Routelearn.net
Course menu

Course 1: Cisco IOSLesson 1.1 (1 of 5 in this course)1 of 91 in the CCNA series

CLI modes and navigation

Console and SSH access, user and privileged EXEC, configuration modes, help, shortcuts and reading error messages.

Beginner · 10 min read

Cisco IOS CLI (command-line interface) modes are the separate command levels of the IOS command line, mainly user EXEC, privileged EXEC, global configuration and sub-configuration modes such as interface mode. Each mode allows a different set of commands, and the prompt shows which mode is active.

In simple terms: The router's command line has different “rooms.” Some only let you look around, others let you change settings, and the prompt always tells you which room you're in.

A real-life situation

A new router arrives in a box. It has no IP address, so you can't reach it over the network yet. You plug a console cable from your laptop into its console port, open a terminal program, press Enter, and a prompt appears: Router>. Everything you do on a Cisco device starts from this prompt. This lesson shows you how to move around in it without getting lost.

Two ways in: console and remote access

Cisco IOS (Internetwork Operating System) is the software on Cisco routers and switches. Newer devices run IOS XE, which feels the same at the command line. You reach its CLI (command-line interface) in one of two ways:

  • Console port: a direct cable from your laptop to the device (an RJ-45 "rollover" cable with a USB-to-serial adapter, or a USB console cable). It works even when the device has no IP address at all. The usual terminal settings are 9600 baud, 8 data bits, no parity, 1 stop bit, no flow control.
  • Remote access over the network with SSH (encrypted, use this) or Telnet (plain text, avoid it). The device needs an IP address, and its VTY lines (virtual terminal lines, the "ports" that remote sessions land on) must be set up. See SSH and Telnet for how the protocols work.
consoleGi0/1Gi1/0/24Gi1/0/1Gi0/0Admin laptopconsole cableR1Gi0/1 192.168.10.1SW1Vlan1 192.168.10.2Admin PC192.168.10.10ISP198.51.100.1
  1. 1. Day one: the console cable. A direct serial connection. No IP address or network needed, so it always works.
  2. 2. Later: SSH over the LAN. Once R1 has an address and its VTY lines allow SSH, the admin PC connects across SW1.
  3. 3. Switches too. SW1 is managed through its own IP address on a VLAN interface (an SVI).

What the CLI modes are

The CLI is split into modes. Each mode allows a different set of commands, and the prompt always tells you which mode you are in. That is the most useful habit to build: read the prompt before you type.

Read from the top: each command moves you one mode deeper
User EXECR1>
Look only: ping, traceroute, a few show commands.
▲ enable▼ disable
Privileged EXECR1#
Every show command, debug, copy, reload, clear.
▲ configure terminal▼ end or Ctrl+Z
Global configurationR1(config)#
Settings for the whole device: hostname, routes, passwords.
▲ interface … / line … / router …▼ exit
Interface config
R1(config-if)#
via interface g0/1
Line config
R1(config-line)#
via line vty 0 4
Routing config
R1(config-router)#
via router ospf 1
exit goes back one level; end (or Ctrl+Z) jumps from any configuration mode straight to privileged EXEC.
ModePromptEnter withUsed for
User EXECR1>Log inBasic checks: ping, traceroute, some show commands
Privileged EXECR1#enableAll show and debug commands, copy, reload
Global configurationR1(config)#configure terminalSettings that apply to the whole device
Interface configurationR1(config-if)#interface g0/1Settings for one interface
Line configurationR1(config-line)#line console 0 / line vty 0 4Console and remote login settings
Router configurationR1(config-router)#router ospf 1A routing protocol

Why it works that way

The modes are a simple safety system. Most people who log in only need to look, so user EXEC lets them look a little and change nothing. Commands that can disrupt the network (reloading the device, erasing its configuration, changing a route) sit behind enable, which can be protected with its own password. Configuration is split again so that an interface command can only land on the interface you chose. You can't accidentally give the whole router an IP address; you must first pick an interface.

Behind the scenes, user EXEC is privilege level 1 and privileged EXEC is privilege level 15 (the highest). Levels 2 to 14 exist for custom roles but are rarely used.

How it works step by step

  1. You connect (console or SSH) and, if a password is set, log in. You land in user EXEC: R1>.
  2. enable asks for the enable password if one is set, then gives you privileged EXEC: R1#.
  3. configure terminal takes you to global configuration: R1(config)#. Every command you enter takes effect immediately in the running configuration. There is no "apply" button.
  4. A command such as interface GigabitEthernet0/1 opens a sub-mode: R1(config-if)#.
  5. exit goes back one level. end or Ctrl+Z jumps straight back to privileged EXEC.

💡 Typing a global command while in a sub-mode usually works: IOS drops you back to global configuration and runs it. That is handy, but it also means a mistyped interface command can quietly land in the wrong place. Keep an eye on the prompt.

How to use it on Cisco IOS

Moving between modes

enable configure terminal interface GigabitEthernet0/1 description LAN to SW1 Gi1/0/24 exit line console 0 logging synchronous end

A full walk down and back up: from user EXEC to interface mode, back to global config, into line mode, then straight back to privileged EXEC.

Getting help

  • ? on its own lists every command available in the current mode.
  • cl? (no space) lists commands that start with "cl".
  • show ip ? (with a space) lists the next words that can follow.
  • Tab completes a partly typed word, as long as only one command matches.

Shortcuts worth knowing

Key or commandDoes
Up arrow / Ctrl+PPrevious command in the history buffer
Down arrow / Ctrl+NNext command in the history buffer
Ctrl+A / Ctrl+EJump to the start / end of the line
Ctrl+ZLeave configuration mode (same as end)
Ctrl+Shift+6Break out of a running ping, traceroute or DNS lookup
Space / Enter at --More--Next page / next line of long output; any other key stops it
do <command>Run an EXEC command (such as do show ip interface brief) from any config mode
terminal length 0Turn off --More-- paging for this session

You can also shorten any word to the fewest letters that make it unique: conf t, sh ip int br, int g0/1. You will see these abbreviations everywhere, including in exam questions.

Two settings that make life easier

configure terminal no ip domain-lookup line console 0 logging synchronous exec-timeout 15 0 end

no ip domain-lookup stops the DNS lookup after a typo. logging synchronous reprints your half-typed line after a log message interrupts it. exec-timeout logs an idle session out after 15 minutes.

How to verify where you are

The prompt is the first check. When in doubt, two commands confirm your level and what you have typed recently.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show privilege
Current privilege level is 15
Level 15 is privileged EXEC. In user EXEC the same command reports level 1.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show history
  enable
  configure terminal
  show ip interface brief
  show privilege
  show history
The last commands typed in this session (10 by default). Change the size with terminal history size.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip ?
  access-lists     List IP access lists
  arp              IP ARP table
  dhcp             Show items in the DHCP database
  interface        IP interface status and configuration
  ospf             OSPF information
  protocols        IP routing protocol process parameters and statistics
  route            IP routing table
  ...
Context help: the words that can follow show ip, each with a one-line description. The real list is much longer.

Reading error messages

IOS has only a few error messages, and each points to a different mistake.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip interface brif
                     ^
% Invalid input detected at '^' marker.
The caret ^ points at the first character IOS could not accept. Here "brif" is a typo. You also get this error when the command is fine but you are in the wrong mode, for example configure terminal typed at the R1> prompt.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#co
% Ambiguous command:  "co"
Too few letters: "co" could be configure, connect or copy. Type more letters, or co? to see the choices.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip
% Incomplete command.
The command needs more words. Add a space and ? to see what can come next.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#shwo
Translating "shwo"...domain server (255.255.255.255)
% Unknown command or computer name, or unable to find computer address
A single unknown word in EXEC mode is treated as a host name to Telnet to. IOS broadcasts a DNS query and waits. Press Ctrl+Shift+6 to cancel, and configure no ip domain-lookup so it doesn't happen again.

What goes wrong and how to troubleshoot it

  • Nothing appears on the console. Check the terminal settings (9600 8N1, no flow control), the COM port your adapter uses, and that the cable is in the console port, not the AUX or an Ethernet port. Press Enter a few times.
  • Garbage characters on the console. The speed is wrong. Try 9600 first, then 115200 (some newer platforms use it).
  • A command is rejected that you know is correct. Look at the prompt. You are probably in the wrong mode, such as trying show running-config from user EXEC or ip address in global configuration.
  • Log messages keep breaking your typing. Add logging synchronous under the line you use.
  • SSH or Telnet is refused. The VTY lines may not have a password or login method, or SSH isn't set up. The Initial switch and router setup lesson covers the line settings.

Common mistakes

  • Expecting changes to need saving before they work. They take effect the moment you press Enter; saving only makes them survive a reload.
  • Typing show commands in configuration mode without do.
  • Using exit repeatedly to leave configuration mode, when end gets you there in one step.
  • Confusing cl? (commands starting with "cl") with cl ? (what follows the command "cl", which is ambiguous).

💡 Exam tip: expect questions that show a prompt and ask which mode it is, or which command moves you between two modes. Know the prompts by heart: >, #, (config)#, (config-if)#, (config-line)#, (config-router)#. Know that end and Ctrl+Z return to privileged EXEC, and that do runs EXEC commands from config mode. Simulation questions also accept abbreviations, so practise them.

Key takeaways

  • Console works without any IP address; SSH needs an address and configured VTY lines.
  • User EXEC (>) → enable → privileged EXEC (#) → configure terminal → global config → sub-modes.
  • exit goes up one level; end or Ctrl+Z goes straight to privileged EXEC.
  • ?, Tab and abbreviations make the CLI fast; the caret in an error shows where the problem is.
  • Configuration changes apply immediately.

Check yourself

Predict · scenario 1

The prompt shows R1(config-if)#. You type end. What prompt do you see next?

Predict · scenario 2

At the R1> prompt you type configure terminal and get '% Invalid input detected'. Why?

Predict · scenario 3

You type 'co' and press Enter. IOS replies '% Ambiguous command'. What does that mean?

Predict · scenario 4

You are in interface configuration mode and want to check the interface status without leaving. What do you type?

Predict · scenario 5

You mistype a single word in privileged EXEC and the router hangs for several seconds with 'Translating...'. What prevents this?

FAQ

What is the difference between user EXEC and privileged EXEC mode?
User EXEC (the > prompt) is a look-but-don't-touch mode with a few basic commands such as ping and some show commands. Privileged EXEC (the # prompt) unlocks every show and debug command, plus commands that change the device's state, such as copy, reload and configure terminal. You move up with enable and back down with disable.
Why does my router freeze for a few seconds when I mistype a command?
In EXEC mode, IOS treats an unknown single word as the name of a host you want to Telnet to, and tries to look it up with DNS. With no DNS server configured it waits for the lookup to time out. Configure no ip domain-lookup to stop it, or press Ctrl+Shift+6 to cancel the lookup.
Do I have to type full Cisco commands?
No. IOS accepts any abbreviation that matches only one command at that point, so conf t means configure terminal and sh ip int br means show ip interface brief. If the letters match more than one command you get an Ambiguous command error; type a few more letters.
How do I run a show command while I am in configuration mode?
Put do in front of it, for example do show ip interface brief. The do keyword runs a privileged EXEC command from any configuration mode without leaving that mode.