A real-life situation
A new router arrives in a box. It has no IP address, so you can't reach it over the network yet. You plug a console cable from your laptop into its console port, open a terminal program, press Enter, and a prompt appears: Router>. Everything you do on a Cisco device starts from this prompt. This lesson shows you how to move around in it without getting lost.
Two ways in: console and remote access
Cisco IOS (Internetwork Operating System) is the software on Cisco routers and switches. Newer devices run IOS XE, which feels the same at the command line. You reach its CLI (command-line interface) in one of two ways:
- Console port: a direct cable from your laptop to the device (an RJ-45 "rollover" cable with a USB-to-serial adapter, or a USB console cable). It works even when the device has no IP address at all. The usual terminal settings are 9600 baud, 8 data bits, no parity, 1 stop bit, no flow control.
- Remote access over the network with SSH (encrypted, use this) or Telnet (plain text, avoid it). The device needs an IP address, and its VTY lines (virtual terminal lines, the "ports" that remote sessions land on) must be set up. See SSH and Telnet for how the protocols work.
- 1. Day one: the console cable. A direct serial connection. No IP address or network needed, so it always works.
- 2. Later: SSH over the LAN. Once R1 has an address and its VTY lines allow SSH, the admin PC connects across SW1.
- 3. Switches too. SW1 is managed through its own IP address on a VLAN interface (an SVI).
What the CLI modes are
The CLI is split into modes. Each mode allows a different set of commands, and the prompt always tells you which mode you are in. That is the most useful habit to build: read the prompt before you type.
R1>enable▼ disableR1#configure terminal▼ end or Ctrl+ZR1(config)#interface … / line … / router …▼ exitR1(config-if)#R1(config-line)#R1(config-router)#| Mode | Prompt | Enter with | Used for |
|---|---|---|---|
| User EXEC | R1> | Log in | Basic checks: ping, traceroute, some show commands |
| Privileged EXEC | R1# | enable | All show and debug commands, copy, reload |
| Global configuration | R1(config)# | configure terminal | Settings that apply to the whole device |
| Interface configuration | R1(config-if)# | interface g0/1 | Settings for one interface |
| Line configuration | R1(config-line)# | line console 0 / line vty 0 4 | Console and remote login settings |
| Router configuration | R1(config-router)# | router ospf 1 | A routing protocol |
Why it works that way
The modes are a simple safety system. Most people who log in only need to look, so user EXEC lets them look a little and change nothing. Commands that can disrupt the network (reloading the device, erasing its configuration, changing a route) sit behind enable, which can be protected with its own password. Configuration is split again so that an interface command can only land on the interface you chose. You can't accidentally give the whole router an IP address; you must first pick an interface.
Behind the scenes, user EXEC is privilege level 1 and privileged EXEC is privilege level 15 (the highest). Levels 2 to 14 exist for custom roles but are rarely used.
How it works step by step
- You connect (console or SSH) and, if a password is set, log in. You land in user EXEC:
R1>. enableasks for the enable password if one is set, then gives you privileged EXEC:R1#.configure terminaltakes you to global configuration:R1(config)#. Every command you enter takes effect immediately in the running configuration. There is no "apply" button.- A command such as
interface GigabitEthernet0/1opens a sub-mode:R1(config-if)#. exitgoes back one level.endor Ctrl+Z jumps straight back to privileged EXEC.
💡 Typing a global command while in a sub-mode usually works: IOS drops you back to global configuration and runs it. That is handy, but it also means a mistyped interface command can quietly land in the wrong place. Keep an eye on the prompt.
How to use it on Cisco IOS
Moving between modes
enable
configure terminal
interface GigabitEthernet0/1
description LAN to SW1 Gi1/0/24
exit
line console 0
logging synchronous
endA full walk down and back up: from user EXEC to interface mode, back to global config, into line mode, then straight back to privileged EXEC.
Getting help
?on its own lists every command available in the current mode.cl?(no space) lists commands that start with "cl".show ip ?(with a space) lists the next words that can follow.- Tab completes a partly typed word, as long as only one command matches.
Shortcuts worth knowing
| Key or command | Does |
|---|---|
| Up arrow / Ctrl+P | Previous command in the history buffer |
| Down arrow / Ctrl+N | Next command in the history buffer |
| Ctrl+A / Ctrl+E | Jump to the start / end of the line |
| Ctrl+Z | Leave configuration mode (same as end) |
| Ctrl+Shift+6 | Break out of a running ping, traceroute or DNS lookup |
Space / Enter at --More-- | Next page / next line of long output; any other key stops it |
do <command> | Run an EXEC command (such as do show ip interface brief) from any config mode |
terminal length 0 | Turn off --More-- paging for this session |
You can also shorten any word to the fewest letters that make it unique: conf t, sh ip int br, int g0/1. You will see these abbreviations everywhere, including in exam questions.
Two settings that make life easier
configure terminal
no ip domain-lookup
line console 0
logging synchronous
exec-timeout 15 0
endno ip domain-lookup stops the DNS lookup after a typo. logging synchronous reprints your half-typed line after a log message interrupts it. exec-timeout logs an idle session out after 15 minutes.
How to verify where you are
The prompt is the first check. When in doubt, two commands confirm your level and what you have typed recently.
R1#show privilege Current privilege level is 15
R1#show history enable configure terminal show ip interface brief show privilege show history
terminal history size.R1#show ip ? access-lists List IP access lists arp IP ARP table dhcp Show items in the DHCP database interface IP interface status and configuration ospf OSPF information protocols IP routing protocol process parameters and statistics route IP routing table ...
show ip, each with a one-line description. The real list is much longer.Reading error messages
IOS has only a few error messages, and each points to a different mistake.
R1#show ip interface brif ^ % Invalid input detected at '^' marker.
^ points at the first character IOS could not accept. Here "brif" is a typo. You also get this error when the command is fine but you are in the wrong mode, for example configure terminal typed at the R1> prompt.R1#co % Ambiguous command: "co"
configure, connect or copy. Type more letters, or co? to see the choices.R1#show ip % Incomplete command.
? to see what can come next.R1#shwo Translating "shwo"...domain server (255.255.255.255) % Unknown command or computer name, or unable to find computer address
no ip domain-lookup so it doesn't happen again.What goes wrong and how to troubleshoot it
- Nothing appears on the console. Check the terminal settings (9600 8N1, no flow control), the COM port your adapter uses, and that the cable is in the console port, not the AUX or an Ethernet port. Press Enter a few times.
- Garbage characters on the console. The speed is wrong. Try 9600 first, then 115200 (some newer platforms use it).
- A command is rejected that you know is correct. Look at the prompt. You are probably in the wrong mode, such as trying
show running-configfrom user EXEC orip addressin global configuration. - Log messages keep breaking your typing. Add
logging synchronousunder the line you use. - SSH or Telnet is refused. The VTY lines may not have a password or login method, or SSH isn't set up. The Initial switch and router setup lesson covers the line settings.
Common mistakes
- Expecting changes to need saving before they work. They take effect the moment you press Enter; saving only makes them survive a reload.
- Typing
showcommands in configuration mode withoutdo. - Using
exitrepeatedly to leave configuration mode, whenendgets you there in one step. - Confusing
cl?(commands starting with "cl") withcl ?(what follows the command "cl", which is ambiguous).
💡 Exam tip: expect questions that show a prompt and ask which mode it is, or which command moves you between two modes. Know the prompts by heart: >, #, (config)#, (config-if)#, (config-line)#, (config-router)#. Know that end and Ctrl+Z return to privileged EXEC, and that do runs EXEC commands from config mode. Simulation questions also accept abbreviations, so practise them.
Key takeaways
- Console works without any IP address; SSH needs an address and configured VTY lines.
- User EXEC (
>) →enable→ privileged EXEC (#) →configure terminal→ global config → sub-modes. exitgoes up one level;endor Ctrl+Z goes straight to privileged EXEC.?, Tab and abbreviations make the CLI fast; the caret in an error shows where the problem is.- Configuration changes apply immediately.
Check yourself
The prompt shows R1(config-if)#. You type end. What prompt do you see next?
At the R1> prompt you type configure terminal and get '% Invalid input detected'. Why?
You type 'co' and press Enter. IOS replies '% Ambiguous command'. What does that mean?
You are in interface configuration mode and want to check the interface status without leaving. What do you type?
You mistype a single word in privileged EXEC and the router hangs for several seconds with 'Translating...'. What prevents this?