welcome: please sign in
location: SwitchConfiguration

Moved to: https://osmium.morningside.edu/confluence/x/JgIRCw


This document may be used as a quick-reference for CLI switch configurations.


Console Access
With a console cable connected to USB or serial port on a PC, use a terminal emulator to connect (such as PuTTY or HyperTERM)
Remote access (Telnet/SSH)

If the switch is already configured and networked, one may telnet (or preferably SSH) into it if it is so configured. Ex: telnet


A properly configured switch will only allow remote connections from management addresses. See the ip authorized-managers part of the templates section.

Term settings
No matter what terminal is chosen, the following settings must be employed to successfully connect:
  • Option


    Baud Rate






    Data bits


    Hardware Flow Control


    Software Flow Control


  • Actually connecting
    Once the terminal is configured and plugged in, press return ("enter") twice to initialize the connection.

    Basic Configuration Steps

    1. Connect to the device
    2. Enter configuration context with configure terminal. (Remember, any command may be abbreviated)

    3. Set a valid and descriptive hostname for the switch with hostname <hostname>

    4. Set the primary switch IP Address from the VLAN 101 context:
      • vlan 101
        name Net_Mgmt
        ip address 192.168.1.n
    5. Physically label the switch with the IP address and hostname.
    6. Set a valid default gateway with ip default-gateway

    7. Set ports with the proper vlan tagging for Net_Mgmt vlan with the vlan 100 tagged <i>port-list</i> or vlan 101 untagged <i>port-list</i> commands.

    8. Save your changes: write memory

    9. logout, you're done!


    From the command line, at any point, TAB completion is available. Pressing the TAB key will show possible completions for the command you may have partially typed. If the command is unique, it will be completed for you. If there are multiple possibilities, they will be displayed.

    Additionally, pressing the ?-key at any point will display contextual help for a given command.

    For more help, ending a command with help will display a more verbose description of that command.

    Upgrading Switch Firmware



    First, a copy of the latest edition of the firmware must be obtained from the HP Support website. Search the switch model and take a look at the versions of software under "General Availability."

    Download and extract the ZIP file. The *.swi file must be moved into the directory shared by tftp.

    Once the firmware is downloaded, compare the version to that running on the switch using the show flash command on the switch.


    I see from the support site that the latest version of the firmware is J.15.09 released on 22-Oct-2013.

    Suppose the IP of the tftp server is The firmware has been extracted into the tftp server directory as J_15_09_0014.swi.

    From the console, it may be transfered into primary flash:

    After copying, verify the flash versions and use the boot command to reboot the switch into the primary flash.

    Once the device has rebooted, repeat the procedure to copy the new image into the secondary flash:

    ProCurve Switch 2520G-8-PoE(config)# copy tftp flash J_15_09_0014.swi secondary 
    The Secondary OS Image will be deleted, continue [y/n]?  y
    Validating and Writing System Software to FLASH...

    The switch software is now up to date.

    Standard Switch Configuration

    --meyersh 19:40, 15 July 2009 (UTC)

    General Configuration stuff

    hostname "<Switch Hostname>" 
    snmp-server location "<Description of Switch Location>" 
    snmp-server contact "Shaun Meyer" 
    logging facility local4
    timesync sntp
    sntp unicast
    sntp server priority 1
    time timezone -300
    ip authorized-managers access manager
    ip authorized-managers access manager
    ip authorized-managers access manager
    ip authorized-managers access manager
    ip default-gateway
    snmp-server community "public" unrestricted
    snmp-server community "feeblexxx" operator
    snmp-server host community "public"
    vlan 101
       name "Net_Mgmt"
       no ip address
    password manager
    write memory


    spanning-tree force-version RSTP-operation

    Loop Protect

    Ensure that loop-protect is enabled on edge ports.

    loop-protect 1-24

    IP Routing

    1. To enable IP routing, use the ip routing command. Now, all IP addresses on all VLANs on the switch (now router) will be routed.

    2. VLANs get an IP address by the ip-address command:

      vlan xxx ip-address 192.168.x.y/24

    3. A default route must be added.

      ip route <dest ip>

    4. A DHCP helper address may be needed on the vlan.

      vlan xxx ip helper-address

    5. A route back to the router (from the default gateway) must be created on the default gateway.

      ip route 192.168.x.0/24 <router ip>

    SwitchConfiguration (last edited 2018-04-10 15:29:23 by meyersh)