-
dampening
Sets dampening parameters for the route in BGP address-family mode.
-
database-overflow-interval
(OSPFv2)Configures frequency for monitoring database overflow.
-
database-overflow-interval
(OSPFv3)Configures frequency for monitoring database overflow.
-
dead-interval Configures the interval for which a Virtual Router Redundancy Protocol (VRRP) backup
router waits for a hello message from the VRRP master router before determining that
the master is offline. When backup routers determine that the master is offline, the
backup router with the highest priority becomes the new VRRP master router.
dead-interval (VSRP)Configures the number of seconds a backup waits for a Hello message from the master
before determining that the master is dead.
decnet-protoConfigures the DECnet protocol VLAN.
default-aclConfigures the default ACL for failed, timed-out, or guest user sessions.
default-gatewayConfigures the default gateway for a VLAN.
-
default-information-originate
(BGP)Configures the device to originate and advertise a default BGP4 or BGP4+ route.
-
default-information-originate
(OSPFv2)Controls distribution of default information to an OSPFv2 device.
-
default-information-originate
(OSPFv3)Controls distribution of default information to an OSPFv3 device.
- default-ip-address enable
Configures default IP addresses on the
management and default VE interfaces through the CLI.
default-ipv6-gateway
Configures the IPv6 address of the default gateway on a VLAN.
-
default-local-preference
Enables setting of a local preference value to indicate a degree of preference for
a route relative to that of other routes.
-
default-metric
(BGP)Changes the default metric used for redistribution.
-
default-metric (OSPF)Sets the default metric value for the OSPFv2 or OSPFv3 routing protocol.
default-metric (RIP)Changes the RIP metric the router assigns by default to redistributed routes.
-
default-passive-interface
Marks all OSPFv2 and OSPFv3 interfaces passive by default.
default-vlan-idChanges the default VLAN ID.
delay-notificationsConfigures the delay time for notifying the Layer 3 protocols of the VE down event.
delay-serverDelays the Network Time Protocol (NTP)
server response so that the synchronization time is not sent to NTP clients until
the device
has synchronized with an external NTP server.
delete-allDeletes all user records from a local user database.
deny (Extended IPv4 ACLs and
IPv6 ACLs)Inserts filtering rules to deny packets
in IPv4 extended named or numbered access-lists (ACLs) or IPv6 ACLs.
deny (Standard IPv4
ACLs)Inserts filtering rules in IPv4 standard named or numbered ACLs that will deny packets.
deployDeploys the LAG.
description
(IKEv2)Describes an Internet Key Exchange version 2 (IKEv2) profile.
-
description
(IPsec)Describes an IP security (IPsec) profile.
destination-ipSets the destination IP address of an
Encapsulated Remote Switched Port Analyzer (ERSPAN) mirror.
dhcp-default-routerSpecifies the IP addresses of the default routers for a client.
dhcp-gateway-listConfigures a gateway list when DHCP Assist is enabled on a Layer 2 switch.
dhcp snooping client-learning disableDisables DHCP client learning on an individual port or range of ports.
dhcp snooping relay informationEnables DHCP snooping relay information (DHCP Option 82) on an interface.
dhcp snooping relay information circuit-idConfigures a unique circuit ID per port.
dhcp snooping relay information remote-idConfigures a unique remote ID per port.
dhcp snooping relay information subscriber-idConfigures a unique subscriber ID per port or on a range of ports.
dhcp snooping trustEnables trust on a port connected to a DHCP server.
dhcp6 snooping trustEnables trust on a port connected to a DHCPv6 server.
dhgroupConfigures a Diffie-Hellman (DH) group for an Internet Key Exchange version 2 (IKEv2)
proposal.
diagnostics (MRP)Enables diagnostics on a metro ring.
disable (LAG)Disables the individual ports within a LAG.
disable (NTP)Disables NTP client and server mode.
disable (Port)Disables a port.
disable (VSRP)Disables the VSRP VRID for a port-based VLAN.
disable authentication md5 Disables the MD5 authentication scheme for Network Time Protocol (NTP).
disable-agingDisables aging of MAC sessions at the global level.
-
distance
(BGP)Changes the default administrative distances for eBGP, iBGP, and local BGP.
-
distance
(OSPF)Configures an administrative distance value for OSPFv2 and OSPFv3 routes.
distance (RIP)Increases the administrative distance that the RIP router adds to routes.
-
distribute-list prefix-list
(OSPFv3)Applies a prefix list to OSPF for IPv6 routing updates. Only routes permitted by the
prefix-list can go into the routing table.
distribute-list prefix-list (RIPng)Applies a prefix list to RIPng to control routing updates that are received or sent.
-
distribute-list route-map
Creates a route-map distribution list.
dlb-internal-trunk-hashChanges the hashing method for inter-packet-processor (inter-pp) HiGig links that
are used to connect master and slave units in ICX 7450-48 devices.
dlogger moduleEnables module filter logging.
dlogger redirectChanges the distributed logger module log
destination.
dns-filterDefines Domain Name System (DNS) filters that will restrict DNS queries from unauthenticated
hosts to be forwarded explicitly to defined servers.
dns-server
(DHCPv6)Specifies the IPv6 address of a Domain Name System (DNS) server.
domain-nameConfigures the domain name for the DHCP client.
dot1x enableEnables 802.1X authentication globally.
dot1x guest-vlanSpecifies the VLAN into which the port should be placed when the client's response
to the dot1x requests for authentication times out.
dot1x initializeInitializes 802.1X authentication on a port.
dot1x macauth-overrideSets an override option so that MAC authentication is attempted when 802.1X authentication
fails for the client.
dot1x max-reauth-req
Configure the maximum number of times (attempts) EAP-request/identity frames are
sent for reauthentication after the first authentication attempt.
dot1x max-req
Configures the retransmission parameter that defines the maximum number of times
EAP request/challenge frames are retransmitted when EAP response/identity frame is
not received from the client.
dot1x-mka-enableEnables MACsec Key Agreement (MKA) capabilities on a licensed device and enters dot1x-mka
configuration mode.
dot1x port-controlControls port-state authorization and configures the port control type to activate
authentication on an 802.1X-enabled interface.
dot1x timeout
Configures the timeout parameters that determine the time interval for client reauthentication
and EAP retransmissions.
dynamicConfigures dynamic ports.
dynamic-bootpEnables the Dynamic Host Configuration
Protocol (DHCP) server to assign an IP address or a range of IP addresses to the
Bootstrap
Protocol (BOOTP) clients within its address pool.
eckeypair (PKI)Specifies which EC keypair to use during enrollment.
eeeEnables Energy Efficient Ethernet (EEE) globally, per port or on a range of ports.
-
egress-buffer-profile Attaches a user-configured egress buffer profile to one or more ports.
enable (LAG)Enables an individual port within a LAG.
enable (MAC Port Security)Enables MAC port security.
enable (MRP)Enables the metro ring.
enable (Port)Enables a port.
enable (VSRP)Enables the VSRP VRID for a port-based VLAN.
enable (Web Authentication)Enables Web Authentication.
enable aaa consoleEnables AAA support for commands entered at the console.
enable accounting (ACL)Enables accounting for MAC ACLs at Layer 2, IPv4 ACLs, or IPv6 ACLs.
enable egress-acl-on-cpu-trafficEnables applying outbound access control
lists (ACLs) to traffic generated by the central processing unit (CPU).
enable nd hop-limitFor an IPv6 ACL, enables dropping neighbor discovery (ND) packets for which the hop
limit is less than 255.
enable password-displayEnables the display of the community string.
enable password-min-lengthConfigures the minimum length on the Line (Telnet), Enable, or Local passwords.
enable port-config-passwordAllows read-and-write access for specific ports but not for global (systemwide) parameters.
- enable privilege-mode password
Enables a password for the Privileged
mode
enable read-only-passwordAllows access to the Privileged EXEC mode and User EXEC mode of the CLI, but only
with read access.
enable snmpEnables display of virtual interface statistics via SNMP.
enable strict-password-enforcementEnables the password security feature.
enable super-user-passwordAllows complete read-and-write access to the system.
enable telnetConfigures Telnet access control parameters.
enable-tcp-mssEnables the Transmission Control Protocol (TCP) maximum segment size (MSS) feature.
enable userConfigures login and password parameters specific to a user.
enable accounting (ACL)Enables accounting for MAC ACLs at Layer 2, IPv4 ACLs, or IPv6 ACLs.
enable-mkaEnables MACsec Key Agreement (MKA) to
support MACSec licensing functionality on a specified interface, and changes the
mode to
dot1x-mka-interface mode to allow related parameters to be configured.
encapsulation-modeSpecifies the encapsulation mode for an IPsec proposal.
encryptionConfigures an encryption algorithm for an Internet Key Exchange version 2 (IKEv2)
proposal.
encryption-algorithmConfigures an encryption algorithm to protect data traffic for an IPsec proposal.
-
enforce-first-as
Enforces the use of the first autonomous system (AS) path for external BGP (eBGP)
routes.
enrollment (PKI)Sets the enrollment retry count, retry period, or profile.
erase flashErases an image stored in the system flash.
erase pre-8090-startup-backupFor all stack units, removes the backup startup-config file for releases prior to
08.0.90 (created on upgrade to 08.0.90).
erase startup-configErases the startup configuration.
erase system factory-default Erases the system settings and restores
factory default settings.
errdisable packet-inerror-detect Enables the device to monitor configured ports for inError packets and defines the
sampling time interval in which the number of inError packets is counted.
errdisable recovery Enables a port to recover automatically from the error-disabled state.
esn-enable (IPsec)Used with replay-protection in IPsec to enable 64-bit sequence numbering for encrypted
packets for tracking and verification by the receiving IPsec endpoint.
ethernet (EFM-OAM)Enables or disables EFM-OAM on an interface or multiple interfaces.
ethernet loopback Enables the Ethernet loopback functionality on a port in the VLAN-unaware mode.
ethernet loopback (VLAN-aware) Configures the Ethernet loopback functionality on one or a set of ports in a specific
VLAN (VLAN-aware mode).
ethernet loopback test-mac Configures the port as flow-aware by specifying the source and destination MAC addresses
of the flow on the interface.
exclude ethernetExcludes a port from the protocol VLAN membership.
excluded-addressSpecifies the addresses that should be excluded from the address pool.
- exclude-ports
Excludes a port from the dynamic port
profile configuration.
execute batchIssues the commands that are saved in the batch buffer immediately or at a scheduled
time, count, and interval.
extend vlan add (VXLAN) Configures a VLAN to be extended over the VXLAN tunnel to the designated remote site.
extend vlan-range
(VXLAN)Extends a range of mapped VLANs over a
VXLAN overlay gateway.
-
external-lsdb-limit
(OSPFv2)Configures the maximum size of the external link state database (LSDB).
-
external-lsdb-limit
(OSPFv3)Configures the maximum size of the external link state database (LSDB).
-
failoverEnables or disables LAG (Link Aggregation Group) hardware failover on the next port
in the LAG or on all ports in the LAG.
- failure-detection (VXLAN)
Sends keep-alive messages to check whether
the connection to a remote site is up.
-
fast-external-fallover
Resets the session if a link to an eBGP peer goes down.
fast port-spanEnables Fast Port Span, configuring the ports attached to the end stations to enter
into the forwarding state in four seconds.
fast uplink-spanEnables Fast Uplink Span, configuring a device deployed as a wiring closet switch
to decrease the convergence time for the uplink ports to another device to just one
second.
fdp advertiseConfigures the IP management address to advertise for Foundry Discovery Protocol (FDP)
neighbors.
fdp enableEnables Foundry Discovery Protocol (FDP) on an interface.
fdp holdtimeConfigures the Foundry Discovery Protocol (FDP) update hold time.
fdp runEnables a device to send Foundry Discovery Protocol (FDP) packets globally.
fdp timerConfigures the Foundry Discovery Protocol (FDP) update timer.
fecEnables Forward Error Correction (FEC) on
an Ethernet port to improve link reliability.
filter-strict-security enable Enables or disables strict filter security for MAC authentication and 802.1X authentication.
fingerprint (PKI)Sets the authentication fingerprint for the Certificate Authority (CA).
flashUse the
flash command to perform basic flash file maintenance.
flash-timeoutConfigures the flash timeout duration.
flexlink backupConfigures a pair of interfaces (physical
or LAG) as Flexlink interfaces which act as an active link and backup link to provide
link
redundancy.
flexlink preemption
delayConfigures the time delay before a
Flexlink interface preempts the other link according to the configured preemption
scheme.
flexlink preemption
modeConfigures the preemption scheme to
specify the preferred Flexlink interface for forwarding traffic.
flow-controlEnables or disables flow control and flow control negotiation, and advertises flow
control.
force-up ethernet Forces the member port of a dynamic LAG (Link Aggregation Group) to be logically
operational even if the dynamic LAG is not operating.
format disk0Formats the external USB.
forwarding-profileConfigures a forwarding profile.
gig-defaultConfigures the Gbps fiber negotiation mode on individual ports, overriding the global
configuration mode.
graceful-restart (BGP)Enables the BGP graceful restart capability.
graceful-restart (OSPFv2)Enables the OSPF Graceful Restart (GR) capability.
-
graceful-restart helper
(OSPFv3)Enables the OSPFv3 graceful restart (GR) helper capability.
graft-retransmit-timerConfigures the time between the transmission of graft messages sent by a device to
cancel a prune state.
group-router-interfaceCreates router interfaces for each VLAN in the VLAN group.
hardware-drop-disableDisables passive multicast route insertion (PMRI).
-
hello-interval (VRRP)Configures the interval at which master Virtual Router Redundancy Protocol (VRRP)
routers advertise their existence to the backup VRRP routers.
-
hello-interval (VSRP)Configures the number of seconds between hello messages from the master to the backups
for a given VRID.
hello-timerConfigures the interval at which hello messages are sent out of Protocol Independent
Multicast (PIM) interfaces.
hitless-failover enable Enables hitless stacking failover and switchover. The standby controller is allowed
to take over the active role without reloading the stack when failover occurs.
hold-down-intervalConfigures the hold-down interval.
hostname Configures a system name for a device and saves the information locally in the configuration
file for future reference.
host-max-numLimits the number of hosts that are authenticated at any one time.