TP-Link T2600G-18TSTL-SG3216 T2600G-28MPSUN V2 CLI Reference Guide Guide
TP-Link T2600G-18TSTL-SG3216 Manual
View all TP-Link T2600G-18TSTL-SG3216 manuals
Add to My Manuals
Save this manual to your list of manuals |
TP-Link T2600G-18TSTL-SG3216 manual content summary:
- TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 1
CLI Reference Guide JetStream Gigabit L2 Managed Switch T2600G-18TS(TL-SG3216) T2600G-28TS (TL-SG3424) T2600G-52TS (TL-SG3452) T2600G-28MPS (TL-SG3424P) REV2.1.0 1910012012 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 2
COPYRIGHT & TRADEMARKS Specifications are subject to change without notice. is a registered trademark of TP-Link TECHNOLOGIES CO., LTD. Other brands and product names are trademarks or registered trademarks of their respective holders. No part of the specifications may be reproduced in any form - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 3
Conventions...19 1.4.1 Format Conventions 19 1.4.2 Special Characters ...20 1.4.3 Parameter Format ...20 Chapter 2 User Interface 21 2.1 enable...21 2.2 service password-encryption 21 2.3 enable password...22 2.4 enable secret ...23 2.5 configure ...24 2.6 exit ...25 2.7 end ...25 2.8 history - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 4
3.11 3.12 show vlan ...35 show interface switchport 35 Chapter 4 MAC-based VLAN Commands 37 4.1 mac-vlan mac-address ...37 4.2 mac-vlan ...38 4.3 show mac-vlan...38 4.4 show mac-vlan interface 39 Chapter 5 Protocol-based VLAN Commands 40 5.1 protocol-vlan template (For T2600G-18TS only 40 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 5
lacp...77 show lacp sys-id...78 Chapter 12 User Management Commands 80 12.1 12.2 12.3 12.4 user name (password) ...80 user name (secret) ...81 service password-recovery 82 user access-control ip-based 83 IV - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 6
12.5 12.6 12.7 12.8 12.9 12.10 12.11 12.12 12.13 12.14 12.15 12.16 12.17 user access-control mac-based 84 user access-control port-based 85 line ...85 password ...86 login ...88 login local...88 media-type rj45 ...89 telnet ...90 serial_port baud-rate...90 show password-recovery 91 show user - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 7
15.2 15.3 15.4 15.5 15.6 15.7 15.8 15.9 15.10 15.11 15.12 15.13 15.14 15.15 ip dhcp snooping ...109 ip dhcp snooping vlan ...110 ip dhcp snooping information option 111 ip dhcp snooping information strategy 111 ip dhcp snooping information remote-id 112 ip dhcp snooping information circuit-id - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 8
Chapter 19 ND Detection Commands 135 19.1 19.2 19.3 19.4 19.5 ipv6 nd detection ...135 ipv6 nd detection vlan ...135 ipv6 nd detection trust...136 show ipv6 nd detection 137 show ipv6 nd detection interface 137 Chapter 20 ARP Inspection Commands 139 20.1 20.2 20.3 20.4 20.5 20.6 20.7 20.8 20 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 9
Chapter 23 PPPoE ID-Insertion Commands 159 23.1 23.2 23.3 23.4 23.5 23.6 pppoe id-insertion(global 159 pppoe circuit-id(interface 160 pppoe circuit-id type ...160 pppoe remote-id ...161 show pppoe id-insertion global 162 show pppoe id-insertion interface 162 Chapter 24 System Log Commands - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 10
.10 27.11 27.12 27.13 27.14 27.15 27.16 27.17 27.18 27.19 27.20 27.21 system-time manual ...194 system-time ntp ...194 system-time dst predefined 196 system-time dst date ...197 system-time dst recurring 198 hostname...199 location ...200 contact - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 11
27.22 27.23 27.24 27.25 27.26 27.27 27.28 27.29 27.30 27.31 27.32 27.33 27.34 27.35 27.36 27.37 27.38 27.39 27.40 27.41 boot autoinstall auto-save 210 boot autoinstall auto-reboot 210 boot autoinstall retry-count 211 show boot autoinstall ...212 show boot autoinstall downloaded-config 212 ping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 12
29.7 29.8 29.9 29.10 29.11 29.12 29.13 29.14 29.15 29.16 29.17 29.18 jumbo ...232 jumbo-size...232 speed ...233 storm-control pps...234 storm-control...234 bandwidth...235 clear counters...236 show interface status ...237 show interface counters 237 show interface configuration 238 show storm- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 13
33.1 33.2 33.3 33.4 33.5 33.6 33.7 33.8 loopback-detection(global 257 loopback-detection interval 257 loopback-detection recovery-time 258 loopback-detection(interface 258 loopback-detection config 259 loopback-detection recover 260 show loopback-detection global 260 show loopback-detection - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 14
35.18 35.19 35.20 35.21 35.22 35.23 35.24 35.25 35.26 35.27 qos-remark...286 access-list bind acl(interface 287 access-list bind acl(vlan 287 access-list bind(interface 288 access-list packet-content profile 289 access-list packet-content config 289 access-list bind(vlan)...290 show access- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 15
Chapter 37 Ethernet OAM Commands 312 37.1 37.2 37.3 37.4 37.5 37.6 37.7 37.8 37.9 37.10 37.11 37.12 37.13 37.14 37.15 ethernet-oam...312 ethernet-oam mode ...312 ethernet-oam link-monitor symbol-period 313 ethernet-oam link-monitor frame 314 ethernet-oam link-monitor frame-period 315 ethernet- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 16
39.11 39.12 39.13 39.14 39.15 39.16 39.17 39.18 39.19 39.20 39.21 39.22 39.23 39.24 39.25 39.26 39.27 39.28 39.29 39.30 39.31 39.32 ip igmp snooping vlan-config (router-port-forbidden 336 ip igmp snooping multi-vlan-config 337 ip igmp snooping multi-vlan-config (router-port-forbidden 338 ip igmp - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 17
40.15 40.16 40.17 40.18 40.19 40.20 40.21 40.22 40.23 40.24 40.25 40.26 40.27 40.28 40.29 40.30 ipv6 mld snooping querier vlan 362 ipv6 mld snooping querier vlan (general query 362 ipv6 mld snooping max-groups 363 ipv6 mld profile ...365 deny...365 permit ...366 range ...366 ipv6 mld filter ... - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 18
41.21 41.22 41.23 41.24 41.25 41.26 41.27 show snmp-server community 391 show snmp-server host 392 show snmp-server engineID 392 show rmon history ...393 show rmon event...393 show rmon alarm...394 show rmon statistics ...394 Chapter 42 LLDP Commands 396 42.1 42.2 42.3 42.4 42.5 42.6 42.7 42 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 19
44.4 44.5 44.6 44.7 44.8 44.9 44.10 44.11 44.12 44.13 44.14 44.15 44.16 44.17 44.18 44.19 interface range port-channel 414 description ...414 shutdown ...415 interface port-channel ...416 ip route ...416 ipv6 routing ...417 ipv6 route ...418 show interface vlan...418 show ip interface ...419 show - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 20
18 47.19 47.20 47.21 47.22 47.23 47.24 47.25 47.26 service dhcp server ...446 ip dhcp server extend-option capwap-ac-ip 446 ip dhcp server extend-option server excluded-address 460 show ip dhcp server manual-binding 460 show ip dhcp server binding 461 clear ip dhcp server statistics 461 XIX - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 21
47.27 clear ip dhcp server binding 462 Chapter 48 DHCP Relay Commands 463 48.1 48.2 48.3 48.4 48.5 48.6 48.7 48.8 48.9 48.10 service dhcp relay...463 ip helper-address...463 ip dhcp relay information 464 ip dhcp relay information policy 465 ip dhcp relay information custom 465 ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 22
apply to these models if not specially noted, and T2600G-28TS is taken as an example model in the example commands. Overview of this Guide Chapter 1: Using the CLI Provide information about how to use the CLI, CLI Command Modes, Security Levels and some Conventions. Chapter 2: User Interface Provide - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 23
Chapter 11: Etherchannel Commands Provide information about the commands used for configuring LAG (Link Aggregation Group) and LACP (Link Aggregation Control Protocol). Chapter 12: User Management Commands Provide information about the commands used for user management. Chapter 13: HTTP and HTTPS - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 24
Chapter 25: SSH Commands Provide information about the commands used for configuring and managing SSH (Security Shell). Chapter 26: MAC Address Commands Provide information about the commands used for Address configuration. Chapter 27: System Configuration Commands Provide information about the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 25
Chapter 38: DLDP Commands Provide information about the commands used for configuring the DLDP (Device Link Detection Protocol). Chapter 39: IGMP Snooping Commands Provide information about the commands used for configuring the IGMP Snooping (Internet Group Management Protocol Snooping). Chapter 40: - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 26
required. The USB driver is provided on the resource CD. Follow the InstallSheild Wizard to accomplish the installation. The TP-Link USB Console Driver supports the following Windows operating systems: 32-bit Windows XP SP3 64-bit Windows XP 32-bit Windows Vista 64-bit Windows Vista 32-bit - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 27
64-bit Windows 8 32-bit Windows 8.1 64-bit Windows 8.1 After the TP-Link USB Console Driver is installed, the PC's USB port will act as RS-232 serial port when the PC's USB port is connected to the switch's Micro-USB console port. And the PC's USB port will act as standard USB port when the PC - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 28
5. The DOS prompt "T2600G-28TS>" will appear after pressing the Enter button as shown in Figure 1-2. It indicates that you can use the CLI now. Figure 1-2 Log in the Switch 1.1.2 Logon by Telnet For Telnet connection, you should also configure the Telnet login mode and login authentication - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 29
Login Local Mode Firstly, configure the Telnet login mode as "login local" in the prompted DOS screen shown in Figure 1-3. Figure 1-3 Configure login local mode Now, you can logon by Telnet in login local mode. 1. Make sure the switch and the PC are in the same LAN. Click Start and type in cmd in - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 30
3. Type the default user name and password (both of them are admin), then press the Enter button so as to enter User EXEC Mode. Figure 1-6 Enter into the User EXEC Mode 4. Type enable command to enter Privileged EXEC Mode. Figure 1-7 Enter into the Priviledged EXEC Mode Now you can manage your - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 31
Now, you can logon by Telnet in login mode: 1. Make sure the switch and the PC are in the same LAN. Click Start and type in cmd in the Search programs and files window and press the Enter button. Figure 1-9 Run Window 2. Type telnet 192.168.0.1 in the command prompt shown as Figure 1-10, and press - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 32
4. Type enable command to enter Privileged EXEC Mode. Figure 1-12 Enter into the Privileged EXEC Mode Now you can manage your switch with CLI commands through Telnet connection. Note: You can refer to Chapter 11 User Management Commands for detailed commands information of the Telnet connection - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 33
Password Authentication Mode 1. Open the software to log on to the interface of PuTTY. Enter the IP address of the switch into Host Name field; keep the default value 22 in the Port field; select SSH as the Connection type. Figure 1-14 SSH Connection Config 2. Click the Open button in the above - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 34
Key Authentication Mode 1. Select the key type and key length, and generate SSH key. Figure 1-16 Generate SSH Key Note: 1. The key length is in the range of 512 to 3072 bits. 2. During the key generation, randomly moving the mouse quickly can accelerate the key generation. 13 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 35
2. After the key is successfully generated, please save the public key and private key to a TFTP server. Figure 1-17 Save the Generated Key 3. Log on to the switch by Telnet and download the public key file from the TFTP server to the switch, as the following figure shows: Figure 1-18 Download the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 36
Note: 1. The key type should accord with the type of the key file. 2. The SSH key downloading can not be interrupted. 4. After the public key is downloaded, please log on to the interface of PuTTY and enter the IP address for login. Figure 1-19 SSH Connection Config 15 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 37
5. Click Browse to download the private key file to SSH client software and click Open. Figure 1-20 Download the Private Key 6. After successful authentication, please enter the login user name. If you log on to the switch without entering password, it indicates that the key has been successfully - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 38
Interface Configuration Mode can also be divided into Interface Ethernet, Interface link-aggregation and some other modes, which is shown as the following diagram. The following table gives detailed information about the Accessing path, Prompt of each mode and how to exit the current mode and - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 39
Mode Accessing Path Prompt Logout or Access the next mode Layer 3 Interface: Use the no switchport command to enter Routed Port mode from Interface Configuration mode. Interface Configuration Mode Use the interface vlan vlan-id command to enter VLAN Interface mode from Global Configuration - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 40
, you are required to enter it to access Privileged EXEC mode. 1.4 Conventions 1.4.1 Format Conventions The following conventions are used in this Guide: Items in square brackets [ ] are optional Items in braces { } are required Alternative items are grouped in braces and separated by vertical - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 41
Normal Font indicates a constant (several options are enumerated and only one can be selected). For example: mode {dynamic | static | permanent} Italic Font indicates a variable (an actual value must be assigned). For example: bridge aging-time aging-time 1.4.2 Special Characters You should pay - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 42
set the password to access Privileged EXEC Mode from User EXEC Mode: T2600G-28TS>enable Enter password: T2600G-28TS# 2.2 service password-encryption Description The service password-encryption command is used to encrypt the password when the password is defined or when the configuration is written - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 43
Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable the global encryption function: T2600G-28TS(config)# service password-encryption 2.3 enable password Description The enable password command is used to set or change the password for users to access - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 44
have access to these commands. User Guidelines If the password you configured here is unencrypted and the global encryption function is enabled in service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. Example Set the super password as - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 45
encrypted password is configured, you should use the corresponding unencrypted password if you re-enter this mode. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. User Guidelines If both the enable password and enable secret are - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 46
2.6 exit Description The exit command is used to return to the previous Mode from the current Mode. Syntax exit Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Return to Global Configuration Mode from Interface Configuration Mode, and then return to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 47
2.8 history Description The history command is used to show the latest 20 commands you entered in the current mode since the switch is powered. Syntax history Command Mode Privileged EXEC Mode and any Configuration Mode Privilege Requirement None. Example Show the commands you have entered in the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 48
T2600G-28TS(config)#history clear 27 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 49
Chapter 3 IEEE 802.1Q VLAN Commands VLAN (Virtual Local Area Network) technology is developed for the switch to divide the LAN into multiple logical LANs flexibly. Hosts in the same VLAN can communicate with each other, regardless of their physical locations. VLAN can enhance performance by - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 50
Description The interface vlan command is used to create VLAN Interface and enter Interface VLAN Mode. To delete VLAN Interface, please use no interface vlan command. Syntax interface vlan vlan-id no interface vlan vlan-id Parameter vlan-id -- Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 51
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the name of VLAN 2 as "group1": T2600G-28TS(config)# vlan 2 T2600G-28TS(config-vlan)# name group1 3.4 switchport mode Description The switchport mode command is used to configure the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 52
3.5 switchport access vlan Description The switchport access vlan command is used to add the desired Access port to IEEE 802.1Q VLAN, or to remove a port from the corresponding VLAN. Syntax switchport access vlan vlan-id no switchport access vlan Parameter vlan-id -- Specify IEEE 802.1Q VLAN ID, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 53
Parameter vlan-list -- VLAN ID list, ranging from 2 to 4094, in the format of 2-3, 5. It is multi-optional. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 54
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure Gigabit Ethernet port 1/0/4 whose link type is "general" to VLAN 2 and its egress-rule as "tagged": T2600G-28TS(config)#interface gigabitEthernet 1/0/4 T2600G-28TS(config-if)# - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 55
3.9 show vlan summary Description The show vlan summary command is used to display the summarized information of IEEE 802.1Q VLAN. Syntax show vlan summary Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the summarized information of IEEE 802. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 56
3.11show vlan Description The show vlan command is used to display the information of IEEE 802.1Q VLAN. Syntax show vlan [ id vlan-id ] Parameter vlan-id -- Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. It is multi-optional. Using the show vlan command without parameter displays the detailed - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 57
Privilege Requirement None. Example Display the VLAN configuration information of all ports and port channels: T2600G-28TS(config)# show interface switchport 36 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 58
Chapter 4 MAC-based VLAN Commands MAC VLAN (Virtual Local Area Network) is the way to classify the VLANs based on MAC Address. A MAC address is relative to a single VLAN ID. The untagged packets and the priority-tagged packets coming from the MAC address will be tagged with this VLAN ID. 4.1 mac- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 59
4.2 mac-vlan Description The mac-vlan command is used to enable a port for the MAC-based VLAN feature. Only the port is enabled can the configured MAC-based VLAN take effect. To disable the MAC-based VLAN function, please use no mac-vlan command. All the ports are disabled by default. Syntax mac- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 60
Privilege Requirement None. Parameter mac-addr -- MAC address, in the format of XX:XX:XX:XX:XX:XX. vlan-id -- Specify IEEE 802.1Q VLAN ID, ranging from 1 to 4094. Example Display the information of all the MAC-based VLAN entry: T2600G-28TS(config)#show mac-vlan all 4.4 show mac-vlan interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 61
Chapter 5 Protocol-based VLAN Commands Protocol VLAN (Virtual Local Area Network) is the way to classify VLANs based on Protocols. A Protocol is relative to a single VLAN ID. The untagged packets and the priority-tagged packets matching the protocol template will be tagged with this VLAN ID. 5.1 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 62
T2600G-18TS(config)#protocol-vlan template name TP frame ether_2 ether-type 2024 5.2 protocol-vlan template (For other switches) Description The protocol-vlan template command is used to create Protocol-based VLAN template. To delete Protocol-based VLAN template, please use no protocol-vlan template - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 63
T2600G-28TS(config)#protocol-vlan template name TP frame ether_2 ether-type 2024 5.3 protocol-vlan vlan Description The protocol-vlan vlan command is used to create a Protocol-based VLAN entry. To delete a Protocol-based VLAN entry, please use no protocol-vlan vlan command. Syntax protocol-vlan vlan - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 64
5.4 protocol-vlan group Description The protocol-vlan command is used to add the port to a specified protocol group. To remove the port from this protocol group, please use no protocol-vlan group command. Syntax protocol-vlan group index no protocol-vlan group index Parameter index -- Specify the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 65
Privilege Requirement None. Example Display the information of the Protocol-based VLAN templates: T2600G-28TS(config)#show protocol-vlan template 5.6 show protocol-vlan vlan Description The show protocol-vlan vlan command is used to display the information about Protocol-based VLAN entry. Syntax - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 66
with VLAN tags of private networks to be encapsulated with VLAN tags of public networks at the network access terminal of the Internet Service Provider. And these packets will be transmitted with double-tag across the public networks. 6.1 dot1q-tunnel Description The dot1q-tunnel command is used - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 67
Configure Global TPID of the VLAN-VPN as 0x9100: T2600G-28TS(config)#dot1q-tunnel tpid 9100 6.3 dot1q-tunnel mapping Note: T2600G-18TS doesn't support this command. Description The dot1q-tunnel mapping command is used to enable the VLAN Mapping feature globally. To disable this function, please use - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 68
c-vlan sp-vlan [descript] no switchport dot1q-tunnel mapping c-vlan Parameter c-vlan -- Customer VLAN ID, ranging from 1 to 4094. sp-vlan -- Service Provider VLAN ID, ranging from 1 to 4094. descript -- Give a description to the VLAN Mapping entry, which contains 15 characters at most. Command Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 69
-tunnel mode { uni/nni } no switchport dot1q-tunnel mode Parameter uni --The port connected to the clients. (Note: T2600G-18TS does't support uni port setting.) nni --The port connected to the ISP. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 70
Syntax show dot1q-tunnel Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration information of the VLAN VPN: T2600G-28TS(config)#show dot1q-tunnel 6.7 show dot1q-tunnel mapping Description The show dot1q-tunnel mapping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 71
Syntax show dot1q-tunnel interface Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the port type of all VLAN VPN ports: T2600G-28TS(config)#show dot1q-tunnel interface 50 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 72
Chapter 7 Private VLAN Commands Note: T2600G-18TS doesn't support this command. Private VLANs are configured specially for saving VLAN resource of uplink devices and decreasing broadcast. 7.1 private-vlan primary Description The private-vlan primary - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 73
Syntax private-vlan community no private-vlan community Command Mode VLAN Configuration Mode (VLAN) Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the VLAN 4 as the community VLAN of the private VLAN: T2600G-28TS(config)#vlan 4 T2600G-28TS( - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 74
7.4 private-vlan association Description The private-vlan association command is used to associate primary VLAN with secondary VLAN. To exterminate the currently association, please use no private-vlan association command. Syntax private-vlan association vlan_list no private-vlan association - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 75
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure Gigabit Ethernet port 3 as "host - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 76
Example Configure host type Gigabit Ethernet port 1/0/3 as a member of primary VLAN 3 and secondary VLAN 4, with the type of VLAN 4 as community: T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)#switchport private-vlan host-association 3 4 community 7.7 switchport private- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 77
7.8 show vlan private-vlan Description The show vlan private-vlan command is used to display the Private VLAN configuration information of the switch. Syntax show vlan private-vlan Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin and Operator level users - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 78
Example Display the configuration information of all the Ethernet ports: T2600G-28TS(config)#show vlan private-vlan interface 57 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 79
8 L2PT Commands L2PT (Layer 2 Protocol Tunneling) is a feature for service providers to transmit packets from different customers across their ISP networks and maintain Layer 2 protocol configurations of each customer. The supported Layer 2 protocols are STP (Spanning Tree Protocol), GVRP (GARP VLAN - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 80
. Specify the port's type as UNI if it is connecting to the user's local network. 01000ccccccc | 01000ccccccd | gvrp | stp | all -- Select the supported Layer 2 protocol type. Packets of the specified protocol will be encapsulated with their destination MAC address before they are sent to the ISP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 81
T2600G-28TS(config)#interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# l2protocol-tunnel type uni stp threshold 1000 8.3 show l2protocol-tunnel global Description The show l2protocol-tunnel global command is used to display the global L2PT status. Syntax show l2protocol-tunnel global Command - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 82
Privilege Requirement None. Example Display the L2PT configuration information of Gigabit Ethernet port 1/0/1: T2600G-28TS(config)#show l2protocol-tunnel interface gigabitEthernet 1/0/1 Display the L2PT configuration information of all Ethernet ports: T2600G-28TS(config)#show l2protocol-tunnel - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 83
Chapter 9 GVRP Commands GVRP (GARP VLAN registration protocol) is an implementation of GARP (generic attribute registration protocol). GVRP allows the switch to automatically add or remove the VLANs via the dynamic VLAN registration information and propagate the local VLAN registration information - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 84
no gvrp Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the GVRP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 85
Example Configure the GVRP registration mode as "fixed" for Gigabit Ethernet ports 1/0/2-6: T2600G-28TS(config)#interface range gigabitEthernet 1/0/2-6 T2600G-28TS(config-if-range)#gvrp registration fixed 9.4 gvrp timer Description The gvrp timer command is used to set a GVRP timer for the desired - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 86
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Set the GARP leaveall timer of Gigabit Ethernet port 1/0/6 as 2000 centiseconds and restore the join timer of it to the default value: T2600G-28TS(config)#interface gigabitEthernet 1/0/6 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 87
9.6 show gvrp global Description The show gvrp global command is used to display the global GVRP status. Syntax show gvrp global Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global GVRP status: T2600G-28TS(config)#show gvrp global 66 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 88
Chapter 10 Voice VLAN Commands Voice VLANs are configured specially for voice data stream. By configuring Voice VLANs and adding the ports with voice devices attached to voice VLANs, you can perform QoS-related configuration for voice data, ensuring the transmission priority of voice data stream and - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 89
Syntax voice vlan aging time no voice vlan aging Parameter time -- Aging time (in minutes) to be set for the Voice VLAN. It ranges from 1 to 43200 minutes and the default value is 1440 minutes. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 90
Example Configure the priority of the Voice VLAN as 5: T2600G-28TS(config)# voice vlan priority 5 10.4voice vlan mac-address Description The voice vlan mac-address command is used to create Voice VLAN OUI. To delete the specified Voice VLAN OUI, please use no voice vlan mac-address command. Syntax - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 91
is used to configure the Voice VLAN mode for the Ethernet port. Syntax switchport voice vlan mode { manual | auto } Parameter manual | auto -- Port mode. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 92
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable port 1/0/3 for the Voice VLAN security feature: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# switchport voice vlan security 10.7show voice vlan - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 93
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Display the configuration information of Voice VLAN OUI: T2600G-28TS(config)# show voice vlan oui 10.9show voice vlan switchport - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 94
Chapter 11 Etherchannel Commands Etherchannel Commands are used to configure LAG and LACP function. LAG (Link Aggregation Group) is to combine a number of ports together to make a single high-bandwidth data path, which can highly extend the bandwidth. The bandwidth of the LAG is the sum of bandwidth - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 95
Example Add ports 2-4 to EtherChannel Group 1 and enable the static LAG: T2600G-28TS(config)# interface range gigabitEthernet 1/0/2-4 T2600G-28TS(config-if-range)# channel-group 1 mode on 11.2port-channel load-balance Description The port-channel load-balance command is used to configure the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 96
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the Aggregate Arithmetic for LAG as "src-dst-ip": T2600G-28TS(config)# port-channel load-balance src-dst-ip 11.3lacp system-priority - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 97
Description The lacp port-priority command is used to configure the LACP port priority for specified ports. To return to the default configurations, please use no lacp port-priority command. Syntax lacp port-priority pri no lacp port-priority Parameter pri -- The port priority, ranging from 0 to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 98
Parameter channel-group-num -- The EtherChannel Group number, ranging from 1 to 14. By default, it is empty, and will display the information of all EtherChannel Groups. detail -- The detailed information of EtherChannel. summary -- The EtherChannel information in summary. Command Mode Privileged - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 99
Description The show lacp command is used to display the LACP information for a specified EtherChannel Group. Syntax show lacp [ channel-group-num ] { internal | neighbor } Parameter channel-group-num -- The EtherChannel Group number, ranging from 1 to 14. By default, it is empty, and will display - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 100
T2600G-28TS(config)# show lacp sys-id 79 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 101
Chapter 12 User Management Commands User Manage Commands are used to manage the user's logging information by Web, Telnet or SSH, so as to protect the settings of the switch from being randomly changed. 12.1user name (password) Description The user name command is used to add a new user or modify - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 102
have access to these commands. User Guidelines If the password you configured here is unencrypted and the global encryption function is enabled in service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. Example Add and enable a new admin - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 103
will be displayed in the encrypted form. T2600G-28TS(config)#user name tplink privilege admin secret 0 admin 12.3service password-recovery Description The service password-recovery command is used to enable the password-recovery feature. To disable the password-recovery feature, please use no - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 104
startup. For more details about password recovery procedure, please refer to Appendix A in the User Guide. Syntax service password-recovery no service password-recovery Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Enable - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 105
Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the access-control of the user whose IP address is 192.168.0.148: T2600G-28TS(config)# user access-control ip-based 192.168.0.148 255.255.255.255 12.5user - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 106
T2600G-28TS(config)# user access-control mac-based 00:00:13:0A:00:01 12.6user access-control port-based Description The user access-control port-based command is used to limit the ports for login. Only the users connected to these ports you set here are allowed to login. To cancel the user access - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 107
Syntax line { console linenum | vty startlinenum endlinenum | ssh | telnet } Parameter linenum -- The number of users allowed to login through console port. Its value is 0 in general, for the reason that console input is only active on one console port at a time. startlinenum --The start serial - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 108
to these commands. User Guidelines If the password you configured here is unencrypted and the global encryption function is enabled in service password-encryption, the password in the configuration file will be displayed in the symmetric encrypted form. Example Configure the connection password - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 109
12.9 login Description The login command is used to configure the login mode of a switch which uses connection password to login. At this situation, a connection password must be set for virtual terminal connection. Syntax login Command Mode Line Configuration Mode Privilege Requirement Only Admin - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 110
Privilege Requirement Only Admin level users have access to these commands. Example Configure the login of virtual terminal connection 0-5 as login local mode: T2600G-28TS(config)#line vty 0 5 T2600G-28TS(config-line)#login local Configure the login of Console port connection 0 as login local mode: - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 111
Receive the micro-USB console input prior to the RJ-45 console input: T2600G-28TS(config)# line console 0 T2600G-28TS(config-line)# no media-type rj45 12.12 telnet Description The telnet enable command is used to enable the Telnet function. To disable the Telnet function, please use the telnet - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 112
Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify the communication baud rate on the console port to the default value: T2600G-28TS(config)# no serial_port 12.14 show password-recovery Description The show - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 113
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the information of the current users: T2600G-28TS(config)# show user account-list 12.16 show user configuration Description The show user - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 114
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display whether the Telnet function is enabled: T2600G-28TS(config)# show telnet-status 93 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 115
Chapter 13 HTTP and HTTPS Commands With the help of HTTP (HyperText Transfer Protocol) or HTTPS (Hyper Text Transfer Protocol over Secure Socket Layer), you can manage the switch through a standard browser. HTTP is the protocol to exchange or transfer hypertext. SSL (Secure Sockets Layer), a - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 116
13.2ip http max-users (For T2600G-18TS only) Description The ip http max-users command is used to configure the maximum number of users that are allowed to connect to the HTTP server. To cancel this limitation, please use no ip http max-users command. Syntax ip http max-users admin-num operator-num - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 117
13.3ip http max-users (For other switches) Description The ip http max-users command is used to configure the maximum number of users that are allowed to connect to the HTTP server. To cancel this limitation, please use no ip http max-users command. Syntax ip http max-users admin-num guest-num no ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 118
no ip http session timeout Parameter time --The timeout time, ranging from 5 to 30 in minutes. By default, the value is 10. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the timeout time of the HTTP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 119
-protocol ssl3 13.7ip http secure-ciphersuite Description The ip http secure-ciphersuite command is used to configure the cipherSuites over the SSL connection supported by the switch. To restore to the default ciphersuite types, please use no ip http secure-ciphersuite command. Syntax ip http secure - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 120
-sha ] [ des-cbc-sha ] -- Specify the encryption algorithm and the digest algorithm to use on an SSL connection. By default, the switch supports all these ciphersuites. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 121
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the maximum number of the Admin and Guest users logging on to the HTTPs server as 5 and 3: T2600G-28TS(config)# ip http secure-max-users 5 3 13.9ip http secure-session timeout - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 122
to 25 characters. The Certificate must be BASE64 encoded. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 123
to 25 characters. The Key must be BASE64 encoded. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 124
Syntax show ip http configuration Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of the HTTP server: T2600G-28TS(config)# show ip http configuration 13.13 show ip http secure-server Description The show ip http - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 125
contains two types of ARP entries: dynamic and static. An ARP dynamic entry is automatically created and maintained by ARP. A static ARP entry is manually configured and maintained. 14.1 arp Description This arp command is used to add a static ARP entry. To delete the specified ARP entry, please use - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 126
14.2clear arp-cache Description This clear arp-cache command is used to clear all the dynamic ARP entries. Syntax clear arp-cache Command Mode Privileged EXEC Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear all the dynamic ARP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 127
Example Configure the ARP aging time as 60 seconds on interface 1/0/1: T2600G-28TS(config)# interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)# arp timeout 60 14.4show arp Description This show arp command is used to display the active ARP entries. If no parameter is speicified, all the active - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 128
Parameter port -- Specify the number of the routed port. port-channel-id -- Specify the ID of the port channel. id -- Specify the VLAN interface ID. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the ARP entry associated with VLAN interface 2 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 129
source binding Description The ip source binding command is used to bind the IP address, MAC address, VLAN ID and the Port number together manually. You can manually bind the IP address, MAC address, VLAN ID and the Port number together in the condition that you have got the related information of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 130
these commands. Example Bind an ACL entry with the IP 192.168.0.1, MAC 00:00:00:00:00:01, VLAN ID 2 and the Port number 5 manually. And then enable the entry for the ARP detection: T2600G-28TS(config)#ip source binding host1 192.168.0.1 00:00:00:00:00:01 vlan - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 131
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the DHCP Snooping function globally: T2600G-28TS(config)#ip dhcp snooping 15.3ip dhcp snooping vlan Description The ip dhcp snooping vlan command is used to enable DHCP Snooping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 132
15.4ip dhcp snooping information option Description The ip dhcp snooping information option command is used to enable the Option 82 function of DHCP Snooping. To disable the Option 82 function, please use no ip dhcp snooping information option command. Syntax ip dhcp snooping information option no - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 133
Parameter strategy -- The operations for Option 82 field of the DHCP request packets from the Host, including three types: keep: Indicates to keep the Option 82 field of the packets. It is the default option; replace: Indicates to replace the Option 82 field of the packets with the switch defined - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 134
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the customized sub- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 135
Example Enable and configure the customized sub-option Circuit ID for the Option 82 as "tplink" on port 1/0/1: T2600G-28TS(config)#interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#ip dhcp snooping information circuit-id tplink 15.8ip dhcp snooping trust Description The ip dhcp snooping trust - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 136
containing the MAC address of the Host. The MAC Verify feature is to compare the two fields and discard the packet if the two fields are different. Syntax ip dhcp snooping mac-verify no ip dhcp snooping mac-verify Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 137
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Set the Flow Control of GigabitEthernet port 2 as 20 pps: T2600G-28TS(config)#interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)#ip dhcp snooping limit rate 20 15.11 ip dhcp snooping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 138
T2600G-28TS(config-if)#ip dhcp snooping decline 20 15.12 show ip source binding Description The show ip source binding command is used to display the IP-MAC-VIDPORT binding table. Syntax show ip source binding Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 139
15.14 show ip dhcp snooping interface Description The show ip dhcp snooping interface command is used to display the DHCP Snooping configuration of a desired Gigabit Ethernet port/port channel or of all Ethernet ports/port channels. Syntax show ip dhcp snooping interface [ gigabitEthernet port | - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 140
Parameters port -- The Ethernet port number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the DHCP snooping option 82 configuration of all Ethernet ports and port channels: T2600G-28TS#show ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 141
binding Description The ipv6 source binding command is used to bind the IPv6 address, MAC address, VLAN ID and the Port number together manually. You can manually bind the IPv6 address, MAC address, VLAN ID and the Port number together in the condition that you have got the related information - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 142
to these commands. Example Bind an ACL entry with the IP 2001::1, MAC 00:00:00:00:00:01, VLAN ID 2 and the Port number 5 manually. And then enable the entry for the ND Detection: T2600G-28TS(config)#ipv6 source binding host1 2001::1 00:00:00:00:00:01 vlan 2 interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 143
Example Enable the DHCPv6 Snooping function globally: T2600G-28TS(config)#ipv6 dhcp snooping 16.3ipv6 dhcp snooping vlan Description The ipv6 dhcp snooping vlan command is used to enable DHCPv6 Snooping function on a specified VLAN. To disable DHCPv6 Snooping function on this VLAN, please use no - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 144
Syntax ipv6 dhcp snooping trust no ipv6 dhcp snooping trust Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 145
T2600G-28TS(config)#ipv6 nd snooping 16.6ipv6 nd snooping vlan Description The ipv6 nd snooping vlan command is used to enable ND Snooping function on a specified VLAN. To disable ND Snooping function on this VLAN, please use no ipv6 nd snooping vlan command. Syntax ipv6 nd snooping vlan vlan-range - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 146
Parameter value -- Specify the maximum number of ND snooping entries on this interface. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 147
16.9show ipv6 dhcp snooping Description The show ipv6 dhcp snooping command is used to display the running status of DHCPv6 Snooping. Syntax show ipv6 dhcp snooping Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the running status of DHCPv6 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 148
Example Display the DHCPv6 Snooping configuration of all Ethernet ports and port channels: T2600G-28TS#show ipv6 dhcp snooping interface Display the DHCPv6 Snooping configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ipv6 dhcp snooping interface gigabitEthernet 1/0/5 16.11 show ipv6 nd - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 149
Parameters port -- The Ethernet port number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the ND Snooping configuration of all Ethernet ports and port channels: T2600G-28TS#show ipv6 nd - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 150
Chapter 17 IP Verify Source Commands IP Verify Source is to filter the IP packets based on the IP-MAC Binding entries. Only the packets matched to the IP-MAC Binding rules can be processed, which can enhance the bandwidth utility. 17.1ip verify source Description The ip verify source command is used - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 151
17.2show ip verify source Description The show ip verify source command is used to display the IP Verify Source configuration information. Syntax show ip verify source Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the IP Verify Source - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 152
Example Display the IP verify source configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ip verify source interface gigabitEthernet 1/0/5 131 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 153
Chapter 18 IPv6 Verify Source Commands IPv6 Verify Source is to filter the IPv6 packets based on the IPv6-MAC Binding entries. Only the packets matched to the IPv6-MAC Binding rules can be processed, which can enhance the bandwidth utility. Before configuring IPv6 Verify Source feature, you should - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 154
T2600G-28TS(config)#interface range gigabitEthernet 1/0/5-10 T2600G-28TS(config-if-range)#ipv6 verify source sipv6+mac 18.2show ipv6 verify source Description The show ipv6 verify source command is used to display the IPv6 Verify Source configuration information. Syntax show ipv6 verify source - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 155
Privilege Requirement None. Example Display the IPv6 verify source configuration of Gigabit Ethernet port 1/0/5: T2600G-28TS#show ipv6 verify source interface gigabitEthernet 1/0/5 134 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 156
Chapter 19 ND Detection Commands The ND Detection feature allows the switch to detect the ND packets based on the binding entries in the IPv6-MAC Binding Table and filter out the illegal ND packets. Before configuring ND Detection, complete IPv6-MAC Binding configuration. For details, refer to IPv6- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 157
Parameter vlan-range --Enter the vlan range in the format of 1-3, 5. Command Mode Global Configuration Mode Example Enable the ND Detection function on VLAN 1,4,6-7: T2600G-28TS(config)#ipv6 nd detection vlan 1,4,6-7 19.3ipv6 nd detection trust Description The ipv6 nd detection trust command is used - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 158
19.4show ipv6 nd detection Description The show ipv6 nd detection command is used to display the ND detection global configuration including the enable/disable status. Syntax show ipv6 nd detection Command Mode Privileged EXEC Mode and Any Configuration Mode Example Display the ND Detection - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 159
Example Display the configuration of Gigabit Ethernet port 1/0/1: T2600G-28TS(config)#show ipv6 nd detection interface gigabitEthernet 1/0/1 Display the configuration of all Ethernet ports: T2600G-28TS(config)#show ipv6 nd detection interface 138 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 160
Chapter 20 ARP Inspection Commands ARP (Address Resolution Protocol) Detect function is to protect the switch from the ARP cheating, such as the Network Gateway Spoofing and Man-In-The-Middle Attack, etc. 20.1ip arp inspection(global) Description The ip arp inspection command is used to enable the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 161
Syntax ip arp inspection trust no ip arp inspection trust Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the Gigabit - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 162
Example Enable the arp defend function for the Gigabit Ethernet ports 1/0/2-6: T2600G-28TS(config)#interface range gigabitEthernet 1/0/2-6 T2600G-28TS(config-if-range)#ip arp inspection 20.4ip arp inspection limit-rate Description The ip arp inspection limit-rate command is used to configure the ARP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 163
20.5ip arp inspection recover Description The ip arp inspection recover command is used to restore a port to the ARP transmit status from the ARP filter status. Syntax ip arp inspection recover Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 164
Example Display the ARP detection configuration globally: T2600G-28TS(config)#show ip arp inspection 20.7show ip arp inspection interface Description The show ip arp inspection interface command is used to display the interface configuration of ARP detection. Syntax show ip arp inspection interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 165
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the number of the illegal ARP packets received: T2600G-28TS(config)#show ip arp inspection statistics 20.9clear ip arp inspection statistics Description The clear ip arp inspection statistics - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 166
) Attack is to occupy the network bandwidth maliciously by the network attackers or the evil programs sending a lot of service requests to the Host. With the DoS Defend enabled, the switch can analyze the specific field of the received packets and provide the defend measures - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 167
Syntax ip dos-prevent type { land | scan-synfin | xma-scan | null-scan | port-less-1024 | blat | ping-flood | syn-flood | win-nuke } no ip dos-prevent type { land | scan-synfin | xma-scan | null-scan | port-less-1024 | blat | ping-flood | syn-flood | win-nuke } Parameter land -- Land attack. scan- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 168
21.3show ip dos-prevent Description The show ip dos-prevent command is used to display the DoS information of the detected DoS attack, including enable/disable status, the DoS Defend Type, the count of the attack, etc. Syntax show ip dos-prevent Command Mode Privileged EXEC Mode and Any - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 169
LAN. Authenticator: controls the physical access to the network based on the authentication status of the supplicant. It is usually an 802.1X-supported network device, such as this TP-Link switch. It acts as an intermediary (proxy) between the supplicant and the authentication server, requesting - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 170
22.2dot1x handshake Description The dot1x handshake command is used enable the handshake feature. The handshake feature is used to detect the connection status between the TP-Link 802.1x supplicant and the switch. Please disable the handshake feature if you are using a non-TP-Link 802.1x-compliant - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 171
pap: EAP termination mode. IEEE 802.1X authentication system uses extensible authentication protocol (EAP) to exchange information between the switch and the client. The EAP packets are terminated at the switch and repackaged in the Password Authentication Protocol (PAP) packets, and then - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 172
Example Enable the enable the IEEE 802.1X accounting function globally: T2600G-28TS(config)#dot1x accounting 22.5dot1x guest-vlan(global) Description The dot1x guest-vlan command is used to enable the Guest VLAN function globally. To disable the Guest VLAN function, please use no dot1x guest-vlan - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 173
Syntax dot1x quiet-period [ time ] no dot1x quiet-period Parameter time -- The length of the quiet-period time. If one user's authentication fails, its subsequent IEEE 802.1x authentication requests will not be processed during the quiet-period time. It ranges from 1 to 999 seconds and the default - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 174
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the supplicant timeout value as 5 seconds: T2600G-28TS(config)#dot1x timeout supplicant-timeout 5 22.8dot1x max-reauth-req Description The - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 175
22.9 dot1x Description The dot1x command is used to enable the IEEE 802.1X function for a specified port. To disable the IEEE 802.1X function for a specified port, please use no dot1x command. Syntax dot1x no dot1x Command Mode Interface Configuration Mode (interface gigabitEthernet / interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 176
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Guest VLAN function for Gigabit Ethernet port 1/0/2: T2600G-28TS(config)# - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 177
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the Control Mode for Gigabit Ethernet port 20 as "authorized-force": T2600G-28TS(config)#interface gigabitEthernet 1/0/20 T2600G-28TS(config-if)#dot1x port-control authorized-force - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 178
Example Configure the Control Type for Gigabit Ethernet port 20 as "port-based": T2600G-28TS(config)#interface gigabitEthernet 1/0/20 T2600G-28TS(config-if)#dot1x port-method port-based 22.13 show dot1x global Description The show dot1x global command is used to display the global configuration of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 179
Privilege Requirement None. Example Display the configuration information of 801.X for Gigabit Ethernet port 20: T2600G-28TS(config)#show dot1x interface gigabitEthernet 1/0/20 Display the configuration information of 801.X for all Ethernet ports: T2600G-28TS(config)#show dot1x interface 158 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 180
Chapter 23 PPPoE ID-Insertion Commands The PPPoE ID-Insertion feature provides a way to extract a Vendor-specific tag as an identifier for the authentication, authorization, and accounting (AAA) access requests on an Ethernet interface. When enabled, the switch attaches a tag to the PPPoE discovery - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 181
23.2pppoe circuit-id(interface) Description The pppoe circuit-id command is used to enable the PPPoE Circuit-ID Insertion function for a specified port. To disable the PPPoE Circuit-ID Insertion function on a specified port, please use no pppoe circuit-id command. Syntax pppoe circuit-id no pppoe - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 182
ip: The IP address of the switch will be used to encode the Circuit-ID option. This is the default value. udf: A user specified string with the maximum length of 40 characters will be used to encode the Circuit-ID option. udf-only: Only the user specified string with the maximum length of 40 will be - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 183
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the remote-ID as "mac" for the Gigabit Ethernet port 1/0/1: T2600G-28TS ( - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 184
Syntax show pppoe id-insertion interface [gigabitEthernet port ] Parameter port -- The Fast/Gigabit Ethernet port number. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of PPPoE Circuit-ID Insertion function of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 185
Chapter 24 System Log Commands The log information will record the settings and operation of the switch respectively for you to monitor operation status and diagnose malfunction. 24.1logging buffer Description The logging buffer command is used to store the system log messages to an internal buffer. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 186
Syntax logging buffer level level no logging buffer level Parameter level -- Severity level of the log information output to each channel. There are 8 severity levels marked with values 0-7. The smaller value has the higher priority. Only the log with the same or smaller severity level value will be - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 187
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the log file flash function: T2600G-28TS(config)#logging file flash 24.4logging file flash frequency Description The logging file flash frequency command is used to specify the frequency to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 188
24.5logging file flash level Description The logging file flash level command is used to specify the system log message severity level. Messages will a severity level equal to or higher than this value will be stored to the flash. To restore to the default level, please use no logging file flash - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 189
Syntax logging host index idx host-ip level no logging host index idx Parameter idx -- The index of the log host. The switch supports 4 log hosts at most. host-ip -- The IP for the log host. level -- The severity level of the log information sent to each log host. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 190
Example Enable logging to the console port: T2600G-28TS(config)# logging console 24.8logging console level Description The logging console level command is used to limit messages logged to the console port. System logs no higher than the set threshold level will be displayed on the console port. To - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 191
Description The logging monitor command is used to display the system logs on the terminal devices. To disable logging to the terminal, please use no logging monitor command. This function is enabled by default. Syntax logging monitor no logging monitor Command Mode Global Configuration Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 192
Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Output the log information with severity levels between 0-7 to the terminal devices: T2600G-28TS(config)# logging monitor level 7 24.11 clear logging Description - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 193
24.12 show logging local-config Description The show logging local-config command is used to display the configuration of the Local Log output to the console, the terminal, the log buffer and the log file. Syntax show logging local-config Command Mode Privileged EXEC Mode and Any Configuration Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 194
Example Display the configuration of the log host 2: T2600G-28TS(config)# show logging loghost 2 24.14 show logging buffer Description The show logging buffer command is used to display the log information in the log buffer according to the severity level. Syntax show logging buffer [ level level ] - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 195
Parameter level -- Severity level. There are 8 severity levels marked with values 0-7. The information of levels with priority not lower than the select level will display. Display all the log information in the log file by default. Command Mode Privileged EXEC Mode and Any Configuration Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 196
Chapter 25 SSH Commands SSH (Security Shell) can provide the unsecured remote management with security and powerful authentication to ensure the security of the management information. 25.1ip ssh server Description The ip ssh server command is used to enable SSH function. To disable the SSH function - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 197
Parameter v1 | v2 -- The SSH protocol version to be enabled. They represent SSH v1 and SSH v2 respectively. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable SSH v2: T2600G-28TS(config)# ip ssh - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 198
25.4ip ssh timeout Description The ip ssh timeout command is used to specify the idle-timeout time of SSH. To restore to the factory defaults, please use ip ssh timeout command. Syntax ip ssh timeout value no ip ssh timeout Parameter value -- The Idle-timeout time. During this period, the system - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 199
must be in the range of 512 to 3072 bits. ip-addr -- The IP address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 200
Example Download an SSH-1 type key file named ssh-key from TFTP server with the IP address 192.168.0.148: T2600G-28TS(config)# ip ssh download v1 ssh-key ip-address 192.168.0.148 Download an SSH-1 type key file named ssh-key from TFTP server with the IP address fe80::1234: T2600G-28TS(config)# ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 201
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of SSH: T2600G-28TS(config)# show ip ssh 180 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 202
MAC address entry. To remove the corresponding entry, please use no mac address-table static command. The static address can be added or removed manually, independent of the aging time. In the stable networks, the static MAC address entries can facilitate the switch to reduce broadcast packets and - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 203
filtering command. The filtering address function is to forbid the undesired package to be forwarded. The filtering address can be added or removed manually, independent of the aging time. Syntax mac address-table filtering mac-addr vid vid no mac address-table filtering {[ mac-addr ] [ vid vid - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 204
vid -- The corresponding VLAN ID of the MAC address. It ranges from 1 to 4094. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Add a filtering address entry of which VLAN ID is 1 and MAC address is 00 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 205
out of the influence of the aging time and can only be deleted manually. The learned entries will be cleared after the switch is rebooted. When be out of the influence of the aging time and can only be deleted manually too. However, the learned entries will be saved even the switch is rebooted. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 206
• forward: The packets will be forward but not be learned when learned MAC number exceeds the the maximum MAC address number on this port. • drop: The packets will be dropped when learned MAC number exceeds the the maximum MAC address number on this port. • disable: The MAC address threshold on this - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 207
exceed-max-learned enable | disable -- Enable/Disable the MAC address threshold notification on this port. With this feature enabled, a SNMP notification is generated and sent to the network management system (NMS) when the MAC address threshold limit on this port is reached or exceeded. To - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 208
number -- Configure the threshold of the MAC address table in this VLAN. It ranges from 0 to 16383. forward | drop | disable -- Choose the mode when learned MAC number exceeds the threshold of the MAC address table in this VLAN. • Drop: The packets will be dropped when learned MAC number exceeds the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 209
Example Display the information of all address entries: T2600G-28TS(config)# show mac address-table 26.9clear mac address-table Description The show mac address-table command is used to clear the specified address entries. Syntax clear mac address-table { dynamic | static | filtering } Parameter - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 210
Example Display the Aging Time of the MAC address: T2600G-28TS(config)# show mac address-table aging-time 26.11 show mac address-table max-mac-count Description The show mac address-table max-mac-count interface gigabitEthernet command is used to display the security configuration of all ports or - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 211
Syntax show mac address-table interface { gigabitEthernet port | port-channel port-channel-id } Parameter port -- The Ethernet port number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 212
Description The show mac address-table address command is used to display the information of the specified MAC address. Syntax show mac address-table address mac-addr [ interface { gigabitEthernet port | port-channel port-channel-id } | vid vlan-id ] Parameter mac-addr --The specified MAC address. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 213
Example Display the MAC address configuration of vlan 1: T2600G-28TS(config)# show mac address-table vlan 1 26.16 show mac address-table notification Description The show mac address-table notification command is used to display the MAC notificaiton configuration globally or on the specified port. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 214
Privilege Requirement None. Example Display the MAC address security configuration of VLAN 1: T2600G-28TS(config)# show mac address-table security vid 1 193 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 215
the switch, upgrade the switch system and other operations. 27.1system-time manual Description The system-time manual command is used to configure the system time manually. Syntax system-time manual time Parameter time -- Set the date and time manually, MM/DD/YYYY-HH:MM:SS. The valid value of the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 216
The detailed information that each time-zone means are displayed as follow: UTC-12:00 -- TimeZone for International Date Line West. UTC-11:00 -- TimeZone for Coordinated Universal Time-11. UTC-10:00 -- TimeZone for Hawaii. UTC-09:00 -- TimeZone for Alaska. UTC-08:00 -- TimeZone for Pacific Time - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 217
backup-ntp-server -- The IP address for the Secondary NTP Server. fetching-rate -- Specify the rate fetching time from NTP server. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the system time mode as - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 218
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the daylight saving time as USA standard: T2600G-28TS(config)#system-time dst predefined USA 27.4system-time dst date Description The system-time dst date command is used to configure the one- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 219
Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure the daylight saving time from zero clock, Apr 1st to zero clock Oct 1st and the offset is 30 minutes in 2015: T2600G-28TS(config)# system-time dst date - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 220
etime -- The end moment of the daylight saving time, HH:MM. offset -- The number of minutes to add during the daylight saving time. It is 60 minutes by default. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 221
27.7 location Description The location command is used to configure the system location. To clear the system location information, please use no location command. Syntax location [ location ] no location Parameter location -- Device Location. It consists of 32 characters at most. It is "SHENZHEN" by - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 222
27.9ip address Description This ip address command is used to configure the IP address and IP subnet mask for the specified interface manually. The interface type includes: routed port, port-channel interface, loopback interface and VLAN interface. Syntax ip address { ip-addr } { mask } [ secondary - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 223
27.10 ip address-alloc Description The IP address-alloc command is used to enable the DHCP Client function or the BOOTP Protocol. When this function is enabled, the specified interface will obtain IP from DHCP Server or BOOTP server. To disable the IP obtaining function on the specified interface, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 224
27.11 reset Description The reset command is used to reset the switch's software. After resetting, all configuration of the switch will restore to the factory defaults and your current settings will be lost. Syntax reset Command Mode Privileged EXEC Mode Privilege Requirement Only Admin level users - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 225
27.13 reboot-schedule Description This reboot-schedule command is used to configure the switch to reboot at a certain time point. To delete the reboot schedule settings, please use the reboot-schedule cancel command. Syntax reboot-schedule at time [ date ] [ save_before_reboot ] reboot-schedule in - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 226
startup-config tftp ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. name -- Specify the name for the configuration file which would be backup. Command Mode Privileged EXEC Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 227
tftp startup-config ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. name -- Specify the name for the configuration file which would be downloaded. Command Mode Privileged EXEC Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 228
27.17 boot application Description The boot application command is used to configure the image file as startup image or backup image. Syntax boot application filename { image1 | image 2 } { startup | backup } no boot application Parameter image1 | image2 -- Specify the image file to be configured. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 229
Syntax firmware upgrade ip-address ip-addr filename name Parameter ip-addr -- IP Address of the TFTP server. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.1 or fe80::1234. name -- Specify the name for the firmware file. Command Mode Privileged EXEC Mode Privilege Requirement Only - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 230
upgrade the backup image. Continue? (Y/N):y Operation OK! Reboot with the backup image? (Y/N): n 27.20 boot autoinstall start Note: Only T2600G-18TS supports this command. Description The boot autoinstall start command is used to start Auto Install function. To stop the Auto Install function, use no - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 231
Example Start Auto Install function: T2600-18TS(config)# boot autoinstall persistent-mode 27.22 boot autoinstall auto-save Note: Only T2600G-18TS supports this command. Description The boot autoinstall auto-save command is used to automatically save the new configuration file that was downloaded by - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 232
Install function completed successfully: T2600-18TS(config)# boot autoinstall auto-reboot 27.24 boot autoinstall retry-count Note: Only T2600G-18TS supports this command. Description The boot autoinstall retry-count command is used to configure retry count when Auto Install function uses TFTP to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 233
the configuration of Auto Install function: T2600-18TS# show boot autoinstall 27.26 show boot autoinstall downloaded-config Note: Only T2600G-18TS supports this command. Description The show boot autoinstall downloaded-config command is used to display the configuration file which downloaded by Auto - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 234
. ip_addr -- The IP address of the destination node for ping test. If the parameter ip/ipv6 is not selected, both IPv4 and IPv6 addresses are supported, for example 192.168.0.100 or fe80::1234. -n count -- The amount of times to send test data during Ping testing. It ranges from 1 to 10 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 235
should be IPv6. ip_addr -- The IP address of the destination device. If the parameter ip/ipv6 is not selected, both IPv4 and IPv6 addresses are supported, for example 192.168.0.100 or fe80::1234. maxHops -- The maximum number of the route hops the test data can pass though. It ranges from - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 236
27.29 show system-info Description The show system-info command is used to display System Description, System Name, System Location, Contact Information, Hardware Version, Software Version, Bootloader Version, Mac Address, System Time, Run Time and so on. Syntax show system-info Command Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 237
27.31 show image-info Description The show imsage-info command is used to display the information of image files in the system. Syntax show image-info Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 238
27.33 show running-config Description The show running-config command is used to display the current operating configuration of the system or of a specified port. Syntax show running-config Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 239
27.35 show system-time Description The show system-time command is used to display the time information of the switch. Syntax show system-time Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the time information of the switch T2600G-28TS# show - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 240
of the connected Ethernet Port., which facilitates you to check the connection status of the cable connected to the switch, locate and diagnose the trouble spot of the network. Syntax show cable-diagnostics interface gigabitEthernet port Parameter port -- The number of the port which is selected for - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 241
27.39 show cable-diagnostics careful interface Description The show cable-diagnostics careful interface gigabitEthernet command is used to display the connection status of the cable connected to the switch. Syntax show cable-diagnostics careful interface [ gigabitEthernet port ] Parameter port -- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 242
T2600G-28TS# show cpu-utilization 27.41 show memory-utilization Description The show memory-utilization command is used to display the system's memory utilization in the last 5 seconds/1minute/5minutes. Syntax show memory-utilization Command Mode Privileged EXEC Mode and Any Configuration Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 243
enable the automatic configuration of the ipv6 link-local address. The switch has only one ipv6 link-local address, which can be configured automatically or manually. The general ipv6 link-local address 222 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 244
address autoconfig 28.3ipv6 address link-local Description The ipv6 address link-local command is used to configure the ipv6 link-local address manually on a specified interface. To delete the configured link-local address, please use no ipv6 address link-local command. Syntax ipv6 address ipv6-addr - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 245
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the link-local address as fe80::1234 on the VLAN interface 1: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 address fe80::1234 link-local 28.4ipv6 address dhcp - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 246
1: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 address ra 28.6ipv6 address eui-64 Description This command is used to manually configure a global IPv6 address with an extended unique identifier (EUI) in the low-order 64 bits on the interface. Specify only the network prefix - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 247
-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ipv6 address 3ffe::/64 eui-64 28.7ipv6 address Description This command is used to manually configure a global IPv6 address on the interface. To remove a global IPv6 address from the interface, please use no ipv6 address command. Syntax ipv6 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 248
Description This command is used to display the configured ipv6 information of the management interface, including ipv6 function status, link-local address and global address, ipv6 multicast groups etc. Syntax show ipv6 interface Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 249
Chapter 29 Ethernet Configuration Commands Ethernet Configuration Commands can be used to configure the Bandwidth Control, Negotiation Mode and Storm Control for Ethernet ports. 29.1interface gigabitEthernet Description The interface gigabitEthernet command is used to enter the Interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 250
Syntax interface range gigabitEthernet port-list Parameter port-list -- The list of Ethernet ports. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. User Guidelines Command in the Interface Range - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 251
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Add a description Port_5 to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 252
Description The flow-control command is used to enable the flow-control function for a port. To disable the flow-control function for this corresponding port, please use no flow-control command. With the flow-control function enabled, the Ingress Rate and Egress Rate can be synchronized to avoid - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 253
. Example Allow jumbo frame on port 1/0/3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# jumbo 29.8 jumbo-size Note: Only T2600G-18TS supports this command. Description The jumbo-size command is used to specify the size of jumbo frames. Syntax jumbo-size size 232 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 254
Parameter size -- The value of jumbo frames. It ranges from 1518 to 9216 bytes, and the default is 1518 bytes. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Globally configure the size of jumbo - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 255
29.10 storm-control pps Note: T2600G-18TS doesn't support this command. Description The storm-control pps command is used to configure the storm control mode as pps(packets per second) on an interface. To - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 256
Parameter broadcast | multicast | unicast -- Enable broadcast/multicast/unicast storm control on the interface. kbps | ratio | pps -- Specify the storm control type. kbps: Specify the threshold in kbits per second. ratio: Specify the threshold as a percentage of the bandwidth. pps: Specify the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 257
Parameter ingress-rate -- Specify the bandwidth for receiving packets. Range: 1-1000000Kbps for the gigaport. egress-rate -- Specify the bandwidth for sending packets. Range: 1-1000000Kbps for the gigaport. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 258
Example Clear the statistic information of all ports and port channels: T2600G-28TS(config)# clear counters 29.14 show interface status Description The show interface status command is used to display the connection status of the Ethernet port/port channel. Syntax show interface status [ - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 259
port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the statistics information of all Ethernet ports and port channels: T2600G-28TS(config)# show interface counters Display the statistics information - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 260
29.17 show storm-control Description The show storm-control command is used to display the storm-control information of Ethernet ports. Syntax show storm-control interface [ gigabitEthernet port-list ] [ port-channel port-channel-id-list ] Parameter port-list --The list of Ethernet ports. port- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 261
Privilege Requirement None. Example Display the bandwidth-limit information of port 1/0/4: T2600G-28TS(config)# show bandwidth interface gigabitEthernet 1/0/4 240 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 262
of a better quality. 30.1qos (For T2600G-18TS only) Description The qos command is used to configure CoS (Class of Service) based on port. To return to the default configuration, please use no qos command. Syntax qos tc-id no qos Parameter tc-id -- The priority - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 263
Description The qos command is used to configure CoS (Class of Service) based on port. To return to the default configuration, please 1/0/5 T2600G-28TS(config-if)# qos 3 30.3qos cos Note: Only T2600G-18TS supports this command. Description The qos cos command is used to enable the mapping relation - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 264
Syntax qos cos no qos cos Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. User Guidelines IEEE 802.1P gives the Pri field in IEEE 802.1Q tag a recommended definition. When the mapping relation between IEEE - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 265
datagram will be classified into the egress queue based on the mapping relation between DSCP priority and CoS value. Example Enable the mapping relation between DSCP Priority and CoS value: T2600G-28TS(config)# qos dscp 30.5qos queue cos-map Description The qos queue cos-map command is used to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 266
Example Map CoS 5 to TC 2: T2600G-28TS(config)# qos queue cos-map 5 2 30.6qos queue dscp-map (For T2600G-18TS only) Description The qos queue dscp-map command is used to configure the mapping relation between DSCP Priority and the CoS value. To return to the default configuration, please use no qos - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 267
Example Map DSCP values 10-12 to TC 2: T2600G-28TS(config)# qos queue dscp-map 10-12 2 30.7qos queue dscp-map (For other switches) Description The qos queue dscp-map command is used to configure the mapping relation between DSCP Priority and the CoS value. To return to the default configuration, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 268
Example Map DSCP values 10-12 to CoS 2: T2600G-28TS(config)# qos queue dscp-map 10-12 2 30.8qos queue mode Description The qos queue mode command is used to configure the Schedule Mode. To return to the default Equal-Mode, please use no qos queue mode command. When the network is congested, the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 269
equ -- Equal-Mode. In this mode, all the queues occupy the bandwidth equally. The weight value ratio of all the queues is 1:1:1:1:1:1:1:1 Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 270
weight values of TC0, TC1, TC2, TC3, TC4, TC5 and TC6 are 1, 2, 4, 8, 16, 32 and 64 respectively, while the value of TC7 is 0 and non-configurable. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 271
Display the configuration of QoS for ports 1/0/1-4: T2600G-28TS# show qos interface gigabitEthernet 1/0/1-4 30.11 show qos cos-map Description The show qos cos-map command is used to display the configuration of IEEE 802.1P Priority and the mapping relation between cos-id and tc-id. Syntax show qos - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 272
30.13 show qos queue mode Description The show qos queue mode command is used to display the schedule rule of the egress queues. Syntax show qos queue mode Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the schedule rule of the egress queues: - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 273
, the monitoring port is connected to data diagnose device, which is used to analyze the monitored packets for monitoring and troubleshooting the network. 31.1monitor session destination interface Description The monitor session destination interface command is used to configure the monitoring port - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 274
T2600G-28TS(config)# no monitor session 1 destination interface gigabitEthernet 1/0/2 Delete the monitor session 1: T2600G-28TS(config)# no monitor session 1 31.2monitor session source interface Description The monitor session source interface command is used to configure the monitored port. To - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 275
3. Whether the monitoring port and monitored ports are in the same VLAN or not is not demanded strictly. 4. The monitoring port and monitored ports cannot be link-aggregation member. Example Create monitor session 1, then configure port 4, 5, 7 as monitored port and enable ingress monitoring: T2600G - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 276
Chapter 32 Port Isolation Commands Port Isolation provides a method of restricting traffic flow to improve the network security by forbidding the port to forward packets to the ports that are not on its forwarding port list. 32.1port isolation Description The port isolation command is used to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 277
32.2show port isolation interface Description The show port isolation interface command is used to display the forward port list of a port/port channel. Syntax show port isolation interface [ gigabitEthernet port | port-channel port-channel-id ] Parameter port -- The number of Ethernet port you want - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 278
Chapter 33 Loopback Detection Commands With loopback detection feature enabled, the switch can detect loops using loopback detection packets. When a loop is detected, the switch will display an alert or further block the corresponding port according to the configuration. 33.1 loopback-detection( - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 279
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the interval-time as 50 seconds: T2600G-28TS(config)# loopback-detection interval 50 33.3loopback-detection recovery-time Description The - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 280
by which the switch copes with the detected loops. Syntax loopback-detection config [ process-mode { alert | port-based }] [ recovery-mode { auto | manual }] Parameter process-mode -- The mode how the switch processes the detected loops. Alert: When a loop is detected, display an alert. Port based - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 281
User level users have access to these commands. Example Configure the loopback detection process-mode as port-based and recovery-mode as manual for port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# loopback-detection config process-mode port-based recovery-mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 282
Description The show loopback-detection global command is used to display the global configuration of loopback detection function such as loopback detection global status, loopback detection interval and loopback detection recovery time. Syntax show loopback-detection global Command Mode Privileged - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 283
Display the configuration of loopback detection function and the status of port 5: T2600G-28TS# show loopback-detection interface gigabitEthernet 1/0/5 262 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 284
Chapter 34 DDM Commands The DDM (Digital Diagnostic Monitoring) function allows the user to monitor the status of the SFP modules inserted into the SFP ports on the switch. The user can choose to shut down the monitoring SFP port automatically when specified parameter exceeds the alarm threshold or - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 285
Syntax ddm shutdown { none | warning | alarm } Parameter none -- The port will never be shut down regardless of the exceeding alarm threshold and warning threshold events. warning -- Shut down the port when an exceeding warning threshold event is encountered. alarm -- Shut down the port when an - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 286
high_warning --Specify the highest threshold for the warning. When the operating parameter rises above the value hereinafter, action associated with the warning will be taken. low_alarm --Specify the lowest threshold for the alarm. When the operating parameter falls below the value hereinafter, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 287
low_alarm --Specify the lowest threshold for the alarm. When the operating parameter falls below the value hereinafter, action associated with the alarm will be taken. low_warning -- Specify the lowest threshold for the warning. When the operating parameter falls below the value hereinafter, action - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 288
low_warning -- Specify the lowest threshold for the warning. When the operating parameter falls below the value hereinafter, action associated with the warning will be taken. value -- Enter the threshold value in mA. Default Setting None. Command Mode Interface Configuration Mode (interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 289
value -- Enter the threshold value in mW. Default Setting None. Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure the high_alarm threshold of DDM Tx Power on the port 1/0/ - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 290
Command Mode Interface Configuration Mode (interface fastEthernet / interface range fastEthernet / interface gigabitEthernet / interface range gigabitEthernet) Example Configure the high_alarm threshold of DDM Rx Power on the port 1/0/25 as 5: T2600G-28TS(config)#interface gigabitEthernet 1/0/25 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 291
34.9show ddm status Description The show ddm status command is used to display the DDM status, which is the digital diagnostic monitoring status of SFP modules inserting into the switch's SFP ports. Syntax show ddm status Command Mode Privileged EXEC Mode and Any Configuration Mode Example View the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 292
Chapter 35 ACL Commands ACL (Access Control List) is used to filter data packets by configuring a series of match conditions, operations and time ranges. It provides a flexible and secured access control policy and facilitates you to control the network security. 35.1 time-range Description The time - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 293
Syntax absolute start start-date end end-date no absolute Parameter start-date -- The start date in Absoluteness Mode, in the format of MM/DD/YYYY. By default, it is 01/01/1970. end-date -- The end date in Absoluteness Mode, in the format of MM/DD/YYYY. By default, it is 12/31/2099. The Absoluteness - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 294
Parameter week-day -- Periodic Mode, in the format of 1-3,6 or daily, weekend, weekdays. 1-3, 6 represent Monday, Tuesday, Wednesday and Saturday; daily represents every day; weekend represents weekend and weekdays represents working day. By default, the Periodic Mode is disabled. time-slice -- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 295
T2600G-28TS(config-time-range)#holiday 35.5 holiday(global) Description The holiday command is used to define a holiday. To delete the corresponding holiday, please use no holiday command. Syntax holiday name start-date start-date end-date end-date no holiday Parameter name -- The holiday name, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 296
Parameter access-list-num -- ACL ID, ranging from 0 to 4499. The ID range of the MAC ACL is 0-499, the Standard-IP ACL is 500-1499, the Extend-IP ACL is 1500-2499, the Combined ACL is 2500-3499 and the IPv6 ACL is 3500-4499. Command Mode Global Configuration Mode Privilege Requirement Only Admin, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 297
35.8access-list standard Description The access-list standard command is used to add Standard-IP ACL rule. To delete the corresponding rule, please use no access-list standard command. Standard-IP ACLs analyze and process data packets based on a series of match conditions, which can be the source IP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 298
255.255.255.0, the time-range for the rule to take effect is "tRange1", and the packets match this rule will be forwarded by the switch: T2600G-28TS(config)# access-list create 520 T2600G-28TS(config)# access-list standard 520 rule 10 permit sip 192.168.0.100 smask 255.255.255.0 tseg tSeg1 35. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 299
s-port -- The source port number. d-port -- The destination port number. tcpflag -- Specify the flag value when using TCP protocol. protocol -- Configure the value of the matching protocol. tos -- Enter the IP ToS contained in the rule. pre -- Enter the IP Precedence contained in the rule. Command - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 300
Parameter acl-id -- The desired Standard-IP ACL for configuration. rule-id -- The rule ID. deny -- The operation to discard packets. permit --The operation to forward packets. It is the default value. source-mac -- The source MAC address contained in the rule. source-mac-mask -- The source MAC - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 301
Example Create a Combined ACL whose ID is 2700, and add Rule 10 for it. In the rule, the source MAC address is 00:01:3F:48:16:23, the source MAC address mask is 11:11:11:11:11:00, the source IP address is 192.168.0.100, the source IP address mask is 255.255.255.0, the time-range for the rule to take - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 302
is required if you typed the destination IP address. s-port -- The source port number. d-port -- The destination port number. (Note: T2600G-18TS doesn't support s-port and d-port setting.) time-segment -- The time-range for the rule to take effect. By default, it is not limited. Command Mode Global - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 303
no rule rule-id Parameter rule-id -- The rule ID. deny -- The operation to discard packets. permit --The operation to forward packets. It is the default value. source-mac -- The source MAC address contained in the rule. source-mac-mask -- The source MAC address mask. It is required if you typed the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 304
35.13 access-list policy name Description The access-list policy name command is used to add Policy. To delete the corresponding Policy, please use no access-list policy name command. A Policy is used to control the data packets those match the corresponding ACL rules by configuring ACLs and actions - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 305
Parameter policy-name -- The Policy Name, ranging from 1 to 16 characters. acl-id -- The ID of the ACL to which the above policy is applied. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Add ACL - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 306
35.16 s-condition Description The s-condition command is used to configure Stream Condition function of policy action. Syntax s-condition rate rate osd { none | discard } Parameter rate -- The rate of Stream Condition, ranging from 0 to 1000000kbps. osd -- Out of Band disposal of Stream Condition. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 307
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Edit the actions for policy1. Specify the mirror port as Gigabit Ethernet port 1/0/2 for the data packets matching ACL 120: T2600G-28TS(config)#access-list policy action policy1 120 T2600G- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 308
-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# access-list bind acl 100 35.20 access-list bind acl(vlan) Note: Packet content ACL doesn't support VLAN bind. Description The access-list bind acl command is used to bind an ACL to the specified VLAN. To cancel the bind relation - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 309
Parameter acl-id -- The ID of the ACL desired to bind. Command Mode Interface VLAN Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Bind ACL 100 to VLAN 2: T2600G-28TS(config)# interface vlan 2 T2600G-28TS(config-if)# access-list bind - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 310
packet-content profile chunk-offset0 0 chunk-offset1 1 chunk-offset2 2 chunk-offset3 3 35.23 access-list packet-content config Note: T2600G-18TS doesn't support this command. Description The access-list packet-content config command is used to add Packet Content ACL rule. To delete the corresponding - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 311
(config)# access-list packet-content profile chunk-offset0 0 chunk-offset1 1 chunk-offset2 2 chunk-offset3 3 35.24 access-list bind(vlan) Note: Packet content ACL doesn't support VLAN bind. 290 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 312
Description The access-list bind command is used to bind a policy to a VLAN. To cancel the bind relation, please use no access-list bind command. Syntax access-list bind policy-name no access-list bind policy-name Parameter policy-name -- The name of the policy desired to bind. Command Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 313
T2600G-28TS(config)# show access-list 20 35.26 show access-list policy Description The show access-list policy command is used to display the information of a specified policy. Syntax show access-list policy name Parameter name -- The Policy Name desired to show. Command Mode Privileged EXEC Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 314
Chapter 36 MSTP Commands MSTP (Multiple Spanning Tree Protocol), compatible with both STP and RSTP and subject to IEEE 802.1s, can disbranch a ring network. STP is to block redundant links and backup links as well as optimize paths. 36.1debug spanning-tree Description The debug spanning-tree command - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 315
Privilege Requirement Only Admin level users have access to these commands. Example Display all the spanning-tree debug messages: T2600G-28TS# debug spanning-tree all 36.2 spanning-tree(global) Description The spanning-tree command is used to enable STP function globally. To disable the STP function - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 316
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the STP function for port 1/0/2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree 36.4spanning-tree common-config Description The spanning- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 317
default, it is automatic. It ranges from o to 2000000. By default, it is 0 which is mean auto. portfast -- Enable/ Disable Edge Port. By default, it is disabled. The edge port can transit its state from blocking to forwarding rapidly without waiting for forward delay. point-to-point -- The P2P link - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 318
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the spanning-tree mode as mstp: T2600G-28TS(config)# spanning-tree mode mstp 36.6spanning-tree mst configuration Description The spanning-tree - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 319
please use no instance command. When an instance is disabled, the related mapping VLANs will be removed. Syntax instance instance-id vlan vlan-id no instance instance-id [ vlan vlan-id ] Parameters instance-id -- Instance ID, ranging from 1 to 8. vlan-id -- The VLAN ID selected to mapping with the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 320
Parameters name -- The region name, used to identify MST region. It ranges from 1 to 32 characters. Command Mode MST Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the region name of MST as "region1": T2600G- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 321
Description The spanning-tree mst instance command is used to configure the priority of MST instance. To return to the default value of MST instance priority, please use no spanning-tree mst instance command. Syntax spanning-tree mst instance instance-id priority pri no spanning-tree mst instance - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 322
Parameter instance-id -- Instance ID, ranging from 1 to 8. pri -- Port Priority, which must be multiple of 16 ranging from 0 to 240. By default, it is 128. Port Priority is an important criterion on determining if the port will be chosen as the root port by the device connected to this port. cost -- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 323
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the bridge priority as 4096: T2600G-28TS(config)# spanning-tree priority 4096 36.13 spanning-tree timer Description The spanning-tree timer command is used to configure forward-time - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 324
T2600G-28TS(config)# spanning-tree timer forward-time 16 hello-time 3 max-age 22 36.14 spanning-tree hold-count Description The spanning-tree hold-count command is used to configure the maximum number of BPDU packets transmitted per Hello Time interval. To return to the default configurations, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 325
Parameter value -- The maximum number of hops that occur in a specific region before the BPDU is discarded, ranging from 1 to 40 in hop. By default, it is 20. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 326
Description The spanning-tree bpduguard command is used to enable the BPDU protect function for a port. With the BPDU protect function enabled, the port will set itself automatically as ERROR-PORT when it receives BPDU packets, and the port will disable the forwarding function for a while. To - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 327
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the Loop Protect function for port 2: T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree guard loop 36.19 spanning-tree guard root Description - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 328
function, please use no spanning-tree guard tc command. A switch removes MAC address entries upon receiving TC-BPDUs. If a malicious user continuously sends TC-BPDUs to a switch, the switch will be busy with removing MAC address entries, which may decrease the performance and stability of the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 329
T2600G-28TS(config)# interface gigabitEthernet 1/0/2 T2600G-28TS(config-if)# spanning-tree mcheck 36.22 show spanning-tree active Description The show spanning-tree active command is used to display the active information of spanning-tree. Syntax show spanning-tree active Command Mode Privileged - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 330
36.24 show spanning-tree interface Description The show spanning-tree interface command is used to display the spanning-tree information of all ports or a specified port. Syntax show spanning-tree interface [ gigabitEthernet port | port-channel port-channel-id ] [ edge | ext-cost | int-cost | mode | - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 331
Syntax show spanning-tree interface-security [ gigabitEthernet port | port-channel port-channel-id ] [ bpdufilter | bpduguard | loop | root | tc | tc-defend ] Parameter port -- The Ethernet port number. port-channel-id -- The ID of the port channel. Command Mode Privileged EXEC Mode and Any - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 332
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the region information and mapping information of VLAN and MST Instance: T2600G-28TS(config)#show spanning-tree mst configuration Display the related information of MST Instance 1: T2600G-28TS( - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 333
Ethernet OAM Commands Ethernet OAM (standing for Operation, Administration, and Maintenance) is Layer 2 protocol that is used for monitoring and troubleshooting Ethernet networks. It can report the network status to network administrators through the OAMPDUs exchanged between two OAM entities. The - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 334
Syntax ethernet-oam mode { passive | active } no ethernet-oam mode Parameter passive -- Specify the OAM mode as passive. active --Specify the OAM mode as active. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 335
window -- Configure the error symbol-period event detection interval. The range is from 10 to 600, in terms of 100 ms intervals. The default value is 10. notify -- Enable/Disable the event notification. By default, it is enabled. threshold | window | notify -- The parameter that you want to return - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 336
notify -- Enable/Disable the event notification. By default, it is enabled. threshold | window | notify -- The parameter that you want to return to the default configuration. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 337
threshold | window | notify -- The parameter that you want to return to the default configuration. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin and Operator level users have access to these commands. Example - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 338
threshold | window | notify -- The parameter that you want to return to the default configuration. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin and Operator level users have access to these commands. Example - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 339
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin and Operator level users have access to these commands. Example Disable the Dying Gasp link event notification on Gigabit Ethernet port 1/0/7: T2600G-28TS(config)# - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 340
1/0/1 T2600G-28TS(config-if)# ethernet-oam remote-loopback received -remote-loopback process 37.9ethernet-oam remote-loopback Note: T2600G-18TS doesn't support this command. Description The ethernet-oam remote-loopback command is used to request the remote peer to start or stop the Ethernet OAM - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 341
37.10 clear ethernet-oam statistics Description The clear ethernet-oam statistics command is used to clear Ethernet OAM statistics. Syntax clear ethernet-oam statistics [ interface gigabitEthernet port ] Parameter port -- The Gigabit Ethernet port number. By default, the Ethernet OAM statistics of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 342
Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Clear Ethernet OAM event log of Gigabit Ethernet port 1/0/3: T2600G-28TS(config)# clear ethernet-oam event-log interface gigabitEthernet 1/0/3 37.12 show ethernet- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 343
37.13 show ethernet-oam event-log Description The show ethernet-oam event-log command is used to display the Ethernet OAM event log. Syntax show ethernet-oam event-log [ interface gigabitEthernet port ] Parameter port -- The Gigabit Ethernet port number. By default, the Ethernet OAM event logs of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 344
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Display Ethernet OAM statistics of Gigabit Ethernet port 1/0/2: T2600G-28TS(config)# show ethernet-oam statistics interface gigabitEthernet - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 345
state of fiber-optic or twisted-pair Ethernet cables. When a unidirectional link is detected, the corresponding port will be shut down automatically or manually (depending on the shut mode configured). 38.1 dldp(global) Description The dldp command is used to enable the DLDP function globally. To - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 346
-mode Description The dldp shut-mode command is used to configure the shutdown mode when a unidirectional link is detected. Syntax dldp shut-mode { auto | manual } Parameter auto -- The switch automatically shuts down ports when a unidirectional link is detected. By default, the shut-mode is auto - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 347
38.4dldp reset(global) Description The dldp reset command is used to reset all the unidirectional links and restart the link detect process. Syntax dldp reset Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Reset - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 348
T2600G-28TS (config-if-range)# dldp 38.6dldp reset(interface) Description The dldp reset command is used to reset the specified port and restart the link detect process. Syntax dldp reset Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 349
Example Display the global configuration of DLDP function: T2600G-28TS# show dldp 38.8show dldp interface Description The show dldp interface command is used to display the configuration and state of the specified Ethernet port. By default, the configuration and state of all the ports will be - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 350
Chapter 39 IGMP Snooping Commands IGMP Snooping (Internet Group Management Protocol Snooping) is a multicast control mechanism running on Layer 2 switch. It can effectively prevent multicast groups being broadcasted in the network. 39.1ip igmp snooping(global) Description The ip igmp snooping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 351
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet / interface port-channel / interface range port-channel) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable IGMP Snooping function - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 352
39.4ip igmp snooping mtime Description The ip igmp snooping mtime command is used to specify member port aging time globally. The default aging time is 260 seconds. To restore the default timer, please use no ip igmp snooping mtime command. Syntax ip igmp snooping mtime mtime no ip igmp snooping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 353
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP report suppression function: T2600G-28TS(config)# ip igmp snooping report-suppression 39.6ip igmp snooping immediate-leave Description The ip igmp snooping immediate-leave - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 354
Syntax ip igmp snooping drop-unknown no ip igmp snooping drop-unknown Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the operation to process unknown multicast as discard: T2600G-28TS(config - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 355
39.9ip igmp snooping last-listener query-count Description The ip igmp snooping last-listener query-count command is used to specify the numbers of Specific Query Message to be sent. The default value is 2. To restore the default number, please use no ip igmp snooping last-listener query-count - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 356
no ip igmp snooping vlan-config vlan-id-list [ rtime router-time | mtime member-time | rport interface { gigabitEthernet port-list | port-channel port-channel-id } ] no ip igmp snooping vlan-config vlan-id-list static ip interface { gigabitEthernet port-list | port-channel port-channel-id } - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 357
T2600G-28TS(config)# ip igmp snooping vlan-config 2 static 225.0.0.1 interface gigabitEthernet 1/0/1-3 39.11 ip igmp snooping vlan-config (router-port-forbidden) Description This command is used to forbid the specified ports as being router ports in the specified VLAN(s). To delete the forbidden - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 358
39.12 ip igmp snooping multi-vlan-config Description The ip igmp snooping multi-vlan-config command is used to create Multicast VLAN. To delete the corresponding Multicast VLAN, please use no ip igmp snooping multi-vlan-config command. To restore the default values, please use no ip igmp snooping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 359
T2600G-28TS(config)# ip igmp snooping multi-vlan-config 3 rtime 100 T2600G-28TS(config)# ip igmp snooping multi-vlan-config 3 mtime 100 T2600G-28TS(config)# ip igmp snooping multi-vlan-config 3 rport interface gigabitEthernet 1/0/3 39.13 ip igmp snooping multi-vlan-config (router-port-forbidden) - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 360
39.14 ip igmp snooping multi-vlan-config (source-ip-replace) Description This command is used to replace the multicast source IP address of the IGMP packets in the specified multicast VLAN. To delete the forbidden router ports, please use no ip igmp snooping multi-vlan-config replace-sourceip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 361
no ip igmp snooping querier vlan vlan-id Parameter vlan-id - VLAN ID, ranging from 1 to 4094. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the IGMP Snooping Querier function of VLAN 1: - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 362
Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example For VLAN 2, specify its query-interval as 200 seconds, and the response-time as 20 seconds: T2600G-28TS(config)#ip igmp snooping querier vlan 2 query- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 363
replace -- When the number of the dynamic multicast groups that a port joins has exceeded the max-group, the newly joined multicast group will replace an existing multicast group with the lowest multicast group address. Command Mode Interface Configuration Mode (interface gigabitEthernet / interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 364
User Guidelines The IGMP Authentication feature will take effect only when AAA function is enabled and the RADIUS server is configured. For how to enable AAA function and configure RADIUS server, please refer to aaa enable and radius-server host. Example Enable IGMP authentication on port 1/0/3: - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 365
Syntax ip igmp profile id no ip igmp profile id Parameter id -- Specify the id of the configuration profile, ranging from 1 to 999. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create the profile - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 366
39.22 permit Description The permit command is used to configure the filtering mode of profile as permit. Syntax permit Command Mode Profile Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure the filtering mode of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 367
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure one of the filter multicast address entry as range 225.1.1.1 to 226.3.2.1 in profile 1: T2600G-28TS(config)# ip igmp profile 1 T2600G-28TS(config-igmp-profile)#range 225.1.1.1 226 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 368
Syntax clear ip igmp snooping statistics Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear the statistics of the IGMP packets: T2600G-28TS(config)# clear ip igmp snooping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 369
show ip igmp snooping interface [ port-channel [ port-channel-id ] ] { basic-config | max-groups } Parameter port -- The Ethernet port number. port-list -- The list of Ethernet ports. basic-config | max-groups | packet-stat -- The related configuration information selected to display. Command Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 370
Privilege Requirement None. Example Display the IGMP snooping configuration information of VLAN 2: T2600G-28TS# show ip igmp snooping vlan 2 39.29 show ip igmp snooping multi-vlan Description The show ip igmp snooping multi-vlan command is used to display the Multicast VLAN configuration. Syntax - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 371
count-- The numbers of all multicast groups. dynamic-- Display dynamic multicast groups. dynamic count-- The numbers of all dynamic multicast groups. static-- Display static multicast groups. static count-- The numbers of all static multicast groups. Command Mode Privileged EXEC Mode and Any - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 372
Syntax show ip igmp snooping querier [ vlan vlan-id ] Parameter vlan-id --The VLAN ID selected to display, ranging from 1 to 4094. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display all Querier information: T2600G-28TS(config)# show ip igmp - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 373
Chapter 40 MLD Snooping Commands MLD Snooping (Multicast Listener Discovery Snooping) is a multicast control mechanism running on Layer 2 switch. It can effectively prevent multicast groups being broadcasted in the IPv6 network. 40.1ipv6 mld snooping(global) Description The ipv6 mld snooping command - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 374
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable MLD Snooping on port 1/0/3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config-if)# ipv6 mld snooping 40.3ipv6 mld snooping rtime Description The ipv6 mld snooping rtime - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 375
Parameter mtime -- Specify the aging time in seconds, ranging from 60 to 600. The default aging time is 260 seconds. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify MLD Snooping member port aging time as - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 376
Description The ipv6 mld snooping immediate-leave command is used to configure the Fast Leave function for port. To disable the Fast Leave function, please use no ipv6 mld snooping immediate-leave command. Syntax ipv6 mld snooping immediate-leave no ipv6 mld snooping immediate-leave Command Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 377
40.8ipv6 mld snooping last-listener query-inteval Description The ipv6 mld snooping last-listener query-inteval command is used to specify the interval to send Specific Query Message. The default value is 1 second. To restore the default interval, please use no ipv6 mld snooping last-listener query- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 378
Privilege Requirement Only Admin and Operator level users have access to these commands. Example Specify the number of Specific Query Message to 3: T2600G-28TS(config)# ipv6 mld snooping last-listener query-count 3 40.10 ipv6 mld snooping vlan-config Description The ipv6 mld snooping vlan-config - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 379
port-channel-id -- The ID of the port channels. ip -- The static multicast IP address. Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Enable the MLD Snooping function and modify Router Port Time as 300 seconds, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 380
Parameter vlan-id-list -- The ID list of the VLAN desired to modify configuration, ranging from 1 to 4094, in the format of 1-3, 5. port-list -- Forbid the specified ports as being router ports. Packets sent from multicast routers to these ports will be discarded. port-channel-id -- Forbid the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 381
router-time -- Router Port Time. Within this time, if the switch does not receive IGMP query message from the router port, it will consider this port is not a router port any more. Router Port Time ranges from 60 to 600 in seconds. By default, it is 0 and the global router-time will be used. member- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 382
no ipv6 mld snooping multi-vlan-config router-port-forbidd [ interface { gigabitEthernet port-list | port-channel port-channel-id } ] Parameter vlan-id-- The ID of the multicast VLAN. port-list -- Forbid the specified ports as being router ports. Packets sent from multicast routers to these ports - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 383
Privilege Requirement Only Admin level users have access to these commands. Example Replace the source IP address of the MLD packets in multicast VLAN 1 as fe80::02ff:ffff:fe00:0001: T2600G-28TS(config)# ipv6 mld snooping multi-vlan-config 1 replace-sourceip fe80::02ff:ffff:fe00:0001 40.15 ipv6 mld - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 384
return to the default configuration, please use no ipv6 mld snooping querier vlan command. Syntax ipv6 mld snooping querier vlan vlan-id { query-interval interval | max-response-time response-time | general-query source-ip ip-addr } no ipv6 mld snooping querier vlan vlan-id { query-interval | max- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 385
receives an MLD report message and the maximum number of entries is in the forwarding table. To remove the maximum group limitation and return to the default of no limitation on the specified port, please use the no ipv6 mld snooping max-groups command. To return to the default action of dropping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 386
40.18 ipv6 mld profile Description The ipv6 mld profile command is used to create the configuration profile. To delete the corresponding profile, please use no ipv6 mld profile command. Syntax ipv6 mld profile id no ipv6 mld profile id Parameter id -- Specify the id of the configuration profile, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 387
T2600G-28TS(config)# ipv6 mld profile 1 T2600G-28TS(config-igmp-profile)#deny 40.20 permit Description The permit command is used to configure the filtering mode of profile as permit. Syntax permit Command Mode Profile Configuration Mode Privilege Requirement Only Admin and Operator level users have - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 388
Command Mode Profile Configuration Mode Privilege Requirement Only Admin and Operator level users have access to these commands. Example Configure one of the filter multicast address entry as range ff80::1234 to ff80::1235 in profile 1: T2600G-28TS(config)# ipv6 mld profile 1 T2600G-28TS(config-igmp - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 389
Syntax clear ipv6 mld snooping statistics Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Clear the statistics of the MLD packets: T2600G-28TS(config)# clear ipv6 mld snooping - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 390
show ipv6 mld snooping interface [ port-channel [ port-channel-id ] ] { basic-config | max-groups } Parameter port -- The Ethernet port number. port-list -- The list of Ethernet ports. basic-config | max-groups | packet-stat -- The related configuration information selected to display. Command Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 391
Privilege Requirement None. Example Display all of the VLAN information: T2600G-28TS(config)# show ipv6 mld snooping vlan 40.27 show ipv6 mld snooping multi-vlan Description The show ipv6 mld snooping multi-vlan command is used to display the Multicast VLAN configuration. Syntax show ipv6 mld - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 392
dynamic count-- The numbers of all dynamic multicast groups. static-- Display static multicast groups. static count-- The numbers of all static multicast groups. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display all of the multicast groups: - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 393
Syntax show ipv6 mld profile [ id ] Parameter id -- Specify the ID of the profile, ranging from 1 to 999. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration information of all profiles: T2600G-28TS(config)# show ipv6 mld profile - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 394
Chapter 41 SNMP Commands SNMP (Simple Network Management Protocol) functions are used to manage the network devices for a smooth communication, which can facilitate the network administrators to monitor the network nodes and implement the proper operation. 41.1 snmp-server Description The snmp- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 395
Parameter name -- The entry name of View, ranging from 1 to 16 characters. Each View includes several entries with the same name. mib-oid -- MIB Object ID. It is the Object Identifier (OID) for the entry of View, ranging from 1 to 61 characters. include | exclude -- View Type, with include and - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 396
Parameter name --The SNMP Group name, ranging from 1 to 16 characters. The Group Name, Security Model and Security Level compose the identifier of the SNMP Group. These three items of the Users in one group should be the same. smode -- Security Model, with v1、v2c and v3 options. They represent SNMP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 397
41.4snmp-server user Description The snmp-server user command is used to add User. To delete the corresponding User, please use no snmp-server user command. The User in an SNMP Group can manage the switch via the management station software. The User and its Group have the same security level and - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 398
emode -- The Privacy Mode of the SNMP v3 User, with none and DES options. None indicates no privacy method is used, and DES indicates DES encryption method is used. By default, the Privacy Mode is "none". encrypt-pwd -- Privacy Password, ranging from 1 to 16 characters. The question marks and spaces - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 399
retries ] [ timeout timeout ] no snmp-server host ip user-name Parameter ip -- The IP Address of the management Host. Both IPv4 and IPv6 addresses are supported, for example 192.168.0.100 or fe80::1234. udp-port -- UDP port, which is used to send notifications. The UDP port functions with the IP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 400
type has a higher security than the trap type and resend and timeout need to be configured if you select this option. You can only select the trap type in Security Model v1. By default, the type of the notifications is "trap". retries -- The amount of times the switch retries an inform request, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 401
41.7snmp-server engineID Description The snmp-server engineID command is used to configure the local and remote engineID of the switch. To restore to the default setting, please use no snmp-server engineID command. Syntax snmp-server engineID { [ local local-engineID ] [ remote remote-engineID ] } - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 402
disable the sending of SNMP standard traps, please use no snmp-server traps snmp command. Syntax snmp-server traps snmp [ linkup | linkdown | warmstart | coldstart | auth-failure ] no snmp-server traps snmp [ linkup | linkdown | warmstart | coldstart | auth-failure ] Parameter linkup -- Enable - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 403
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin level users have access to these commands. Example Enable SNMP link status trap for port 3: T2600G-28TS(config)# interface gigabitEthernet 1/0/3 T2600G-28TS(config - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 404
lldp topologychange -- a notification generated by the local device to sense the change in the topology that indicates a new remote device attached to a local port, or a remote device disconnected or moved from one port to another. loopback-detection -- Enable loopback-detection trap. It is sent - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 405
DDM traps. And the no snmp-server traps ddm command without any parameter is used to disable all the types of DDM traps. For more instructions about the alarm threshold or warning threshold, refer to Chapter 34 DDM Commands. Command Mode Global Configuration Mode Example Enable all the SNMP DDM - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 406
Parameter create -- Enable VLAN-created trap. It is sent when new VLAN is created successfully. delete -- Enable VLAN-deleted traps. It is sent when VLAN is deleted successfully. Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access to these commands. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 407
owner-name -- The owner of the history sample entry, ranging from 1 to 16 characters. By default, it is "monitor". number -- The maximum number of buckets desired for the RMON history group of statistics, ranging from 1 to 130. The default is 50 buckets. Command Mode Global Configuration Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 408
sending trap messages to the management station, and both indicates logging the event and sending trap messages to the management station. owner-name -- The owner of the event entry, ranging from 1 to 16 characters. By default, it is "monitor". Command Mode Global Configuration Mode Privilege - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 409
sindex -- Specify the statistics index. alarm-variable -- The alarm variable. By default, the option is revbyte. s-type -- Sample Type, which is the sampling method for the selected variable and comparing the value against the thresholds. There are two options, absolute and delta. Absolute indicates - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 410
to configure the entries of SNMP-RMON statistics. To delete the corresponding entry, please use no rmon statistics command. The maximum supported entries are 1000. Syntax rmon statistics index interface gigabitEthernet port [ owner owner-name] [ status { underCreation | valid }] no rmon statistics - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 411
Description The show snmp-server command is used to display SNMP configuration globally. Syntax show snmp-server Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display SNMP configuration globally: - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 412
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Display the Group table: T2600G-28TS# show snmp-server group 41.20 show snmp-server user Description The show snmp-server user command is used to display - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 413
Example Display the Community table: T2600G-28TS# show snmp-server community 41.22 show snmp-server host Description The show snmp-server host command is used to display the Host table. Syntax show snmp-server host Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 414
41.24 show rmon history Description The show rmon history command is used to display the configuration of the history sample entry. Syntax show rmon history [ index ] Parameter index -- The index number of the entry selected to display the configuration, ranging from 1 to 12, in the format of 1-3, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 415
Privilege Requirement Only Admin level users have access to these commands. Example Display the Event configuration of entry1-4: T2600G-28TS# show rmon event 1-4 41.26 show rmon alarm Description The show rmon alarm command is used to display the configuration of the Alarm Management entry. Syntax - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 416
Parameter index -- The index number of the statistics entry selected to display the configuration, ranging from 1 to 65535. By default, the configuration of all statistics entries is displayed. Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement Only Admin level users - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 417
Chapter 42 LLDP Commands LLDP function enables network devices to advertise their own device information periodically to neighbors on the same LAN. The information of the LLDP devices in the LAN can be stored by its neighbor in a standard MIB, so it is possible for the information to be accessed by - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 418
Parameter multiplier -- Configure the Hold Multiplier parameter. It ranges from 2 to 10. By default, it is 4. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify Hold Multiplier as 5: T2600G-28TS( - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 419
fast-count -- When the port's LLDP state transforms from Disable (or Rx_Only) to Tx&Rx (or Tx_Only), the fast start mechanism will be enabled, that is, the transmit interval will be shorten to a second, and several LLDPDUs will be sent out (the number of LLDPDUs equals this parameter). The value - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 420
42.5lldp transmit Description The lldp transmit command is used to enable the designated port to transmit LLDPDU. To disable the function, please use no lldp transmit command. Syntax lldp transmit no lldp transmit Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 421
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the SNMP notification for Gigabit Ethernet port 1/0/1: T2600G-28TS(config)#interface gigabitEthernet 1/0/1 T2600G-28TS(config-if)#lldp snmp-trap 42.7lldp tlv-select Description The - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 422
42.8lldp med-fast-count Description The lldp med-fast-count command is used to configure the number of the LLDP-MED frames that will be sent out. When LLDP-MED fast start mechanism is activated, multiple LLDP-MED frames will be transmitted based on this parameter. The default value is 4. To return - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 423
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the LLDP-MED feature for port 1/0/2: T2600G-28TS(config)# interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 424
box post-office-box ] [ additional additional ] [ country-code country-code ] [ what { dhcp-server | endpoint | switch } ] ] } Parameter emergency-number -- Emergency Call Service ELIN identifier, which is used during emergency call setup to a traditional CAMA or ISDN trunk-based PSAP. The length of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 425
42.12 show lldp Description The show lldp command is used to display the global configuration of LLDP. Syntax show lldp Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of LLDP: T2600G-28TS#show lldp 42.13 show lldp - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 426
42.14 show lldp local-information interface Description The show lldp local-information interface command is used to display the LLDP information of the corresponding port. By default, the LLDP information of all the ports will be displayed. Syntax show lldp local-information interface [ - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 427
Example Display the neighbor information of Gigabit Ethernet port 1/0/1: T2600G-28TS#show lldp neighbor-information interface gigabitEthernet 1/0/1 42.16 show lldp traffic interface Description The show lldp traffic interface command is used to display the LLDP statistic information between the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 428
Chapter 43 sFlow Commands Note: T2600G-18TS doesn't support this command. sFlow (Sampled Flow) is a technology for accurately monitoring network traffic at high speeds. The sFlow monitoring system consists of an sFlow agent (embedded - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 429
43.2sflow enable Description The sflow enable command is used to enable sFlow function. To disable the sFlow function, please use no sflow enable command. Syntax sflow enable no sflow enable Command Mode Global Configuration Mode Privilege Requirement Only Admin and Operator level users have access - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 430
port --The number of the udp port which is selected for the sFlow collector. maxData --Specify the maximum number of data bytes that can be sent in a single sample datagram. The value ranges from 300 to 1400 and the default value is 300 bytes. timeout --Specify the aging time of the sFlow collector, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 431
the next sample is taken. The value ranges from 1024 to 65535 and the default value is 0 which means no packets will be sampled. maxHeader --Specify the maximum number of bytes that should be copied from a sampled packet. The value ranges from 18 to 256 and the default value is 128 bytes. Command - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 432
43.6show sflow collector Description The show sflow collector command is used to display the global configuration of the sFlow collector. Syntax show sflow collector Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the global configuration of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 433
Chapter 44 Static Routes Commands 44.1interface vlan Description This interface vlan command is used to create the VLAN interface. To delete the specified VLAN interface, please use the no interface vlan command. Syntax interface vlan { vid } no interface vlan { vid } Parameter vid -- The ID of the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 434
Parameter id -- The ID of the loopback interface, ranging from 1 to 64. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create the loopback interface 1: T2600G-28TS(config)# interface loopback 1 44.3 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 435
44.4interface range port-channel Description This interface range port-channel command is used to create multiple port-channel interfaces. Syntax interface range port-channel port-channel-list Parameter port-channel-list -- The list of the port-channel interface, ranging from 1 to 14, in the format - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 436
Command Mode Interface Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Add a description system-if to the routed port 1/0/9 : T2600G-28TS(config)# interface gigabitEthernet 1/0/9 T2600G-28TS(config-if)# no switchport - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 437
44.7interface port-channel Description This interface port-channel command is used to create the port-channel interface. To delete the specified port-channel interface, please use the no interface port-channel command. Syntax interface port-channel { port-channel-id } no interface port-channel { - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 438
next-hop-address -- The address of the next-hop. distance -- The distance metric of this route, ranging from 1 to 255. The smaller the distance is, the higher the priority is. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 439
44.10 ipv6 route Description This ipv6 route command is configure the IPv6 static route. To clear the corresponding entry, please use the no ipv6 route command. Syntax ipv6 route { ipv6-dest-address } { next-hop-address } [ distance ] no ipv6 route { ipv6-dest-address } { next-hop-address } - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 440
Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the information of VLAN 2: T2600G-28TS(config)#show interface vlan 2 44.12 show ip interface Description This show ip interface command is used to display the detailed information of the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 441
44.13 show ip interface brief Description This show ip interface brief command is used to display the summary information of the Layer 3 interfaces. Syntax show ip interface brief Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the summary - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 442
Example Display the static routes: T2600G-28TS(config)# show ip route static 44.15 show ip route specify Description This show ip route specify command is used to display the valid routing information to the specified IP address or network segments. Syntax show ip route specify { ip } [ mask ] [ - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 443
44.16 show ip route summary Description This show ip route summary command is used to display the summary information of the route entries classified by their sources. Syntax show ip route summary Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 444
44.18 show ipv6 route Description This show ipv6 route command is used to display the IPv6 route entries of the specified type. Syntax show ipv6 route [ static | connected ] Parameter static | connected -- Specify the route type. If not specified, all types of route entries will be displayed. static - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 445
Example Display the summary information of IPv6 route entries: T2600G-28TS(config)# show ipv6 route summary 424 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 446
prefer Description The sdm prefer command is used to configure the SDM template. The SDM template is used to allocate system resources to best support the features being used in your application. To return to use the default template, please use the sdm prefer default command. The template change - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 447
45.2show sdm prefer Description The show sdm prefer command is used to display resource allocation of the current SDM template in use, or the SDM templates that can be used. Syntax show sdm prefer { used | default | enterpriseV4 | enterpriseV6 } Parameter used -- Display the resource allocation of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 448
Telnet, SSH and HTTP. Authentication Method List A method list describes the authentication methods and their sequence to authenticate a user. The switch supports Login List for users to gain access to the switch, and Enable List for normal users to gain administrative privileges. RADIUS/TACACS - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 449
Example Enable the AAA function globally: T2600G-28TS(config)# aaa enable 46.2tacacas-server host Description The tacacs-server host command is used to configure a new TACACS+ server. To delete the specified TACACS+ server, please use no tacacs-server host command. Syntax tacacs-server host ip- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 450
User Guidelines The TACACS+ servers you configured are added in the server group "tacacs" by default. Example Configure a TACACS+ server with the IP address as 1.1.1.1, TCP port as 1500, timeout as 6 seconds, and the unencrypted key string as 12345. T2600G-28TS(config)# tacacs-server host 1.1.1.1 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 451
Syntax radius-server host ip-address [ auth-port port-id ] [ acct-port port-id ] [ timeout time ] [ retransmit number ] [ key { [ 0 ] string | 7 encrypted-string } ] no radius-server host ip-address Parameter ip-address -- Specify the IP address of the RADIUS server. auth-port port-id -- Specify the - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 452
Example Configure a RADIUS server with the IP address as 1.1.1.1, authentication port as 1200, timeout as 6 seconds, retransmit times as 3, and the unencrypted key string as 12345. T2600G-28TS(config)# radius-server host 1.1.1.1 auth-port 1200 timeout 6 retransmit 3 key 12345 46.5show radius-server - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 453
Syntax aaa group { radius | tacacs } group-name no aaa group { radius | tacacs } group-name Parameter radius | tacacs -- Specify the server group type as RADIUS or TACACS+. group-name -- Specify the server group name. Command Mode Global Configuration Mode Privilege Requirement Only Admin level - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 454
T2600G-28TS(config)# aaa group radius radius1 T2600G-28TS(aaa-group)# server 1.1.1.1 46.8show aaa group Description This show aaa group command is used to display the summary information of the AAA groups. All the servers in this group will be listed if you specify the group name. Syntax show aaa - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 455
Parameter method-list -- Specify the method list name. method1, method2, method3, method4 -- Specify the authentication methods in order. The next authentication method is tried only if the previous method does not respond, not if it fails. The preset methods include radius, tacacs, local and none. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 456
Parameter method-list -- Specify the method list name. method1, method2, method3, method4 -- Specify the authentication methods in order. The next authentication method is tried only if the previous method does not respond, not if it fails. The preset methods include radius, tacacs, local and none. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 457
aaa accounting dot1x default { method } no aaa accounting dot1x default Parameter method -- Specify the method name. Only RADIUS server group is supported, and the default method is server group "radius". Command Mode Global Configuration Mode Privilege Requirement Only Admin level users have access - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 458
46.13 show aaa authentication Description This show aaa authentication command is used to display the summary information of the authentication login, enable and dot1x metheod list. Syntax show aaa authentication [ login | enable | dot1x ] Parameter login | enable | dot1x -- Specify the method list - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 459
Example Display the information of the default 802.1X accounting method list: T2600G-28TS(config)# show aaa accounting 46.15 line console Description The line console command is used to enter the Line Configuration Mode configure the console port to which you want to apply the authentication list. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 460
Parameter method-list -- Specify the login method list on the console port. It is "default" by default, which contains the method "local". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 461
T2600G-28TS(config)# line console 0 T2600G-28TS(config-line)# enable authentication list2 46.18 line telnet Description The line telnet command is used to enter the Line Configuration Mode to configure the telnet terminal line to which you want to apply the authentication list. Syntax line telnet - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 462
Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the login authentication method list on the telnet terminal line as "list1": T2600G-28TS(config)#line telnet T2600G-28TS(config-line)# login authentication list1 46.20 - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 463
Syntax login authentication { method-list } no login authentication Parameter method-list -- Specify the login method list on the ssh terminal line. It is "default" by default, which contains the method "local". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 464
Privilege Requirement Only Admin level users have access to these commands. Example Configure the enable authentication method list on the telnet terminal line as "list2": T2600G-28TS(config)#line telnet T2600G-28TS(config-line)# enable authentication list2 46.23 enable authentication(ssh) - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 465
46.24 ip http login authentication Description The ip http login authentication command is used to apply the login authentication method list to users accessing through HTTP. To restore to the default authentication method list, please use the no ip http login authentication command. Syntax ip http - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 466
Parameter method-list -- Specify the enable method list on the HTTP access. It is "default" by default, which contains the method "none". Command Mode Line Configuration Mode Privilege Requirement Only Admin level users have access to these commands. Example Configure the enable authentication - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 467
Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable DHCP server service globally: T2600G-28TS(config)# service dhcp server 47.2ip dhcp server extend-option capwap-ac-ip Description The ip dhcp server extend-option capwap-ac-ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 468
Parameter ip-address -- Specify the IP address of the remote server. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Set the remote DHCP server's IP address as 192.168.3.1: T2600G-28TS(config)# ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 469
47.4ip dhcp server exclude-address Description The ip dhcp server exclude-address command is used to specify the reserved IP addresses which are forbidden to allocate, such as the gateway address, the network segment broadcast address, the server address etc. To delete the reserved IP addresses, - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 470
Parameter pool-name -- Specify the address pool name, ranging from 1 to 8 characters. Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Create the address pool of name POOL1: T2600G-28TS(config)# ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 471
47.7ip dhcp server ping packets Description The ip dhcp server ping packets command is used to specify the number of PING packets sent. If this value is set to 0, the PING process will be disabled. To resume the default value, please use no ip dhcp server ping packets command. Syntax ip dhcp server - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 472
Command Mode DHCP Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the address pool "product" as 192.168.1.0 255.255.255.0: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# network 192. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 473
47.10 address hardware-address Description The address hardware-address command is used to reserve the static address bound with hardware address in the address pool. To delete the binding, please use no address hardware-address. Syntax address ip-address hardware-address hardware-address hardware- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 474
Syntax address ip-address client-identifier client-id [ascii] no address ip-address Parameter ip-address -- Specify the static binding IP address. client-id -- Specify the client ID, in the format of hex value. ascii -- The client ID is entered with ascii characters. Command Mode DHCP Configuration - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 475
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the address pool product's default gateways as 192.168.0.1 and 192.168.1.1: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(dhcp-config)# default-gateway 192.168.0.1,192. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 476
47.14 netbios-name-server Description The netbios-name-server command is used to specify the Netbios server's IP address. To delete the Netbios servers, please use no netbios-name-server command. Syntax netbios-name-server NBNS-list no netbios-name-server Parameter NBNS-list -- Specify the Netbios - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 477
Command Mode DHCP Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Specify the address pool's Netbios server type as b-node: T2600G-28TS(config)# ip dhcp server pool product T2600G-28TS(config-dhcp)# netbios-node-type b- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 478
47.17 domain-name Description The domain-name command is used to specify the domain name for the DHCP client. To delete the domain name, please use no domain-name command. Syntax domain-name domainname no domain-name Parameter domainname -- Specify the domain name for the DHCP client. Command Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 479
boot1 47.19 show ip dhcp server status Description The show ip dhcp server status command is used to display the status of the DHCP service. Syntax show ip dhcp server status Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the status of DHCP - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 480
Privilege Requirement None. Example Display the statistics of DHCP packets received and sent by the DHCP server: T2600G-28TS(config)# show ip dhcp server statistics 47.21 show ip dhcp server extend-option Description The show ip dhcp server extend-option command is used to display the configuration - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 481
Example Display the configured reserved addresses: T2600G-28TS(config)# show ip dhcp server excluded-address 47.24 show ip dhcp server manual-binding Description The show ip dhcp server manual-binding command is used to display the configuration of static binding address. Syntax show ip dhcp server - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 482
T2600G-28TS(config)# show ip dhcp server manual-binding 47.25 show ip dhcp server binding Description The show ip dhcp server binding command is used to display the binding entries. Syntax show - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 483
Example Clear the packet statistics: T2600G-28TS(config)# clear ip dhcp server statistics 47.27 clear ip dhcp server binding Description The clear ip dhcp server binding command is used to clear the binding information. Syntax clear ip dhcp server binding [ ip-address ] Parameter ip-address -- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 484
Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable DHCP Relay function globally: T2600G-28TS(config)# service dhcp relay 48.2ip helper-address Description The ip helper-address command is used to add DHCP Server address to the Layer 3 interface - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 485
(config-if)# ip helper-address 192.168.2.1 48.3ip dhcp relay information Description The ip dhcp relay information command is used to enable option 82 support in DHCP Relay. To disable this function, please use no ip dhcp relay information command. Syntax ip dhcp relay information no ip dhcp relay - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 486
48.4ip dhcp relay information policy Description The ip dhcp relay information policy command is used to specify the operation for the Option 82 field of the DHCP request packets from the Host. To restore to the default option, please use no ip dhcp relay information policy command. Syntax ip dhcp - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 487
no ip dhcp relay information custom Command Mode Global Configuration Mode Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Enable the switch to customize the option 82 field: T2600G-28TS(config)# ip dhcp relay information custom 48.6ip - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 488
48.7ip dhcp relay information remote-id Description The ip dhcp relay information remote-id command is used to specify the custom remote ID when option 82 customization is enabled. To clear the remote ID, please use no ip dhcp relay information remote-id command. Syntax ip dhcp relay information - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 489
Privilege Requirement Only Admin, Operator and Power User level users have access to these commands. Example Configure interface VLAN 1 as the default relay agent interface: T2600G-28TS(config)# interface vlan 1 T2600G-28TS(config-if)# ip dhcp relay default-interface 48.9ip dhcp relay vlan - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 490
48.10 show ip dhcp relay Description The show ip dhcp relay command is used to display the global status and Option 82 configuration of DHCP Relay. Syntax show ip dhcp relay Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 491
Chapter 49 PoE Commands Note: Only T2600G-28MPS supports PoE function. PoE (Power over Ethernet) technology describes a system to transmit electrical power along with data to remote devices over standard twisted-pair cable in - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 492
power inline disconnect-method {deny-next-port|deny-low-priority} Parameter deny-next-port -- When the supply power exceeds the power limit, the PD linked to the next port will be disconnected. deny-low priority -- When the supply power exceeds the power limit, the PD linked to the port with lower - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 493
power the port in the profile can supply, with five options: "power-limit", "auto", "class1", "class2", "class3" and "class4". "Power-limit" indicates you can manually enter a value ranging from 1 to 300. The value is in the unit of 0.1 watt. For instance, if you want to configure the max power as - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 494
Global Configuration Mode Privilege Requirement None. Example Create a PoE time-range named "tRange1" for the switch: T2600G-28MPS(config)# power time-range tRange1 49.5power holiday Description The power holiday command is used to create PoE holiday for the switch. To delete the corresponding PoE - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 495
49.6 absolute Description The absolute command is used to create an absolute mode time-range for the PoE time-range of the switch. The switch will supply power when the specified absolute time occurs. To delete the corresponding absolute mode time-range configuration, please use no absolute command. - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 496
periodic { [ week-date week-day ] [ time-slice1 time-slice ] [ time-slice2 time-slice ] [ time-slice3 time-slice ] [ time-slice4 time-slice ] } no periodic [ week-date | time-slice ] Parameter week-day -- Periodic Mode, with "1-7", "daily", "off-day" and "working-day" options. "1-7" should be - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 497
power the port in the profile can supply, with five options: "power-limit", "auto", "class1", "class2", "class3" and "class4". "Power-limit" indicates you can manually enter a value ranging from 1 to 300. The value is in the unit of 0.1 watt. For instance, if you want to configure the max power as - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 498
T2600G-28MPS(config-if)# power inline consumption 50 49.10 power inline priority Description The power inline priority command is used to configure the PoE priority for the corresponding port Syntax power inline priority { low | middle | high } Parameter priority -- The PoE priority of the port. The - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 499
Command Mode Interface Configuration Mode (interface gigabitEthernet / interface range gigabitEthernet) Privilege Requirement None. Example Enable the PoE feature for port 2: T2600G-28MPS(config)# interface gigabitEthernet 1/0/2 T2600G-28MPS(config-if)# power inline supply enable 49.12 power inline - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 500
49.13 power inline time-range Description The power inline time-range command is used to bind a PoE time-range to the corresponding port. To cancel the bind relation, please use no power inline time-range command. Syntax power inline time-range name no power inline time-range Parameter name -- The - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 501
T2600G-28MPS# show power inline 49.15 show power inline configuration interface Description The show power inline configuration interface command is used to display the PoE configuration of the certain port. Syntax show power inline configuration interface [ gigabitEthernet port ] Parameter port -- - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 502
Display the PoE information of all ports: T2600G-28MPS# show power inline information interface 49.17 show power profile Description The show power profile command is used to display the defined PoE profile. Syntax show power profile Command Mode Privileged EXEC Mode and Any Configuration Mode - TP-Link T2600G-18TSTL-SG3216 | T2600G-28MPSUN V2 CLI Reference Guide Guide - Page 503
49.19 show power time-range Description The show power time-range command is used to display the configuration of PoE time-range. Syntax show power time-range Command Mode Privileged EXEC Mode and Any Configuration Mode Privilege Requirement None. Example Display the configuration of PoE time-range:
CLI Reference Guide
JetStream Gigabit L2 Managed Switch
T2600G-18TS(TL-SG3216)
T2600G-28TS (TL-SG3424)
T2600G-52TS (TL-SG3452)
T2600G-28MPS (TL-SG3424P)
REV2.1.0
1910012012