features and options of the switch. For every configuration
command, there is a show command that displays the configuration setting.
• Clear commands clear some or all of the settings to factory defaults.
Note: Only static routing is available. Dynamic routing protocols are not available in the EdgeSwitch
software.
This section describes the commands you use to configure a logical interface for management access. To
configure the management VLAN, see “network mgmt_vlan” on page 217.
enable (Privileged EXEC access)
This command gives you access to the Privileged EXEC mode. From the Privileged EXEC mode, you can configure
the network interface.
Format
ModeUser EXEC
enable
do (Privileged EXEC commands)
This command executes Privileged EXEC mode commands from any of the configuration modes.
Formatdo Priv Exec Mode Command
Mode• Global Config
• Interface Config
• VLAN Config
• Routing Config
Example: The following is an example of the do command that executes the Privileged Exec command script
list in Global Config Mode.
(UBNT EdgeSwitch) #configure
(UBNT EdgeSwitch)(config)#do script list
Configuration Script Name Size(Bytes)
This command sets the device’s IP address, subnet mask, and gateway. The IP address and gateway must be
on the same subnet. If you specify the none option, the IP address and subnet mask are set to the factory
defaults.
Format
ModePrivileged EXEC
network parms {ipaddr netmask [gateway] | none}
network protocol
This command specifies the network configuration protocol to be used. If you modify this value, change is
effective immediately. If you use the bootp parameter, the switch periodically sends requests to a BootP
server until a response is received. If you use the dhcp parameter, the switch periodically sends requests to
a DHCP server until a response is received. If you use the none parameter, you must configure the network
information for the switch manually.
This command enables the DHCPv4 client on a Network port. If the client-id optional parameter is given,
the DHCP client messages are sent with the client identifier option.
Defaultnone
Format
ModeGlobal Config
network protocol dhcp [client-id]
There is no support for the no form of the command network protocol dhcp client-id. To remove
the client-id option from the DHCP client messages, issue the command network protocol dhcp
without the client-id option. The command network protocol none can be used to disable the
DHCP client and client-id option on the interface.
Example: The following shows an example of the command.
This command sets locally administered MAC addresses. The following rules apply:
• Bit 6 of byte 0 (called the U/L bit) indicates whether the address is universally administered (b’0’) or locally
administered (b’1’).
• Bit 7 of byte 0 (called the I/G bit) indicates whether the destination address is an individual address (b’0’) or a
group address (b’1’).
• The second character, of the twelve character macaddr, must be 2, 6, A or E.
A locally administered address must have bit 6 On (b’1’) and bit 7 Off (b’0’).
Format
ModePrivileged EXEC
network mac-address macaddr
network mac-type
This command specifies whether the switch uses the burned-in or the locally administered MAC address.
Defaultburnedin
Format
ModePrivileged EXEC
network mac-type {local | burnedin}
no network mac-type
This command resets the value of MAC address to its default.
Format
ModePrivileged EXEC
no network mac-type
network javamode
This command specifies whether or not the switch should allow access to the Java applet in the header frame of
the web interface. When access is enabled, the Java applet can be viewed from the web interface. When access is
disabled, the user cannot view the Java applet.
This command disallows access to the Java applet in the header frame of the web interface. When access is
disabled, the user cannot view the Java applet.
Format
ModePrivileged EXEC
no network javamode
show network
This command displays configuration settings associated with the switch’s network interface. The network
interface is the logical interface used for in-band connectivity with the switch via any of the switch’s front
panel ports. The configuration parameters associated with the switch’s network interface do not affect the
configuration of the front panel ports through which traffic is switched or routed. The network interface is always
considered to be up, whether or not any member ports are up; therefore, the show network command will
always show Interface Status as Up.
Format
Modes• Privileged EXEC
TermDefinition
Interface StatusThe network interface status; it is always considered to be “Up”.
IP AddressThe IP address of the interface. The factory default value is 0.0.0.0.
Subnet MaskThe IP subnet mask for this interface. The factory default value is 0.0.0.0.
Default GatewayThe default gateway for this IP interface. The factory default value is 0.0.0.0.
IPv6 Administrative ModeWhether enabled or disabled.
Burned In MAC AddressThe burned in MAC address used for in-band connectivity.
Locally Administered MAC
Address
MAC Address TypeThe MAC address which should be used for in-band connectivity. The choices are the burned in or the
Configured IPv4 ProtocolThe IPv4 network protocol being used. The options are bootp | dhcp | none.
Configured IPv6 ProtocolThe IPv6 network protocol being used. The options are dhcp | none.
DHCPv6 Client DUIDThe DHCPv6 client’s unique client identifier. This row is displayed only when the configured IPv6
IPv6 Autoconfig ModeWhether IPv6 Stateless address autoconfiguration is enabled or disabled.
DHCP Client IdentifierThe client identifier is displayed in the output of the command only if DHCP is enabled with the client-
show network
• User EXEC
If desired, a locally administered MAC address can be configured for in-band connectivity. To take
effect, ‘MAC Address Type’ must be set to ‘Locally Administered’. Enter the address as 12 hexadecimal
digits (6 bytes) with a colon between each byte. Bit 1 of byte 0 must be set to a 1 and bit 0 to a 0,
i.e. byte 0 should have the mask ‘xxxx xx10’. The MAC address used by this bridge when it must be
referred to in a unique fashion. It is recommended that this be the numerically smallest MAC address
of all ports that belong to this bridge. However it is only required to be unique. When concatenated
with dot1dStpPriority a unique Bridge Identifier is formed which is used in the Spanning Tree Protocol.
Locally Administered address. The factory default is to use the burned in MAC address.
protocol is dhcp.
id option on the network port. See “network protocol dhcp” on page 39.
Example: The following shows example CLI display output for the network port.
(admin) #show network
Interface Status............................... Always Up
IP Address..................................... 10.250.3.1
This section describes the commands you use to configure and view Telnet settings. You can use Telnet to
manage the device from a remote management host.
ip telnet server enable
Use this command to enable Telnet connections to the system and to enable the Telnet Server Admin Mode. This
command opens the Telnet listening port.
Defaultenabled
Format
ModePrivileged EXEC
no ip telnet server enable
Use this command to disable Telnet access to the system and to disable the Telnet Server Admin Mode. This
command closes the Telnet listening port and disconnects all open Telnet sessions.
ip telnet server enable
Format
ModePrivileged EXEC
no ip telnet server enable
transport input telnet
This command regulates new Telnet sessions. If enabled, new Telnet sessions can be established until there are
no more sessions available. An established session remains active until the session is ended or an abnormal
network error ends the session.
Note: If the Telnet Server Admin Mode is disabled, Telnet sessions cannot be established. Use the ip
telnet server enable command to enable Telnet Server Admin Mode.
Defaultenabled
Format
ModeLine Config
transport input telnet
no transport input telnet
Use this command to prevent new Telnet sessions from being established.
Format
ModeLine Config
no transport input telnet
telnetcon maxsessions
This command specifies the maximum number of Telnet connection sessions that can be established. A value of
0 indicates that no Telnet connection can be established. The range is 0-5.
Default5
Format
ModePrivileged EXEC
telnetcon maxsessions 0-5
no telnetcon maxsessions
This command sets the maximum number of Telnet connection sessions that can be established to the default
value.
This command sets the Telnet connection session timeout value, in minutes. A session is active as long as the
session has not been idle for the value set. The time is a decimal value from 1 to 160.
Note: When you change the timeout value, the new value is applied to all active and inactive sessions
immediately. Any sessions that have been idle longer than the new timeout value are disconnected
immediately.
Default5
Format
ModePrivileged EXEC
no telnetcon timeout
This command sets the Telnet connection session timeout value to the default.
Note: Changing the timeout value for active sessions does not become effective until the session is
accessed again. Also, any keystroke activates the new timeout duration.
telnetcon timeout 1-160
Format
ModePrivileged EXEC
no telnetcon timeout
show telnetcon
This command displays the current inbound Telnet settings. In other words, these settings apply to Telnet
connections initiated from a remote system to the switch.
Format
Mode• Privileged EXEC
TermDefinition
Remote Connection Login
Timeout (minutes)
Maximum Number of
Remote Connection Sessions
Allow New Telnet SessionsNew Telnet sessions will not be allowed when this field is set to no. The factory default value is yes.
show telnetcon
• User EXEC
This object indicates the number of minutes a remote connection session is allowed to remain inactive
before being logged off. May be specified as a number from 1 to 160. The factory default is 5.
This object indicates the number of simultaneous remote connection sessions allowed. The factory
default is 5.
This section describes the commands you use to configure Secure Shell (SSH) access to the switch. Use SSH to
access the switch from a remote management host.
Note: The system allows a maximum of 5 SSH sessions.
ip ssh
Use this command to enable SSH access to the system. (This command is the short form of the ip ssh
server enable command.)
Defaultdisabled
Format
ModePrivileged EXEC
ip ssh protocol
This command is used to set or remove protocol levels (or versions) for SSH. Either SSH1 (1), SSH2 (2), or both
SSH 1 and SSH 2 (1 and 2) can be set.
Default2
Format
ModePrivileged EXEC
ip ssh
ip ssh protocol [1] [2]
ip ssh server enable
This command enables the IP secure shell server. No new SSH connections are allowed, but the existing SSH
connections continue to work until timed-out or logged-out.
Defaultenabled
Format
ModePrivileged EXEC
ip ssh server enable
no ip ssh server enable
This command disables the IP secure shell server.
Format
ModePrivileged EXEC
no ip ssh server enable
sshcon maxsessions
This command specifies the maximum number of SSH connection sessions that can be established. A value of 0
indicates that no SSH connection can be established. The range is 0 to 5.
Default5
Format
ModePrivileged EXEC
no sshcon maxsessions
This command sets the maximum number of allowed SSH connection sessions to the default value.
This command sets the SSH connection session timeout value, in minutes. A session is active as long as the
session has been idle for the value set. The time is a decimal value from 1 to 160.
Changing the timeout value for active sessions does not become effective until the session is re accessed. Also,
any keystroke activates the new timeout duration.
Default5
Format
ModePrivileged EXEC
no sshcon timeout
This command sets the SSH connection session timeout value, in minutes, to the default.
Changing the timeout value for active sessions does not become effective until the session is re-accessed. Also,
any keystroke activates the new timeout duration.
sshcon timeout 1-160
Format
ModePrivileged EXEC
no sshcon timeout
show ip ssh
This command displays the SSH settings.
Format
ModePrivileged EXEC
TermDefinition
Administrative ModeThis field indicates whether the administrative mode of SSH is enabled or disabled.
Protocol LevelThe protocol level may have the values of version 1, version 2 or both versions 1 and version 2.
SSH Sessions Currently
Active
Max SSH Sessions AllowedThe maximum number of SSH sessions allowed.
SSH TimeoutThe SSH timeout value in minutes.
Keys PresentIndicates whether the SSH RSA and DSA key files are present on the device.
Key Generation in ProgressIndicates whether RSA or DSA key files generation is currently in progress.
This section describes commands you use to generate keys and certificates, which you can do in addition to
loading them as before.
crypto certificate generate
Use this command to generate a self-signed certificate for HTTPS. The generated RSA key for SSL has a length of
1024 bits. The resulting certificate is generated with a common name equal to the lowest IP address of the device
and a duration of 365 days.
Format
ModeGlobal Config
crypto certificate generate
no crypto certificate generate
Use this command to delete the HTTPS certificate files from the device, regardless of whether they are selfsigned or downloaded from an outside source.
Format
ModeGlobal Config
no crypto certificate generate
crypto key generate rsa
Use this command to generate an RSA key pair for SSH. The new key files will overwrite any existing generated or
downloaded RSA key files.
Format
ModeGlobal Config
crypto key generate rsa
no crypto key generate rsa
Use this command to delete the RSA key files from the device.
Format
ModeGlobal Config
no crypto key generate rsa
crypto key generate dsa
Use this command to generate a DSA key pair for SSH. The new key files will overwrite any existing generated or
downloaded DSA key files.
Format
ModeGlobal Config
crypto key generate dsa
no crypto key generate dsa
Use this command to delete the DSA key files from the device.
This section describes the commands you use to configure Hypertext Transfer Protocol (HTTP) and secure HTTP
access to the switch. Access to the switch by using a web browser is enabled by default. Everything you can view
and configure by using the CLI is also available by using the web.
ip http accounting exec, ip https accounting exec
This command applies user exec (start-stop/stop-only) accounting list to the line methods HTTP and HTTPS.
The user exec accounting list should be created using the command “aaa accounting” on page 67.
Format
ModeGlobal Config
ParameterDescription
http/https
default
listname
ip {http|https} accounting exec {default|listname}
The line method for which the list needs to be applied.
The default list of methods for authorization services.
An alphanumeric character string used to name the list of accounting methods.
no ip http/https accounting exec
This command deletes the authorization method list.
Format
ModeGlobal Config
no ip {http|https} accounting exec {default|listname}
ip http authentication
Use this command to specify authentication methods for http server users. The default configuration is the
local user database is checked. This action has the same effect as the command ip http authentication
local. The additional methods of authentication are used only if the previous method returns an error, not if
it fails. To ensure that the authentication succeeds even if all methods return an error, specify none as the final
method in the command line. For example, if none is specified as an authentication method after RADIUS, no
authentication is used if the RADIUS server is down.
Defaultlocal
Format
ModeGlobal Config
ip http authentication method1 [method2...]
The following table lists the possible values for the method parameter.
Parameter ValueDescription
local
none
radius
tacacs
Uses the local username database for authentication.
Uses no authentication.
Uses the list of all RADIUS servers for authentication.
Uses the list of all TACACS+ servers for authentication.
Example: The following example configures the http authentication.
(UBNT EdgeSwitch)(config)# ip http authentication radius local
Use this command to specify authentication methods for https server users. The default configuration is the local
user database is checked. This action has the same effect as the command ip https authentication
local. The additional methods of authentication are used only if the previous method returns an error, not if
it fails. To ensure that the authentication succeeds even if all methods return an error, specify none as the final
method in the command line. For example, if none is specified as an authentication method after RADIUS, no
authentication is used if the RADIUS server is down.
Defaultlocal
Format
ModeGlobal Config
The following table lists the possible values for the method parameter.
Parameter ValueDescription
local
none
radius
tacacs
ip https authentication method1 [method2...]
Uses the local username database for authentication.
Uses no authentication.
Uses the list of all RADIUS servers for authentication.
Uses the list of all TACACS+ servers for authentication.
Example: The following example configures https authentication.
(UBNT EdgeSwitch)(config)# ip https authentication radius local
no ip https authentication
Use this command to return to the default.
Format
ModeGlobal Config
no ip https authentication
ip http server
This command enables access to the switch through the web interface. When access is enabled, the user can
login to the switch from the web interface. When access is disabled, the user cannot login to the switch’s web
server. Disabling the web interface takes effect immediately. All interfaces are affected.
Defaultenabled
Format
ModePrivileged EXEC
no ip http server
This command disables access to the switch through the web interface. When access is disabled, the user cannot
login to the switch’s web server.
Format
ModePrivileged EXEC
ip http server
no ip http server
ip http secure-server
This command is used to enable the secure socket layer for secure HTTP.
Defaultdisabled
Format
ModePrivileged EXEC
Ubiquiti Networks, Inc.
ip http secure-server
48
Page 49
no ip http secure-server
This command is used to disable the secure socket layer for secure HTTP.
This command configures the hard timeout for un-secure HTTP sessions in hours. Configuring this value to zero
will give an infinite hard-timeout. When this timeout expires, the user will be forced to reauthenticate. This timer
begins on initiation of the web session and is unaffected by the activity level of the connection.
Default24
Format
ModePrivileged EXEC
ip http session hard-timeout 1-168
no ip http session hard-timeout
This command restores the hard timeout for un-secure HTTP sessions to the default value.
Format
ModePrivileged EXEC
no ip http session hard-timeout
ip http session maxsessions
This command limits the number of allowable un-secure HTTP sessions. Zero is the configurable minimum.
Default16
Format
ModePrivileged EXEC
ip http session maxsessions 0-16
no ip http session maxsessions
This command restores the number of allowable un-secure HTTP sessions to the default value.
Format
ModePrivileged EXEC
no ip http session maxsessions
ip http session soft-timeout
This command configures the soft timeout for un-secure HTTP sessions in minutes. Configuring this value to zero
will give an infinite soft-timeout. When this timeout expires the user will be forced to reauthenticate. This timer
begins on initiation of the web session and is restarted with each access to the switch.
Default5
Format
ModePrivileged EXEC
no ip http session soft-timeout
This command resets the soft timeout for un-secure HTTP sessions to the default value.
This command configures the hard timeout for secure HTTP sessions in hours. When this timeout expires, the
user is forced to reauthenticate. This timer begins on initiation of the web session and is unaffected by the
activity level of the connection. The secure-session hard-timeout can not be set to zero (infinite).
Default24
Format
ModePrivileged EXEC
no ip http secure-session hard-timeout
This command resets the hard timeout for secure HTTP sessions to the default value.
ip http secure-session hard-timeout 1-168
Format
ModePrivileged EXEC
no ip http secure-session hard-timeout
ip http secure-session maxsessions
This command limits the number of secure HTTP sessions. Zero is the configurable minimum.
Default16
Format
ModePrivileged EXEC
ip http secure-session maxsessions 0-16
no ip http secure-session maxsessions
This command restores the number of allowable secure HTTP sessions to the default value.
Format
ModePrivileged EXEC
no ip http secure-session maxsessions
ip http secure-session soft-timeout
This command configures the soft timeout for secure HTTP sessions in minutes. Configuring this value to zero
will give an infinite soft-timeout. When this timeout expires, you are forced to reauthenticate. This timer begins
on initiation of the web session and is restarted with each access to the switch. The secure-session soft-timeout
cannot be set to zero (infinite).
Default5
Format
ModePrivileged EXEC
ip http secure-session soft-timeout 1-60
no ip http secure-session soft-timeout
This command restores the soft timeout for secure HTTP sessions to the default value.
Format
ModePrivileged EXEC
no ip http secure-session soft-timeout
ip http secure-port
This command is used to set the SSL port where port can be 1025-65535 and the default is port 443.
Default443
Format
ModePrivileged EXEC
Ubiquiti Networks, Inc.
ip http secure-port portid
50
Page 51
no ip http secure-port
This command is used to reset the SSL port to the default value.
Use the commands in this section to close remote connections or to view information about connections to
thesystem.
disconnect
Use the disconnect command to close HTTP, HTTPS, Telnet or SSH sessions. Use all to close all active sessions, or
use session-id to specify the session ID to close. To view the possible values for session-id, use the
show loginsession command.
Format
ModePrivileged EXEC
disconnect {session_id | all}
show loginsession
This command displays current Telnet, SSH and serial port connections to the switch. This command displays
truncated user names. Use the show loginsession long command to display the complete usernames.
Format
ModePrivileged EXEC
TermDefinition
IDLogin Session ID.
User NameThe name the user entered to log on to the system.
Connection FromIP address of the remote client machine or EIA-232 for the serial port connection.
Idle TimeTime this session has been idle.
Session TimeTotal time this session has been connected.
Session TypeShows the type of session, which can be HTTP, HTTPS, telnet, serial, or SSH.
show loginsession
show loginsession long
This command displays the complete user names of the users currently logged in to the switch.
Format
ModePrivileged EXEC
show loginsession long
Example: The following shows an example of the command.
This section describes the commands you use to add, manage, and delete system users. The EdgeSwitch
software has one default user account: ubnt. The ubnt user can view and configure system settings.
Note: You cannot delete the default read/write user account (ubnt). You can configure up to five additional
user accounts on the system. Additional user accounts can be read-only or read/write.
aaa authentication login
Use this command to set authentication at login. The default and optional list names created with the
command are used with the aaa authentication login command. Create a list by entering the aaa
authentication login list-namemethodcommand, where list-name is any character string
used to name this list. The method argument identifies the list of methods that the authentication algorithm
tries, in the given sequence.
The additional methods of authentication are used only if the previous method returns an error, not if there is
an authentication failure. To ensure that the authentication succeeds even if all methods return an error, specify
none as the fInal method in the command line. For example, if none is specified as an authentication method
after RADIUS, no authentication is used if the RADIUS server is down.
DefaultnetworkList. Used by telnet and SSH and only contains the method local.
Uses the listed authentication methods that follow this argument as the default list of methods when a
user logs in.
Character string of up to 15 characters used to name the list of authentication methods activated
when a user logs in.
At least one from the following:
• enable Uses the enable password for authentication.
• local Uses the local username database for authentication.
• none Uses no authentication.
• radius Uses the list of all RADIUS servers for authentication.
• tacacs Uses the list of all TACACS servers for authentication.
Example: The following shows an example of the command.
(UBNT EdgeSwitch)(config)# aaa authentication login default radius local enable none
no aaa authentication login
This command returns to the default.
Format
ModeGlobal Config
aaa authentication login {default | list-name}
aaa authentication enable
Use this command to set authentication for accessing higher privilege levels. The default enable list is
enableList. It is used by telnet and SSH, and contains the method as enable followed by none.
T
he default and optional list names created with the aaa authentication enable command are used with
the enable authentication command. Create a list by entering the aaa authentication enable
list-name method command where list-name is any character string used to name this list. The method
argument identifies the list of methods that the authentication algorithm tries in the given sequence.
The user manager returns ERROR (not PASS or FAIL) for enable and line methods if no password is configured,
and moves to the next configured method in the authentication list. The method none reflects that there is no
authentication needed.
The user will only be prompted for an enable password if one is required. The following authentication methods
do not require passwords:
• none
• deny
• enable (if no enable password is configured)
• line (if no line password is configured)
Example: See the examples below.
a. aaa authentication enable default enable none
b. aaa authentication enable default line none
c. aaa authentication enable default enable radius none
d. aaa authentication enable default line tacacs none
Examples a and b do not prompt for a password, however because examples c and d contain the RADIUS and
TACACS methods, the password prompt is displayed.
If the login methods include only enable, and there is no enable password configured, then the EdgeSwitch
software does not prompt for a username. In such cases, the EdgeSwitch software only prompts for a password.
the EdgeSwitch software supports configuring methods after the local method in authentication and
authorization lists. If the user is not present in the local database, then the next configured method is tried.
The additional methods of authentication are used only if the previous method returns an error, not if it fails. To
ensure that the authentication succeeds even if all methods return an error, specify none as the final method
in the command line.
Use the command “show authorization methods” on page 55 to display information about the
authentication methods.
Note: Requests sent by the switch to a RADIUS server include the username $enabx$, where x is the
requested privilege level. For enable to be authenticated on RADIUS servers, add $enabx$ users to
them. The login user ID is now sent to TACACS+ servers for enable authentication.
no aaa authentication enable {default | list-name}
aaa authorization
Use this command to configure command and exec authorization method lists. This list is identified by default
or a user-specified list-name. If tacacs is specified as the authorization method, authorization commands
are notified to a TACACS+ server. If none is specified as the authorization method, command authorization is
not applicable. A maximum of five authorization method lists can be created for the commands type.
Note: Local method is not supported for command authorization. Command authorization with RADIUS
will work if, and only if, the applied authentication method is also RADIUS.
Format
ModeGlobal Config
ParameterDescription
commandsProvides authorization for all user-executed commands.
execProvides exec authorization.
defaultThe default list of methods for authorization services.
list-nameAlphanumeric character string used to name the list of authorization methods.
methodTACACS+/RADIUS/Local and none are supported.
Example: The following shows an example of the command.
Use this command to return to the default specified by the enable authentication command.
Format
ModeLine Config
no enable authentication
username (Global Config)
Use the username command in Global Config mode to add a new user to the local user database. The default
privilege level is 1. Using the encrypted keyword allows the administrator to transfer local user passwords
between devices without having to know the passwords. When the password parameter is used along with
encrypted parameter, the password must be exactly 128 hexadecimal characters in length. If the password
strength feature is enabled, this command checks for password strength and returns an appropriate error if it
fails to meet the password strength criteria. Giving the optional parameter override-complexity-check
disables the validation of the password strength.
The user level. Level 0 can be assigned by a level 15 user to another user to suspend that user’s access.
Range 0-15. Enter access level 1 for Read Access or 15 for Read/Write Access. If not specified where it is
optional, the privilege level is 1.
Encrypted password entered, copied from another switch configuration.
Disables the validation of the password strength.
Example: The following example configures user bob with password xxxyyymmmm and user level 15.
(UBNT EdgeSwitch)(config)# username bob password xxxyyymmmm level 15
Example: The following example configures user test with password testPassword and assigns a user level of 1
(read-only). The password strength will not be validated.
(UBNT EdgeSwitch)(config)# username test password testPassword level 1 override-complexity-check
Example: A third example.
(UBNT EdgeSwitch) (Config)#username test password testtest
This command displays the configured user names and their settings. The show users command displays
truncated user names. Use the show users long command to display the complete user names. The
show users command is only available for users with Read/Write privileges. The SNMPv3 fields will only be
displayed if SNMP is available on the system.
Format
ModePrivileged EXEC
TermDefinition
User NameThe name the user enters to login using the serial port, telnet or web.
Access ModeShows whether the user is able to change parameters on the switch (Read/Write) or is only able to
SNMPv3 Access Mode
SNMPv3 AuthenticationThe authentication protocol to be used for the specified login user.
SNMPv3 EncryptionThe encryption protocol to be used for the specified login user.
show users
view them (Read Only). As a factory default, the “ubnt” user has Read/Write access.
The SNMPv3 Access Mode. If the value is set to ReadWrite, the SNMPv3 user is able to set and retrieve
parameters on the system. If the value is set to ReadOnly, the SNMPv3 user is only able to retrieve
parameter information. The SNMPv3 access mode may be different than the CLI and web access mode.
show users long
This command displays the complete usernames of the configured users on the switch.
Format
ModePrivileged EXEC
Example: The following shows an example of the command.
(UBNT EdgeSwitch) #show users long
User Name
-----------ubnt
test1111test1111test1111test1111
show users long
show users accounts
This command displays local user status with respect to user account lockout and password aging. Displayed
user names are truncated. Use the show users long command to show the complete user names.
Format
ModePrivileged EXEC
TermDefinition
User NameThe local user account’s user name.
Access LevelThe user’s access level (1 for read-only or 15 for read/write).
Password AgingNumber of days, since the password was configured, until the password expires.
Password Expiry DateThe current password expiration date in date format.
LockoutIndicates whether the user account is locked out (true or false).
If the detail keyword is included, the following additional fields are displayed.
TermDefinition
Password Override
Complexity Check
Password StrengthDisplays the user password’s strength (Strong or Weak). This field is displayed only if the Password
show users accounts [detail]
Displays the user’s Password override complexity check status. By default it is disabled.
Strength feature is enabled.
Ubiquiti Networks, Inc.
58
Page 59
Example: The following example displays information about the local user database.
(UBNT EdgeSwitch)#show users accounts
UserName Privilege Password Password Lockout
Aging Expiry date
Use this command to display information about the login history of users.
Format
ModePrivileged EXEC
ParameterDescription
name
show users login-history [username name]
Name of the user. Range: 1-20 characters.
Example: The following example shows user login history outputs.
(UBNT EdgeSwitch) #show users login-history
Login Time Username Protocol Location
-------------------- --------- --------- --------------Jan 19 2005 08:23:48 Bob Serial
Jan 19 2005 08:29:29 Robert HTTP 172.16.0.8
Jan 19 2005 08:42:31 John SSH 172.16.0.1
Jan 19 2005 08:49:52 Betty Telnet 172.16.1.7
login authentication
Use this command to specify the login authentication method list for a line (telnet or SSH). The default
configuration uses the default set with the command aaa authentication login.
Format
ModeLine Configuration
ParameterDefinition
default
list-name
login authentication {default | list-name}
Uses the default list created with the aaa authentication login command.
Uses the indicated list created with the aaa authentication login command.
Example: The following example specifies the default authentication method for telnet.
Use this command to return to the default specified by the authentication login command.
password
This command allows the currently logged in user to change his or her password without having read/write
privileges.
Format
ModeUser EXEC
password
Example: The following is an example of the command.
(UBNT EdgeSwitch) #password
Enter old password:********
Enter new password:********
Confirm new password:********
password (Line Configuration)
Use the password command in Line Configuration mode to specify a password on a line. The default
configuration is no password is specified.
Format
ModeLine Config
ParameterDefinition
password
encrypted
Example: The following example specifies a password mcmxxyyy on a line.
password [password [encrypted]]
Password for this level. Range: 8-64 characters
Encrypted password to be entered, copied from another switch configuration. The encrypted password
should be 128 characters long because the assumption is that this password is already encrypted with AES.
(UBNT EdgeSwitch)(config-line)# password mcmxxyyy
Example: The following is another example of the command.
Use this command to allow a user to change the password for only that user. This command should be used after
the password has aged. The user is prompted to enter the old password and the new password.
Format
ModeUser EXEC
password
Example: The following example shows the prompt sequence for executing the password command.
(UBNT EdgeSwitch)>password
Enter old password:********
Enter new password:********
Confirm new password:********
password (aaa IAS User Config)
This command is used to configure a password for a user. An optional parameter [encrypted] is provided to
indicate that the password given to the command is already preencrypted.
Format
Modeaaa IAS User Config
no password (aaa IAS User Config)
This command is used to clear the password of a user.
Format
Modeaaa IAS User Config
Example: The following shows an example of the command.
Use the enable password configuration command to set a local password to control access to the
privileged EXEC mode.
Format
ModePrivileged EXEC
ParameterDefinition
password
encrypted
enable password [password [encrypted]]
Password string. Range: 8-64 characters.
Encrypted password you entered, copied from another switch configuration. The encrypted password
should be 128 characters long because the assumption is that this password is already encrypted with AES.
Use the no enable password command to remove the password requirement.
Format
ModePrivileged EXEC
no enable password
passwords min-length
Use this command to enforce a minimum password length for local users. The value also applies to the enable
password. The valid range is 8-64.
Default8
Format
ModeGlobal Config
passwords min-length 8-64
no passwords min-length
Use this command to set the minimum password length to the default value.
Format
ModeGlobal Config
no passwords min-length
passwords history
Use this command to set the number of previous passwords that shall be stored for each user account. When
a local user changes his or her password, the user will not be able to reuse any password stored in password
history. This ensures that users don’t reuse their passwords often. The valid range is 0-10.
Default0
Format
ModeGlobal Config
passwords history 0-10
no passwords history
Use this command to set the password history to the default value.
Format
ModeGlobal Config
no passwords history
passwords aging
Use this command to implement aging on passwords for local users. When a user’s password expires, the user is
prompted to change it before logging in again. The valid range is 1-365. The default is 0, or no aging.
Default0
Format
ModeGlobal Config
Ubiquiti Networks, Inc.
passwords aging 1-365
62
Page 63
no passwords aging
Use this command to set the password aging to the default value.
Use this command to strengthen the security of the switch by locking user accounts that have failed login due to
wrong passwords. When a lockout count is configured, a user that is logged in must enter the correct password
within that count. Otherwise the user will be locked out from further switch access. Only a user with read/write
access can reactivate a locked user account. The valid range is 1-5. The default is 0, or no lockout count enforced.
Default0
Format
ModeGlobal Config
passwords lock-out 1-5
no passwords lock-out
Use this command to set the password lock-out count to the default value.
Format
ModeGlobal Config
no passwords lock-out
passwords strength-check
Use this command to enable the password strength feature. It is used to verify the strength of a password during
configuration.
DefaultDisable
Format
ModeGlobal Config
passwords strength-check
no passwords strength-check
Use this command to set the password strength checking to the default value.
Format
ModeGlobal Config
no passwords strength-check
passwords strength maximum consecutive-characters
Use this command to set the maximum number of consecutive characters to be used in password strength. The
valid range is 0-15. The default is 0. Minimum of 0 means no restriction on that set of characters.
Default0
Format
ModeGlobal Config
passwords strength maximum consecutive-characters 0-15
passwords strength maximum repeated-characters
Use this command to set the maximum number of repeated characters to be used in password strength. The
valid range is 0-15. The default is 0. Minimum of 0 means no restriction on that set of characters.
Default0
Format
ModeGlobal Config
passwords strength maximum consecutive-characters 0-15
Use this command to enforce a minimum number of uppercase letters that a password should contain. The valid
range is 0-16. The default is 2. Minimum of 0 means no restriction on that set of characters.
Default2
Format
ModeGlobal Config
no passwords strength minimum uppercase-letters
Use this command to reset the minimum uppercase letters required in a password to the default value.
passwords strength minimum uppercase-letters
Format
ModeGlobal Config
no passwords strength minimum uppercase-letter
passwords strength minimum lowercase-letters
Use this command to enforce a minimum number of lowercase letters that a password should contain. The valid
range is 0-16. The default is 2. Minimum of 0 means no restriction on that set of characters.
Default2
Format
ModeGlobal Config
passwords strength minimum lowercase-letters
no passwords strength minimum lowercase-letters
Use this command to reset the minimum lower letters required in a password to the default value.
Format
ModeGlobal Config
no passwords strength minimum lowercase-letter
passwords strength minimum numeric-characters
Use this command to enforce a minimum number of numeric characters that a password should contain. The
valid range is 0-16. The default is 2. Minimum of 0 means no restriction on that set of characters.
Default2
Format
ModeGlobal Config
passwords strength minimum numeric-characters
no passwords strength minimum numeric-characters
Use this command to reset the minimum numeric characters required in a password to the default value.
Format
ModeGlobal Config
no passwords strength minimum numeric-characters
passwords strength minimum special-characters
Use this command to enforce a minimum number of special characters that a password should contain. The valid
range is 0-16. The default is 2. Minimum of 0 means no restriction on that set of characters.
Use this command to reset the minimum special characters required in a password to the default value.
Format
ModeGlobal Config
no passwords strength minimum special-characters
passwords strength minimum character-classes
Use this command to enforce a minimum number of characters classes that a password should contain.
Character classes are uppercase letters, lowercase letters, numeric characters and special characters. The valid
range is 0-4. The default is 4.
Default4
Format
ModeGlobal Config
passwords strength minimum character-classes
no passwords strength minimum character-classes
Use this command to reset the minimum number of character classes required in a password to the default
value.
Format
ModeGlobal Config
no passwords strength minimum character-classes
passwords strength exclude-keyword
Use this command to exclude the specified keyword while configuring the password. The password does not
accept the keyword in any form (in between the string, case in-sensitive and reverse) as a substring. User can
configure up to a maximum of 3 keywords.
Format
ModeGlobal Config
passwords strength exclude-keyword keyword
no passwords strength exclude-keyword
Use this command to reset the restriction for the specified keyword or all the keywords configured.
Format
ModeGlobal Config
no passwords strength exclude-keyword [keyword]
show passwords configuration
Use this command to display the configured password management settings.
Format
ModePrivileged EXEC
TermDefinition
Minimum Password LengthMinimum number of characters required when changing passwords.
Password HistoryNumber of passwords to store for reuse prevention.
Password AgingLength in days that a password is valid.
Lockout AttemptsNumber of failed password login attempts before lockout.
Minimum Password
Uppercase Letters
Minimum Password
Lowercase Letters
Minimum Password Numeric
Characters
show passwords configuration
Minimum number of uppercase characters required in a password.
Minimum number of lowercase characters required in a password.
Minimum number of numeric characters required in a password.
Password Exclude-Keywords The set of keywords to be excluded from the configured password when strength checking is enabled.
Maximum number of consecutive characters allowed in a password.
Maximum number of repeated characters allowed in a password.
Minimum number of character classes (uppercase, lowercase, numeric and special) required when
configuring passwords.
show passwords result
Use this command to display the last password set result information.
Format
ModePrivileged EXEC
TermDefinition
Last User Whose Password
Is Set
Password Strength CheckShows whether password strength checking is enabled.
Last Password Set ResultShows if the attempt to set a password succeeded; if not, the reason for the failure is included.
show passwords result
Shows the name of the user with the most recently set password.
write memory
Use this command to save running configuration changes to NVRAM so that changes you make will persist
across a reboot. This command is the same as copy system:running-config nvram:startup-
config. Use the confirm keyword to directly save the configuration to NVRAM without prompting for
confirmation.
Format
ModePrivileged EXEC
write memory [confirm]
aaa ias-user username
The Internal Authentication Server (IAS) database is a dedicated internal database used for local authentication
of users for network access through the IEEE 802.1X feature. Use the aaa ias-user username command
in Global Config mode to add the specified user to the internal user database. This command also changes the
mode to AAA User Config mode.
Format
ModeGlobal Config
aaa ias-user username user
no aaa ias-user username
Use this command to remove the specified user from the internal user database.
Format
ModeGlobal Config
Example: The following shows an example of the command.
Use this command in Global Config mode to specify if the same session-id is used for Authentication,
Authorization and Accounting service type within a session.
Defaultcommon
Format
ModeGlobal Config
ParameterDefinition
common
unique
no aaa session-id
Use this command in Global Config mode to reset the aaa session-id behavior to the default.
aaa session-id [common | unique]
Use the same session-id for all AAA Service types.
Use a unique session-id for all AAA Service types.
Format
ModeGlobal Config
no aaa session-id [unique]
aaa accounting
Use this command in Global Config mode to create an accounting method list for user EXEC sessions, userexecuted commands, or 802.1X. This list is identified by default or a user-specified list_name.
Accounting records, when enabled for a line-mode, can be sent at both the beginning and at the end (start-
stop) or only at the end (stop-only). If none is specified, then accounting is disabled for the specified list.
If tacacs is specified as the accounting method, accounting records are notified to a TACACS+ server.
If radius is the specified accounting method, accounting records are notified to a RADIUS server.
Note: Please note the following:
• A maximum of five Accounting Method lists can be created for each exec and commands type.
• Only the default Accounting Method list can be created for 802.1X. There is no provision to create more.
• The same list-name can be used for both exec and commands accounting type
• AAA Accounting for commands with RADIUS as the accounting method is not supported.
• Start-stop or None are the only supported record types for 802.1X accounting. Start-stop enables
accounting and None disables accounting.
• RADIUS is the only accounting method type supported for 802.1X accounting.
Provides accounting for a user EXEC terminal sessions.
Provides accounting for all user executed commands.
Provides accounting for 802.1X user commands.
The default list of methods for accounting services.
Character string used to name the list of accounting methods.
Sends a start accounting notice at the beginning of a process and a stop accounting notice at the
beginning of a process and a stop accounting notice at the end of a process.
Sends a stop accounting notice at the end of the requested user process.
Disables accounting services on this line.
Use either tacacs or radius server for accounting purposes.
For the same set of accounting type and list name, the administrator can change the record type, or the methods
list, without having to first delete the previous configuration.
The first aaa command creates a method list for exec sessions with the name ExecList, with record-
type as stop-only and the method as tacacs (TACACS+). The second command changes the
record-type to start-stop from stop-only for the same method list. The third command, for the
same list changes the methods list to {tacacs, radius} from {tacacs}.
Use this command to specify a password for a user in the IAS database. An optional parameter encrypted is
provided to indicate that the password given to the command is already preencrypted.
Format
ModeAAA IAS User Config
ParameterDefinition
password
encrypted
password password [encrypted]
Password for this level. Range: 8-64 characters
Encrypted password to be entered, copied from another switch configuration.
Example: Following are the IAS configuration commands shown in the output of show running-config
command. Passwords shown in the command output are always encrypted.
This causes accounting for each command execution attempt. If a user is enabling accounting for exec
mode for the current line-configuration type, the user will be logged out.
The default Accounting List.
Enter a string of not more than 15 characters.
Example: The following is a example of the command.
Use this command to remove accounting from a Line Configuration mode.
Format
ModeLine Configuration
no accounting {exec|commands]
show accounting
Use this command to display ordered methods for accounting lists.
Format
ModePrivileged EXEC
show accounting
Example: The following shows example CLI display output for the command.
(UBNT EdgeSwitch) #show accounting
Number of Accounting Notifications sent at beginning of an EXEC session: 0
Errors when sending Accounting Notifications beginning of an EXEC session: 0
Number of Accounting Notifications at end of an EXEC session: 0
Errors when sending Accounting Notifications at end of an EXEC session: 0
Number of Accounting Notifications sent at beginning of a command execution: 0
Errors when sending Accounting Notifications at beginning of a command execution: 0
Number of Accounting Notifications sent at end of a command execution: 0
Errors when sending Accounting Notifications at end of a command execution: 0
show accounting methods
Use this command to display configured accounting method lists.
Format
ModePrivileged EXEC
Example: The following shows example CLI display output for the command.
This section describes the commands you use to configure Simple Network Management Protocol (SNMP) on the
switch. You can configure the switch to act as an SNMP agent so that it can communicate with SNMP managers
on your network.
snmp-server
This command sets the name and the physical location of the switch, and the organization responsible for the
network. The parameters name, loc, and con can be up to 255 characters in length.
Defaultnone
Format
ModeGlobal Config
snmp-server community
This command adds (and names) a new SNMP community, and optionally sets the access mode, allowed IP
address, and create a view for the community.
Note:
using the same community name, the first entry is kept and processed and all duplicate entries are ignored.
Default• Public and private, which you can rename.
Format
ModeGlobal Config
snmp-server {sysname name | location loc | contact con}
Community names in the SNMP Community Table must be unique. When making multiple entries
• Default values for the remaining four community names are blank.
A name associated with the switch and with a set of SNMP managers that manage it with a specified
privileged level. The length of community-name can be up to 16 case-sensitive characters.
The access mode of the SNMP community, which can be public (Read-Only/RO), private (Read-Write/
RW), or Super User (SU).
The associated community SNMP packet sending address and is used along with the client IP mask
value to denote a range of IP addresses from which SNMP clients may use that community to access
the device. A value of 0.0.0.0 allows access from any IP address. Otherwise, this value is ANDed with the
mask to determine the range of allowed client IP addresses.
The name of the view to create or update.
no snmp-server community
This command removes this community name from the table. The name is the community name to be deleted.
Format
ModeGlobal Config
no snmp-server community community-name
snmp-server community-group
This command configures a community access string to permit access via the SNMPv1 and SNMPv2 protocols.
The Port MAC locking component interprets this command and configures violation action to send an SNMP trap
with default trap frequency of 30 seconds. The Global command configures the trap violation mode across all
interfaces valid for port-security (for other port security commands, see “Port Security Commands” on page
290). There is no global trap mode as such.
Defaultdisabled
Format
Mode• Global Config
no snmp-server enable traps violation
This command disables the sending of new violation traps.
snmp-server enable traps violation
• Interface Config
Format
ModeInterface Config
no snmp-server enable traps violation
snmp-server enable traps
This command enables the Authentication Flag.
Defaultenabled
Format
ModeGlobal Config
snmp-server enable traps
no snmp-server enable traps
This command disables the Authentication Flag.
Format
ModeGlobal Config
no snmp-server enable traps
snmp trap link-status
This command enables link status traps on an interface or range of interfaces.
Note: This command is valid only when the Link Up/Down Flag is enabled.
Format
ModeInterface Config
no snmp trap link-status
This command disables link status traps by interface.
snmp trap link-status
Note: This command is valid only when the Link Up/Down Flag is enabled.
Format
ModeInterface Config
no snmp trap link-status
snmp trap link-status all
This command enables link status traps for all interfaces.
Note: This command is valid only when the Link Up/Down Flag is enabled.
Format
ModeGlobal Config
Ubiquiti Networks, Inc.
snmp trap link-status all
73
Page 74
no snmp trap link-status all
This command disables link status traps for all interfaces.
Note: This command is valid only when the Link Up/Down Flag is enabled.
Note: This command may not be available on all platforms.
This command enables Link Up/Down traps for the entire switch. When enabled, link traps are sent only if the
Link Trap flag setting associated with the port is enabled. See “show snmp” on page 79.
Defaultenabled
Format
ModeGlobal Config
snmp-server enable traps linkmode
no snmp-server enable traps linkmode
This command disables Link Up/Down traps for the entire switch.
Format
ModeGlobal Config
no snmp-server enable traps linkmode
snmp-server enable traps multiusers
This command enables Multiple User traps. When the traps are enabled, a Multiple User Trap is sent when a user
logs in to the terminal interface (EIA 232 or Telnet) and there is an existing terminal interface session.
Defaultenabled
Format
ModeGlobal Config
snmp-server enable traps multiusers
no snmp-server enable traps multiusers
This command disables Multiple User traps.
Format
ModeGlobal Config
no snmp-server enable traps multiusers
snmp-server enable traps stpmode
This command enables the sending of new root traps and topology change notification traps.
Defaultenabled
Format
ModeGlobal Config
no snmp-server enable traps stpmode
This command disables the sending of new root traps and topology change notification traps.
This command configures the SNMP engine ID on the local device.
DefaultThe engineID is configured automatically, based on the device MAC address.
Format
ModeGlobal Config
ParameterDefinition
engineid-string
default
CAUTION: Changing the engine ID will invalidate all SNMP configuration that exists on the box.
no snmp-server engineID local
This command removes the specified engine ID.
DefaultThe engineID is configured automatically, based on the device MAC address.
Format
ModeGlobal Config
snmp-server engineID local {engineid-string|default}
A hexadecimal string identifying the engine ID, used for localizing configuration. The engine ID must
be an even length in the range of 6 to 32 hexadecimal characters.
Sets the engine ID to the default string, based on the device MAC address.
no snmp-server engineID local
snmp-server filter
This command creates a filter entry for use in limiting which traps will be sent to a host.
The label for the filter being created. The range is 1 to 30 characters.
The OID subtree to include or exclude from the filter. Subtrees may be specified numerically (1.3.6.2.4)
or by keywords (system), and asterisks may be used to specify a subtree family (1.3.*.4).
The tree is included in the filter.
The tree is excluded from the filter.
no snmp-server filter
This command removes the specified filter.
DefaultNo filters are created by default.
Format
ModeGlobal Config
snmp-server filter filtername [oid-tree]
snmp-server group
This command creates an SNMP access group.
DefaultGeneric groups are created for all versions and privileges using the default views.
The IPv4 or IPv6 address of the host to send the trap or inform to.
User used to send a Trap or Inform message. This user must be associated with a group that supports
the version and access method. The range is 1 to 30 characters.
Send SNMP traps to the host. This is the default option.
Send SNMP informs to the host.
Number of seconds to wait for an acknowledgement before resending the Inform. The default is 15
seconds. The range is 1 to 300 seconds.
Number of times to resend an Inform. The default is 3 attempts. The range is 0 to 255 retries.
Enables authentication but not encryption.
No authentication or encryption. This is the default.
Enables authentication and encryption.
The SNMP Trap receiver port. This value defaults to port 162.
The filter name to associate with this host. Filters can be used to specify which traps are sent to this
host. The range is 1 to 30 characters.
Use this command in Global Configuration mode to configure the global source-interface (Source IP address) for
all SNMP communication between the SNMP client and the server.
Format
ModeGlobal Configuration
ParameterDefinition
slot/port
loopback-id
tunnel-id
vlan-id
no snmptrap source-interface
Use this command in Global Configuration mode to remove the global source-interface (Source IP selection) for
all SNMP communication between the SNMP client and the server.
This command displays trap conditions. The command’s display shows all the enabled OSPFv2 and OSPFv3
trapflags. Configure which traps the switch should generate by enabling or disabling the trap condition. If a trap
condition is enabled and the condition is detected, the SNMP agent on the switch sends the trap to all enabled
trap receivers. You do not have to reset the switch to implement the changes. Cold and warm start traps are
always generated and cannot be disabled.
Format
ModePrivileged EXEC
TermDefinition
Authentication FlagCan be enabled or disabled. The factory default is enabled. Indicates whether authentication failure
Link Up/Down FlagCan be enabled or disabled. The factory default is enabled. Indicates whether link status traps will
Multiple Users FlagCan be enabled or disabled. The factory default is enabled. Indicates whether a trap will be sent when
Spanning Tree FlagCan be enabled or disabled. The factory default is enabled. Indicates whether spanning tree traps
show trapflags
traps will be sent.
besent.
the same user ID is logged into the switch more than once at the same time (either through Telnet or
the serial port).
This section describes the commands you use to configure the switch to use a Remote Authentication Dial-In
User Service (RADIUS) server on your network for authentication and accounting.
radius accounting mode
This command is used to enable the RADIUS accounting function.
Defaultdisable
Format
ModeGlobal Config
no radius accounting mode
This command is used to set the RADIUS accounting function to the default value - i.e. the RADIUS accounting
function is disabled.
radius accounting mode
Format
ModeGlobal Config
no radius accounting mode
radius server attribute 4
This command specifies the RADIUS client to use the NAS-IP Address attribute in the RADIUS requests. If the
specific IP address is configured while enabling this attribute, the RADIUS client uses that IP address while
sending NAS-IP-Address attribute in RADIUS communication.
Format
ModeGlobal Config
ParameterDefinition
4
ipaddr
no radius server attribute 4
The no version of this command disables the NAS-IP-Address attribute global parameter for RADIUS client. When
this parameter is disabled, the RADIUS client does not send the NAS-IP-Address attribute in RADIUS requests.
Format
ModeGlobal Config
Example: The following shows an example of the command.
(UBNT EdgeSwitch) (Config) #radius server attribute 4 192.168.37.60
(UBNT EdgeSwitch) (Config) #radius server attribute 4
radius server attribute 4 [ipaddr]
NAS-IP-Address attribute to be used in RADIUS requests.
The IP address of the server.
no radius server attribute 4 [ipaddr]
radius server host
This command configures the IP address or DNS name to use for communicating with the RADIUS server of a
selected server type. While configuring the IP address or DNS name for the authenticating or accounting servers,
you can also configure the port number and server name. If the authenticating and accounting servers are
configured without a name, the command uses the Default_RADIUS_Auth_Server and Default_RADIUS_Acct_
Server as the default names, respectively. The same name can be configured for more than one authenticating
servers and the name should be unique for accounting servers. The RADIUS client allows the configuration of a
maximum of 32 authenticating and accounting servers.
If you use the auth parameter, the command configures the IP address or hostname to use to connect to a
RADIUS authentication server. You can configure up to 3 servers per RADIUS client. If the maximum number of
configured servers is reached, the command fails until you remove one of the servers by issuing the no form of
the command. If you use the optional port parameter, the command configures the UDP port number to use
when connecting to the configured RADIUS server. The port number range is 1-65535, with a default of 1812.
Note: To reconfigure a RADIUS authentication server to use the default UDP port, set the port
parameter to 1812.
If you use the acct parameter, the command configures the IP address or hostname to use for the RADIUS
accounting server. You can only configure one accounting server. If an accounting server is currently configured,
use the no form of the command to remove it from the configuration. The IP address or hostname you specify
must match that of a previously configured accounting server. If you use the optional port parameter, the
command configures the UDP port to use when connecting to the RADIUS accounting server. If a port is already
configured for the accounting server, the new port replaces the previously configured port. The port value
must be in the range 0-65535, with a default of 1813.
Note: To reconfigure a RADIUS accounting server to use the default UDP port, set the port parameter
The port number to use to connect to the specified RADIUS server.
The alias name to identify the server.
no radius server host
The no form of this command deletes the configured server entry from the list of configured RADIUS servers.
If the RADIUS authenticating server being removed is the active server in the servers that are identified by the
same server name, then the RADIUS client selects another server for making RADIUS transactions. If auth is
used, the previously configured RADIUS authentication server is removed from the configuration. Similarly,
if acct is used, the previously configured RADIUS accounting server is removed from the configuration. The
ipaddr|dnsname parameter must match the IP address or DNS name of the previously configured RADIUS
authentication/accounting server.
Format
ModeGlobal Config
Example: The following shows an example of the command.
(UBNT EdgeSwitch) (Config) #radius server host acct 192.168.37.60
(UBNT EdgeSwitch) (Config) #radius server host acct 192.168.37.60 port 1813
(UBNT EdgeSwitch) (Config) #radius server host auth 192.168.37.60 name Network1_RS port 1813
(UBNT EdgeSwitch) (Config) #radius server host acct 192.168.37.60 name Network2_RS
(UBNT EdgeSwitch) (Config) #no radius server host acct 192.168.37.60
no radius server host {auth | acct} {ipaddr|dnsname}
radius server key
This command configures the key to be used in RADIUS client communication with the specified server.
Depending on whether the auth or acct keyword is used, the shared secret is configured for the RADIUS
authentication or RADIUS accounting server. The IP address or hostname provided must match a previously
configured server. When this command is executed, the secret is prompted.
Text-based configuration supports RADIUS server’s secrets in encrypted and non-encrypted format. When you save
the configuration, these secret keys are stored in encrypted format only. If you want to enter the key in encrypted
format, enter the key along with the encrypted keyword. In the show running-config command’s display,
these secret keys are displayed in encrypted format. You cannot show these keys in plain text format.
Ubiquiti Networks, Inc.
83
Page 84
Note: The secret must be an alphanumeric value not exceeding 16 characters.
radius server key {auth | acct} {ipaddr|dnsname} encrypted password
The IP address of the server.
The DNS name of the server.
The password in encrypted format.
Example: The following shows an example of the CLI command.
radius server key acct 10.240.4.10 encrypted encrypt-string
radius server msgauth
This command enables the message authenticator attribute to be used for the specified RADIUS Authenticating
server.
Format
ModeGlobal Config
ParameterDefinition
ip addr
dnsname
no radius server msgauth
The no version of this command disables the message authenticator attribute to be used for the specified
RADIUS Authenticating server.
radius server msgauth ipaddr|dnsname
The IP address of the server.
The DNS name of the server.
Format
ModeGlobal Config
no radius server msgauth ipaddr|dnsname
radius server primary
This command specifies a configured server that should be the primary server in the group of servers which
have the same server name. Multiple primary servers can be configured for each number of servers that have
the same name. When the RADIUS client has to perform transactions with an authenticating RADIUS server of
specified name, the client uses the primary server that has the specified server name by default. If the RADIUS
client fails to communicate with the primary server for any reason, the client uses the backup servers configured
with the same server name. These backup servers are identified as the Secondary type.
Format
ModeGlobal Config
ParameterDefinition
ip addr
dnsname
radius server primary {ipaddr|dnsname}
The IP address of the RADIUS Authenticating server.
The DNS name of the server.
radius server retransmit
This command configures the RADIUS client global parameter that specifies the maximum number of message
transmissions before using the fall back server upon unsuccessful communication with the current RADIUS
authenticating server. When the maximum number of retries is reached for the RADIUS accounting server and no
response is received, the client does not communicate with any other server.
The maximum number of transmission attempts in the range of 1 to 15.
no radius server retransmit
The no form of this command sets the value of this global parameter to the default value.
Format
ModeGlobal Config
no radius server retransmit
radius source-interface
Use this command to specify the physical or logical interface to use as the RADIUS client source interface (source
IP address). If configured, the address of source-interface is used for all RADIUS communications
between the RADIUS server and the RADIUS client. The selected source-interface IP address is used for
filling the IP header of RADIUS management protocol packets. This allows security devices (firewalls) to identify
the source packets coming from the specific switch.
If a source-interface is not specified, the primary IP address of the originating (outbound) interface is
used as the source address. If the configured interface is down, the RADIUS client falls back to its default behavior.
Format
ModeGlobal Config
ParameterDefinition
slot/port
loopback-id
vlan-id
no radius source-interface
Use this command to reset the RADIUS source interface to the default settings.
Configures the loopback interface. The range of the loopback ID is 0 to 7.
Configures the VLAN interface to use as the source IP address. The range of the VLAN ID is 1 to 4093.
no radius source-interface
radius server timeout
This command configures the RADIUS client global parameter that specifies the timeout value (in seconds) after
which a request must be retransmitted to the RADIUS server if no response is received. The timeout value is an
integer in the range of 1 to 30.
Default5
Format
ModeGlobal Config
ParameterDefinition
seconds
Ubiquiti Networks, Inc.
radius server timeout seconds
Timeout value in seconds in the range 1–30.
85
Page 86
no radius server timeout
The no version of this command sets the timeout global parameter to the default value.
Round Trip TimeThe time interval, in hundredths of a second, between the most recent Accounting-Response and the
RequestsThe number of RADIUS Accounting-Request packets sent to this server. This number does not include
RetransmissionThe number of RADIUS Accounting-Request packets retransmitted to this RADIUS accounting server.
ResponsesThe number of RADIUS packets received on the accounting port from this server.
Malformed ResponsesThe number of malformed RADIUS Accounting-Response packets received from this server.
Bad AuthenticatorsThe number of RADIUS Accounting-Response packets containing invalid authenticators received from
Pending RequestsThe number of RADIUS Accounting-Request packets sent to this server that have not yet timed out or
TimeoutsThe number of accounting timeouts to this server.
Unknown TypesThe number of RADIUS packets of unknown types, which were received from this server on the
Packets DroppedThe number of RADIUS packets received from this server on the accounting port and dropped for
The name of the accounting server.
Accounting-Request that matched it from this RADIUS accounting server.
retransmissions.
Malformed packets include packets with an invalid length. Bad authenticators or signature attributes
or unknown types are not included as malformed accounting responses.
this accounting server.
received a response.
accounting port.
some other reason.
Example: The following shows example CLI display output for the command.
This command displays the summary statistics of configured RADIUS Authenticating servers.
Format
ModePrivileged EXEC
ParameterDefinition
ipaddr
dnsname
servername
TermDefinition
RADIUS Server NameThe name of the authenticating server.
Server Host Address The IP address of the host.
Access RequestsThe number of RADIUS Access-Request packets sent to this server. This number does not include
Access RetransmissionsThe number of RADIUS Access-Request packets retransmitted to this RADIUS authentication server.
Access AcceptsThe number of RADIUS Access-Accept packets, including both valid and invalid packets, that were
Access RejectsThe number of RADIUS Access-Reject packets, including both valid and invalid packets, that were
Access ChallengesThe number of RADIUS Access-Challenge packets, including both valid and invalid packets, that were
Malformed Access
Responses
Bad AuthenticatorsThe number of RADIUS Access-Response packets containing invalid authenticators or signature
Pending RequestsThe number of RADIUS Access-Request packets destined for this server that have not yet timed out or
TimeoutsThe number of authentication timeouts to this server.
Unknown TypesThe number of packets of unknown type that were received from this server on the authentication
Packets DroppedThe number of RADIUS packets received from this server on the authentication port and dropped for
show radius statistics {ipaddr|dnsname | name servername}
The IP address of the server.
The DNS name of the server.
The alias name to identify the server.
retransmissions.
received from this server.
received from this server.
received from this server.
The number of malformed RADIUS Access-Response packets received from this server. Malformed
packets include packets with an invalid length. Bad authenticators or signature attributes or unknown
types are not included as malformed access responses.
attributes received from this server.
received a response.
port.
some other reason.
Ubiquiti Networks, Inc.
90
Page 91
Example: The following shows example CLI display output for the command.
TACACS+ provides access control for networked devices via one or more centralized servers. Similar to RADIUS,
this protocol simplifies authentication by making use of a single database that can be shared by many clients
on a large network. TACACS+ is based on the TACACS protocol (described in RFC1492) but additionally provides
for separate authentication, authorization, and accounting services. The original protocol was UDP based with
messages passed in clear text over the network; TACACS+ uses TCP to ensure reliable delivery and a shared key
configured on the client and daemon server to encrypt all messages.
tacacs-server host
Use the tacacs-server host command in Global Configuration mode to configure a TACACS+ server.
This command enters into the TACACS+ configuration mode. The ip-address|hostname parameter is the
IP address or hostname of the TACACS+ server. To specify multiple hosts, multiple tacacs-server host
commands can be used.
Format
ModeGlobal Config
tacacs-server host ip-address|hostname
no tacacs-server host
Use the no tacacs-server host command to delete the specified hostname or IP address. The ipaddress|hostname parameter is the IP address of the TACACS+ server.
Format
ModeGlobal Config
no tacacs-server host ip-address|hostname
tacacs-server key
Use the tacacs-server key command to set the authentication and encryption key for all TACACS+
communications between the switch and the TACACS+ daemon. The key-string parameter has a range of
0-128 characters and specifies the authentication and encryption key for all TACACS communications between
the switch and the TACACS+ server. This key must match the key used on the TACACS+ daemon.
Text-based configuration supports TACACS server’s secrets in encrypted and non-encrypted format. When you
save the configuration, these secret keys are stored in encrypted format only. If you want to enter the key in
encrypted format, enter the key along with the encrypted keyword. The show running-config command
displays these secret keys in encrypted format. You cannot show these keys in plain text format.
Format
ModeGlobal Config
no tacacs-server key
Use the no tacacs-server key command to disable the authentication and encryption key for all TACACS+
communications between the switch and the TACACS+ daemon. The key-string parameter has a range of
0-128 characters This key must match the key used on the TACACS+ daemon.
Use the tacacs-server keystring command to set the global authentication encryption key used for all TACACS+
communications between the TACACS+ server and the client.
Format
ModeGlobal Config
tacacs-server keystring
Example: The following shows an example of the CLI command.
(UBNT EdgeSwitch)(Config)#tacacs-server keystring
Enter tacacs key:********
Re-enter tacacs key:********
tacacs-server source-interface
Use this command in Global Configuration mode to configure the source interface (Source IP address) for
TACACS+ server configuration. The selected source-interface IP address is used for filling the IP header of
management protocol packets. This allows security devices (firewalls) to identify the source packets coming from
the specific switch.
If a source-interface is not specified, the primary IP address of the originating (outbound) interface is used as the
source address.
Use this command in Global Configuration mode to remove the global source interface (Source IP selection) for
all TACACS+ communications between the TACACS+ client and the server.
Format
ModeGlobal Config
no tacacs-server source-interface
tacacs-server timeout
Use the tacacs-server timeout command to set the timeout value for communication with the
TACACS+ servers. The timeout parameter has a range of 1-30 and is the timeout value in seconds.
Use the no tacacs-server timeout command to restore the default timeout value for all TACACS
servers.
Format
ModeGlobal Config
no tacacs-server timeout
key
Use the key command in TACACS Configuration mode to specify the authentication and encryption key for all
TACACS communications between the device and the TACACS server. This key must match the key used on the
TACACS daemon. The key-string parameter specifies the key name. For an empty string use “ ”. The range is
0-128 characters.
Text-based configuration supports TACACS server’s secrets in encrypted and non-encrypted format. When you
save the configuration, these secret keys are stored in encrypted format only. If you want to enter the key in
encrypted format, enter the key along with the encrypted keyword. In the show running-config command’s
display, these secret keys are displayed in encrypted format. You cannot show these keys in plain text format.
Format
ModeTACACS Config
key [key-string | encrypted key-string]
keystring
Use the keystring command in TACACS Server Configuration mode to set the TACACS+ server-specific
authentication encryption key used for all TACACS+ communications between the TACACS+ server and the client
Format
ModeTACACS Server Config
Example: The following shows an example of the command.
Enter tacacs key:********
Re-enter tacacs key:********
port
Use the port command in TACACS Configuration mode to specify a server port number. The server port-
number range is 0 - 65535.
Default49
Format
ModeTACACS Config
port port-number
priority (TACACS Config)
Use the priority command in TACACS Configuration mode to specify the order in which servers are used,
where 0 (zero) is the highest priority. The priority parameter specifies the priority for servers. The highest priority
is 0 (zero), and the range is 0 - 65535.
Use the timeout command in TACACS Configuration mode to specify the timeout value in seconds. If no
timeout value is specified, the global value is used. The timeout parameter has a range of 1-30 and is the
timeout value in seconds.
Format
ModeTACACS Config
timeout timeout
show tacacs
Use the show tacacs command to display the configuration, statistics, and source interface details of the
TACACS+ client.
Format
ModePrivileged EXEC
Parameter/TermDefinition
Host addressThe IP address or hostname of the configured TACACS+ server.
PortThe configured TACACS+ server port number.
TimeOutThe timeout in seconds for establishing a TCP conection.
PriorityThe preference order in which TACACS+ servers are contacted. If a server connection fails, the next
client
server
show tacacs [ip-address|hostname|client|server]
highest priority server is contacted.
Display SNTP client information.
Display SNTP server information.
show tacacs source-interface
Use the show tacacs source-interface command in Global Config mode to display the configured global source
interface details used for a TACACS+ client. The IP address of the selected interface is used as source IP for all
communications with the server.
Format
ModePrivileged EXEC
show tacacs source-interface
Example: The following shows example CLI display output for the command.
Configuration Scripting allows you to generate text-formatted script files representing the current configuration
of a system. You can upload these configuration script files to a PC or UNIX system and edit them. Then, you can
download the edited files to the system and apply the new configuration. You can apply configuration scripts to
one or more switches with no or minor modifications.
Use the show running-config command (see “show running-config” on page 119) to capture the
running configuration into a script. Use the copy command (see “copy” on page 140) to transfer the
configuration script to or from the switch.
You should use scripts on systems with default configuration; however, you are not prevented from applying
scripts on systems with non-default configurations.
Scripts must conform to the following rules:
• The file extension must be “.scr”.
• A maximum of ten scripts are allowed on the switch.
• The combined size of all script files on the switch shall not exceed 2048 KB.
• The maximum number of configuration file command lines is 2000.
You can type single-line annotations at the command prompt to use when you write test or configuration
scripts to improve script readability. The exclamation point (!) character flags the beginning of a comment. The
comment flag character can begin a word anywhere on the command line, and all input following this character
is ignored. Any command line that begins with ”!” is recognized as a comment line and ignored by the parser.
The following lines show an example of a script:
! Script file for displaying management access
show telnet !Displays the information about remote connections
! Display information about direct connections
show serial
! End of the script file!
Note: To specify a blank password for a user in the configuration script, you must specify it as a space
within quotes. For example, to change the password for user jane from a blank password to hello, the
script entry is as follows:
users passwd jane
“ “
hello
hello
script apply
This command applies the commands in the script to the switch. The scriptname parameter is the name of
the script to apply.
Format
ModePrivileged EXEC
script apply scriptname
script delete
This command deletes a specified script where the scriptname parameter is the name of the script to
delete. The all option deletes all the scripts present on the switch.
This command lists all scripts present on the switch as well as the remaining available space.
Format
ModePrivileged EXEC
TermDefinition
Configuration ScriptName of the script.
Size Privileged EXEC
script list
script show
This command displays the contents of a script file, which is named scriptname.
Format
ModePrivileged EXEC
TermDefinition
Output Formatline number: line contents
script show scriptname
script validate
This command validates a script file by parsing each line in the script file where scriptname is the name
of the script to validate.The validate option is intended to be used as a tool for script development. Validation
identifies potential problems. It might not identify all problems with a given script on any given device.
Prelogin Banner, System Prompt, and Host Name Commands
This section describes the commands you use to configure the prelogin banner and the system prompt. The
prelogin banner is the text that displays before you login at the User: prompt.
copy (pre-login banner)
The copy command includes the option to upload or download the CLI Banner to or from the switch. You can
specify local URLs by using TFTP, SFTP, SCP, or Xmodem.
Note: The parameter ipaddr is either an IPv4 address, or an IPv6 address for routing packages that
support IPv6.
Defaultnone
FormatCopy banner to the switch:
ModePrivileged EXEC
set prompt
This command changes the name of the prompt. The length of name may be up to 64 alphanumeric characters.
Use this command to configure the prelogin CLI banner before displaying the login prompt.
Format
ModeGlobal Config
ParameterDefinition
line
set clibanner line
Banner text where ““ (double quote) is a delimiting character. The banner message can be up to 2000
characters.
no set clibanner
Use this command to unconfigure the prelogin CLI banner.
Format
ModeGlobal Config
no set clibanner
Ubiquiti Networks, Inc.
99
Page 100
Chapter 3: Utility Commands
This chapter describes the utility commands available in the EdgeSwitch CLI.
The chapter contains the following sections:
• “AutoInstall Commands” on page 101
• “CLI Output Filtering Commands” on page 104
• “Dual Image Commands” on page 106
• “System Information and Statistics Commands” on page 107
• “Box Services Commands” on page 125
• “Logging Commands” on page 126
• “Email Alerting and Mail Server Commands” on page 131
• “System Utility and Clear Commands” on page 136
• “Simple Network Time Protocol Commands” on page 144
• “Time Zone Commands” on page 148
• “DHCP Server Commands” on page 151
• “DNS Client Commands” on page 160
• “IP Address Conflict Commands” on page 164
• “Serviceability Packet Tracing Commands” on page 165
• “Cable Test Command” on page 179
• “Remote Monitoring Commands” on page 180
• “Statistics Application Commands” on page 191
Utility CommandsEdgeSwitch CLI Command Reference
Note: The commands in this chapter consist of four functional groups:
• Show commands display switch settings, statistics, and other information.
• Configuration commands configure features and options of the switch. For every configuration
command, there is a show command that displays the configuration setting.
• Copy commands transfer or save configuration and informational files to and from the switch.
• Clear commands clear some or all of the settings to factory defaults.
Ubiquiti Networks, Inc.
100
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.