A real-life situation
You spend an hour setting up R1. Everything works. That night a power cut reboots the router, and in the morning it is back to Router> with no addresses and no passwords. Nothing was broken: the configuration was simply never saved. Knowing where IOS keeps its configuration, and when it reads it, prevents this mistake.
What running-config and startup-config are
A Cisco device has two configurations at any time:
- running-config: the active configuration, held in RAM (the device's working memory). Every command you type in configuration mode changes it immediately.
- startup-config: the saved configuration, held in NVRAM (non-volatile RAM, memory that keeps its contents without power). The device reads it once, at boot.
The IOS software itself is a file in flash memory. Backups can live in flash too, or better, on a server somewhere else.
running-configstartup-configIOS image, backup filesoff-box backupscopy running-config startup-configSave your changes (same as write memory).reloadAt boot, startup-config is copied into RAM.copy running-config tftp:Back up the live configuration off the device.copy tftp: running-configMerge a saved file into the live configuration.copy running-config flash:backup.cfgKeep a local copy before a risky change.Why it works that way
Applying changes instantly while keeping a separate saved copy gives you a built-in safety net. If a change goes badly (for example you lock yourself out of a remote router), a reload brings back the last saved configuration. Engineers working on a distant site sometimes schedule a reload with reload in 10 before a risky change, and cancel it with reload cancel once they know the change worked.
How it works step by step: the boot sequence
If NVRAM is empty, IOS asks: Would you like to enter the initial configuration dialog? [yes/no]:. Answer no and configure the device yourself. The router also checks a setting called the configuration register. The normal value 0x2102 means "load startup-config". The value 0x2142 means "ignore it", which is how password recovery works.
How to manage it on Cisco IOS
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.
Look at the configurations
show running-config
show startup-config
show running-config | section interface
show running-config interface GigabitEthernet0/1Privileged EXEC. The filtered forms save scrolling through hundreds of lines.
Save
copy running-config startup-configCopies RAM to NVRAM. The order is always copy <from> <to>. write memory does the same.
Erase and start again
erase startup-config
delete flash:vlan.dat
reloadErase NVRAM (write erase is the same). On a switch, also delete the VLAN database. At the reload prompt, answer no to saving, or you write the old configuration back.
Back up and restore with TFTP
TFTP (Trivial File Transfer Protocol, UDP port 69) is a very simple file transfer protocol with no login and no encryption. It is still common for configuration backups inside a trusted network. FTP and SCP work the same way with ftp: and scp:. See FTP, SFTP and TFTP.
- 1. copy running-config tftp: R1 asks to write a file and sends the configuration in numbered blocks (UDP 69 to start the transfer).
- 2. Each block is acknowledged. The server confirms every block; IOS prints a ! for progress.
- 3. copy tftp: running-config Restoring pulls the file back and merges it into the running configuration.
copy running-config tftp:
copy startup-config flash:r1-backup.cfg
copy tftp: running-config
copy tftp: startup-configBack up off the box, back up locally, merge a file into the live config, or replace the saved config (it takes effect at the next reload).
How to verify it
R1#copy running-config startup-config Destination filename [startup-config]? Building configuration... [OK]
R1#show startup-config Using 1843 out of 262144 bytes ! version 15.9 service password-encryption ! hostname R1 ! ...
startup-config is not present instead.R1#copy running-config tftp: Address or name of remote host []? 192.168.10.50 Destination filename [r1-confg]? !! 1843 bytes copied in 0.204 secs (9034 bytes/sec)
-confg. Each ! is a successful block. A row of dots and an error mean the server is unreachable or not running.R1#reload System configuration has been modified. Save? [yes/no]: yes Building configuration... [OK] Proceed with reload? [confirm]
R1#show version | include register Configuration register is 0x2102
What goes wrong and how to troubleshoot it
- Configuration gone after a reload. It was never saved, or the configuration register is
0x2142(left over from password recovery). Check withshow version; set it back withconfig-register 0x2102. - A restored file left old settings behind. Copying to running-config merges. Old lines that aren't in the file remain. Copy to startup-config and reload for a clean replace.
- Restored interfaces are shut down. When you merge into running-config, interfaces that are currently shut stay shut unless the file contains
no shutdown, which saved files don't show by default. Bring them up by hand. - TFTP copy fails with timeouts. Ping the server, check that the TFTP service is running and that a firewall allows UDP 69 (and the high ports the transfer then uses).
- A wiped switch still has its VLANs. The VLAN database (
vlan.datin flash) wasn't deleted.
Common mistakes
- Reversing the copy order, for example
copy startup-config running-configwhen you meant to save. That merges the old saved config into the live one. - Answering yes to "Save?" after
erase startup-config, which writes everything straight back. - Thinking
erase startup-configchanges the running device. It doesn't, until the next reload. - Keeping the only backup in the device's own flash. If the device dies, so does the backup.
💡 Exam tip: know which memory holds what: RAM = running-config, NVRAM = startup-config, flash = IOS image, ROM = bootstrap and POST. Know that copy is always source then destination, that copying into running-config merges, and that erase startup-config plus reload returns a router to defaults (a switch also needs vlan.dat deleted).
Key takeaways
- Changes go live in running-config (RAM) instantly; only startup-config (NVRAM) survives a reload.
copy running-config startup-configsaves;write memoryis the same.erase startup-config+reloadresets a device; deletevlan.daton a switch.- Back up off the device with TFTP, FTP or SCP; copying into running-config merges rather than replaces.
Check yourself
You configure a new static route on R1 and test it successfully. The router then loses power. Is the route there after it boots?
Which command saves the active configuration so it survives a reload?
You run 'copy tftp: running-config' with a file that has no 'ip domain name' line. The router already has one. What happens to it?
After 'erase startup-config' and 'reload' a switch boots with no hostname, but all its old VLANs are still there. Why?
A router keeps booting into the initial configuration dialog even though show startup-config shows a valid saved config. What should you check?