CX Sandbox

The commands, one note each

What each command does, two or three examples you can type into the sandbox, what changed between AOS-CX 10.15 and 10.18, and where the sandbox fakes hardware instead of reproducing it. Every example is run through the sandbox before this page is built, and every release line comes from the command lists I pulled off the Switch Simulator for each release. The same notes show up beside the terminal as you type.

Basics

configure terminal

Get into configuration mode

Everything that changes the switch starts here. The prompt grows (config) and stays until you type end. Unique abbreviations work: conf t is the same thing.

In every release here, 10.15 to 10.18.

Habit: Take a checkpoint before a change you might want to undo: copy running-config checkpoint before-change.
try it in the sandbox
configure terminalhostname access-01endconf tvlan 10end

Goes withendcopy running-config checkpoint <WORD>

end

Back to the # prompt

Leaves whatever context you are in and drops you at the exec prompt. exit goes up one level; end goes all the way.

In every release here, 10.15 to 10.18.

try it in the sandbox
configure terminalinterface 1/1/1endconfigure terminalvlan 10exitend

Goes withconfigure terminal

hostname <WORD>

Name the switch

Sets the name in the prompt, in LLDP and in logs. Letters, digits, dots and dashes, no spaces.

In every release here, 10.15 to 10.18.

Habit: Put the location in the name. You will read it in an LLDP table at 2 a.m. someday.
try it in the sandbox
hostname access-01hostname idf2-sw1
write memory

Save the running config

Copies the running configuration to the startup configuration so it survives a reboot. copy running-config startup-config does the same.

In every release here, 10.15 to 10.18.

Habit: Save after the change is proven, not before. Until then a reboot is your rollback.
try it in the sandbox
write memorycopy running-config startup-config

Goes withshow startup-config

show running-config

What the switch is running

The whole active configuration. Add interface 1/1/5 to see one port's block. Pipe it to cut it down: | begin, | include.

In every release here, 10.15 to 10.18.

Changed: 10.16 added server priority lines and the built-in radius group to the output; 10.15 printed neither.
try it in the sandbox
show running-configshow running-config interface 1/1/5show running-config | begin "port-access role"

Goes withshow startup-configshow checkpoint

show startup-config

What it will boot with

The saved configuration, the one a reboot loads. If it differs from the running config, something has not been saved yet, on purpose or not.

In every release here, 10.15 to 10.18.

try it in the sandbox
show startup-configcheckpoint diff startup-config running-config

Goes withwrite memoryshow running-config

show version

Which release it runs

The AOS-CX release and build. The first two letters say the platform: ML for the 6200, FL for the 6300. The release picker in the sandbox changes what this says.

In every release here, 10.15 to 10.18.

try it in the sandbox
show versionshow version | include Version

Goes withshow system

show system

Model, serial, uptime

Product name and part number, serial, base MAC, uptime and CPU. The part number is how you tell a 6200F 12-port from a 24-port when nobody wrote it down.

In every release here, 10.15 to 10.18.

Changed: 10.18 added CPU idle, user and system lines; 10.17 printed CPU utilisation only.
try it in the sandbox
show systemshow system | include Product
no page

Stop the more prompt

Turns off paging for this session, so long output scrolls instead of stopping every screen. Every script and screen capture should start with it.

In every release here, 10.15 to 10.18.

try it in the sandbox
no pagepage 40
copy running-config checkpoint <WORD>

A named restore point

Saves the running config under a name. If the running config is identical to a checkpoint that exists, 10.18 refuses with An identical checkpoint already exists.

In every release here, 10.15 to 10.18.

Habit: The box also makes system checkpoints (CPC...) after changes on its own. Name yours so you can find them.
try it in the sandbox
copy running-config checkpoint before-changeshow checkpoint

Goes withcheckpoint rollback <WORD>show checkpoint

checkpoint rollback <WORD>

Go back to a checkpoint

Replaces the running config with the checkpoint. It does not ask. checkpoint diff checkpoint <name> running-config shows the difference first, and that is worth doing.

In every release here, 10.15 to 10.18.

try it in the sandbox
copy running-config checkpoint before-changecheckpoint rollback before-changecheckpoint rollback startup-config

Goes withcopy running-config checkpoint <WORD>show checkpoint

show checkpoint

List the checkpoints

Every checkpoint, newest first, with the startup config among them by date. show checkpoint <name> prints one. There is no show checkpoint list on 10.18: the box reads list as a checkpoint name.

In every release here, 10.15 to 10.18.

try it in the sandbox
show checkpointshow checkpoint before-change
checkpoint diff <from> <to>

What changed between two configs

Compares any two of running-config, startup-config and checkpoint <name> as a unified diff: a line starting with a plus is only in the second, one starting with a minus only in the first. No difference in configs. means they match. Worth running before every rollback.

In every release here, 10.15 to 10.18.

Habit: checkpoint diff startup-config running-config before you walk away tells you whether anything is unsaved.
try it in the sandbox
copy running-config checkpoint before-changecheckpoint diff checkpoint before-change running-configcheckpoint diff startup-config running-config

Goes withcheckpoint rollback <WORD>show checkpoint

VLANs

vlan <1-4094>

Create a VLAN

Creates the VLAN and enters its context. Name it there. A port cannot use a VLAN that does not exist.

In every release here, 10.15 to 10.18.

try it in the sandbox
vlan 10name STAFFvlan 30name VOICEvoice

Goes withshow vlanname <WORD>

name <WORD>

Name the VLAN

Shows in show vlan and in LLDP. One word here; the box takes a longer line too.

In every release here, 10.15 to 10.18.

try it in the sandbox
vlan 20name PRINTERSvlan 99name AP-MGMT
voice

Mark the voice VLAN

Tells LLDP-MED this VLAN carries voice. Phones that speak LLDP-MED learn it from the network policy the switch sends on ports that tag it: VLAN, priority 6, DSCP 46 with nothing else configured.

In every release here, 10.15 to 10.18.

Habit: Tag the voice VLAN on the phone port and leave the data VLAN native, so the PC behind the phone needs nothing.
try it in the sandbox
vlan 30voiceshow vlan voice

Goes withlldp med network-policyshow lldp neighbor-info

show vlan

VLANs and their ports

Every VLAN, up or down, and which ports carry it. Down with no_member_port means no port is in it; no_member_forwarding means ports are in it but none is up. A role a client holds adds its VLANs to that port here.

In every release here, 10.15 to 10.18.

try it in the sandbox
show vlanshow vlan 30show vlan | include VOICE

Interfaces

interface <IFNAME>

Configure a port or a range

Enters one port (1/1/5) or a range (1/1/1-1/1/8). Member/slot/port: 1/1/5 is member 1, slot 1, port 5.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/5description printerinterface 1/1/1-1/1/8no shutdown
shutdown

Turn a port off

Admin down. no shutdown turns it back on and also clears an error-disabled port. A port nobody configured may be shut: show interface brief says Administratively down.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/11shutdowninterface 1/1/8no shutdown
description <LINE>

Say what is on the port

Free text on the port, shown in show interface brief and LLDP.

In every release here, 10.15 to 10.18.

Habit: Describe uplinks and anything odd. The next person reads the brief, not your ticket.
try it in the sandbox
interface 1/1/7description desk 7, pair 3-6 open at 23 minterface lag 1description uplink to core
no routing

Make it a switch port

A routed port takes an ip address; a switched port takes VLANs. no routing makes it switched. Some platforms (and the Switch Simulator) start every port routed, so check before you assign a VLAN.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/1no routingvlan access 10interface 1/1/12routingip address 203.0.113.129/25
vlan access <1-4094>

One untagged VLAN

Makes the port an access port in that VLAN. The VLAN has to exist.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/5vlan access 20interface 1/1/1-1/1/4vlan access 10
vlan trunk allowed <VLIST>

Tag VLANs on a port

Makes the port a trunk and adds VLANs to its allowed list. It adds: vlan trunk allowed 10 then vlan trunk allowed 20 leaves 10,20, as the lab switch did. no vlan trunk allowed 10 takes one out.

In every release here, 10.15 to 10.18.

Habit: A trunk prints vlan trunk native 1 even when you never set it. Set the native VLAN on purpose.
try it in the sandbox
interface 1/1/3vlan trunk native 10vlan trunk allowed 10,30interface lag 1vlan trunk allowed 10,20,30

Goes withvlan trunk native <1-4094>

vlan trunk native <1-4094>

The untagged VLAN on a trunk

The VLAN whose frames cross the trunk untagged. On a phone port it is the PC's data VLAN; the phone tags voice.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/3vlan trunk native 10vlan trunk allowed 30interface 1/1/13vlan trunk native 99vlan trunk allowed 10,20,99
speed auto

Port speed and auto-negotiation

speed auto offers every speed the port can do; speed auto 1g 2.5g offers only those; speed 1000-full fixes it and turns auto-negotiation off. Since 10.09 the CLI hides speeds the hardware lacks.

In every release here, 10.15 to 10.18.

Where the sandbox pretends: The sandbox models the hardware. The Switch Simulator has virtual ports and hides speed entirely; the syntax is from HPE's fundamentals guide.
Habit: Leave Smart Rate ports on speed auto. Pinning an AP to 1G to fix a flap hides the real problem, usually the cable.
try it in the sandbox
interface 1/1/1speed autointerface 1/1/1speed auto 1g 2.5g 5ginterface 1/1/2no speed

Goes withshow interface <PORT> physicaldiag cable-diagnostic test <PORT>

show interface brief

Every port on one screen

Native VLAN, mode, enabled, up or down, why it is down, speed and description. Read the Reason column first.

In every release here, 10.15 to 10.18.

try it in the sandbox
show interface briefshow interface brief | include down
show interface <PORT>

One port in detail

State, why it is down (State information), VLANs and counters. Blocked by Port Access Security means the link is up but no client has authenticated.

In every release here, 10.15 to 10.18.

Changed: 10.15 says how long the link has been up; 10.16 says up; 10.17 added the Hardware port line.
try it in the sandbox
show interface 1/1/5show interface 1/1/5 | include State
show interface <PORT> physical

Speed, PoE and state

Link and admin state, the speed it runs at next to what it is configured to allow, flow control, PoE draw.

In every release here, 10.15 to 10.18.

Where the sandbox pretends: The PoE column is the sandbox's: the lab's virtual ports draw nothing.
try it in the sandbox
show interface 1/1/1 physicalshow interface physical
show mac-address-table

Who is behind which port

Learned MACs by VLAN and port. port-access-security means the MAC was learned through port-access. Filter by vlan or interface, or pipe it.

In every release here, 10.15 to 10.18.

try it in the sandbox
show mac-address-tableshow mac-address-table interface 1/1/6show mac-address-table | include 53:4c

LAGs and LACP

LACP: both ends have to agree before a member carries traffic access-01 interface lag 1 lacp mode active members 1/1/13-14 2 core interface lag 1 lacp mode active members 1/1/49-50 LACPDUs both ways on each member: every 30 s, or 1 s with lacp rate fast 3 1. Hello: both ends active each sends system id, key and port A L F N C D 2. In sync: same aggregation each agrees the other belongs in lag 1 A L F N C D 3. Up: collecting, distributing only now does the member carry traffic A L F N C D 1 A active, P passive · L long timeout, S short · F aggregable · N in sync · C collecting · D distributing 1 Passive on both ends: nobody starts, nothing forms. One end active is enough; both active is the habit. 2 A new LAG on 10.18 is administratively down. Nothing forms until no shutdown on interface lag 1. 3 No lacp mode means a static LAG: no LACPDUs, so a member cabled to the wrong box still forwards. Proof: show lacp interfaces reads ALFNCD for actor and partner on every member; show lacp aggregates lists them.
LACP bringing up a two-member LAG, and the flags that prove it.
  • Build the LAG first, then add members, then no shutdown the LAG. Settings live on the LAG.
  • lacp mode active on both ends. A static LAG only where the far end cannot speak LACP.
  • lacp rate fast on both ends notices a dead member in about three seconds instead of ninety.
  • Done means ALFNCD for actor and partner on every member in show lacp interfaces.
interface lag <1-256>

Create a link aggregation

Creates lagN and enters it. On 10.18 a new LAG is administratively down: nothing forms until no shutdown.

In every release here, 10.15 to 10.18.

Habit: Configure the LAG first, then put ports in it. Settings live on the LAG, not the members.
try it in the sandbox
interface lag 1no shutdownno routingvlan trunk allowed 10,20lacp mode active

Goes withlag <1-256>lacp mode <active|passive>

lag <1-256>

Put a port in a LAG

Makes the port a member. Its VLAN settings come from the LAG from then on.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/13-1/1/14lag 1
lacp mode <active|passive>

Run LACP

active sends LACPDUs; passive only answers. Two passive ends never form a LAG. Without lacp mode the LAG is static: no LACP at all.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface lag 1lacp mode activeinterface lag 1lacp mode passive
lacp rate <fast|slow>

LACPDUs every second

Asks the partner for a short timeout: a dead link is noticed in about three seconds instead of ninety. The S in PSFNCD is the partner asking for the same.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface lag 1lacp rate fastinterface lag 1no lacp rate
show lacp interfaces

Did the partner agree

Actor and partner state per member. ALFNCD is what you want: Active, Long timeout, aggregable, in sync, collecting, distributing. An empty partner line means nothing is talking back.

In every release here, 10.15 to 10.18.

Changed: 10.18 added IE (LACP fallback active) to the legend; 10.17 has no such line.
try it in the sandbox
show lacp interfacesshow lacp interfaces 1/1/13
show lacp aggregates

Each LAG, its members and mode

Members, heartbeat rate, hash and mode per LAG.

In every release here, 10.15 to 10.18.

try it in the sandbox
show lacp aggregatesshow interface lag 1

Spanning tree

spanning-tree

Turn on spanning tree

MSTP by default. Without it an accidental loop takes the VLAN down. mode rpvst switches to Rapid PVST+.

In every release here, 10.15 to 10.18.

Habit: Decide who is root and set their priority low. Leave it to chance and the oldest switch wins.
try it in the sandbox
spanning-treespanning-treespanning-tree priority 4
spanning-tree port-type admin-edge

An edge port

A port where only end devices live: it forwards at once instead of waiting through listening and learning.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/1-1/1/12spanning-tree port-type admin-edge

Goes withspanning-tree bpdu-guard

spanning-tree bpdu-guard

Shut the port if a switch appears

A BPDU arriving on the port error-disables it. Pair it with admin-edge on every access port. no shutdown brings it back once the switch is gone.

In every release here, 10.15 to 10.18.

Habit: Access ports: admin-edge plus bpdu-guard. Uplinks: neither.
try it in the sandbox
interface 1/1/1-1/1/12spanning-tree bpdu-guard
loop-protect

Catch loops spanning tree cannot see

Sends probes and error-disables the port if one comes back, which catches a loop through an unmanaged switch that drops BPDUs.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/1-1/1/12loop-protect
show spanning-tree

Root, role and state per port

Who is root, which port leads there, and each port's role and state.

In every release here, 10.15 to 10.18.

try it in the sandbox
show spanning-treeshow spanning-tree | include Root

LLDP

LLDP-MED: the phone speaks first, then the switch hands it the voice VLAN IP phone MED endpoint, PC behind it Switch 1/1/3 network connectivity device LLDPDU with LLDP-MED TLVs capabilities, class III, inventory, PoE 2 LLDPDU with a network policy 1 voice: VLAN 30, tagged, prio 6, DSCP 46 Phone tags voice 30, DHCPs there voice frames, tagged 30 PC frames, untagged: native VLAN 10 ON THE SWITCH vlan 30 name VOICE voice interface 1/1/3 vlan trunk native 10 vlan trunk allowed 10,30 lldp med network-policy is on by default on every port WHAT PROVES IT show lldp neighbor-info 1/1/3 show vlan voice show mac-address-table 1 The policy goes out only after the switch hears the phone's MED TLVs. 10.18 added lldp med force-send. 2 On a port-access port, LLDP from a device that has not authenticated is dropped. allow-lldp-bpdu lets it in. No MED from the phone, no network policy back: check the phone's LLDP setting before the switch.
LLDP-MED on a phone port: the phone speaks first, the switch answers with the voice VLAN.
  • Make the voice VLAN a real VLAN with voice set, tag it on the phone port, and leave the data VLAN native.
  • No network policy on the phone? Check the phone sends LLDP-MED before touching the switch.
  • On a NAC port add allow-lldp-bpdu, or LLDP from the phone is dropped before anything reads it.
lldp med network-policy

Send voice VLAN policy to phones

On by default. On a port that tags a voice VLAN the switch sends LLDP-MED network policy, but only after it has heard the endpoint's own LLDP-MED TLVs. no lldp med network-policy stops it.

In every release here, 10.15 to 10.18.

Changed: New in 10.18: lldp med force-send. By default MED TLVs go out only after the endpoint's own arrive (HPE's guide and the lab agree); the sandbox does not model force-send.
try it in the sandbox
interface 1/1/3lldp med network-policyinterface 1/1/3no lldp med network-policy

Goes withvoice

lldp <transmit|receive>

LLDP on a port

LLDP sends and listens on every port by default. no lldp transmit and no lldp receive turn each half off.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/9no lldp transmitinterface 1/1/9lldp transmitlldp receive
show lldp neighbor-info

Who is plugged in where

The LLDP table: port, chassis, remote port, name. Give a port for the full record: capabilities, power it asks for, LLDP-MED class and network policy.

In every release here, 10.15 to 10.18.

Habit: On a port-access port the switch drops LLDP from a client that has not authenticated, unless the port has allow-lldp-bpdu. An empty neighbour on a phone port is often that.
try it in the sandbox
show lldp neighbor-infoshow lldp neighbor-info 1/1/3show lldp neighbor-info | include CAM

RADIUS

802.1X against ClearPass: who says what, in order Laptop supplicant Switch 1/1/1 authenticator, relays only ClearPass RADIUS server, decides EAP-Request, Identity EAPOL on the wire; link came up EAP-Response, Identity the outer identity only RADIUS Access-Request 1 EAP inside, UDP 1812, shared secret PEAP or EAP-TLS: Access-Challenge and Access-Request, several round trips the TLS tunnel runs from the laptop to ClearPass; the switch never sees inside it RADIUS Access-Accept Aruba-User-Role = EMPLOYEE EAP-Success port opens in the role's VLAN CoA-Request, UDP 3799 2 new role, or end the session CoA-ACK 1 A wrong shared secret looks like a dead server: ClearPass drops the request and the switch counts a timeout. 2 On 10.18 a CoA needs radius dyn-authorization client with that server's address, or it is dropped as invalid.
802.1X against ClearPass, from link up to a change of authorization.
  • Two RADIUS servers in the group before go-live. One server is a single point of failure for every port.
  • A critical role on every port-access port, so a ClearPass outage ends somewhere you chose.
  • radius dyn-authorization client for each ClearPass node, or CoA and Disconnect fail without a sound.
  • Auth failing? Look in Access Tracker first. No entry at all means the request never arrived: secret, address or VRF.
radius-server host <A.B.C.D> key plaintext <WORD>

Point the switch at ClearPass

Defines a RADIUS server and the shared secret. The running config shows the key as ciphertext. A wrong key looks like a dead server: the server drops the request and the switch times out.

In every release here, 10.15 to 10.18.

Habit: Use a group (aaa group server radius) even with one server, so adding the second is one line.
try it in the sandbox
radius-server host 192.0.2.10 key plaintext cppm-lab-keyradius-server host 192.0.2.11 key plaintext cppm-lab-key vrf mgmt

Goes withaaa group server radius <WORD>show radius-server

aaa group server radius <WORD>

A group of RADIUS servers

Port-access points at a group, not a server. Servers are tried in priority order; entered without a priority they number themselves in the order you add them.

In every release here, 10.15 to 10.18.

Changed: 10.16 added server <ip> priority <n>; 10.15 has no priority in a group.
Changed: 10.18 added load-balancing-mode (round-robin or priority-based) in the group.
try it in the sandbox
aaa group server radius CLEARPASSserver 192.0.2.10server 192.0.2.11aaa group server radius CLEARPASSserver 192.0.2.11 priority 1

Goes withradius-server host <A.B.C.D> key plaintext <WORD>

show radius-server

Servers and whether they answer

Each server with its ports and VRF. A star in front means the switch has marked it unreachable.

In every release here, 10.15 to 10.18.

try it in the sandbox
show radius-servershow radius-server detail

Goes withshow radius-server statistics authentication

show radius-server statistics authentication

Requests, accepts, rejects, timeouts

Counters per server. Timeouts climbing with no accepts usually means the shared secret. show radius-server statistics on its own is incomplete on 10.18.

In every release here, 10.15 to 10.18.

try it in the sandbox
show radius-server statistics authenticationshow radius-server statistics authentication | include Timeouts
radius dyn-authorization enable

Listen for CoA

Lets ClearPass change or end a session after the fact (RFC 5176). On 10.18 that is two pieces: enable it, and name each server allowed to send with radius dyn-authorization client. Without the client line requests are dropped and counted as invalid client addresses.

In every release here, 10.15 to 10.18.

try it in the sandbox
radius dyn-authorization enableradius dyn-authorization client 192.0.2.10 secret-key plaintext cppm-lab-key

Goes withshow radius dyn-authorization

show radius dyn-authorization

CoA counters and clients

Whether dynamic authorization is on, the port (3799), the invalid-address counters, and per client the CoA and disconnect requests, ACKs and NAKs.

In every release here, 10.15 to 10.18.

try it in the sandbox
show radius dyn-authorization

Port access

One port, a phone and a PC: multi-domain authentication PC plugged into the phone IP phone no supplicant Switch 1/1/6 auth-mode multi-domain 1 ClearPass names the roles VOICE DOMAIN Phone MAC auth, or an LLDP device profile 3 Accept, role VOICE device-traffic-class voice 2 The voice device VLAN 30 tagged, 10 native DATA DOMAIN PC 802.1X, straight through the phone Accept, role EMPLOYEE vlan access 10 The data device VLAN 10 untagged show port-access clients lists both on 1/1/6. show vlan counts 1/1/6 in 10 and in 30. 1 A port takes one client by default. The PC is refused until the port is multi-domain or client-limit 2. 2 The voice device is whoever holds a voice-class role. Without it the phone is one more data client. 3 LLDP from a phone that has not authenticated is dropped, so a device profile never sees it without allow-lldp-bpdu. A client that fails authentication does not use up a place; only the ones that got in count.
Multi-domain authentication: a phone and the PC behind it, each with its own role.
  • Multi-domain is one voice device plus one data device. More PCs behind a phone: raise client-limit multi-domain.
  • The phone's role carries device-traffic-class voice, a native data VLAN and the voice VLAN tagged.
  • Test the failure path before users do: take ClearPass away and read what the phone and the PC get.
aaa authentication port-access dot1x authenticator

802.1X, switch-wide

Global switch for 802.1X plus the RADIUS group it uses. It needs enable here and on each port: either one off and nothing authenticates.

In every release here, 10.15 to 10.18.

try it in the sandbox
aaa authentication port-access dot1x authenticatorradius server-group CLEARPASSenableinterface 1/1/1-1/1/8aaa authentication port-access dot1x authenticatorenable

Goes withaaa authentication port-access mac-authshow port-access clients

aaa authentication port-access mac-auth

MAC authentication, switch-wide

The same pattern as 802.1X: a global block with the group and enable, and enable per port. The switch sends the MAC as username and password, 00005e005305 style by default.

In every release here, 10.15 to 10.18.

try it in the sandbox
aaa authentication port-access mac-authradius server-group CLEARPASSenableinterface 1/1/5aaa authentication port-access mac-authenable
aaa authentication port-access client-limit <1-256>

How many clients a port takes

One by default. A PC behind a phone needs two, or a multi-domain port. Only clients that got in take a place.

In every release here, 10.15 to 10.18.

Changed: 10.18 added client-limit device-mode <n> on the port and in a role.
try it in the sandbox
interface 1/1/3aaa authentication port-access client-limit 2
aaa authentication port-access auth-precedence <order>

Which method goes first

dot1x then mac-auth is the default. A device with no supplicant waits out the 802.1X timeout before MAC auth starts; mac-auth first is faster for printers and slower for laptops.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/5aaa authentication port-access auth-precedence mac-auth dot1xinterface 1/1/1aaa authentication port-access auth-precedence dot1x mac-auth
aaa authentication port-access critical-role <WORD>

A role when RADIUS is down

If every RADIUS server times out, clients get this role instead of nothing. reject-role is the same for a reject.

In every release here, 10.15 to 10.18.

Habit: Decide what a building does when ClearPass is unreachable before it happens. Critical role is that decision written down.
try it in the sandbox
interface 1/1/1aaa authentication port-access critical-role QUARANTINEinterface 1/1/1aaa authentication port-access reject-role GUEST
aaa authentication port-access auth-mode multi-domain

A phone and a PC on one port

One voice device and one data device (client-limit multi-domain raises the data count). The voice device is whoever holds a role with device-traffic-class voice.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/6aaa authentication port-access auth-mode multi-domaininterface 1/1/6aaa authentication port-access client-limit multi-domain 2

Goes withdevice-traffic-class voiceaaa authentication port-access allow-lldp-bpdu

aaa authentication port-access allow-lldp-bpdu

Hear LLDP before authentication

A port-access port drops LLDP from a client that has not authenticated. A phone that never authenticates is then invisible to LLDP, its device profile never matches, and it gets no voice VLAN. This lets LLDP through. Found the hard way on the lab switch on 2026-09-28.

In every release here, 10.15 to 10.18.

Changed: 10.17 added aaa authentication port-access lldp-loop-guard enable beside it.
try it in the sandbox
interface 1/1/6aaa authentication port-access allow-lldp-bpdu

Goes withdebug <portaccess|radius|lldp> <what>

port-access role <WORD>

A local user role

What a client gets once it is in: an access VLAN, or a native VLAN and a tagged list, and more on 10.18. RADIUS names the role; the switch must have it or the client fails authorization.

In every release here, 10.15 to 10.18.

Changed: 10.18 added speed, voice-vlan, stp-bpdu-guard, rate-limits, toggle-link and client-limit device-mode to a role.
try it in the sandbox
port-access role EMPLOYEEvlan access 10port-access role AP-TRUNKvlan trunk native 99vlan trunk allowed 10,20,99

Goes withshow port-access role

device-traffic-class voice

This role is the voice device

On a multi-domain port the client holding this role is the voice device. Pair it with a native data VLAN and the voice VLAN tagged.

In every release here, 10.15 to 10.18.

try it in the sandbox
port-access role VOICEdevice-traffic-class voicevlan trunk native 10vlan trunk allowed 30
show port-access clients

Who is on and how

One line per client: port, name, role, VLAN, and four flags: how it got in (1x, ma, dp), mode (c, d, m), device type (d, v) and status (s, f, p). --|c|-|f is a failure. Add detail for the history, interface, mac or role to filter.

In every release here, 10.15 to 10.18.

Habit: Read Auth History in the detail view bottom to top: it is the order things happened.
try it in the sandbox
show port-access clientsshow port-access clients interface 1/1/6 detailshow port-access clients onboarding-method device-profile
show aaa authentication port-access interface all client-status

Client status, compact

The authentication and authorization blocks for every client, without VLAN and MACsec detail.

In every release here, 10.15 to 10.18.

try it in the sandbox
show aaa authentication port-access interface all client-statusshow aaa authentication port-access interface 1/1/1 client-status
show port-access role

The roles and what they carry

Each local role: VLANs, device type, gateway zone. show port-access role name X for one.

In every release here, 10.15 to 10.18.

try it in the sandbox
show port-access roleshow port-access role name VOICE
port-access reauthenticate interface <IFNAME>

Make clients authenticate again

10.18 has no clear port-access clients. To start clients over: reauthenticate a port, or log one off by MAC, port or role.

In every release here, 10.15 to 10.18.

try it in the sandbox
port-access reauthenticate interface 1/1/1port-access log-off client mac 00:00:5e:00:53:01port-access log-off client role GUEST
port-access fallback-role <WORD>

A role for whatever is on the port

The role a client gets when nothing else gives it one. With no authentication on the port that is everything plugged in: with a gateway zone in the role, that is port-based tunnelling.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface 1/1/4port-access fallback-role PBT-IOT

Tunnelling

gateway-zone zone <WORD> gateway-role <WORD>

Tunnel this role's traffic

Clients in this role are tunnelled to the gateway cluster of the zone, where the gateway role applies. That is user-based tunnelling when RADIUS assigns the role, port-based when a port's fallback role does.

In every release here, 10.15 to 10.18.

try it in the sandbox
port-access role TUNNEL-EMPLOYEEgateway-zone zone CAMPUS gateway-role authenticatedport-access role PBT-IOTgateway-zone zone CAMPUS gateway-role iot

Goes withubt zone <WORD> vrf <WORD>port-access fallback-role <WORD>

ubt-client-vlan <1-4094>

The VLAN tunnelled clients use

In local-vlan mode (what show ubt reports) this is the reserved VLAN all tunnelled client traffic uses to reach the gateway. Create it first and use it for nothing else, as HPE's guide says.

In every release here, 10.15 to 10.18.

try it in the sandbox
vlan 666name UBT-TRANSPORTexitubt-client-vlan 666

Goes withubt zone <WORD> vrf <WORD>

ubt zone <WORD> vrf <WORD>

Where the tunnels go

A zone names the gateway cluster: primary and backup controller addresses, reached in a VRF, and enable. show ubt says whether it is up.

In every release here, 10.15 to 10.18.

Changed: 10.16 took IPv6 controller addresses.
Where the sandbox pretends: The gateway is a bench device in the sandbox; a zone is up when the switch can reach it.
try it in the sandbox
ubt zone CAMPUS vrf defaultprimary-controller ip 192.0.2.50backup-controller ip 192.0.2.51enable
show ubt

Zone state

Each zone's controllers, VLAN, admin and operational state. brief is one line per zone; users all lists who is tunnelled.

In every release here, 10.15 to 10.18.

try it in the sandbox
show ubtshow ubt briefshow ubt users all

Device profiles

port-access lldp-group <WORD>

Recognise a device by its LLDP

Ordered match and ignore rules; the first rule a neighbour hits decides. sysname is exact, sys-desc matches if the description contains the word (proved on the lab switch), vendor-oui plus type matches a TLV. Rules without seq number themselves 10, 20, 30.

In every release here, 10.15 to 10.18.

Changed: 10.18 added match chassis-id. sys-desc, sysname and vendor-oui are there from 10.15.
try it in the sandbox
port-access lldp-group APSmatch sys-desc AP-515port-access lldp-group LLDP-MED-ENDPOINTSseq 10 match vendor-oui 0012bb type 1port-access lldp-group COREmatch sysname core1

Goes withport-access device-profile <WORD>

port-access device-profile <WORD>

Give a recognised device a role

Ties an LLDP group to a role, then enable. Works on a port with no port-access at all; on a port-access port it applies when 802.1X and MAC auth do not get the device in. The client shows as dp.

In every release here, 10.15 to 10.18.

try it in the sandbox
port-access device-profile APSassociate lldp-group APSassociate role AP-TRUNKenable

Goes withshow port-access device-profile

show port-access device-profile

Profiles and who matched

The profiles and their state. interface all lists each matched neighbour with its profile, group, role and whether it applied.

In every release here, 10.15 to 10.18.

try it in the sandbox
show port-access device-profileshow port-access device-profile interface all

Routing

interface vlan <1-4094>

An address on a VLAN

A switch virtual interface: the switch's own address in that VLAN, up only when a port in the VLAN is up.

In every release here, 10.15 to 10.18.

try it in the sandbox
interface vlan 10ip address 192.0.2.1/24
ip route <A.B.C.D/M> <A.B.C.D>

A static route

Prefix and next hop. The default route is 0.0.0.0/0.

In every release here, 10.15 to 10.18.

try it in the sandbox
ip route 0.0.0.0/0 203.0.113.1ip route 198.51.100.0/24 203.0.113.1
router ospf <1-63>

Start OSPF

The process, its router-id and areas. Interfaces join with ip ospf <process> area <area>. Both ends of a link must agree on the area.

In every release here, 10.15 to 10.18.

try it in the sandbox
router ospf 1router-id 203.0.113.2area 0.0.0.0exitinterface vlan 100ip ospf 1 area 0.0.0.0
show ip route

The routing table

Connected (C), local (L), static (S) and OSPF (O) routes with next hop and interface.

In every release here, 10.15 to 10.18.

try it in the sandbox
show ip routeshow ip ospf neighborsping 198.51.100.10

Stacking

vsf member <1-8>

Stack another switch

Virtual Switching Framework: pre-provision a member by part number and name the ports that form its stack links. A member's links are its own ports, 2/1/x for member 2. Member 1 is the switch you are on. vsf secondary-member picks the standby; without it there is none.

Not in the Switch Simulator's command set for 10.15 to 10.18. Syntax from HPE's guides.

Where the sandbox pretends: The Switch Simulator has no VSF, so nothing here was checked against a capture. The syntax is from HPE's VSF guide; the sandbox never cables a second switch.
try it in the sandbox
vsf member 2type jl725alink 1 2/1/27exitvsf secondary-member 2vsf member 1link 1 1/1/16

Goes withshow vsf

show vsf

The stack and its members

Each member with its role (conductor, standby, member), status and part number. show vsf link lists the stack links and whether they are up.

Not in the Switch Simulator's command set for 10.15 to 10.18. Syntax from HPE's guides.

Where the sandbox pretends: The layout is the sandbox's own: the Switch Simulator has no VSF to capture. A provisioned member shows Not Present because no second switch is ever cabled.
try it in the sandbox
show vsfshow vsf link

Diagnostics

debug <portaccess|radius|lldp> <what>

Log what port-access does

Writes port-access events to the debug buffer, the default destination. debug radius all and debug lldp event add those modules. show debug lists what is on; no debug all turns it off.

In every release here, 10.15 to 10.18.

Habit: Clear the buffer, turn debug on, reproduce once, read, turn it off. A busy switch fills the buffer in seconds.
try it in the sandbox
debug portaccess alldebug lldp eventshow debug buffer module portaccessshow debug buffer module lldp | include 1/1/6

Goes withshow debug buffer

show debug buffer

Read the debug log

Everything logged, oldest first. module portaccess, radius or lldp narrows it; a pipe narrows it further.

In every release here, 10.15 to 10.18.

Where the sandbox pretends: The sandbox logs the lines that tell a client's story, in the lab's format; the box logs far more.
try it in the sandbox
show debug buffershow debug buffer module portaccess | include DEVICEPROFILEclear debug buffer
diag cable-diagnostic test <PORT>

Test the cable from the switch

A TDR test on a copper port: per pair good, open or short, the cable length or the distance to the fault. It drops the link while it runs and asks first. show prints the result; clear forgets it.

In every release here, 10.15 to 10.18.

Changed: Introduced in 10.11 (HPE's diagnostics guide).
Where the sandbox pretends: Faked hardware. The Switch Simulator has no PHY and refuses the command; the sandbox builds the result from the lab's description of the cable, in the guide's layout.
try it in the sandbox
diag cable-diagnostic test 1/1/7diag cable-diagnostic show 1/1/7diag cable-diagnostic clear 1/1/7

REST

sim rest post /rest/v10.18/login

The same switch through REST

sim rest is a laptop calling the REST API: log in, then GET, POST, PATCH or DELETE under /rest/v10.18, and POST /rest/v10.18/cli for AnyCLI, which runs only the exact commands GET /rest/v10.18/cli/commands lists. Each answer names its CLI twin.

A sandbox command, not a switch command.

Where the sandbox pretends: A sandbox command, not a switch command: the shapes are the lab switch's REST answers from 2026-09-28.
try it in the sandbox
sim rest post /rest/v10.18/loginsim rest get /rest/v10.18/system/vlans?depth=2&attributes=id,namesim rest post /rest/v10.18/cli {"cmd":"show vlan"}

Sandbox

sim connect <DEV>

Plug a device in

The sandbox talking, not the switch. sim connect and sim disconnect plug bench devices in and out, sim coa has the fake ClearPass send a change of authorization, sim release picks the AOS-CX release, sim status shows what is plugged in.

A sandbox command, not a switch command.

try it in the sandbox
sim statussim connect phonesim release 10.16

Nothing matches that. Try a shorter word.