D-Link xStack DES-6500 Cli Manual
D-Link xStack DES-6500 Cli Manual

D-Link xStack DES-6500 Cli Manual

Modular layer 3 chassis ethernet switch
Hide thumbs Also See for xStack DES-6500:

Advertisement

Quick Links

CLI Manual
DES-6500
TM
Product Model :
Modular Layer 3 Chassis Ethernet Switch
Release 3.6

Advertisement

Table of Contents
loading

Summary of Contents for D-Link xStack DES-6500

  • Page 1 CLI Manual DES-6500 Product Model : Modular Layer 3 Chassis Ethernet Switch Release 3.6...
  • Page 3: Table Of Contents

    Access Authentication Control Commands ..................162 SSH Commands ..........................187 SSL Commands........................... 195 802.1X Commands ..........................201 Access Control List (ACL) Commands (Including CPU)................. 222 Safeguard Engine Commands ......................248 Traffic Segmentation Commands......................251 D-Link Single IP Management Commands................... 254...
  • Page 4 Time and SNTP Commands ......................... 266 ARP Commands ..........................272 VRRP Commands ..........................276 Routing Table Commands ........................284 Route Redistribution Commands......................288 DHCP Relay Commands ........................294 DNS Relay Commands ........................300 RIP Commands ........................... 304 DVMRP Commands..........................307 PIM Commands...........................
  • Page 5: Introduction

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual NTRODUCTION The xStack DES-6500 layer 3 modular chassis Ethernet switch is a member of the D-Link xStack family. Ranging from 10/100Mbps edge switches to core gigabit switches, the xStack switch family has been future-proof designed to provide a stacking architecture with fault tolerance, flexibility, port density, robust security and maximum throughput with a user-friendly management interface for the networking professional.
  • Page 6 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Setting the Switch’s IP Address Each switch must be assigned its own IP Address, which is used for communication with an SNMP network manager or other TCP/IP application (for example BOOTP, TFTP). The Switch’s default IP address is 10.90.90.90. You can change the default switch IP address to meet the specification of your networking address scheme.
  • Page 7 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Figure 1-3. Assigning an IP Address In the above example, the Switch was assigned an IP address of 10.53.13.144 with a subnet mask of 255.0.0.0. The system message Success indicates that the command was executed successfully. The Switch can now be configured and managed via...
  • Page 8: Using The Console Cli

    ONSOLE The xStack DES-6500 supports a console management interface that allows the user to connect to the Switch’s management agent via a serial port and a terminal or a computer running a terminal emulation program. The console can also be used over the network using the TCP/IP Telnet protocol.
  • Page 9 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Figure 2-1. Initial Console Screen Commands are entered at the command prompts, DES-6500:4#. There are a number of helpful features included in the CLI. Entering the ? command will display a list of all of the top-level commands.
  • Page 10 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Figure 2-3. Example Command Parameter Help In this case, the command config account was entered with the parameter <username>. The CLI will then prompt to enter the <username> with the message, Next possible completions:. Every command in the CLI has this feature, and complex commands have several layers of parameter prompting.
  • Page 11 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual If a command is entered that is unrecognized by the CLI, the top-level commands will be displayed under the Available commands: prompt. Figure 2-5. The Available Commands Prompt The top-level commands consist of commands such as show or config. Most of these commands require one or more parameters to narrow the top-level command.
  • Page 12: Command Syntax

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual OMMAND YNTAX The following symbols are used to describe how command entries are made and values and arguments are specified in this manual. The online help contained in the CLI and available through the console interface uses the same syntax.
  • Page 13 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual {braces} Purpose Encloses an optional value or set of optional arguments. Syntax reset {[config | system]} Description In the above syntax example, you have the option to specify config or system. It is not necessary to specify either optional value, however the effect of the system reset is dependent on which, if any, value is specified.
  • Page 14: Basic Switch Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ASIC WITCH OMMANDS The basic switch commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create account [admin | user] <username 15>...
  • Page 15 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create account Purpose Used to create user accounts. Syntax create [admin | user] <username 15> Description The create account command is used to create user accounts that consist of a username of 1 to 15 characters and a password of 0 to 15 characters.
  • Page 16 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To configure the user password of “dlink” account: D E S - 6 5 0 0 : 4 # c o n f i g a c c o u n t d l i n k...
  • Page 17 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete account Restrictions Only Administrator-level users can issue this command. Example usage: To delete the admin account “System”: D E S - 6 5 0 0 : 4 # d e l e t e a c c o u n t S y s t e m...
  • Page 18 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 C o n f i g u r a t i o n F i r m w a r e : B u i l d 3 . 6 0 . B 0 2 C o p y r i g h t ( C ) 2 0 0 4 - 2 0 0 8 D - L i n k C o r p o r a t i o n .
  • Page 19 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual C T R L + C E S C q Q u i t S P A C E n N e x t P a g e E N T E R N e x t...
  • Page 20 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D N S R S t a t u s : D i s a b l e d V R R P : D i s a b l e d...
  • Page 21 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # show serial_port Purpose Used to display the current serial port settings. Syntax show serial_port Description This command displays the current serial port settings.
  • Page 22 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To configure the baud rate: D E S - 6 5 0 0 : 4 # c o n f i g s e r i a l _ p o r t b a u d _ r a t e 1 1 5 2 0 0 C o m m a n d : c o n f i g s e r i a l _ p o r t b a u d _ r a t e 1 1 5 2 0 0 S u c c e s s .
  • Page 23 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d i s a b l e c l i p a g i n g C o m m a n d : d i s a b l e c l i p a g i n g S u c c e s s .
  • Page 24 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # enable web Purpose Used to enable the HTTP-based management software on the Switch. Syntax enable web <tcp_port_number 1-65535> Description This command is used to enable the Web-based management software on the Switch.
  • Page 25 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual save Purpose Used to save changes in the Switch’s configuration to non-volatile RAM. Syntax save Description This command is used to enter the current switch configuration into non-volatile RAM. The saved switch configuration will be loaded into the Switch’s memory each time the Switch is restarted.
  • Page 26 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual reset Purpose Used to reset the Switch to the factory default settings. Syntax reset {[config | system]} Description This command is used to restore the Switch’s configuration to the default settings assigned from the factory.
  • Page 27 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual logout Purpose Used to log out a user from the Switch’s console. Syntax logout Description This command terminates the current user’s session on the Switch’s console. Parameters None. Restrictions None.
  • Page 28 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config greeting_message Purpose Used to configure the greeting message or banner for the opening screen of the Command Line Interface. Syntax config greeting_message {default} Description This command is used to configure the greeting message or login banner for the opening screen of the CLI.
  • Page 29 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # show greeting_message Purpose Used to view the currently configured greeting message configured on the Switch. Syntax show greeting_message Description This command is used to view the currently configured greeting message on the Switch.
  • Page 30 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# console_swap unit 5 Command: console_swap unit 5 Console Swap To Unit 5 ---> press "Enter" DES-6507 Command Line Interface Firmware: Build 3.60.Bxx Copyright(C) 2004-2007 D-Link Corporation. All rights reserved.
  • Page 31: Switch Port Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual WITCH OMMANDS The switch port commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config ports [<portlist> | all] {speed [auto | 10_half | 10_full | 100_half | 100_full |...
  • Page 32 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config ports Any other configuration will result in a link down status for both ports. None denotes the Switch will serve no role for stacking. flow_control [enabled | disabled] – Enable or disable flow control for the specified ports.
  • Page 33 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To display the configuration of all ports on a standalone switch: D E S - 6 5 0 0 : 4 # s h o w p o r t s...
  • Page 34 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w p o r t s 1 : 1 d e s c r i p t i o n...
  • Page 35: Port Security Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ECURITY OMMANDS The port security commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config port_security ports [<portlist> | all] {admin_state [enabled | disabled] | max_learning_addr <max_lock_no 0-64>...
  • Page 36 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To configure the port security: D E S - 6 5 0 0 : 4 # c o n f i g p o r t _ s e c u r i t y p o r t s 5 : 1 - 5 : 5...
  • Page 37 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w p o r t _ s e c u r i t y p o r t s 1 : 1 - 1 : 1 0...
  • Page 38 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d e l e t e p o r t _ s e c u r i t y _ e n t r y _ v l a n _ n a m e...
  • Page 39: Network Management (Snmp) Commands

    The xStack DES-6500 support the Simple Network Management Protocol (SNMP) versions 1, 2c, and 3. Users can specify which version of SNMP to use to monitor and control the Switch. The three versions of SNMP vary in the level of security provided between the management station and the network device.
  • Page 40 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters config snmp engineID <snmp_engineID> show snmp engineID create snmp group <groupname 32> {v1 | v2c | v3 [noauth_nopriv | auth_nopriv | auth_priv]} {read_view <view_name 32> | write_view <view_name 32> | notify_view <view_name 32>}...
  • Page 41 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create snmp user source. Encryption  Scrambles the contents of messages to prevent it from being viewed by an unauthorized source. <username 32>  An alphanumeric name of up to 32 characters that Parameters will identify the new SNMP user.
  • Page 42 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create snmp user  <priv_key 32-32> - Enter an alphanumeric key string of exactly 32 characters, in hex form, that will be used to encrypt the contents of messages the host sends to the agent.
  • Page 43 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show snmp user Purpose Used to display information about each SNMP username in the SNMP group username table. Syntax show snmp user Description The show snmp user command displays information about each SNMP username in the SNMP group username table.
  • Page 44 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c r e a t e s n m p v i e w d l i n k v i e w 1 . 3 . 6 v i e w _ t y p e i n c l u d e d C o m m a n d : c r e a t e s n m p v i e w d l i n k v i e w 1 .
  • Page 45 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w s n m p v i e w C o m m a n d : s h o w s n m p v i e w...
  • Page 46 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create snmp community allowed to access on the Switch. read_only  Specifies that SNMP community members using the community string created with this command can only read the contents of the MIBs on the Switch.
  • Page 47 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show snmp community Purpose Used to display SNMP community strings configured on the Switch. Syntax show snmp community {<community_string 32>} Description The show snmp community command is used to display SNMP community strings that are configured on the Switch.
  • Page 48 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # show snmp engineID Purpose Used to display the identification of the SNMP engine on the Switch.
  • Page 49 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create snmp group  Authentication  Determines if an SNMP message is from a valid source.  Encryption  Scrambles the contents of messages to prevent it being viewed by an unauthorized source.
  • Page 50 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To delete the SNMP group named “sg1”. D E S - 6 5 0 0 : 4 # d e l e t e s n m p g r o u p s g 1 C o m m a n d : d e l e t e s n m p g r o u p s g 1 S u c c e s s .
  • Page 51 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual R e a d V i e w N a m e : R e a d V i e w W r i t e V i e w N a m e...
  • Page 52 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual G r o u p N a m e : W r i t e G r o u p R e a d V i e w N a m e...
  • Page 53 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create snmp host being viewed by an unauthorized source. noauth_nopriv  Specifies that there will be no authorization and no encryption of packets sent between the Switch and a remote SNMP manager.
  • Page 54 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # show snmp host Purpose Used to display the recipient of SNMP traps generated by the Switch’s SNMP agent.
  • Page 55 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create trusted_host Restrictions Only Administrator-level users can issue this command. Example usage: To create the trusted host: D E S - 6 5 0 0 : 4 # c r e a t e t r u s t e d _ h o s t 1 0 . 4 8 . 7 4 . 1 2 1 C o m m a n d : c r e a t e t r u s t e d _ h o s t 1 0 .
  • Page 56 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete trusted_host Description This command is used to delete a trusted host entry made using the create trusted_host command above. <ipaddr>  The IP address of the trusted host. Parameters Restrictions Only Administrator-level users can issue this command.
  • Page 57 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To turn on SNMP authentication trap support: D E S - 6 5 0 0 : 4 # e n a b l e s n m p a u t h e n t i c a t e _ t r a p s C o m m a n d : e n a b l e s n m p a u t h e n t i c a t e _ t r a p s S u c c e s s .
  • Page 58 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # disable snmp authenticate_traps Purpose Used to disable SNMP authentication trap support. Syntax disable snmp authenticate_traps Description This command is used to disable SNMP authentication support on the Switch.
  • Page 59 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c o n f i g s n m p s y s t e m _ c o n t a c t M I S...
  • Page 60 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c o n f i g s n m p s y s t e m _ n a m e D E S - 6 5 0 0 C h a s s i s...
  • Page 61 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d i s a b l e r m o n C o m m a n d : d i s a b l e r m o n S u c c e s s .
  • Page 62: Switch Utility Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual WITCH TILITY OMMANDS The switch utility commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters download [firmware_fromTFTP <ipaddr> <path_filename 64> unit [all_line_card | cpu | <unitid 1-8>] | cfg_fromTFTP <ipaddr>...
  • Page 63 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual download  increment  Allows the download of a partial switch configuration file. This allows a file to be downloaded that will change only the Switch parameters explicitly stated in the configuration file.
  • Page 64 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual upload Purpose Used to upload the current switch settings or the switch history log to a TFTP server or a CompactFlash memory card. Syntax upload [cfg_toTFTP | log_toTFTP] <ipaddr> <path_filename 64>...
  • Page 65 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ping be specified. The default is 1 second. Pinging an IP address without the times parameter will ping the target device an infinite amount of times. Restrictions None. Example usage: To ping the IP address 10.48.74.121 four times:...
  • Page 66 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual traceroute Purpose Used to trace the routed path between the Switch and a destination endstation. Syntax <ipaddr> {ttl <value 1-60> | port <value 30000-64900> | timeout <sec 1-65535> | probe <value <1-9>}...
  • Page 67 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual enable autoconfig (same as: config ipif System dhcp). The DHCP server must have the TFTP server IP address and configuration file name, and be configured to deliver this information in the data field of the DHCP reply packet. The TFTP server must be running and have the requested configuration file in its base directory when the request is received from the Switch.
  • Page 68 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual C o m m a n d : d o w n l o a d c o n f i g u r a t i o n 1 0 . 4 1 . 4 4 . 4 4 c : \ c f g \ s e t t i n g .
  • Page 69 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual With autoconfig enabled, the Switch ipif settings now define the NOTE: Switch as a DHCP client. Use the show switch command to display the new IP settings status. show autoconfig Purpose Used to display the current autoconfig status of the Switch.
  • Page 70: Network Monitoring Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ETWORK ONITORING OMMANDS The network monitoring commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters show packet ports <portlist>...
  • Page 71 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show packet ports relevant to the type of packets and Table C is relevant to the type of frame associated with these packets. <portlist>  Specifies a range of ports to be displayed. The port list...
  • Page 72 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show error ports Description This command will display all of the packet error statistics collected and logged by the Switch for a given port list. <portlist>  Specifies a range of ports to be displayed. The port...
  • Page 73 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To display the current CPU utilization: D E S - 6 5 0 0 : 4 # s h o w u t i l i z a t i o n c p u...
  • Page 74 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show stack_information Purpose Used to display the stack information table. Syntax show stack_information Description This command displays stack information. Parameters None. Restrictions None. Usage example: To display stack information: DES-6500:4#show stack_information...
  • Page 75 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual clear counters Purpose Used to clear the Switch’s statistics counters. Syntax clear counters {ports <portlist>} Description This command will clear the counters used by the Switch to compile statistics. ports <portlist>  Specifies a range of ports to be displayed. The...
  • Page 76 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show log Purpose Used to display the Switch history log. Syntax show log {index <value_list>} Description This command will display the contents of the Switch’s history log. index <value_list>  Enter a value that corresponds to an entry Parameters made in the log.
  • Page 77 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual disable syslog Purpose Used to disable the system log function on the Switch. Syntax disable syslog Description The disable syslog command disables the system log function on the Switch. After disabling, Syslog entries will no longer be sent to a remote host.
  • Page 78 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create syslog host | local1 | local2 | local3 | local4 | local5 | local6 | local7] | udp_port <udp_port_number> | ipaddress <ipaddr> | state [enabled | disabled]} Description The create syslog host command is used to create a new syslog host.
  • Page 79 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create syslog host local use 4 (local4) local use 5 (local5) local use 6 (local6) local use 7 (local7) local0  Specifies that local use 0 messages will be sent to the remote host.
  • Page 80 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config syslog host local7] | udp_port<udp_port_number> | ipaddress <ipaddr> | state [enabled | disabled]] Description The config syslog host command is used to configure the syslog protocol to send system log information to a remote host.
  • Page 81 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config syslog host local use 4 (local4) local use 5 (local5) local use 6 (local6) local use 7 (local7) local0  Specifies that local use 0 messages will be sent to the remote host.
  • Page 82 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # c o n f i g s y s l o g h o s t 1 i p a d d r e s s 1 0 .
  • Page 83 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config syslog host all been explicitly assigned a Facility may use any of the "local use" facilities or they may use the "user-level" Facility. Those Facilities that have been designated are shown in the following: Bold font indicates that the facility values the Switch currently supports.
  • Page 84 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To configure all syslog hosts: D E S - 6 5 0 0 : 4 # c o n f i g s y s l o g h o s t a l l s e v e r i t y a l l C o m m a n d : c o n f i g s y s l o g h o s t a l l s e v e r i t y a l l S u c c e s s .
  • Page 85 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d e l e t e s y s l o g h o s t 4 C o m m a n d : d e l e t e s y s l o g h o s t 4 S u c c e s s .
  • Page 86 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config system_severity to the SNMP agent (trap), the Switch’s log or both. Events occurring on the Switch are separated into three main categories.  Information – Events classified as information are basic events occurring on the Switch that are not deemed as problematic, such as enabling or disabling various functions on the Switch.
  • Page 87 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show system_severity Purpose To display the current severity settings set on the Switch. Syntax show system_severity Description This command is used to view the severity settings that have been implemented on the Switch using the config system_severity command.
  • Page 88: Multiple Spanning Tree Protocol (Mstp) Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual (MSTP) C ULTIPLE PANNING ROTOCOL OMMANDS This switch supports three versions of the Spanning Tree Protocol; 802.1d STP, 802.1w Rapid STP and 802.1s MSTP. Multiple Spanning Tree Protocol, or MSTP, is a standard defined by the IEEE community that allows multiple VLANs to be mapped to a single spanning tree instance, which will provide multiple pathways across the network.
  • Page 89 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters delete stp instance_id <value 1-15> config stp priority <value 0-61440> instance_id <value 0-15> config stp mst_config_id {revision_level <int 0-65535> | name <string>} config stp mst_ports <portlist> instance_id <value 0-15> {internalCost [auto | value 1-200000000] | priority <value 0-240>}...
  • Page 90 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d i s a b l e s t p C o m m a n d : d i s a b l e s t p S u c c e s s .
  • Page 91 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config stp has still not been received from the Root Bridge, the Switch will start sending its own BPDU to all other switches for permission to become the Root Bridge. If it turns out that your switch has the lowest Bridge Identifier, it will become the Root Bridge.
  • Page 92 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # config stp ports Purpose Used to setup STP on the port level. Syntax config stp ports <portlist> {externalCost [auto | <value 1- 200000000>] | hellotime <value 1-10>...
  • Page 93 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config stp ports received it automatically loses edge port status. false indicates that the port does not have edge port status. p2p [true | false | auto] – true indicates a point-to-point (P2P) shared link.
  • Page 94 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c r e a t e s t p i n s t a n c e _ i d 2 C o m m a n d : c r e a t e s t p i n s t a n c e _ i d 2 S u c c e s s .
  • Page 95 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # Example usage: To remove VID 10 from instance ID 2: D E S - 6 5 0 0 : 4 # c o n f i g s t p i n s t a n c e _ i d 2 r e m o v e _ v l a n 1 0 C o m m a n d : c o n f i g s t p i n s t a n c e _ i d 2 r e m o v e _ v l a n 1 0 S u c c e s s .
  • Page 96 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config stp priority instance_id <value 0-15> - Enter the value corresponding to the previously configured instance ID of which to set the priority value. An instance id of 0 denotes the default instance_id (CIST) internally set on the Switch.
  • Page 97 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # config stp mst_ports Purpose Used to update the port configuration for a MSTP instance.
  • Page 98 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual i n s t a n c e _ i d 2 i n t e r n a l C o s t a u t o p r i o r i t y 1 6 S u c c e s s .
  • Page 99 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual F o r w a r d D e l a y : 1 5 M a x A g e : 2 0 T X H o l d C o u n t...
  • Page 100 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w s t p p o r t s 1 : 1 - 1 : 9...
  • Page 101 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual E x t e r n a l R o o t C o s t : 2 0 0 0 1 2 R e g i o n a l R o o t B r i d g e...
  • Page 102: Forwarding Database Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ORWARDING ATABASE OMMANDS The forwarding database commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create fdb <vlan_name 32> <macaddr> port <port>...
  • Page 103 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c r e a t e f d b d e f a u l t 0 0 - 0 0 - 0 0 - 0 0 - 0 1 - 0 2...
  • Page 104 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config multicast_fdb [add | delete]  Add will add ports to the forwarding table. Delete will remove ports from the multicast forwarding table.  <portlist>  Specifies a range of ports to be displayed. The port list is specified by listing the lowest line card number and the beginning port number on that line card, separated by a colon.
  • Page 105 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # config fdb aging_time Purpose Used to set the aging time of the forwarding database.
  • Page 106 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To delete a permanent FDB entry: D E S - 6 5 0 0 : 4 # d e l e t e f d b d e f a u l t 0 0 - 0 0 - 0 0 - 0 0 - 0 1 - 0 2 C o m m a n d : d e l e t e f d b d e f a u l t 0 0 - 0 0 - 0 0 - 0 0 - 0 1 - 0 2 S u c c e s s .
  • Page 107 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # show multicast_fdb Purpose Used to display the contents of the Switch’s multicast forwarding database. Syntax show mulitcast_fdb {vlan <vlan_name 32> | mac_address <macaddr>}...
  • Page 108 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show fdb <macaddr>  The MAC address that is present in the forwarding database table. static  Displays the static MAC address entries. aging_time  Displays the aging time for the MAC address forwarding database.
  • Page 109 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ipfdb Purpose Used to display the current IP address forwarding database table. Syntax show ipfdb {<ipaddr>} Description This command will display the current contents of the Switch’s IP forwarding database.
  • Page 110: Broadcast Storm Control Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ROADCAST TORM ONTROL OMMANDS On a computer network, packets such as Multicast packets and Broadcast packets continually flood the network as normal procedure. At times, this traffic may increase do to a malicious endstation on the network or a malfunctioning device, such as a faulty network card.
  • Page 111 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config traffic control <portlist>  Used to specify a range of ports to be configured for traffic Parameters control. The port list is specified by listing the lowest line card number and the beginning port number on that line card, separated by a colon.
  • Page 112 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config traffic control Broadcast packet counts sent from the Switch’s chip to the Traffic Control function. These packet counts are the determining factor in deciding when incoming packets exceed the Threshold value.
  • Page 113 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # config traffic control_trap Purpose Used to configure the trap settings for the packet storm control mechanism. Syntax config traffic control_trap [none | storm_occurred |...
  • Page 114 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show traffic control between line card 1, port 3 and line card 2, port 4  in numerical order. Restrictions None. Example usage: To display traffic control setting: D E S - 6 5 0 0 : 4 # s h o w t r a f f i c c o n t r o l 1 : 1 - 1 : 5...
  • Page 115: Qos Commands

    OMMANDS The xStack DES-6500 supports 802.1p priority queuing. This switch has eight classes of service for each port on the Switch, one of which is internal and not configurable to the user. These hardware classes of service are numbered from 6 (Class 6) —...
  • Page 116 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters config bandwidth_control [<portlist> | all] {rx_rate [no_limit | <value 1-9999>] | tx_rate [no_limit <value 1-9999>]} show bandwidth_control {<portlist>} config scheduling <class_id 0-6> max_packet <value 0-15> show scheduling config 802.1p user_priority <priority 0-7>...
  • Page 117 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config bandwidth_control packets transmitted by the above specified ports.  <value 1-9999>  Specifies the packet limit, in Mbps, that the above ports will be allowed to transmit. Restrictions Only Administrator-level users can issue this command.
  • Page 118 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -...
  • Page 119 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config scheduling method of forwarding packets — as long as the priority classes with a 0 in their max_packet field are empty. When a packet arrives in a priority class with a 0 in its max_packet field, this class will automatically begin forwarding packets until it is empty.
  • Page 120 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show scheduling Purpose Used to display the currently configured traffic scheduling on the Switch. Syntax show scheduling Description The show scheduling command displays the current configuration for the maximum number of packets (max_packets) assigned to the seven hardware priority classes on the Switch.
  • Page 121 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config 802.1p user_priority Value Priority Queue --------- ------------------ <priority 0-7>  Specifies which of the eight 802.1p priority tags (0 Parameters through 7) to map to one of the Switch’s hardware priority classes of service (<class_id>, 0 through 6).
  • Page 122 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual P r i o r i t y - 1 - > < C l a s s - 0 > P r i o r i t y - 2 - >...
  • Page 123 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show 802.1 default_priority Purpose Used to display the currently configured 802.1p priority tags that will be assigned to incoming, untagged packets before being forwarded to its destination. Syntax show 802.1p default_priority {<portlist>} Description The show 802.1p default_priority command displays the currently...
  • Page 124 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config scheduling_mechanism Purpose Used to configure the scheduling mechanism for the QoS function Syntax config scheduling_mechanism [strict | weight_fair] Description The config scheduling_mechanism command allows the user to select between a Weight Fair (WRR) and a Strict mechanism for emptying the priority classes of service of the QoS function.
  • Page 125 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example Usage: To show the scheduling mechanism: D E S - 6 5 0 0 : 4 # s h o w s c h e d u l i n g _ m e c h a n i s m...
  • Page 126 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual disable hol_prevention prevention. Parameters None. Restrictions Only Administrator-level users can issue this command. Example Usage: To disable HOL prevention: D E S - 6 5 0 0 : 4 # d i s a b l e h o l _ p r e v e n t i o n C o m m a n d : d i s a b l e h o l _ p r e v e n t i o n S u c c e s s .
  • Page 127: Port Mirroring Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual IRRORING OMMANDS The port mirroring commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config mirror port <port> [add | delete] source ports <portlist> [rx | tx | both]...
  • Page 128 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To add the mirroring ports: D E S - 6 5 0 0 : 4 # c o n f i g m i r r o r p o r t 1 : 1 0 a d d s o u r c e p o r t s...
  • Page 129 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c o n f i g m i r r o r p o r t 1 : 1 0 d e l e t e s o u r c e...
  • Page 130 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d i s a b l e m i r r o r C o m m a n d : d i s a b l e m i r r o r S u c c e s s .
  • Page 131: Vlan Commands

    VLAN C OMMANDS The xStack DES-6500 incorporates protocol-based VLANs. This standard, defined by the IEEE 802.1v standard maps packets to protocol-defined VLANs by examining the type octet within the packet header to discover the type of protocol associated with it. After assessing the protocol, the Switch will forward the packets to all ports within the protocol-assigned VLAN. This feature will benefit the administrator by better balancing load sharing and enhancing traffic classification.
  • Page 132 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create vlan tag <vlanid 2-4094>  The VLAN ID of the VLAN to be created. Allowed values = 2-4094 type – This parameter uses the type field of the packet header to determine the packet protocol and destination VLAN.
  • Page 133 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create vlan information is defined by the Systems Network Architecture (SNA) 802.2 Protocol.  protocol–snaEthernet2 - Using this parameter will instruct the Switch to forward packets to this VLAN if the tag in the packet header is concurrent with this protocol.
  • Page 134 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual NOTE: A specific protocol VLAN and a user defined protocol VLAN with the same encapsulation protocol cannot coexist and will result in a Fail! Message. (For example, if a user creates an Ethernet2 protocol VLAN, the...
  • Page 135 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config vlan add Purpose Used to add additional ports to a previously configured VLAN. Syntax config vlan <vlan_name 32> {[add [ tagged | untagged | forbidden] <portlist> | advertisement [enabled | disabled]}...
  • Page 136 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config vlan delete <portlist>  A range of ports to delete from the VLAN. The port list is specified by listing the lowest line card number and the beginning port number on that line card, separated by a colon.
  • Page 137 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config gvrp by the Switch. pvid – Specifies the default VLAN ID associated with the port. Restrictions Only Administrator-level users can issue this command. Example usage: To set the ingress checking status, the sending and receiving GVRP information :...
  • Page 138 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual disable gvrp configuration on the Switch. Parameters None. Restrictions Only Administrator-level users can issue this command. Example usage: To disable the Group VLAN Registration Protocol (GVRP): D E S - 6 5 0 0 : 4 # d i s a b l e g v r p C o m m a n d : d i s a b l e g v r p S u c c e s s .
  • Page 139 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual F o r b i d d e n p o r t s : T o t a l E n t r i e s : 1 D E S - 6 5 0 0 : 4 #...
  • Page 140 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w g v r p C o m m a n d : s h o w g v r p...
  • Page 141: Link Aggregation Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual GGREGATION OMMANDS The link aggregation commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create link_aggregation group_id <value 1-32> {type [lacp | static]} delete link_aggregation group_id <value 1-32>...
  • Page 142 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c r e a t e l i n k _ a g g r e g a t i o n g r o u p _ i d 1 C o m m a n d : c r e a t e l i n k _ a g g r e g a t i o n g r o u p _ i d 1 S u c c e s s .
  • Page 143 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual group _id <value 1-32>  Specifies the group ID. The Switch allows up Parameters to 32 link aggregation groups to be configured. The group number identifies each of the groups.
  • Page 144 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c o n f i g l i n k _ a g g r e g a t i o n g r o u p _ i d 1 m a s t e r _ p o r t...
  • Page 145 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show link_aggregation Purpose Used to display the current link aggregation configuration on the Switch. Syntax show link_aggregation {group_id <value 1-32> | algorithm} Description This command will display the current link aggregation configuration of the Switch.
  • Page 146 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config lacp_port mode – Select the mode to determine if LACP ports will initially send LACP control frames.  active – Active LACP ports are capable of processing and sending LACP control frames. This allows LACP compliant devices to negotiate the aggregated link so the group may be changed dynamically as needs require.
  • Page 147 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w l a c p _ p o r t 1 : 1 - 1 : 8...
  • Page 148: Ip Commands (Including Ip Multinetting)

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual IP C IP M OMMANDS NCLUDING ULTINETTING IP Multinetting is a function that allows multiple IP interfaces to be assigned to the same VLAN. This is beneficial to the administrator when the number of IPs on the original interface is insufficient and the network administrator wishes not to resize the interface.
  • Page 149 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create ipif (10.1.2.3/8). <vlan_name 32>  The name of the VLAN that will be associated with the above IP interface. secondary – Enter this parameter if this configured IP interface is to be a secondary IP interface of the VLAN previously specified.
  • Page 150 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config ipif vlan <vlan_name 32>  The name of the VLAN corresponding to the previously created IP interface. If a primary and secondary IP interface are configured for the same VLAN (subnet), the user cannot change the VLAN of the IP interface.
  • Page 151 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual disable ipif Purpose Used to disable the configuration of an IP interface on the Switch. Syntax disable ipif [<ipif_name 12> | all] Description This command will disable an IP interface on the Switch, without altering its configuration values.
  • Page 152 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ipif Purpose Used to display the configuration of an IP interface on the Switch. Syntax show ipif {<ipif_name 12>} Description This command will display the configuration of an IP interface on the Switch.
  • Page 153: Igmp Commands (Including Igmp V3)

    If there are no members on a subnetwork, packets will not be forwarded to that subnetwork. The current release of the xStack DES-6500 now implements IGMPv3. Improvements of IGMPv3 over version 2 include: ...
  • Page 154 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config igmp <ipif_name 12>  The name of the IP interface for which to configure Parameters IGMP. all  Specifies all the IP interfaces on the Switch. version <value 1-3>  Select the IGMP version number.
  • Page 155 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w i g m p C o m m a n d : s h o w i g m p...
  • Page 156 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # Example usage: To view details regarding the IGMP group: D E S - 6 5 0 0 : 4 # s h o w i g m p g r o u p g r o u p 2 2 4 . 0 . 1 . 1 i p i f S y s t e m C o m m a n d : s h o w i g m p g r o u p g r o u p 2 2 4 .
  • Page 157: Igmp Snooping Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual IGMP S NOOPING OMMANDS The IGMP Snooping commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config igmp_snooping [<vlan_name 32> | all] {host_timeout <sec 1-16711450> | router_timeout <sec 1-16711450>...
  • Page 158 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To configure IGMP snooping: D E S - 6 5 0 0 : 4 # c o n f i g i g m p _ s n o o p i n g d e f a u l t h o s t _ t i m e o u t 2 5 0...
  • Page 159 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config igmp_snooping querier  By default, the robustness variable is set to 2. You might want to increase this value if you expect a subnet to be lossy. last_member_query_interval <sec 1-25>  The maximum amount of time between group-specific query messages, including those sent in response to leave-group messages.
  • Page 160 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual disable igmp_snooping Purpose Used to enable IGMP snooping on the Switch. Syntax disable igmp_snooping {forward_mcrouter_only} Description This command disables IGMP snooping on the Switch. IGMP snooping can be disabled only if IP multicast routing is not being used. Disabling IGMP snooping allows all IGMP and IP multicast traffic to flood within a given IP interface.
  • Page 161 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To set up static router ports: D E S - 6 5 0 0 : 4 # c o n f i g r o u t e r _ p o r t s d e f a u l t a d d 2 : 1 - 2 : 1 0 C o m m a n d : c o n f i g r o u t e r _ p o r t s d e f a u l t a d d 2 : 1 - 2 : 1 0 S u c c e s s .
  • Page 162 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show router_ports Purpose Used to display the currently configured router ports on the Switch. Syntax show router_ports {vlan <vlan_name 32>} {static | dynamic | forbidden} Description This command will display the router ports currently configured on the Switch.
  • Page 163 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show igmp_snooping snooping configuration. Restrictions None. Example usage: To show IGMP snooping: D E S - 6 5 0 0 : 4 # s h o w i g m p _ s n o o p i n g...
  • Page 164 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual V L A N N a m e : d e f a u l t M u l t i c a s t g r o u p : 2 2 4 . 0 . 0 . 2...
  • Page 165 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show igmp_snooping forwarding Purpose Used to display the IGMP snooping forwarding table entries on the Switch. Syntax show igmp_snooping forwarding {vlan <vlan_name 32>} Description This command will display the current IGMP snooping forwarding table entries currently configured on the Switch.
  • Page 166: Access Authentication Control Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual CCESS UTHENTICATION ONTROL OMMANDS The Access Authentication Control commands allows secure access to the Switch using the TACACS / XTACACS / TACACS+ and RADIUS protocols. When a user logs in to the Switch or tries to access the administrator level privilege, he or she is prompted for a password.
  • Page 167 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual NOTE: TACACS, XTACACS and TACACS+ are separate entities and are not compatible. The Switch and the server must be configured exactly the same, using the same protocol. (For example, if the Switch is set up for TACACS authentication, so must be the host server.)
  • Page 168 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters config authen parameter attempt <int 1-255> show authen parameter enable admin config admin local_enable <password 15> Each command is listed, in detail, in the following sections. enable authen_policy Purpose Used to enable system access authentication policy.
  • Page 169 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d i s a b l e a u t h e n _ p o l i c y C o m m a n d : d i s a b l e a u t h e n _ p o l i c y S u c c e s s .
  • Page 170 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c r e a t e a u t h e n _ l o g i n m e t h o d _ l i s t _ n a m e...
  • Page 171 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config authen_login server listed in the server group list.  server_group <string 15> - Adding this parameter will require the user to be authenticated using a user-defined server group previously configured on the Switch.
  • Page 172 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # Example usage: To configure the default method list with authentication methods XTACACS, TACACS+ and local, in that order:...
  • Page 173 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show authen_login  Method List Name – The name of a previously configured method list name.  Priority – Defines which order the method list protocols will be queried for authentication when a user attempts to log on to the Switch.
  • Page 174 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create authen_enable method_list_name privileges to Administrator level privileges using authentication methods on the Switch. Once a user acquires normal user level privileges on the Switch, he or she must be authenticated by a method on the Switch to gain administrator privileges on the Switch, which is defined by the Administrator.
  • Page 175 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config authen_enable a combination of up to four (4) of the following authentication methods:  tacacs – Adding this parameter will require the user to be authenticated using the TACACS protocol from the remote TACACS server hosts of the TACACS server group list.
  • Page 176 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To configure the user defined method list “Trinity” with authentication methods TACACS, XTACACS and local, in that order. D E S - 6 5 0 0 : 4 # c o n f i g a u t h e n _ e n a b l e m e t h o d _ l i s t _ n a m e T r i n i t y...
  • Page 177 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show authen_enable Purpose Used to display the method list of authentication methods for promoting normal user level privileges to Administrator level privileges on the Switch. Syntax show authen_enable [default | method_list_name <string 15> | all]...
  • Page 178 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual d e f a u l t t a c a c s + B u i l t - i n G r o u p l o c a l...
  • Page 179 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual d e f a u l t S u c c e s s . D E S - 6 5 0 0 : 4 # show authen application Purpose Used to display authentication methods for the various applications on the Switch.
  • Page 180 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create authen server_host authentication protocol can be run on the same physical server host but, remember that TACACS/XTACACS/TACACS+ and RADIUS are separate entities and are not compatible with each other. The maximum supported number of server hosts is 16.
  • Page 181 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config authen server_host Purpose Used to configure a user-defined authentication server host. Syntax config authen server_host <ipaddr> protocol [tacacs | xtacacs | tacacs+ | radius] {port <int 1-65535> | key [<key_string 254> | none] | timeout <int 1-255>...
  • Page 182 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To configure a TACACS authentication server host, with port number 4321, a timeout value of 12 seconds and a retransmit count of 4. D E S - 6 5 0 0 : 4 # c o n f i g a u t h e n s e r v e r _ h o s t 1 0 . 1 . 1 . 1 2 1 p r o t o c o l t a c a c s p o r t 4 3 2 1 t i m e o u t 1 2 r e t r a n s m i t 4 C o m m a n d : c o n f i g a u t h e n s e r v e r _ h o s t 1 0 .
  • Page 183 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show authen server_host Purpose Used to view a user-defined authentication server host. Syntax show authen server_host Description This command is used to view user-defined authentication server hosts previously created on the Switch.
  • Page 184 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create authen server_group Purpose Used to create a user-defined authentication server group. Syntax create authen server_group <string 15> Description This command will create an authentication server group. A server group is a technique used to group TACACS/XTACACS/TACACS+ and RADIUS server hosts into user defined categories for authentication using method lists.
  • Page 185 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config authen server_group utilizing the TACACS+ protocol may be added to this group.  radius - Use this parameter to utilize the built-in RADIUS server protocol on the Switch. Only server hosts utilizing the RADIUS protocol may be added to this group.
  • Page 186 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To delete the server group “group_1”: D E S - 6 5 0 0 : 4 # d e l e t e s e r v e r _ g r o u p g r o u p _ 1 C o m m a n d : d e l e t e s e r v e r _ g r o u p g r o u p _ 1 S u c c e s s .
  • Page 187 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config authen parameter response_timeout Purpose Used to configure the amount of time the Switch will wait for a user to enter authentication before timing out. Syntax config authen parameter response_timeout <int 0-255>...
  • Page 188 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config authen parameter attempt disconnected from the Switch. Parameters parameter attempt <int 1-255> - Set the maximum number of attempts the user may try to become authenticated by the Switch, before being locked out.
  • Page 189 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual enable admin Purpose Used to promote user level privileges to administrator level privileges. Syntax enable admin Description This command is for users who have logged on to the Switch on the normal user level, to become promoted to the administrator level.
  • Page 190 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c o n f i g a d m i n l o c a l _ e n a b l e...
  • Page 191: Ssh Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual SSH C OMMANDS The steps required to use the SSH protocol for secure communication between a remote PC (the SSH Client) and the Switch (the SSH Server), are as follows: ...
  • Page 192 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual enable ssh Purpose Used to enable SSH. Syntax enable ssh Description This command is used to enable SSH on the Switch. Parameters None. Restrictions Only Administrator-level users can issue this command.
  • Page 193 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config ssh authmode Parameters password – This parameter may be chosen if the administrator wishes to use a locally configured password for authentication on the Switch. publickey - This parameter may be chosen if the administrator wishes to use a publickey configuration set on a SSH server, for authentication.
  • Page 194 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # config ssh server Purpose Used to configure the SSH server. Syntax config ssh server {maxsession <int 1-8> | contimeout <sec 120- 600>...
  • Page 195 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ssh server Restrictions None. Usage example: To display the SSH server: D E S - 6 5 0 0 : 4 # s h o w s s h s e r v e r...
  • Page 196 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config ssh user  Publickey – This parameter should be chosen to use the publickey on a SSH server for authentication.  None – This parameter should be chosen to employ no security authentication.
  • Page 197 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Note: To configure the SSH user, the administrator must create a user account on the Switch. For information concerning configuring a user account, please see the section of this manual entitled Basic Switch Commands and then the command, create user account.
  • Page 198 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To configure SSH algorithm: D E S - 6 5 0 0 : 4 # c o n f i g s s h a l g o r i t h m B l o w f i s h e n a b l e C o m m a n d : c o n f i g s s h a l g o r i t h m B l o w f i s h e n a b l e S u c c e s s .
  • Page 199: Ssl Commands

    This function of the Switch cannot be executed without the presence and implementation of the certificate file and can be downloaded to the Switch by utilizing a TFTP server. The xStack DES-6500 supports SSLv3 and TLSv1. Other versions of SSL may not be compatible with this Switch and may cause problems upon authentication and transfer of messages from client to host.
  • Page 200 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Each command is listed, in detail, in the following sections. enable ssl Purpose To enable the SSL function on the Switch. Syntax enable ssl {ciphersuite {RSA_with_RC4_128_MD5 | RSA_with_3DES_EDE_CBC_SHA | DHE_DSS_with_3DES_EDE_CBC_SHA |...
  • Page 201 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual NOTE: Enabling the SSL function on the Switch will disable the port for the web manager (port 80). To log on to the web based manager, the entry of your URL must begin with https://. (ex. https://10.90.90.90)
  • Page 202 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # d i s a b l e s s l c i p h e r s u i t e...
  • Page 203 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To view the SSL cache timeout on the Switch: D E S - 6 5 0 0 : 4 # s h o w s s l c a c h e t i m e o u t C o m m a n d : s h o w s s l c a c h e t i m e o u t C a c h e t i m e o u t i s 6 0 0 s e c o n d ( s ) .
  • Page 204 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual download certificate Purpose Used to download a certificate file for the SSL function on the Switch. Syntax download certificate <ipaddr> certfilename <path_filename 64> keyfilename <path_filename 64> Description This command is used to download a certificate file for the SSL function on the Switch from a TFTP server.
  • Page 205: Commands

    802.1X C OMMANDS The xStack DES-6500 implement the server-side of the IEEE 802.1x Port-based and MAC-based Network Access Control. This mechanism is intended to allow only authorized users, or other network devices, access to network resources by establishing criteria for each port on the Switch that a user or network device must meet before allowing that port to forward or receive frames.
  • Page 206 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Each command is listed, in detail, in the following sections. enable 802.1x Purpose Used to enable the 802.1x server on the Switch. Syntax enable 802.1x Description The enable 802.1x command enables the 802.1x Network Access control server application on the Switch.
  • Page 207 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create 802.1x user Purpose Used to create a new 802.1x user. Syntax create 802.1x user <username 15> Description The create 802.1x user command is used to create new 802.1x users.
  • Page 208 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual T o t a l e n t r i e s : 1 D E S - 6 5 0 0 : 4 # delete 802.1x user Purpose Used to delete an 802.1x user account on the Switch.
  • Page 209 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show 802.1x auth_configuration and transmitting directions, or just the receiving direction. OpenCtlDir: Both/In  Shows whether a controlled Port that is unauthorized will exert control over communication in both receiving and transmitting directions, or just the receiving direction.
  • Page 210 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual A d m i n C r l D i r : B o t h O p e n C r l D i r : B o t h...
  • Page 211 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w 8 0 2 . 1 x a u t h _ s t a t e C o m m a n d : s h o w 8 0 2 .
  • Page 212 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual C T R L + C E S C q Q u i t S P A C E n N e x t P a g e E n t e r N e x t E n t r y a A l l config 802.1x auth_mode...
  • Page 213 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config 802.1x capability ports none] Description The config 802.1x command has two capabilities that can be set for each port, authenticator and none. <portlist>  Specifies a range of ports. The port list is specified by...
  • Page 214 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config 802.1x auth_parameter and the highest port number of the range (also separated by a colon) are specified. The beginning and end of the port list range are separated by a dash. For example, 1:3 specifies line card number 1, port 3.
  • Page 215 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # config 802.1x auth_protocol Purpose Used to configure the 802.1x authentication protocol on the Switch.
  • Page 216 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config 802.1x init ports. MAC address approved for initialization can then be specified.  ports <portlist>  Specifies a range of ports. The port list is specified by listing the lowest line card number and the beginning port number on that line card, separated by a colon.
  • Page 217 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config 802.1x reauth ports mac-based - This instructs the Switch to re-authorize 802.1x function based on a specific MAC address. Ports approved for re-authorization can then be specified.  ports <portlist>  Specifies a range of ports. The port list is specified by listing the lowest line card number and the beginning port number on that line card, separated by a colon.
  • Page 218 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config radius add Purpose Used to add a new RADIUS server. Syntax config radius add <server_index 1-3> <server_ip> key <passwd 32> [default | {auth_port <udp_port_number 1-65535> | acct_port <udp_port_number 1-65535>}]...
  • Page 219 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To delete previously configured RADIUS server communication settings: D E S - 6 5 0 0 : 4 # c o n f i g r a d i u s d e l e t e 1 C o m m a n d : c o n f i g r a d i u s d e l e t e 1 S u c c e s s .
  • Page 220 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show radius Purpose Used to display the current RADIUS configurations on the Switch. Syntax show radius Description The show radius command is used to display the current RADIUS configurations on the Switch.
  • Page 221 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual r a d i u s A c c t C l i e n t I n v a l i d S e r v e r A d d r e s s e s...
  • Page 222 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual r a d i u s A u t h S e r v e r E n t r y = = > r a d i u s A u t h S e r v e r I n d e x : 0 r a d i u s A u t h S e r v e r A d d r e s s 0 .
  • Page 223 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual P o r t n u m b e r : 1 : 1 6 E n t e r s C o n n e c t i n g...
  • Page 224 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w a u t h _ s e s s i o n _ s t a t i s t i c s p o r t s 1 : 1 6...
  • Page 225 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # s h o w a u t h _ s t a t i s t i c s p o r t s 1 : 1 6...
  • Page 226: Access Control List (Acl) Commands (Including Cpu)

    CCESS ONTROL OMMANDS NCLUDING The xStack DES-6500 implement Access Control Lists that enable the Switch to deny network access to specific devices or device groups based on IP settings, MAC address, packet content and IPv6 settings. Command Parameters create access_profile profile_id <value 1-8>...
  • Page 227 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters delete cpu access_profile profile_id <value 1-5> profile_id <value 1-5> [add access_id <value 1-100> [ethernet {vlan config cpu access_profile <vlan_name 32> | source_mac <macaddr> | destination_mac <macaddr> | ethernet_type <hex 0x0-0xffff>} | ip {vlan <vlan_name 32> | source_ip <ipaddr>...
  • Page 228 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Due to a chipset limitation, the Switch supports a maximum of 8 access profiles. The rules used to define the access profiles are limited to a total of 9600 rules for the Switch, depending on line cards installed.
  • Page 229 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters create access_profile profile_id <value 1-8> [ethernet {vlan | source_mac <macmask> | destination_mac <macmask> | 802.1p | ethernet_type} config access_profile profile_id <value 1-8> [add access_id <value 1-65535> [ethernet {vlan <vlan_name 32>...
  • Page 230 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create access_profile (for Ethernet) Purpose Used to create an access profile on the Switch by examining the Ethernet part of the packet header. Masks entered can be combined with the values the Switch finds in the specified frame header fields.
  • Page 231 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config access_profile profile_id (for Ethernet) method, with the values the Switch finds in the specified frame header fields. Syntax config access_profile profile_id <value 1-8> [add access_id <value 1- 65535> [ethernet {vlan <vlan_name 32> | source_mac <macaddr> | destination_mac <macaddr>...
  • Page 232 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config access_profile profile_id (for Ethernet) the criteria specified previously in this command, before forwarding it on to the specified CoS queue. Otherwise, a packet will have its incoming 802.1p user priority re-written to its original value before being forwarded by the Switch.
  • Page 233 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create access_profile (IP) special emphasis on one or more of the following: vlan  Specifies a VLAN mask.  source_ip_mask <netmask>  Specifies an IP address mask for the ...
  • Page 234 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # c r e a t e a c c e s s _ p r o f i l e i p p r o t o c o l _ i d...
  • Page 235 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config access_profile profile_id (IP) code <value 0-255>  Specifies that the access profile will apply to this  ICMP code defined by a value between 0 and 255. igmp  Specifies that the Switch will examine the Internet Group ...
  • Page 236 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config access_profile profile_id (IP) CoS queue specified previously by the user. {replace_priority}  Enter this parameter to re-write the 802.1p default  priority of a packet to the value entered in the Priority field, which meets the criteria specified previously in this command, before forwarding it on to the specified CoS queue.
  • Page 237 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create access_profile (packet content mask) Parameters profile_id <value 1-8> - Specifies an index number between 1 and 8 that will identify the access profile being created with this command. packet_content_mask – Specifies that the Switch will mask the packet header beginning with the offset value specified as follows: ...
  • Page 238 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config access_profile profile_id (packet content mask) Parameters profile_id <value 1-8> - Enter an integer between 1 and 8 that is used to identify the access profile that will be configured with this command. This value is assigned to the access profile when it is created with the create access_profile command.
  • Page 239 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config access_profile profile_id (packet content mask) delete access_id <value 1-65535>  Use this command to delete a specific rule from the packet content mask profile. Up to 65535 rules may be specified for the Packet Content access profile.
  • Page 240 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create access_profile (ipv6) for the destination IPv6 address. Restrictions Only Administrator-level users can issue this command. Example usage: To create an access profile based on IPv6 classification: D E S - 6 5 0 0 : 4 # c r e a t e a c c e s s _ p r o f i l e i p v 6 c l a s s...
  • Page 241 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config access_profile profile_id (ipv6)  destination_ipv6 <ipv6addr> - Specifies an IP address mask for the destination IPv6 address. port <portlist> - The access profile for Ethernet may be defined for each port on the Switch.
  • Page 242 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete access_profile Purpose Used to delete a previously created access profile. Syntax delete access_profile profile_id <value 1-8> Description The delete access_profile command is used to delete a previously created access profile on the Switch.
  • Page 243 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual A c c e s s P r o f i l e I D : 1 T Y P E : E t h e r n e t...
  • Page 244 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create cpu access_profile Purpose Used to create an access profile specifically for CPU Interface Filtering on the Switch and to define which parts of each incoming frame’s header the Switch will examine.
  • Page 245 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create cpu access_profile igmp  Specifies that the switch will examine each frame’s Internet Group  Management Protocol (IGMP) field. type  Specifies that the switch will examine each frame’s IGMP Type ...
  • Page 246 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual s o u r c e _ i p _ m a s k 2 0 . 0 . 0 . 0 d e s t i n a t i o n _ i p _ m a s k 1 0 . 0 . 0 . 0 d s c p i c m p t y p e c o d e p e r m i t p r o f i l e _ i d 1 S u c c e s s .
  • Page 247 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config cpu access_profile <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> | offset_32-47 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> | offset_48-63 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0- 0xffffffff> | offset_64-79 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0- 0xffffffff>...
  • Page 248 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config cpu access_profile type <value 0-255>  Specifies that the access profile will apply to  packets that have this IGMP type value. tcp  Specifies that the Switch will examine the Transmission Control ...
  • Page 249 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config cpu access_profile permit | deny – Specify that the packet matching the criteria configured with command will either be permitted entry to the cpu or denied entry to the cpu.
  • Page 250 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual disable cpu_interface_filtering Purpose Used to disable CPU interface filtering on the Switch. Syntax disable cpu_interface_filtering Description This command is used, in conjunction with the enable cpu_interface_filtering command above, to enable and disable CPU interface filtering on the Switch without affecting configurations.
  • Page 251 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show cpu_access_profile Purpose Used to view the CPU access profile entry currently set in the Switch. Syntax show cpu_access_profile profile_id <value 1-5> Description The show cpu_access_profile command is used view the current CPU interface filtering entries set on the Switch.
  • Page 252: Safeguard Engine Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual AFEGUARD NGINE OMMANDS Periodically, malicious hosts on the network will attack the Switch by utilizing packet flooding (ARP Storm) or other methods. These attacks may increase the CPU utilization beyond its capability. To alleviate this problem, the Safeguard Engine function was added to the Switch’s software.
  • Page 253 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config safeguard_engine Purpose Used to configure the Safeguard Engine settings for the Switch. Syntax config safeguard_engine {state [enable | disable] | utilization {rising <value 20-100> | falling <value 20-100> | trap_log [enable | disable} |...
  • Page 254 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show safeguard_engine Purpose To display the Safeguard Engine parameters currently set in the Switch. Syntax show safeguard_engine Description This command is used to show the Safeguard Engine information currently set on the Switch.
  • Page 255: Traffic Segmentation Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual RAFFIC EGMENTATION OMMANDS Traffic segmentation allows you to further sub-divide VLANs into smaller groups of ports that will help to reduce traffic on the VLAN. The VLAN rules take precedence, and then the traffic segmentation rules are applied. The traffic segmentation commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table.
  • Page 256 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S u c c e s s . D E S - 6 5 0 0 : 4 # show traffic_segmentation Purpose Used to display the current traffic segmentation configuration on the Switch.
  • Page 257 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual 1 : 1 2 1 : 1 - 1 : 1 0 , 2 : 1 - 2 : 1 2 1 : 1 3 1 : 1 - 1 : 1 0 , 2 : 1 - 2 : 1 2...
  • Page 258: D-Link Single Ip Management Commands

    ANAGEMENT OMMANDS Simply put, D-Link Single IP Management is a concept that will stack switches together over Ethernet instead of using stacking ports or modules. Switches using Single IP Management (labeled here as SIM) must conform to the following rules: ...
  • Page 259 CS belongs. However if a MS has its own IP address, it can belong to SNMP communities to which other switches in the group, including the CS, do not belong. The D-Link Single IP Management commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table.
  • Page 260 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual enable sim Parameters None. Restrictions Only Administrator-level users can issue this command. Example usage: To enable SIM on the Switch: D E S - 6 5 0 0 : 4 # e n a b l e s i m C o m m a n d : e n a b l e s i m S u c c e s s .
  • Page 261 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show sim Device Name - Displays the user-defined device name on the Switch. MAC Address - Displays the MAC Address of the Switch. Capabilities – Displays the type of switch, be it Layer 2 (L2) or Layer 3 (L3).
  • Page 262 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual R o l e S t a t e : C o m m a n d e r D i s c o v e r y I n t e r v a l...
  • Page 263 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual S I M G r o u p N a m e : d e f a u l t M A C A d d r e s s...
  • Page 264 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual T o t a l E n t r i e s : 3 D E S - 6 5 0 0 : 4 # reconfig Purpose Used to connect to a member switch, through the commander switch using telnet.
  • Page 265 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual P l e a s e w a i t f o r A C K . . . S I M C o n f i g S u c c e s s ! ! ! S u c c e s s .
  • Page 266 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config sim hold time from 100 to 255 seconds. Restrictions Only Administrator-level users can issue this command. Example usage: To change the time interval of the discovery protocol: D E S - 6 5 0 0 : 4 # c o n f i g s i m c o m m a n d e r d p _ i n t e r v a l 3 0 C o m m a n d : c o n f i g s i m c o m m a n d e r d p _ i n t e r v a l 3 0 S u c c e s s .
  • Page 267 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # download sim_ms Purpose Used to download firmware or configuration file to an indicated device. Syntax download sim_ms [firmware | configuration] <ipaddr>...
  • Page 268 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual D E S - 6 5 0 0 : 4 # To download configuration files: D E S - 6 5 0 0 : 4 # d o w n l o a d s i m _ m s c o n f i g u r a t i o n 1 0 . 5 3 . 1 3 . 9 4 c : / d g s s r i .
  • Page 269 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#...
  • Page 270: Time And Sntp Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual SNTP C IME AND OMMANDS The Simple Network Time Protocol (SNTP) {an adaptation of the Network Time Protocol (NTP)} commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table.
  • Page 271 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To configure SNTP settings: DES-6500:4#config sntp primary 10.1.1.1 secondary 10.1.1.2 poll-interval 30 Command: config sntp primary 10.1.1.1 secondary 10.1.1.2 poll- interval 30 Success. DES-6500:4# show sntp Purpose Used to display the SNTP information.
  • Page 272 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# disable sntp Purpose Disables SNTP server support. Syntax disable sntp Description This will disable SNTP support. SNTP service must be separately configured (see config sntp). Parameters None. Restrictions Only Administrator-level users can issue this command.
  • Page 273 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config time zone Purpose Used to determine the time zone used in order to adjust the system clock. Syntax config time_zone {operator [+ | -] | hour <gmt_hour 0-13> | min <minute 0-59>}...
  • Page 274 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config dst October 14. s_week - Configure the week of the month in which DST begins.  <start_week 1-4,last> - The number of the week during the month in which DST begins where 1 is the first week, 2 is the second week and so on, last is the last week of the month.
  • Page 275 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Success. DES-6500:4# show time Purpose Used to display the current time settings and status. Syntax show time Description This will display system time and date configuration as well as display current system time.
  • Page 276: Arp Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ARP C OMMANDS The ARP commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create arpentry <ipaddr> <macaddr> delete arpentry [<ipaddr>...
  • Page 277 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete arpentry Purpose Used to delete a static entry into the ARP table. Syntax delete arpentry [<ipaddr> | all] Description This command is used to delete a static ARP entry, made using the create arpentry command above, by specifying either the IP address of the entry or all.
  • Page 278 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show arpentry Purpose Used to display the ARP table. Syntax show arpentry {ipif <ipif_name 12> | static} Description This command is used to display the current contents of the Switch’s ARP table.
  • Page 279 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To display an entry in the ARP table: DES-6500:4#show arpentry ipaddress 10.1.1.169 Command: show arpentry ipaddress 10.1.1.169 ARP Aging Time : 30 Interface IP Address MAC Address Type...
  • Page 280: Vrrp Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual VRRP C OMMANDS VRRP or Virtual Routing Redundancy Protocol is a function on the Switch that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN. The VRRP router that controls the IP address associated with a virtual router is called the Master, and will forward packets sent to this IP address.
  • Page 281 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To enable VRRP globally on the Switch: DES-6500:4#enable vrrp Command: enable vrrp Success. DES-6500:4# Example usage: To enable the virtual IP address to be pinged: DES-6500:4#enable vrrp ping Command: enable vrrp ping Success.
  • Page 282 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create vrrp vrid Purpose To create a VRRP router on the Switch. Syntax vrid <vrid 1-255> ipif <ipif_name 12> ipaddress <ipaddr> {state [enable | disable] | priority <int 1-254> | advertisement_interval <int 1-255>...
  • Page 283 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create vrrp vrid network connections. critical_ip_state [enable | disable] - This parameter is used to enable or disable the critical IP address entered above. The default is disable. Restrictions Only Administrator-level users can issue this command.
  • Page 284 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config vrrp vrid assigned to the VRRP entry. This IP address is also the default gateway that will be statically assigned to end hosts and must be set for all routers that participate in this group.
  • Page 285 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config vrrp ipif Parameters ipif <ipif_name 12> - Enter the name of a previously configured IP interface for which to configure the VRRP entry. This IP interface must be assigned to a VLAN on the Switch.
  • Page 286 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show vrrp Purpose To view the VRRP settings set on the Switch. Syntax show vrrp ipif {ipif <ipif_name 12> {vrid <vrid 1-255>}} Description This command is used to view current VRRP settings of the VRRP Operations table.
  • Page 287 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete vrrp ipif <ipif_name 12> - Enter the name of the IP interface which holds the VRRP router to delete. Restrictions Only Administrator-level users can issue this command. Example usage:...
  • Page 288: Routing Table Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual OUTING ABLE OMMANDS The routing table commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create iproute <network_address> [<ipaddr> {<metric 1-65535> |...
  • Page 289 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# create iproute default Purpose Used to create IP route entries to the Switch’s IP routing table. Syntax [<ipaddr> {<metric 1-65535>}|null0] Description This command is used to create a default static IP route entry to the Switch’s IP routing table.
  • Page 290 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#delete iproute 10.48.74.121/8 10.1.1.254 Command: delete iproute 10.48.74.121/8 10.1.1.254 Success. DES-6500:4# delete iproute default Purpose Used to delete a default IP route entry from the Switch’s IP routing table. Syntax...
  • Page 291 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#show iproute Command: show iproute Routing Table IP Address/Netmask Gateway Interface Cost Protocol --------------- --------------- --------------- ---- ----------- 0.0.0.0 10.1.1.254 System Default 10.0.0.0/8 10.48.74.122 System Local Total Entries: 2 DES-6500:4#...
  • Page 292: Route Redistribution Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual OUTE EDISTRIBUTION OMMANDS The route redistribution commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create route redistribute dst ospf src [static | rip | local] {mettype [1 | 2] | metric <value 0-16777214>}...
  • Page 293 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Route Source Metric Metric Type 0 to 16777214 mettype 1 mettype 2 Static 0 to 16777214 mettype 1 mettype 2 Local 0 to 16777214 mettype 1 mettype 2 Allowed Metric Type combinations are mettype 1 or mettype 2. The metric value 0 above will be redistributed in OSPF as the metric 20.
  • Page 294 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create route redistribute dst rip src This is analogous to a HOP Count in the RIP routing protocol. Restrictions Only Administrator-level users can issue this command. Routing information source  OSPF and the Static Route table. Routing information will be redistributed to RIP. The following table lists the allowed values for the routing metrics and the types (or forms) of the routing information that will be redistributed.
  • Page 295 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config route redistribute dst ospf src src [static | rip | local]  Allows the selection of the protocol of the Parameters source device. mettype  allows the selection of one of the methods for calculating the metric value.
  • Page 296 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config route redistribute dst rip src routers current routing protocol. The Switch can redistribute routing information between the OSPF and RIP routing protocols to all routers on the network that are running OSPF or RIP. Routing information entered into the Static Routing Table on the local switch is also redistributed.
  • Page 297 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete route redistribute OSPF. Restrictions Only Administrator-level users can issue this command. Example usage: To delete route redistribution settings: DES-6500:4#delete route redistribute dst rip src ospf Command: delete route redistribute dst rip src ospf Success.
  • Page 298: Dhcp Relay Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DHCP R ELAY OMMANDS The DHCP relay commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config dhcp_relay {hops <value 1-16> | time <sec 0-65535>} config dhcp_relay add ipif <ipif_name 12>...
  • Page 299 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config dhcp_relay add ipif Purpose Used to add an IP destination address to the Switch's DHCP/BOOTP relay table. Syntax config dhcp_relay add ipif <ipif_name 12> <ipaddr> Description This command adds an IP address as a destination to which to forward (relay) DHCP/BOOTP relay packets.
  • Page 300 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config dhcp_relay option_82 state Purpose Used to configure the state of DHCP relay agent information option 82 of the switch. Syntax config dhcp_relay option_82 state [enable | disable] Description This command is used to configure the state of DHCP relay agent information option 82 of the switch.
  • Page 301 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config dhcp_relay option_82 check disable - When the field is toggled to disable, the relay agent will not check the validity of the packet’s option 82 field. Restrictions Only Administrator-level users can issue this command.
  • Page 302 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show dhcp_relay Switch, or if an IP interface name is specified, the DHCP relay configuration for that IP interface. Parameters ipif <ipif_name 12> The name of the IP interface for which to display the current DHCP relay configuration.
  • Page 303 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Success. DES-6500:4# disable dhcp_relay Purpose Used to disable the DHCP/BOOTP relay function on the switch. Syntax disable dhcp_relay Description This command is used to disable the DHCP/BOOTP relay function on the switch.
  • Page 304: Dns Relay Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DNS R ELAY OMMANDS The DNS relay commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config dnsr [[primary | secondary] nameserver <ipaddr> | [add | delete] static <domain_name 32>...
  • Page 305 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#config dnsr add static dns1 10.43.21.12 Command: config dnsr add static dns1 10.43.21.12 Success. DES-6500:4# Example usage: To delete an entry domain name dns1, IP address 10.43.21.12 from DNS static table.
  • Page 306 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#enable dnsr static Command: enable dnsr static Success. DES-6500:4# disable dnsr Purpose Used to disable DNS relay on the Switch. Syntax disable dnsr {cache | static} Description This command is used, in combination with the enable dnsr command above, to enable and disable DNS Relay on the Switch.
  • Page 307 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show dnsr Purpose Used to display the current DNS relay status. Syntax show dnsr {static} Description This command is used to display the current DNS relay status. static  Allows the display of only the static entries into the DNS relay Parameters table.
  • Page 308: Rip Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual RIP C OMMANDS The RIP commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config rip [ipif <ipif_name 12> | all] {authentication [enabled <password 16>...
  • Page 309 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config rip RIP packets. v1_only  Specifies that only RIP v1 packets will be  transmitted.  v2_only - Specifies that only RIP v2 packets will be transmitted.  v1_or_v2 - Specifies that only RIP v1 or v2 packets will be transmitted.
  • Page 310 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To disable RIP: DES-6500:4#disable rip Command: disable rip Success. DES-6500:4# show rip Purpose Used to display the RIP configuration and statistics for the Switch. Syntax show rip {ipif <ipif_name 12>}...
  • Page 311: Dvmrp Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DVMRP C OMMANDS The DVMRP commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config dvmrp [ipif <ipif_name 12> | all] {metric <value 1-31> | probe <sec 1-65535>...
  • Page 312 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config dvmrp Restrictions Only Administrator-level users can issue this command. Example usage: To configure DVMRP configurations of IP interface System: DES-6500:4#config dvmrp ipif System neighbor_timeout 30 metric 1 probe 5...
  • Page 313 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#disable dvmrp Command: disable dvmrp Success. DES-6500:4# show dvmrp routing_table Purpose Used to display the current DVMRP routing table. Syntax show dvmrp routing table {ipaddress <network_address>} Description The command is used to display the current DVMRP routing table.
  • Page 314 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Example usage: To display DVMRP neighbor table: DES-6500:4#show dvmrp neighbor Command: show dvmrp neighbor DVMRP Neighbor Address Table Interface Neighbor Address Generation ID Expire Time -------------- ------------------ --------------- --------- System 10.2.1.123...
  • Page 315 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show dvmrp Syntax show dvmrp {<ipif_name 12>} Description The command will display the current DVMRP routing table. <ipif_name 12>  Adding this parameter will display DVMRP Parameters settings for a specific IP interface.
  • Page 316: Pim Commands

    PIM or Protocol Independent Multicast is a method of forwarding traffic to multicast groups over the network using any pre- existing unicast routing protocol, such as RIP or OSPF, set on routers within a multicast network. The xStack DES-6500 switch series supports two types of PIM, Dense Mode (PIM-DM) and Sparse Mode (PIM-SM).
  • Page 317 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Register and Register Suppression Messages Multicast sources do not always join the intended receiver group. The first hop router (DR) can send multicast data without being the member of a group or having a designated source, which essentially means it has no information about how to relay this information to the RP distribution tree.
  • Page 318 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters create pim static_rp group < network_address> rp <ipaddr> delete pim static_rp group <network_address> show pim static_rp config pim rp_spt_threshold [<value 0-65535> | infinity] config pim last_hop_spt_threshold [<value 0-65535> | infinity]...
  • Page 319 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual disable pim Purpose Used to disable PIM function on the Switch. Syntax disable pim Description This command will disable PIM for the Switch. Any previously configured PIM settings will remain unchanged and may be enabled at a later time with the enable pim command.
  • Page 320 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config pim dr_priority <uint 0 – 4294967294> - Enter the priority of this IP interface to become the Designated Router for the multiple access network. The user may enter a DR priority between 0 and 4,294,967,294 with a default setting of 1.
  • Page 321 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config pim register_suppression_time Purpose Used to configure the interval between the sending of register packets for the PIM protocol. Syntax config pim register_suppression_time <value 3-255> Description This command is to be configured for the first hop router from the source.
  • Page 322 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#create pim crp group 231.0.0.1/32 rp Trinity Command: create pim crp group 231.0.0.1/32 rp Trinity Success. DES-6500:4# delete pim crp Purpose To disable the Switch in becoming a possible candidate to be the Rendezvous Point (RP).
  • Page 323 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config pim crp wildcard_prefix_cnt [0 | 1] - The user may set the Prefix Count value of the wildcard group address here by choosing a value between 0 and 1 with a default setting of 0.
  • Page 324 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete pim static_rp Purpose To remove the multicast group IP address used in identifying the Rendezvous Point (RP). Syntax delete pim static_rp group <ip_addr/netmask> Description This command will remove the multicast group IP address used in identifying the Rendezvous Point (RP).
  • Page 325 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# config pim rp_spt_threshold Purpose Used to configure the threshold of register packets needed to enable the Shortest Path Tree (SPT). Syntax config pim rp_spt_threshold [<value 0-65535> | infinity] Description This command will set the threshold of register packets needed to enable the Shortest Path Tree (SPT).
  • Page 326 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#config pim last_hop_spt_threshold 0 Command: config pim last_hop_spt_threshold 0 Success. DES-6500:4# show pim rpset Purpose Used to display the RP Set of the Switch. Syntax show pim rpset Description This command will display the information regarding the RP Set learned by the BSR.
  • Page 327 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command: show pim crp PIM Candidate-RP Table C-RP Holdtime : 150 C-RP Priority C-RP wildcard prefix count Group Interface --------------------- --------------------- 224.0.0.0/4 Trinity DES-6500:4# config pim cbsr Purpose Used to configure the settings for the Candidate Bootstrap Router and the priority of the selected IP interface to become the Boot Strap Router (BSR) for the PIM-SM network domain.
  • Page 328 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#config pim cbsr ipif Trinity priority 4 Command: config pim cbsr ipif Trinity priority 4 Success. DES-6500:4# Usage example: To configure the hash mask length for the CBSR: DES-6500:4#config pim cbsr hash_masklen 30 Command: config pim cbsr hash_masklen 30 Success.
  • Page 329 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# show pim cbsr Command: show pim cbsr PIM Candidate-BSR Table C-BSR Hash Mask Len : 30 C-BSR Bootstrap Period : 60 Interface IP Address Priority ------------ ------------------ ------------- System 10.90.90.90/8...
  • Page 330 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#show pim Command: show pim PIM Global State : Disabled Last Hop SPT Threshold packet per second(switch to SPT tree immediately) RP SPT Threshold packet per second(switch to SPT tree immediately)
  • Page 331 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# show pim neighbor Command: show pim neighbor PIM Neighbor Address Table Interface Name Neighbor Address Expired Time --------------------- ----------------- ------------ 10.20.6.251 Total Entries: 1 DES-6500:4# show pim ipmroute Purpose Used to display the PIM IP Multicast Route Table on the Switch.
  • Page 332 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create pim register_checksum_include_data Purpose Used to set the RPs that the Switch will send Register packets to and create checksums to be included with the data in Registered packets. Syntax create pim register_checksum_include_data rp_address <ipaddr>...
  • Page 333 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#delete pim register_checksum_include_data rp_address 11.1.1.1 Command: delete pim register_checksum_include_data rp_address 11.1.1.1 Success. DES-6500:4# show pim register_checksum_include_data_rp_list Purpose Used to display RPs that the Switch will send Register packets to and create checksums to be included with the data in Registered packets.
  • Page 334: Ip Multicasting Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual IP M ULTICASTING OMMANDS The IP multicasting commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters show ipmc cache {group <group>} {ipaddress <network_address>}...
  • Page 335 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ipmc Purpose Used to display the IP multicast interface table. Syntax show ipmc {ipif <ipif_name 12> | protocol [inactive | dvmrp | pim]} Description This command will display the current IP multicast interface table.
  • Page 336: Md5 Configuration Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual MD5 C ONFIGURATION OMMANDS The MD5 configuration commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create md5 key <key_id 1-255>...
  • Page 337 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#config md5 key 1 taboo Command: config md5 key 1 taboo Success. DES-6500:4# delete md5 key Purpose Used to delete an entry in the MD5 key table. Syntax delete md5 key <key_id 1-255>...
  • Page 338: Ospf Configuration Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual OSPF C ONFIGURATION OMMANDS The OSPF configuration commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters config ospf router_id <ipaddr>...
  • Page 339 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Command Parameters create ospf virtual_link <area_id> <neighbor_id> {hello_interval <sec 1-65535> | dead_interval <sec 1-65535> | authentication [none | simple <password 8> | md5 <key_id 1- 255>]} config ospf virtual_link <area_id> <neighbor_id> {hello_interval <sec 1-65535> | dead_interval <sec 1-65535>...
  • Page 340 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# disable ospf Purpose Used to disable OSPF on the Switch. Syntax disable ospf Description This command, in combination with the enable ospf command above, is used to enable and disable OSPF on the Switch.
  • Page 341 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4#show ospf Command: show ospf OSPF Interface Settings Interface IP Address Area ID State Link Metric Status ------------ ------------------ --------------- -------- --------- --------- System 10.90.90.90/8 0.0.0.0 Disabled Link Up Total Entries : 1...
  • Page 342 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# delete ospf area Purpose Used to delete an OSPF area. Syntax delete ospf area <area_id> Description This command is used to delete an OSPF area. <area_id>  A 32-bit number in the form of an IP address Parameters (xxx.xxx.xxx.xxx) that uniquely identifies the OSPF area in the OSPF...
  • Page 343 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ospf area Purpose Used to display an OSPF area’s configuration. Syntax show ospf area {<area_id>} Description This command will display the current OSPF area configuration. <area_id>  A 32-bit number in the form of an IP address Parameters (xxx.xxx.xxx.xxx) that uniquely identifies the OSPF area in the OSPF...
  • Page 344 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# delete ospf host_route Purpose Used to delete an OSPF host route. Syntax delete ospf host_route <ipaddr> Description This command is used to delete an OSPF host route. <ipaddr>  The IP address of the OSPF host.
  • Page 345 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ospf host_route Purpose Used to display the current OSPF host route table. Syntax show ospf host_route {<ipaddr>} Description This command will display the current OSPF host route table. <ipaddr>  The IP address of the host.
  • Page 346 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# delete ospf aggregation Purpose Used to delete an OSPF area aggregation configuration. Syntax delete ospf aggregation <area_id> <network_address> lsdb_type summary Description This command is used to delete an OSPF area aggregation configuration.
  • Page 347 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To configure the OSPF area aggregation settings: DES-6500:4#config ospf aggregation 10.1.1.1 10.48.76.122/16 lsdb_type summary advertise enable Command: config ospf aggregation 10.1.1.1 10.48.76.122/16 lsdb_type summary advertise enable Success. DES-6500:4# show ospf aggregation Purpose Used to display the current OSPF area aggregation settings.
  • Page 348 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ospf lsdb link. Restrictions None. NOTE: When this command displays a “ ” (a star symbol) in the OSPF LSDB table for the area_id or the Cost, this is interpreted as “no area ID”...
  • Page 349 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# show ospf virtual_neighbor Purpose Used to display the current OSPF virtual neighbor router table. Syntax show ospf virtual_neighbor {<area_id> <neighbor id>} Description This command will display the current OSPF virtual neighbor router table.
  • Page 350 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config ospf ipif Interval, Authorization Type, and Authorization Key should be the same for all routers on the same network. dead_interval <sec 1-65535>  Allows the specification of the length of time between the receipt of Hello packets from a neighbor router before the selected area declares that router down.
  • Page 351 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config ospf all Purpose Used to configure all of the OSPF interfaces on the Switch at one time. Syntax <ipif_name 12> {area <area_id> | priority <value 0-255> | hello_interval <sec 1-65535 > | dead_interval <sec 1-65535> | authentication [none | simple <password 8>...
  • Page 352 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual DES-6500:4# show ospf ipif Purpose Used to display the current OSPF interface settings for the specified interface name. Syntax show ospf ipif <ipif_name 12> Description This command will display the current OSPF interface settings for the specified interface name.
  • Page 353 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Priority: DR State: DR Address: 10.42.73.10 Backup DR Address: None Hello Interval: Dead Interval: Transmit Delay: Retransmit Time: Authentication: None Interface Name: ipif2 IP Address: 123.234.12.34/24 ((Link Up) Network Medium Type: BROADCAST...
  • Page 354 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual create ospf virtual_link Restrictions Only Administrator-level users can issue this command. Usage example: To create an OSPF virtual interface: DES-6500:4#create ospf virtual_link 10.1.12 20.1.1.1 hello_interval 10 Command: create ospf virtual_link 10.1.12 20.1.1.1 hello_interval 10 Success.
  • Page 355 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To configure the OSPF virtual interface settings: DES-6500:4#config ospf virtual_link 10.1.1.2 20.1.1.1 hello_interval 10 Command: config ospf virtual_link 10.1.1.2 20.1.1.1 hello_interval 10 Success. DES-6500:4# delete ospf virtual_link Purpose Used to delete an OSPF virtual interface.
  • Page 356 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual show ospf virtual_link Restrictions None. Usage example: To display the current OSPF virtual interface configuration: DES-6500:4#show ospf virtual_link Command: show ospf virtual_link Virtual Interface Configuration Transit Virtual Hello Dead Authentication...
  • Page 357: Jumbo Frame Commands

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual UMBO RAME OMMANDS Certain switches can support jumbo frames (frames larger than the standard Ethernet frame size of 1518 bytes). To transmit frames of up to 9216 bytes (and 9220 bytes tagged), the user can increase the maximum transmission unit (MTU) size from the default of 1536 by enabling the Jumbo Frame command.
  • Page 358 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual To enable the jumbo frame function on the Switch: DES-6500:4#disable jumbo_frame Command: disable jumbo_frame Success. DES-6500:4# show jumbo_frame Purpose Used to show the status of the jumbo frame function on the Switch.
  • Page 359: Ipv4 Multicast Static Route List

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ULTICAST TATIC OUTE The IPv4 Multicast Static Route commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters create ipmroute <network_address>...
  • Page 360 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual delete ipmroute Purpose Used to delete an ip multicast static route configuration entry. Syntax delete ipmroute [<network_address>|all] Description Deletes an ip multicast static route configuration entry. Parameters network_address - The entry corresponds to the specified network to be deleted.
  • Page 361: Command History List

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual OMMAND ISTORY The command history list commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command Parameters {<command>} show command_history config command_history <value 1-40>...
  • Page 362 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual CTRL+C ESC q Quit SPACE n Next Page ENTER Next Entry a All Example usage: To display the parameters for a specific command: DES-6500:4#? config stp Command:? config stp Command: config stp Usage: {maxage <value 6-40>...
  • Page 363 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual config command_history Purpose Used to configure the command history. Syntax config command_history <value 1-40> Description This command is used to configure the command history. <value 1-40>  The number of previously executed commands Parameters maintained in the buffer.
  • Page 364: Technical Specifications

    DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual ECHNICAL PECIFICATIONS Physical and Environmental AC inputs & External 100 - 240 VAC, 50/60 Hz (internal universal power supply) Redundant Power Supply 296W Power Consumption DES-6504: 30W maximum DES-6505: 20W maximum...
  • Page 365 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual Performance Store-and-forward-L3 Routing Transmission Method 256 MB per Linecard, 256MB on CPU Card. RAM Buffer Filtering Address Table 16 K MAC addresses per device 3K IP addresses per device Full-wire speed for all connections.
  • Page 366 DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual General Standard IEEE 802.3u 100BASE-TX Fast Ethernet IEEE 802.3ab 1000BASE-T Gigabit Ethernet IEEE 802.1D Spanning Tree IEEE 802.1w Rapid Spanning Tree IEEE 802.1s Multiple Spanning Tree IEEE 802.1 P/Q VLAN IEEE 802.1p Priority Queues...

Table of Contents