TP-Link T2500G-10TS T2500G-10TSUN V2 CLI Reference Guide Guide
TP-Link T2500G-10TS Manual
View all TP-Link T2500G-10TS manuals
Add to My Manuals
Save this manual to your list of manuals |
TP-Link T2500G-10TS manual content summary:
- TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 1
CLI Reference Guide T2500G-10TS (TL-SG3210) 1910012494 REV2.0.0 November 2018 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 2
COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-Link Technologies Co., Ltd. Other brands and product names are trademarks or registered trademarks of their respective holders. No part of the specifications may be reproduced - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 3
2.7 2.8 2.9 2.10 enable...17 service password-encryption 17 enable password...18 enable secret ...19 configure ...20 exit ...21 end ...21 show user account-list...26 3.4 show user configuration 27 Chapter 4 System Configuration Commands 28 4.1 system-time manual ...28 4.2 system-time ntp ...28 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 4
4.36 4.37 4.38 hostname...33 location ...34 contact-info ...34 ip address ...35 ip management-vlan...36 ip address-alloc...36 reset ...37 reboot...38 reboot-schedule ...38 copy running-config startup-config Chapter 5 EEE Configuration Commands 55 5.1 eee ...55 5.2 show interface eee ...55 III - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 5
...67 duplex...67 jumbo-size...68 speed ...69 clear counters...69 show interface status ...70 show interface counters 71 show interface configuration 71 Chapter 9 Port Isolation Commands 73 9.1 port isolation ...73 9.2 show port isolation interface 74 Chapter 10 Loopback Detection Commands 75 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 6
84 ddm tx_power_threshold 85 ddm rx_power_threshold 86 show ddm configuration 87 show ddm status ...88 Chapter 12 Etherchannel Commands notification (interface 100 mac address-table security 101 mac address-table vlan-security 102 show mac address-table 103 clear mac address-table 103 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 7
mac-vlan ...117 show mac-vlan...117 show mac-vlan interface 118 Chapter 16 Protocol-based VLAN Commands 119 16.1 16.2 16.3 16.4 16.5 protocol-vlan template 119 protocol-vlan vlan ...120 protocol-vlan group...121 show protocol-vlan template 122 show protocol-vlan vlan 122 Chapter 17 VLAN-VPN - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 8
validation 137 ip igmp snooping vlan-config 137 ip igmp snooping vlan-config (immediate-leave 139 ip igmp snooping vlan-config (report-suppression 139 ip igmp snooping vlan-config (router-ports-forbidden 140 ip igmp snooping vlan-config (rport interface 141 ip igmp snooping vlan-config (static - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 9
ipv6 mld filter ...169 clear ipv6 mld snooping statistics 169 show ipv6 mld snooping 170 show ipv6 mld snooping interface 170 show ipv6 mld snooping vlan 171 show ipv6 mld snooping groups 172 show ipv6 mld profile ...172 Chapter 21 MVR Commands 174 21.1 21.2 21.3 21.4 21.5 21.6 21.7 21 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 10
183 spanning-tree (global) ...184 spanning-tree (interface 184 spanning-tree common-config 185 spanning-tree mode ...186 spanning-tree mst configuration 187 instance ...188 name...188 revision ...189 spanning-tree mst instance 190 spanning-tree mst ...190 spanning-tree priority ...191 spanning - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 11
.9 26.10 26.11 service dhcp relay...225 ip dhcp relay hops...225 ip dhcp relay time...226 ip dhcp relay vlan ...227 ip dhcp relay information 227 ip dhcp relay information strategy 228 ip dhcp relay information format 229 ip dhcp relay information circuit-id 230 ip dhcp relay information remote - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 12
27.2 27.3 27.4 27.5 27.6 27.7 27.8 27.9 ip dhcp l2relay ...233 ip dhcp l2relay vlan ...233 ip dhcp l2relay information 234 ip dhcp l2relay information strategy 234 ip dhcp l2relay information format 235 ip dhcp l2relay information circuit-id 236 ip dhcp l2relay information remote-id 237 show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 13
30.7 voice vlan (interface) ...255 voice vlan priority ...256 voice vlan oui ...257 show voice vlan ...257 show voice vlan oui-table 258 show voice vlan interface 258 Chapter 32.4 32.5 32.6 user access-control ip-based enable 266 user access-control ip-based 266 user access-control mac-based - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 14
33.13 show ip http configuration 280 33.14 show ip http secure-server 281 Chapter 34 SSH Commands 282 34.1 34.2 34.3 34.4 34.5 34.6 34.7 34.8 34.9 ip ssh server...282 ip ssh port...282 ip ssh version ...283 ip ssh algorithm ...284 ip ssh timeout ...284 ip ssh max-client ...285 ip ssh download - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 15
enable authentication (telnet 304 enable authentication (ssh 305 ip http login authentication 305 ip http enable authentication 306 show aaa global ...307 enable auth-protocol ...310 dot1x vlan-assignment 311 dot1x accounting ...312 dot1x mab ...313 dot1x guest-vlan ...313 dot1x timeout quiet- - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 16
IMPB Commands 345 42.1 42.2 42.3 42.4 42.5 42.6 42.7 ip source binding...345 ip dhcp snooping ...346 ip dhcp snooping vlan ...347 ip dhcp snooping max-entries 347 show ip source binding 348 show ip dhcp snooping 349 show ip dhcp snooping interface 349 Chapter 43 IPv6 IMPB Commands 351 43 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 17
46.7 46.8 46.9 ip dhcp filter ...365 ip dhcp filter (interface 365 ip dhcp filter mac-verify 366 ip dhcp filter limit rate...367 ip dhcp filter decline rate 368 ip dhcp filter server permit-entry 368 show ip dhcp filter...369 show ip dhcp filter interface 370 show ip dhcp filter server permit - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 18
traps snmp 393 snmp-server traps ...394 snmp-server traps ddm 396 snmp-server traps vlan 397 snmp-server traps security 398 snmp-server traps acl ...399 snmp-server traps ip ...399 snmp-server traps link-status 400 rmon history...400 rmon event ...401 rmon alarm ...402 rmon statistics...404 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 19
51.12 51.13 ip arp inspection...411 ip arp inspection validate 411 ip arp inspection vlan ...412 ip arp inspection vlan logging 413 ip arp inspection trust ...414 ip arp inspection limit-rate 414 ip arp inspection burst-interval 415 ip arp inspection recover 416 show ip arp inspection ...416 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 20
53.14 show logging buffer...433 53.15 show logging flash ...433 XIX - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 21
this Guide stands for T2500G-10TS JetStream 8-Port Gigabit L2 Managed Switch with 2 SFP Slots without any explanation. Overview of this Guide Chapter System Configuration Commands Provide information about the commands used for configuring the System information and System IP, reboot and reset the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 22
information about the commands used for configuring LAG (Link Aggregation Group) and LACP (Link Aggregation Control Protocol). Chapter 13: MAC Address Commands Provide information about the commands used for Address configuration. Chapter 14 IEEE 802.1Q VLAN Commands Provide information about the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 23
. Chapter 29: Bandwidth Commands Provide information about the commands used for configuring the Bandwidth Control. Chapter 30: Voice VLAN Commands Provide information about the commands used for configuring Voice VLAN. Chapter 31: Auto VoIP Commands Provide information about the commands used - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 24
Chapter 41: ACL Commands Provide information about the commands used for configuring the ACL (Access Control List). Chapter 42: IPv4 IMPB Commands Provide information about the commands used for binding the IP address, MAC address, VLAN and the connected Port number of the Host together. Chapter 43 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 25
steps: 1. Click Start and type in cmd in the Search programs and files window and press the Enter button. Figure 1-1 Run Window 2. Telnet the switch's IP address (factory setting is 192.168.0.1) in the prompt cmd window and press Enter. Figure 1-2 Type in the telnet command 5 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 26
3. Type in the User name and Password (the factory default value for both of them are admin) and press SSH connection: Password Authentication Mode: It requires username and password, which are both admin by default. Key Authentication Mode: It requires a public key for the switch and a private key - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 27
Figure 1-5 Enable SSH function Password Authentication Mode 1. Open the software to log on to the interface of PuTTY. Enter the IP address of the switch into Host Name field; keep the default value 22 in the Port field; select SSH as the Connection type. Figure 1-6 SSH Connection Config 7 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 28
the login user name and password to log on the switch, and then enter enable to enter Privileged EXEC Mode, so you can continue to configure the switch. Figure 1-7 Log on the Switch Key Authentication Mode 1. Select the key type and key length, and generate SSH key. Figure 1-8 Generate SSH Key - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 29
2. During the key generation, randomly moving the mouse quickly can accelerate the key generation. 2. After the key is successfully generated, please save the public key and private key to a TFTP server. Figure 1-9 Save the Generated Key 9 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 30
3. Log on to the switch by Telnet and download the public key file from the TFTP server to the switch, as the following figure shows: Figure 1-10 Download the Public Key Note: 1. The key type should accord with the type of the key file. 2. The SSH key downloading can not be interrupted. 10 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 31
4. After the public key is downloaded, please log on to the interface of PuTTY and enter the IP address for login. Figure 1-11 SSH Connection Config 11 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 32
downloaded. Figure 1-13 Log on the Switch 1.2 CLI Command Modes The CLI is divided into different command modes: User EXEC Mode, Privileged EXEC Mode, Global Configuration Mode, Interface Configuration Mode and VLAN Configuration Mode. 12 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 33
Configuration Mode can also be divided into Interface Ethernet, Interface link Configuration Mode Use the configure command to enter this mode from Privileged EXEC mode. T2500G-10TS> T2500G-10TS# T2500G-10TS(config Configuration mode. Use the vlan vlan-list to access VLAN Configuration mode. 13 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 34
mode. Use the end command or press Ctrl+Z to return to Privileged EXEC mode. Enter the exit or the # command to return to Global Configuration mode. T2500G-10TS(config-vlan)# Use the end command or press Ctrl+Z to return to Privileged EXEC mode. Enter the exit command or the # command to return to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 35
, such as broadcast storm. d). Interface range link-aggregation: Configure parameters for multi-trunks. e). Interface vlan: Configure parameters for the vlan-port. VLAN Configuration Mode: In this mode, users can create a VLAN and add a specified port to the VLAN. 3. Some commands are global, that - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 36
address must be enter in the format of xx:xx:xx:xx:xx:xx. One or several values can be typed for a port-list or a vlan-list using comma to separate. Use a hyphen to designate a range of values, for instance, 1/0/1, 1/0/3-5, 1/0/7 indicates choosing port 1/0/1, 1/0/3, 1/0/4, 1/0/5, 1/0/7. 16 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 37
EXEC Mode from User EXEC Mode: T2500G-10TS>enable Enter password: T2500G-10TS# 2.2 service password-encryption Description The service password-encryption command is used to encrypt the password when the password is defined or when the configuration is written, using the symmetric encryption - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 38
Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the global encryption function: T2500G-10TS(config)# service type. 0 indicates that an unencrypted password will follow. By default, the encryption type is 0. password -- Super password, a - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 39
service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. Example Set the super password as "admin" and unencrypted to access Privileged EXEC Mode from User EXEC Mode: T2500G-10TS default, it is empty. The password in the configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 40
. The password will be displayed in the encrypted form. T2500G-10TS(config)#enable secret 0 admin 2.5 configure Description The configure command is used to access Global Configuration Mode from Privileged EXEC Mode. Syntax configure Command Mode Privileged EXEC Mode Privilege Requirement Only Admin - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 41
Mode Privilege Requirement None. Example Return to Global Configuration Mode from Interface Configuration Mode, and then return to Privileged EXEC Mode: T2500G-10TS(config-if)# exit T2500G-10TS(config)#exit T2500G-10TS# 2.7 end Description The end command is used to return to Privileged - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 42
use no clipaging command. Syntax clipaging no clipaging Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Disable the pause function for the screen display: T2500G-10TS(config)#no clipaging 2.9 history Description The history command is used to show the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 43
command. Syntax history clear Command Mode Privileged EXEC Mode and any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear the commands you have entered in the current mode: T2500G-10TS(config)#history clear 23 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 44
settings of different functions without the right to edit or modify. It is "admin" by default. For more details about privilege restrictions, please refer to the Privilege Requirement part in each command with fixed length, which you can copy from another switch's configuration file. After the 24 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 45
encryption function is enabled in service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. Example Add and enable a new admin user named "tplink", of which the password is "admin" and unencrypted: T2500G-10TS(config)#user name tplink - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 46
default. 0 -- Specify the encryption type. 0 indicates that an unencrypted password will follow. By default configured password will take effect. Example Add and enable a new admin user named "tplink", of which the password is "admin". The password will be displayed in the encrypted form. T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 47
these commands. Example Display the information of the current users: T2500G-10TS(config)# show user account-list 3.4 show user configuration Description The show user configuration command is used to display the security configuration information of the users, including access-control, max-number - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 48
the time is 12/20/2010 17:30:35 T2500G-10TS(config)# system-time manual 12/20/2010-17:30:35 4.2 system-time ntp Description The system-time ntp command is used to configure the time zone and the IP address for the NTP Server. The switch will get UTC automatically if it has connected - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 49
Solomon Is., New Caledonia, Vladivostok. UTC+12:00 -- TimeZone for Fiji, Magadan, Auckland, Welington. UTC+13:00 -- TimeZone for Nuku'alofa, Samoa. ntp-server -- The IP address for the Primary NTP Server. 29 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 50
Configure the system time mode as NTP, the time zone is UTC-12:00, the primary NTP server is 133.100.9.2 and the secondary NTP server is 139.78.100.163, the fetching-rate is 11 hours: T2500G-10TS Australia, Europe and New-Zealand respectively. The default value is Europe. Following are the time - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 51
the daylight saving time as USA standard: T2500G-10TS(config)#system-time dst predefined USA 4.4 system-time dst date Description The system-time dst date command is used to configure the one-off daylight saving time. The start date is in the current year by default. The time range of the daylight - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 52
by default. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the daylight saving time from zero clock, Apr 1st to zero clock Oct 1st and the offset is 30 minutes in 2015: T2500G-10TS(config)# system - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 53
] no hostname Parameter hostname -- System Name. The length of the name ranges from 1 to 32 characters. By default, it is the device name, for example "T2500G-10TS". Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. 33 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 54
characters at most. It is "SHENZHEN" by default. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the system location as SHENZHEN: T2500G-10TS(config)# location SHENZHEN 4.8 contact-info Description The - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 55
www.tp-link.com: T2500G-10TS(config)# contact-info www.tp-link.com 4.9 ip address Description This ip address command is used to configure the IP address and IP subnet mask for the management interface manually. Syntax ip address { ip-addr } { mask } gateway {default-gateway} no ip address [ ip-addr - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 56
configure the IP address of the management interface as 192.168.0.150/24 and default gateway as 192.168.0.10: T2500G-10TS(config)# interface vlan 1 T2500G-10TS(config-if)# ip address 192.168.0.150 255.255.255.0 gateway 192.168.0.10 4.10 ip management-vlan Description This ip management-vlan command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 57
function on the VLAN interface 1: T2500G-10TS(config)# interface vlan 1 T2500G-10TS(config-if)# no ip address 4.12 reset Description The reset command is used to reset the switch's software. After resetting, all configuration of the switch will restore to the factory defaults and your current - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 58
users have access to these commands. Example Reset the software of the switch: T2500G-10TS# reset 4.13 reboot Description The reboot command is Example Reboot the switch: T2500G-10TS# reboot 4.14 reboot-schedule Description This reboot-schedule command is used to configure the switch to reboot at - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 59
; otherwise the switch will reboot at the time point the next day. Example Specify the switch to save the configuration files and reboot in 200 minutes,: T2500G-10TS(config)# reboot-schedule in 200 save_before_reboot 4.15 copy running-config startup-config Description The copy running-config startup - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 60
148 and name this file config.cfg: T2500G-10TS# copy startup-config tftp ip-address 192.168.0.148 filename config Backup the configuration files to TFTP server with the IP fe80::1234 and name this file config.cfg: T2500G-10TS# copy startup-config tftp ip-address fe80::1234 filename config 4.17 copy - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 61
from TFTP server with the IP 192.168.0.148: T2500G-10TS# copy tftp startup-config ip-address 192.168.0.148 filename config Download the configuration file named as config.cfg to the switch from TFTP server with the IP fe80::1234 T2500G-10TS# copy tftp startup-config ip-address fe80::1234 filename - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 62
Admin level users have access to these commands. Example Export the backup configuration file of the switch to the TFTP server with the IP 192.168.0.148 and name the file config.cfg: T2500G-10TS# copy backup-config tftp ip-address 192.168.0.148 filename config 4.19 copy backup-config startup-config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 63
. Command Mode Privileged EXEC Mode Privilege Requirement Only Admin level users have access to these commands. Example Download the configuration file named config.cfg from the TFTP server with the IP 192.168.0.148: T2500G-10TS# copy tftp backup-config ip-address 192.168.0.148 filename config 43 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 64
-- Specify the image file to be configured. By default, the image1.bin is the startup image T2500G-10TS(config)# boot application filename image2 startup 4.23 boot config Description The boot config command is used to configure the configuration file as startup configuration or backup configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 65
configuration file to be configured. By default, the config1.cfg is the startup image and the config2.cfg is the backup image. startup | backup-- Specify the property of the configuration. Command Mode Global Configuration Example Configure the config2.cfg as the startup image: T2500G-10TS(config)# - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 66
firmware upgrade ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for the TFTP server with the IP address fe80::1234, but do not reboot the switch: T2500G-10TS# firmware upgrade ip-address fe80::1234 filename firmware. - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 67
test, the connection between the switch and the network device is failed to establish: T2500G-10TS# ping 192.168.0.131 -n 8 -l 512 To test the connectivity between the switch and the network device with the IP fe80::1234, please specify the count (-l) as 512 bytes and count (-i) as 1000 milliseconds - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 68
20 maxHops, the connection between the switch and the destination device is failed to establish: T2500G-10TS# tracert 192.168.0.131 20 Test the connectivity between the switch and the network device with the IP fe80::1234. If the destination device has not been found after 20 maxHops, the connection - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 69
System Time, Run Time and so on. Syntax show system-info Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the system information: T2500G-10TS# show system-info 4.29 show image-info Description The show image-info command is used to display the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 70
users have access to these commands. Example Display the system boot configuration information: T2500G-10TS# show boot 4.31 show running-config Description The show running-config command is used to display the current operating configuration of the system or of a specified port. Syntax show running - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 71
Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the saved configuration: T2500G-10TS# show startup-config 4.33 show system-time Description The show system-time command is used to display the time information of the switch. Syntax show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 72
information of the switch. Syntax show system-time dst Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DST information of the switch T2500G-10TS# show system-time dst 4.35 show system-time ntp Description The show system-time ntp command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 73
of the cable connected to the switch, locate and diagnose the trouble spot of the network. Syntax show cable-diagnostics interface { fastEthernet EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Show the cable-diagnostics of port 3: T2500G-10TS# show cable-diagnostics - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 74
system's memory utilization in the last 5 seconds/1minute/5minutes. Syntax show memory-utilization Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the memory utilization information of the switch: T2500G-10TS# show memory-utilization 54 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 75
access to these commands. Example Enable EEE on port 1/0/1: T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#eee 5.2 show interface eee Description The show interface eee command is used to display the EEE configuration on each port. Syntax show interface eee [ fastEthernet - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 76
Privilege Requirement None. Example Display the EEE configuration of each port T2500G-10TS# show interface eee 56 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 77
". enterpriseV6 -- Specify the SDM template used in the switch as "enterpriseV6". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Specify the SDM template as enterpriseV4: T2500G-10TS(config)# sdm prefer enterpriseV4 57 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 78
sdm prefer { used | default | enterpriseV4 | enterpriseV6 } Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the resource allocation of the template currently in use, and the template that will become active after a reboot: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 79
-range named "tRange1" for the switch: T2500G-10TS(config)# time-range tRange1 7.2 absolute Description The absolute command is used to create an absolute time-range for the time-range of the switch. To delete the corresponding absolute time-range configuration, please use no absolute command. 59 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 80
T2500G-10TS(config)#time-range tRange1 T2500G-10TS(config-time-range)#absolute from 05/05/2017 to 10/05/2017 7.3 periodic Description The periodic command is used to create a periodic mode time-range for the time-range of the switch. To delete the corresponding periodic mode time-range configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 81
and Power User level users have access to these commands. Example Configure the time-range named "tRange2" as a periodic time-range and specify the date and time as 8:30 to 12:00 on weekends: T2500G-10TS(config)#time-range tRange2 T2500G-10TS(config -time-range)#periodic start 08:30 end 12:00 day - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 82
and Power User level users have access to these commands. Example Create a holiday named "holiday1" and configure the start date as October 1st and the end date as October 3rd: T2500G-10TS(config)# holiday holiday1 start-date 10/01 end-date 10/03 7.6 show holiday Description The show holiday - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 83
Example Display the defined holiday: T2500G-10TS# show holiday 7.7 show time-range Description The show time- from 1 to 16 characters. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the defined time-range: T2500G-10TS# show time-range 63 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 84
Power User level users have access to these commands. Example To enter the Interface gigabitEthernet Configuration Mode and configure port 2: T2500G-10TS(config)# interface gigabitEthernet 1/0/2 8.2 interface range gigabitEthernet Description The interface range gigabitEthernet command is used to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 85
one port. Example To enter the Interface range gigabitEthernet Configuration Mode, and configure ports 1, 2, 3, 6, 7 and 9 at the same time by adding them to one port-list: T2500G-10TS(config)# interface range gigabitEthernet 1/0/1-3,1/0/6-7,1/0/9 8.3 description Description The description command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 86
-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# description Port_5 8.4 shutdown Description The shutdown command is used to disable an Ethernet port. To enable this port again, please use no shutdown command. Syntax shutdown no shutdown Command Mode Interface Configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 87
flow-control function for port 1/0/3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# flow-control 8.6 duplex Description The duplex command is used to configure the Duplex Mode for an Ethernet port. To return to the default configuration, please use no duplex command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 88
from 1518 to 9216 bytes, and the default is 1518 bytes. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Globally configure the size of jumbo frames as 9216: T2500G-10TS(config)# jumbo-size 9216 68 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 89
100Mbps, 1000Mbps and Auto negotiation mode (default). Command Mode Interface Configuration Mode (interface fastEthernet / interface range these commands. Example Configure the Speed Mode as 100Mbps for port 1/0/3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 90
port number. port-channel-id -- The ID of the port channel.. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the connection status of all ports and port channels: T2500G-10TS(config)# show interface status Display the connection status of port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 91
counters Display the statistics information of port 1/0/2: T2500G-10TS(config)# show interface counters gigabitEthernet 1/0/2 8.12 show interface configuration Description The show interface configuration command is used to display the configurations of all ports and port channels, including Port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 92
Privilege Requirement None. Example Display the configurations of all Ethernet ports and port channels: T2500G-10TS(config)# show interface configuration Display the configurations of port 1/0/2: T2500G-10TS(config)# show interface configuration gigabitEthernet 1/0/2 72 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 93
The port isolation command is used to configure the forward port/port channel list of on its list. To delete the corresponding configuration, please use no port isolation command. Interface Configuration Mode of port 1/0/5: T2500G-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 94
its forward port list, ranging from 1 to 6. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the forward-list of port 1/0/2: T2500G-10TS# show port isolation interface gigabitEthernet 1/0/2 Display the forward-list of all Ethernet ports and - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 95
Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the loopback detection function globally: T2500G-10TS of sending loopback detection packets. It ranges from 1 to 1000 seconds. By default, this value is 30. 75 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 96
2 to 1000000 seconds. By default, this value is 90. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the recovery-time as 70 seconds: T2500G-10TS(config)# loopback-detection recovery-time - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 97
detection function of ports 1-3: T2500G-10TS(config)# interface range gigabitEthernet 1/0/1-3 T2500G-10TS(Config-if-range)# loopback-detection 10.5 loopback-detection config process-mode Description The loopback-detection config process-mode command is used to configure the process-mode for the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 98
loop is detected and no packets can pass through the port. vlan-based -- When a loop is detected, the switch will send Configure the loopback detection process-mode as port-based, and configure the recovery mode as manual for port 2: T2500G-10TS(config)# interface gigabitEthernet 1/0/2 T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 99
. Syntax show loopback-detection global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of loopback detection function: T2500G-10TS# show loopback-detection global 10.8 show loopback-detection interface Description The - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 100
and block status of the VLAN which the specified port belongs to. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of loopback detection function and the status of all ports: T2500G-10TS# show loopback-detection interface - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 101
no ddm state enable Default Setting Enabled on all the SFP ports. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Example Enable DDM function on port 1/0/25: T2500G-10TS(config)#interface gigabitEthernet 1/0/25 T2500G-10TS(config-if)#ddm state - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 102
an exceeding alarm threshold event is encountered. Default Setting none, which means the port will T2500G-10TS(config)#interface gigabitEthernet 1/0/25 T2500G-10TS(config-if)#ddm shutdown warning 11.3 ddm temperature_threshold Description The ddm temperature_threshold command is used to configure - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 103
in Celsius. Default Setting None. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet ) Example Configure the high_alarm threshold of DDM temperature on the port 1/0/25 as 5: T2500G-10TS(config)#interface gigabitEthernet 1/0/25 T2500G-10TS(config-if - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 104
in Volt. Default Setting None. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet ) Example Configure the high_alarm threshold of DDM voltage on the port 1/0/25 as 5: T2500G-10TS(config)#interface gigabitEthernet 1/0/25 T2500G-10TS(config-if)#ddm - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 105
in mA. Default Setting None. Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure the high_alarm threshold of DDM Bias Current on the port 1/0/25 as 5: T2500G-10TS(config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 106
in mW. Default Setting None. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet ) Example Configure the high_alarm threshold of DDM Tx Power on the port 1/0/25 as 5: T2500G-10TS(config)#interface gigabitEthernet 1/0/25 T2500G-10TS(config-if)#ddm - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 107
the threshold of the DDM Tx Power value. rx_power -- Displays the threshold of the DDM Rx Power value. Command Mode Privileged EXEC Mode and Any Configuration Mode Example View the DDM configuration state: T2500G-10TS(config)#show ddm configuration state View the threshold of the DDM Voltage value - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 108
the digital diagnostic monitoring status of SFP modules inserting into the switch's SFP ports. Syntax show ddm status Command Mode Privileged EXEC Mode and Any Configuration Mode Example View the DDM status: T2500G-10TS(config)#show ddm status 88 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 109
aggregation and disaggregation by exchanging LACP packets with its partner. The switch can dynamically group similarly configured ports into a single logical link, which will highly extend the bandwidth and flexibly balance the load. 12.1 channel-group Description The channel-group command is used - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 110
(config)# interface range gigabitEthernet 1/0/2-4 T2500G-10TS(config-if-range)# channel-group 1 mode on 12.2 port-channel load-balance Description The port-channel load-balance command is used to configure the Aggregate Arithmetic for LAG. To return to the default configurations, please use no port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 111
Arithmetic for LAG as "src-dst-ip": T2500G-10TS(config)# port-channel load-balance src-dst-ip 12.3 lacp system-priority Description The lacp system-priority command is used to configure the LACP system priority globally. To return to the default configurations, please use no lacp system-priority - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 112
32768 by default. Command Mode Interface Configuration Mode ( T2500G-10TS(config)# interface range gigabitEthernet 1/0/1-3 T2500G-10TS(config-if-range)# lacp port-priority 1024 Configure the LACP port priority as 2048 for port 4: T2500G-10TS(config)# interface gigabitEthernet 1/0/4 T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 113
The EtherChannel information in summary. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the detailed information of EtherChannel Group 1: T2500G-10TS(config)# show etherchannel 1 detail 12.6 show etherchannel load-balance Description The show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 114
-group-num -- The EtherChannel Group number, ranging from 1 to 14. By default, it is empty, and will display the information of all LACP groups. internal and Any Configuration Mode Privilege Requirement None. Example Display the internal LACP information of EtherChannel Group 1: T2500G-10TS(config)# - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 115
Example Display the LACP system priority: T2500G-10TS(config)# show lacp sys-id 95 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 116
can be added or removed manually, independent of the aging Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Add a static Mac address entry to bind the MAC address 00:02:58:4f:6c:23, VLAN1 and port 1 together: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 117
default. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the aging time as 500 seconds: T2500G-10TS filtering address can be added or removed manually, independent of the aging time. Syntax - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 118
Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Add a filtering address entry of which VLAN ID is 1 and MAC address is 00:1e:4b:04:01:5d: T2500G-10TS second by default. Command Mode Global Configuration Mode Privilege - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 119
T2500G-10TS(config)# mac address-table notification global-status enable table-full-status enable interval 2 13.5 mac address-table max-mac-count Description The mac address-table max-mac-count command is used to configure the Port Security. To return to the default configurations deleted manually. - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 120
port. By default this function T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)# mac address-table max-mac-count max-number 30 mode static status drop 13.6 mac address-table notification (interface) Description The mac address-table notification command is used to configure - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 121
-10TS(config)# interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# mac address-table notification learn-mode-change enable 13.7 mac address-table security Description The mac address-table security command is used to configure the maximum number of MAC address cane be learned in specified VLANs - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 122
Only Admin, Operator and Power User level users have access to these commands. Example Configure the max learned MAC address number is VLAN 2 as 1000, and drop the packets that have no match in the MAC address table: T2500G-10TS(config)# mac address-table security vid 2 max-learn 1000 drop 13.8 mac - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 123
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the max learned MAC address number is VLAN 2 as 1000: T2500G-10TS(config)# mac address-table vlan-security vid 2 max-learn 1000 13.9 show mac address-table Description The show mac address - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 124
of the MAC address. Syntax show mac address-table aging-time Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the Aging Time of the MAC address: T2500G-10TS(config)# show mac address-table aging-time 13.12 show mac address-table max-mac-count - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 125
Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the security configuration of all ports: T2500G-10TS(config)# show mac address-table max-mac-count all Display the security configuration of port 1/0/1: T2500G-10TS(config)# show mac address-table max - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 126
which the MAC entries belong to. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the total MAC entry information in different VLANs: T2500G-10TS(config)# show mac address-table count 13.15 show mac address-table address Description The show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 127
. Syntax show mac address-table vlan vid Parameter vid --The specified VLAN id. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the MAC address configuration of vlan 1: T2500G-10TS(config)# show mac address-table vlan 1 13.17 show mac address - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 128
mac address-table vlan-security [ vid vid ] Parameter vid --The specified VLAN id. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the MAC address security configuration of VLAN 1: T2500G-10TS(config)# show mac address-table vlan- security vid - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 129
of 2-3, 5. It is multi-optional. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create VLAN 2-10 and VLAN 100: T2500G-10TS(config)# vlan 2-10,100 Delete VLAN 2: T2500G-10TS(config)# no vlan 2 109 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 130
16 characters at most. Command Mode VLAN Configuration Mode(VLAN) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the name of VLAN 2 as "group1": T2500G-10TS(config)# vlan 2 T2500G-10TS(config-vlan)# name group1 14.3 switchport - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 131
have access to these commands. Example Configure Gigabit Ethernet port 1/0/4 whose link type is "general" to VLAN 2 and its egress-rule as "tagged": T2500G-10TS(config)#interface gigabitEthernet 1/0/4 T2500G-10TS(config-if)#switchport mode general T2500G-10TS(config-if)#switchport general allowed - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 132
1/0/2 T2500G-10TS(config-if)# switchport pvid 2 14.5 switchport check ingress Description The switchport check ingress command is used to enable the Ingress Checking function for the switch ports. With this function enabled, the port will accept the packet of which the VLAN ID is in the port's VLAN - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 133
Checking. To restore to the default setting, please use no switchport Command Mode Interface Configuration Mode (interface fastEthernet T2500G-10TS(config)#interface gigabitEthernet 1/0/4 T2500G-10TS(config-if)#switchport acceptable frame tagged 14.7 show vlan summary Description The show vlan - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 134
information of IEEE 802.1Q VLAN. Syntax show vlan brief Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the brief information of IEEE 802.1Q VLAN: T2500G-10TS(config)# show vlan brief 14.9 show vlan Description The show vlan command is used to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 135
Privilege Requirement None. Example Display the information of vlan 5: T2500G-10TS(config)# show vlan id 5 14.10 show interface switchport Description The show interface switchport command is used to display the IEEE 802.1Q VLAN configuration information of the specified port/port channel. Syntax - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 136
8 characters at most. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create VLAN 2 with the MAC address 00:11:11:01:01:12 and the name "TP": T2500G-10TS(config)#mac-vlan mac-address 00:11:11:01:01 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 137
access to these commands. Example Enable the Gigabit Ethernet port 1/0/3 for the MAC-based VLAN feature: T2500G-10TS(config)#interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)#mac-vlan 15.3 show mac-vlan Description The show mac-vlan command is used to display the information of the MAC-based - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 138
all the MAC-based VLAN entry: T2500G-10TS(config)#show mac-vlan all 15.4 show mac-vlan interface Description The show mac-vlan interface command is used to display the port state of MAC-based VLAN. Syntax show mac-vlan interface Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 139
and the SSAP type. template-idx -- The number of the Protocol-based VLAN Template. You can get the template corresponding to the number by the show protocol-vlan template command. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 140
type is 0x2024: T2500G-10TS(config)#protocol-vlan template name TP frame ether_2 ether-type 2024 16.2 protocol-vlan vlan Description The protocol-vlan vlan command is used to create a Protocol-based VLAN entry. To delete a Protocol-based VLAN entry, please use no protocol-vlan vlan command. Syntax - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 141
Example Create Protocol-based VLAN 2 and bind it with Protocol-based VLAN Template 3: T2500G-10TS(config)#protocol-vlan vlan 2 template 3 16.3 protocol-vlan group Description The protocol-vlan command is used to add the port to a specified protocol group. To remove the port from this protocol group, - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 142
Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of the Protocol-based VLAN templates: T2500G-10TS(config)#show protocol-vlan template 16.5 show protocol-vlan vlan Description The show protocol-vlan vlan command is used to display the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 143
to these commands. Example Enable the VLAN-VPN function globally: T2500G-10TS(config)#dot1q-tunnel 17.2 switchport dot1q-tunnel tpid Description The switchport dot1q-tunnel tpid command is used to configure Global TPID for the ports. To restore to the default value, please use the no switchport - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 144
gigabitEthernet 1/0/2 T2500G-10TS(config)#dot1q-tunnel tpid 9100 17.3 dot1q-tunnel mapping Description The dot1q-tunnel mapping command is used to enable the VLAN Mapping feature globally. To disable this function, please use the no dot1q-tunnel mapping command. By default, the VLAN Mapping feature - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 145
the VLAN mapping feature globally: T2500G-10TS(config)#dot1q-tunnel mapping 17.4 switchport dot1q-tunnel mode Description The switchport dot1q-tunnel mode command is used to configure the VPN port's mode. To close this VPN port, please use the no switchport dot1q-tunnel mode command. By default, no - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 146
and Power User level users have access to these commands. Example Enable the VLAN-VPN missdrop function for Gigabit Ethernet port 1/0/3: T2500G-10TS(config)#interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)#switchport dot1q-tunnel missdrop 17.6 switchport dot1q-tunnel mapping Note: Choose - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 147
VLAN as VLAN 2 and the Service Provider VLAN as VLAN 3: T2500G-10TS(config)#interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)#switchport dot1q-tunnel mapping 2 3 17.7 show dot1q-tunnel Description The show dot1q-tunnel command is used to display the global configuration information of the VLAN - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 148
Mapping entry. Syntax show dot1q-tunnel mapping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of VLAN Mapping entry: T2500G-10TS(config)#show dot1q-tunnel mapping 17.9 show dot1q-tunnel interface Description The show dot1q - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 149
Example Display the port type of all VLAN VPN ports: T2500G-10TS(config)#show dot1q-tunnel interface 129 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 150
no gvrp command. Syntax gvrp no gvrp Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the GVRP function globally: T2500G-10TS(config)#gvrp 18.2 gvrp (interface) Description The gvrp command is - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 151
Ethernet ports 1/0/2-6: T2500G-10TS(config)#interface range gigabitEthernet 1/0/2-6 T2500G-10TS(config-if-range)#gvrp 18.3 gvrp registration Description The gvrp registration command is used to configure the GVRP registration type for the desired port. To restore to the default value, please use - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 152
Example Configure the GVRP registration mode as "fixed" for Gigabit Ethernet ports 1/0/2-6: T2500G-10TS(config)#interface range gigabitEthernet 1/0/2-6 T2500G-10TS(config-if-range)#gvrp registration fixed 18.4 gvrp timer Description The gvrp timer command is used to set a GVRP timer for the desired - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 153
of it to the default value: T2500G-10TS(config)#interface gigabitEthernet 1/0/6 T2500G-10TS(config-if)#gvrp timer leaveall 2000 T2500G-10TS(config-if)#no gvrp timer join 18.5 show gvrp interface Description The show gvrp interface command is used to display the GVRP configuration information of - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 154
18.6 show gvrp global Description The show gvrp global command is used to display the global GVRP status. Syntax show gvrp global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global GVRP status: T2500G-10TS(config)#show gvrp global 134 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 155
. Example Enable IGMP Snooping function: T2500G-10TS(config)# ip igmp snooping 19.2 ip igmp snooping version Description The ip igmp snooping version command is used to configure IGMP version globally. To return to the default configuration, please use no ip igmp snooping version command. Syntax - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 156
version as v2: T2500G-10TS (config)# ip igmp snooping version v2 19.3 ip igmp snooping drop-unknown Description The ip igmp snooping drop-unknown command is used to configure the way how the switch processes multicast streams that are sent to unknown multicast groups as Discard. By default, it is - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 157
Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable IGMP Header Validation: T2500G-10TS(config)# ip igmp snooping header-validation 19.5 ip igmp snooping vlan-config Description The ip igmp snooping vlan-config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 158
the default Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP Snooping function and modify Router Port Aging Time as 300 seconds, Member Port Aging Time as 200 seconds for VLAN 1-3: T2500G-10TS(config)# ip - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 159
5. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Fast Leave for VLAN 1-3: T2500G-10TS(config)# ip igmp snooping vlan-config 1-3 immediate-leave 19.7 ip igmp snooping vlan-config (report - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 160
Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP Report Suppression for VLAN 1-3: T2500G-10TS(config)# ip igmp snooping vlan-config 1-3 report-suppression 19.8 ip igmp snooping vlan-config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 161
discarded. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in VLAN 1 : T2500G-10TS(config)# ip igmp snooping vlan-config 1 router-ports-forbidd - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 162
. Example Set the router port as 1/0/1 for VLAN 1-2: T2500G-10TS(config)# ip igmp snooping vlan-config 1-2 rport interface gigabitEthernet 1/0/1 19.10 ip igmp snooping vlan-config (static) Description This command is used to configure interfaces to statically join a multicast group. To remove - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 163
Example Configure port ports 1/0/1-3 in VLAN 2 to statically join multicast group 225.0.0.1: T2500G-10TS(config)# ip igmp snooping vlan-config 2 static 225.0.0.1 interface gigabitEthernet 1/0/1-3 19.11 ip igmp snooping vlan-config (querier) Description This command is used to enable the IGMP - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 164
default value is 1 second. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP Snooping Querier for VLAN 3, and configure the query interval as 100 seconds: T2500G-10TS(config)# ip igmp - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 165
Example Enable IGMP Snooping function of port 1/0/3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# ip igmp snooping 19.13 ip igmp snooping max-groups Description The ip igmp snooping max-groups command is used to configure the maximum number of groups that a port can - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 166
numbers of groups that ports 1/0/2-5 can join as 10, and configure the throttling action as replace: T2500G-10TS(config)#interface range gigabitEthernet 1/0/2-5 T2500G-10TS(config-if-range)#ip igmp snooping max-groups 10 T2500G-10TS(config-if-range)#ip igmp snooping max-groups action replace 19.14 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 167
RADIUS server is configured. For how to enable AAA function and configure RADIUS server, please refer to aaa enable and radius-server host. Example Enable IGMP authentication on port 1/0/3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# ip igmp snooping authentication - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 168
User level users have access to these commands. Example Enable IGMP accounting globally: T2500G-10TS(config)# ip igmp snooping accounting 19.17 ip igmp profile Description The ip igmp profile command is used to create the configuration profile. To delete the corresponding profile, please use no - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 169
Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the filtering mode of profile 1 as deny: T2500G-10TS(config)# ip igmp profile 1 T2500G-10TS(config-igmp-profile)#deny 19.19 permit Description The permit command is used to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 170
access to these commands. Example Configure one of the filter multicast address entry as range 225.1.1.1 to 226.3.2.1 in profile 1: T2500G-10TS(config)# ip igmp profile 1 T2500G-10TS(config-igmp-profile)#range 225.1.1.1 226.3.2.1 19.21 ip igmp filter Description The ip igmp filter command is used - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 171
User level users have access to these commands. Example Clear the statistics of the IGMP packets: T2500G-10TS(config)# clear ip igmp snooping statistics 19.23 show ip igmp snooping Description The show ip igmp snooping command is used to display the global configuration of IGMP snooping. Syntax show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 172
Requirement None. Example Display the IGMP baisic configuration configuration of all ports and port channels: T2500G-10TS# show ip igmp snooping interface basic-config Display the IGMP basic configuration of port 1/0/2: T2500G-10TS# show ip igmp snooping interface gigabitEthernet 1/0/2 basic-config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 173
T2500G-10TS# show ip igmp snooping interface gigabitEthernet 1/0/1-4 packet-stat 19.25 show ip igmp snooping vlan Description The show ip igmp snooping vlan command is used to display the VLAN configuration of IGMP snooping. Syntax show ip igmp snooping vlan [ vlan-id ] Parameter vlan-id --The VLAN - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 174
count Display the count of static multicast entries of VLAN 5 T2500G-10TS(config)#show ip igmp snooping groups vlan 5 static count 19.27 show ip igmp profile Description The show ip igmp profile command is used to display the configuration information of all the profiles or a specific profile. 154 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 175
Syntax show ip igmp profile [ id ] Parameter id -- Specify the ID of the profile, ranging from 1 to 999. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of all profiles: T2500G-10TS(config)# show ip igmp profile - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 176
command. Syntax ipv6 mld snooping no ipv6 mld snooping Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable MLD Snooping: T2500G-10TS(config)# ipv6 mld snooping 20.2 ipv6 mld snooping drop-unknown Description - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 177
T2500G-10TS(config)# ipv6 mld snooping drop-unknown 20.3 ipv6 mld snooping vlan-config Description The ipv6 mld snooping vlan-config command is used to enable VLAN vlan-config vlan-id-list [ rtime | mtime | ltime ] Parameter vlan-id-list -- The ID list of the VLAN desired to modify configuration, - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 178
Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the MLD Snooping function and modify Router Port Time as 300 seconds, Member Port Time as 200 seconds for VLAN 1-3: T2500G-10TS(config)# ipv6 mld snooping vlan-config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 179
, in the format of 1-3, 5. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the MLD Report Suppression for VLAN 1-3: T2500G-10TS(config)# ipv6 mld snooping vlan-config 1-3 report-suppression 159 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 180
discarded. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Forbid the Ethernet ports 1/0/1-3 as being router ports in VLAN 1: T2500G-10TS(config)# ipv6 mld snooping vlan-config 1 router-ports-forbidd - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 181
commands. Example Set the router port as 1/0/1 for VLAN 1-2: T2500G-10TS(config)# ipv6 mld snooping vlan-config 1-2 rport interface gigabitEthernet 1/0/1 20.8 ipv6 mld snooping vlan-config (static) Description This command is used to configure interfaces to statically join a multicast group. To - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 182
Only Admin, Operator and Power User level users have access to these commands. Example Configure port ports 1/0/1-3 in VLAN 2 to statically join multicast group 225.0.0.1: T2500G-10TS(config)# ipv6 mld snooping vlan-config 2 static 225.0.0.1 interface gigabitEthernet 1/0/1-3 20.9 ipv6 mld snooping - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 183
source-ip | last-listener-query-count | last-listener-query-interval ] Parameter vlan-id-list -- The ID list of the VLAN desired to modify configuration, ranging are from 10 to 300 seconds, and the default value is 60 seconds. ip-addr-- The source IP address of the general query messages sent by the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 184
Example Enable the MLD Snooping Querier for VLAN 3, and configure the query interval as 100 seconds: T2500G-10TS(config)# ipv6 mld snooping vlan-config 3 querier T2500G-10TS(config)# ipv6 mld snooping vlan-config 3 querier query interval 100 20.10 ipv6 mld snooping (interface) Description The ipv6 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 185
the port can join. It ranges from 0 to 1000 and the default value is 1000. drop -- When the number of the dynamic multicast configure the throttling action as replace: T2500G-10TS(config)#interface range gigabitEthernet 1/0/2-5 T2500G-10TS(config-if-range)#ipv6 mld snooping max-groups 10 T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 186
the Fast Leave function for port 1/0/3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# ipv6 mld snooping immediate-leave 20.13 ipv6 mld profile Description The ipv6 mld profile command is used to create the configuration profile. To delete the corresponding profile - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 187
Operator level users have access to these commands. Example Configure the filtering mode of profile 1 as deny: T2500G-10TS(config)# ipv6 mld profile 1 T2500G-10TS(config-MLD-profile)#deny 20.15 permit Description The permit command is used to configure the filtering mode of profile as permit. Syntax - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 188
mld profile 1 T2500G-10TS(config-igmp-profile)#permit 20.16 range Description The range command is used to configure the range of the profile's filtering multicast address. To delete the corresponding filtering multicast address, please use no range command. A profile contains 16 filtering IP-range - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 189
1/0/2 T2500G-10TS(config-if)# ipv6 mld filter 1 20.18 clear ipv6 mld snooping statistics Description The clear ipv6 mld snooping statistics command is used to clear the statistics of the MLD packets. Syntax clear ipv6 mld snooping statistics Command Mode Privileged EXEC Mode and Any Configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 190
of MLD Snooping. Syntax show ipv6 mld snooping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of MLD Snooping: T2500G-10TS(config)# show ipv6 mld snooping 20.20 show ipv6 mld snooping interface Description The show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 191
. Syntax show ipv6 mld snooping vlan [ vlan-id ] Parameter vlan-id -- The VLAN ID selected to display, ranging from 1 to 4094. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display all of the VLAN information: T2500G-10TS(config)# show ipv6 mld - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 192
[ vlan { vlan-id } ] [ ipv6_multicast_addr | count | dynamic | dynamic count | static | static count ] Parameter vlan-id --The VLAN ID Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display all of the multicast groups: T2500G-10TS(config)# show ipv6 mld snooping - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 193
Parameter id -- Specify the ID of the profile, ranging from 1 to 999. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of all profiles: T2500G-10TS(config)# show ipv6 mld profile 173 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 194
VLANs, a copy of the multicast streams is sent to each VLAN that has member ports. While MVR provides a dedicated multicast VLAN to Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable MVR globally: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 195
T2500G-10TS (config)# mvr group 225.1.2.3 3 21.3 mvr mode Description The mvr mode command is used to configure the MVR mode as compatible or dynamic. By default, it is compatible. To return to the default configuration via the multicast VLAN (with appropriate translation of the VLAN ID). So the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 196
as dynamic: T2500G-10TS(config)# mvr mode dynamic 21.4 mvr querytime Description The mvr querytime command is used to configure the maximum time to wait for IGMP report on a receiver port before removing the port from multicast group membership. To return to the default configuration, please use - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 197
access to these commands. Example Configure the multicast VLAN as VLAN 10: T2500G-10TS(config)# mvr vlan 10 21.6 mvr (interface) Description This command is used to enable MVR for specific interfaces. To disable MVR for the interfaces, please use no mvr command. By default, it is disabled. Syntax - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 198
Enable MVR for port 1/0/1: T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#mvr 21.7 mvr type Description The mvr type command is used to configure the MVR port type as receiver or source. By default, the port is a non-MVR port. If you attempt to configure a non-MVR port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 199
support Fast Leave. Before enabling Fast Leave for a port, make sure there is only a single receiver device connecting to the port. Example Enable the Fast Leave feature of MVR for port 1/0/3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)#mvr immediate 21.9 mvr vlan - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 200
to MVR group 225.1.2.3 statically. The multicast VLAN is VLAN 10: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)#mvr vlan 10 group 225.1.2.3 21.10 show mvr Description The show mvr command is used to display the global configuration of MVR. Syntax show mvr Command Mode - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 201
the MVR configuration of port 1/0/3: T2500G-10TS# show mvr interface gigabitEthernet 1/0/3 21.12 show mvr members Description The show mvr members command is used to display the membership information of all MVR groups or the specified MVR group. Syntax show mvr members [ ip-addr ] Parameter ip-addr - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 202
mvr traffic command is used to display the statistics information of all MVR groups. Syntax show mvr traffic Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the statistics information of all MVR groups: T2500G-10TS# show mvr traffic 182 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 203
Tree Protocol), compatible with both STP and RSTP and subject to IEEE 802.1s, can disbranch a ring network. STP is to block redundant links and backup links as well as optimize paths. 22.1 debug spanning-tree Description The debug spanning-tree command is used to enable debuggning of spanning-tree - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 204
. Syntax spanning-tree no spanning-tree Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the STP function: T2500G-10TS(config)# spanning-tree 22.3 spanning-tree (interface) Description The - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 205
1/0/2 T2500G-10TS(config-if)# spanning-tree 22.4 spanning-tree common-config Description The spanning-tree common-config command is used to configure the parameters of the ports for comparison in the CIST and the common parameters of all instances. To return to the default configuration, please - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 206
1/0/1 T2500G-10TS(config-if)# spanning-tree common-config port-priority 64 ext-cost 100 int-cost 100 portfast enable point-to-point open 22.5 spanning-tree mode Description The spanning-tree mode command is used to configure the STP mode of the switch. To return to the default configurations, please - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 207
spanning-tree mode as mstp: T2500G-10TS(config)# spanning-tree mode mstp 22.6 spanning-tree mst configuration Description The spanning-tree mst configuration command is used to access MST Configuration Mode from Global Configuration Mode, as to configure the VLAN-Instance mapping, region name and - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 208
remove all the mapping VLANs 1-100: T2500G-10TS(config)# spanning-tree mst configuration T2500G-10TS(config-mst)# no instance 1 Remove VLANs 1-50 in mapping VLANs 1-100 for Instance 1: T2500G-10TS(config)# spanning-tree mst configuration T2500G-10TS(config-mst)# no instance 1 vlan 1-50 22.8 name - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 209
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the region name of MST as "region1": T2500G-10TS(config)# spanning-tree mst configuration T2500G-10TS(config-mst)# name region1 22.9 revision Description The revision command is used to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 210
the MST Instance 1 and configure its priority as 4096: T2500G-10TS(config)# spanning-tree mst instance 1 priority 4096 22.11 spanning-tree mst Description The spanning-tree mst command is used to configure MST Instance Port. To return to the default configuration of the corresponding Instance Port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 211
as 2000: T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)# spanning-tree mst instance 1 port-priority 64 cost 2000 22.12 spanning-tree priority Description The spanning-tree priority command is used to configure the bridge priority. To return to the default value of bridge - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 212
the bridge priority as 4096: T2500G-10TS(config)# spanning-tree priority 4096 22.13 spanning-tree timer Description The spanning-tree timer command is used to configure forward-time, hello-time and max-age of Spanning Tree. To return to the default configurations, please use no spanning-tree - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 213
, ranging from 1 to 20 in pps. By default, it is 5. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the hold-count of STP as 8pps: T2500G-10TS(config)# spanning-tree hold-count 8 22.15 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 214
discarded, ranging from 1 to 40 in hop. By default, it is 20. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the max-hops of STP as 30: T2500G-10TS(config)# spanning-tree max-hops 30 22.16 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 215
bpduflood no spanning-tree bpduflood Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / Enable the BPDU forward function for port 1/0/2: T2500G-10TS(config)# interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# spanning-tree bpduflood 22.18 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 216
Configuration Mode T2500G-10TS(config-if)# spanning-tree bpduguard 22.19 spanning-tree guard loop Description The spanning-tree guard loop command is used to enable the Loop Protect function for a port. Loop Protect is to prevent the loops in the network brought by recalculating STP because of link - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 217
no spanning-tree guard root Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet /interface Example Enable the Root Protect function for port 2: T2500G-10TS(config)# interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# spanning-tree guard root 22.21 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 218
Tree for port 2: T2500G-10TS(config)# interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# spanning-tree guard tc 22.22 spanning-tree mcheck Description The spanning-tree mcheck command is used to enable mcheck. Syntax spanning-tree mcheck Command Mode Interface Configuration Mode (interface - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 219
of spanning-tree. Syntax show spanning-tree active Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the active information of spanning-tree: T2500G-10TS(config)# show spanning-tree active 22.24 show spanning-tree bridge Description The show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 220
number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the spanning-tree information of all ports: T2500G-10TS(config)# show spanning-tree interface Display the spanning-tree information of port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 221
number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the protect information of all ports: T2500G-10TS(config)# show spanning-tree interface-security Display the protect information of port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 222
Privilege Requirement None. Example Display the region information and mapping information of VLAN and MST Instance: T2500G-10TS(config)#show spanning-tree mst configuration Display the related information of MST Instance 1: T2500G-10TS(config)#show spanning-tree mst instance 1 Display all the ports - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 223
lldp command. Syntax lldp no lldp Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable LLDP function globally: T2500G-10TS(config)#lldp 23.2 lldp forward_message Description The lldp forward_message - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 224
the Hold Multiplier parameter. It ranges from 2 to 10. By default, it is 4. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify Hold Multiplier as 5: T2500G-10TS(config)#lldp hold-multiplier 5 204 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 225
the interval for the local device to transmit LLDPDU to its neighbors. The value ranges from 5 to 32768 and the default value is 30 seconds. tx-delay -- Configure a value from 1 to 8192 in seconds to specify the time for the local device to transmit LLDPDU to its neighbors after changes occur - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 226
45 T2500G-10TS(config)#lldp timer notify-interval 120 23.5 lldp receive Description The lldp receive command is used to enable the designated port to receive LLDPDU. To disable the function, please use no lldp receive command. Syntax lldp receive no lldp receive Command Mode Interface Configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 227
Enable Gigabit Ethernet port 1/0/1 to transmit LLDPDU: T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#lldp transmit 23.7 lldp snmp-trap snmp-trap no lldp snmp-trap Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernetinterface / - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 228
outgoing from Gigabit Ethernet port 1/0/1: T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)# no lldp tlv-select management-address port-vlan 23.9 lldp management-address Description The lldp management-address command is used to configure the port's management address to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 229
ip-address } no lldp management-address Command Mode Interface Configuration Configure the port's management address as 192.168.1.100 for port 1/0/1: T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS parameter. The default value is 4. To return to the default configuration, please use - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 230
1/0/2 T2500G-10TS(config-if)# lldp med-status 23.12 lldp med-tlv-select Description The lldp med-tlv-select command is used to configure LLDP-MED TLVs to be included in outgoing LLDPDU for the corresponding port. To exclude LLDP-MED TLVs, please use no lldp med-tlv-select command. By default, All - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 231
T2500G-10TS(config)# interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# no lldp med-tlv-select network-policy inventorymanagement 23.13 lldp med-location Description The lldp med-location command is used to configure Call Service ELIN identifier, which is used during emergency call setup to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 232
the civic address in the Location Identification TLV's content in outgoing LLDPDU of port 1/0/2. Configure the language as English and city as London: T2500G-10TS(config)# interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# lldp med-location civic-address language English lci-city London 23.14 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 233
the LLDP configuration of Gigabit Ethernet port 1/0/1: T2500G-10TS#show lldp interface gigabitEthernet 1/0/1 23.16 show lldp local-information interface Description The show lldp local-information interface command is used to display the LLDP information of the corresponding port. By default, the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 234
-- The Ethernet port number. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the neighbor information of Gigabit Ethernet port 1/0/1: T2500G-10TS#show lldp neighbor-information interface gigabitEthernet 1/0/1 23.18 show lldp traffic interface - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 235
Parameters port -- The Ethernet port number. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the LLDP statistic information of Gigabit Ethernet port 1/0/1: T2500G-10TS#show lldp traffic interface gigabitEthernet 1/0/1 215 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 236
Tunneling) is a feature for service providers to transmit packets from different customers across their ISP networks and maintain Layer 2 protocol configurations of each customer. The supported Layer 2 protocols are STP (Spanning Tree Protocol), GVRP (GARP VLAN Registration Protocol), CDP (Cisco - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 237
for the STP packets. lacp: Enable protocol tunneling for the LACP packets. • all: All the above Layer 2 protocols are supported for tunneling. threshold --Configure the threshold for packets-per-second accepted for encapsulation. Packets beyond the threshold will be dropped. It ranges from 0 to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 238
L2PT status. Syntax show l2protocol-tunnel global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global L2PT status: T2500G-10TS(config)# show l2protocol-tunnel global 24.4 show l2protocol-tunnel interface Description The show l2protocol - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 239
Requirement None. Example Display the L2PT configuration information of Gigabit Ethernet port 1/0/1: T2500G-10TS(config)#show l2protocol-tunnel interface gigabitEthernet 1/0/1 Display the L2PT configuration information of all Ethernet ports: T2500G-10TS(config)#show l2protocol-tunnel interface 219 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 240
-insertion command. Syntax pppoe id-insertion no pppoe id-insertion Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the PPPoE ID-Insertion function: T2500G-10TS(config)# pppoe id-insertion 220 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 241
T2500G-10TS (config)# interface gigabitEthernet 1/0/1 T2500G-10TS (config-if)# pppoe circuit-id 25.3 pppoe circuit-id type Description The pppoe circuit-id type command is used to configure the type of PPPoE Circuit-ID for a specified port. By default, the PPPoE Circuit-ID type is "ip". Syntax - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 242
ip: The IP address of the switch will be used to encode the Circuit-ID option. This is the default value. udf: A user specified . Example Configure the type of PPPoE Circuit-ID as "mac" for the Gigabit Ethernet port 1/0/1: T2500G-10TS (config)# interface gigabitEthernet 1/0/1 T2500G-10TS (config-if - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 243
Admin, Operator and Power User level users have access to these commands. Example Configure the remote-ID as "mac" for the Gigabit Ethernet port 1/0/1: T2500G-10TS (config)# interface gigabitEthernet 1/0/1 T2500G-10TS (config-if)# pppoe remote-id mac 25.5 show pppoe id-insertion global Description - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 244
information of PPPoE Circuit-ID Insertion function of all Ethernet ports: T2500G-10TS# show pppoe id-insertion interface Display the configuration of PPPoE Circuit-ID Insertion function of the Gigabit Ethernet port 1/0/1 : T2500G-10TS# show pppoe id-insertion interface gigabitEthernet 1/0/1 224 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 245
command. Syntax service dhcp relay no service dhcp relay Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable DHCP Relay function globally: T2500G-10TS(config)# service dhcp relay 26.2 ip dhcp relay - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 246
1 to 16, and the default value is 4. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the maximum number of relay hops as 6: T2500G-10TS(config)# ip dhcp relay hops 6 26.3 ip dhcp relay time - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 247
Configure the DHCP Relay time as 30 seconds: T2500G-10TS(config)# ip dhcp relay time 30 26.4 ip dhcp relay vlan Description The ip dhcp relay vlan command is used to add DHCP Server address to the vlan interface. To delete the server address, please use no ip helper-address command. Syntax ip - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 248
access to these commands. Example Enable option 82 support in DHCP Relay for port 2: T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# ip dhcp relay information 26.6 ip dhcp relay information strategy Description The ip dhcp relay information strategy command is used to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 249
-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# ip dhcp relay information strategy replace 26.7 ip dhcp relay information format Description The ip dhcp relay information format command is used to select the format of option 82 sub-option value field. To restore to the default - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 250
commands. Example Specify the circuit ID as "TP-Link" for port 2: T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# ip dhcp relay information circuit-id TP-Link 26.9 ip dhcp relay information remote-id Description The ip dhcp relay information remote-id command is used - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 251
T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# ip dhcp relay information remote-id TP-Link 26.10 ip dhcp relay default-interface Description The ip dhcp relay default-interface command is used to configure default relay agent interface. When the switch works at DHCP VLAN - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 252
Example Configure interface VLAN 1 as the default relay agent interface: T2500G-10TS(config)# interface vlan 1 T2500G-10TS(config-if)# ip dhcp relay default-interface 26.11 show ip dhcp relay Description The show ip dhcp relay command is used to display the global status and Option 82 configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 253
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable DHCP L2 Relay function globally: T2500G-10TS(config)# ip dhcp l2relay 27.2 ip dhcp l2relay vlan Description The ip dhcp l2relay vlan command is - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 254
users have access to these commands. Example Enable DHCP L2 Relay for VLAN 2: T2500G-10TS(config)# ip dhcp l2relay vlan 2 27.3 ip dhcp l2relay information Description The ip dhcp l2relay information command is used to enable option 82 support in DHCP Relay. To disable this function, please use no - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 255
1/0/2 T2500G-10TS(config-if)# ip dhcp l2relay information strategy replace 27.5 ip dhcp l2relay information format Description The ip dhcp l2relay information format command is used to select the format of option 82 sub-option value field. To restore to the default option, please use no ip dhcp - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 256
is the value you configure for the related sub-option. Command Mode Interface Configuration Mode (interface fastEthernet T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)#ip dhcp l2relay information format normal 27.6 ip dhcp l2relay information circuit-id Description The ip - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 257
ID as "TP-Link" for port 2: T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)# ip dhcp l2relay information remote-id TP-Link 27.8 show ip dhcp l2relay Description The show ip dhcp l2relay command is used to display the global status and Option 82 configuration of DHCP Relay - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 258
l2relay Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of DHCP Relay: T2500G-10TS(config)# show ip dhcp l2relay 27.9 show ip dhcp l2relay interface Description The show ip dhcp l2relay interface command is used to display - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 259
Description The qos trust mode command is used to configure the trust mode of CoS (Class of Service) function for the ports. The default trust mode is trust port priority. Syntax qos trust as dscp: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# qos trust mode dscp 239 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 260
the priority of port 5 as 3: T2500G-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# qos port-priority 3 28.3 qos cos-map Description The qos cos-map command is used to configure 802.1p to queue mapping globally. To return to the default configuration, please use no qos cos-map - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 261
these commands. Example Map the 802.1p priority 5 to TC-2: T2500G-10TS (config)# qos cos-map 5 2 28.4 qos dot1p-remap Description The qos dot1p-remap command is used to configure the 802.1p to 802.1p mappings. To return to the default configuration, please use no qos dot1p-remap command. When 802.1p - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 262
. Example Remap 802.1p priority 5 to 802.1p priority 6: T2500G-10TS(config)#qos dot1p-remap 5 6 28.5 qos dscp-map Description The qos dscp-map command is used to configure the DSCP to 802.1p mapping. To return to the default configuration, please use no qos dscp-map command. DSCP (DiffServ Code - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 263
Example Map DSCP Priority 5 to 802.1p priority 2: T2500G-10TS(config)#qos dscp-map 5 2 28.6 qos dscp-remap Description The qos dscp-remap command is used to configure the DSCP to DSCP mappings. To return to the default configuration, please use no qos dscp-remap command. When DSCP remap is - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 264
you need to specify the queue weight at the same time. weight -- Configure the weight value of the specified TC queue. When the scheduler mode is set the queue weight as 10 for port 1/0/1: T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)# qos queue 1 mode wrr weight 10 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 265
to 802.1p priority mappings. Syntax show qos dot1p-remap Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the IEEE 802.1P remap configuration: T2500G-10TS# show qos dot1p-remap 28.10 show qos dscp-map Description The show qos dscp-map command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 266
priority to DSCP priority mappingss. Syntax show qos dscp-remap Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DSCP to DSCP mappings: T2500G-10TS# show qos dscp-remap 28.12 show qos port-priority interface Description The show qos port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 267
. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the trust mode of all the ports: T2500G-10TS# show qos trust interface 28.14 show qos queue interface Description The show qos queue interface - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 268
Parameter port -- The port number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the scheduler settings of all the ports: T2500G-10TS# show qos queue interface 248 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 269
storm-control rate-mode command is used to configure the storm control mode of the interface. To return to the default configuration, please use no storm-control rate-mode command on port 1/0/5: T2500G-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# storm-control rate-mode kbps - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 270
levels on an interface. To return to the default configuration, please use no storm-control command. Syntax Configure the broadcast storm control rate as 1024 kbps on port 1/0/5: T2500G-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# storm-control rate-mode kbps T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 271
to 3600 and the default value is 0. When Configure the action as drop on port 1/0/5: T2500G-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# storm-control exceed drop 29.4 storm-control recover Description The storm-control recover command is used to recover the port manually - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 272
users have access to these commands. Example Recover port 1/0/5 manually: T2500G-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# storm-control recover 29.5 bandwidth Description The bandwidth command is used to configure the bandwidth limit for an Ethernet port. To disable the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 273
Admin, Operator and Power User level users have access to these commands. Example Configure the ingress-rate as 5120Kbps and egress-rate as 1024Kbps for port 1/0/5: T2500G-10TS(config)# interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)# bandwidth ingress 5120 egress 1024 29.6 show storm-control - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 274
list of Ethernet ports. port-channel-id-list -- The list of port channels. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the bandwidth-limit information of port 1/0/4: T2500G-10TS(config)# show bandwidth interface gigabitEthernet 1/0/4 254 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 275
. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Voice VLAN function for VLAN 10: T2500G-10TS(config)# voice vlan 10 30.2 voice vlan (interface) Description The voice vlan command is used - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 276
Enable the Voice VLAN function for port 1/0/1: T2500G-10TS(config)# interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#voice vlan 30.3 voice vlan priority Description The voice vlan priority command is used to configure the priority for the Voice VLAN. To restore to the default priority, please - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 277
a Voice VLAN OUI described as TP-Phone with the OUI address 00:11:11:11:11:11 and the mask address FF:FF:FF:00:00:00: T2500G-10TS(config)#voice vlan oui 00:11:11 oui-desc TP-Phone 30.5 show voice vlan Description The show voice vlan command is used to display the global configuration information of - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 278
commands. Example Display the configuration information of Voice VLAN globally: T2500G-10TS(config)# show voice vlan 30.6 show voice vlan oui-table Description The show voice vlan oui command is used to display the configuration information of Voice VLAN OUI. Syntax show voice vlan oui Command Mode - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 279
Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Display the Voice VLAN configuration information of all ports and port channels: T2500G-10TS(config)# show voice vlan interface 259 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 280
can help ensure that the sound quality of an IP phone does not deteriorate when data traffic on Configuration Mode Example Enable the Auto VoIP function globally: T2500G-10TS(config)# auto-voip 31.2 auto-voip (interface) Description The auto-voip command is used to specify the interface mode as VLAN - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 281
Configuration Mode (interface fastEthernet / interface range fastEthernet /interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Example Set Auto VoIP VLAN 3 for port 3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 282
T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# auto-voip untagged 31.5 auto-voip none Description The auto-voip none command is used to specify the interface mode as none for the ports. In this mode, the switch allows the voice devices to use its own configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 283
Example Instruct voice devices that are connected to port 3 to send the packets according to its own configuration: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# auto-voip none 31.6 no auto-voip (interface) Description The no auto-voip command is used to specify the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 284
By default, it is 0. Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet /interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Example Set DSCP value of Auto VoIP on port 3 as 33: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 285
the Auto VoIP configuration information of ports. When no parameter is entered, displays the global Auto VoIP configuration information. Command Mode Privileged EXEC Mode and any Configuration Mode Example Displays the global Auto VoIP configuration information: T2500G-10TS (config)# show auto - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 286
level users have access to these commands. Example Configure the access control mode as IP-based: T2500G-10TS(config)# user access-control ip-based enable 32.2 user access-control ip-based Description The user access-control ip-based command is used to limit the IP-range of the users for login. Only - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 287
enabled by default. id -- Delete the specified IP-based entry. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the access-control of the user whose IP address is 192.168.0.148: T2500G-10TS(config)# user - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 288
entry to be deleted. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure that only the user whose MAC address is 00:00:13:0A:00:01 is allowed to login: T2500G-10TS(config)# user access-control mac-based 00 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 289
Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the access control mode as Port-based: T2500G-10TS(config)# user access-control port-based enable 32.6 user access-control port-based Description The user access-control port-based - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 290
by default. id-- Specify the ID of the port-based entry to be deleted. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure that only the users connected to ports 2-6 are allowed to login: T2500G-10TS(config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 291
by default. The HTTP and HTTPS server function cannot be disabled at the same time. Syntax ip http server no ip http server Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable the HTTP function: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 292
users have access to these commands. Example Set the port number of HTTP server as 1800: T2500G-10TS(config)# ip http port 1800 33.3 ip http max-users Description The ip http max-users command is used to configure the maximum number of users that are allowed to connect to the HTTP server. To cancel - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 293
as 5, 1, 1, 1 for HTTP: T2500G-10TS(config)# ip http max-users 5 1 1 1 33.4 ip http session timeout Description The ip http session timeout command is used to configure the connection timeout of the HTTP server. To restore to the default timeout time, please use no ip http session timeout command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 294
Disable the HTTP function: T2500G-10TS(config)# no ip http secure-server 33.6 ip http secure-port Description The ip http secure-port command is used to configure the port number of the HTTPS server within the switch. To set the number to the default value, please use no ip http secure-port command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 295
as 2800: T2500G-10TS(config)# ip http port 2800 33.7 ip http secure-protocol Description The ip http secure-protocol command is used to configure the SSL protocol version. To restore to the default SSL version, please use no ip http secure-protocol command. By default, the switch supports SSLv3 and - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 296
connection as SSL 3.0: T2500G-10TS(config)# ip http secure-protocol ssl3 33.8 ip http secure-ciphersuite Description The ip http secure-ciphersuite command is used to configure the cipherSuites over the SSL connection supported by the switch. To restore to the default ciphersuite types, please use - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 297
than 16. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the maximum number of the Admin, Operator, Power User and User as 5, 1, 1, 1 for HTTPs: T2500G-10TS(config)# ip http secure-max-users - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 298
in minutes. By default, the value is 10. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the timeout time of the HTTPs connection as 15 minutes: T2500G-10TS(config)# ip http secure-session - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 299
. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Download an SSL Certificate named ssl-cert from TFTP server with the IP address of 192.168.0.146: T2500G-10TS(config)# ip http secure-server download - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 300
from TFTP server with the IP address of fe80::1234 T2500G-10TS(config)# ip http secure-server download key ssl-key ip-address fe80::1234 33.13 show ip http configuration Description The show ip http configuration command is used to display the configuration information of the HTTP server, including - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 301
secure-server command is used to display the global configuration of SSL. Syntax show ip http secure-server Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of SSL: T2500G-10TS(config)# show ip http secure-server 281 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 302
to these commands. Example Enable the SSH function: T2500G-10TS(config)# ip ssh server 34.2 ip ssh port Description The ip ssh port command is used to configure the port for SSH service. To set the value to the default, please use no ip ssh port command. Syntax ip ssh port port no ip ssh port 282 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 303
from 1 to 65535. The default value is 22. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the SSH port number as 22: T2500G-10TS(config)# ip ssh port 22 34.3 ip ssh version Description The - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 304
as AES128-CBC: T2500G-10TS(config)# ip ssh algorithm AES128-CBC 34.5 ip ssh timeout Description The ip ssh timeout command is used to specify the idle-timeout time of SSH. To restore to the factory defaults, please use ip ssh timeout command. Syntax ip ssh timeout value no ip ssh timeout Parameter - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 305
as 30 seconds: T2500G-10TS(config)# ip ssh timeout 30 34.6 ip ssh max-client Description The ip ssh max-client command is used to specify the maximum number of the connections to the SSH server. To return to the default configuration, please use no ip ssh max-client command. Syntax ip ssh max-client - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 306
::1234. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Download an SSH-1 type key file named ssh-key from TFTP server with the IP address 192.168.0.148: T2500G-10TS(config)# ip ssh download v1 ssh - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 307
34.9 show ip ssh Description The show ip ssh command is used to display the global configuration of SSH. Syntax show ip ssh Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of SSH: T2500G-10TS(config)# show ip ssh 287 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 308
command. This function is enabled by default. Syntax telnet enable telnet disable Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable the Telnet function: T2500G-10TS(config)# telnet disable 35.2 telnet port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 309
level users have access to these commands. Example Configure the telnet port number as 566: T2500G-10TS(config)# telnet port 566 35.3 show telnet-status Description The show telnet-status command is used to display the configuration information of the Telnet function. Syntax show telnet-status - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 310
console port. The default baul rate is 38400 bps. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify the communication baud rate on the console port to the default value: T2500G-10TS(config)# no serial_port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 311
methods and their sequence to authenticate a user. The switch supports Login List for users to gain access to the switch, and Enable List for normal users to gain administrative privileges. RADIUS/TACACS+ Server User can configure the RADIUS/TACACS+ servers for the connection between the switch - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 312
are added in the server group "tacacs" by default. Example Configure a TACACS+ server with the IP address as 1.1.1.1, TCP port as 1500, timeout as 6 seconds, and the unencrypted key string as 12345. T2500G-10TS(config)# tacacs-server host 1.1.1.1 port 1500 timeout 6 key 12345 37.2 show tacacs - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 313
T2500G-10TS(config)# show tacacs-server 37.3 radius-server host Description The radius-server host command is used to configure ip-address Parameter ip-address -- Specify the IP address of the RADIUS server. auth-port port-id -- Specify the UDP destination port for authentication requests. By default - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 314
are added in the server group "radius" by default. Example Configure a RADIUS server with the IP address as 1.1.1.1, authentication port as 1200, timeout as 6 seconds, retransmit times as 3, and the unencrypted key string as 12345. T2500G-10TS(config)# radius-server host 1.1.1.1 auth-port 1200 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 315
type as RADIUS or TACACS+. group-name -- Specify the server group name. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Create a RADIUS server group with the name radius1: T2500G-10TS(config)# aaa group radius radius1 295 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 316
the server's IP address. Command Mode Server Group Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Create the RADIUS server 1.1.1.1 to RADIUS server group "radius1": T2500G-10TS(config)# aaa group radius radius1 T2500G-10TS(aaa-group)# server - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 317
to these commands. Example Display the information of all the server groups: T2500G-10TS(config)# show aaa group 37.8 aaa authentication login Description This aaa authentication login command is used to configure a login authentication method list. A method list describes the authentication methods - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 318
to these commands. User Guidelines By default the login authentication method list is "default" with "local" as method1. Example Configure a login authentication method list "list1" with the priority1 method as radius and priority2 method as local: T2500G-10TS(config)# aaa authenticaiton login list1 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 319
group is supported, and the default method is server group "radius". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the default 802.1x authentication method as "radius1": T2500G-10TS(config)# aaa authentication - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 320
server group is supported, and the default method is server group "radius". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the default 802.1x accounting method as "radius1": T2500G-10TS(config)# aaa accounting - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 321
to these commands. Example Display the information of the default 802.1x accounting method list: T2500G-10TS(config)# show aaa accounting 37.14 line telnet Description The line telnet command is used to enter the Line Configuration Mode to configure the telnet terminal line to which you want to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 322
" by default, which contains the method "local". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the telnet terminal line as "list1": T2500G-10TS(config)#line telnet T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 323
Enter the ssh terminal line configuration mode: T2500G-10TS(config)#line ssh 37.17 login authentication (ssh) Description The login authentication command is used to apply the login authentication method list to the ssh terminal line. To restore to the default authentication method list, please use - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 324
" by default, which contains the method "none". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the enable authentication method list on the telnet terminal line as "list2": T2500G-10TS(config)#line telnet T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 325
by default, which contains the method "none". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the enable authentication method list on the ssh terminal line as "list2": T2500G-10TS(config)# line ssh T2500G-10TS(config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 326
. It is "default" by default, which contains the method "local". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the HTTP access as "list1": T2500G-10TS(config)# ip http login - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 327
Example Configure the enable authentication method list on the HTTP access as "list2": T2500G-10TS(config)# ip http enable authentication list2 37.22 show aaa global Description This show aaa global command is used to display global status of AAA function and - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 328
Privilege Requirement Only User, Power User and Operator level users have access to these commands. Example Get the administrative privelges (the Enable password is "123456"): T2500G-10TS# enable-admin Password: 123456 308 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 329
the supplicant. It is usually an 802.1x-supported network device, such as this TP-Link switch. It acts as an intermediary (proxy Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IEEE 802.1x function: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 330
commands. Example Disable the 802.1x handshake function: T2500G-10TS(config)# no dot1x handshake 38.3 dot1x auth-protocol Description The dot1x auth-protocol command is used to configure the authentication protocol of IEEE 802.1x and the default 802.1x authentication method is "eap". To restore - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 331
have access to these commands. Example Configure the Authentication protocol of IEEE 802.1x as "pap": T2500G-10TS(config)#dot1x auth-protocol pap 38.4 dot1x vlan-assignment Description The dot1x vlan-assignment command is used to enable the VLAN assignment feature.To disable this feature, please - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 332
Syntax dot1x vlan-assignment no dot1x vlan-assignment Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the VLAN assignment feature: T2500G-10TS(config)#dot1x vlan-assignment 38.5 dot1x - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 333
. Example Enable the MAB feature on the Gigabit Ethernet port 1/0/1: T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#dot1x mab 38.7 dot1x guest-vlan Description The dot1x guest-vlan command is used to configure the Guest VLAN function on the port. To disable the Guest - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 334
Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Guest VLAN function for VLAN 5 and set the VLAN ID as 20 on the Gigabit Ethernet port 1/0/1: T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 335
Ethernet port 1/0/1: T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#dot1x quiet-period 5 38.9 dot1x timeout supp-timeout Description The dot1x timeout supp-timeout command is used to configure the supplicant timeout on the port.To restore to the default, please use no - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 336
gigabitEthernet 1/0/1 T2500G-10TS(config-if)#dot1x timeout supp-timeout 5 38.10 dot1x max- req Description The dot1x max-req command is used to configure the maximum transfer times of the repeated authentication request when the server cannot be connected. To restore to the default value, please - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 337
for the Gigabit Ethernet port 1: T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#dot1x 38.12 dot1x port-control Description The dot1x port-control command is used to configure the Control Mode of IEEE 802.1x for the specified port. By default, the control mode is "auto - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 338
"authorized-force": T2500G-10TS(config)#interface gigabitEthernet 1/0/20 T2500G-10TS(config-if)#dot1x port-control authorized-force 38.13 dot1x port-method Description The dot1x port-method command is used to configure the control type of IEEE 802.1x for the specified port. By default, the control - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 339
Admin, Operator and Power User level users have access to these commands. Example Configure the Control Type for Gigabit Ethernet port 20 as "port-based": T2500G-10TS(config)#interface gigabitEthernet 1/0/20 T2500G-10TS(config-if)#dot1x port-method port-based 38.14 dot1x auth-init Description The - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 340
client whose MAC address is a 00:02:58:4f:6c:23 on port 1: T2500G-10TS(Config)# interface gigabitEthernet 1/0/1 T2500G-10TS(Config-if)#dot1x auth-reauth mac 00:02:58:4f:6c:23 38.16 show dot1x global Description The show dot1x global command is used to display the global configuration of 801.X. 320 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 341
Syntax show dot1x global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of 801.X globally: T2500G-10TS(config)#show dot1x global 38.17 show dot1x interface Description The show dot1x interface command is used to display all - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 342
of each port. Syntax show dot1x auth-state [ interface fastEthernet port | interface gigabitEthernet port] Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the authentication status of each port: T2500G-10TS(config)#show dot1x auth-state 322 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 343
security feature of the port and configure the related parameters. To disable the feature and restore the parameters to defaults on the port, please use feature and configure the mode as permanent and the status as drop: T2500G-10TS (config)#interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#mac - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 344
port | gigabitEthernet port | ten-gigabitEthernet port } Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the port security configuration on port 1/0/1 T2500G-10TS# show mac address-table max-mac-count interface gigabitEthernet 1/0/1 324 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 345
troubleshooting the network. 40.1 monitor session destination interface Description The monitor session destination interface command is used to configure . Example Create monitor session 1 and configure port 1/0/1 as the monitoring port: T2500G-10TS(config)# monitor session 1 destination interface - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 346
session 1 destination interface gigabitEthernet 1/0/2 Delete the monitor session 1: T2500G-10TS(config)# no monitor session 1 40.2 monitor session source Description The monitor session source command is used to configure the monitored interface. To delete the corresponding monitored interface - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 347
ports are in the same VLAN or not is not demanded strictly. 4. The monitoring port and monitored ports cannot be link-aggregation member. Example Create monitor session 1, then configure port 4, 5, 7 as monitored port and enable ingress monitoring: T2500G-10TS(config)# monitor session 1 source - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 348
Example Display the monitoring configuration of monitor session 1: T2500G-10TS(config)# show monitor session 1 328 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 349
Enter a name to identify the ACL. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create an IP ACL whose ID is 523: T2500G-10TS(config)# access-list create 523 41.2 access-list resequence Description - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 350
Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Resequence the rules of ACL 12 with the start ID as 1 and step value as 5: T2500G-10TS type ether-type] [pri dot1p-priority] [vid vlan-id] [tseg time-range-name] no access- - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 351
-range. The default is No Limit. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create MAC ACL 50 and configure Rule 5 to permit packets with source MAC address 00:34:a2:d4:34:b5: T2500G-10TS (config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 352
mask d-port-mask] [tcpflag tcpflag]] [tseg time-range-name] no access-list ip acl-id-or-name rule rule-id Parameter acl-id-or-name -- Enter the -- Specify the action to be taken with the packets that match the rule. By default, it is set to permit. The packets will be discarded if "deny" is selected - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 353
. The default is No Limit. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create IP ACL 600, and configure Rule 1 to permit packets with source IP address 192.168.1.100: T2500G-10TS (config)#access - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 354
a destination MAC address is entered. vlan-id: The VLAN ID ranges from 1 to 4094. ether-type -- Specify the Ethernet-type with 4 hexadecimal numbers. priority -- The user priority ranges from 0 to 7. The default is No Limit. source-ip: Enter the source IP address. source-ip-mask -- Enter the mask of - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 355
default is No Limit. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create Combined ACL 1100 and configure Rule 1 to deny packets with source IP address 192.168.3.100 in VLAN 2: T2500G-10TS(config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 356
permit -- Specify the action to be taken with the packets that match the rule. By default, it is set to permit. The packets will be discarded if "deny" is selected but only the first 64 bits will be valid. source-ip-mask -- Enter the source IP address mask. The mask is required if the source IPv6 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 357
an IPv6 ACL to a VLAN or interface, you should configure the SDM template as "enterpriseV6" and save your configurations. Example Create IPv6 ACL 1600 and configure Rule 1 to deny packets with source IPv6 address CDCD:910A:2222:5498:8475:1111:3900:2020: T2500G-10TS(config)# access-list create 1600 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 358
be redirected. The default is All. Command Mode Action Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Define the policy to redirect the matched packets to port 1/0/1 for rule 1 of ACL 6: T2500G-10TS(config)# access-list - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 359
specified rate. The default is None. Configure a policy for rule 1 of ACL 6: limit the transmission rate of the matched packets as 1000 Kbps and if the number of bytes per second is beyond 100, the packets will be discarded by the switch: T2500G-10TS(config)#access-list action 6 rule 1 T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 360
matching this rule: T2500G-10TS(config)#access-list action 6 rule 1 T2500G-10TS(config-action)#s-mirror interface gigabitEthernet 1/0/2 41.11 qos-remark Description The qos-remark command is used to configure QoS Remark function of policy action. To restore the settings to the default, please use no - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 361
Configure a policy for rule 1 of ACL 6: specify the DSCP region as 30 and local priority 2 for the packets matching this rule: T2500G-10TS(config)#access-list action 6 rule 1 T2500G-10TS access-list bind acl-id-or-name interface { [ vlan vlan-list ] | [ fastEthernet port-list ] | [gigabitEthernet - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 362
access to these commands. Example Bind ACL 1 to port 3 and VLAN 4: T2500G-10TS(config)#access-list bind 1 interface vlan 4 gigabitEthernet 1/0/3 41.13 show access-list Description The show access-list command is used to display configuration of ACL. Syntax show access-list acl-id-or-name Parameter - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 363
ACL entry resource. Syntax show access-list status Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the usage status of ACL entry resource: T2500G-10TS(config)# show access-list status 41.16 show access-list counter Description The show access - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 364
Example Display the packet counter of ACL 100: T2500G-10TS(config)# show access-list 100 counter 41.17 ID of the rule. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Clear the packet counter of ACL 100: T2500G-10TS(config)# clear access-list 100 344 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 365
verify source to filter the packets. 42.1 ip source binding Description The ip source binding command is used to bind the IP address, MAC address, VLAN ID and the Port number together manually. You can manually bind the IP address, MAC address, VLAN ID and the Port number together in the condition - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 366
User level users have access to these commands. Example Bind an ACL entry with the IP 192.168.0.1, MAC 00:00:00:00:00:01, VLAN ID 2 and the Port number 5 manually. And then enable the entry for the ARP detection: T2500G-10TS(config)#ip source binding host1 192.168.0.1 00:00:00:00:00:01 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 367
function on VLAN 1,4,6-7: T2500G-10TS(config)#ip dhcp snooping vlan 1,4,6-7 42.4 ip dhcp snooping max-entries Description The ip dhcp snooping max-entries command is used to configure the maximum number of entries that can be learned on a port via DHCP Snooping. To restore to the default setting - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 368
to these commands. Example Configure the maximum number of entries that can be learned on port 1 as 100: T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS(config-if)#ip dhcp snooping max-entries 100 42.5 show ip source binding Description The show ip source binding command is used - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 369
None. Example Display the running status of DHCP Snooping: T2500G-10TS#show ip dhcp snooping 42.7 show ip dhcp snooping interface Description The show ip dhcp snooping interface command is used to display the DHCP Snooping configuration of a desired Gigabit Ethernet port/port channel or of - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 370
Example Display the DHCP Snooping configuration of all Ethernet ports and port channels: T2500G-10TS#show ip dhcp snooping interface Display the DHCP Snooping configuration of Gigabit Ethernet port 1/0/5: T2500G-10TS#show ip dhcp snooping interface gigabitEthernet 1/0/5 350 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 371
IP verify source to filter the packets. 43.1 Ipv6 source binding Description The ipv6 source binding command is used to bind the IPv6 address, MAC address, VLAN ID and the Port number together manually. You can manually bind the IPv6 address, MAC address, VLAN Mode Global Configuration Mode 351 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 372
binding. Syntax Ipv6 dhcp snooping no ipv6 dhcp snooping Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCPv6 Snooping function globally: T2500G-10TS(config)#ipv6 dhcp snooping 352 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 373
on VLAN 1,4,6-7: T2500G-10TS(config)#ipv6 dhcp snooping vlan 1,4,6-7 43.4 ipv6 dhcp snooping max-entries Description The ipv6 dhcp snooping max-entries command is used to configure the maximum number of entries that can be learned on a port via DHCPv6 Snooping. To restore to the default setting - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 374
Configure the maximum number of entries that can be learned on port 1 as 100: T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS(config VLAN and the connected Port number of the Host for automatic binding. Syntax ipv6 nd snooping no ipv6 nd snooping Command Mode Global Configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 375
format of 1-3, 5. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the ND snooping function on VLAN 1,4,6-7: T2500G-10TS(config)#ipv6 nd snooping vlan 1,4,6-7 43.7 ipv6 nd snooping max-entries - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 376
and Power User level users have access to these commands. Example Configure the maximum number of binding entries from ND Snooping of Gigabit Ethernet port 1/0/2 is 100: T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)#ipv6 nd snooping max-entries 100 43.8 show ipv6 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 377
of DHCPv6 Snooping. Syntax show ipv6 dhcp snooping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the running status of DHCPv6 Snooping: T2500G-10TS#show ipv6 dhcp snooping 43.10 show ipv6 dhcp snooping interface Description The show ipv6 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 378
Requirement None. Example Display the DHCPv6 Snooping configuration of all Ethernet ports and port channels: T2500G-10TS#show ipv6 dhcp snooping interface Display the DHCPv6 Snooping configuration of Gigabit Ethernet port 1/0/5: T2500G-10TS#show ipv6 dhcp snooping interface gigabitEthernet 1/0/5 43 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 379
which can enhance the bandwidth utility. 44.1 ip verify source Description The ip verify source command is used to configure the IP Verify Source mode for a specified port. To disable the IP Verify Source function, please use no ip verify source command. Syntax ip verify source { sip+mac | sip } no - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 380
switch generate logs when receiving illegal packets: T2500G-10TS(config)#ip verify source logging 44.3 show ip verify source Description The show ip verify source command is used to display the IP Verify Source configuration information. Syntax show ip verify source Command Mode Privileged EXEC Mode - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 381
Requirement None. Example Display the IP Verify Source configuration information: T2500G-10TS(config)#show ip verify source 44.4 show ip verify source interface Description The show ip verify source interface command is used to display the IP verify source configuration of a desired Gigabit Ethernet - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 382
with its source IPv6 address and port number matched to the IPv6-MAC binding rules can be processed. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet ) Privilege Requirement Only Admin, Operator and Power User level users have access to these - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 383
information. Syntax show ipv6 verify source Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the IPv6 Verify Source configuration information: T2500G-10TS(config)#show ipv6 verify source 45.3 show ipv6 verify source interface Description The - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 384
Privilege Requirement None. Example Display the IPv6 verify source configuration of Gigabit Ethernet port 1/0/5: T2500G-10TS#show ipv6 verify source interface gigabitEthernet 1/0/5 364 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 385
filter command. Syntax ip dhcp filter no ip dhcp filter Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCP Filter function globally: T2500G-10TS(config)#ip dhcp filter 46.2 ip dhcp filter - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 386
on port 1/0/1 T2500G-10TS(config)#interface gigabitEthernet 1/0/1 T2500G-10TS(Config-if)#ip dhcp filter 46.3 ip dhcp filter mac-verify Description The ip dhcp filter mac different. Syntax ip dhcp filter mac-verify no ip dhcp filter mac-verify Command Mode Interface Configuration Mode (interface - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 387
T2500G-10TS(config-if)#ip dhcp filter mac-verify 46.4 ip dhcp filter limit rate Description The ip dhcp filter limit rate command is used to enable the Flow Control feature for the DHCP packets. The excessive DHCP packets will be discarded. To restore to the default configuration, please use no ip - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 388
have access to these commands. Example Configure the rate limit of DHCP Decline packets as 20 packets per second on Gigabit Ethernet port 1/0/2: T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)#ip dhcp filter decline 20 46.6 ip dhcp filter server permit-entry Description - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 389
without client MAC address restricted: T2500G-10TS(config)#ip dhcp filter server permit-entry server-ip 192.168.0.100 client-mac all interface gigabitEthernet 1/0/1 46.7 show ip dhcp filter Description The show ip dhcp filter command is used to display the configuration of DHCP Filter. Syntax show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 390
None. Example Display the DHCP Filter configuration: T2500G-10TS#show ip dhcp filter 46.8 show ip dhcp filter interface Description The show ip dhcp filter interface command is used to display the configuration of DHCP Filter on ports. Syntax show ip dhcp filter interface [fastEthernet port - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 391
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the legal DHCP server configuration: T2500G-10TS#show ip dhcp filter server permit-entry 371 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 392
are present on the network and both provide DHCPv6 services to different distinct groups of clients. 47.1 ipv6 dhcp Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCPv6 Filter function globally: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 393
1/0/1 T2500G-10TS(Config-if)#ipv6 dhcp filter 47.3 ipv6 dhcp filter limit rate Description The ipv6 dhcp filter limit rate command is used to enable the Flow Control feature for the DHCPv6 packets. The excessive DHCPv6 packets will be discarded. To restore to the default configuration, please - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 394
port 2 as 20 pps: T2500G-10TS(config)#interface gigabitEthernet 1/0/2 T2500G-10TS(config-if)#ipv6 dhcp filter limit rate 20 47.4 ipv6 dhcp filter decline rate Description The ipv6 dhcp filter decline rate command is used to enable the Decline Protect feature and configure the rate limit on DHCP - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 395
. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create an entry for the legal DHCPv6 server whose IP address is 192.168.0.100 and connected port number is 1/0/1: T2500G-10TS(config)#ipv6 dhcp filter - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 396
of DHCPv6 Filter. Syntax show ipv6 dhcp filter Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DHCPv6 Filter configuration: T2500G-10TS#show ipv6 dhcp filter 47.7 show ipv6 dhcp filter interface Description The show ipv6 dhcp filter - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 397
is used to display the legal server configuration. Syntax show ipv6 dhcp filter server permit-entry Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the legal DHCPv6 server configuration: T2500G-10TS#show ipv6 dhcp filter server permit-entry - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 398
sending a lot of service requests to the Host. Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the DoS defend function globally: T2500G-10TS(config)#ip dos-prevent 48.2 ip dos-prevent type Description The ip - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 399
with Ping packets, creating a broadcast storm that makes it impossible for the system to respond to legal communication. syn-flood --The attacker uses a fake IP address to send TCP request packets to the server. Upon receiving the request packets, the server responds with SYN-ACK packets. Since the - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 400
with traffic. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the DoS Defend Type named Land attack: T2500G-10TS(config)#ip dos-prevent type land 48.3 show ip dos-prevent Description The show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 401
Example Display the DoS information of the detected DoS attack globally: T2500G-10TS(config)#show ip dos-prevent 381 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 402
link is detected, the corresponding port will be shut down automatically or manually (depending on the shut mode configured). Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the DLDP function globally: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 403
. The operation to shut down the unidirectional link ports is accomplished by the users. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the shut-mode as manual: T2500G-10TS(config)# dldp shut-mode - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 404
commands. Example Enable the DLDP function of ports 1/0/2-4: T2500G-10TS (config)# interface range gigabitEthernet 1/0/2-4 T2500G-10TS (config-if-range)# dldp 49.5 show dldp Description The show dldp command is used to display the global configuration of DLDP function such as DLDP global state, DLDP - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 405
Example Display the global configuration of DLDP function: T2500G-10TS# show dldp 49.6 show dldp interface Description The show dldp interface command is used to display the configuration and state of the specified Ethernet port. By default, the configuration and state of all the ports will be - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 406
. To return to the default configuration, please use no snmp-server command. Syntax snmp-server no snmp-server Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the SNMP function: T2500G-10TS(config)# snmp-server 50 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 407
Only Admin level users have access to these commands. Example Add a View named view1, configuring the OID as 1.3.6.1.6.3.20, and this OID can be managed by the SNMP management station: T2500G-10TS(config)# snmp-server view view1 1.3.6.1.6.3.20 include 50.3 snmp-server group Description The snmp - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 408
group, and configure the name as group 1, the Security Model as SNMP v3, the security level as authNoPriv, the management access to the assigned View viewDefault as read-write, besides the notification messages sent by View viewDefault can be received by Management station: T2500G-10TS(config)# snmp - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 409
ID and user password are used to compute the authentication and privacy digests, before configuring a remote user, you need to set the remote engine ID first. group- highest to lowest is: noAuthNoPriv, authNoPriv, authPriv, and the default is noAuthNoPriv. The security level of the user should not be - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 410
method is used. By default, the Privacy Mode is configure the Security Model of the user as v3, the Security Level of the group as authPriv, the Authentication Mode of the user as MD5, the Authentication Password as 11111, the Privacy Mode as DES, and the Privacy Password as 22222: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 411
community to access. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Add community public, and the community has read-write management right to View viewDefault: T2500G-10TS(config)# snmp-server community public read-write - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 412
timeout need to be configured if you select this option. You can only select the trap type in Security Model v1. By default, the type of T2500G-10TS(config)# snmp-server host 192.168.0.146 162 admin smode v2c type inform retries 100 timeout 1000 Add a Notification entry, and configure the IP - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 413
the local and remote are both not configured. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Specify the local engineID as 1234567890, and the remote engineID as abcdef123456: T2500G-10TS(config)# snmp-server engineID local - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 414
when a received SNMP request fails the authentication. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable SNMP standard linkup trap for the switch: T2500G-10TS(config)# snmp-server traps snmp linkup 50.9 snmp-server traps - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 415
you have set. The limit of CPU utilization rate for the switch is 80% by default. flash --Triggered when flash is modified during operations such as backup, reset, firmware upgrade, configuration import, and so on. lldp remtableschange --An lldp RemTablesChange notification is sent when the value - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 416
is disabled by default. The system will generate the trap when the memory utilization exceeds 80%. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable SNMP extended bandwidth-control trap for the switch: T2500G-10TS(config - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 417
DDM traps. For more instructions about the alarm threshold or warning threshold, refer to Chapter 11 DDM Commands. Command Mode Global Configuration Mode Example Enable all the SNMP DDM traps for the switch: T2500G-10TS(config)# snmp-server traps ddm 50.11 snmp-server traps vlan Description The snmp - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 418
feature is enabled and the switch receives an illegal IP packet. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the DHCP filter trap for the switch: T2500G-10TS(config)# snmp-server traps security dhcp-filter 398 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 419
disabled by default. The Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the ACL trap for the switch: T2500G-10TS(config)# snmp-server traps acl 50.14 snmp-server traps ip Description The snmp-server traps ip command is used to enable IP - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 420
status trap for port 3: T2500G-10TS(config)# interface gigabitEthernet 1/0/3 T2500G-10TS(config-if)# snmp-server traps link-status 50.16 rmon history Description The rmon history command is used to configure the history sample entry. To return to the default configuration, please use no rmon history - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 421
as 100 seconds for the entry 1-3: T2500G-10TS(config)# rmon history 1-3 interface gigabitEthernet 1/0/2 interval 100 owner owner1 50.17 rmon event Description The rmon event command is used to configure the entries of SNMP-RMON Event. To return to the default configuration, please use no rmon event - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 422
owner of the event as owner1: T2500G-10TS(config)# rmon event 1-4 user user1 description description1 type log owner owner1 50.18 rmon alarm Description The rmon alarm command is used to configure SNMP-RMON Alarm Management. To return to the default configuration, please use no rmon alarm command - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 423
the Rising Threshold. It ranges from 1 to 12. f-hold -- The falling counter value that triggers the Falling Threshold alarm, ranging from 1 to 2147483647. By default, it is 100. f-event -- Fall Event, which is the index of the corresponding event which will be triggered if the sampled value is lower - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 424
. By default, it is 1800. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure rmon alarm entries 1-3 binding with statistics entry 2, the owners as owner1 and the alarm intervals as 100 seconds: T2500G-10TS(config)#rmon - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 425
Mode Privilege Requirement Only Admin level users have access to these commands. Example Display SNMP configuration globally: T2500G-10TS# show snmp-server 50.21 show snmp-server view Description The show snmp-server view command is used to display the View table. Syntax show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 426
Group table. Syntax show snmp-server group Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the Group table: T2500G-10TS# show snmp-server group 50.23 show snmp-server user Description The show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 427
Host table. Syntax show snmp-server host Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the Host table: T2500G-10TS# show snmp-server host 50.26 show snmp-server engineID Description The show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 428
. By default, the configuration of all history sample entries is displayed. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the configuration of all history sample entries: T2500G-10TS# show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 429
command. By default, the configuration of all SNMP-RMON enabled entries is displayed. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the Event configuration of entry1-4: T2500G-10TS# show rmon - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 430
to 65535. By default, the configuration of all statistics entries is displayed. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the configuration of the statistics entry 1: T2500G-10TS#show rmon - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 431
detection command. Syntax ip arp inspection no ip arp inspection Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the ARP Detection function globally: T2500G-10TS(config)#ip arp inspection 51 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 432
Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the switch to check whether the source MAC address and the sender MAC address are the same when receiving an ARP packet T2500G-10TS(config)#ip arp - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 433
the switch generate a log when an ARP packet is discarded. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the log feature on VLAN 2: T2500G-10TS(config)#ip arp inspection vlan 2 logging 413 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 434
Port: T2500G-10TS(config)#interface range gigabitEthernet 1/0/2-5 T2500G-10TS(config-if-range)#ip arp inspection trust 51.6 ip arp inspection limit-rate Description The ip arp inspection limit-rate command is used to configure the ARP speed of a specified port. To restore to the default speed - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 435
5: T2500G-10TS(config)#interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)#ip arp inspection limit-rate 50 51.7 ip arp inspection burst-interval Description The ip arp inspection burst-interval command is used to configure the burst interval of a specified port. To restore to the default speed - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 436
access to these commands. Example Configure the burst interval as 2 seconds for Gigabit Ethernet port 5: T2500G-10TS(config)#interface gigabitEthernet 1/0/5 T2500G-10TS(config-if)#ip arp inspection burst-interval 2 51.8 ip arp inspection recover Description The ip arp inspection recover command is - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 437
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the ARP detection configuration globally: T2500G-10TS(config)#show ip arp inspection 51.10 show ip arp inspection interface Description The show ip arp inspection interface command is used to - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 438
is used to display the VLAN configuration of ARP detection. Syntax show ip arp inspection vlan Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the ARP Inspection configuration of VLAN: T2500G-10TS(config)#show ip arp inspection vlan 51.12 show - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 439
statistics Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear the statistic of the illegal ARP packets received: T2500G-10TS(config)#clear ip arp inspection statistics 419 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 440
ipv6 nd detection no ipv6 nd detection Command Mode Global Configuration Mode Example Enable the ND Detection function globally: T2500G-10TS(config)#ipv6 nd detection 52.2 ipv6 nd detection vlan Description The ipv6 nd detection vlan command is used to enable ND Detection function on a specified - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 441
command. Syntax ipv6 nd detection vlan vlan-range logging no ipv6 nd detection vlan vlan-range logging Parameter vlan-range --Enter the vlan range in the format of 1-3, 5. Command Mode Global Configuration Mode Example Enable the Log function on VLAN 1,4,6-7: T2500G-10TS(config)#ipv6 nd detection - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 442
including the enable/disable status. Syntax show ipv6 nd detection Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the ND Detection configuration globally: T2500G-10TS(config)#show ipv6 nd detection 52.6 show ipv6 nd detection interface Description The show ipv6 nd - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 443
The show ipv6 nd detection vlan command is used to display the VLAN configuration of ND Detection. Syntax show ipv6 nd detection vlan Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the ipv6 ND Detection configuration of VLAN. T2500G-10TS(config)#show ipv6 nd detection - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 444
Enable the system log buffer: T2500G-10TS(config)#logging buffer 53.2 logging buffer level Description The logging buffer level command is used to configure the severity level and the status of the configuration input to the log buffer. To return to the default configuration, please use no logging - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 445
. By default, it is 6 indicating that the log information with level 0-6 will be saved in the log buffer. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Set the severity level as 5: T2500G-10TS(config)#logging - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 446
flash, ranging from 1 to 48 hours. By default, the synchronization process takes place every 24 hours. immediate Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify the log file synchronization frequency as 10 hours: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 447
value will be stored to the flash. To restore to the default level, please use no logging file flash level command. Syntax T2500G-10TS(config)#logging file flash level 7 53.6 logging host index Description The logging host index command is used to configure the Log Host. To clear the configuration - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 448
of the log host. The switch supports 4 log hosts at most. host-ip -- The IP for the log host. level Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable log host 2 and set its IP address as 192.168.0.148, the level 5: T2500G-10TS - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 449
be output to the terminal devices. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Output the log information with severity levels between 0-7 to the console port: T2500G-10TS(config)# logging console level 7 429 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 450
. This function is enabled by default. Syntax logging monitor no logging monitor Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable logging to the terminal devices: T2500G-10TS(config)# no logging monitor 53 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 451
: buffer and flash. Clear the information of the two channels, by default. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Clear the information in the log file: T2500G-10TS(config)# clear logging buffer 431 - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 452
the log file. Syntax show logging local-config Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of the Local Log: T2500G-10TS(config)# show logging local-config 53.13 show logging loghost Description The show logging loghost - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 453
. Display all the log information in the log buffer by default. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the log information from level 0 to level 5 in the log buffer: T2500G-10TS(config)# show logging buffer level 5 53.15 show logging - TP-Link T2500G-10TS | T2500G-10TSUN V2 CLI Reference Guide Guide - Page 454
level will display. Display all the log information in the log file by default. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the log information with the level marked 0~3 in the log file: T2500G-10TS(config)# show logging flash level 3 434
CLI Reference Guide
T2500G-10TS (TL-SG3210)
1910012494 REV2.0.0
November 2018