100-fxEnables 100Base-FX on chassis-based and stackable devices.
100-txConfigures a 1000Base-TX small form-factor pluggable (SFP) transceiver to operate
at a speed of 100 Mbps.
aaa accounting commandsConfigures the AAA accounting configuration parameters for EXEC commands.
aaa accounting dot1xEnables 802.1X accounting.
aaa accounting execConfigures the AAA accounting configuration parameters for SSH and Telnet access.
aaa accounting mac-authEnables or disables RADIUS accounting for MAC authentication sessions.
aaa accounting systemConfigures AAA accounting to record when system events occur on the device.
aaa authentication dot1xEnables 802.1X and MAC authentication.
aaa authentication enableConfigures the AAA authentication method for securing access to the Privileged EXEC
level and global configuration levels of the CLI.
aaa authentication loginConfigures the AAA authentication method for securing access to Telnet or SSH access
to the CLI.
aaa authentication snmp-serverConfigures the AAA authentication method for SNMP server access.
aaa authentication web-serverConfigures the AAA authentication method to access the device through the Web Management
Interface.
aaa authorization coa enableEnables RADIUS Change of Authorization (CoA).
aaa authorization coa ignore Discards the specified RADIUS Change of Authorization (CoA) messages.
aaa authorization commandsConfigures the AAA authorization configuration parameters for EXEC commands.
aaa authorization execDetermines the user privilege level when users are authenticated.
-
accept-lifetime Configures the time period during which the key on a keychain becomes active and is
received as valid.
accept-mode Enables a backup Virtual Router Redundancy Protocol (VRRP) device to respond to ping,
traceroute, and Telnet packets if the backup device becomes the master VRRP device.
accept-register Configures the register message filter
rule for Protocol Independent Multicast (PIM) and IPv6 Protocol Independent Multicast
(PIMv6).
access-control vlanEnables the VLAN containment for Network Time Protocol (NTP).
access-list accounting
timerSets frequency of ACL accounting statistics collection.
accountingEnables RADIUS accounting for Web Authentication.
acl-mirror-portConfigures ACL-based inbound mirroring.
activate (VRRP)Activates the configured Virtual Router Redundancy Protocol (VRRP) virtual routing
instance.
activate (VSRP)Activates the Virtual Switch Redundancy Protocol (VSRP) Virtual Router ID (VRID) for
a port-based VLAN.
add macPermanently authenticates certain hosts.
add-vlanAdds individual VLANs or a range of VLANs.
address-familyEnables IPv4 or IPv6 address-family configuration mode.
-
address-family unicast (BGP)Enables the IPv4 or IPv6 address family configuration mode to configure a variety
of Border Gateway Protocol Version 4 (BGP4) unicast routing options.
advertise backupAdvertises a Virtual Router Redundancy Protocol (VRRP) backup router to a VRRP master
router.
advertise backup (VSRP)Enables a backup to send Hello messages to the master.
ageConfigures the device to age out secure MAC addresses after a specified amount of
time.
aggregate-address
(BGP)Configures the device to aggregate routes from a range of networks into a single network
prefix.
aggregated-vlanEnables support for larger Ethernet frames.
aliasAn alias serves as a shorthand version of a longer CLI command.
all-clientRestricts all remote management access methods expect for a specified host.
-
always-compare-med
Configures the device always to compare the Multi-Exit Discriminators (MEDs), regardless
of the autonomous system (AS) information in the paths.
-
always-propagate
Enables the device to reflect BGP routes even though they are not installed in the
Routing Table Manager (RTM).
anycast-rpConfigures PIM anycast rendezvous points (RPs) in IPv4 and IPv6 multicast domains.
area (OSPFv2)Configures an Open Shortest Path First
Version 2 (OSPFv2) area.
area (OSPFv3)Configures an Open Shortest Path First
Version 3 (OSPFv3) area.
-
area authentication (IPsec)
Enables IPSec authentication for an OSPF Version 3 (OSPFv3) area.
area authentication (OSPFv3)Configures HMAC-SHA-1 or HMAC-SHA-256 authentication for an Open Shortest Path First
version 3 (OSPFv3) area.
-
area authentication keychain (OSPFv3) Configures keychain authentication for an Open Shortest Path First version 3 (OSPFv3)
area.
-
area nssa
(OSPFv2)Creates a not-so-stubby area (NSSA) or modifies its parameters.
-
area nssa
(OSPFv3)Creates a not-so-stubby area (NSSA) or modifies its parameters.
-
area range
(OSPFv2)Specifies area range parameters on an area border router (ABR).
-
area range
(OSPFv3)Specifies area range parameters on an area border router (ABR).
-
area stub
(OSPFv2)Creates or deletes a stub area or modifies its parameters.
-
area stub (OSPFv3)Creates or deletes a stub area or modifies its parameters.
-
area virtual-link
(OSPFv2)Creates or modifies virtual links for an Open Shortest Path First version 2 (OSPFv2)
area.
-
area virtual-link
(OSPFv3)Creates or modifies virtual links for an area.
-
area virtual-link authentication (OSPFv2) Configures MD5, HMAC-SHA-1 or HMAC-SHA-256 authentication for an Open Shortest Path
First version 2 (OSPFv2) area virtual link.
-
area virtual-link authentication (OSPFv3)Enables HMAC-SHA-1 or HMAC-SHA-256 authentication for virtual links in an OSPFv3 area.
-
area virtual-link authentication ipsec (OSPFv3) Enables IPsec (IP Security) authentication for virtual links in an OSPFv3 area.
-
area virtual-link authentication key-activation-wait-time (OSPFv2) Configures the time before an authentication key change is activated for an Open
Shortest Path First version 2 (OSPFv2) area virtual link.
-
area virtual-link authentication key-activation-wait-time (OSPFv3) Configures the time before an authentication key change is activated for an Open
Shortest Path First version 3 (OSPFv3) area virtual link.
-
area virtual-link authentication keychain
(OSPFv2) Configures keychain authentication for Open Shortest Path First version 2 (OSPFv2)
area virtual link.
-
area virtual-link authentication keychain
(OSPFv3) Configures keychain authentication for Open Shortest Path First version 3 (OSPFv3)
area virtual link.
-
area virtual-link authentication plain-text
(OSPFv2) Configures simple password-based authentication for an Open Shortest Path First version
2 (OSPFv2) area.
-
area virtual-link authentication rfc6506
(OSPFv3) Configures keychain authentication in accordance with RFC 6506 for an Open Shortest
Path First version 3 (OSPFv3) area virtual link.
arpCreates static ARP entry.
arp inspection trustEnables dynamic ARP inspection (DAI) trust on a port.
arp-internal-priority Configures the priority of ingress ARP packets.
-
as-path-ignore
Disables the comparison of the autonomous system (AS) path lengths of otherwise equal
paths.
atalk-protoConfigures the AppleTalk protocol-based VLAN.
attempt-max-numConfigures the number of times a user can enter an invalid username and password;
that is, the number of Web Authentication attempts during the specified cycle time.
auth allow-tagged enableAllows tagged packets to be processed when the port is not tagged in the incoming
tagged VLAN.
auth auth-modeConfigures Flexible authentication mode at the interface level.
auth-default-vlanSpecifies the auth-default VLAN globally.
auth-fail-action (Flexible Authentication)Configures, at a global level, the action taken after 802.1X and MAC authentication
failure.
auth-modeSpecifies the authentication mode, for
example, single-host, multiple-hosts, or multiple-untagged.
auth-mode captive-portal Authenticates the users in a VLAN through external Web Authentication (Captive Portal
user authentication mode).
auth-mode noneEnables automatic Web Authentication.
auth-mode passcodeEnables Web Authentication to use dynamically created passcodes to authenticate users
in the VLAN.
auth-mode username-passwordEnables the username and password Web Authentication mode.
auth-orderSpecifies the sequence of authentication methods, 802.1X authentication and MAC authentication
at the global level.
auth-timeout-actionConfigures, at a global level, the action taken when external server authentication
times out.
auth-vlan-modeEnables the Flexible authentication-enabled ports to be member of multiple untagged
VLANs.
authenticateEnables Network Time Protocol (NTP) strict authentication.
authenticated-mac-age-timeConfigures the time duration after which the user-associated MAC address is aged out
and reauthentication is enforced.
authenticationEnters the authentication mode.
authentication (IKEv2)Configures an authentication proposal for an Internet Key Exchange version 2 (IKEv2)
profile.
authentication auth-default-vlanSpecifies the authentication default VLAN at the interface level.
authentication auth-orderSpecifies the sequence of authentication methods, 802.1X authentication and MAC authentication,
on a specific interface.
authentication auth-vlan-modeEnables multiple-untagged mode on a specific Flexible authentication-enabled port
and allows it to be member of multiple untagged VLANs.
authentication disable-agingDisables aging of MAC sessions at the interface level.
authentication dos-protectionEnables denial of service (DoS) authentication protection on the interface.
authentication fail-actionSpecifies the authentication failure action to move the client port to the restricted
VLAN after authentication failure for both MAC authentication and 802.1X authentication
on an interface.
authentication filterApplies an 802.1X authentication
override filter to permit or deny traffic from a specified MAC address or set of
MAC
addresses.
authentication filter-strict-security Enables or disables strict filter security for 802.1X and MAC-authentication enabled
interfaces.
- authentication mac-authentication lldp-override
Configures the switch to replace the
authenticated MAC address on a FlexAuth-enabled port with the MAC address received
in an
LLDP frame.
authentication max-sessionsSpecifies the maximum number of MAC sessions that can be authenticated per device
or per port for MAC authentication and 802.1X authentication.
authentication reauth-timeoutSets the time to wait before
reauthenticating a client that has timed out and a timeout action has been applied.
This
command is applicable for MAC authentication and 802.1X authentication.
authentication source-guard-protection enableEnables Source Guard Protection along with authentication on a specified interface.
authentication timeout-actionConfigures the authentication timeout actions to specify the action for the RADIUS
server if an authentication timeout occurs.
authentication voice-vlanCreates a voice VLAN ID for a port or for a group of ports.
-
authentication-algorithm Specifies the cryptographic algorithm to be used for the key in the keychain.
- authentication-algorithm (MKA)
Specifies the cryptographic algorithm to
be used for the specified key in the MKA (MACsec) keychain.
authentication-keyDefines an authentication key for Network Time Protocol (NTP).
-
auto-cost reference-bandwidth
(OSPFv2)Configures reference bandwidth.
-
auto-cost reference-bandwidth
(OSPFv3)Configures reference bandwidth.
auto-enroll (PKI)Sends enrollment message to the CA and local auto-enroll certificates.
auto-lacpConfigures the auto-LACP (Link Aggregation Control Protocol) deployment for a specific
port or a range of ports.
autosaveAutomatically saves learned secure MAC addresses to the startup configuration at specified
intervals.
backupDesignates a virtual router as a Virtual Router Redundancy Protocol (VRRP) or VRRP
Extended (VRRP-E) backup device and configures priority and track values.
backup (VSRP)Configures the device as a Virtual Switch Redundancy Protocol (VSRP) backup for the
Virtual Routing ID (VRID) or changes the backup priority and the track priority.
-
backup-hello-intervalConfigures the interval at which backup Virtual Router Redundancy Protocol (VRRP)
routers advertise their existence to the master router.
backup-hello-interval (VSRP)Configures the time interval during which Hello messages are sent by the backup.
bandwidth (Interface) Sets and communicates bandwidth value for an interface to higher-level protocols
such as OSPFv2 and OSPFv3, so this setting can be used to influence the routing cost
for routes learned on these interfaces.
bannerDefines a login banner.
batch bufferCreates a group of CLI commands per batch ID that is used in the automatic execution
of commands in batches.
bfdEnables Bidirectional Forwarding Detection (BFD).
bfd holdover-intervalConfigures the time interval for which Border Gateway Protocol (BGP) or Open Shortest
Path First (OSPF) routes are withdrawn after a Bidirectional Forwarding Detection
(BFD) session is declared down.
bfd min-txConfigures Bidirectional Forwarding Detection (BFD) session parameters for Border
Gateway Protocol (BGP).
bfd per-linkEnables micro-Bidirectional Forwarding Detection (micro-BFD) on each member link of
a Link Aggregation Group (LAG) interface.
-
bgp-redistribute-internal
Causes the device to allow the redistribution of IBGP routes from BGP into OSPF for
non-default VRF instances.
blockConfigures the time users must wait before the next cycle of Web Authentication begins
after they have exceeded the limit for Web Authentication attempts.
block unknown-unicastBlocks the unknown unicast traffic on
ports, including Link Aggregation Group (LAG) ports.
boot system flashConfigures the device to boot from the image stored in the flash memory.
bootfileSpecifies the boot image to be used by the client.
bootfile-urlSpecifies the URL of the bootfile that the
DHCPv6 client downloads during the boot process.
bootp-relay-max-hopsModifies the maximum number of BootP or DHCP hops.
bpdu-flood-enableConfigures the MCT cluster devices to flood the SSTP or MSTP BPDUs in the SSTP or
MSTP domain.
breakout ethernetConfigures sub-ports from 40-Gbps or
100-Gbps ports.
broadcast clientConfigures a device to receive Network Time Protocol (NTP) broadcast messages on a
specified interface.
broadcast destinationConfigures Network Time Protocol (NTP) broadcast destination options.
- broadcast limit
Configures the maximum number of broadcast
packets allowed per second and generates infralogs for pps packets.
- bsicloud enable
Enables BSI cloud mode on the ICX
device.
bsr-candidateConfigures a bootstrap router (BSR) as a candidate to distribute rendezvous point
(RP) information to the other PIM Sparse devices within a PIM Sparse domain.
bsr-msg-intervalSets the PIM BSR message interval timer.
buffer-profile port-regionConfigures a buffer profile on a device.
buffer-sharing-fullRemoves the buffer allocation limits on all ports and all traffic classes globally.