Show���Interface Commands�
Ñ]ëi|ˆ\
اﻷﻣـر
show interface brief sh int b
show interface config sh int con
show interface status sh int st
show interface status sh int st
اﻷﻣـر Ñ]ëi|ˆ\
show interface sh int
show interface custum 40
choose :
(port, type, status, speed, mode, mdi, flow,
name, vlan, enabled, intrusion, bcast)
Ex: sh int cu 40 port status speed
show running-config interface 1 sh run int 1
اﻷﻣـر Ñ]ëi|ˆ\
show interface 1 sh int 1
show interface 1-3 sh int 1-3
show interface 1-3 sh int 1-3
اﻷﻣـر Ñ]ëi|ˆ\
show interface port-utilization sh int p
show interface tranceiver sh int tra
sh tec tra
Show VLAN Commands
اﻷﻣـر Ñ]ëi|ˆ\
show vlans sh vl
show running-config vlan sh ru n vl
show vlans 12 sh vl 12
اﻷﻣـر Ñ]ëi|ˆ\
show running-config vlan 12 sh run vl 12
On Core Switch On Edge Switch
show vlan ports 1-5 sh vl p 1-5
show vlans custom name
sh vl p 1-5
choose :
(id, name, status, voice, jumbo,
ipconfig, ipaddr, ipmask, proxyarp,
localproxyarp, state)
Show���MAC-Address���Commands�
اﻷﻣـر Ñ]ëi|ˆ\
show mac-address sh mac-add
ﻟرؤﯾﺔ ﺟﻣﯾﻊ اﻟـ
Mac Address
ﻟﻸﺟﮭزة اﻟﻣﺗﺻﻠﺔ ﻋﻠﻰ اﻟﺳوﯾﺗش
show mac-address vlan 10 sh mac-add vl 10
ﻟرؤﯾﺔ ﺟﻣﯾﻊ اﻟـ
Mac Address
ﻟﻸﺟﮭزة اﻟﻣﺗﺻﻠﺔ ﻋﻠﻰ اﻟﺳوﯾﺗش
10 اﻟﺧﺎﺻﺔ ﺑـ ﻓﯾﻼن رﻗم
show mac-address | include 94e1
sh mac-add | inc 94e1
ﻟﻠﺑﺣث ﻋن اﻷﺟﮭزة ﺑﺟزء ﻣن اﻟـ
Mac Address
show mac-address 94e1ac-20ee68
sh mac-a 94e1ac-20ee68
ﻟﻠﺑﺣث ﻋن ﺟﮭﺎز واﺣد ﺑﺎﻟـ
Mac Address
اﻷﻣـر Ñ]ëi|ˆ\
show mac-address 5 sh mac-add 5
ﻟﻠﺑﺣث ﻋن
Mac Address
5 اﻟﺧﺎص ﺑـ ﺑورت رﻗم
show mac-address 35-40 sh mac-add 1-5
Show�Connected���Devices�with���Switch
اﻷﻣـر Ñ]ëi|ˆ\
# To Show all Devices that connect on your switch ﻟﻣﻌرﻓﺔ اﻷﺟﮭزة اﻟﻣﺗﺻﻠﺔ
(Another Switch , Access Point or IP Phone ﺑﺎﻟﺳوﯾﺗش
Show CDP neighbors sh cdp ne
Show lldp info remote-device sh ll in r
داﺋﻣﺎ ً ﻟﺣﻔظ اﻷواﻣر ﺑﻌد ﻋﻣل أي ﺗﻌدﯾل ﯾﺟب ﻛﺗﺎﺑﺔ اﻷﻣر
wr me
اﻷﻣـر \ˆ|Ñ]ëi
Show lldp info remote-device 3 sh ll in r 3
ﻟرؤﯾﺔ ﺗﻔﺎﺻﯾل اﻟﺟﮭﺎز اﻟﻣﺗﺻل ﺑﺎﻟﺳوﯾﺗش
ﻋﻠﻰ اﻟﺑورت رﻗم 3
اﻷﻣـر Ñ]ëi|ˆ\
Show lldp info remote-device detail
ﻟرؤﯾﺔ ﺗﻔﺎﺻﯾل اﻷﺟﮭزة اﻟﻣﺗﺻﻠﺔ ﺑﺎﻟﺳوﯾﺗش
sh ll in r d
{Rename Switch and Give it IP Address}
Tab ﻟﻣﻌرﻓﺔ اﻷﻣر ﻛﺎﻣﻼً ﺑدل اﻹﺧﺗﺻﺎل ﯾﻣﻛﻧك اﻟﺿﻐط ﻋﻠﻰ ذر
؟ ﻟﻣﻌرﻓﺔ ﺑﺎﻗﻲ اﺳﺗﻛﻣﺎل اﻷﻣر ﯾﻣﻛﻧك اﻟﺿﻐط ﻋﻠﻰ
Ñ]ëi|ˆ\
اﻷﻣـر
# Give Switch new name :
conf
hostname SW1
exit
# Give Switch IP Address :
conf
vlan 1
ip add 10.1.1.1 255.255.255.0
exit
{Create Password for Switch}
Ñ]ëi|ˆ\
اﻷﻣـر
# Create Admin Password (can do everything) :
conf
password manager username admin password P@ssw0rd
Ñ]ëi|ˆ\
conf
pas ma u admin p P@ssw0rd
# Create Operator Password (for view only) :
conf
password operator username omar password P@ssw0rd
Ñ]ëi|ˆ\
conf
pas o u omar p P@ssw0rd
# Recovering from a lost manager password :
If you cannot start a console session at the manager level because of a lost
manager password, clear the password by following these steps:
Get physical access to the switch.
Press and hold the Clear button on the switch for a minimum of one second.
This deletes all passwords and usernames (manager and operator) used by the
console and the WebAgent.
Create VLANs
Ñ]ëi|ˆ\
اﻷﻣـر
# Create VLANs on Core Switch with Interface IP Address :
conf
vlan 10 name LAN
tagged A2-A8,B1-B8
exit
vlan 10
ip add 10.1.10.1 255.255.255.0 A2-A8,B1-B8 ﺣﯾث أن اﻟـ
exit ھﻲ أرﻗﺎم اﻟﺑورﺗﺎت ﻋﻠﻰ اﻟـ
vlan 2 0 name wifi Core Switch
tagged A2-A8,B1-B8
ip add 10.1.20.1 255.255.255.0
exit
vlan 30 name Voice
tagged A2-A8,B1-B8
exit
ip add 10.1.30.1 255.255.255.0
exit
# Create VLANs on Edge Switch :
conf
vlan 10 name LAN
tagged 49
exit
vlan 2 0 name wifi 49 ﺣﯾث أن اﻟـ
tagged 49 ھو رﻗم اﻟﺑورت اﻟﻣﺗﺻل ﺑﺎﻟـ
exit Core Switch
vlan 30 name Voice
tagged 49
exit
Assigning ports to VLANs
اﻷﻣـر
# Add one port to vlan :
conf
int 1
untagged vlan 10
exit
wr me
# Add multiple ports to vlan :
conf
int 1-48
untagged vlan 10
exit
wr me
# Shutdown one port : # Shutdown Multiple Port s:
conf conf
int 1 int 1-5
disable disable
exit exit
# Enable one port : # Enable Multiple Ports :
conf conf
int 1 int 1-5
enable enable
exit exit
# Create Port Trunk
ﯾﺟب ﻋدم ﺗوﺻﯾل أي ﻛﺎﺑﻼت ﺑﺎﻟﺑورت اﻟﻣراد ﺟﻌﻠﮫ ﺗراﻧك إﻻ ﺑﻌد ﻋﻣل اﻹﻋدادات: ﻣﻠﺣوظﺔ ھﺎﻣﺔ ﺟدا
اﻟﻣطﻠوﺑﺔ أو ﯾﺟب إﻏﻼق اﻟﺑورت أوﻻ ﺛم ﻋﻣل إﻋدادات اﻟﺗراﻧك ﻟﺗﺟﻧب ﻋﻣل
Broadcast Storm
# Create one port as Trunk :
conf
trunk 46 Trk1 trunk
exit
wr me
# Create Multiple port s as Trunk :
conf
trunk 47-48 Trk1 trunk
exit
wr me
# Assign vlan to trunk :
conf
vlan 10
untagged trk1
exit
vlan 11
tagged trk1
exit
wr me
# Assign Multiple vlans to trunk :
conf
vlan 10-15,100,200
tagged trk1
exit
wr me
# Remove Port Trunk
ﯾؤدي إﻟﻰLoop إﻟﻐﺎء اﻟﺑورت ﻣن إﻋدادات اﻟﺗراﻧك ﻗد ﺗؤدي إﻟﻰ ﻋﻣل: ﻣﻠﺣوظﺔ ھﺎﻣﺔ ﺟدا
ً وﻟﮭذا ﯾﺟب ﻓﺻل اﻟﺑورت أو إﻏﻼﻗﮫ أوﻻBroadcast Strom
# Remove vlan from trunk :
conf
vlan 10
no tagged trk1
exit
wr me
# Remove Multiple vlan to trunk :
conf
vlan 10-15,100,200
no tagged trk1
exit
wr me
# Remove trunk from port :
conf
no trunk 46
exit
wr me
# Show trunk Command :
show trunk
# Create LACP Link Aggregation
# Configuration for a Two Ports LACP Trunk Group :
conf
int 47-48 lacp active
trunk 47-48 trk1 lacp
exit
vlan 6
untagged trk1
exit
vlan 7
tagged trk1
exit
wr me
# Remove lacp trunk from port :
conf
no trunk
47-48
exit
wr me
# LACP Link Aggregation Commands
show lacp
show run int 47-48 show run vlan 6
show lacp peer
show lacp counter
show vlans ports trk1 detail
# Spanning-Tree Configuration
# On Core Switch
spanning-tree
spanning-tree config-name "LV"
spanning-tree config-revision 1
spanning-tree
instance 1 vlan 1-200 1003
spanning-tree root primary priority 0
wr me
# On Edge Switch
spanning-tree
spanning-tree config-name "LV"
spanning-tree config-revision 1
spanning-tree instance 1 vlan 1-200
spanning-tree ethernet 1-48 auto-edge-port
wr me
# Spanning-Tree Commands
sh spanning-tree
Remove spanning-tree
conf
no spanning-tree
sh spanning-tree mst -config
# Spanning Tree Configuration
# Configure DHCP from server 10.1.2.3
conf
vlan 10
ip helper-address 10.1.2.3
exit
vlan 20
ip helper-address 10.1.2.3
exit
# Configure DHCP pool on Core Switch :
conf
dhcp-server disable
dhcp-server pool "AP"
default-router "10.1.100.1"
dns-server "10.1.2.3,8.8.8.8"
lease 08:00:00 OR lease infinite network
10.1.100.0 255.255.255.0 range
10.1.100.121 10.1.100.250
exit
dhcp-server enable vlan 100
dhcp-server
wr me
# Configure DHCP pool on Core Switch :
conf
dhcp-server disable
dhcp-server pool "AP"
static-bind ip 10.1.100.100 255.255.255.0 mac 42:EC:ED:A3:B3:64
# DHCP show commands
show dhcp-server
show dhcp-server pool
show dhcp-server binding
# To clear dhcp IPs :
clear dhcp-ser bin
# Device-Profile Configuration
# Create Device-Profile for Access Point : : ﻟﺗﻐﯾﯾر اﻟﺑورت ﺣﺳب اﻟﺟﮭﺎز
conf اﻟﻣﺗﺻل ﺑﮫ
device-profile name "AP" ﺑﻣﻌﻧﻰ ﻟو ﺗم ﺗوﺻﯾ ل
untagged-vlan 100 Aruba Access Point
tagged-vlan 5,14-21,23-28 AP ﯾﺗﺣول اﻟﺑورت إﻟﻰ ﻓﯾﻼن اﻟـ
exit
وﻟو ﺗم ﺗوﺻﯾ ل
Aruba Switch
device-profile type "aruba-ap"
ﯾﺗﺣول اﻟﺑورت إﻟﻰ ﺗرﻧ ك
associate "AP"
ﯾﺗﺣولPC وﻟو ﺗم ﺗوﺻﯾل
enable اﻟﺑورت إﻟﻰ ﻓﯾﻼن اﻷﺟﮭ زة
exit ﻛل دا ﺑدون ﺗﺧدل ﻣﻧك
# Create Device-Profile for Aruba Switch :
conf
device-profile name "SW"
tagged-vlan 2-21,23-28,100,200
exit
device-profile type "aruba-switch"
associate "SW"
enable
exit
show device-profile status
show device-profile config
# Remove Device-Profile :
# Remove Device-Profile for Access Point :
conf
no device-profile type "aruba-ap"
no device-profile name "AP"
# Remove Device-Profile for Aruba Switch :
conf
no device-profile type "aruba-switch"
no device-profile name "SW"
# SNMP-Server Configuration
# Create SNMP-Server with ICM server IP 10.1.2.9 :
conf
snmp-server community "public" unrestricted
snmp-server community "LV" operator unrestricted
snmp-server host 10.1.2.9 community "LV" trap-level all
snmpv3 targetaddress "traphost.LV.10.1.2.9" params "traphost.LV.10.1.2.9"
10.1.2.9 taglist "TrapHost"
snmpv3 params "traphost.LV.10.1.2.9" user "LV" sec-model ver2c message-
processing ver2c
Show snmp-server
# Access-List Configuration
# Create access-list to allow specific vlan and specific hosts to access
specific vlan and specific Host:
conf
ip access-list extended "NVR"
10 permit ip 10.1.14.0 0.0.0.255 10.1.4.0 0.0.0.255
11 permit ip 10.1.7.47 0.0.0.0 10.1.4.253 0.0.0.0
12 permit ip 10.1.12.83 0.0.0.0 10.1.4.0 0.0.0.255
13 deny ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255
exit
vlan 4
ip access-group "NVR" out