Edge-Core ECS4620-52P User manual

  • Hello! I am an AI chatbot trained to assist you with the Edge-Core ECS4620-52P User manual. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
CLI Reference Guide
www.edge-core.com
ECS4620 Series
28/52-Port Layer 3
Stackable GE Switch
Software Release v1.2.2.26
CLI Reference Guide
ECS4620-28T Stackable GE Switch
Layer 3 Stackable Gigabit Ethernet Switch
with 24 10/100/1000BASE-T (RJ-45) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
ECS4620-28P Stackable GE PoE Switch
Layer 3 Stackable Gigabit Ethernet PoE Switch
with 24 10/100/1000BASE-T (RJ-45) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
ECS4620-28F Stackable GE Fiber Switch
Layer 3 Stackable Gigabit Ethernet Fiber Switch
with 22 SFP Ports,
2 10/100/1000BASE-T (RJ-45/SFP) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
ECS4620-28T-DC Stackable GE Switch
Layer 3 Stackable Gigabit Ethernet Switch
with 24 10/100/1000BASE-T (RJ-45) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
ECS4620-28F-DC Stackable GE Fiber Switch
Layer 3 Stackable Gigabit Ethernet Fiber Switch
with 22 SFP Ports,
2 10/100/1000BASE-T (RJ-45/SFP) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
ECS4620-28F-2AC Stackable GE Fiber Switch
Layer 3 Stackable Gigabit Ethernet Fiber Switch
with 22 SFP Ports,
2 10/100/1000BASE-T (RJ-45/SFP) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
(Dual AC/DC power inputs)
ECS4620-52T Stackable GE Switch
Layer 3 Stackable Gigabit Ethernet Switch
with 48 10/100/1000BASE-T (RJ-45) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
ECS4620-52P Stackable GE PoE Switch
Layer 3 Stackable Gigabit Ethernet PoE Switch
with 48 10/100/1000BASE-T (RJ-45) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
ECS4620-52P-2AC Stackable GE PoE Switch
Layer 3 Stackable Gigabit Ethernet PoE Switch
with 48 10/100/1000BASE-T (RJ-45) Ports,
2 10-Gigabit SFP+ Ports,
and Optional Module with 2 10-Gigabit SFP+ Ports
(Dual AC/DC power inputs)
E022019-CS-R06
– 3 –
How to Use This Guide
This guide includes detailed information on the switch software, including how to
operate and use the management functions of the switch. To deploy this switch
effectively and ensure trouble-free operation, you should first read the relevant
sections in this guide so that you are familiar with all of its software features.
Who Should Read This
Guide?
This guide is for network administrators who are responsible for operating and
maintaining network equipment. The guide assumes a basic working knowledge of
LANs (Local Area Networks), the Internet Protocol (IP), and Simple Network
Management Protocol (SNMP).
How This Guide is
Organized
This guide describes the switchs command line interface (CLI). For more detailed
information on the switchs key features or information about the web browser
management interface refer to the Web Management Guide.
The guide includes these sections:
Section I “Getting Started” — Includes information on initial configuration.
Section II “Command Line Interface — Includes all management options
available through the CLI.
Section III “Appendices — Includes information on troubleshooting switch
management access.
Related
Documentation
This guide focuses on switch software configuration through the CLI.
For information on how to manage the switch through the Web management
interface, see the following guide:
Web Management Guide
For information on how to install the switch, see the following guide:
Installation Guide
For all safety information and regulatory statements, see the following documents:
Quick Start Guide
Safety and Regulatory Information
How to Use This Guide
– 4 –
Conventions The following conventions are used throughout this guide to show information:
Note:
Emphasizes important information or calls your attention to related features
or instructions.
Caution:
Alerts you to a potential hazard that could cause loss of data, or damage
the system or equipment.
Documentation
Notice
This documentation is provided for general information purposes only. If any
product feature details in this documentation conflict with the product datasheet,
refer to the datasheet for the latest information.
Revision History This section summarizes the changes in each revision of this guide.
February 2019 Revision
This is the sixth version of this guide. This guide is valid for software release
v1.2.2.26. It contains the following changes:
Added documentation notice.
November 2016 Revision
This is the fifth version of this guide. This guide is valid for software release
v1.2.2.26. It contains the following changes:
Added information for ECS4620-52T-2AC and ECS4620-52P-2AC.
Added "show process cpu guard" on page 130.
Added SFTP option to "copy" on page 142.
Updated syntax for "snmp-server user" on page 215.
Added "show authorization" on page 267.
Added "telnet (client)" on page 274.
Updated Command Usage for "dot1x default" on page 285.
Updated syntax for "ip dhcp snooping information option circuit-id" on
page 347.
Updated syntax for "clear ip dhcp snooping binding" on page 349.
Updated Command Usage for "ip source-guard max-binding" on page 365.
How to Use This Guide
– 5 –
Added Command Usage for "show interfaces brief" on page 433.
Updated syntax for "show port monitor" on page 475.
Updated Command Usage for "spanning-tree bpdu-filter" on page 536.
Updated Command Usage for "spanning-tree bpdu-guard" on page 537.
Added Command Usage to "spanning-tree spanning-disabled" on page 547.
Updated syntax for "switchport allowed vlan" on page 595.
Added "switchport dot1q-tunnel priority map" on page 604.
Updated syntax for "show l2protocol-tunnel" on page 613.
Updated syntax for "show protocol-vlan protocol-group" on page 618.
Updated syntax for "class-map" on page 646.
Updated syntax for "show policy-map interface" on page 663.
Added "ipv6 mld snooping proxy-reporting" on page 703.
Added "ipv6 mld snooping unsolicited-report-interval" on page 708.
Updated syntax for "ipv6 mld snooping vlan immediate-leave" on page 709.
Updated syntax for "show ipv6 mld snooping" on page 712.
Updated syntax for "show ipv6 mld snooping group source-list" on page 713.
Added "show ipv6 mld snooping statistics" on page 715.
Updated Command Usage for "ipv6 nd reachable-time" on page 949.
Updated syntax for "vrrp authentication" on page 966, "vrrp ip" on page 966,
"vrrp preempt" on page 967, "vrrp priority" on page 968, and "vrrp timers
advertise" on page 969.
Updated syntax for "ipv6 route" on page 981.
Updated syntax for "show ipv6 route" on page 983.
Updated syntax for "redistribute" on page 1011.
Updated syntax for "redistribute" on page 1053.
How to Use This Guide
– 6 –
December 2014 Revision
This is the fourth version of this guide. This guide is valid for software release
v1.2.2.0. It contains the following changes:
Added information for ECS4620-28F-DC.
July 2014 Revision
This is the third version of this guide. This guide is valid for software release v1.2.2.0.
It contains the following changes:
Added information for ECS4620-28T-DC.
Updated usage information for the command "mac-learning" on page 312.
Updated syntax and usage information for the command "ip source-guard
binding" on page 362.
Updated usage information for the command "ip source-guard mode" on
page 366.
Added the command "loopback-detection action" on page 502.
April 2014 Revision
This is the second version of this guide. This guide is valid for software release
v1.2.1.3. It contains the following changes:
Added information for ECS4620-28F, ECS4620-28T, and ECS4620-28P.
Extended configurable VLAN range from 1-4093 to 1-4094.
Added "Stack Operations" on page 69.
Added the command "show process cpu task" on page 130.
Added "Stacking" on page 198.
Updated syntax for "snmp-server enable traps" on page 208.
Added the commands "snmp-server enable port-traps mac-notification" on
page 212 and "show snmp-server enable port-traps" on page 212.
Updated command usage section for the command "pppoe
intermediate-agent port-format-type" on page 305.
Added the command "pppoe intermediate-agent port-format-type remote-id-
delimiter" on page 306.
Added the command "mac-learning" on page 312.
How to Use This Guide
– 7 –
Updated command usage section for the command "port security" on
page 313.
Added the command "port security mac-address-as-permanent" on page 315.
Added the commands "ip dhcp snooping information option encode no-
subtype" on page 342, "ip dhcp snooping information option remote-id" on
page 343, and "ip dhcp snooping information option tr101 board-id" on
page 344.
Added the commands "ipv6 dhcp snooping option remote-id" on page 355,
and "ipv6 dhcp snooping option remote-id policy" on page 356.
Updated syntax for the command "ip source-guard binding" on page 362 and
"ip source-guard max-binding" on page 365, and "show ip source-guard
binding" on page 368.
Added the commands "ip source-guard mode" on page 366 and "clear ip
source-guard binding blocked" on page 367.
Updated syntax for the command "media-type" on page 429.
Updated range for the commands "transceiver-threshold current" on page 442,
"transceiver-threshold rx-power" on page 443, "transceiver-threshold
temperature" on page 444, "transceiver-threshold tx-power" on page 445, and
"transceiver-threshold voltage" on page 446.
Added the command "show interfaces transceiver-threshold" on page 448.
Updated command usage section for the command "power inline maximum
allocation" on page 468.
Updated syntax for the command "auto-traffic-control control-release" on
page 495.
Added the command "loopback-detection action" on page 502.
Removed the command “loopback-detection mode.
Added the command "loopback detection trap" on page 504.
Added the commands "udld detection-interval" on page 507, "udld recovery"
on page 509, and "udld recovery-interval" on page 509.
Updated range for the command "mac-address-table aging-time" on page 515.
Added the commands "spanning-tree tc-prop" on page 531, "spanning-tree
tc-prop-stop" on page 547, and "show spanning-tree tc-prop" on page 552.
Updated syntax for the command "mac-vlan" on page 622.
How to Use This Guide
– 8 –
Updated syntax for the commands "show qos map cos-dscp" on page 641,
"show qos map dscp-mutation" on page 641, and "show qos map phb-queue"
on page 642.
Added the commands "clear ip igmp snooping groups dynamic" on page 683,
and "clear ip igmp snooping statistics" on page 683.
Updated command usage section for the command "ip igmp authentication"
on page 693.
Added the commands "clear ipv6 mld snooping groups dynamic" on page 711
and "clear ipv6 mld snooping statistics" on page 712.
Updated range for the command "mvr priority" on page 730.
Added the commands "clear mrv groups dynamic" on page 739 and "clear mrv
statistics" on page 739.
Updated syntax for the command "show mvr members" on page 743 and
"show mvr statistics" on page 745.
Added the command "mvr6 priority" on page 751.
Added the command "clear efm oam event-log" on page 866.
Updated syntax for the commands "ip route" on page 976 and "show ip route"
on page 978.
Added BGP to the parameter list for the RIP command "redistribute" on
page 991.
Added BGP to the parameter list for the OSPFv2 command "redistribute" on
page 1011.
Added the command "area authentication" on page 1014.
Added the command "neighbor password" on page 1126.
December 2013 Revision
This is the first version of this guide. This guide is valid for software release v1.1.1.1.
– 9 –
Contents
How to Use This Guide 3
Contents 9
Figures 53
Tables 55
Section I Getting Started 63
1 Initial Switch Configuration 65
Connecting to the Switch 65
Configuration Options 65
Connecting to the Console Port 66
Logging Onto the Command Line Interface 67
Setting Passwords 67
Remote Connections 68
Stack Operations 69
Selecting the Stack Master 69
Selecting the Backup Unit 70
Recovering from Stack Failure or Topology Change 70
Renumbering the Stack 71
Ensuring Consistent Code is Used Across the Stack 71
Configuring the Switch for Remote Management 72
Using the Network Interface 72
Setting an IP Address 72
Enabling SNMP Management Access 78
Managing System Files 80
Upgrading the Operation Code 81
Saving or Restoring Configuration Settings 81
Automatic Installation of Operation Code and Configuration Settings 83
Contents
– 10 –
Downloading Operation Code from a File Server 83
Specifying a DHCP Client Identifier 86
Downloading a Configuration File and Other Parameters from a DHCP Server 87
Setting the System Clock 89
Setting the Time Manually 89
Configuring SNTP 90
Configuring NTP 90
Section II Command Line Interface 93
2 Using the Command Line Interface 95
Accessing the CLI 95
Console Connection 95
Telnet Connection 96
Entering Commands 97
Keywords and Arguments 97
Minimum Abbreviation 97
Command Completion 97
Getting Help on Commands 98
Partial Keyword Lookup 100
Negating the Effect of Commands 100
Using Command History 100
Understanding Command Modes 100
Exec Commands 101
Configuration Commands 102
Command Line Processing 104
Showing Status Information 105
CLI Command Groups 105
3 General Commands 109
prompt 109
reload (Global Configuration) 110
enable 111
quit 112
show history 112
Contents
– 11 –
configure 113
disable 114
reload (Privileged Exec) 114
show reload 115
end 115
exit 115
4 System Management Commands 117
Device Designation 117
hostname 118
Banner Information 118
banner configure 119
banner configure company 120
banner configure dc-power-info 121
banner configure department 121
banner configure equipment-info 122
banner configure equipment-location 123
banner configure ip-lan 123
banner configure lp-number 124
banner configure manager-info 125
banner configure mux 125
banner configure note 126
show banner 127
System Status 127
show access-list tcam-utilization 128
show memory 128
show process cpu 129
show process cpu guard 130
show process cpu task 130
show running-config 131
show startup-config 133
show system 134
show tech-support 135
show users 136
show version 137
Contents
– 12 –
show watchdog 138
watchdog software 138
Fan Control 138
fan-speed force-full 138
Frame Size 139
jumbo frame 139
File Management 140
General Commands 141
boot system 141
copy 142
delete 146
dir 147
whichboot 149
Automatic Code Upgrade Commands 149
upgrade opcode auto 149
upgrade opcode path 150
upgrade opcode reload 151
show upgrade 152
TFTP Configuration Commands 152
ip tftp retry 152
ip tftp timeout 153
show ip tftp 153
Line 154
line 155
databits 155
exec-timeout 156
login 157
parity 158
password 158
password-thresh 159
silent-time 160
speed 161
stopbits 161
timeout login response 162
disconnect 162
Contents
– 13 –
terminal 163
show line 164
Event Logging 165
logging facility 165
logging history 166
logging host 167
logging on 167
logging trap 168
clear log 169
show log 169
show logging 170
SMTP Alerts 172
logging sendmail 172
logging sendmail destination-email 172
logging sendmail host 173
logging sendmail level 174
logging sendmail source-email 174
show logging sendmail 175
Time 175
SNTP Commands 176
sntp client 176
sntp poll 177
sntp server 178
show sntp 178
NTP Commands 179
ntp authenticate 179
ntp authentication-key 180
ntp client 181
ntp server 181
show ntp 182
Manual Configuration Commands 183
clock summer-time (date) 183
clock summer-time (predefined) 184
clock summer-time (recurring) 185
clock timezone 187
Contents
– 14 –
calendar set 188
show calendar 188
Time Range 189
time-range 189
absolute 190
periodic 191
show time-range 192
Switch Clustering 192
cluster 193
cluster commander 194
cluster ip-pool 195
cluster member 195
rcommand 196
show cluster 197
show cluster members 197
show cluster candidates 197
Stacking 198
switch all renumber 198
switch master button 199
switch stacking button 200
show switch master button 200
show switch stacking button 201
show switch stacking interfaces 201
5 SNMP Commands 203
General SNMP Commands 205
snmp-server 205
snmp-server community 205
snmp-server contact 206
snmp-server location 207
show snmp 207
SNMP Target Host Commands 208
snmp-server enable traps 208
snmp-server host 210
snmp-server enable port-traps mac-notification 212
Contents
– 15 –
show snmp-server enable port-traps 212
SNMPv3 Commands 213
snmp-server engine-id 213
snmp-server group 214
snmp-server user 215
snmp-server view 217
show snmp engine-id 218
show snmp group 219
show snmp user 220
show snmp view 221
Notification Log Commands 221
nlm 221
snmp-server notify-filter 222
show nlm oper-status 223
show snmp notify-filter 224
Additional Trap Commands 224
memory 224
process cpu 225
process cpu guard 226
6 Remote Monitoring Commands 229
rmon alarm 230
rmon event 231
rmon collection history 232
rmon collection rmon1 233
show rmon alarms 234
show rmon events 234
show rmon history 234
show rmon statistics 235
7 Flow Sampling Commands 237
sflow owner 237
sflow polling instance 239
sflow sampling instance 240
show sflow 241
Contents
– 16 –
8 Authentication Commands 243
User Accounts and Privilege Levels 244
enable password 244
username 245
privilege 246
show privilege 247
Authentication Sequence 248
authentication enable 248
authentication login 249
RADIUS Client 250
radius-server acct-port 250
radius-server auth-port 251
radius-server host 251
radius-server key 252
radius-server retransmit 253
radius-server timeout 253
show radius-server 254
TACACS+ Client 254
tacacs-server host 255
tacacs-server key 255
tacacs-server port 256
tacacs-server retransmit 256
tacacs-server timeout 257
show tacacs-server 257
AAA 258
aaa accounting commands 258
aaa accounting dot1x 259
aaa accounting exec 260
aaa accounting update 261
aaa authorization exec 262
aaa group server 263
server 263
accounting dot1x 264
accounting commands 264
Contents
– 17 –
accounting exec 265
authorization exec 265
show accounting 266
show authorization 267
Web Server 268
ip http authentication 268
ip http port 269
ip http secure-port 269
ip http secure-server 270
ip http server 271
Telnet Server 272
ip telnet max-sessions 272
ip telnet port 273
ip telnet server 273
telnet (client) 274
show ip telnet 274
Secure Shell 275
ip ssh authentication-retries 278
ip ssh server 278
ip ssh server-key size 279
ip ssh timeout 279
delete public-key 280
ip ssh crypto host-key generate 281
ip ssh crypto zeroize 281
ip ssh save host-key 282
show ip ssh 282
show public-key 283
show ssh 284
802.1X Port Authentication 284
General Commands 285
dot1x default 285
dot1x eapol-pass-through 286
dot1x system-auth-control 287
Authenticator Commands 287
dot1x intrusion-action 287
Contents
– 18 –
dot1x max-reauth-req 288
dot1x max-req 288
dot1x operation-mode 289
dot1x port-control 290
dot1x re-authentication 290
dot1x timeout quiet-period 291
dot1x timeout re-authperiod 291
dot1x timeout supp-timeout 292
dot1x timeout tx-period 293
dot1x re-authenticate 293
Supplicant Commands 294
dot1x identity profile 294
dot1x max-start 294
dot1x pae supplicant 295
dot1x timeout auth-period 296
dot1x timeout held-period 296
dot1x timeout start-period 297
Information Display Commands 297
show dot1x 297
Management IP Filter 300
management 300
show management 301
PPPoE Intermediate Agent 302
pppoe intermediate-agent 303
pppoe intermediate-agent format-type 303
pppoe intermediate-agent port-enable 304
pppoe intermediate-agent port-format-type 305
pppoe intermediate-agent port-format-type remote-id-delimiter 306
pppoe intermediate-agent trust 306
pppoe intermediate-agent vendor-tag strip 307
clear pppoe intermediate-agent statistics 307
show pppoe intermediate-agent info 308
show pppoe intermediate-agent statistics 309
9 General Security Measures 311
Contents
– 19 –
Port Security 312
mac-learning 312
port security 313
port security mac-address-as-permanent 315
show port security 315
Network Access (MAC Address Authentication) 317
network-access aging 318
network-access mac-filter 319
mac-authentication reauth-time 320
network-access dynamic-qos 320
network-access dynamic-vlan 321
network-access guest-vlan 322
network-access link-detection 323
network-access link-detection link-down 324
network-access link-detection link-up 324
network-access link-detection link-up-down 325
network-access max-mac-count 325
network-access mode mac-authentication 326
network-access port-mac-filter 327
mac-authentication intrusion-action 328
mac-authentication max-mac-count 328
clear network-access 329
show network-access 329
show network-access mac-address-table 330
show network-access mac-filter 331
Web Authentication 332
web-auth login-attempts 333
web-auth quiet-period 333
web-auth session-timeout 334
web-auth system-auth-control 334
web-auth 335
web-auth re-authenticate (Port) 335
web-auth re-authenticate (IP) 336
show web-auth 336
show web-auth interface 337
Contents
– 20 –
show web-auth summary 337
DHCPv4 Snooping 338
ip dhcp snooping 339
ip dhcp snooping information option 341
ip dhcp snooping information option encode no-subtype 342
ip dhcp snooping information option remote-id 343
ip dhcp snooping information option tr101 board-id 344
ip dhcp snooping information policy 344
ip dhcp snooping limit rate 345
ip dhcp snooping verify mac-address 345
ip dhcp snooping vlan 346
ip dhcp snooping information option circuit-id 347
ip dhcp snooping trust 348
clear ip dhcp snooping binding 349
clear ip dhcp snooping database flash 350
ip dhcp snooping database flash 350
show ip dhcp snooping 351
show ip dhcp snooping binding 351
DHCPv6 Snooping 351
ipv6 dhcp snooping 352
ipv6 dhcp snooping option remote-id 355
ipv6 dhcp snooping option remote-id policy 356
ipv6 dhcp snooping vlan 357
ipv6 dhcp snooping max-binding 358
ipv6 dhcp snooping trust 358
clear ipv6 dhcp snooping binding 359
clear ipv6 dhcp snooping statistics 360
show ipv6 dhcp snooping 360
show ipv6 dhcp snooping binding 360
show ipv6 dhcp snooping statistics 361
IPv4 Source Guard 361
ip source-guard binding 362
ip source-guard 364
ip source-guard max-binding 365
ip source-guard mode 366
/