The system commands can be broken down into the functional groups shown below.
Command Group | Description |
General | Basic commands for entering privileged access mode, restarting the system, or quiting the CLI |
Flash/File | Manages code image or switch configuration files |
System Management | Controls system logs, system passwords, user name, browser management options, and a variety of other system information |
Radius Client | Configures RADIUS client-server authentication for logon access |
LACP | Configures Link Aggregation Control Protocol for port trunking |
SNMP | Activates authentication failure traps; configures community access strings, and trap managers |
Line |
Sets communication parameters for the serial port, including baud rate and console time-out |
Interface | Configures the connection parameters for all Ethernet ports, aggregated links, and VLANs |
Address Table | Configures the address table for filtering specified addresses, displaying current entries, clearing the table, or setting the aging time |
IP | Configures the IP address and gateway for management access, displays the default gateway, or pings a specified device |
Mirror Port | Mirrors data to another port for analysis without affecting the data passing through or the performance of the monitored port |
Spanning Tree | Configures Spanning Tree settings for the switch |
Shows the configuration for bridge extension commands | |
Priority | Sets port priority for untagged frames, and relative weight for each priority queue; also sets priority for TCP/UDP traffic types, IP precedence, and DSCP |
VLAN | Configures VLAN settings, and defines port membership for VLAN groups |
Port Trunking | Aggregates multiple ports into a single logical trunk |
IGMP Snooping | Configures IGMP multicast filtering, querier eligibility, query parameters, and specifies ports attached to a multicast router |
Broadcast Storm Control | Configures broadcast storm control |
Note that the access mode shown in the following tables is indicated by these abbreviations: NE (Normal Exec), PE (Privileged Exec), GC (Global Configuration), IE (Interface Configuration), LC (Line Configuration), and VC (VLAN Database Configuration).
Command | Function | Mode | |
enable | Activates privileged mode | NE | |
disable | Returns to normal mode from privileged mode | PE | |
configure | Activates global configuration mode | PE | |
show history | Shows the command history buffer | NE, PE | |
reload | Restarts the system | PE | |
end | Returns to Privileged Exec mode | GC, IC, LC, VC | |
exit | Returns to the previous configuration mode, or exits CLI | any | |
quit | Exits a CLI session | NE, PE | |
help | Shows how to use help | any | |
? | Shows options for command completion (context sensitive) | any |
Command | Function | Mode | |
copy | Copies a code image or a switch configuration to or from Flash memory or a TFTP server | PE | |
delete | Deletes a file or code image | PE | |
dir | Displays a list of files in Flash memory | PE | |
whichboot | Displays the files booted | PE | |
boot system | Specifies the file or image used to start up the system | GC |
Command | Function | Mode | |
enable password | Sets a password to control access to various privilege levels | GC | |
logging on | Controls logging of error messages | GC | |
logging history | Limits syslog messages sent to the SNMP network management station based on severity | GC | |
clear logging | Clears messages from the logging buffer | PE | |
username | Establishes a username-based authentication system at login | GC | |
hostname | Specifies or modifies the host name for the device | GC | |
jumbo frame | Allows jumbo frames to pass through this device | GC | |
ip http port | Specifies the port to be used by the web browser interface | GC | |
ip http server | Allows the switch to be monitored or configured from a browser | GC | |
show startup-config | Displays the contents of the configuration file (stored in Flash) that is used to start up the system | PE | |
show running-config | Displays the configuration data currently in use | PE | |
show logging | Displays the state of logging | PE | |
show system | Displays system information | NE, PE | |
show users | Shows all active console and Telnet sessions, including user name, idle time, and IP address of Telnet client | NE, PE | |
show version | Displays version information for the system | NE, PE |
Command | Function | Mode | |
authentication login | Defines logon authentication method and precedence | GC | |
radius-server
host |
Specifies the Radius server | GC | |
radius-server port | Sets the Radius server network port | GC | |
radius-server key | Sets the Radius encryption key | GC | |
radius-server retransmit | Sets the number of retries | GC | |
radius-server timeout | Sets the interval between sending authentication requests | GC | |
show radius-server | Displays current settings for the Radius server | PE |
Command | Function | Mode | |
lacp
|
Configures LACP for the current interface | IC |
Command | Function | Mode | |
show snmp | Displays the status of SNMP communications | NE, PE | |
snmp-server
community |
Sets up the community access string to permit access to SNMP commands | GC | |
snmp-server contact | Sets the system contact string | GC | |
snmp-server host | Specifies the recipient of an SNMP notification operation | GC | |
snmp-server location | Sets the system location string | GC | |
snmp-server enable traps | Enables the device to send SNMP traps or inform requests (i.e., SNMP notifications) | GC |
Command | Function | Mode | |
line | Identifies a specific line for configuration and starts the line configuration mode | GC | |
login | Enables password checking at login | LC | |
password | Specifies a password on a line | LC | |
exec-timeout | Sets the interval that the command interpreter waits until user input is detected | LC | |
password-thresh | Sets the password intrusion threshold, which limits the number of failed logon attempts | LC | |
silent-time | Sets the amount of time the management console is inaccessible after the number of unsuccessful logon attempts exceeds the threshold set by the password-thresh command | LC | |
databits | Sets the number of data bits per character that are interpreted and generated by hardware | LC | |
parity | Defines generation of a parity bit | LC | |
speed | Sets the terminal baud rate | LC | |
stopbits | Sets the number of the stop bits transmitted per byte | LC | |
show line | Displays a terminal line's parameters | NE, PE |
Command | Function | Mode | |
interface | Configures an interface type and enters interface configuration mode | GC | |
shutdown | Disables an interface | IC | |
clear counters | Clears statistics on an interface | PE | |
description | Adds a description to an interface configuration | IC | |
speed-duplex | Configures the speed and duplex operation of a given interface when autonegotiation is disabled | IC | |
negotiation | Enables autonegotiation on a given interface | IC | |
capabilities | Advertises the port capabilities of a given interface for use in autonegotiation | IC | |
flowcontrol | Enables flow control on a given interface | IC | |
show interfaces status | Displays status for the specified interface | NE, PE | |
show interfaces counters | Displays statistics for the specified interface | NE, PE | |
show interfaces switchport | Displays the administrative and operational status of an interface | NE, PE |
Command | Function | Mode | |
bridge address | Maps a static address to a port in a VLAN | GC | |
clear bridge | Removes any learned entries from the forwarding database and clears the transmit and receive counts for any statically or system configured entries | PE | |
show bridge | Displays classes of entries in the bridge-forwarding database | PE | |
bridge-group aging-time | Sets the aging time of the address table | GC | |
show bridge group aging-time | Shows the aging time for the address table | PE |
Command | Function | Mode | |
ip address | Sets the IP address for this device | IC | |
ip dhcp restart | Submits a BOOTP or DCHP client request | PE | |
ip default-gateway | Defines the default gateway through which an in-band management station can reach this device | GC | |
show ip interface | Displays the IP settings for this device | NE, PE | |
show ip redirects | Displays the default gateway configured for this device | PE | |
ping | Sends ICMP echo request packets to another node on the network | NE, PE |
Command | Function | Mode | |
port
monitor |
Configures a mirror session | IC | |
show port monitor | Shows the configuration for a mirror port | NE, PE |
Command | Function | Mode | |
bridge spanning-tree | Enables the spanning tree protocol | GC | |
bridge forward-time | Configures the spanning tree bridge forward time | GC | |
bridge hello-time | Configures the spanning tree bridge hello time | GC | |
bridge max-age | Configures the spanning tree bridge maximum age | GC | |
bridge priority | Configures the spanning tree bridge priority | GC | |
bridge-group path-cost | Configures the spanning tree path cost of an interface | IC | |
bridge-group priority | Configures the spanning tree priority of an interface | IC | |
bridge-group portfast | Sets fast forwarding for an interface | IC | |
show bridge group | Shows spanning tree configuration for the overall bridge or a selected interface | PE |
Command | Function | Mode | |
show bridge-ext | Shows bridge extension configuration | PE |
Command | Function | Mode | |
switchport priority default | Sets a port priority for incoming untagged frames or the priority of frames sent by the device connected to the specified port | IC | |
queue cos map | Assigns class of service values to the priority queues | IC | |
show queue cos-map | Shows the class of service map | PE | |
show interfaces switchport | Displays the administrative and operational status of an interface | PE |
Command | Function | Mode | |
vlan database | Enters VLAN database mode to add, change, and delete VLANs | GC | |
vlan | Configures a VLAN, including VID, name and state | VC | |
interface vlan | Enters interface configuration mode for specified VLAN | IC | |
swicthport ingress-filtering | Enables ingress filtering on an interface | IC | |
switchport acceptable-frame-types | Configures frame types to be accepted by an interface | IC | |
switchport mode | Configures VLAN frame tag usage for an interface | IC | |
switchport allowed vlan | Configures the VLANs associated with an interface | IC | |
switchport native vlan | Configures the PVID (native VLAN) of an interface | IC | |
switchport forbidden vlan | Configures forbidden VLANs for an interface | IC | |
show vlan | Shows VLAN information | NE, PE | |
show interfaces status vlan | Displays MAC address for the specified VLAN interface | NE, PE |
Command | Function | Mode | |
interface port-channel | Configures a trunk and enters interface configuration mode for the trunk | GC | |
channel-group | Adds a port to a trunk | IC | |
show interfaces status port-channel | Shows trunk information | PE |
Command | Function | Mode | |
ip igmp snooping | Enables IGMP snooping | GC | |
ip igmp snooping vlan mrouter | Adds a multicast router port | GC | |
ip igmp snooping vlan static | Adds an interface as a member of a multicast group | GC | |
ip igmp snooping querier | Allows this device to act as the querier for IGMP snooping | GC | |
ip igmp snooping query-count | Configures the query count | GC | |
ip
igmp snooping query-interval |
Configures the query interval | GC | |
ip igmp snooping query-max-response-time | Configures the report delay | GC | |
ip
igmp snooping query-time-out |
Configures the query timeout | GC | |
ip igmp snooping version | Configures the IGMP version for snooping | GC | |
show
ip igmp snooping |
Shows the IGMP snooping configuration | PE | |
show ip igmp snooping mrouter | Shows multicast router ports | PE | |
show bridge multicast | Shows the IGMP snooping MAC multicast list | PE |
Command | Function | Mode | |
switchport broadcast | Configures broadcast storm control | IC | |
show interfaces switchport | Displays the administrative and operational status of a port. | NE, PE |