site (VXLAN) Creates one remote site for the VXLAN
overlay gateway.
slow-startConfigures a slow-start timer interval to extend the time interval beyond the dead-interval
time before a Virtual Router Redundancy Protocol Extended (VRRP-E) master device assumes
the role of master device after being offline. When the original master device went
offline, a backup VRRP-E device with a lower priority became the master device.
slow-path-forwardingConfigures the slow path forwarding of IPv4 and IPv6 multicast data packets.
snmp-clientRestricts SNMP access to a host with the specified IPv4 or IPV6 address.
- snmp-server
Enable SNMP access.
snmp-server communityConfigures the SNMP community string and access privileges.
snmp-server contact Configures the identification of the contact person for the managed node.
snmp-server disableDisables SNMP MIB support.
snmp-server enableConfigures SNMP access only to specific clients.
snmp-server enable mibEnables MIB support for SNMP server.
snmp-server enable trapsEnables SNMP traps for various events.
snmp-server enable traps holddown-timeConfigures the wait time before starting to send SNMP traps.
snmp-server enable traps mac-notification Enables the MAC-notification trap whenever a MAC address event is generated on a
device or an interface.
snmp-server engineid localModifies the default SNMPv3 engine ID.
snmp-server groupCreates user-defined groups for SNMPv1/v2c/v3 and configures read, write, and notify
permissions to access the MIB view.
snmp-server hostConfigures a trap receiver to ensure that all SNMP traps sent by the
RUCKUS device go to the same SNMP trap receiver or set of receivers, typically one or more
host devices on the network.
snmp-server legacyConfigures legacy values for SNMP MIBs.
snmp-server locationConfigures the SNMP server location.
- snmp-server log-suppress-timer
Configures the SNMP authentication failure
suppress time interval.
snmp-server max-ifindex-per-moduleConfigures the maximum number of ifindexes per module.
snmp-server preserve-statisticsDecouples SNMP statistics from CLI-based statistics.
snmp-server pw-checkControls password check on file operation MIB objects.
snmp-server trap-sourceConfigures an interface as the source for all traps.
snmp-server user Creates or changes the attributes of SNMPv3 users, and allows an SNMPv3 user to be
associated with the user-defined group name.
snmp-server viewCreates an SNMP view.
source-guard enableEnables IP Source Guard (IPSG) on a port
or a range of ports, per-port per-VLAN, or a VLAN or a range of VLANs.
source-interfaceConfigures the source IP address of the Network Time Protocol (NTP) packets.
source-ipSets the source IP address of an
Encapsulated Remote Switched Port Analyzer (ERSPAN) mirror.
spanning-treeConfigures STP on all ports on a device.
spanning-tree (Ethernet, LAG)Configures the Spanning Tree Protocol (STP) path and priority costs for an Ethernet
port or Link Aggregation Group (LAG).
spanning-tree 802-1wConfigures the 802.1w parameters.
spanning-tree 802-1w ethernetEnables the spanning-tree 802.1w port commands on Ethernet ports.
spanning-tree designated-protect Disallows the designated forwarding state on a port in STP 802.1d or 802.1w.
spanning-tree path-cost-methodConfigures all ports running Spanning Tree Protocol (STP) to alter the path costs
to match either the 802.1D 1998 path costs or the 802.1D 2004 path costs.
spanning-tree root-protectConfigures STP root guard.
spanning-tree rstpEnables 802.1w Draft 3 in a port-based VLAN.
speed-duplexSets link speed and mode (full or half duplex, or slave or master).
spt-thresholdChanges the number of packets the device receives using the RP before switching to
the SPT.
spx allow-pe-movementAllows you to move PE units to other CB SPX ports without changing the PE ID or changing
any related port configuration.
spx cb-configureEnters 802.1br control bridge (CB) configuration mode, where SPX ports and LAGs are
configured.
spx cb-enableEnables a standalone ICX 7750 or ICX 7650 or an ICX 7750 or ICX 7650 stack as an SPX
control bridge (CB).
spx interactive-setupAllows you to configure several options interactively: change existing PE IDs, discover
and assign IDs to new PE units, and convert existing or new standalone devices to
PE units.
spx pe-enableEnables SPX port extender (PE) mode.
spx pingPings specified PE data port, based on its ECID, to determine if the port is reachable.
spx suggested-idDefines a preferred ID for the PE unit being configured.
spx unconfigureRemoves the PE startup file and recovers the designated PE unit or units to regular
mode.
spx unitConfigures a reserved SPX unit or certain parameters on a live SPX unit.
spx zero-touch-denyConfigures a standalone unit so that it cannot be discovered by the SPX zero-touch
or SPX interactive-setup utility.
spx-lagConfigures one end of a multi-port connection on a CB or a PE unit.
spx-mon enableEnables spx-mon analysis tools.
spx-portConfigures one or more SPX ports for the control bridge (CB) or a port extender (PE)
unit.
sshStarts an SSH2 client connection to an SSH2 server using password authentication.
ssh access-groupConfigures an ACL that restricts SSH access to the device.
ssm-enableGlobally enables source-specific multicast (SSM).
stack disablePrevents a device from joining a traditional stack and from listening for, or sending,
stacking packets.
stack enableEnables stack configuration on the device. Enter this command on the intended active
controller.
stack interactive-setupPresents command options that you can select to discover new stack units or standalones
and integrate them, with your confirmation, into the stacking system. Also offers
the option to change the IDs of existing stack units.
stack macManually configures a specific MAC address for a traditional stack.
-
stack suggested-idSpecifies the preferred stack unit ID for a standalone device before it joins a stack.
stack suppress-warningStops periodic output of background stack diagnostic reports.
stack switch-overSwitches active controllers without reloading the stack and without packet loss to
services and protocols supported by hitless stacking.
stack unconfigure Returns a stack member to its pre-stacking configuration or state.
stack zero-touch-enableEnables background zero-touch provisioning (ZTP) to form a stack system or to add
new stack units without user intervention.
stack-portConfigures a stacking port used to link between two units.
stack-trunk Configures a stack to form a trunk from contiguous links on one side of a stack connection.
static-mac-addressConfigures a static MAC address and assigns the address to the premium queue.
static-mac-ip-mappingAdds the client MAC address mapping to the IP address.
static-port-ip-mappingMaps an Ethernet interface to the IP
address for a Dynamic Host Configuration Protocol (DHCP) server.
store-and-forwardResets the switching method for forwarding packets from cut-through to store-and-forward.
stp-bpdu tx-filterSuppresses transmission of Spanning Tree
Protocol (STP) Bridge Protocol Data Units (BPDUs) on an interface while still allowing
the
interface to receive and process BPDUs for supported STP modes, such as Rapid Spanning
Tree
Protocol (RSTP).
stp-bpdu-guardEnables STP BPDU Guard on the Ethernet interfaces.
stp-groupChanges the CLI to the STP group configuration level.
stp-protectPrevents an end station from initiating or participating in STP topology changes.
subnet6 (DHCPv6)Configures a subnet for a DHCPv6 server and accesses DHCPv6 subnet configuration mode.
-
summary-address (OSPFv2)Configures route summarization for redistributed routes for an Autonomous System Boundary
Router (ASBR).
ip tftp blocksizeSpecifies the size of Trivial File
Transfer Protocol (TFTP) blocks.
-
summary-address (OSPFv3)Configures route summarization for redistributed routes for an Autonomous System Boundary
Router (ASBR).
supportsaveCollects logs from different modules and
uploads the logs into a remote SCP or TFTP server.
switch-over-active-roleActivates switchover of the active and standby management modules without any packet
loss to the services and protocols that are supported by hitless management.
symmetrical-flow-control enableEnables symmetrical flow control (SFC)
globally.
system-max gre-tunnelsAllocates maximum number of GRE tunnels.
system-max igmp-snoop-group-addrSets the maximum number of Internet Group Management Protocol (IGMP) snooping group
addresses on a device.
system-max igmp-snoop-mcacheConfigures the maximum number of Internet Group Management Protocol (IGMP) snooping
mcache entries supported on a device.
system-max ip-arpConfigures the maximum number of Address
Resolution Protocol (ARP) table entries.
system-max ip-cacheConfigures the maximum number of IPv4
cache entries.
system-max ip-routeIncreases the capacity of the IP route table.
system-max
ip-route-default-vrfConfigures maximum IPv4 routes to be allocated for the default VRF instance.
system-max ip-route-vrfConfigures default maximum IPv4 routes to be allocated per user-defined VRF.
system-max
ip-static-arpConfigures the maximum number of static
Address Resolution Protocol (ARP) table entries.
system-max ip-subnet-portIncreases the number of IP subnet interfaces that can be configured on each port of
the device.
system-max ip-vrfConfigures maximum VRF instances supported by the software.
system-max ip6-cacheConfigures the maximum number of IPv6 cache entries.
system-max ip6-neighborConfigures the maximum number of IPv6 neighbors.
system-max ip6-routeConfigures maximum IPv6 routes, used to initialize hardware during system init.
system-max
ip6-route-default-vrfConfigures maximum IPv6 routes to be allocated for the default VRF instance.
system-max
ip6-route-vrfConfigures default maximum IPv6 routes to be allocated per user-defined VRF.
system-max l3-interfaceConfigures the maximum number of Layer 3
interfaces that can be configured on a system for
ICX 7150 devices.
system-max macChanges the capacity of the MAC address table.
system-max mac-notification-bufferChanges the value of the MAC-notification buffer.
system-max max-ecmpConfigures the maximum limit of ECMP paths at the system level.
system-max max-ip-macChanges the maximum number of MAC addresses that can be configured on IP interfaces.
system-max mld-snoop-group-addrSets the maximum number of Multicast Listening Discovery (MLD) snooping group addresses
on a device.
system-max mld-snoop-mcacheSets the maximum number of Multicast Listening Discovery (MLD) snooping mcache entries
supported on a device.
system-max msdp-sa-cacheConfigures the maximum number of source active (SA) messages n the Multicast Source
Discovery Protocol (MSDP) cache.
system-max
openflow-flow-entriesConfigures the openflow flow table
entries limit in the flow table.
system-max
openflow-pvlan-entriesConfigures the CAM size of openflow
protected VLAN entries for the device.
system-max
openflow-unprotectedvlan-entriesConfigures the CAM size of openflow
unprotected VLAN entries for the device.
system-max pim-hw-mcacheSets the maximum number of SG entries allowed in the device.
system-max pim6-hw-mcacheSets the maximum number of SG entries allowed in the device.
system-max pms-global-poolConfigures the maximum number of global resources shared among all interfaces on the
device to store secure MAC addresses for port MAC security (PMS).
system-max rmon-entriesConfigures the maximum number of entries allowed in the RMON control table.
system-max spanning-treeConfigures the system maximum value for the number of spanning tree instances.
system-max view Configures the maximum number of SNMP views available on a device.
system-max virtual-interfaceIncreases the maximum number of virtual routing interfaces you can configure.
system-max vlanIncreases the maximum number of VLANs you can configure.
sz active-listConfigures the SmartZone IP addresses that the ICX switch will use first to initiate
a connection with SmartZone.
sz disableDisables SmartZone management of the device.
sz disconnectDisconnects the switch from the current SmartZone connection and initiates a new connection
to SmartZone based on the IP address list that is currently available.
sz passiveConfigures the lowest priority SmartZone IP addresses that the ICX switch will use
to initiate a connection with SmartZone.
sz query Initiates a query to a specific SmartZone IP address if it is not yet connected.
sz registrarAllows an administrator to override the default registrar host used in registrar-based
SmartZone discovery.
sz registrar-listAllows administrators to clear addresses learned via the switch registrar from the
SmartZone node list.
sz registrar-query-restartAllows administrators to force start the SmartZone discovery on ICX devices via the
SmartZone registrar.
-
table-map
Maps external entry attributes into the BGP routing table, ensuring that those attributes
are preserved after being redistributed into OSPF.
tacacs-server deadtimeConfigures the duration for which the device waits for the primary authentication
server to reply before deciding the TACACS server is dead and trying to authenticate
using the next server.
tacacs-server enable Configures the device to allow TACACS server management access only to clients connected
to ports within port-based VLAN.
tacacs-server hostConfigures the TACACS/TACACS+ server host to authenticate access to a device.
tacacs-server keyConfigures the value that the device sends to the TACACS server when trying to authenticate
user access.
tacacs-server retransmitConfigures the maximum number of retransmission attempts for a request when a TACACS
authentication request times out.
tacacs-server timeoutConfigures the number of seconds the device waits for a response from a TACACS server
before either retrying the authentication request or determining that the TACACS servers
are unavailable and moving on to the next authentication method in the authentication
method list.
tag-profileConfigures or changes the tag profile for 802.1ad tagging.
tag-profile enableDirects the individual ports or a range of ports to the tag profile.
tagged ethernetTags a port to allow communication among the different VLANs to which the port is
assigned.
tagged lagTags LAG virtual interfaces to allow communication among the different VLANs to which
the LAG virtual interface is assigned.
telnetEnables a Telnet connection from the device to a remote IPv6 host using the console.
telnet access-groupConfigures an ACL that restricts Telnet access to the device.
telnet clientRestricts Telnet access to a host with the specified IP address.
telnet login-retriesConfigures the number of attempts you can enter a correct username and password before
the device disconnects the Telnet session.
telnet login-timeoutConfigures the login timeout for a Telnet session.
telnet server enableConfigures Telnet access only to clients in a specific VLAN.
telnet server suppress-reject-messageConfigures the device to suppress the Telnet connection rejection message.
telnet strict-management-vrfAllows incoming Telnet connection requests only from the management VRF and not from
the out-of-band (OOB) management port.
telnet timeoutConfigures the duration of time, a Telnet session can remain idle before it is timed
out.
temperature warning Changes the temperature threshold at which the device sends a syslog message and
an SNMP trap.
terminal loggingDisables or re-enables terminal logging, which captures all the console prints generated
on the system to a RAMFS file and copies the RAMFS file to the flash memory upon certain
triggers.
terminal monitorEnables the real-time display for a Telnet or SSH session.
tftp client enableConfigures the device to allow TFTP access only to clients in a specific VLAN.
tftp disableDisables TFTP client access.
tftp-serverSpecifies the address or name of the TFTP server to be used by the DHCP client.
-
tftp-server (Image) Configures the TFTP server location where auto image copy can download a software
image.
timeout (EFM-OAM) Configures the time in seconds for which the local Data Terminal Equipment (DTE)
waits to receive OAM Protocol Data Units (OAMPDUs) from the remote entity.
-
timers
(BGP)Adjusts the interval at which BGP KEEPALIVE and HOLDTIME messages are sent.
-
timers (OSPFv2)Configures Link State Advertisement (LSA) pacing and Shortest Path First (SPF) throttle
timers.
-
timers
(OSPFv3) Configures Link State Advertisement (LSA) pacing and Shortest Path First (SPF) timers.
timers (RIP)Specifies how often RIP update messages are sent.
timers (RIPng)Adjusts RIPng timers.
-
tolerance Configures the tolerance value for the accept keys and send keys for the keychain
to extend the lifetime of the keys beyond the active lifetime duration (prior to the
start of the lifetime or after the end of the lifetime).
topology-groupConfigures the topology group.
- trace-l2
Displays the Layer 2 path that a packet
takes from a source device to a destination device and displays all paths in the specified
VLAN.
tracerouteDetermines the path through which a
RUCKUS device can reach another device.
-
track-port Configures network reachability tracking for a specific Virtual Router Redundancy
Protocol (VRRP) or VRRP Extended (VRRP-E) port.
track-port (VSRP)Configures the VRID on one interface to track the link state of another interface
on the device.
traffic-policy countConfigures a traffic policy and enables counting the number of bytes and the conformance
level per packet.
traffic-policy rate-limit adaptiveConfigures an ACL-based flexible-bandwidth traffic policy to define rate limits on
packets so that you can allow for bursts above the limit.
traffic-policy rate-limit fixedConfigures an ACL-based fixed-rate traffic policy to define rate limits on packets.
The policy either drops all traffic that exceeds the limit or forwards the traffic
at the lowest priority level.
transformConfigures a transform set for an IPsec proposal.
trunk-thresholdConfigures the threshold value for the number of active member ports in a LAG, below
which all the ports in a LAG group are disabled.
trust dscpConfigures the device to honor DSCP-based QoS for routed and switched traffic.
trust-portConfigures ports of a Web Authentication VLAN as trusted ports.
tunnel destination Configures the destination address for a specific tunnel interface.
tunnel mode gre ip Enables generic routing encapsulation (GRE) over on a tunnel interface and specifies
that the tunneling protocol is IPv4.
tunnel mode ipsecConfigures the mode of a virtual tunnel interface (VTI) as IPsec.
tunnel mode ipv6ipConfigures the tunnel mode as a manual IPv6 tunnel.
tunnel
path-mtu-discoveryEnables Path MTU Discovery (PMTUD).
tunnel protection ipsec profileConfigures an IPsec profile for an IPsec virtual tunnel interface (VTI).
tunnel source Configures the source address or a source interface for a specific tunnel interface.
tunnel tosConfigures the Type of Service (ToS) value for an IPsec virtual tunnel interface (VTI).
tunnel vrfConfigures the base VRF for an IPsec virtual tunnel interface (VTI).
unit-name (Stacking)Applies a name to a stack member.
- unknown-unicast limit
Configures the maximum number of unknown
unicast packets allowed per second and generates infralogs for pps packets.
unmount disk0Unmounts the external USB.
untaggedAdds untagged ports to the VLAN.
update-lag-nameChanges the name of an existing LAG without causing any impact on the functionality
of the LAG.
-
update-time
(BGP)Configures the interval at which BGP next-hop tables are modified. BGP next-hop tables
should always have IGP (non-BGP) routes.
update-time (RIP)Specifies how often the device sends RIP route advertisements to its RIP neighbors.
- uplink-port (Web Auth)
Specifies an Ethernet port or LAG to be
used for connecting to the user's uplink switch.
use-radius-serverMaps a RADIUS server to a port.
use-v2-checksum Enables the v2 checksum computation method for an IPv4 Virtual Router Redundancy
Protocol version 3 (VRRPv3) session.
use-vrrp-path (RIP)Suppresses RIP advertisements for interfaces on which Virtual Router Redundancy Protocol
(VRRP) or VRRP Extended (VRRP-E) backup routers are configured.
usernameCreates or updates a user account.
username (Local Database)Creates a user record in the local user database.
valid-lifetime (DHCPv6)Specifies how long the IPv6 prefix remains valid for onlink determination.
vendor-classSpecifies the vendor type (option 60) and configuration value for a DHCP client.
verifyAllows the verification of boot images based on hash codes and the generation of hash
codes where needed.
verify device-keyVerifies the cryptographic key and certificate stored on the ICX device.
versionSets the version number for a Virtual Router Redundancy Protocol (VRRP) session.
violationConfigures the action that must be taken according to the configurable violation modes
when a security violation occurs.
virtual-ip Configures the IP address of the external captive portal server as the virtual IP
address.
virtual-port Configures the HTTP port number to facilitate HTTP services for the clients in external
Web Authentication.
vlanCreates a VLAN or range of VLANs.
vlan-configConfigures Virtual Local Area Network (VLAN) tasks such as all or selective ports
to a VLAN, moving untagged port membership between VLANs, and removing ports from
a VLAN.
vlan-groupConfigures a VLAN group.
vni-countersEnable VXLAN Network Identifier (VNI)
counters for a VXLAN overlay-gateway.
voice-vlanCreates a voice VLAN at the global level.
vrfConfigures a Virtual Routing and Forwarding (VRF) and enters VRF configuration mode.
vrf forwardingAssigns a virtual routing and forwarding
(VRF) routing instance to an interface.
vsrpConfigures VSRP on a device.
vsrp auth-typeConfigures a simple text-string as a password in packets sent on the interface.
vsrp-awareConfigures the security features on a VSRP-aware device.
- vxlan-riot
Enables Virtual Extensible Local Area
Network (VXLAN) Routing In and Out of Tunnels (RIOT) for an overlay gateway and configures
the overlay next-hop partition size.
web access-groupConfigures an ACL that restricts web management access to the device.
web clientAllows web management access only to a host with a specified IP address.
web-managementConfigures web management access options.
webauthConfigures a Web Authentication VLAN and enters the Web Authentication configuration
mode.
webauth-redirect-addressConfigures a redirect address for Web Authentication to prevent the display of error
messages saying that the certificate does not match the name of the site.
- webpage custom-label
Customizes the User ID or Password label
on the Web Authentication page.
webpage custom-textCustomizes the text that appears on the title bar, login button, header, and footer
on the Web Authentication pages.
webpage logoCustomizes the logo that appears on all Web Authentication pages and its placement.
- webpage remove-userid-label
Removes the User ID label and text field
from the Web Authentication page.
webpage termsCustomizes the text box that appears on the Web Authentication Login page.
- white-list (Web Authentication)
Adds IPv4 or FQDN addresses allowed access
during authentication along with the required Captive-Portal server, DNS servers,
or DHCP
servers.
- wired direct-clients enable
Use this command to show (on the SmartZone
GUI) the device information for wired clients that are connected directly to this
switch.
wpadSpecifies the Proxy Auto-Config (PAC) file location using the Web Proxy Auto-Discovery
(WPAD) protocol.
write terminalDisplays the running configuration.
xwindow-managerSpecifies the IP addresses of systems that are running the X Window System Display
Manager and are available to the client.
zero-touch-enableAllows the CB in a Campus Fabric (SPX) domain to discover PE candidates and convert
them to active PE units.
zero-touch-portsDefines additional ports on which candidate PE units can be discovered when the zero
touch provisioning utility or SPX interactive-setup is enabled.