TP-Link T1500-28PCT T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide
TP-Link T1500-28PCT Manual
View all TP-Link T1500-28PCT manuals
Add to My Manuals
Save this manual to your list of manuals |
TP-Link T1500-28PCT manual content summary:
- TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 1
CLI Reference Guide Jetstream Smart Switches 1910012775 REV3.3.0 June 2020 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 2
COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-Link Technologies Co., Ltd. Other brands and product names are trademarks or registered trademarks of their respective holders. No part of the specifications may be reproduced - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 3
2.3 2.4 2.5 2.6 2.7 2.8 2.9 2.10 enable ...17 service password-encryption 17 enable password...18 enable secret ...19 configure...20 show user configuration...27 Chapter 4 System Configuration Commands 28 4.1 system-time manual ...28 4.2 system-time ntp ...28 4.3 system-time dst predefined ...30 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 4
ip address...36 ip management-vlan...37 ip address-alloc...37 controller cloud-based (Only for Certain Devices 38 controller inform-url (Only for Certain Devices 39 reset ...40 service reset ...46 boot config...47 remove backup-image...48 firmware upgrade...48 ping ...49 tracert ...50 show system - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 5
4.43 4.44 show memory-utilization...57 show controller (Only for Certain Devices 57 Chapter 5 EEE Configuration Commands 59 5.1 eee ...59 5.2 show interface eee...59 Chapter 6 SDM Template Commands 61 6.1 sdm prefer...61 6.2 show sdm prefer ...62 Chapter 7 Time Range Commands 63 7.1 time- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 6
-mac-count 99 show mac address-table interface 99 show mac address-table count 100 show mac address-table address 100 show mac address-table vlan 101 Chapter 13 IEEE 802.1Q VLAN Commands 102 13.1 13.2 vlan...102 name...103 V - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 7
Chapter 17 IGMP Snooping Commands 122 17.1 17.2 17.3 17.4 17.5 17.6 ip igmp snooping (global) ...122 ip igmp snooping version...122 ip igmp snooping drop-unknown 123 ip igmp snooping header-validation 124 ip igmp snooping vlan-config 124 ip igmp snooping vlan-config (immediate-leave 126 VI - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 8
17.23 17.24 17.25 ip igmp snooping vlan-config (report-suppression 126 ip igmp snooping vlan-config (router-ports-forbidden 127 ip igmp snooping vlan-config (rport interface 128 ip igmp snooping vlan-config (static 129 ip igmp snooping vlan-config (querier 130 ip igmp snooping (interface 131 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 9
18.22 18.23 clear ipv6 mld snooping statistics 154 show ipv6 mld snooping...155 show ipv6 mld snooping interface 155 show ipv6 mld snooping vlan 156 show ipv6 mld snooping groups 157 show ipv6 mld profile...157 Chapter 19 MVR Commands 159 19.1 19.2 19.3 19.4 19.5 19.6 19.7 19 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 10
lldp traffic interface ...199 Chapter 22 IPv6 Address Configuration Commands 201 22.1 22.2 22.3 22.4 22.5 ipv6 enable...201 ipv6 address autoconfig...201 ipv6 address link-local ...202 ipv6 address dhcp ...203 ipv6 address ra ...203 IX - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 11
23.4 23.5 23.6 23.7 23.8 23.9 23.10 23.11 service dhcp relay ...207 ip dhcp relay hops ...207 ip dhcp relay time...208 ip dhcp relay vlan ...209 ip dhcp relay information ...209 ip dhcp relay information strategy 210 ip dhcp relay information format 211 ip dhcp relay information circuit-id 212 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 12
27.7 voice vlan...237 voice vlan (interface)...237 voice vlan priority...238 voice vlan oui...239 show voice vlan ...239 show voice vlan oui-table...240 show voice vlan interface ...240 -control ip-based enable 248 user access-control ip-based 248 user access-control mac-based enable 249 XI - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 13
264 31.1 31.2 31.3 31.4 31.5 31.6 31.7 31.8 31.9 ip ssh server ...264 ip ssh port...264 ip ssh version ...265 ip ssh algorithm ...266 ip ssh timeout...266 ip ssh max-client ...267 ip ssh download...268 remove public-key...268 show ip ssh...269 Chapter 32 Telnet Commands 270 32.1 32.2 32.3 32 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 14
dot1x default 282 show aaa authentication ...282 show aaa accounting...283 line telnet ...283 login authentication (telnet)...284 line ssh...285 login authentication (ssh) ...285 enable authentication (telnet 286 enable authentication (ssh) ...287 ip http login authentication...287 ip http - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 15
17 access-list create ...313 access-list resequence ...313 access-list mac ...314 access-list ip ...316 access-list combined ...317 access-list ipv6 ...319 access-list action...321 redirect ...322 329 38.1 38.2 38.3 ip source binding ...329 ip dhcp snooping ...330 ip dhcp snooping vlan ...331 XIV - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 16
max-entries 331 show ip source binding ...332 show ip dhcp snooping...333 show ip dhcp snooping interface 333 Chapter 39 IPv6 IMPB Commands 335 39.1 39.2 39.3 39.4 39.5 39.6 39.7 39.8 39.9 39.10 39.11 39.12 Ipv6 source binding...335 ipv6 dhcp snooping ...336 ipv6 dhcp snooping vlan ...337 ipv6 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 17
interface 361 show ip dhcp filter server permit-entry 362 Chapter 44 DoS Defend Commands 363 44.1 44.2 44.3 ip dos-prevent ...363 ip dos-prevent type...363 show ip dos-prevent...365 traps...380 snmp-server traps vlan...381 snmp-server traps security...382 snmp-server traps acl ...383 snmp-server - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 18
-server traps power (Only for Certain Devices 384 snmp-server traps link-status 385 rmon history ...386 rmon event ...387 rmon alarm ...388 ip arp inspection...405 ip arp inspection validate ...405 ip arp inspection vlan...406 ip arp inspection vlan logging 407 ip arp inspection trust ...408 ip - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 19
.10 48.11 48.12 48.13 ip arp inspection burst-interval 409 ip arp inspection recover ...410 show ip arp inspection ...410 show ip arp inspection interface 411 show ip arp inspection vlan ...412 show ip arp inspection statistics 412 clear ip arp inspection statistics 413 Chapter 49 ND Detection - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 20
Guide stands for JetStream Gigabit Smart Switch without any explanation. Some models featured in this guide may be unavailable in your country or region. For local sales information, visit https://www.tp-link.com. Overview of this Guide IP, reboot and reset the switch, upgrade the switch system - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 21
about the commands used for configuring LAG (Link Aggregation Group) and LACP (Link Aggregation Control Protocol). Chapter 12: MAC Address Commands Provide information about the commands used for Address configuration. Chapter 13: IEEE 802.1Q VLAN Commands Provide information about the commands used - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 22
about the commands used for configuring the ACL (Access Control List). Chapter 38: IPv4 IMPB Commands Provide information about the commands used for binding the IP address, MAC address, VLAN and the connected Port number of the Host together. 3 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 23
VLAN and the connected Port number of the Host together. Chapter 40: IP Verify Source Commands Provide information about the commands used for guarding the IP Source by filtering the IP packets based on the IP DLDP (Device Link Detection Protocol). Chapter used for protecting the switch from the ARP - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 24
an Ethernet port. 1.1.1 Logon by Telnet To log on to the switch by a Telnet connection, please take the following steps: 1. Click Start window and press the Enter button. Figure 1-1 Run Window 2. Telnet the switch's IP address (factory setting is 192.168.0.1) in the prompt cmd window and press Enter. - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 25
to set up an SSH connection: Password Authentication Mode: It requires username and password, which are both admin by default. Key Authentication Mode: It requires a public key for the switch and a private key for the SSH client software. You can generate the public key and the private key through - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 26
Figure 1-5 Enable SSH function • Password Authentication Mode 1. Open the software to log on to the interface of PuTTY. Enter the IP address of the switch into Host Name field; keep the default value 22 in the Port field; select SSH as the Connection type. Figure 1-6 SSH Connection Config 7 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 27
, and then enter enable to enter Privileged EXEC Mode, so you can continue to configure the switch. Figure 1-7 Log on the Switch • Key Authentication Mode 1. Select the key type and key length, and generate SSH key. Figure 1-8 Generate SSH Key Note: 1. The key length is in the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 28
key is successfully generated, please save the public key and private key to a TFTP server. Figure 1-9 Save the Generated Key 3. Log on to the switch by Telnet and download the public key file from the TFTP server to the switch, as the following figure shows: Figure 1-10 Download the Public Key 9 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 29
Note: 1. The key type should accord with the type of the key file. 2. The SSH key downloading can not be interrupted. 4. After the public key is downloaded, please log on to the interface of PuTTY and enter the IP address for login. Figure 1-11 SSH Connection Config 10 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 30
password, it indicates that the key has been successfully downloaded. Figure 1-13 Log on the Switch 1.2 CLI Command Modes The CLI is divided into different Command Modes: User EXEC Mode, Privileged EXEC Mode, Global Configuration Mode, Interface Configuration Mode and VLAN Configuration Mode. 11 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 31
into Interface Ethernet, Interface link-aggregation and some other Configuration Mode Primary mode once it is connected with the switch. Use the enable command to enter this mode from access interface Configuration mode. Use the vlan vlan-list to access VLAN Configuration mode. Use the end command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 32
. Use the end command or press Ctrl+Z to return to Privileged EXEC mode. Enter the exit or the # command to return to Global Configuration mode. Switch(config-vlan)# Use the end command or press Ctrl+Z to return to Privileged EXEC mode. Enter the exit command or the # command to return to Global - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 33
information of switch, for example: statistic information, port information, VLAN information. • history: Display the commands history. 1.3 Privilege Restrictions This switch's security the enable command. In default case, no password is needed. In Global Configuration Mode, you can configure 14 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 34
guaranteed and will vary as a result of client limitations and environmental factors. 1.4.2 Format Conventions The following conventions are used in this Guide: • Items in square brackets [ ] are optional • Items in braces { } are required • Alternative items are grouped in braces and separated by - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 35
• One or several values can be typed for a port-list or a vlan-list using comma to separate. Use a hyphen to designate a range of values, for instance, 1/0/1, 1/0/3-5, 1/0/7 indicates choosing port 1/0/1, 1/0/3, 1/0/4, 1/0/5, 1/0/7. 16 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 36
None. Example If you have set the password to access Privileged EXEC Mode from User EXEC Mode: Switch>enable Enter password: Switch# 2.2 service password-encryption Description The service password-encryption command is used to encrypt the password when the password is defined or when the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 37
commands. Example Enable the global encryption function: Switch(config)# service password-encryption 2.3 enable password Description The enable password digits and 17 kinds of special characters. The special characters are By default, it is empty. 7 -- Indicates a symmetric encrypted password with - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 38
encryption function is enabled in service password-encryption, the password in access Privileged EXEC Mode from User EXEC Mode: Switch(config)#enable password 0 admin 2.4 enable secret Mode from User EXEC Mode. To return to the default configuration, please use no enable secret command. This command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 39
as "admin" and unencrypted to access Privileged EXEC Mode from User EXEC Mode. The password will be displayed in the encrypted form. Switch(config)#enable secret 0 admin 2.5 configure Description The configure command is used to access Global Configuration Mode from Privileged EXEC Mode. Syntax - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 40
None. Example Return to Global Configuration Mode from Interface Configuration Mode, and then return to Privileged EXEC Mode: Switch(config-if)# exit Switch(config)#exit Switch# 2.7 end Description The end command is used to return to Privileged EXEC Mode. Syntax end Command Mode Privileged - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 41
clipaging command is used to enable the pause function for the screen display. If you want to display all the related information of the switch at once when using the show command, please use no clipaging command. Syntax clipaging no clipaging Command Mode Privileged EXEC Mode and Any Configuration - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 42
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear the commands you have entered in the current mode: Switch(config)#history clear 23 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 43
Web, Telnet or SSH, so as to protect the settings of the switch from being randomly changed. 3.1 user name (password) Description The user name without the right to edit or modify. It is "admin" by default. For more details about privilege restrictions, please refer to the Privilege Requirement - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 44
is unencrypted and the global encryption function is enabled in service password-encryption, the password in the configuration file will be user named "tplink", of which the password is "admin" and unencrypted: Switch(config)#user name tplink privilege admin password 0 admin 3.2 user name (secret - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 45
is "admin" by default. 0 -- Specify the encryption type. 0 indicates that an unencrypted password will follow. By default, the encryption type is "admin". The password will be displayed in the encrypted form. Switch(config)#user name tplink privilege admin secret 0 admin 3.3 show user account - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 46
Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the information of the current users: Switch(config)# show user account-list 3.4 show user configuration Description The show user configuration command is used to display the security - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 47
configure the System information and System IP, reboot and reset the switch, upgrade the switch system and other operations. 4.1 system-time manual Description The system-time manual command is used to configure the system time manually. Syntax system-time manual time Parameter time -- Set the date - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 48
Solomon Is., New Caledonia, Vladivostok. UTC+12:00 -- TimeZone for Fiji, Magadan, Auckland, Welington. UTC+13:00 -- TimeZone for Nuku'alofa, Samoa. ntp-server -- The IP address for the Primary NTP Server. 29 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 49
The IP address for server is 139.78.100.163, the fetching-rate is 11 hours: Switch(config)# system-time ntp UTC-12:00 133.100.9.2 139.79.100 are 4 options which are USA, Australia, Europe and New-Zealand respectively. The default value is Europe. Following are the time ranges of each option: USA -- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 50
these commands. Example Configure the daylight saving time as USA standard: Switch(config)#system-time dst predefined USA 4.4 system-time dst date one-off daylight saving time. The start date is in the current year by default. The time range of the daylight saving time must shorter than one year, - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 51
commands. Example Configure the daylight saving time from zero clock, Apr 1st to zero clock Oct 1st and the offset is 30 minutes in 2015: Switch(config)# system-time dst date Apr 1 00:00 2015 Oct 1 00:00 2015 30 4.5 system-time dst recurring Description The system-time dst recurring command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 52
to 2:00am, the last Sunday of Oct and the offset is 45 minutes: Switch(config)# system-time dst recurring first Sun May 02:00 last Sun Oct 02 name ranges from 1 to 32 characters. By default, it is the device name, for Example "TL-SG2210MP". Command Mode Global Configuration Mode Privilege Requirement - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 53
have access to these commands. Example Configure the system location as SHENZHEN: Switch(config)# location SHENZHEN 4.8 contact-info Description The contact-info command is used . It consists of 32 characters at most. It is "www.tp-link.com" by default. Command Mode Global Configuration Mode 34 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 54
: Switch(config)# contact-info www.tp-link.com 4.9 service led (Only for Certain Devices) Note: Only certain devices support this command. Description The led command is used to control the LEDs. Syntax service led {on | off} Parameter on | off-- The LEDs are configured as on or off. By default - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 55
: Switch(config)# led off 4.11 ip address Description This ip address command is used to configure the IP address and IP subnet mask for the management interface manually. Syntax ip address { ip-addr } { mask } gateway {default-gateway} no ip address [ ip-addr ] [ mask ] Parameter ip-addr -- The IP - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 56
as 192.168.0.150/24 and default gateway as 192.168.0.10: Switch(config)# interface vlan 1 Switch(config-if)# ip address 192.168.0.150 255.255.255.0 gateway 192.168.0.10 4.12 ip management-vlan Description This ip management-vlan command is used to specify the management vlan. Only the user in the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 57
: Switch(config)# interface vlan 1 Switch(config-if)# ip address-alloc dhcp Disable the IP address obtaining function on the VLAN interface 1: Switch(config)# interface vlan 1 Switch(config-if)# no ip address 4.14 controller cloud-based (Only for Certain Devices) Note: Only certain devices support - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 58
url (Only for Certain Devices) Note: Only certain devices support this command. Description If your switch and Omada SDN Controller are not located on the same Specify the URL of Omada SDN Controller. controller-ip -- Specify the IP address of Omada SDN Controller. Command Mode Gloabal Configuration - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 59
except its IP address: Switch# reset except-ip 4.17 service reset-disable Description The service reset-disable command is used to disable the reset function of the console port or reset button. To enable the reset function, use no service reset-disable command. By default, the reset function is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 60
] reboot-schedule in interval [ save_before_reboot ] reboot-schedule cancel Parameter time -- Specify the time point for the switch to reboot, in the format of hh:mm. date -- Specify the date for the switch to reboot, in the format of DD:MM:YYYY. The date should be within 30 days. save_before_reboot - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 61
the time that this command is executed, the switch will reboot later that day; otherwise the switch will reboot at the time point the next day. Example Specify the switch to save the configuration files and reboot in 200 minutes: Switch(config)# reboot-schedule in 200 save_before_reboot 4.20 copy - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 62
startup-config tftp ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for Example to TFTP server with the IP fe80::1234 and name this file config.cfg: Switch# copy startup-config tftp ip-address fe80::1234 filename config - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 63
is used to export the backup configuration file of the switch to TFTP server. Syntax copy backup-config tftp ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for Example 192.168.0.1 or fe80::1234. name -- Specify the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 64
Example Export the backup configuration file of the switch to the TFTP server with the IP 192.168.0.148 and name the file config.cfg: Switch# copy backup-config tftp ip-address 192.168.0.148 filename config 4.24 copy backup-config startup-config Description The copy backup-config startup-config - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 65
Copy tftp backup-config ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for Example 192. .cfg from the TFTP server with the IP 192.168.0.148: Switch# copy tftp backup-config ip-address 192.168.0.148 filename config 4.27 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 66
Example Configure the image2.bin as the startup image: Switch(config)# boot application filename image2 startup 4.28 boot application Parameter config1 | config2 -- Specify the configuration file to be configured. By default, the config1.cfg is the startup image and the config2.cfg is the backup - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 67
Backup Image, and user can choose whether to reboot the switch with the Backup Image. Syntax firmware upgrade tftp ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for Example 192.168.0.1 or fe80::1234. name -- Specify - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 68
to these commands. Example Upgrade the switch's backup iamge file with the file firmware.bin in the TFTP server with the IP address 192.168.0.148, and reboot the switch with this firmware: Switch# firmware upgrade tftp ip-address 192.168.0.148 filename firmware.bin It will only upgrade the backup - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 69
request packets. It ranges from 100 to 1000 milliseconds. By default, this value is 1000. Command Mode Privileged EXEC Mode Privilege Requirement None. Example To test the connectivity between the switch and the network device with the IP 192.168.0.131, please specify the count (-l) as 512 bytes - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 70
of the destination device. If the Parameter ip/ipv6 is not selected, both IPv4 and IPv6 addresses are supported, for Example 192.168.0.100 or fe80::1234. maxHops -- The maximum number of the route hops the test data can pass though. It ranges from 1 to 30. By default, this value is 4. Command Mode - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 71
Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the system image files' information: Switch# show image-info 4.35 show boot Description The show boot command is used to display the boot configuration of the system. Syntax - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 72
include keyword ] | interface {fastEthernet | gigabitEthernet | ten-gigabitEthernet} port ] Parameter unit -- Specify the unit number of a switch to show the unit's operating configurations. By default, it is 1. all -- Display all the operating configurations of the whole system or a specified unit - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 73
# show startup-config 4.38 show system-time Description The show system-time command is used to display the time information of the switch. Syntax show system-time Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the time information of the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 74
. Syntax show system-time dst Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DST information of the switch Switch# show system-time dst 4.40 show system-time ntp Description The show system-time ntp command is used to display the NTP mode - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 75
the connected Ethernet Port., which facilitates you to check the connection status of the cable connected to the switch, locate and diagnose the trouble spot of the network. Syntax show cable-diagnostics interface { fastEthernet port | gigabitEthernet port | ten-gigabitEthernet port } Parameter port - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 76
Mode Privilege Requirement None. Example Display the memory utilization information of the switch: Switch# show memory-utilization 4.44 show controller (Only for Certain Devices) Note: Only certain devices support this command. Description The show controller command is used to display the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 77
Example Display the current controller settings and status: Switch# show controller 58 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 78
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable EEE on port 1/0/1: Switch(config)#interface gigabitEthernet 1/0/1 Switch(config-if)#eee 5.2 show interface eee Description The show interface eee command is used to display the EEE configuration - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 79
Privilege Requirement None. Example Display the EEE configuration of each port Switch# show interface eee 60 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 80
resources on the switch for different uses. 6.1 sdm prefer Description The sdm prefer command is used to configure the SDM template. The SDM template is used to allocate system resources to best support the features being used in your application. To return to use the default template, please use - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 81
in use, or the SDM templates that can be used. Syntax show sdm prefer { used | default | enterpriseV4 | enterpriseV6 } Parameter used -- Display the resource allocation of the template currently in use , and the template that will become active after a reboot: Switch(config)#show sdm prefer used 62 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 82
bind it to a PoE port or an ACL rule. 7.1 time-range Description The time-range command is used to create time-range entry for the switch and enter Time-range Create Configuration Mode. After a time-range entry is created, you need to specify the date and time. A time-range can implement - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 83
2017 to 10/05/2017 7.3 periodic Description The periodic command is used to create a periodic mode time-range for the time-range of the switch. To delete the corresponding periodic mode time-range configuration, please use no periodic command. Syntax periodic start start-time end end-time day-of-the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 84
Configure the time-range named "tRange2" as a periodic time-range and specify the date and time as 8:30 to 12:00 on weekends: Switch(config)#time-range tRange2 Switch(config -time-range)#periodic start 08:30 end 12:00 day-of-the-week 6-7 7.4 holiday (time-range mode) Description The holiday command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 85
level users have access to these commands. Example Define Labour Day, configuring the start date as May 1st, and the end date as May 3rd: Switch(config)# holiday labourday start-date 05/01 end-date 05/03 7.6 show holiday Description The show holiday command is used to display the defined holiday - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 86
Example Display the defined holiday: Switch# show holiday 7.7 show time-range Description The show time-range command is used to display the defined time Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the defined time range: Switch# show time-range 67 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 87
User level users have access to these commands. Example To enter the Interface gigabitEthernet Configuration Mode and configure port 2: Switch(config)# interface gigabitEthernet 1/0/2 8.2 interface range gigabitEthernet Description The interface range gigabitEthernet command is used to enter the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 88
port. Example To enter the Interface range gigabitEthernet Configuration Mode, and configure ports 1, 2, 3, 6, 7 and 9 at the same time by adding them to one port-list: Switch(config)# interface range gigabitEthernet 1/0/1-3,1/0/6-7,1/0/9 69 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 89
Admin, Operator and Power User level users have access to these commands. Example Add a Description Port_5 to port 1/0/5: Switch(config)# interface gigabitEthernet 1/0/5 Switch(config-if)# Description Port_5 8.4 shutdown Description The shutdown command is used to disable an Ethernet port. To enable - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 90
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Disable port 1/0/3: Switch(config)# interface gigabitEthernet 1/0/3 Switch(config-if)# shutdown 8.5 flow-control Description The flow-control command is used to enable the flow-control function - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 91
(config)# interface gigabitEthernet 1/0/3 Switch(config-if)# duplex full 8.7 jumbo-size Description The jumbo-size command is used to specify the size of jumbo frames. Syntax jumbo-size size Parameter size -- The value of jumbo frames. It ranges from 1518 to 9216 bytes, and the default is 1518 bytes - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 92
. Example Globally configure the size of jumbo frames as 9216: Switch(config)# jumbo-size 9216 8.8 speed Description The speed command is used to configure the Speed Mode for an Ethernet port. To return to the default configuration, please use no speed command. Syntax speed { 10 | 100 | 1000 | - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 93
(Only for Certain Devices) Note: Only certain devices support this command. Description The serdes-mode command is used port 1/0/26 to collocate with electrical interface modules: Switch(config)# interface gigabitEthernet 1/0/9 Switch(config-if)# serdes-mode sgmii 8.10 clear counters Description - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 94
Only Admin and Operator level users have access to these commands. Example Clear the statistic information of all ports and port channels: Switch(config)# clear counters 8.11 show interface status Description The show interface status command is used to display the connection status of the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 95
None. Example Display the statistics information of all Ethernet ports and port channels: Switch(config)# show interface counters Display the statistics information of port 1/0/2: Switch(config)# show interface counters gigabitEthernet 1/0/2 8.13 show interface configuration Description The show - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 96
Switch(config)# show interface configuration Display the configurations of port 1/0/2: Switch(config)# show interface configuration gigabitEthernet 1/0/2 77 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 97
users have access to these commands. Example Set port 1, 2, 4 and port channel 2 to the forward list of port 1/0/5: Switch(config)# interface gigabitEthernet 1/0/5 Switch(config-if)# port isolation gi-forward-list 1/0/1-2,1/0/4 po-forward-list 2 Set all Ethernet ports and port channels to forward - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 98
)# interface gigabitEthernet 1/0/2 Switch(config-if)# no port isolation 9.2 show port isolation Configuration Mode Privilege Requirement None. Example Display the forward-list of port 1/0/2: Switch# show port isolation interface gigabitEthernet 1/0/2 Display the forward-list of all Ethernet ports - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 99
switch can detect loops using loopback detection packets. When a loop is detected, the switch Example Enable the loopback detection function globally: Switch(config)# loopback-detection 10.2 loopback-detection of sending loopback detection packets from switch ports to network, aiming at detecting - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 100
commands. Example Specify the interval-time as 50 seconds: Switch(config)# loopback-detection interval 50 10.3 loopback-detection recovery-time detection would restart. It ranges from 2 to 1000000 seconds. By default, this value is 90. Command Mode Global Configuration Mode Privilege Requirement - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 101
-mode is Port Based or VLAN Based. Syntax loopback-detection config process-mode { alert | port-based | vlan-based } recovery-mode { auto | manual } Parameter alert -- When a loop is detected, the switch will send a trap message and generate an entry on the log file. It is the default setting. 82 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 102
and generate an entry on the log file. In addition, the switch will block the VLAN in which the loop is detected and only the packets of the blocked VLAN cannot pass through the port. auto -- Block status can be automatically removed after recovery time. manual -- Block status can only be removed - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 103
Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of loopback detection function: Switch# show loopback-detection global 10.8 show loopback-detection interface Description The show loopback-detection interface command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 104
to 14. detail -- Displays the loop status and block status of the VLAN which the specified port belongs to. Command Mode Privileged EXEC Mode and Any loopback detection function and the status of all ports: Switch# show loopback-detection interface Display the configuration of loopback - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 105
Control Protocol) is defined in IEEE802.3ad and enables the dynamic link aggregation and disaggregation by exchanging LACP packets with its partner. The switch can dynamically group similarly configured ports into a single logical link, which will highly extend the bandwidth and flexibly balance the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 106
Aggregate Arithmetic for LAG is "src-dst-mac" by default. src-ip -- The source IP address. When this option is selected, the Aggregate Arithmetic will be based on the source IP address of the packets. dst-ip -- The destination IP address. When this option is selected, the Aggregate Arithmetic will - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 107
": Switch(config)# port-channel load-balance src-dst-ip 11.3 lacp system-priority Description The lacp system-priority command is used to configure the LACP system priority globally. To return to the default configurations, please use no lacp system-priority command. Syntax lacp system-priority pri - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 108
configure the LACP port priority for specified ports. To return to the default configurations, please use no lacp port-priority command. Syntax lacp port-priority LACP port priority as 2048 for port 4: Switch(config)# interface gigabitEthernet 1/0/4 Switch(config-if)# lacp port-priority 2048 11.5 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 109
-- The EtherChannel Group number, ranging from 1 to 14. By default, it is empty, and will display the information of all EtherChannel Requirement None. Example Display the detailed information of EtherChannel Group 1: Switch(config)# show etherchannel 1 detail 11.6 show etherchannel load-balance - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 110
channel-group-num -- The EtherChannel Group number, ranging from 1 to 14. By default, it is empty, and will display the information of all LACP groups. internal None. Example Display the internal LACP information of EtherChannel Group 1: Switch(config)# show lacp 1 internal 11.8 show lacp sys-id - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 111
Example Display the LACP system priority: Switch(config)# show lacp sys-id 92 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 112
added or removed manually, independent of the aging time. In the stable networks, the static MAC address entries can facilitate the switch to reduce mac-addr --The MAC address of the entry you desire to add. vid -- The VLAN ID number of your desired entry. It ranges from 1 to 4094. port -- The - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 113
Example Delete the MAC addresses on VLAN 1: Switch(config)# no mac address-table dynamic vid 1 12.3 mac address-table aging-time Description The mac address-table aging-time command is used to configure aging time for the dynamic address. To return to the default - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 114
package to be forwarded. The filtering address can be added or removed manually, independent of the aging time. Syntax mac address-table filtering mac- Example Add a filtering address entry of which VLAN ID is 1 and MAC address is 00:1e:4b:04:01:5d: Switch(config)# mac address-table filtering 00:1e: - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 115
that can be learned on the port. It ranges from 0 to 64. By default, this value is 64. dynamic | static | permanent -- Learn mode for MAC addresses the aging time and can only be deleted manually. The learned entries will be cleared after the switch is rebooted. When permanent mode is selected, - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 116
reaches 30 on this port, new entry will be dropped: Switch(config)# interface gigabitEthernet 1/0/1 Switch(config-if)# mac address-table max-mac-count max-number 30 static | filtering -- The type of your desired entry. By default, all the entries are displayed. Command Mode Privileged EXEC Mode and - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 117
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear the information of all static address entries: Switch(config)# clear mac address-table static 12.8 show mac address-table aging-time Description The show mac address-table aging-time command is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 118
(config)# show mac address-table max-mac-count all Display the security configuration of port 1/0/1: Switch(config)# show mac address-table max-mac-count interface gigabitEthernet 1/0/1 12.10 show mac address-table interface Description The show mac address-table interface command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 119
to. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the total MAC entry information in different VLANs: Switch(config)# show mac address-table count 12.12 show mac address-table address Description The show mac address-table address command is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 120
Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of the MAC address 00:00:00:00:23:00 in VLAN 1: Switch(config)#show mac address-table address 00:00:00:00:23:00 vid 1 12.13 show mac address-table - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 121
(Virtual Local Area Network) technology is developed for the switch to divide the LAN into multiple logical LANs flexibly. Hosts in the same VLAN can communicate with each other, regardless of their physical locations. VLAN can enhance performance by conserving bandwidth, and improve security by - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 122
to these commands. Example Specify the name of VLAN 2 as "group1": Switch(config)# vlan 2 Switch(config-vlan)# name group1 13.3 vlan_trunk (globally) Description The vlan_trunk command is used to enable VLAN Trunk globally. To disable VLAN Trunk, use the no vlan_trunk command. Syntax vlan_trunk - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 123
Enable VLAN Trunk globally: Switch(config)#vlan_trunk 13.4 vlan_trunk (interface) Description The vlan_trunk command is used to enable VLAN Trunk for the desired port. When enabled, all packets in VLANs will pass through this port. To disable VLAN Trunk, use the no vlan_trunk command. By default, it - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 124
to these commands. Example Configure Gigabit Ethernet port 1/0/4 whose link type is "general" to VLAN 2 and its egress-rule as "tagged": Switch(config)#interface gigabitEthernet 1/0/4 Switch(config-if)#switchport general allowed vlan 2 tagged 13.6 switchport pvid Description The switchport pvid - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 125
The switchport check ingress command is used to enable the Ingress Checking function for the switch ports. With this function enabled, the port will accept the packet of which the VLAN ID is in the port's VLAN list and discard others. With this function disabled, the port will forward the packet - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 126
frame type for the switch ports and the ports will perform this operation before Ingress Checking. To restore to the default setting, please use Switch(config)#interface gigabitEthernet 1/0/4 Switch(config-if)#switchport acceptable frame general 13.9 show vlan summary Description The show vlan - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 127
Example Display the summarized information of IEEE 802.1Q VLAN: Switch(config)# show vlan summary 13.10 show vlan brief Description The show vlan brief command is used to display the brief information of IEEE 802.1Q VLAN. Syntax show vlan brief Command Mode Privileged EXEC Mode and Any Configuration - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 128
command without Parameter displays the detailed information of all VLANs. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of vlan 5: Switch(config)# show vlan id 5 13.12 show interface switchport Description The show interface - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 129
VLAN entry. To delete a MAC-based VLAN entry, please use the no mac-vlan mac-address command. Syntax mac-vlan mac-address mac-addr vlan vlan-id [Description descript] no mac-vlan , in the format of XX:XX:XX:XX:XX:XX. vlan-id -- Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. descript -- Give a - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 130
Switch(config)#mac-vlan mac-address 00:11:11:01:01:12 vlan 2 Description TP 14.2 mac-vlan Description The mac-vlan command is used to enable a port for the MAC-based VLAN feature. Only the port is enabled can the configured MAC-based VLAN take effect. To disable the MAC-based VLAN function, please - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 131
the format of XX:XX:XX:XX:XX:XX. vlan-id -- Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. Example Display the information of all the MAC-based VLAN entry: Switch(config)#show mac-vlan all 14.4 show mac-vlan interface Description The show mac-vlan interface command is used to display the port - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 132
will be tagged with this VLAN ID. 15.1 protocol-vlan template Description The protocol-vlan template command is used to create Protocol-based VLAN template. To delete Protocol-based VLAN template, please use no protocol-vlan template command. Syntax protocol-vlan template name protocol-name frame - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 133
: Switch(config)#protocol-vlan template name TP frame ether_2 ether-type 2024 15.2 protocol-vlan vlan Description The protocol-vlan vlan command is used to create a Protocol-based VLAN entry. To delete a Protocol-based VLAN entry, please use no protocol-vlan vlan command. Syntax protocol-vlan vlan - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 134
Example Create Protocol-based VLAN 2 and bind it with Protocol-based VLAN Template 3: Switch(config)#protocol-vlan vlan 2 template 3 15.3 protocol-vlan group Description The protocol-vlan command is used to add the port to a specified protocol group. To remove the port from this protocol group, - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 135
information of the Protocol-based VLAN templates: Switch(config)#show protocol-vlan template 15.5 show protocol-vlan vlan Description The show protocol-vlan vlan command is used to display the information about Protocol-based VLAN entry. Syntax show protocol-vlan vlan Command Mode Privileged EXEC - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 136
attribute registration protocol). GVRP allows the switch to automatically add or remove the VLANs via the dynamic VLAN registration information and propagate the local VLAN registration information to other switches, without having to individually configure each VLAN. 16.1 gvrp Description The gvrp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 137
(config)#interface range gigabitEthernet 1/0/2-6 Switch(config-if-range)#gvrp 16.3 gvrp registration Description The gvrp registration command is used to configure the GVRP registration type for the desired port. To restore to the default value, please use no gvrp registration command. Syntax gvrp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 138
" for Gigabit Ethernet ports 1/0/2-6: Switch(config)#interface range gigabitEthernet 1/0/2-6 Switch(config-if-range)#gvrp registration fixed 16.4 gvrp timer Description The gvrp timer command is used to set a GVRP timer for the desired port. To restore to the default setting of a GARP timer, please - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 139
Gigabit Ethernet port 1/0/6 as 2000 centiseconds and restore the join timer of it to the default value: Switch(config)#interface gigabitEthernet 1/0/6 Switch(config-if)#gvrp timer leaveall 2000 Switch(config-if)#no gvrp timer join 16.5 show gvrp interface Description The show gvrp interface command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 140
16.6 show gvrp global Description The show gvrp global command is used to display the global GVRP status. Syntax show gvrp global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global GVRP status: Switch(config)#show gvrp global 121 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 141
IGMP Snooping function: Switch(config)# ip igmp snooping 17.2 ip igmp snooping version Description The ip igmp snooping version command is used to configure IGMP version globally. To return to the default configuration, please use no ip igmp snooping version command. Syntax ip igmp snooping version - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 142
the way how the switch processes multicast streams that are sent to unknown multicast groups as Discard. By default, it is Forward. To return to the default configuration, please use no ip igmp snooping drop-unknown command. Syntax ip igmp snooping drop-unknown no ip igmp snooping drop-unknown - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 143
IGMP Snooping Parameters. To disable the VLAN IGMP Snooping function, please use no ip igmp snooping vlan-config command. To restore the default values, please use no ip igmp snooping vlan-config with specified Parameters. Syntax ip igmp snooping vlan-config vlan-id-list [ rtime router-time | mtime - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 144
Time. Valid values are from 1 to 30 in seconds, and the default value is 1 second. When the switch receives a leave message from a port to leave a multicast group, it for VLAN 1-3: Switch(config)# ip igmp snooping vlan-config 1-3 rtime 300 Switch(config)# ip igmp snooping vlan-config 1-3 mtime 200 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 145
Fast Leave on the VLANs, please use no ip igmp snooping vlan-config vlan-id-list immediate-leave command. This function is disabled by default. Syntax ip igmp snooping vlan-config vlan-id-list immediate-leave no ip igmp snooping vlan-config vlan-id-list immediate-leave Parameter vlan-id-list -- The - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 146
default. Syntax ip igmp snooping vlan-config vlan-id-list report-suppression no ip igmp snooping vlan-config vlan-id-list report-suppression Parameter vlan-id-list -- The ID list of the VLAN VLAN 1-3: Switch(config)# ip igmp snooping vlan-config 1-3 report-suppression 17.8 ip igmp snooping vlan- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 147
these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in VLAN 1 : Switch(config)# ip igmp snooping vlan-config 1 router-ports-forbidd interface gigabitEthernet 1/0/1-3 17.9 ip igmp snooping vlan-config (rport interface) Description This command is used to specify the static - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 148
Example Set the router port as 1/0/1 for VLAN 1-2: Switch(config)# ip igmp snooping vlan-config 1-2 rport interface gigabitEthernet 1/0/1 17.10 ip igmp snooping vlan-config (static) Description This command is used to configure interfaces to statically join a multicast group. To remove interfaces - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 149
feature on the VLANs, please use no ip igmp snooping vlan-config vlan-id-list querier command without any Parameters. To restore the default values, please use no ip igmp snooping vlan-config vlan-id-list querier command with specified Parameters. Syntax ip igmp snooping vlan-config vlan-id-list - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 150
and configure the query interval as 100 seconds: Switch(config)# ip igmp snooping vlan-config 3 querier Switch(config)# ip igmp snooping vlan-config 3 querier query interval 100 17.12 ip igmp snooping (interface) Description The ip igmp snooping command is used to enable the IGMP Snooping function - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 151
the default of no limitation on the specified port, please use the no ip igmp snooping max-groups command. To return to the default action of dropping the report, please use the no ip igmp 10, and configure the throttling action as replace: Switch(config)#interface range gigabitEthernet 1/0/2-5 132 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 152
access to these commands. Example Enable the Fast Leave function for port 1/0/3: Switch(config)# interface gigabitEthernet 1/0/3 Switch(config-if)# ip igmp snooping immediate-leave 17.15 ip igmp profile Description The ip igmp profile command is used to create the configuration profile. To delete - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 153
Admin, Operator and Power User level users have access to these commands. Example Configure the filtering mode of profile 1 as deny: Switch(config)# ip igmp profile 1 Switch(config-igmp-profile)#deny 17.17 permit Description The permit command is used to configure the filtering mode of profile as - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 154
, Operator and Power User level users have access to these commands. Example Configure the filtering mode of profile 1 as permit: Switch(config)# ip igmp profile 1 Switch(config-igmp-profile)#permit 17.18 range Description The range command is used to configure the range of the profile's filtering - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 155
one of the filter multicast address entry as range 225.1.1.1 to 226.3.2.1 in profile 1: Switch(config)# ip igmp profile 1 Switch(config-igmp-profile)#range 225.1.1.1 226.3.2.1 17.19 ip igmp filter Description The ip igmp filter command is used to bind the specified profile to the interface. To - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 156
Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of IGMP: Switch# show ip igmp snooping 17.22 show ip igmp snooping interface Description The show ip igmp snooping interface command is used to display the port configuration of IGMP snooping. If no - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 157
Switch# show ip igmp snooping interface gigabitEthernet 1/0/1-4 packet-stat 17.23 show ip igmp snooping vlan Description The show ip igmp snooping vlan command is used to display the VLAN configuration of IGMP snooping. Syntax show ip igmp snooping vlan [ vlan-id ] Parameter vlan-id --The VLAN - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 158
Display the information of all IGMP snooping groups: Switch#show ip igmp snooping groups Display all the multicast entries in VLAN 5: Switch(config)#show ip igmp snooping groups vlan 5 Display the count of multicast entries in VLAN 5: Switch(config)#show ip igmp snooping groups vlan 5 count 139 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 159
groups of VLAN 5 Switch(config)#show ip igmp snooping groups vlan 5 dynamic Display the static multicast groups of VLAN 5 Switch(config)#show ip igmp snooping groups vlan 5 static Display the count of dynamic multicast entries of VLAN 5 Switch(config)#show ip igmp snooping groups vlan 5 dynamic - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 160
level users have access to these commands. Example Enable MLD Snooping: Switch(config)# ipv6 mld snooping 18.2 ipv6 mld snooping drop-unknown Description this function, please use no ipv6 mld snooping drop-unknown command. By default, it is disabled. Syntax ipv6 mld snooping drop-unknown no ipv6 mld - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 161
] no ipv6 mld snooping vlan-config vlan-id-list [ rtime | mtime | ltime ] Parameter vlan-id-list -- The ID list of the VLAN desired to modify configuration, values are from 1 to 30 in seconds, and the default value is 1 second. When the switch receives a done message from a port to leave a multicast - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 162
Port Time as 300 seconds, Member Port Time as 200 seconds for VLAN 1-3: Switch(config)# ipv6 mld snooping vlan-config 1-3 rtime 300 Switch(config)# ipv6 mld snooping vlan-config 1-3 mtime 200 18.4 ipv6 mld snooping vlan-config (immediate-leave) Description This command is used to enable the Fast - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 163
for specific VLANs. When enabled, the switch will only vlan-config vlan-id-list report-suppression command. This function is disabled by default. Syntax ipv6 mld snooping vlan-config vlan-id-list report-suppression no ipv6 mld snooping vlan-config vlan-id-list report-suppression Parameter vlan - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 164
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in VLAN 1: Switch(config)# ipv6 mld snooping vlan-config 1 router-ports-forbidd interface gigabitEthernet 1/0/1-3 145 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 165
users have access to these commands. Example Set the router port as 1/0/1 for VLAN 1-2: Switch(config)# ipv6 mld snooping vlan-config 1-2 rport interface gigabitEthernet 1/0/1 18.8 ipv6 mld snooping vlan-config (static) Description This command is used to configure interfaces to statically join - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 166
snooping vlan-config vlan-id-list static ip interface { gigabitEthernet port-list | port-channel port-channel-list } Parameter vlan-id-list -- The ID list of the VLAN ports 1/0/1-3 in VLAN 2 to statically join multicast group ff80::1234:1: Switch(config)# ipv6 mld snooping vlan-config 2 static - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 167
. Valid values are from 10 to 300 seconds, and the default value is 60 seconds. ip-addr-- The source IP address of the general query messages sent by the switch. It should be a unicast address. By default, it is fe80::2ff:ffff:fe00:1. count -- The number of group-specific queries to be sent. With - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 168
queries. Valid values are from 1 to 5 seconds, and the default value is 1 second. Command Mode Global Configuration Mode Privilege Requirement for VLAN 3, and configure the query interval as 100 seconds: Switch(config)# ipv6 mld snooping vlan-config 3 querier Switch(config)# ipv6 mld snooping vlan- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 169
the maximum numbers of groups that the port can join. It ranges from 0 to 1000 and the default value is 1000. drop -- When the number of the dynamic multicast groups that a port joins has 10, and configure the throttling action as replace: Switch(config)#interface range gigabitEthernet 1/0/2-5 150 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 170
Only Admin and Operator level users have access to these commands. Example Enable the Fast Leave function for port 1/0/3: Switch(config)# interface gigabitEthernet 1/0/3 Switch(config-if)# ipv6 mld snooping immediate-leave 18.13 ipv6 mld profile Description The ipv6 mld profile command is used - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 171
Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Create the profile 1: Switch(config)# ipv6 mld profile 1 18.14 deny Description The deny command is used to configure the filtering mode of profile as deny. Syntax - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 172
profile 1 Switch(config-igmp-profile)#permit 18.16 range Description The range command is used to configure the range of the profile's filtering multicast address. To delete the corresponding filtering multicast address, please use no range command. A profile contains 16 filtering IP-range entries - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 173
Only Admin and Operator level users have access to these commands. Example Bind profile 1 to interface gigabitEthernet 1/0/2: Switch(config)# interface gigabitEthernet 1/0/2 Switch(config-if)# ipv6 mld filter 1 18.18 clear ipv6 mld snooping statistics Description The clear ipv6 mld snooping - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 174
snooping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of MLD Snooping: Switch(config)# show ipv6 mld snooping 18.20 show ipv6 mld snooping interface Description The show ipv6 mld snooping interface command is used - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 175
. Syntax show ipv6 mld snooping vlan [ vlan-id ] Parameter vlan-id -- The VLAN ID selected to display, ranging from 1 to 4094. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display all of the VLAN information: Switch(config)# show ipv6 mld snooping - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 176
groups [ vlan { vlan-id } ] [ ipv6_multicast_addr | count | dynamic | dynamic count | static | static count ] Parameter vlan-id --The VLAN ID selected Mode Privilege Requirement None. Example Display all of the multicast groups: Switch(config)# show ipv6 mld snooping groups 18.23 show ipv6 mld - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 177
Parameter id -- Specify the ID of the profile, ranging from 1 to 999. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of all profiles: Switch(config)# show ipv6 mld profile 158 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 178
VLANs, a copy of the multicast streams is sent to each VLAN that has member ports. While MVR provides a dedicated multicast VLAN VLANs. Clients can dynamically join or leave the multicast VLAN without interfering with their relationships in other VLANs Enable MVR globally: Switch(config)# mvr 19.2 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 179
. dynamic -- In this mode, after receiving report or leave messages from the hosts, the switch will forward them to the IGMP querier via the multicast VLAN (with appropriate translation of the VLAN ID). So the IGMP querier can learn the multicast groups membership information through the report and - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 180
to these commands. Example Configure the MVR mode as dynamic: Switch(config)# mvr mode dynamic 19.4 mvr querytime Description The mvr before removing the port from multicast group membership. To return to the default configuration, please use no mvr querytime command. Syntax mvr querytime time - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 181
10: Switch(config)# mvr vlan 10 19.6 mvr (interface) Description This command is used to enable MVR for specific interfaces. To disable MVR for the interfaces, please use no mvr command. By default, it is disabled. Syntax mvr no mvr Command Mode Interface Configuration Mode (interface fastEthernet - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 182
Switch(config)# interface gigabitEthernet 1/0/1 Switch(config-if)#mvr 19.7 mvr type Description The mvr type command is used to configure the MVR port type as receiver or source. By default on the multicast VLAN as source ports. Source ports should belong to the multicast VLAN. receiver -- Configure - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 183
ports support Fast Switch(config-if)#mvr immediate 19.9 mvr vlan (group) Description This command is used to statically add ports to an MVR group. Then the ports can receive multicast traffic sent to the IP multicast address via the multicast VLAN. Syntax mvr vlan vlan-id group ip-addr Parameter vlan - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 184
add a receiver port to an MVR group. Example Add port 1/0/3 to MVR group 225.1.2.3 statically. The multicast VLAN is VLAN 10: Switch(config)# interface gigabitEthernet 1/0/3 Switch(config-if)#mvr vlan 10 group 225.1.2.3 19.10 show mvr Description The show mvr command is used to display the global - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 185
Requirement None. Example Display the MVR configuration of port 1/0/3: Switch# show mvr interface gigabitEthernet 1/0/3 19.12 show mvr members MVR group. Syntax show mvr members [ ip-addr ] [ status active | inactive ] Parameter ip-addr--The multicast IP address of the MVR group. active-- Display - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 186
Example Display the membership information of all MVR groups: Switch# show mvr members 167 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 187
Tree Protocol), compatible with both STP and RSTP and subject to IEEE 802.1s, can disbranch a ring network. STP is to block redundant links and backup links as well as optimize paths. 20.1 debug spanning-tree Description The debug spanning-tree command is used to enable debuggning of spanning-tree - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 188
Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the STP function: Switch(config)# spanning-tree 20.3 spanning-tree (interface) Description The spanning-tree command is used to enable STP function for a port. To - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 189
CIST and the common Parameters of all instances. To return to the default configuration, please use no spanning-tree common-config command. CIST (Common and Internal Spanning Tree) is the spanning tree in a switched network, connecting all devices in the network. Syntax spanning-tree common-config - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 190
The P2P link status, with auto, open and close options. By default, the option is auto. If the two ports in the P2P link are root port mode command is used to configure the STP mode of the switch. To return to the default configurations, please use no spanning-tree mode command. Syntax spanning- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 191
command is used to access MST Configuration Mode from Global Configuration Mode, as to configure the VLAN-Instance mapping, region name and revision level. To return to the default configuration of the corresponding Instance, please use no spanning-tree mst configuration command. Syntax spanning - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 192
namely remove all the mapping VLANs 1-100: Switch(config)# spanning-tree mst configuration Switch(config-mst)# no instance 1 Remove VLANs 1-50 in mapping VLANs 1-100 for Instance 1: Switch(config)# spanning-tree mst configuration Switch(config-mst)# no instance 1 vlan 1-50 20.8 name Description The - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 193
and Power User level users have access to these commands. Example Configure the region name of MST as "region1": Switch(config)# spanning-tree mst configuration Switch(config-mst)# name region1 20.9 revision Description The revision command is used to configure the revision level of MST instance - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 194
from 1 to 8. pri -- MSTI Priority, which must be multiple of 4096 ranging from 0 to 61440. By default, it is 32768. MSTI priority is an important criterion on determining if the switch will be chosen as the root bridge in the specific instance. Command Mode Global Configuration Mode Privilege - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 195
(config)# interface gigabitEthernet 1/0/1 Switch(config-if)# spanning-tree mst instance 1 port-priority 64 cost 2000 20.12 spanning-tree priority Description The spanning-tree priority command is used to configure the bridge priority. To return to the default value of bridge priority, please use - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 196
is the interval to send BPDU packets, and used to test the links. Hello Time ranges from 1 to 10 in seconds and it is 2 by default. Otherwise, 2 * (Hello Time + 1) - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 197
Switch(config)# spanning-tree timer forward-time 16 hello-time 3 max-age 22 20.14 spanning-tree hold-count Description The spanning-tree hold-count command is used to configure the maximum number of BPDU packets transmitted per Hello Time interval. To return to the default configurations, please use - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 198
before the BPDU is discarded, ranging from 1 to 40 in hop. By default, it is 20. Command Mode Global Configuration Mode Privilege Requirement Only Admin, function enabled, the port does not forward BPDUs from the other switches. To disable the BPDU filter function, please use no spanning-tree - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 199
and Power User level users have access to these commands. Example Enable the BPDU forward function for port 1/0/2: Switch(config)# interface gigabitEthernet 1/0/2 Switch(config-if)# spanning-tree bpduflood 20.18 spanning-tree bpduguard Description The spanning-tree bpduguard command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 200
1/0/2 Switch(config-if)# spanning-tree bpduguard 20.19 spanning-tree guard loop Description The spanning-tree guard loop command is used to enable the Loop Protect function for a port. Loop Protect is to prevent the loops in the network brought by recalculating STP because of link failures - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 201
Admin, Operator and Power User level users have access to these commands. Example Enable the Root Protect function for port 2: Switch(config)# interface gigabitEthernet 1/0/2 Switch(config-if)# spanning-tree guard root 20.21 spanning-tree guard tc Description The spanning-tree guard tc command is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 202
and Power User level users have access to these commands. Example Enable the TC Protect of Spanning Tree for port 2: Switch(config)# interface gigabitEthernet 1/0/2 Switch(config-if)# spanning-tree guard tc 20.22 spanning-tree mcheck Description The spanning-tree mcheck command is used to enable - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 203
tree active Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the active information of spanning-tree: Switch(config)# show spanning-tree active 20.24 show spanning-tree bridge Description The show spanning-tree bridge command is used to display - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 204
Mode Privilege Requirement None. Example Display the spanning-tree information of all ports: Switch(config)# show spanning-tree interface Display the spanning-tree information of port 1/0/2: Switch(config)# show spanning-tree interface gigabitEthernet 1/0/2 Display the spanning-tree mode information - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 205
)# show spanning-tree interface-security Display the protect information of port 1: Switch(config)# show spanning-tree interface-security gigabitEthernet 1/0/1 Display the interface security bpdufilter information: Switch(config)# show spanning-tree interface-security bpdufilter 20.27 show spanning - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 206
information and mapping information of VLAN and MST Instance: Switch(config)#show spanning-tree mst configuration Display the related information of MST Instance 1: Switch(config)#show spanning-tree mst instance 1 Display all the ports information of MST Instance 1: Switch(config)#show spanning-tree - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 207
Power User level users have access to these commands. Example Enable LLDP function globally: Switch(config)#lldp 21.2 lldp forward_message Description The lldp forward_message command is used to enable the switch to forward LLDP messages when LLDP function is disabled. To disable the LLDP messages - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 208
these commands. Example Enable the switch to forward LLDP messages when LLDP function is disabled globally: Switch(config)#lldp forward_message 21.3 lldp . TTL = Hold Multiplier * Transmit Interval. To return to the default configuration, please use no lldp hold-multiplier command. Syntax lldp hold- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 209
-count } Parameter tx-interval -- Configure the interval for the local device to transmit LLDPDU to its neighbors. The value ranges from 5 to 32768 and the default value is 30 seconds. tx-delay -- Configure a value from 1 to 8192 in seconds to specify the time for the local device to transmit LLDPDU - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 210
Only Admin, Operator and Power User level users have access to these commands. Example Enable port 1/0/1 to receive LLDPDU: Switch(config)#interface gigabitEthernet 1/0/1 Switch(config-if)#lldp receive 21.6 lldp transmit Description The lldp transmit command is used to enable the designated port to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 211
, Operator and Power User level users have access to these commands. Example Enable Gigabit Ethernet port 1/0/1 to transmit LLDPDU: Switch(config)# interface gigabitEthernet 1/0/1 Switch(config-if)#lldp transmit 21.7 lldp snmp-trap Description The lldp snmp-trap command is used to enable the port - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 212
select command. By default, All TLVs are ] [ port-vlan ] [ protocol-vlan ] [ vlan-name ] [ link-aggregation ] [ mac vlan-id" TLVs in LLDPDU outgoing from Gigabit Ethernet port 1/0/1: Switch(config)# interface gigabitEthernet 1/0/1 Switch(config-if)# no lldp tlv-select management-address port-vlan - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 213
management-address { ip-address } no as 192.168.1.100 for port 1/0/1: Switch(config)# interface gigabitEthernet 1/0/1 Switch(config-if)# lldp management-address 192. Start Count Parameter. It ranges from 1 to 10. By default, it is 4. Command Mode Global Configuration Mode Privilege Requirement Only - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 214
1/0/2 Switch(config-if)# lldp med-status 21.12 lldp med-tlv-select Description The lldp med-tlv-select command is used to configure LLDP-MED TLVs to be included in outgoing LLDPDU for the corresponding port. To exclude LLDP-MED TLVs, please use no lldp med-tlv-select command. By default, All - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 215
-office-box ] [ additional additional ] [ country-code country-code ] [ what { dhcp-server | endpoint | switch } ] ] } Parameter emergency-number -- Emergency Call Service ELIN identifier, which is used during emergency call setup to a traditional CAMA or ISDN trunk-based PSAP. The length of this - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 216
the language as English and city as London: Switch(config)# interface gigabitEthernet 1/0/2 Switch(config-if)# lldp med-location civic-address language Privilege Requirement None. Example Display the global configuration of LLDP: Switch#show lldp 21.15 show lldp interface Description The show - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 217
Example Display the LLDP configuration of Gigabit Ethernet port 1/0/1: Switch#show lldp interface gigabitEthernet 1/0/1 21.16 show lldp local- command is used to display the LLDP information of the corresponding port. By default, the LLDP information of all the ports will be displayed. Syntax show - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 218
Display the neighbor information of Gigabit Ethernet port 1/0/1: Switch#show lldp neighbor-information interface gigabitEthernet 1/0/1 21.18 between the local device and neighbor device of the corresponding port. By default, the LLDP statistic information of all the ports will be displayed. Syntax - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 219
Privilege Requirement None. Example Display the LLDP statistic information of Gigabit Ethernet port 1/0/1: Switch#show lldp traffic interface gigabitEthernet 1/0/1 200 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 220
vlan 1 Switch(config-if)# ipv6 enable 22.2 ipv6 address autoconfig Description This command is used to enable the automatic configuration of the ipv6 link-local address. The switch has only one ipv6 link-local address, which can be configured automatically or manually. The general ipv6 link - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 221
of the ipv6 link-local address on VLAN interface 1: Switch(config)# interface vlan 1 Switch(config-if)# ipv6 address autoconfig 22.3 ipv6 address link-local Description The ipv6 address link-local command is used to configure the ipv6 link-local address manually on a specified interface - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 222
the VLAN interface 1: Switch(config)# interface vlan 1 Switch(config-if)# ipv6 address fe80::1234 link-local 22.4 ipv6 address dhcp Description The ipv6 address dhcp command is used to enable the DHCPv6 Client function. When this function is enabled, the Layer 3 interface will try to obtain IP from - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 223
configuration function to obtain IPv6 address through the RA message on VLAN interface 1: Switch(config)# interface vlan 1 Switch(config-if)# ipv6 address ra 22.6 ipv6 address eui-64 Description This command is used to manually configure a global IPv6 address with an extended unique identifier (EUI - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 224
EUI-64 global address on the interface with the network prefix 3ffe::/64: Switch(config)# interface vlan 1 Switch(config-if)# ipv6 address 3ffe::/64 eui-64 22.7 ipv6 address Description This command is used to manually configure a global IPv6 address on the interface. To remove a global IPv6 address - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 225
to manually configure the IPv6 gateway address on the interface. Syntax ipv6 gateway ipv6-addr Command Mode VLAN Configuration Mode (VLAN) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the ipv6 gateway for vlan 1: Switch(config - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 226
Admin, Operator and Power User level users have access to these commands. Example Enable DHCP Relay function globally: Switch(config)# service dhcp relay 23.2 ip dhcp relay hops Description The ip dhcp relay hops command is used to specify the maximum hops (DHCP Relay agent) that the DHCP packets - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 227
packet is greater than the value set here, the DHCP packet will be dropped by the switch. To restore the default value, please use no service dhcp relay time command. Syntax ip dhcp relay time time no ip dhcp relay time Parameter time --Specify the DHCP relay time threshold. The valid value ranges - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 228
. Example Add DHCP Server address 192.168.2.1 to interface VLAN 1: Switch(config)# ip dhcp relay vlan 1 helper-address 192.168.2.1 23.5 ip dhcp relay information Description The ip dhcp relay information command is used to enable option 82 support in DHCP Relay. To disable this function, please use - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 229
have access to these commands. Example Enable option 82 support in DHCP Relay for port 2: Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)# ip dhcp relay information 23.6 ip dhcp relay information strategy Description The ip dhcp relay information strategy command is used to specify - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 230
gigabitEthernet 1/0/2 Switch(config-if)# ip dhcp relay information strategy replace 23.7 ip dhcp relay information format Description The ip dhcp relay information format command is used to select the format of option 82 sub-option value field. To restore to the default option, please use no ip dhcp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 231
to these commands. Example Specify the circuit ID as "TP-Link" for port 2: Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)# ip dhcp relay information circuit-id TP-Link 23.9 ip dhcp relay information remote-id Description The ip dhcp relay information remote-id command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 232
remote-id TP-Link 23.10 ip dhcp relay default-interface Description The ip dhcp relay default-interface command is used to configure default relay agent interface. When the switch works at DHCP VLAN Relay mode and there is no IP interface in the VLAN, the switch uses the IP of default relay agent - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 233
Switch(config)# interface vlan 1 Switch(config-if)# ip dhcp relay default-interface 23.11 show ip dhcp relay Description The show ip dhcp relay command is used to display the global status and Option 82 configuration of DHCP Relay. Syntax show ip dhcp relay Command Mode Privileged EXEC Mode and Any - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 234
: Switch(config)# ip dhcp l2relay 24.2 ip dhcp l2relay vlan Description The ip dhcp l2relay vlan command is used to enable DHCP L2 relay in the specified VLAN. To disable DHCP L2 Relay in the specific vlan, please use no ip dhcp l2relay vlan command. Syntax ip dhcp l2relay vlan vlan-range no ip dhcp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 235
level users have access to these commands. Example Enable DHCP L2 Relay for VLAN 2: Switch(config)# ip dhcp l2relay vlan 2 24.3 ip dhcp l2relay information Description The ip dhcp l2relay information command is used to enable option 82 support in DHCP Relay. To disable this function, please use no - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 236
1/0/2 Switch(config-if)# ip dhcp l2relay information strategy replace 24.5 ip dhcp l2relay information format Description The ip dhcp l2relay information format command is used to select the format of option 82 sub-option value field. To restore to the default option, please use no ip dhcp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 237
sub-option value field as TLV (type-length-value) for port 2: Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)#ip dhcp l2relay information format normal 24.6 ip dhcp l2relay information circuit-id Description The ip dhcp l2relay information circuit-id command is used to specify the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 238
access to these commands. Example Specify the remote ID as "TP-Link" for port 2: Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)# ip dhcp l2relay information remote-id TP-Link 24.8 show ip dhcp l2relay Description The show ip dhcp l2relay command is used to display the global status - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 239
EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of DHCP Relay: Switch(config)# show ip dhcp l2relay 24.9 show ip dhcp l2relay interface Description The show ip dhcp l2relay interface command is used to display the DHCP L2 Relay status for the ports - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 240
experience of a better quality. The switch implements three priority modes based on port, on 802.1p and on DSCP. 25.1 qos trust mode Description The qos trust mode command is used to configure the trust mode of CoS (Class of Service) function for the ports. The default trust mode is trust port - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 241
(config)# interface gigabitEthernet 1/0/5 Switch(config-if)# qos port-priority 3 25.3 qos cos-map Description The qos cos-map command is used to configure 802.1p to queue mapping globally. To return to the default configuration, please use no qos cos-map command. When 802.1P Priority is enabled - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 242
have access to these commands. Example Map the 802.1p priority 5 to TC-2: Switch (config)# qos cos-map 5 2 25.4 qos dot1p-remap Description The qos used to configure the 802.1p to 802.1p mappings. To return to the default configuration, please use no qos dot1p-remap command. When 802.1p remap is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 243
commands. Example Remap 802.1p priority 5 to 802.1p priority 6: Switch(config)#qos dot1p-remap 5 6 25.5 qos dscp-map Description The default configuration, please use no qos dscp-map command. DSCP (DiffServ Code Point) is a new definition to IP ToS field given by IEEE. This field is used to divide IP - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 244
Example Map DSCP Priority 5 to 802.1p priority 2: Switch(config)#qos dscp-map 5 2 25.6 qos dscp-remap Description The qos dscp-remap command is used to configure the DSCP to DSCP mappings. To return to the default configuration, please use no qos dscp-remap command. When DSCP remap is configured, - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 245
have access to these commands. Example Specify the Scheduler Mode of TC1 as WRR and set the queue weight as 10 for port 1/0/1: Switch(config)# interface gigabitEthernet 1/0/1 Switch(config-if)# qos queue 1 mode wrr weight 10 25.8 show qos cos-map Description The show qos cos-msp command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 246
Syntax show qos cos-map Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the 802.1p to queue mappings: Switch# show qos cos-map 25.9 show qos dot1p-remap Description The show qos dot1p-remap interface command is used to display the 802.1p - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 247
show qos dscp-remap Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DSCP to DSCP mappings: Switch# show qos dscp-remap 25.12 show qos port-priority interface Description The show qos port-priority interface command is used to display the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 248
port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the trust mode of all the ports: Switch# show qos trust interface 25.14 show qos queue interface Description The show qos queue interface command is used to display the scheduler - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 249
Parameter port -- The port number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the scheduler settings of all the ports: Switch# show qos queue interface 230 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 250
rate on each port. Storm Control function allows the switch to monitor broadcast packets, multicast packets and Unknown unicast frames configure the storm control mode of the interface. To return to the default configuration, please use no storm-control rate-mode command. Syntax storm-control - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 251
and to set threshold levels on an interface. To return to the default configuration, please use no storm-control command. Syntax storm-control { broadcast kbps on port 1/0/5: Switch(config)# interface gigabitEthernet 1/0/5 Switch(config-if)# storm-control rate-mode kbps Switch(config-if)# storm- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 252
shutdown. The valid values are from 0 to 3600 and the default value is 0. When the port is shutdown, it can recover and you can recover the port manually using storm-control recover command. as drop on port 1/0/5: Switch(config)# interface gigabitEthernet 1/0/5 Switch(config-if)# storm-control exceed - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 253
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Recover port 1/0/5 manually: Switch(config)# interface gigabitEthernet 1/0/5 Switch(config-if)# storm-control recover 26.5 bandwidth Description The bandwidth command is used to configure the bandwidth - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 254
access to these commands. Example Configure the ingress-rate as 5120 Kbps and egress-rate as 1024 Kbps for port 1/0/5: Switch(config)# interface gigabitEthernet 1/0/5 Switch(config-if)# bandwidth ingress 5120 egress 1024 26.6 show storm-control Description The show storm-control command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 255
-- The list of port channels. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the bandwidth-limit information of port 1/0/4: Switch(config)# show bandwidth interface gigabitEthernet 1/0/4 236 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 256
have access to these commands. Example Enable the Voice VLAN function for VLAN 10: Switch(config)# voice vlan 10 27.2 voice vlan (interface) Description The voice vlan command is used to enable Voice VLAN function on the desired ports. To disable Voice VLAN function on ports, please use no voice - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 257
Enable the Voice VLAN function for port 1/0/1: Switch(config)# interface gigabitEthernet 1/0/1 Switch(config-if)#voice vlan 27.3 voice vlan priority Description The voice vlan priority command is used to configure the priority for the Voice VLAN. To restore to the default priority, please use - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 258
these commands. Example Create a Voice VLAN OUI described as TP-Phone with the OUI address 00:11:11:11:11:11 and the mask address FF:FF:FF:00:00:00: Switch(config)#voice vlan oui 00:11:11 oui-desc TP-Phone 27.5 show voice vlan Description The show voice vlan command is used to display - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 259
and Power User level users have access to these commands. Example Display the configuration information of Voice VLAN globally: Switch(config)# show voice vlan 27.6 show voice vlan oui-table Description The show voice vlan oui command is used to display the configuration information of Voice - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 260
vlan interface Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Display the Voice VLAN configuration information of all ports and port channels: Switch(config)# show voice vlan - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 261
that the sound quality of an IP phone does not deteriorate when data function globally: Switch(config)# auto-voip 28.2 VLAN ID for the ports. In this mode, the voice devices will send voice packets with desired VLAN tag. Syntax auto-voip vlan-id Parameter vlan-id --Specify the Auto VoIP VLAN - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 262
gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Example Set Auto VoIP VLAN 3 for port 3: Switch(config)# interface gigabitEthernet 1/0/3 Switch(config-if)# auto-voip 3 28.3 auto-voip dot1p Description The auto-voip dot1p command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 263
to specify the interface mode as none for the ports. In this mode, the switch allows the voice devices to use its own configuration to send voice traffic. Syntax / interface port-channel / interface range port-channel) Example Instruct voice devices that are connected to port 3 to send the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 264
/ interface range port-channel) Example Disable the Auto VoIP function on port 1/0/3: Switch(config)# interface gigabitEthernet 1/0/3 Switch(config-if)# no auto-voip 28.7 auto-voip dscp Description The auto-voip dscp of Auto VoIP on specified ports. It ranges from 0 to 63. By default, it is 0. 245 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 265
used to enable or disable the CoS Override Mode on specified ports. Syntax auto-voip data priority { trust | untrust } Parameter trust--In this mode, the switch will then put the voice packets in the corresponding TC queue according to the 802.1p priority of the packets. untrust--In this mode, the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 266
entered, displays the global Auto VoIP configuration information. Command Mode Privileged EXEC Mode and any Configuration Mode Example Displays the global Auto VoIP configuration information: Switch (config)# show auto-voip 247 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 267
access to these commands. Example Configure the access control mode as IP-based: Switch(config)# user access-control ip-based enable 29.2 user access-control ip-based Description The user access-control ip-based command is used to limit the IP-range of the users for login. Only the users within the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 268
Specify the access interface. These interfaces are enabled by default. id -- Delete the specified IP-based entry. Command Mode Global Configuration Mode Privilege Requirement Only -control of the user whose IP address is 192.168.0.148: Switch(config)# user access-control ip-based 192.168.0.148 255. - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 269
[ https ] [ ping ] [ all ] -- Specify the access interface. These interfaces are enabled by default. id-- Specify the ID of the mac-based entry to be deleted. Command Mode Global Configuration Mode Privilege 01 is allowed to login: Switch(config)# user access-control mac-based 00:00:13:0A:00:01 250 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 270
Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the access control mode as Port-based: Switch(config)# user access-control port-based enable 29.6 user access-control port-based Description The user access-control port-based command is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 271
https ] [ ping ] [ all ] -- Specify the access interface. These interfaces are enabled by default. id-- Specify the ID of the port-based entry to be deleted. Command Mode Global Configuration are allowed to login: Switch(config)# user access-control port-based interface gigabitEthernet 1/0/2-6 252 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 272
key. The Certificate/Key Download function enables the user to replace the default key pair. 30.1 ip http server Description The ip http server command is used to enable the HTTP server within the switch. To disable the HTTP function, please use no ip http server command. This function is enabled by - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 273
port command is used to configure the port number of the HTTP server within the switch. To set the number to the default value, please use no ip http port command. Syntax ip http port port-num no ip http port Parameter port-num -- Enter the port number. This value ranges from 1 to 65535. Command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 274
1, 1, 1 for HTTP: Switch(config)# ip http max-users 5 1 1 1 30.4 ip http session timeout Description The ip http session timeout command is used restore to the default timeout time, please use no ip http session timeout command. Syntax ip http session timeout time no ip http session timeout - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 275
Disable the HTTP function: Switch(config)# no ip http secure-server 30.6 ip http secure-port Description The ip http secure-port command is used to configure the port number of the HTTPS server within the switch. To set the number to the default value, please use no ip http secure-port command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 276
used to configure the SSL protocol version. To restore to the default SSL version, please use no ip http secure-protocol command. By default, the switch supports all the protocol versions, including SSL 3.0, TLS 1.1 and TLS 1.2. Syntax ip http secure-protocol { ssl3 | tls1 | tls11 | tls12 | all } no - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 277
-ciphersuite command is used to configure the cipher suites over the SSL connection supported by the switch. To restore to the default cipher suite types, please use no ip http secure-ciphersuite command. Syntax ip http secure-ciphersuite { [ rc4-128-md5 ] [ rc4-128-sha ] [ des-cbc-sha ] [ 3des - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 278
Power User level users have access to these commands. Example Configure the maximum number of the Admin, Operator, Power User and User as 5, 1, 1, 1 for HTTPs: Switch(config)# ip http secure-max-users 5 1 1 1 259 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 279
to 30 in minutes. By default, the value is 10. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the timeout time of the HTTPs connection as 15 minutes: Switch(config)# ip http secure-session - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 280
of the SSL key which is selected to download to the switch. The length of the name ranges from 1 to 25 characters. The Key must be BASE64 encoded. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for Example 192.168.0.1 or fe80::1234. Command Mode Global - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 281
User level users have access to these commands. Example Download an SSL key named ssl-key from TFTP server with the IP address of 192.168.0.146: Switch(config)# ip http secure-server download key ssl-key ip-address 192.168.0.146 Download an SSL key named ssl-key from TFTP server with the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 282
The show ip http secure-server command is used to display the global configuration of SSL. Syntax show ip http secure-server Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of SSL: Switch(config)# show ip http secure - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 283
access to these commands. Example Enable the SSH function: Switch(config)# ip ssh server 31.2 ip ssh port Description The ip ssh port command is used to configure the port for SSH service. To set the value to the default, please use no ip ssh port command. Syntax ip ssh port port no ip ssh port 264 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 284
65535. The default value is 22. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the SSH port number as 22: Switch(config)# ip ssh port 22 31.3 ip ssh version Description The ip ssh version - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 285
as AES128-CBC: Switch(config)# ip ssh algorithm AES128-CBC 31.5 ip ssh timeout Description The ip ssh timeout command is used to specify the idle-timeout time of SSH. To restore to the factory defaults, please use ip ssh timeout command. Syntax ip ssh timeout value no ip ssh timeout Parameter value - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 286
in seconds. By default, this value is 120 seconds. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the idle-timeout time of SSH as 30 seconds: Switch(config)# ip ssh timeout 30 31.6 ip ssh max - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 287
range of 512 to 3072 bits. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for Example 192.168.0.1 or named ssh-key from TFTP server with the IP address 192.168.0.148: Switch(config)# ip ssh download v1 ssh-key ip-address 192.168.0.148 Download an SSH-1 type - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 288
to these commands. Example Remove the SSH-1 type public key from the switch: Switch# remove public-key v1 31.9 show ip ssh Description The show ip ssh command is used to display the global configuration of SSH. Syntax show ip ssh Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 289
log in and manage other devices via telnet. Syntax telnet ip-addr Parameter ip-addr--The IP address of the device you want to log in. Command in via telnet. Example Log in to a device with the IP address of 192.168.0.10: Switch# telnet 192.168.0.10 32.2 telnet enable Description The telnet enable - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 290
Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable the Telnet function: Switch(config)# telnet disable 32.3 telnet port Description The telnet port command is used to configure the telent port number. To restore the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 291
Syntax show telnet-status Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display whether the Telnet function is enabled: Switch(config)# show telnet-status 272 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 292
Method List A method list describes the authentication methods and their sequence to authenticate a user. The switch supports Login List for users to gain access to the switch, and Enable List for normal users to gain administrative privileges. • RADIUS/TACACS+ Server User can configure - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 293
+ servers you configured are added in the server group "tacacs" by default. Example Configure a TACACS+ server with the IP address as 1.1.1.1, TCP port as 1500, timeout as 6 seconds, and the unencrypted key string as 12345. Switch(config)# tacacs-server host 1.1.1.1 port 1500 timeout 6 key 12345 33 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 294
the IP address of the RADIUS server. auth-port port-id -- Specify the UDP destination port for authentication requests. By default it is 1812. acct-port port-id -- Specify the UDP destination port for accouting requests. By deault it is 1813. time -- Specify the time in seconds the switch waits - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 295
a fixed length will follow. By default, the encryption type is 0. "string" is the shared key for the switch and the authentication servers to exchange added in the server group "radius" by default. Example Configure a RADIUS server with the IP address as 1.1.1.1, authentication port as 1200, timeout - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 296
commands. Example Display the information of all the RADIUS servers: Switch(config)# show radius-server 33.5 aaa group Description This group existing TACACS+/RADIUS servers for authentication. This command puts the switch in the server group subconfiguration mode. To delete the corresponding AAA - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 297
no server ip-address Parameter ip-address -- Specify the server's IP address. Command Mode Server Group Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Create the RADIUS server 1.1.1.1 to RADIUS server group "radius1": Switch(config)# aaa - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 298
Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the information of all the server groups: Switch(config)# show aaa group 33.8 aaa authentication login Description This aaa authentication login command is used to configure a login authentication method - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 299
the login authentication method list is "default" with "local" as method1. Example Configure a login authentication method list "list1" with the priority1 method as radius and priority2 method as local: Switch(config)# aaa authenticaiton login list1 radius local 33.9 aaa authentication enable - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 300
server group is supported, and the default method is server group "radius". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the default 802.1x authentication method as "radius1": Switch(config)# aaa authentication - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 301
is supported, and the default method is server group "radius". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the default 802.1x accounting method as "radius1": Switch(config)# aaa accounting dot1x default radius1 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 302
and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the information of the default 802.1x accounting method list: Switch(config)# show aaa accounting 33.14 line telnet Description The line telnet command is used to enter the Line - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 303
" by default, which contains the method "local". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the telnet terminal line as "list1": Switch(config)#line telnet Switch(config - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 304
these commands. Example Enter the ssh terminal line configuration mode: Switch(config)#line ssh 33.17 login authentication (ssh) Description The method list to the ssh terminal line. To restore to the default authentication method list, please use the no login authentication command. Syntax - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 305
(config)# line ssh Switch(config-line)# login authentication list1 33.18 enable authentication (telnet) Description The enable authentication command is used to apply the privilege authentication method list to the telnet terminal line. To restore to the default authentication method list, please - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 306
(config)# line ssh Switch(config-line)# enable authentication list2 33.20 ip http login authentication Description The ip http login authentication command is used to apply the login authentication method list to users accessing through HTTP. To restore to the default authentication method list - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 307
. It is "default" by default, which contains the method "local". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the HTTP access as "list1": Switch(config)# ip http login - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 308
method list on the HTTP access as "list2": Switch(config)# ip http enable authentication list2 33.22 show aaa global Example Display the AAA function's global status and each application's method list: Switch(config)# show aaa global 33.23 enable admin password Description The enable admin - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 309
special characters. The special characters are By default, it is empty. 7 -- Indicates a the global encryption function is enabled in service password-encryption, the password in the configuration users to change the access level to admin: Switch(config)#enable admin password 0 abc123 33.24 enable - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 310
digits and 17 kinds of special characters. The special characters are By default, it is empty. The password in the configuration file will be displayed to admin. The password will be displayed in the encrypted form. Switch(config)#enable admin secret 0 abc123 33.25 enable-admin Description The - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 311
Syntax enable-admin Command Mode Privileged EXEC Mode Privilege Requirement Only User, Power User and Operator level users have access to these commands. Example Get the administrative privelges (the Enable password is "123456"): Switch# enable-admin Password: 123456 292 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 312
the physical access to the network based on the authentication status of the supplicant. It is usually an 802.1x-supported network device, such as this TP-Link switch. It acts as an intermediary (proxy) between the supplicant and the authentication server, requesting identity information from the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 313
is used to detect the connection status between the TP-Link 802.1x supplicant and the switch. Please disable the handshake feature if you are using a non-TP-Link 802.1x-compliant client software. This feature is enabled by default. Syntax dot1x handshake no dot1x handshake Command Mode Global - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 314
is authenticated. If the assigned VLAN does not exist on the switch, the switch will create the related VLAN automatically, add the authenticated port to the VLAN and change the PVID based on the assigned VLAN. If the assigned VLAN exists on the switch, the switch will directly add the authenticated - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 315
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the VLAN assignment feature: Switch(config)#dot1x vlan-assignment 34.5 dot1x accounting Description The dot1x accounting command is used to enable the IEEE 802.1x accounting function - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 316
devices without 802.1x capability. For Example, most printers, IP phones and fax machines do not have 802.1x capability. Switch(config)#interface gigabitEthernet 1/0/1 Switch(config-if)#dot1x mab 34.7 dot1x guest-vlan Description The dot1x guest-vlan command is used to configure the Guest VLAN - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 317
Example Enable the Guest VLAN function for VLAN 5 and set the VLAN ID as 20 on the Gigabit Ethernet port 1/0/1:: Switch(config)#interface gigabitEthernet 1/0/1 Switch(config-if)#dot1x guest-vlan 5 34.8 dot1x quiet-period time. It ranges from 1 to 999 seconds and the default value is 10 seconds. 298 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 318
no dot1x timeout supp-timeout Parameter time --The maximum time for the switch to wait for the response from supplicant before resending a request to the supplicant., ranging from 1 to 60 in second. By default, it is 30 seconds. Command Mode Interface Configuration Mode Privilege Requirement Only - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 319
Switch(config-if)#dot1x timeout supp-timeout 5 34.10 dot1x max- req Description The dot1x max-req command is used to configure the maximum transfer times of the repeated authentication request when the server cannot be connected. To restore to the default to 9 in times. By default, the value is 3. - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 320
config)#interface gigabitEthernet 1/0/1 Switch(config-if)#dot1x 34.12 dot1x port-control Description The dot1x port-control command is used to configure the Control Mode of IEEE 802.1x for the specified port. By default, the control mode is "auto". To restore to the default configuration, please use - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 321
(config)#interface gigabitEthernet 1/0/20 Switch(config-if)#dot1x port-control authorized-force 34.13 dot1x port-method Description The dot1x port-method command is used to configure the control type of IEEE 802.1x for the specified port. By default, the control type is "mac-based". To restore to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 322
User level users have access to these commands. Example Configure the Control Type for Gigabit Ethernet port 20 as "port-based": Switch(config)#interface gigabitEthernet 1/0/20 Switch(config-if)#dot1x port-method port-based 34.14 dot1x auth-init Description The dot1x auth-init command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 323
range gigabitEthernet) Privilege Requirement None. Example Reauthenticate the client whose MAC address is a 00:02:58:4f:6c:23 on port 1: Switch(Config)# interface gigabitEthernet 1/0/1 Switch(Config-if)#dot1x auth-reauth mac 00:02:58:4f:6c:23 34.16 show dot1x global Description The show dot1x global - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 324
Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of 801.X for Gigabit Ethernet port 20: Switch(config)#show dot1x interface gigabitEthernet 1/0/20 Display the configuration information of 801.X for all Ethernet ports - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 325
Example Display the authentication status of each port: Switch(config)#show dot1x auth-state 306 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 326
configure the related Parameters. To disable the feature and restore the Parameters to defaults on the port, please use no mac address-table max-mac-count command. as permanent and the status as drop: Switch (config)#interface gigabitEthernet 1/0/1 Switch(config-if)#mac address-table max-mac-count - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 327
| gigabitEthernet port | ten-gigabitEthernet port } Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the port security configuration on port 1/0/1 Switch# show mac address-table max-mac-count interface gigabitEthernet 1/0/1 308 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 328
ports, LAGs or the CPU) to a destination port. It does not affect the switching of network traffic on source ports, LAGs or the CPU. Usually, the monitoring port used to analyze the monitored packets for monitoring and troubleshooting the network. 36.1 monitor session destination interface - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 329
(config)# no monitor session 1 destination interface gigabitEthernet 1/0/2 Delete the monitor session 1: Switch(config)# no monitor session 1 36.2 monitor session source Description The monitor session source command is used to configure the monitored interface. To delete the corresponding - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 330
monitored ports are in the same VLAN or not is not demanded strictly. 4. The monitoring port and monitored ports cannot be link-aggregation member. Example Create monitor port 4 in monitor session 1 and its configuration: Switch(config)# no monitor session 1 source interface gigabitEthernet 1/0/4 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 331
Switch(config)# show monitor session 1 312 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 332
Enter an ACL ID. The IDs for MAC ACL are from 0 to 499. The IDs for IP ACL are from 500 to 999. The IDs for Combined ACL are from 1000 to 1499. The level users have access to these commands. Example Create an IP ACL whose ID is 523: Switch(config)# access-list create 523 37.2 access-list resequence - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 333
of ACL 12 with the start ID as 1 and step value as 5: Switch(config)# access-list resequence 12 start 1 step 5 37.3 access-list mac destination-mac dmask destination-mac-mask ] [type ether-type] [pri dot1p-priority] [vid vlan-id] [tseg time-range-name] no access-list mac acl-id-or-name rule rule- - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 334
The user priority ranges from 0 to 7. The default is No Limit. vlan-id -- The VLAN ID ranges from 1 to 4094. time-range-name -- The name of the packets with source MAC address 00:34:a2:d4:34:b5: Switch (config)#access-list create 50 Switch (config-mac-acl)#access-list mac 50 rule 5 permit logging - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 335
mask d-port-mask] [tcpflag tcpflag]] [tseg time-range-name] no access-list ip acl-id-or-name rule rule-id Parameter acl-id-or-name -- Enter the -- Specify the action to be taken with the packets that match the rule. By default, it is set to permit. The packets will be discarded if "deny" is selected - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 336
-range. The default is No Limit. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create IP ACL 600, and configure Rule 1 to permit packets with source IP address 192.168.1.100: Switch (config)#access - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 337
a destination MAC address is entered. vlan-id: The VLAN ID ranges from 1 to 4094. ether-type -- Specify the Ethernet-type with 4 hexadecimal numbers. priority -- The user priority ranges from 0 to 7. The default is No Limit. source-ip: Enter the source IP address. source-ip-mask -- Enter the mask of - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 338
. The default is No Limit. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create Combined ACL 1100 and configure Rule 1 to deny packets with source IP address 192.168.3.100 in VLAN 2: Switch (config - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 339
permit -- Specify the action to be taken with the packets that match the rule. By default, it is set to permit. The packets will be discarded if "deny" is selected but only the first 64 bits will be valid. source-ip-mask -- Enter the source IP address mask. The mask is required if the source IPv6 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 340
IP -- The name of the time-range. The default is No Limit. Command Mode Global Configuration Mode Privilege Before binding an IPv6 ACL to a VLAN or interface, you should configure the 2222:5498:8475:1111:3900:2020: Switch(config)# access-list create 1600 Switch(config)# access-list ipv6 1600 rule - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 341
Example Specify the rule 1 of ACL 200 to be configured with policies: Switch(config)# access-list action 200 rule 1 37.8 redirect Description The redirect destination port to which the packets will be redirected. The default is All. Command Mode Action Configuration Mode Privilege Requirement Only - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 342
for the packets whose rate is beyond the specified rate. The default is None. Command Mode Action Configuration Mode Privilege Requirement Only Admin, 100, the packets will be discarded by the switch: Switch(config)#access-list action 6 rule 1 Switch(config-action)# s-condition rate 1000 burst 100 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 343
config)#access-list action 6 rule 1 Switch(config-action)#s-mirror interface gigabitEthernet 1/0/2 37.11 qos-remark Description The qos-remark command is used to configure QoS Remark function of policy action. To restore the settings to the default, please use no qos-remark. Syntax qos-remark [ dscp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 344
local priority 2 for the packets matching this rule: Switch(config)#access-list action 6 rule 1 Switch(config-action)# qos-remark dscp 30 priority 2 37 ACL rules. Syntax access-list bind acl-id-or-name interface { [ vlan vlan-list ] | [ fastEthernet port-list ] | [gigabitEthernet port-list ] - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 345
Example Bind ACL 1 to port 3 and VLAN 4: Switch(config)#access-list bind 1 interface vlan 4 gigabitEthernet 1/0/3 37.13 show access-list None. Example Display the configuration of the MAC ACL whose ID is 20: Switch(config)# show access-list 20 37.14 show access-list bind Description The show - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 346
-list status Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the usage status of ACL entry resource: Switch(config)# show access-list status 37.16 show access-list counter Description The show access-list counter command is used to display the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 347
-- The ID of the rule. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Clear the packet counter of ACL 100: Switch(config)# clear access-list 100 328 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 348
verify source to filter the packets. 38.1 ip source binding Description The ip source binding command is used to bind the IP address, MAC address, VLAN ID and the Port number together manually. You can manually bind the IP address, MAC address, VLAN ID and the Port number together in the condition - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 349
User level users have access to these commands. Example Bind an ACL entry with the IP 192.168.0.1, MAC 00:00:00:00:00:01, VLAN ID 2 and the Port number 5 manually. And then enable the entry for the ARP detection: Switch(config)#ip source binding host1 192.168.0.1 00:00:00:00:00:01 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 350
1,4,6-7: Switch(config)#ip dhcp snooping vlan 1,4,6-7 38.4 ip dhcp snooping max-entries Description The ip dhcp snooping max-entries command is used to configure the maximum number of entries that can be learned on a port via DHCP Snooping. To restore to the default setting, please use no ip dhcp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 351
on port 1 as 100: Switch(config)#interface gigabitEthernet 1/0/1 Switch(config-if)#ip dhcp snooping max-entries 100 38.5 show ip source binding Description The show ip source binding command is used to display the IP-MAC-VIDPORT binding table. Syntax show ip source binding Command Mode Privileged - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 352
Any Configuration Mode Privilege Requirement None. Example Display the running status of DHCP Snooping: Switch#show ip dhcp snooping 38.7 show ip dhcp snooping interface Description The show ip dhcp snooping interface command is used to display the DHCP Snooping configuration of a desired Gigabit - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 353
Example Display the DHCP Snooping configuration of all Ethernet ports and port channels: Switch#show ip dhcp snooping interface Display the DHCP Snooping configuration of Gigabit Ethernet port 1/0/5: Switch#show ip dhcp snooping interface gigabitEthernet 1/0/5 334 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 354
the ARP Inspection and IP verify source to filter the packets. 39.1 Ipv6 source binding Description The ipv6 source binding command is used to bind the IPv6 address, MAC address, VLAN ID and the Port number together manually. You can manually bind the IPv6 address, MAC address, VLAN ID and the Port - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 355
address AA-BB-CC-DD-EE-FF, VLAN ID 10, port number 1/0/5, and enable this entry for ND Detection. Switch(config)# ipv6 source binding host1 2001:0:9d38: process of the Host obtaining the IP address from DHCPv6 server, and record the IPv6 address, MAC address, VLAN and the connected Port number of - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 356
1,4,6-7: Switch(config)#ipv6 dhcp snooping vlan 1,4,6-7 39.4 ipv6 dhcp snooping max-entries Description The ipv6 dhcp snooping max-entries command is used to configure the maximum number of entries that can be learned on a port via DHCPv6 Snooping. To restore to the default setting, please use no - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 357
that can be learned on port 1 as 100: Switch(config)#interface gigabitEthernet 1/0/1 Switch(config-if)#ipv6 dhcp snooping max-entries 100 39.5 ipv6 duplication address detection, and record the IPv6 address, MAC address, VLAN and the connected Port number of the Host for automatic binding. Syntax - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 358
Switch(config)#ipv6 nd snooping vlan 1,4,6-7 39.7 ipv6 nd snooping max-entries Description The ipv6 nd snooping max-entries command is used to specify the maximum number of binding entries that are allow to be bound to a port. To return the default, please use no ipv6 nd snooping max-entries - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 359
to these commands. Example Configure the maximum number of binding entries from ND Snooping of Gigabit Ethernet port 1/0/2 is 100: Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)#ipv6 nd snooping max-entries 100 39.8 show ipv6 source binding Description The show ipv6 source binding - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 360
dhcp snooping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the running status of DHCPv6 Snooping: Switch#show ipv6 dhcp snooping 39.10 show ipv6 dhcp snooping interface Description The show ipv6 dhcp snooping interface command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 361
. Example Display the DHCPv6 Snooping configuration of all Ethernet ports and port channels: Switch#show ipv6 dhcp snooping interface Display the DHCPv6 Snooping configuration of Gigabit Ethernet port 1/0/5: Switch#show ipv6 dhcp snooping interface gigabitEthernet 1/0/5 39.11 show ipv6 nd snooping - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 362
. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the ND Snooping configuration of all Ethernet ports and port channels: Switch#show ipv6 nd snooping interface Display the ND Snooping configuration of Gigabit Ethernet port - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 363
-MAC binding rules can be processed. sip -- Security type. "sip" indicates that only the packets with its source IP address and port number matched to the IP-MAC binding rules can be processed. Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernetinterface - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 364
log feature to make the switch generate logs when receiving illegal packets: Switch(config)#ip verify source logging 40.3 show ip verify source Description The show ip verify source command is used to display the IP Verify Source configuration information. Syntax show ip verify source Command Mode - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 365
Privilege Requirement None. Example Display the IP Verify Source configuration information: Switch(config)#show ip verify source 40.4 show ip verify source interface Description The show ip verify source interface command is used to display the IP verify source configuration of a desired Gigabit - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 366
Chapter 41 IPv6 Verify Source Commands IPv6 Verify Source is to filter the IPv6 packets based on the IPv6-MAC Binding entries. Only the packets matched to the IPv6-MAC Binding rules can be processed, which can enhance the bandwidth utility. Before configuring IPv6 Verify Source feature, you should - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 367
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the IPv6 Verify Source configuration information: Switch(config)#show ipv6 verify source 41.3 show ipv6 verify source interface Description The show ipv6 verify source interface command is used - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 368
Privilege Requirement None. Example Display the IPv6 verify source configuration of Gigabit Ethernet port 1/0/5: Switch#show ipv6 verify source interface gigabitEthernet 1/0/5 349 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 369
network and both provide DHCP services to different distinct groups of clients. 42.1 ip dhcp filter Description The ip dhcp filter command is used to the DHCP Filter function globally: Switch(config)#ip dhcp filter 42.2 ip dhcp filter (interface) Description The ip dhcp filter (interface) command is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 370
User level users have access to these commands. Example Enable the DHCP Filter on port 1/0/1 Switch(config)#interface gigabitEthernet 1/0/1 Switch(Config-if)#ip dhcp filter 42.3 ip dhcp filter mac-verify Description The ip dhcp filter mac-verify command is used to enable the MAC Verify feature. To - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 371
1/0/2 Switch(config-if)#ip dhcp filter mac-verify 42.4 ip dhcp filter limit rate Description The ip dhcp filter limit rate command is used to enable the Flow Control feature for the DHCP packets. The excessive DHCP packets will be discarded. To restore to the default configuration, please use no ip - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 372
interface gigabitEthernet 1/0/2 Switch(config-if)#ip dhcp filter decline 20 42.6 ip dhcp filter server permit-entry Description The ip dhcp filter server permit-entry command is used to add entry for the legal DHCP server. To restore to the default option, please use no ip dhcp snooping information - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 373
connected port number is 1/0/1 without client MAC address restricted: Switch(config)#ip dhcp filter server permit-entry server-ip 192.168.0.100 client-mac all interface gigabitEthernet 1/0/1 42.7 show ip dhcp filter Description The show ip dhcp filter command is used to display the configuration of - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 374
EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DHCP Filter configuration: Switch#show ip dhcp filter 42.8 show ip dhcp filter interface Description The show ip dhcp filter interface command is used to display the configuration of DHCP Filter on ports. Syntax - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 375
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the legal DHCP server configuration: Switch#show ip dhcp filter server permit-entry 356 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 376
more DHCPv6 servers are present on the network and both provide DHCPv6 services to different distinct groups of clients. 43.1 ipv6 dhcp filter Description to these commands. Example Enable the DHCPv6 Filter function globally: Switch(config)#ipv6 dhcp filter 43.2 ipv6 dhcp filter (interface) - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 377
gigabitEthernet 1/0/1 Switch(Config-if)#ipv6 dhcp filter 43.3 ipv6 dhcp filter limit rate Description The ipv6 dhcp filter limit rate command is used to enable the Flow Control feature for the DHCPv6 packets. The excessive DHCPv6 packets will be discarded. To restore to the default configuration - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 378
the Flow Control of GigabitEthernet port 2 as 20 pps: Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)#ipv6 dhcp filter limit rate 20 43.4 ipv6 5, 10, 15, 20, 25 and 30 (units:packet/second). It default value is 0, which stands for "disable". Command Mode Interface Configuration Mode - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 379
packets per second on Gigabit Ethernet port 1/0/2: Switch(config)#interface gigabitEthernet 1/0/2 Switch(config-if)#ipv6 dhcp filter decline 20 43 the default option, please use no ipv6 dhcp snooping information strategy command. Syntax Ipv6 dhcp filter server permit-entry server-ip ipAddr interface - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 380
show ipv6 dhcp filter Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DHCPv6 Filter configuration: Switch#show ipv6 dhcp filter 43.7 show ipv6 dhcp filter interface Description The show ipv6 dhcp filter interface command is used to display - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 381
43.8 show ip dhcp filter server permit-entry Description The show ipv6 dhcp filter server permit-entry command is used EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the legal DHCPv6 server configuration: Switch#show ipv6 dhcp filter server permit-entry 362 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 382
the evil programs sending a lot of service requests to the Host. With the DoS Defend enabled, the switch can analyze the specific field of the the DoS defend function, please use no ip dos-prevent command. Syntax ip dos-prevent no ip dos-prevent Command Mode Global Configuration Mode Privilege - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 383
with Ping packets, creating a broadcast storm that makes it impossible for the system to respond to legal communication. syn-flood --The attacker uses a fake IP address to send TCP request packets to the server. Upon receiving the request packets, the server responds with SYN-ACK packets. Since the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 384
is a distributed denial-of-service attack in which large numbers of Internet Control Message Protocol (ICMP) packets with the intended victim's spoofed source IP are broadcast to a computer network using an IP broadcast address. Most devices on a network will, by default, respond to this by sending - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 385
Example Display the DoS information of the detected DoS attack globally: Switch(config)#show ip dos-prevent 366 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 386
Ethernet cables. When a unidirectional link is detected, the corresponding port will be shut down automatically or manually (depending on the shut mode these commands. Example Enable the DLDP function globally: Switch(config)# dldp 45.2 dldp interval Description The . By default, it is 5 seconds. 367 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 387
is detected. Syntax dldp shut-mode { auto | manual } Parameter auto -- The switch automatically shuts down ports when a unidirectional link is detected. By default, the shut-mode is auto. manual --The switch displays an alert when a unidirectional link is detected. The operation to shut down the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 388
Requirement Only Admin and Operator level users have access to these commands. Example Enable the DLDP function of ports 1/0/2-4: Switch (config)# interface range gigabitEthernet 1/0/2-4 Switch (config-if-range)# dldp 45.5 show dldp Description The show dldp command is used to display the global - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 389
Switch# show dldp 45.6 show dldp interface Description The show dldp interface command is used to display the configuration and state of the specified Ethernet port. By default, the configuration and state of all the ports will be displayed. Syntax show dldp interface [gigabitEthernet port ] - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 390
disabled. To return to the default configuration, please use no snmp-server command. Syntax snmp-server no snmp-server Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the SNMP function: Switch(config)# snmp-server 46 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 391
commands. Example Add a View named view1, configuring the OID as 1.3.6.1.6.3.20, and this OID can be managed by the SNMP management station: Switch(config)# snmp-server view view1 1.3.6.1.6.3.20 include 46.3 snmp-server group Description The snmp-server group command is used to manage and configure - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 392
and a privacy algorithm are applied to check and encrypt packets). By default, the Security Level is noAuthNoPriv. There is no need to configure this notification messages of the assigned SNMP view generated by the switch's SNMP agent. Command Mode Global Configuration Mode Privilege Requirement - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 393
used to add User. To delete the corresponding User, please use no snmp-server user command. The User in an SNMP Group can manage the switch via the management station software. The User and its Group have the same security level and access right. Syntax snmp-server user name { local | remote - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 394
privacy method is used, and DES indicates DES encryption method is used. By default, the Privacy Mode is "none". encrypt-pwd -- Privacy Password, ranging from the Privacy Mode as DES, and the Privacy Password as 22222: Switch(config)# snmp-server user admin local group2 smode v3 slev authPriv cmode - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 395
community has read-write management right to View viewDefault: Switch(config)# snmp-server community public read-write viewDefault 46 timeout ] no snmp-server host ip user-name Parameter ip -- The IP Address of the management Host. Both IPv4 and IPv6 addresses are supported, for Example 192.168.0.100 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 396
By default, the type of the notifications is "trap". retries -- The amount of times the switch retries an inform request, ranging from 1 to 255. The switch will to these commands. Example Add a Notification entry, and configure the IP address of the management Host as 192.168.0.146, the UDP port - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 397
IP Address of the management Host as fe80::1234, the UDP port as 162, the User name of the management station as admin, the Security Model of the management station as v2c, the type of the notifications as inform, the maximum time for the switch of the switch. To restore to the default setting, - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 398
enables all SNMP standard traps. All SNMP standard traps are enabled by default. To disable the sending of SNMP standard traps, please use no device to a port. warmstart -- Indicates the SNMP feature on the switch is reinitialized with the physical configuration unchanged. The trap can be triggered - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 399
the limit that you have set. The limit of CPU utilization rate for the switch is 80% by default. flash --Triggered when flash is modified during operations such as backup, reset, firmware upgrade, configuration import, and so on. lldp remtableschange --An lldp RemTablesChange notification is sent - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 400
function, please use no snmp-server traps vlan command. All VLAN traps are disabled by default. Syntax snmp-server traps vlan [ create | delete ] no snmp-server traps vlan [create | delete ] Parameter create --Triggered when certain VLANs are created successfully. delete --Triggered when certain - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 401
Switch(config)# snmp-server traps vlan create 46.11 snmp-server traps security Description The snmp-server traps security command is used to enable the corresponding security traps. To disable this feature, please use no snmp-server traps security command. All security traps are disabled by default - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 402
the ACL trap for the switch: Switch(config)# snmp-server traps acl 46.13 snmp-server traps ip Description The snmp-server traps ip command is used to enable IP traps. To disable this feature, please use no snmp-server traps ip command. All IP traps are disabled by default. Syntax snmp-server traps - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 403
Admin level users have access to these commands. Example Enable the IP-Change trap for the switch: Switch(config)# snmp-server traps ip change 46.14 snmp-server traps power (Only for Certain Devices) Note: Only certain devices support this command. Description The snmp-server traps power command is - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 404
have access to these commands. Example Enable all PoE traps for the switch: Switch(config)# snmp-server traps power 46.15 snmp-server traps link-status Description The snmp-server traps link-status command is used to enable SNMP link status trap for the specified port. To disable the sending of SNMP - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 405
RMON Groups. After a history group is configured, the switch collects network statistics information periodically, based on which the management RMON history group of statistics, ranging from 1 to 130. The default is 50 buckets. Command Mode Global Configuration Mode Privilege Requirement Only Admin - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 406
used to configure the entries of SNMP-RMON Event. To return to the default configuration, please use no rmon event command. Event Group, as one of owner of the event entry, ranging from 1 to 16 characters. By default, it is "monitor". Command Mode Global Configuration Mode Privilege Requirement Only - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 407
the type of event as log and the owner of the event as owner1: Switch(config)# rmon event 1-4 user user1 Description Description1 type log owner owner1 46.18 is used to configure SNMP-RMON Alarm Management. To return to the default configuration, please use no rmon alarm command. Alarm Group is one - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 408
. By default, it is 1800. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure rmon alarm entries 1-3 binding with statistics entry 2, the owners as owner1 and the alarm intervals as 100 seconds: Switch(config)#rmon - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 409
-- The creator of the event entry, ranging from 1 to 16 characters. By default, it is "monitor". status -- The status of the statistics entry, either " port as 1/0/1, owner as owner1 and status as valid: Switch(config)#rmon statistics 1-3 interface gigabitEthernet 1/0/1 owner owner1 status - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 410
Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the View table: Switch# show snmp-server view 46.22 show snmp-server group Description The show snmp-server group command is used to display the Group table - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 411
Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the Community table: Switch# show snmp-server community 46.25 show snmp-server host Description The show snmp-server host command is used to display the Host - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 412
Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the Host table: Switch# show snmp-server host 46.26 show snmp-server engineID Description The show snmp-server engineID command is used to display the engineID - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 413
commands. Example Display the configuration of all history sample entries: Switch# show rmon history 46.28 show rmon event Description The show 1-3, 5. You can select more than one entry for each command. By default, the configuration of all SNMP-RMON enabled entries is displayed. Command Mode - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 414
1-3, 5. You can select more than one entry for each command. By default, the configuration of all Alarm Management entries is displayed. Command Mode Privileged . Example Display the configuration of the Alarm Management entry 1-2: Switch# show rmon alarm 1-2 46.30 show rmon statistics Description - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 415
Example Display the configuration of the statistics entry 1: Switch#show rmon statistics 1 396 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 416
) Note: Only certain devices support PoE function. PoE (Power network. It is especially useful for supplying power to IP telephones, wireless LAN access points, cameras and so on command is used to create a PoE profile for the switch. To delete the configured PoE profile configuration, please use - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 417
supply power exceeds the system power limit, the PD linked to the port with lower priority will be disconnected. By default, the PoE priority is "low". consumption -- The "low" and the power limit is "5 W": Switch(config)# power profile "IP Camera" supply enable priority low consumption 50 47.3 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 418
class2", "class3" and "class4". "Power-limit" indicates you can manually enter a value ranging from 1 to 300. The value is in value is assigned automatically by the PoE switch. "Class1" represents 4w. "Class2" the PD linked to the port with lower priority will be disconnected. By default, the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 419
. By default, the PoE status is "enable". Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernetinterface / gigabitEthernet / interface range gigabitEthernet) Privilege Requirement None. Example Enable the PoE feature for port 2: Switch(config)# interface - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 420
/ interface range gigabitEthernet) Privilege Requirement None. Example Bind the PoE profile named "IP Camera" to port 2: Switch(config)# interface gigabitEthernet 1/0/2 Switch(config-if)# power inline profile "IP Camera" 47.7 power inline time-range Description The power inline time-range command - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 421
inline Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the PoE information of the system: Switch# show power inline 47.9 show power inline configuration interface Description The show power inline configuration interface command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 422
port number. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the PoE information of all ports: Switch# show power inline information interface 47.11 show power profile Description The show power profile command is used to display the defined - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 423
Example Display the defined PoE profile: Switch# show power profile 404 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 424
have access to these commands. Example Enable the ARP Detection function globally: Switch(config)#ip arp inspection 48.2 ip arp inspection validate Description The ip arp inspection validate command is used to enable the switch to check whether the reveided ARP packet is illegal. To disable, the - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 425
an ARP packet Switch(config)#ip arp inspection validate src-mac 48.3 ip arp inspection vlan Description The ip arp inspection vlan command is used to enable the ARP Detection function on VLANs. To disable the ARP Detection function on VLANs, please use no ip arp detection vlan command. Syntax ip arp - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 426
and Power User level users have access to these commands. Example Enable the ARP Detection function on VLAN 2: Switch(config)#ip arp inspection vlan 2 48.4 ip arp inspection vlan logging Description The ip arp inspection vlan logging command is used to enable the Log function on the specific - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 427
Trusted Port: Switch(config)#interface range gigabitEthernet 1/0/2-5 Switch(config-if-range)#ip arp inspection trust 48.6 ip arp inspection limit-rate Description The ip arp inspection limit-rate command is used to configure the ARP speed of a specified port. To restore to the default speed, please - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 428
gigabitEthernet 1/0/5 Switch(config-if)#ip arp inspection limit-rate 50 48.7 ip arp inspection burst-interval Description The ip arp inspection burst-interval command is used to configure the burst interval of a specified port. To restore to the default speed, please use no ip arp inspection - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 429
to these commands. Example Restore Gigabit Ethernet port 1/0/5 to the ARP transmit status: Switch(config)#interface gigabitEthernet 1/0/5 Switch(config-if)#ip arp inspection recover 48.9 show ip arp inspection Description The show ip arp inspection command is used to display the ARP detection global - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 430
and Any Configuration Mode Privilege Requirement None. Example Display the ARP detection configuration globally: Switch(config)#show ip arp inspection 48.10 show ip arp inspection interface Description The show ip arp inspection interface command is used to display the interface configuration of ARP - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 431
Any Configuration Mode Privilege Requirement None. Example Display the ARP Inspection configuration of VLAN: Switch(config)#show ip arp inspection vlan 48.12 show ip arp inspection statistics Description The show ip arp inspection statistics command is used to display the number of the illegal ARP - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 432
used to clear the statistic of the illegal ARP packets received. Syntax clear ip arp inspection statistics Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Example Clear the statistic of the illegal ARP packets received: Switch(config)#clear ip arp inspection statistics 413 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 433
Example Enable the ND Detection function globally: Switch(config)#ipv6 nd detection 49.2 ipv6 nd detection vlan Description The ipv6 nd detection vlan command is used to enable ND Detection function on a specified VLAN. To disable ND Detection function on this VLAN, please use no ipv6 nd detection - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 434
5. Command Mode Global Configuration Mode Example Enable the Log function on VLAN 1,4,6-7: Switch(config)#ipv6 nd detection vlan 1,4,6-7 logging 49.4 ipv6 nd detection trust Description The ipv6 nd command .The specific port, such as up-linked port, routing port and LAG port, should be set 415 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 435
status. Syntax show ipv6 nd detection Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the ND Detection configuration globally: Switch(config)#show ipv6 nd detection 49.6 show ipv6 nd detection interface Description The show ipv6 nd detection interface command is used to - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 436
1/0/1 Display the configuration of all Ethernet ports: Switch(config)#show ipv6 nd detection interface 49.7 show ipv6 nd detection statistics Description The show ipv6 nd detection statistics command is used to display the ND statistics of each VLAN, including the number of forwarded and dropped ND - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 437
The show ipv6 nd detection vlan command is used to display the VLAN configuration of ND Detection. Syntax show ipv6 nd detection vlan Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the ipv6 ND Detection configuration of VLAN. Switch(config)#show ipv6 nd detection - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 438
and operation of the switch respectively for you Local Log is the system log information saved in the switch. It has two output channels, that is, it command. It will be lost when the switch is restarted. Syntax logging buffer no logging the system log buffer: Switch(config)#logging buffer 50.2 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 439
flash command is used to store the log messages in a file in the flash on the switch. To disable the log file flash function, please use no logging file flash command. This function is disabled by default. The log file flash indicates the flash sector for saving system log. The information in - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 440
to these commands. Example Enable the log file flash function: Switch(config)#logging file flash 50.4 logging file flash frequency Description the log buffer to the flash, ranging from 1 to 48 hours. By default, the synchronization process takes place every 24 hours. immediate -- The system log file - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 441
than this value will be stored to the flash. To restore to the default level, please use no logging file flash level command. Syntax logging file log messages with their severities equal or higher than 7 to the flash: Switch(config)#logging file flash level 7 50.6 logging host index Description The - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 442
idx -- The index of the log host. The switch supports 4 log hosts at most. host-ip -- The IP for the log host. level -- The severity level of smaller severity level value will be sent to the corresponding log host. By default, it is 6 indicating that the log information marked with 0-6 will be - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 443
: Switch(config)# logging console 50.8 logging console level Description The logging console level command is used to limit messages logged to the console port. System logs no higher than the set threshold level will be displayed on the console port. To restore the threshold level to default value - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 444
these commands. Example Disable logging to the terminal devices: Switch(config)# no logging monitor 50.10 logging monitor level Description be displayed on the terminal devices. To restore the threshold level to default value, please use no logging monitor level command. Syntax logging monitor level - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 445
information with severity levels between 0-7 to the terminal devices: Switch(config)# logging monitor level 7 50.11 clear logging Description The and flash. Clear the information of the two channels, by default. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 446
Privilege Requirement None. Example Display the configuration of the Local Log: Switch(config)# show logging local-config 50.13 show logging loghost Description configuration of all the log hosts by default. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. 427 - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 447
display. Display all the log information in the log buffer by default. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None log information from level 0 to level 5 in the log buffer: Switch(config)# show logging buffer level 5 50.15 show logging flash Description - TP-Link T1500-28PCT | T1500-28PCTTL-SL2428PUN V3 CLI Reference Guide Guide - Page 448
information of levels with priority not lower than the select level will display. Display all the log information in the log file by default. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the log information with the level marked 0-3 in the
CLI Reference Guide
Jetstream Smart Switches
1910012775 REV3.3.0
June 2020