TP-Link T1500-28TC TL-SL2428 T1500-28TCUN V1 CLI Reference Guide Guide
TP-Link T1500-28TC TL-SL2428 Manual
View all TP-Link T1500-28TC TL-SL2428 manuals
Add to My Manuals
Save this manual to your list of manuals |
TP-Link T1500-28TC TL-SL2428 manual content summary:
- TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 1
CLI Reference Guide T1500-28TC (TL-SL2428)/T1500-28PCT (TL-SL2428P) 1910012116 REV 2.0.0 March 2017 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 2
COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-Link Technologies Co., Ltd. Other brands and product names are trademarks or registered trademarks of their respective holders. No part of the specifications may be reproduced in any form - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 3
13 1.4.2 Special Characters 13 1.4.3 Parameter Format 14 Chapter 2 User Interface 15 2.1 enable ...15 2.2 enable-admin ...15 2.3 service password-encryption 16 2.4 enable password...17 2.5 enable secret ...18 2.6 configure ...19 2.7 exit ...19 2.8 end ...20 2.9 history - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 4
4.2 voice vlan aging ...28 4.3 voice vlan priority ...29 4.4 voice vlan mac-address 30 4.5 switchport voice vlan mode 31 4.6 switchport voice vlan security 31 4.7 show voice vlan ...32 4.8 show voice vlan oui 33 4.9 show voice vlan switchport 33 Chapter 5 Etherchannel Commands - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 5
7.10 ip http secure-server download key 57 7.11 show ip http configuration 58 7.12 show ip http secure-server 58 Chapter 8 Binding Table Commands 60 8.1 ip source binding ...60 8.2 ip dhcp snooping ...61 8.3 ip dhcp snooping vlan 62 8.4 ip dhcp snooping information option 63 8.5 ip - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 6
11.3 11.4 11.5 11.6 11.7 11.8 11.9 11.10 11.11 11.12 11.13 logging file flash ...82 logging file flash frequency 83 logging file flash level 84 logging host index...84 logging monitor ...85 logging monitor level 86 clear logging ...87 show logging local-config 87 show logging loghost 88 show - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 7
.10 15.11 15.12 15.13 15.14 15.15 15.16 15.17 15.18 15.19 15.20 15.21 system-time manual 119 system-time ntp ...119 system-time dst predefined 121 system-time dst date 122 system-time dst recurring 123 hostname ...124 location ...125 contact - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 8
15.22 15.23 15.24 15.25 15.26 15.27 15.28 15.29 15.30 15.31 show system-info ...135 show image-info ...136 show running-config 136 show startup-config 137 show system-time 137 show system-time dst 138 show system-time ntp 138 show cable-diagnostics interface gigabitEthernet 139 show cpu- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 9
17.11 show qos status ...159 Chapter 18 Port Mirror Commands 160 18.1 monitor session destination interface 160 18.2 monitor session source interface 161 18.3 show monitor session 162 Chapter 19 Port Isolation Commands 163 19.1 port isolation ...163 19.2 show port isolation interface 164 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 10
22.4 22.5 22.6 22.7 22.8 22.9 22.10 22.11 22.12 22.13 22.14 22.15 22.16 22.17 22.18 absolute ...183 periodic ...184 power holiday...186 holiday ...186 power inline consumption (interface 187 power inline priority 188 power inline supply 189 power inline profile 189 power inline time-range 190 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 11
23.23 23.24 23.25 23.26 show spanning-tree bridge 209 show spanning-tree interface 210 show spanning-tree interface-security 211 show spanning-tree mst 211 Chapter 24 IGMP Snooping Commands 213 24.1 24.2 24.3 24.4 24.5 24.6 24.7 24.8 24.9 24.10 24.11 24.12 24.13 24.14 24.15 24.16 24.17 24.18 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 12
25.2 25.3 25.4 25.5 25.6 25.7 25.8 25.9 25.10 25.11 25.12 25.13 25.14 25.15 25.16 25.17 25.18 25.19 25.20 25.21 25.22 25.23 25.24 25.25 25.26 snmp-server view 236 snmp-server group 237 snmp-server user...239 snmp-server community 240 snmp-server host...241 snmp-server engineID 243 snmp-server - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 13
26.13 26.14 26.15 26.16 show lldp interface 266 show lldp local-information interface 267 show lldp neighbor-information interface 267 show lldp traffic interface 268 Chapter 27 AAA Commands 269 27.1 27.2 27.3 27.4 27.5 27.6 27.7 27.8 27.9 27.10 27.11 27.12 27.13 27.14 27.15 27.16 27.17 27. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 14
apply to these models if not specially noted, and T1500-28PCT is taken as an example model in the example commands. Overview of this Guide Chapter 1: Using the CLI Provide information about how to use the CLI, CLI Command Modes, Security Levels and some Conventions. Chapter 2: User Interface Provide - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 15
Chapter 10: DoS Defend Command Provide information about the commands used for DoS defend and detecting the DoS attack. Chapter 11: System Log Commands Provide information about the commands used for configuring system log. Chapter 12: SSH Commands Provide information about the commands used for - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 16
Chapter 24: IGMP Snooping Commands Provide information about the commands used for configuring the IGMP Snooping (Internet Group Management Protocol Snooping). Chapter 25: SNMP Commands Provide information about the commands used for configuring the SNMP (Simple Network Management Protocol) - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 17
Chapter 1 Using the CLI 1.1 Accessing the CLI You can log on to the switch and access the CLI by logging on to the switch remotely by a Telnet or SSH connection through an Ethernet port. 1.1.1 Logon by Telnet To log on to the switch by a Telnet connection, please take the following steps: 1. Click - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 18
3. Type in the User name and Password (the factory default value for both of them are admin) and press the Enter button to enter User EXEC Mode , which is shown as Figure 1-3. Figure 1-3 Log in the Switch 4. Type in enable command to enter Privileged EXEC Mode. Figure 1-4 Enter into Priviledged EXEC - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 19
Figure 1-5 Enable SSH function Password Authentication Mode 1. Open the software to log on to the interface of PuTTY. Enter the IP address of the switch into Host Name field; keep the default value 22 in the Port field; select SSH as the Connection type. Figure 1-6 SSH Connection Config 6 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 20
2. Click the Open button in the above figure to log on to the switch. Enter the login user name and password to log on the switch, and then enter enable to enter Privileged EXEC Mode, so you can continue to configure the switch. Figure 1-7 Log on the Switch Key Authentication Mode 1. Select the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 21
2. After the key is successfully generated, please save the public key and private key to a TFTP server. Figure 1-9 Save the Generated Key 3. Log on to the switch by Telnet and download the public key file from the TFTP server to the switch, as the following figure shows: Figure 1-10 Download the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 22
Note: 1. The key type should accord with the type of the key file. 2. The SSH key downloading can not be interrupted. 4. After the public key is downloaded, please log on to the interface of PuTTY and enter the IP address for login. Figure 1-11 SSH Connection Config 9 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 23
5. Click Browse to download the private key file to SSH client software and click Open. Figure 1-12 Download the Private Key 6. After successful authentication, please enter the login user name. If you log on to the switch without entering password, it indicates that the key has been successfully - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 24
Interface Configuration Mode can also be divided into Interface Ethernet, Interface link-aggregation and some other modes, which is shown as the following diagram. The following table gives detailed information about the Accessing path, Prompt of each mode and how to exit the current mode and access - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 25
Mode Accessing Path Interface Configuration Mode Use the interface vlan vlan-id command to enter VLAN Interface mode from Global Configuration mode. Use the interface loopback id command to enter Loopback Interface mode from Global Configuration mode. VLAN Configuration Mode Use the vlan vlan- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 26
, you are required to enter it to access Privileged EXEC mode. 1.4 Conventions 1.4.1 Format Conventions The following conventions are used in this Guide: Items in square brackets [ ] are optional Items in braces { } are required Alternative items are grouped in braces and separated by vertical - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 27
These six characters can not be input. If a blank is contained in a character string, single or double quotation marks should be used, for example 'hello world', "hello world", and the words in the quotation marks will be identified as a string. Otherwise, the words will be identified as - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 28
Chapter 2 User Interface 2.1 enable Description The enable command is used to access Privileged EXEC Mode from User EXEC Mode. Syntax enable Command Mode User EXEC Mode Privilege Requirement None. Example If you have set the password to access Privileged EXEC Mode from User EXEC Mode: T1500-28PCT> - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 29
pre-defined evaluation password 123 to gain the administrative privilege. T1500-28PCT#enable-admin Password:123 T1500-28PCT# 2.3 service password-encryption Description The service password-encryption command is used to encrypt the password when the password is defined or when the configuration is - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 30
level users have access to these commands. User Guidelines If the password you configured here is unencrypted and the global encryption function is enabled in service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. 17 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 31
Example Set the super password as "admin" and unencrypted to access Privileged EXEC Mode from User EXEC Mode: T1500-28PCT(config)#enable password 0 admin 2.5 enable secret Description The enable secret command is used to set a secret password, which is using an MD5 encryption algorithm, for users to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 32
User Guidelines If both the enable password and enable secret are defined, you must enter the password set in enable secret. Example Set the secret password as "admin" and unencrypted to access Privileged EXEC Mode from User EXEC Mode. The password will be displayed in the encrypted form. T1500- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 33
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Return to Global Configuration Mode from Interface Configuration Mode, and then return to Privileged EXEC Mode: T1500-28PCT(config-if)# exit T1500-28PCT(config)#exit T1500-28PCT# 2.8 end Description The - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 34
Command Mode Privileged EXEC Mode and any Configuration Mode Privilege Requirement None. Example Show the commands you have entered in the current mode: T1500-28PCT (config)# history 1 history 2.10 history clear Description The history clear command is used to clear the commands you have entered in - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 35
Chapter 3 IEEE 802.1Q VLAN Commands VLAN (Virtual Local Area Network) technology is developed for the switch to divide the LAN into multiple logical LANs flexibly. Hosts in the same VLAN can communicate with each other, regardless of their physical locations. VLAN can enhance performance by - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 36
3.2 interface vlan Description The interface vlan command is used to create VLAN Interface and enter Interface VLAN Mode. To delete VLAN Interface, please use no interface vlan command. Syntax interface vlan vlan-id no interface vlan vlan-id Parameter vlan-id -- Specify IEEE 802.1Q VLAN ID, ranging - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 37
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the name of VLAN 2 as "group1": T1500-28PCT(config)# vlan 2 T1500-28PCT(config-vlan)# name group1 3.4 switchport general allowed vlan Description The switchport general allowed vlan - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 38
T1500-28PCT(config-if)# switchport general allowed vlan 2 tagged 3.5 switchport pvid Description The switchport pvid command is used to configure the PVID for the switch ports. Syntax switchport pvid vlan-id Parameter vlan-id -- VLAN ID, ranging from 1 to 4094. Command Mode Interface Configuration - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 39
Privilege Requirement None. Example Display the summarized information of IEEE 802.1Q VLAN: T1500-28PCT(config)# show vlan summary 3.7 show vlan brief Description The show vlan brief command is used to display the brief information of IEEE 802.1Q VLAN. Syntax show vlan brief Command Mode Privileged - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 40
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of vlan 5: T1500-28PCT(config)# show vlan id 5 3.9 show interface switchport Description The show interface switchport command is used to display the IEEE 802.1Q VLAN - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 41
Chapter 4 Voice VLAN Commands Voice VLANs are configured specially for voice data stream. By configuring Voice VLANs and adding the ports with voice devices attached to voice VLANs, you can perform QoS-related configuration for voice data, ensuring the transmission priority of voice data stream and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 42
Syntax voice vlan aging time no voice vlan aging Parameter time -- Aging time (in minutes) to be set for the Voice VLAN. It ranges from 1 to 43200 minutes and the default value is 1440 minutes. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 43
Example Configure the priority of the Voice VLAN as 5: T1500-28PCT(config)# voice vlan priority 5 4.4 voice vlan mac-address Description The voice vlan mac-address command is used to create Voice VLAN OUI. To delete the specified Voice VLAN OUI, please use no voice vlan mac-address command. Syntax - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 44
is used to configure the Voice VLAN mode for the Ethernet port. Syntax switchport voice vlan mode { manual | auto } Parameter manual | auto -- Port mode. Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 45
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 46
4.8 show voice vlan oui Description The show voice vlan oui command is used to display the configuration information of Voice VLAN OUI. Syntax show voice vlan oui Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 47
Example Display the Voice VLAN configuration information of all ports and LAGs: T1500-28PCT(config)# show voice vlan switchport Display the Voice VLAN configuration information of port 1/0/2: T1500-28PCT(config)# show voice vlan switchport fastEthernet 1/0/2 34 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 48
Chapter 5 Etherchannel Commands Etherchannel Commands are used to configure LAG and LACP function. LAG (Link Aggregation Group) is to combine a number of ports together to make a single high-bandwidth data path, which can highly extend the bandwidth. The bandwidth of the LAG is the sum of bandwidth - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 49
Example Add ports 2-4 to EtherChannel Group 1 and enable the static LAG: T1500-28PCT(config)# interface range fastEthernet 1/0/2-4 T1500-28PCT(config-if-range)# channel-group 1 mode on 5.2 port-channel load-balance Description The port-channel load-balance command is used to configure the Aggregate - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 50
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the Aggregate Arithmetic for LAG as "src-dst-ip": T1500-28PCT(config)# port-channel load-balance src-dst-ip 5.3 lacp system-priority - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 51
5.4 lacp port-priority Description The lacp port-priority command is used to configure the LACP port priority for specified ports. To return to the default configurations, please use no lacp port-priority command. Syntax lacp port-priority pri no lacp port-priority Parameter pri -- The port priority - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 52
Syntax show etherchannel [ channel-group-num ] { detail | summary } Parameter channel-group-num -- The EtherChannel Group number, ranging from 1 to 6. By default, it is empty, and will display the information of all EtherChannel Groups. detail -- The detailed information of EtherChannel. summary -- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 53
5.7 show lacp Description The show lacp command is used to display the LACP information for a specified EtherChannel Group. Syntax show lacp [ channel-group-num ] { internal | neighbor } Parameter channel-group-num -- The EtherChannel Group number, ranging from 1 to 6. By default, it is empty, and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 54
Example Display the LACP system priority: T1500-28PCT(config)# show lacp sys-id 41 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 55
Chapter 6 User Management Commands User Manage Commands are used to manage the user's logging information by Web, Telnet or SSH, so as to protect the settings of the switch from being randomly changed. 6.1 user name (password) Description The user name command is used to add a new user or modify the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 56
have access to these commands. User Guidelines If the password you configured here is unencrypted and the global encryption function is enabled in service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. Example Add and enable a new admin - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 57
the the settings of different functions. "user" means that you can only view some of the the settings of different functions without the right to edit or modify. It is "admin" by default. 0 -- Specify the encryption type. 0 indicates that an unencrypted password will follow. By default, the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 58
Syntax user access-control ip-based { ip-addr ip-mask } [ snmp ] [ telnet ] [ ssh ] [ http ] [ https ] [ ping ] [ all ] no user access-control [ ip-based index id ] Parameter ip-addr -- The source IP address. Only the users within the IP-range you set here are allowed to access the switch. ip-mask - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 59
Parameter mac-addr -- The source MAC address. Only the user with this MAC address is allowed to access the switch. [ snmp ] [ telnet ] [ ssh ] [ http ] [ https ] [ ping ] [ all ] -- Specify the access interface. These interfaces are enabled by default. Command Mode Global Configuration Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 60
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure that only the users connected to ports 2-6 are allowed to access the switch: T1500-28PCT(config)# user access-control port-based interface fastEthernet 1/0/2-6 6.6 telnet Description The telnet - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 61
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the information of the current users: T1500-28PCT(config)# show user account-list 6.8 show user configuration Description The show user - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 62
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display whether the Telnet function is enabled: T1500-28PCT(config)# show telnet-status 49 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 63
Chapter 7 HTTP and HTTPS Commands With the help of HTTP (HyperText Transfer Protocol) or HTTPS (Hyper Text Transfer Protocol over Secure Socket Layer), you can manage the switch through a standard browser. HTTP is the protocol to exchange or transfer hypertext. SSL (Secure Sockets Layer), a security - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 64
7.2 ip http max-users Description The ip http max-users command is used to configure the maximum number of users that are allowed to connect to the HTTP server. To cancel this limitation, please use no ip http max-users command. Syntax ip http max-users admin-num operator-num power-user-num user-num - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 65
7.3 ip http session timeout Description The ip http session timeout command is used to configure the connection timeout of the HTTP server. To restore to the default timeout time, please use no ip http session timeout command. Syntax ip http session timeout minutes no ip http session timeout - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 66
the SSL protocol version. To restore to the default SSL version, please use no ip http secure-protocol command. By default, the switch supports SSLv3 and TLSv1. Syntax ip http secure-protocol { [ ssl3 ] [ tls1 ] } no ip http secure-protocol Parameter ssl3 -- The SSL 3.0 protocol. tls1 -- The TLS - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 67
-sha ] [ des-cbc-sha ] -- Specify the encryption algorithm and the digest algorithm to use on an SSL connection. By default, the switch supports all these ciphersuites. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 68
Syntax ip http secure-max-users admin-num operator-num power-user-num user-num no ip http secure-max-users Parameter admin-num -- The maximum number of the users logging on to the HTTPS server as Admin, ranging from 1 to 16. The total number of users should be no more than 16. operator-num -- The - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 69
from 1 to 25 characters. The Certificate must be BASE64 encoded. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. Command Mode Global Configuration Mode 56 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 70
to 25 characters. The Key must be BASE64 encoded. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 71
Example Download an SSL key named ssl-key from TFTP server with the IP address of 192.168.0.146: T1500-28PCT(config)# ip http secure-server download key ssl-key ip-address 192.168.0.146 Download an SSL key named ssl-key from TFTP server with the IP address of fe80::1234 T1500-28PCT(config)# ip http - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 72
Syntax show ip http secure-server Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of SSL: T1500-28PCT(config)# show ip http secure-server 59 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 73
source binding Description The ip source binding command is used to bind the IP address, MAC address, VLAN ID and the Port number together manually. You can manually bind the IP address, MAC address, VLAN ID and the Port number together in the condition that you have got the related information of - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 74
these commands. Example Bind an ACL entry with the IP 192.168.0.1, MAC 00:00:00:00:00:01, VLAN ID 2 and the Port number 5 manually. And then enable the entry for the ARP detection: T1500-28PCT(config)#ip source binding host1 192.168.0.1 00:00:00:00:00:01 vlan - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 75
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCP Snooping function globally: T1500-28PCT(config)#ip dhcp snooping 8.3 ip dhcp snooping vlan Description The ip dhcp snooping vlan command is used to enable DHCP Snooping - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 76
8.4 ip dhcp snooping information option Description The ip dhcp snooping information option command is used to enable the Option 82 function of DHCP Snooping. To disable the Option 82 function, please use no ip dhcp snooping information option command. Syntax ip dhcp snooping information option no - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 77
Parameter strategy -- The operations for Option 82 field of the DHCP request packets from the Host, including three types: keep: Indicates to keep the Option 82 field of the packets. It is the default option; replace: Indicates to replace the Option 82 field of the packets with the switch defined - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 78
Parameter string -- Enter the sub-option Remote ID, which contains 64 characters at most. Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 79
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable and configure the customized sub-option Circuit ID for the Option 82 as "tplink" on port 1/0/1: T1500-28PCT(config)#interface fastEthernet 1/0/1 T1500-28PCT(config-if)#ip dhcp snooping - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 80
8.9 ip dhcp snooping mac-verify Description The ip dhcp snooping mac-verify command is used to enable the MAC Verify feature. To disable the MAC Verify feature, please use no ip dhcp snooping mac-verify command. There are two fields of the DHCP packet containing the MAC address of the Host. The MAC - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 81
Parameter value -- The value of Flow Control. The options are 5/10/15/20/25/30 (packet/second). The default value is 0, which stands for "disable". Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 82
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 83
8.13 show ip dhcp snooping Description The show ip dhcp snooping command is used to display the running status of DHCP Snooping. Syntax show ip dhcp snooping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the running status of DHCP Snooping: - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 84
Example Display the DHCP Snooping configuration of all Ethernet ports and LAGs: T1500-28PCT#show ip dhcp snooping interface Display the DHCP Snooping configuration of port 1/0/5: T1500-28PCT#show ip dhcp snooping interface fastEthernet 1/0/5 8.15 show ip dhcp snooping information interface - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 85
Chapter 9 ARP Inspection Commands ARP (Address Resolution Protocol) Detect function is to protect the switch from the ARP cheating, such as the Network Gateway Spoofing and Man-In-The-Middle Attack, etc. 9.1 ip arp inspection(global) Description The ip arp inspection command is used to enable the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 86
Syntax ip arp inspection trust no ip arp inspection trust Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 87
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the arp defend function for ports 1/0/2-6: T1500-28PCT(config)#interface range fastEthernet 1/0/2-6 T1500-28PCT(config-if-range)#ip arp inspection 9.4 ip arp inspection limit-rate - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 88
T1500-28PCT(config-if)#ip arp inspection limit-rate 50 9.5 ip arp inspection recover Description The ip arp inspection recover command is used to restore a port to the ARP transmit status from the ARP filter status. Syntax ip arp inspection recover Command Mode Interface Configuration Mode ( - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 89
Privilege Requirement None. Example Display the ARP detection configuration globally: T1500-28PCT(config)#show ip arp inspection 9.7 show ip arp inspection interface Description The show ip arp inspection interface command is used to display the interface configuration of ARP detection. Syntax show - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 90
9.8 show ip arp inspection statistics Description The show ip arp inspection statistics command is used to display the number of the illegal ARP packets received. Syntax show ip arp inspection statistics Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 91
) Attack is to occupy the network bandwidth maliciously by the network attackers or the evil programs sending a lot of service requests to the Host. With the DoS Defend enabled, the switch can analyze the specific field of the received packets and provide the defend measures - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 92
Syntax ip dos-prevent type { land | scan-synfin | xma-scan | null-scan | port-less-1024 | blat | ping-flood | syn-flood | win-nuke | smurf | ping-of-death } no ip dos-prevent type { land | scan-synfin | xma-scan | null-scan | port-less-1024 | blat | ping-flood | syn-flood | win-nuke | smurf | ping- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 93
10.3 show ip dos-prevent Description The show ip dos-prevent command is used to display the DoS information of the detected DoS attack, including enable/disable status, the DoS Defend Type, the count of the attack, etc. Syntax show ip dos-prevent Command Mode Privileged EXEC Mode and Any - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 94
Chapter 11 System Log Commands The log information will record the settings and operation of the switch respectively for you to monitor operation status and diagnose malfunction. 11.1 logging buffer Description The logging buffer command is used to store the system log messages to an internal buffer - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 95
Syntax logging buffer level level no logging buffer level Parameter level -- Severity level of the log information output to each channel. There are 8 severity levels marked with values 0-7. The smaller value has the higher priority. Only the log with the same or smaller severity level value will be - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 96
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the log file flash function: T1500-28PCT(config)#logging file flash 11.4 logging file flash frequency Description The logging file flash frequency command is used to specify the frequency to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 97
11.5 logging file flash level Description The logging file flash level command is used to specify the system log message severity level. Messages with a severity level equal to or higher than this value will be stored to the flash. To restore to the default level, please use no logging file flash - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 98
Syntax logging host index idx host-ip level no logging host index idx Parameter idx -- The index of the log host. The switch supports 4 log hosts at most. host-ip -- The IP for the log host. level -- The severity level of the log information sent to each log host. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 99
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable logging to the terminal devices: T1500-28PCT(config)# no logging monitor 11.8 logging monitor level Description The logging monitor level command is used to limit messages logged to the terminal - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 100
11.9 clear logging Description The clear logging command is used to clear the information in the log buffer and log file. Syntax clear logging [ buffer | flash ] Parameter buffer | flash -The output channels: buffer and flash. Clear the information of the two channels, by default. Command Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 101
T1500-28PCT(config)# show logging local-config 11.11 show logging loghost Description The show logging loghost command is used to display the configuration of the log host. Syntax show logging loghost [ index ] Parameter index --The index of the log host whose configuration will be displayed, - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 102
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the log information from level 0 to level 5 in the log buffer: T1500-28PCT(config)# show logging buffer level 5 11.13 show logging flash Description The show logging flash command is used to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 103
Chapter 12 SSH Commands SSH (Security Shell) can provide the unsecured remote management with security and powerful authentication to ensure the security of the management information. 12.1 ip ssh server Description The ip ssh server command is used to enable SSH function. To disable the SSH - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 104
Parameter v1 | v2 -- The SSH protocol version to be enabled. They represent SSH v1 and SSH v2 respectively. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable SSH v2: T1500-28PCT(config)# ip ssh - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 105
12.4 ip ssh timeout Description The ip ssh timeout command is used to specify the idle-timeout time of SSH. To restore to the factory defaults, please use no ip ssh timeout command. Syntax ip ssh timeout value no ip ssh timeout Parameter value -- The Idle-timeout time. During this period, the system - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 106
must be in the range of 512 to 3072 bits. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 107
Download an SSH-1 type key file named ssh-key from TFTP server with the IP address fe80::1234: T1500-28PCT(config)# ip ssh download v1 ssh-key ip-address fe80::1234 12.7 remove public-key Description The remove public-key command is used to remove the SSH public key from the switch. Syntax remove - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 108
LAN. Authenticator: controls the physical access to the network based on the authentication status of the supplicant. It is usually an 802.1X-supported network device, such as this TP-Link switch. It acts as an intermediary (proxy) between the supplicant and the authentication server, requesting - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 109
T1500-28PCT(config)#dot1x system-auth-control 13.2 dot1x handshake Description The dot1x handshake command is used to enable the handshake feature. The handshake feature is used to detect the connection status between the TP-Link 802.1x supplicant and the switch. Please disable the handshake feature - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 110
Parameter pap | eap --Authentication Methods. pap: EAP termination mode. IEEE 802.1X authentication system uses extensible authentication protocol (EAP) to exchange information between the switch and the client. The EAP packets are terminated at the switch and repackaged in the Password - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 111
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the enable the IEEE 802.1X accounting function globally: T1500-28PCT(config)#dot1x accounting 13.5 dot1x guest-vlan(global) Description The dot1x guest-vlan command is used to enable - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 112
13.6 dot1x quiet-period Description The dot1x quiet-period command is used to enable the quiet-period function. To disable the function, please use no dot1x quiet-period command. Syntax dot1x quiet-period [ time ] no dot1x quiet-period Parameter time -- The length of the quiet-period time. If one - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 113
no dot1x timeout supplicant-timeout Parameter supplicant-timeout time --The maximum time for the switch to wait for the response from supplicant before resending a request to the supplicant., ranging from 1 to 9 in second. By default, it is 3 seconds. Command Mode Global Configuration Mode Privilege - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 114
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the maximum transfer times of the repeated authentication request as 5: T1500-28PCT(config)#dot1x max-reauth-req 5 13.9 dot1x Description The dot1x command is used to enable the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 115
13.10 dot1x guest-vlan(interface) Description The dot1x guest-vlan command is used to enable the guest VLAN function for a specified port. To disable the Guest VLAN function for a specified port, please use no dot1x guest-vlan command. Please ensure that the Control Type of the corresponding port is - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 116
Parameter auto | authorized-force | unauthorized-force -- The Control Mode for the port. auto: In this mode, the port will normally work only after passing the 802.1X Authentication. authorized-force: In this mode, the port can work normally without passing the 802.1X Authentication. unauthorized- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 117
mac-based: Any client connected to the port should pass the 802.1X authentication for access. port-based: All the clients connected to the port can access the network on the condition that any one of the clients has passed the 802.1X Authentication. Command Mode Interface Configuration Mode ( - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 118
13.14 show dot1x interface Description The show dot1x interface command is used to display all ports or the specified port's configuration information of 802.1X. Syntax show dot1x interface [ gigabitEthernet port ] Parameter port -- The Ethernet port number. If not specified, the information of all - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 119
MAC address entry. To remove the corresponding entry, please use no mac address-table static command. The static address can be added or removed manually, independent of the aging time. In the stable networks, the static MAC address entries can facilitate the switch to reduce broadcast packets and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 120
address-table filtering command. The filtering address function is to forbid the undesired package to be forwarded. The filtering address can be added or removed manually, independent of the aging time. Syntax mac address-table filtering mac-addr vid vid 107 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 121
no mac address-table filtering {[ mac-addr ] [ vid vid ]} Parameter mac-addr -- The MAC address to be filtered. vid -- The corresponding VLAN ID of the MAC address. It ranges from 1 to 4094. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 122
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the global MAC address notification and table full notification, specify the notification sending interval as 2 seconds: T1500-28PCT(config)# mac - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 123
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the learn-mode-change - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 124
out of the influence of the aging time and can only be deleted manually. The learned entries will be cleared after the switch is rebooted. When be out of the influence of the aging time and can only be deleted manually too. However, the learned entries will be saved even the switch is rebooted. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 125
14.7 mac address-table security Description The mac address-table security command is used to configure security of the MAC address table in a specified VLAN. Syntax mac address-table security vid vid max-learn number { forward | drop | disable } Parameter vid -- Speicify the VLAN ID to configure - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 126
Syntax show mac address-table [ dynamic | static | filtering ] Parameter dynamic | static | filtering -- The type of your desired entry. By default all the entries are displayed. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 127
14.10 show mac address-table aging-time Description The show mac address-table aging-time command is used to display the Aging Time of the MAC address. Syntax show mac address-table aging-time Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 128
Display the security configuration of port 1/0/1: T1500-28PCT(config)# show mac address-table max-mac-count interface fastEthernet 1/0/1 14.12 show mac address-table interface Description The show mac address-table interface command is used to display the address configuration of the specified port/ - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 129
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the total MAC entry information in different VLANs: T1500-28PCT(config)# show mac address-table count 14.14 show mac address-table address Description The show mac address-table address command - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 130
14.15 show mac address-table vlan Description The show mac address-table vlan command is used to display the MAC address configuration of the specified vlan. Syntax show mac address-table vlan vid Parameter vid --The specified VLAN id. Command Mode Privileged EXEC Mode and Any Configuration Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 131
T1500-28PCT(config)# show mac address-table notification all 14.17 show mac address-table security Description The show mac address-table vlan command is used to display the MAC address security configuration of the specified vlan. Syntax show mac address-table security [ vid vid ] Parameter vid -- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 132
switch, upgrade the switch system and other operations. 15.1 system-time manual Description The system-time manual command is used to configure the system time manually. Syntax system-time manual time Parameter time -- Set the date and time manually, MM/DD/YYYY-HH:MM:SS. The valid value of the year - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 133
The detailed information that each time-zone means are displayed as follow: UTC-12:00 -- TimeZone for International Date Line West. UTC-11:00 -- TimeZone for Coordinated Universal Time-11. UTC-10:00 -- TimeZone for Hawaii. UTC-09:00 -- TimeZone for Alaska. UTC-08:00 -- TimeZone for Pacific Time - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 134
backup-ntp-server -- The IP address for the Secondary NTP Server. fetching-rate -- Specify the rate fetching time from NTP server. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the system time mode as - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 135
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the daylight saving time as USA standard: T1500-28PCT(config)#system-time dst predefined USA 15.4 system-time dst date Description The system-time dst date command is used to configure the one- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 136
Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the daylight saving time from zero clock, Apr 1st to zero clock Oct 1st and the offset is 30 minutes in 2015: T1500-28PCT(config)# system-time dst date - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 137
etime -- The end moment of the daylight saving time, HH:MM. offset -- The number of minutes to add during the daylight saving time. It is 60 minutes by default. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 138
15.7 location Description The location command is used to configure the system location. To clear the system location information, please use no location command. Syntax location [ location ] no location Parameter location -- Device Location. It consists of 32 characters at most. It is "SHENZHEN" by - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 139
Description This ip address command is used to configure the IP address, IP subnet mask and default fateway for the specified interface manually. The interface type includes: routed port, port-channel interface, loopback interface and VLAN interface. Syntax ip address { ip-addr } { mask } [ gateway - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 140
15.10 ip management-vlan Description This ip management-vlan command is used to specify the management vlan. Only the user in the specified vlan can access to the switch Syntax ip management-vlan vlan no management-vlan vlan Parameter vlan -- The ID of the management VLAN. Command Mode Global - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 141
bootp -- Specify the Layer 3 interface to obtain IP address from the BOOTP Server. Command Mode Interface Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Disable the IP address obtaining function on the VLAN interface 2: - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 142
Syntax reboot Command Mode Privileged EXEC Mode Privilege Requirement Only Admin level users have access to these commands. Example Reboot the switch: T1500-28PCT# reboot 15.14 copy running-config startup-config Description The copy running-config startup-config command is used to save the current - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 143
tftp startup-config ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. name -- Specify the name for the configuration file which would be downloaded. Command Mode Privileged EXEC Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 144
Privilege Requirement Only Admin level users have access to these commands. Example Download the configuration file named as config.cfg to the switch from TFTP server with the IP 192.168.0.148: T1500-28PCT# copy tftp startup-config ip-address 192.168.0.148 filename config Download the configuration - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 145
Syntax firmware upgrade ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. name -- Specify the name for the firmware file. Command Mode Privileged EXEC Mode Privilege Requirement Only - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 146
. ip_addr -- The IP address of the destination node for ping test. If the parameter ip/ipv6 is not selected, both IPv4 and IPv6 addresses are supported, for example 192.168.0.100 or fe80::1234. -n count -- The amount of times to send test data during Ping testing. It ranges from 1 to 10 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 147
should be IPv6. ip_addr -- The IP address of the destination device. If the parameter ip/ipv6 is not selected, both IPv4 and IPv6 addresses are supported, for example 192.168.0.100 or fe80::1234. maxHops -- The maximum number of the route hops the test data can pass though. It ranges from - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 148
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Test the connectivity between the switch and the network device with the IP 192.168.0.131. If the destination device has not been found after 20 maxHops, the connection between the switch and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 149
15.23 show image-info Description The show image-info command is used to display the information of image files in the system. Syntax show image-info Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 150
15.25 show startup-config Description The show startup-config command is used to display the current configuration saved in the switch. These configuration settings will not be lost the next time you reboot the switch. Syntax show startup-config Command Mode Privileged EXEC Mode and Any - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 151
15.27 show system-time dst Description The show system-time dst command is used to display the DST information of the switch. Syntax show system-time dst Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DST information of the switch T1500- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 152
of the connected Ethernet Port., which facilitates you to check the connection status of the cable connected to the switch, locate and diagnose the trouble spot of the network. Syntax show cable-diagnostics interface gigabitEthernet port Parameter port -- The number of the port which is selected for - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 153
Example Display the CPU utilization information of the switch: T1500-28PCT# show cpu-utilization 15.31 show memory-utilization Description The show memory-utilization command is used to display the current system's memory utilization in the last 5 seconds/1minute/5minutes. Syntax show memory- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 154
Chapter 16 Ethernet Configuration Commands Ethernet Configuration Commands can be used to configure the Bandwidth Control, Negotiation Mode and Storm Control for Ethernet ports. 16.1 interface gigabitEthernet Description The interface gigabitEthernet command is used to enter the Interface - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 155
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. User Guidelines Command in the Interface Range Configuration Mode is executed independently on all ports in the range. It does not affect the execution on the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 156
T1500-28PCT(config-if)# description Port_5 16.4 shutdown Description The shutdown command is used to disable an Ethernet port. To enable this port again, please use no shutdown command. Syntax shutdown no shutdown Command Mode Interface Configuration Mode (interface fastEthernet / interface range - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 157
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin and Operator level users have access to these - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 158
16.7 jumbo-size Description The jumbo-size command is used to configure the size of the jumbo frame which is allowed to pass through the switch. Syntax jumbo-size size Parameter size -- Specify the global jumbo frame size, ranging from 1518 to 9216 bytes. By default it's 1518 bytes. Command Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 159
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin and Operator level users have access to these - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 160
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the broadcast storm control rate as 1000 kbps on port 1/0/5: T1500-28PCT(config)#interface fastEthernet 1/0/5 T1500-28PCT(config-if)# storm-control broadcast kbps 1000 16.10 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 161
16.11 clear counters Description The clear counters command is used to clear the statistics information of all the Ethernet ports and LAGs. Syntax clear counters clear counters interface [ gigabitEthernet port ] [ port-channel lagid ] Parameter port -- The Ethernet port number. lagid -- The ID of - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 162
Example Display the connection status of all ports and LAGs: T1500-28PCT(config)# show interface status Display the connection status of port 1/0/1: T1500-28PCT(config)# show interface status fastEthernet 1/0/1 16.13 show interface counters Description The show interface counters command is used to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 163
Parameter port -- The Ethernet port number. lagid -- The ID of the LAG. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configurations of all Ethernet ports and LAGs: T1500-28PCT(config)# show interface configuration Display the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 164
16.16 show bandwidth Description The show bandwidth command is used to display the bandwidth-limit information of Ethernet ports. Syntax show bandwidth interface [ fastEthernet port-list | gigabitEthernet port-list ] [ port-channel lagid-list ] Parameter port-list --The list of Ethernet ports. lagid - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 165
function is used to optimize the network performance. It provides you with network service experience of a better quality. 17.1 qos Description The qos command is used to configure the priority level of packets from the port. To return to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 166
Syntax qos cos no qos cos Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. User Guidelines IEEE 802.1P gives the Pri field in IEEE 802.1Q tag a recommended definition. When the mapping relation between IEEE - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 167
datagram will be classified into the egress queue based on the mapping relation between DSCP priority and CoS value. Example Enable the mapping relation between DSCP Priority and CoS value: T1500-28PCT(config)# qos dscp 17.4 qos queue cos-map Description The qos queue cos-map command is used to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 168
Example Map CoS 5 to TC 2: T1500-28PCT(config)# qos queue cos-map 5 2 17.5 qos queue dscp-map Description The qos queue dscp-map command is used to configure the mapping relation between DSCP Priority and the TC queue. To return to the default configuration, please use no qos queue dscp-map command. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 169
T1500-28PCT(config)# qos queue dscp-map 10-12 2 17.6 qos queue mode Description The qos queue mode command is used to configure the Schedule Mode. To return to the default Equal-Mode, please use no qos queue mode command. When the network is congested, the program that many packets complete for - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 170
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the Schedule Mode as Weight Round Robin Mode: T1500-28PCT(config)# qos queue mode wrr 17.7 show qos interface Description The show qos interface command is used to display the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 171
Syntax show qos cos-map Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of IEEE 802.1P Priority and the mapping relation between cos-id and tc-id: T1500-28PCT# show qos cos-map 17.9 show qos dscp-map Description The show qos - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 172
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the schedule rule of the egress queues: T1500-28PCT# show qos queue mode 17.11 show qos status Description The show qos status command is used to display the status of IEEE 802.1P priority and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 173
, the monitoring port is connected to data diagnose device, which is used to analyze the monitored packets for monitoring and troubleshooting the network. 18.1 monitor session destination interface Description The monitor session destination interface command is used to configure the monitoring - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 174
Delete the monitoring port 1/0/2 from monitor session 1: T1500-28PCT(config)# no monitor session 1 destination interface fastEthernet 1/0/2 Delete the monitor session 1: T1500-28PCT(config)# no monitor session 1 18.2 monitor session source interface Description The monitor session source interface - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 175
2. Monitored ports number is not limited, but it can't be the monitoring port at the same time. 3. Whether the monitoring port and monitored ports are in the same VLAN or not is not demanded strictly. 4. The monitoring port cannot be link-aggregation member. Example Create monitor session 1, then - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 176
Chapter 19 Port Isolation Commands Port Isolation provides a method of restricting traffic flow to improve the network security by forbidding the port to forward packets to the ports that are not on its forwarding port list. 19.1 port isolation Description The port isolation command is used to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 177
T1500-28PCT(config-if)# no port isolation 19.2 show port isolation interface Description The show port isolation interface command is used to display the forward port list of a port/LAG. Syntax show port isolation interface [ gigabitEthernet port | port-channel lagid ] Parameter port -- The number - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 178
Chapter 20 Loopback Detection Commands With loopback detection feature enabled, the switch can detect loops using loopback detection packets. When a loop is detected, the switch will display an alert or further block the corresponding port according to the configuration. 20.1 loopback-detection( - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 179
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the interval-time as 50 seconds: T1500-28PCT(config)# loopback-detection interval 50 20.3 loopback-detection recovery-time Description The - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 180
by which the switch copes with the detected loops. Syntax loopback-detection config [ process-mode { alert | port-based }] [ recovery-mode { auto | manual }] Parameter process-mode -- The mode how the switch processes the detected loops. Alert: When a loop is detected, display an alert. Port based - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 181
for port 1/0/2: T1500-28PCT(config)#interface fastEthernet 1/0/2 T1500-28PCT(config-if)# loopback-detection config process-mode port-based recovery-mode manual 20.6 loopback-detection recover Description The loopback-detection recover command is used to remove the block status of selected ports/LAGs - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 182
T1500-28PCT(config-if)# loopback-detection recover 20.7 show loopback-detection global Description The show loopback-detection global command is used to display the global configuration of loopback detection function such as loopback detection global status, loopback detection interval and loopback - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 183
Example Display the configuration of loopback detection function and the status of all ports and LAGs: T1500-28PCT# show loopback-detection interface Display the configuration of loopback detection function and the status of port 1/0/5: T1500-28PCT# show loopback-detection interface fastEthernet - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 184
Chapter 21 ACL Commands 21.1 access-list create Description The access-list create command is used to create standard-IP ACL and extend-IP ACL. Syntax access-list create access-list-num Parameter access-list-num -- ACL ID, ranging from 500 to 2499. The ID range of Standard-IP ACL ranges is 500-1499 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 185
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create a MAC ACL whose ID is 23: T1500-28PCT(config)# mac access-list 23 21.3 access-list standard Description The access-list standard command is used - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 186
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create a Standard-IP ACL whose ID is 520, and add Rule 10 for it. In the rule, the source IP address is 192.168.0.100, the source IP address mask is 255.255.255.0, and the packets match this - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 187
d-port -- The destination port number. protocol -- Configure the value of the matching protocol. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create an Extended-IP ACL whose ID is 2220, and add - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 188
Command Mode Mac Access-list Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create a MAC ACL whose ID is 20, and add Rule 10 for it. In the rule, the source MAC address is 00:01:3F:48:16:23, the source MAC address mask - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 189
21.7 access-list policy action Description The access-list policy action command is used to add ACLs for the policy. To delete the corresponding actions, please use no access-list policy action command. Syntax access-list policy action policy-name acl-id no access-list policy action policy-name acl- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 190
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Bind ACL 100 to port 1/0/2: T1500-28PCT(config)#interface fastEthernet 1/0/2 T1500-28PCT(config-if)# access-list bind acl 100 21.9 access-list bind acl(vlan) Description The access-list bind - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 191
Syntax access-list bind policy-name no access-list bind policy-name Parameter policy-name -- The name of the policy desired to bind. Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 192
T1500-28PCT(config)# interface vlan 2 T1500-28PCT(config-if)# access-list bind policy1 21.12 show access-list Description The show access-list command is used to display configuration of ACL. Syntax show access-list acl-id Parameter acl-id -- The ID of the ACL selected to display the configuration. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 193
T1500-28PCT(config)# show access-list policy policy1 21.14 show access-list bind Description The show access-list bind command is used to display the configuration of Policy bind. Syntax show access-list bind Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 194
Chapter 22 PoE Commands Note: Only T1500-28PCT supports PoE function. PoE (Power over Ethernet) technology describes a system to transmit electrical power along with data to remote devices over standard twisted-pair cable in - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 195
the port in the profile can supply. There are six options: "power-limit", "auto", "class1", "class2", "class3" and "class4". "power-limit" indicates you can manually enter a value. It ranges from 1 to 300. The value is in the unit of 0.1 watt. For instance, if you want to configure the max power - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 196
T1500-28PCT(config)# power profile "IP Camera" supply enable priority low consumption 50 22.3 power time-range Description The power time-range command is used to create PoE time-range for the switch and enter Power Time-range Configuration Mode. After a PoE time-range is created, you need to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 197
Repeat this command to create multiple absolute time-ranges. Up to 7 absolute time-ranges can be created in one Time-range, and their union is the Absolute Time-range. If no absolute time range is configured, the absolute time range takes effect from January 1, 2000 00:00 to December 31, 2099 24:00. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 198
The Time-range takes affect only when both Absolute Time and Periodic Time are in effect. Repeat this command to create multiple periodic time-ranges. Up to 7 periodic time-ranges can be created in one Time-range, and their union is the Periodic Time-range. If no periodic time range is configured, - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 199
T1500-28PCT(config-time-range)# periodic start 10:00 end 16:00 day-of-the-week 6-7 22.6 power holiday Description The power holiday command is used to create PoE holiday for the switch. To delete the corresponding PoE holiday configuration, please use no power holiday command. Syntax power holiday - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 200
the port in the profile can supply. There are six options: "power-limit", "auto", "class1", "class2", "class3" and "class4". "power-limit" indicates you can manually enter a value. It ranges from 1 to 300. The value is in the unit of 0.1 watt. For instance, if you want to configure the max power - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 201
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the power limit as " - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 202
22.10 power inline supply Description The power inline supply command is used to configure the PoE status of the corresponding port. Syntax power inline supply { enable | disable } Parameter enable | disable -- The PoE status of the port. By default, the PoE status is "enable". Command Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 203
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Bind the PoE profile named "IP - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 204
22.13 show power inline Description The show power inline command is used to display the global PoE information of the system. Syntax show power inline Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the PoE information of the system: T1500- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 205
22.15 show power inline information interface Description The show power inline information command is used to display the PoE information of the certain port. Syntax show power inline information interface [ gigabitEthernet port ] Parameter port -- The Ethernet port number. Command Mode Privileged - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 206
22.17 show power holiday Description The show power holiday command is used to display the defined PoE holiday. Syntax show power holiday Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the defined PoE holiday: T1500-28PCT# show power holiday - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 207
Chapter 23 MSTP Commands MSTP (Multiple Spanning Tree Protocol), compatible with both STP and RSTP and subject to IEEE 802.1s, can disbranch a ring network. STP is to block redundant links and backup links as well as optimize paths. 23.1 debug spanning-tree Description The debug spanning-tree - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 208
Privilege Requirement Only Admin level users have access to these commands. Example Display all the spanning-tree debug messages: T1500-28PCT# debug spanning-tree all 23.2 spanning-tree(global) Description The spanning-tree command is used to enable STP function globally. To disable the STP function - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 209
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 210
int-cost -- Internal Path Cost, which is used to choose the path and calculate the path costs of ports in an MST region. It is an important criterion on determining the root port. The lower value has the higher priority. By default, it is automatic. It ranges from o to 2000000. By default, it is 0 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 211
Parameter stp --Spanning Tree Protocol, the default value. rstp --Rapid Spanning Tree Protocol mstp --Multiple Spanning Tree Protocol Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 212
23.7 instance Description The instance command is used to configure the VLAN-Instance mapping. To remove the VLAN-instance mapping or disable the corresponding instance, please use no instance command. When an instance is disabled, the related mapping VLANs will be removed. Syntax instance instance- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 213
Syntax name name Parameters name -- The region name, used to identify MST region. It ranges from 1 to 32 characters. Command Mode MST Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the region name of MST as " - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 214
23.10 spanning-tree mst instance Description The spanning-tree mst instance command is used to configure the priority of MST instance. To return to the default value of MST instance priority, please use no spanning-tree mst instance command. Syntax spanning-tree mst instance instance-id priority pri - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 215
no spanning-tree mst instance instance-id Parameter instance-id -- Instance ID, ranging from 1 to 8. pri -- Port Priority, which must be multiple of 16 ranging from 0 to 240. By default, it is 128. Port Priority is an important criterion on determining if the port will be chosen as the root port by - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 216
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the bridge priority as 4096: T1500-28PCT(config)# spanning-tree priority 4096 23.13 spanning-tree timer Description The spanning-tree timer command is used to configure forward-time - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 217
T1500-28PCT(config)# spanning-tree timer forward-time 16 hello-time 3 max-age 22 23.14 spanning-tree hold-count Description The spanning-tree hold-count command is used to configure the maximum number of BPDU packets transmitted per Hello Time interval. To return to the default configurations, - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 218
Parameter value -- The maximum number of hops that occur in a specific region before the BPDU is discarded, ranging from 1 to 40 in hop. By default, it is 20. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 219
23.17 spanning-tree bpduguard Description The spanning-tree bpduguard command is used to enable the BPDU protect function for a port. With the BPDU protect function enabled, the port will set itself automatically as ERROR-PORT when it receives BPDU packets, and the port will disable the forwarding - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 220
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 221
23.20 spanning-tree guard tc Description The spanning-tree guard tc command is used to enable the TC Protect of Spanning Tree function for a port. To disable the TC Protect of Spanning Tree function, please use no spanning-tree guard tc command. A switch removes MAC address entries upon receiving TC - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 222
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 223
Syntax show spanning-tree bridge [ forward-time | hello-time | hold-count | max-age | max-hops | mode | priority | state ] Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the bridge parameters: T1500-28PCT(config)# show spanning-tree bridge 23 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 224
T1500-28PCT(config)# show spanning-tree interface fastEthernet 1/0/2 mode 23.25 show spanning-tree interface-security Description The show spanning-tree interface-security command is used to display the protect information of all ports or a specified port. Syntax show spanning-tree interface- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 225
Syntax show spanning-tree mst { configuration [ digest ] | instance instance-id [ interface [ gigabitEthernet port | port-channel lagid ] ] } Parameter instance-id -- Instance ID desired to show, ranging from 1 to 8. port -- The Ethernet port number. lagid -- The ID of the LAG. Command Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 226
Chapter 24 IGMP Snooping Commands IGMP Snooping (Internet Group Management Protocol Snooping) is a multicast control mechanism running on Layer 2 switch. It can effectively prevent multicast groups being broadcasted in the network. 24.1 ip igmp snooping(global) Description The ip igmp snooping - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 227
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 228
24.4 ip igmp snooping mtime Description The ip igmp snooping mtime command is used to specify member port aging time globally. The default aging time is 260 seconds. To restore the default timer, please use no ip igmp snooping mtime command. Syntax ip igmp snooping mtime mtime no ip igmp snooping - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 229
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP report suppression function: T1500-28PCT(config)# ip igmp snooping report-suppression 24.6 ip igmp snooping immediate-leave Description The ip igmp snooping immediate-leave - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 230
Syntax ip igmp snooping drop-unknown no ip igmp snooping drop-unknown Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the operation to process unknown multicast as discard: T1500-28PCT(config - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 231
24.9 ip igmp snooping last-listener query-count Description The ip igmp snooping last-listener query-count command is used to specify the numbers of Specific Query Message to be sent. The default value is 2. To restore the default number, please use no ip igmp snooping last-listener query-count - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 232
no ip igmp snooping vlan-config vlan-id-list [ rtime router-time | mtime member-time | rport interface { fastEthernet port-list | gigabitEthernet port-list | port-channel lagid } ] no ip igmp snooping vlan-config vlan-id-list static ip interface { fastEthernet port-list | gigabitEthernet port-list | - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 233
T1500-28PCT(config)# ip igmp snooping vlan-config 2 static 225.0.0.1 interface fastEthernet 1/0/1-3 24.11 ip igmp snooping vlan-config (router-ports-forbidden) Description This command is used to forbid the specified ports as being router ports in the specified VLAN(s). To delete the forbidden - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 234
24.12 ip igmp snooping multi-vlan-config Description The ip igmp snooping multi-vlan-config command is used to create Multicast VLAN. To delete the corresponding Multicast VLAN, please use no ip igmp snooping multi-vlan-config command. To restore the default values, please use no ip igmp snooping - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 235
T1500-28PCT(config)# ip igmp snooping multi-vlan-config 3 rtime 100 T1500-28PCT(config)# ip igmp snooping multi-vlan-config 3 mtime 100 T1500-28PCT(config)# ip igmp snooping multi-vlan-config 3 rport interface fastEthernet1/0/3 24.13 ip igmp snooping multi-vlan-config (router-ports-forbidden) - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 236
T1500-28PCT(config)# ip igmp snooping multi-vlan-config 2 router-ports-forbidden interface fastEthernet1/0/1-3 24.14 ip igmp snooping multi-vlan-config (source-ip-replace) Description This command is used to replace the multicast source IP address of the IGMP packets in the specified multicast VLAN. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 237
Querier function of certain VLANs, please use no ip igmp snooping querier vlan command. Syntax ip igmp snooping querier vlan vlan-id no ip igmp snooping querier vlan vlan-id Parameter vlan-id - VLAN ID, ranging from 1 to 4094. Command Mode Global Configuration Mode Privilege Requirement Only Admin, - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 238
ip-addr -- The source IP of the general query frame sent by IGMP Snooping Querier. It should not be a multicast IP or a broadcast IP. By default, it is 192.168.0.1. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 239
drop -- When the number of the dynamic multicast groups that a port joins has exceeded the max-group, the port will not join any new multicast group. replace -- When the number of the dynamic multicast groups that a port joins has exceeded the max-group, the newly joined multicast group will replace - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 240
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create the profile 1: T1500-28PCT(config)# ip igmp profile 1 24.19 deny Description The deny command is used to configure the filtering mode of profile as deny. Syntax deny Command Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 241
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the filtering mode of profile 1 as permit: T1500-28PCT(config)# ip igmp profile 1 T1500-28PCT(config-igmp-profile)#permit 24.21 range Description The range command is used to - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 242
24.22 ip igmp filter Description The ip igmp filter command is used to bind the specified profile to the interface. To delete the binding, please use no ip igmp filter command. Syntax ip igmp filter profile-id no ip igmp filter Parameter profile-id -- Specify the profile ID, ranging from 1 to 999. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 243
Example Clear the statistics of the IGMP packets: T1500-28PCT(config)# clear ip igmp snooping statistics 24.24 show ip igmp snooping Description The show ip igmp snooping command is used to display the global configuration of IGMP snooping. Syntax show ip igmp snooping Command Mode Privileged EXEC - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 244
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the IGMP baisic configuration configuration of all ports and LAGs: T1500-28PCT# show ip igmp snooping interface basic-config Display the IGMP basic configuration of port 1/0/2: T1500-28PCT# show - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 245
24.27 show ip igmp snooping multi-vlan Description The show ip igmp snooping multi-vlan command is used to display the Multicast VLAN configuration. Syntax show ip igmp snooping multi-vlan Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 246
Display information of the multicast group with the IP address 225.1.1.1 in VLAN 5: T1500-28PCT#show ip igmp snooping groups vlan 5 225.1.1.1.1 24.29 show ip igmp snooping groups Description The show ip igmp snooping groups command is used to display the information of all IGMP snooping groups. It - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 247
Display the dynamic multicast groups of VLAN 5: T1500-28PCT(config)#show ip igmp snooping groups vlan 5 dynamic Display the static multicast groups of VLAN 5: T1500-28PCT(config)#show ip igmp snooping groups vlan 5 static Display the count of dynamic multicast entries of VLAN 5: T1500-28PCT(config)# - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 248
Syntax show ip igmp profile [ id ] Parameter id -- Specify the ID of the profile, ranging from 1 to 999. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of all profiles: T1500-28PCT(config)# show ip igmp profile - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 249
Chapter 25 SNMP Commands SNMP (Simple Network Management Protocol) functions are used to manage the network devices for a smooth communication, which can facilitate the network administrators to monitor the network nodes and implement the proper operation. 25.1 snmp-server Description The snmp- - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 250
Parameter name -- The entry name of View, ranging from 1 to 16 characters. Each View includes several entries with the same name. mib-oid -- MIB Object ID. It is the Object Identifier (OID) for the entry of View, ranging from 1 to 61 characters. include | exclude -- View Type, with include and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 251
Parameter name --The SNMP Group name, ranging from 1 to 16 characters. The Group Name, Security Model and Security Level compose the identifier of the SNMP Group. These three items of the Users in one group should be the same. smode -- Security Model, with v1、v2c and v3 options. They represent SNMP - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 252
25.4 snmp-server user Description The snmp-server user command is used to add User. To delete the corresponding User, please use no snmp-server user command. The User in an SNMP Group can manage the switch via the management station software. The User and its Group have the same security level and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 253
emode -- The Privacy Mode of the SNMP v3 User, with none and DES options. None indicates no privacy method is used, and DES indicates DES encryption method is used. By default, the Privacy Mode is "none". encrypt-pwd -- Privacy Password, ranging from 1 to 16 characters. The question marks and spaces - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 254
retries ] [ timeout timeout ] no snmp-server host ip user-name Parameter ip -- The IP Address of the management Host. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.100 or fe80::1234. udp-port -- UDP port, which is used to send notifications. The UDP port functions with the IP - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 255
type has a higher security than the trap type and resend and timeout need to be configured if you select this option. You can only select the trap type in Security Model v1. By default, the type of the notifications is "trap". retries -- The amount of times the switch retries an inform request, - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 256
25.7 snmp-server engineID Description The snmp-server engineID command is used to configure the local and remote engineID of the switch. To restore to the default setting, please use no snmp-server engineID command. Syntax snmp-server engineID { [ local local-engineID ] [ remote remote-engineID ] } - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 257
disable the sending of SNMP standard traps, please use no snmp-server traps snmp command. Syntax snmp-server traps snmp [ linkup | linkdown | warmstart | coldstart | auth-failure ] no snmp-server traps snmp [ linkup | linkdown | warmstart | coldstart | auth-failure ] Parameter linkup -- Enable - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 258
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin level users have access to these commands. Example Enable SNMP link status trap for port 3: T1500-28PCT( - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 259
spanning-tree -- Enable spanning-tree trap. It is sent when the port forwarding status changes or the port receives TCN packet or packet with TC fport-channel-. memory -- Enable memory trap. It is sent when memory usage exceeds 80%. Command Mode Global Configuration Mode Privilege Requirement Only - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 260
Enable VLAN-created trap only for the switch: T1500-28PCT(config)# snmp-server traps vlan create 25.12 rmon history Description The rmon history command is used to configure the history sample entry. To return to the default configuration, please use no rmon history command. RMON (Remote Monitoring - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 261
T1500-28PCT(config)# rmon history 1-3 interface fastEthernet 1/0/2 interval 100 owner owner1 25.13 rmon event Description The rmon event command is used to configure the entries of SNMP-RMON Event. To return to the default configuration, please use no rmon event command. Event Group, as one of the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 262
T1500-28PCT(config)# rmon event 1-4 user user1 description description1 type log owner owner1 25.14 rmon alarm Description The rmon alarm command is used to configure SNMP-RMON Alarm Management. To return to the default configuration, please use no rmon alarm command. Alarm Group is one of the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 263
statistics command is used to configure the entries of SNMP-RMON statistics. To delete the corresponding entry, please use no rmon statistics command. The maximum supported entries are 1000. 250 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 264
Syntax rmon statistics index interface gigabitEthernet port [ owner owner-name] [ status { underCreation | valid }] no rmon statistics index Parameter index -- The index number of the statistics entry, ranging from 1 to 65535, in the format of 1-3,5. port -- The statistics port number, in the format - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 265
Example Display SNMP configuration globally: T1500-28PCT# show snmp-server 25.17 show snmp-server view Description The show snmp-server view command is used to display the View table. Syntax show snmp-server view Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 266
25.19 show snmp-server user Description The show snmp-server user command is used to display the User table. Syntax show snmp-server user Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the User - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 267
Syntax show snmp-server host Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the Host table: T1500-28PCT# show snmp-server host 25.22 show snmp-server engineID Description The show snmp-server - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 268
Parameter index -- The index number of the entry selected to display the configuration, ranging from 1 to 12, in the format of 1-3, 5. You can select more than one entry for each command. By default, the configuration of all history sample entries is displayed. Command Mode Privileged EXEC Mode and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 269
25.25 show rmon alarm Description The show rmon alarm command is used to display the configuration of the Alarm Management entry. Syntax show rmon alarm [ index ] Parameter index -- The index number of the entry selected to display the configuration, ranging from 1 to 12, in the format of 1-3, 5. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 270
Privilege Requirement Only Admin level users have access to these commands. Example Display the configuration of the statistics entry 1: T1500-28PCT#show rmon statistics 1 257 - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 271
Chapter 26 LLDP Commands LLDP function enables network devices to advertise their own device information periodically to neighbors on the same LAN. The information of the LLDP devices in the LAN can be stored by its neighbor in a standard MIB, so it is possible for the information to be accessed by - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 272
Parameter multiplier -- Configure the Hold Multiplier parameter. It ranges from 2 to 10. By default, it is 4. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify Hold Multiplier as 5: T1500-28PCT( - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 273
fast-count -- When the port's LLDP state transforms from Disable (or Rx_Only) to Tx&Rx (or Tx_Only), the fast start mechanism will be enabled, that is, the transmit interval will be shorten to a second, and several LLDPDUs will be sent out (the number of LLDPDUs equals this parameter). The value - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 274
26.5 lldp transmit Description The lldp transmit command is used to enable the designated port to transmit LLDPDU. To disable the function, please use no lldp transmit command. Syntax lldp transmit no lldp transmit Command Mode Interface Configuration Mode (interface fastEthernet / interface range - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 275
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the SNMP notification for port 1/0/1: T1500-28PCT(config)#interface fastEthernet 1/0/1 T1500-28PCT(config-if)#lldp snmp-trap 26.7 lldp tlv-select Description The lldp tlv-select - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 276
26.8 lldp med-fast-count Description The lldp med-fast-count command is used to configure the number of the LLDP-MED frames that will be sent out. When LLDP-MED fast start mechanism is activated, multiple LLDP-MED frames will be transmitted based on this parameter. The default value is 4. To return - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 277
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the LLDP-MED feature for - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 278
box post-office-box ] [ additional additional ] [ country-code country-code ] [ what { dhcp-server | endpoint | switch } ] ] } Parameter emergency-number -- Emergency Call Service ELIN identifier, which is used during emergency call setup to a traditional CAMA or ISDN trunk-based PSAP. The length of - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 279
26.12 show lldp Description The show lldp command is used to display the global configuration of LLDP. Syntax show lldp Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of LLDP: T1500-28PCT#show lldp 26.13 show lldp - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 280
26.14 show lldp local-information interface Description The show lldp local-information interface command is used to display the LLDP information of the corresponding port. By default, the LLDP information of all the ports will be displayed. Syntax show lldp local-information interface [ - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 281
Example Display the neighbor information of port 1/0/1: T1500-28PCT#show lldp neighbor-information interface fastEthernet 1/0/1 26.16 show lldp traffic interface Description The show lldp traffic interface command is used to display the LLDP statistic information between the local device and - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 282
:Telnet, SSH and HTTP. Authentication Method List A method list describes the authentication methods and their sequence to authenticate a user. The switch supports Login List for users to gain access to the switch, and Enable List for normal users to gain administrative privileges. RADIUS/TACACS - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 283
Example Enable the AAA function globally: T1500-28PCT(config)# aaa enable 27.2 enable admin password Description The enable admin password command is used to elevate the current logged-in user from guest to admin and gain administrator level privileges. The authentication password is possibly - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 284
User Guidelines If the password you configured here is unencrypted and the global encryption function is enabled in service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. Example Set the elevation password as 123 for the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 285
Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. User Guidelines If both the enable admin password and enable admin secret are defined, you must enter the password set in enable admin secret. Example Set the secret elevation password - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 286
exchange messages which contains 31 characters at most. The question marks and spaces are not allowed. "encrypted-string" is a symmetric encrypted key with a fixed length, which you can copy from another switch's configuration file. The key or encrypted-key you configured here will be displayed in - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 287
T1500-28PCT(config)# show tacacs-server 27.6 radius-server host Description The radius-server host command is used to configure a new RADIUS server. To delete the specified RADIUS server, please use no radius-server host command. Syntax radius-server host ip-address [ auth-port port-id ] [ acct-port - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 288
Privilege Requirement Only Admin level users have access to these commands. User Guidelines The RADIUS servers you configured are added in the server group "radius" by default. Example Configure a RADIUS server with the IP address as 1.1.1.1, authentication port as 1200, timeout as 6 seconds, - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 289
27.8 aaa group Description This aaa group command is used to create AAA server groups to group existing TACACS+/RADIUS servers for authentication. This command puts the switch in the server group subconfiguration mode. To delete the corresponding AAA group, please use the no aaa group command. - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 290
Syntax server ip-address no server ip-address Parameter ip-address -- Specify the server's IP address. Command Mode Server Group Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Create the RADIUS server 1.1.1.1 to RADIUS server group "radius1": - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 291
27.11 aaa authentication login Description This aaa authentication login command is used to configure a login authentication method list. A method list describes the authentication methods and their sequence to authenticate a user. To delete the specified authentication method list, please use the - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 292
27.12 aaa authentication enable Description This aaa authentication enable command is used to configure a privilege authentication method list. A method list describes the authentication methods and their sequence to elevate a user's privilege. To delete the specified authentication method list, - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 293
authentication dot1x default { method } no aaa authentication dot1x default Parameter method -- Specify the method name. Only RADIUS server group is supported, and the default method is server group "radius". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 294
Parameter method -- Specify the method name. Only RADIUS server group is supported, and the default method is server group "radius". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 295
27.16 show aaa accounting Description This show aaa accounting command is used to display the summary information of the accounting metheod list. Syntax show aaa accounting [ dot1x ] Parameter dot1x -- Specify the method list type. Command Mode Privileged EXEC Mode and Any Configuration Mode - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 296
Example Enter the telnet terminal line configuration mode: T1500-28PCT(config)#line telnet 27.18 login authentication(telnet) Description The login authentication command is used to apply the login authentication method list to the telnet terminal line. To restore to the default authentication - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 297
Syntax line ssh Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enter the ssh terminal line configuration mode: T1500-28PCT(config)#line ssh 27.20 login authentication(ssh) Description The login authentication command is used - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 298
T1500-28PCT(config-line)# login authentication list1 27.21 enable authentication(telnet) Description The enable authentication command is used to apply the privilege authentication method list to the telnet terminal line. To restore to the default authentication method list, please use the no enable - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 299
Syntax enable authentication { method-list } no enable authentication Parameter method-list -- Specify the enable method list on the ssh terminal line. It is "default" by default, which contains the method "none". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 300
Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the HTTP access as "list1": T1500-28PCT(config)# ip http login authentication list1 27.24 ip http enable authentication Description The ip http enable authentication - TP-Link T1500-28TC TL-SL2428 | T1500-28TCUN V1 CLI Reference Guide Guide - Page 301
27.25 show aaa global Description This show aaa global command is used to display global status of AAA function and the login/enable method lists of different application modules: telnet, ssh and HTTP. Syntax show aaa global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege
CLI Reference Guide
T1500-28TC (TL-SL2428)/T1500-28PCT (TL-SL2428P)
1910012116
REV 2.0.0
March 2017