276 commands a CCNA candidate uses on Cisco routers and switches, grouped by topic. Search by keyword or filter by the mode you type them in. Each group links to the lesson that explains it.
Written for RouteLearn.net from Cisco IOS / IOS XE documentation. Exact keywords can differ between platforms and software versions; use ? on your device to confirm.
The first settings on a new router or switch: name, passwords, banner and console/VTY lines.
hostname <name>(config)#Gives the device a name, which also changes the prompt.
hostname R1
enable secret <password>(config)#Sets the password for privileged EXEC mode and stores it as a hash.
enable secret Cl4ss-Lab!
💡 If both enable secret and enable password exist, enable secret wins. Avoid enable password: it is stored in clear text.
service password-encryption(config)#Hides clear-text passwords (line passwords, enable password) in the configuration with weak type 7 encryption.
service password-encryption
💡 Type 7 is easy to reverse; it only stops someone reading a password over your shoulder.
banner motd <delimiter> <text> <delimiter>(config)#Sets a message shown to everyone who connects, before login. Usually a legal warning.
banner motd # Authorized access only. #
💡 The delimiter character must not appear inside the text.
no ip domain-lookup(config)#Stops the device treating a mistyped command as a hostname and trying to resolve it with DNS.
no ip domain-lookup
💡 Saves you waiting for the DNS lookup to time out after a typo.
clock set <hh:mm:ss> <day> <month> <year>#Sets the device clock by hand.
clock set 14:30:00 6 October 2026
💡 Use NTP in production so the time stays accurate.
clock timezone <name> <hours-offset> [minutes-offset](config)#Sets the local time zone as an offset from UTC.
clock timezone EST -5
show clock#Shows the current date and time on the device.
show clock detail
💡 A leading * means the time is not authoritative (not synced).
line console 0(config)#Enters line configuration for the console port.
line console 0
line vty <first> <last>(config)#Enters line configuration for the virtual terminal lines used by Telnet and SSH.
line vty 0 15
💡 Some older devices only have lines 0 4.
password <password>(config-line)#Sets the password for the console or VTY lines.
password LinePass1
💡 Only checked when the line also has the login command.
login(config-line)#Makes the line ask for the password set with the password command.
login
💡 Use login local instead to check usernames from the local database.
logging synchronous(config-line)#Reprints your half-typed command after a log message interrupts it.
logging synchronous
exec-timeout <minutes> [seconds](config-line)#Logs out an idle session after the given time.
exec-timeout 5 0
💡 The default is 10 minutes. exec-timeout 0 0 disables the timeout, which is fine in a lab but not in production.
Save the configuration, view it, wipe it and manage the files in flash.
copy running-config startup-config#Saves the current configuration in RAM to NVRAM so it survives a reload.
copy running-config startup-config
💡 Changes you do not save are lost when the device restarts.
write memory#An older shortcut that also saves the running configuration to the startup configuration.
write memory
show running-config#Shows the configuration the device is using right now.
show running-config | section router ospf
show running-config interface <interface>#Shows only the configuration of one interface.
show running-config interface GigabitEthernet0/1
show startup-config#Shows the saved configuration that will load at the next boot.
show startup-config
erase startup-config#Deletes the saved configuration from NVRAM so the device boots with a blank config.
erase startup-config
💡 On a switch, also delete flash:vlan.dat to remove the VLAN database. write erase does the same as this command.
delete flash:vlan.dat#Removes the file where a Catalyst switch keeps its VLANs, as part of a full reset.
delete flash:vlan.dat
reload#Restarts the device.
reload
💡 IOS asks whether to save first if the running configuration has changed.
reload in <minutes>#Schedules a restart. A safety net when changing remote access: if you lock yourself out, the old saved config returns.
reload in 10
💡 Cancel it with reload cancel once you know the change works.
show version#Shows the IOS version, uptime, model, memory, interfaces, image file and configuration register.
show version
show flash:#Lists the files in flash memory, such as the IOS image.
show flash:
💡 dir flash: gives a similar listing.
copy tftp: flash:#Copies a file, usually a new IOS image, from a TFTP server into flash. IOS prompts for the server and file names.
copy tftp: flash:
copy running-config tftp:#Backs up the running configuration to a TFTP server.
copy running-config tftp:
boot system flash:<filename>(config)#Tells the device which IOS image in flash to load at the next boot.
boot system flash:c2900-universalk9-mz.SPA.157-3.M8.bin
💡 Save the config afterwards, or the setting is lost.
Configure and check physical and logical interfaces.
interface <type><number>(config)#Enters interface configuration mode for one interface.
interface GigabitEthernet0/0
💡 Abbreviations like g0/0 work too.
interface range <type><first> - <last>(config)#Configures several interfaces at once with the same commands.
interface range GigabitEthernet1/0/1 - 24
interface loopback <number>(config)#Creates a virtual interface that is always up while the device is up. Often used for router IDs and management.
interface loopback 0
description <text>(config-if)#Adds a label to an interface so others know what it connects to.
description Uplink to CORE-SW1 Gi1/0/48
ip address <address> <mask>(config-if)#Assigns an IPv4 address and subnet mask to the interface.
ip address 192.168.10.1 255.255.255.0
💡 Add the secondary keyword to give one interface extra addresses.
no shutdown(config-if)#Turns the interface on.
no shutdown
💡 Router interfaces are shut down by default; switch ports are on by default.
shutdown(config-if)#Turns the interface off administratively.
shutdown
💡 Shows as administratively down in show ip interface brief.
speed {10 | 100 | 1000 | auto}(config-if)#Sets the interface speed in Mbps or lets it auto-negotiate.
speed 100
duplex {full | half | auto}(config-if)#Sets the duplex mode or lets it auto-negotiate.
duplex full
💡 A duplex mismatch causes late collisions and slow transfers. Set both ends the same way.
default interface <interface>(config)#Resets an interface back to its default configuration in one step.
default interface GigabitEthernet0/5
show ip interface brief#One line per interface with its IPv4 address and status. The quickest health check.
show ip interface brief
show interfaces [interface]#Detailed status and counters: line and protocol state, speed, duplex, MTU, input/output errors and CRCs.
show interfaces GigabitEthernet0/1
show interfaces status#On a switch, one line per port showing connected or not, VLAN, duplex, speed and type.
show interfaces status
💡 Shows err-disabled ports clearly.
show interfaces description#Lists each interface with its status and description.
show interfaces description
clear counters [interface]#Resets the interface counters so you can see whether errors are still increasing.
clear counters GigabitEthernet0/1
Give a Layer 2 switch an IP address so you can reach it remotely.
interface vlan <vlan-id>(config)#Enters the switch virtual interface (SVI) for a VLAN. On a Layer 2 switch this holds the management address.
interface vlan 1
💡 Best practice is a dedicated management VLAN instead of VLAN 1.
ip address <address> <mask>(config-if)#Assigns the management IPv4 address to the SVI.
ip address 192.168.99.11 255.255.255.0
no shutdown(config-if)#Brings the SVI up.
no shutdown
💡 An SVI only goes up/up when the VLAN exists and at least one port in it is up.
ip default-gateway <address>(config)#Sets the router a Layer 2 switch uses to reach other subnets.
ip default-gateway 192.168.99.1
💡 Ignored once ip routing is enabled; a Layer 3 switch uses a default route instead.
show interfaces vlan <vlan-id>#Shows the status and details of an SVI.
show interfaces vlan 1
Create VLANs, put access ports in them and carry several VLANs over 802.1Q trunks.
vlan <vlan-id>(config)#Creates a VLAN (or edits an existing one) and enters VLAN configuration mode.
vlan 10
💡 no vlan 10 deletes it; ports in that VLAN stop forwarding until moved.
name <vlan-name>(config-vlan)#Gives the VLAN a readable name.
name SALES
switchport mode access(config-if)#Makes the port a permanent access port that carries one data VLAN.
switchport mode access
💡 Also stops the port forming a trunk through DTP.
switchport access vlan <vlan-id>(config-if)#Puts an access port into a VLAN.
switchport access vlan 10
💡 If the VLAN does not exist, the switch creates it. Ports start in VLAN 1.
switchport voice vlan <vlan-id>(config-if)#Adds a separate VLAN for an IP phone on an access port, while the PC behind the phone uses the access VLAN.
switchport voice vlan 20
switchport trunk encapsulation dot1q(config-if)#Sets 802.1Q tagging on switches that also support the old ISL protocol.
switchport trunk encapsulation dot1q
💡 Required before switchport mode trunk on such switches; not available on switches that only support 802.1Q.
switchport mode trunk(config-if)#Makes the port a permanent 802.1Q trunk that carries traffic for many VLANs.
switchport mode trunk
switchport mode dynamic {desirable | auto}(config-if)#Lets DTP decide whether the port becomes a trunk. Desirable asks actively; auto only agrees if the other side asks.
switchport mode dynamic desirable
💡 Two auto ports never form a trunk. Static modes are safer.
switchport trunk allowed vlan <vlan-list>(config-if)#Limits which VLANs may cross the trunk, replacing the current list.
switchport trunk allowed vlan 10,20,30
💡 Use switchport trunk allowed vlan add 40 to add one without removing the others — forgetting add is a common outage.
switchport trunk native vlan <vlan-id>(config-if)#Sets the VLAN whose frames cross the trunk untagged.
switchport trunk native vlan 999
💡 Default is VLAN 1. Both ends must match, or CDP reports a native VLAN mismatch.
switchport nonegotiate(config-if)#Stops the port sending DTP frames.
switchport nonegotiate
💡 Only valid on a port statically set to access or trunk mode.
show vlan brief#Lists every VLAN with its name, status and access ports.
show vlan brief
💡 Trunk ports are not listed here; use show interfaces trunk.
show vlan id <vlan-id>#Shows the details and ports of one VLAN.
show vlan id 10
show interfaces trunk#Lists the trunk ports with their mode, native VLAN and the VLANs allowed and active on each.
show interfaces trunk
show interfaces <interface> switchport#Shows a port's administrative and operational mode, access VLAN, voice VLAN, native VLAN and DTP state.
show interfaces GigabitEthernet1/0/5 switchport
Route between VLANs with a router-on-a-stick or with SVIs on a Layer 3 switch.
interface <interface>.<subinterface>(config)#Creates a subinterface on a router port for router-on-a-stick, usually one per VLAN.
interface GigabitEthernet0/0.10
💡 Matching the subinterface number to the VLAN ID is a convention, not a rule. The physical interface must be no shutdown.
encapsulation dot1q <vlan-id> [native](config-if)#Tells a subinterface which 802.1Q VLAN tag it handles. Configure it before the IP address.
encapsulation dot1q 10
💡 Add native for the subinterface that handles the trunk's untagged native VLAN.
ip routing(config)#Turns on IPv4 routing on a Layer 3 switch so its SVIs and routed ports can route between subnets.
ip routing
💡 On by default on routers, off by default on most Catalyst switches.
sdm prefer lanbase-routing(config)#On a Catalyst 2960, changes the memory template so the switch can do basic static routing on SVIs.
sdm prefer lanbase-routing
💡 Takes effect only after a reload.
interface vlan <vlan-id>(config)#Creates an SVI that acts as the default gateway for hosts in that VLAN on a Layer 3 switch.
interface vlan 20
no switchport(config-if)#Turns a Layer 3 switch port into a routed port that can take an IP address, like a router interface.
no switchport
Bundle several physical links into one logical link with LACP, PAgP or static mode.
channel-group <number> mode {active | passive | desirable | auto | on}(config-if)#Adds the port to an EtherChannel. active/passive use LACP, desirable/auto use PAgP and on forms the bundle without any negotiation.
channel-group 1 mode active
💡 passive+passive and auto+auto never form a bundle. on must be used on both ends.
channel-protocol {lacp | pagp}(config-if)#Limits the port to one negotiation protocol.
channel-protocol lacp
interface port-channel <number>(config)#Enters the logical port-channel interface. Settings here (trunk mode, allowed VLANs, IP address) apply to the whole bundle.
interface port-channel 1
port-channel load-balance <method>(config)#Chooses which address fields decide the link each frame uses, for example src-dst-ip or src-mac.
port-channel load-balance src-dst-ip
💡 Applies to every EtherChannel on the switch. Check the current method with show etherchannel load-balance.
show etherchannel summary#Lists each bundle, its protocol and member ports with flags such as P (bundled), s (suspended) and SU (Layer 2, in use).
show etherchannel summary
show etherchannel port-channel#Shows details of each port-channel, including the protocol and when ports joined.
show etherchannel port-channel
show interfaces port-channel <number>#Shows the status, combined bandwidth and counters of a port-channel interface.
show interfaces port-channel 1
Pick the STP mode, control the root bridge, tune port costs and protect edge ports.
spanning-tree mode rapid-pvst(config)#Switches the device to Rapid PVST+, which runs one RSTP (802.1w) instance per VLAN.
spanning-tree mode rapid-pvst
💡 Many switches default to classic PVST+ (spanning-tree mode pvst).
spanning-tree vlan <vlan-list> priority <priority>(config)#Sets the bridge priority for the VLANs. The lowest bridge ID becomes the root bridge.
spanning-tree vlan 10,20 priority 4096
💡 Must be a multiple of 4096 from 0 to 61440. The default is 32768.
spanning-tree vlan <vlan-list> root primary(config)#Lowers this switch's priority enough to make it the root bridge for those VLANs.
spanning-tree vlan 10 root primary
💡 This is a one-time calculation, not a permanent guarantee; a switch added later with a lower priority can still take over.
spanning-tree vlan <vlan-list> root secondary(config)#Sets the priority to 28672 so this switch becomes the backup root bridge.
spanning-tree vlan 10 root secondary
spanning-tree portfast(config-if)#Lets an access port toward an end device go straight to forwarding, skipping the listening and learning delay.
spanning-tree portfast
💡 Only use it on ports that connect to hosts, never to other switches.
spanning-tree portfast default(config)#Enables PortFast on every access port of the switch.
spanning-tree portfast default
💡 Newer IOS XE releases use spanning-tree portfast edge default.
spanning-tree bpduguard enable(config-if)#Err-disables the port if it ever receives a BPDU, which protects PortFast ports from someone plugging in a switch.
spanning-tree bpduguard enable
💡 Recover the port with shutdown then no shutdown, or with errdisable recovery.
spanning-tree guard root(config-if)#Stops a port becoming a root port. If a better BPDU arrives, the port is blocked (root-inconsistent) until the BPDUs stop.
spanning-tree guard root
spanning-tree [vlan <vlan-list>] cost <cost>(config-if)#Changes the port's STP cost so a different path is preferred toward the root.
spanning-tree vlan 10 cost 10
💡 Lower cost is better. Without vlan it changes the cost for all VLANs on the port.
spanning-tree [vlan <vlan-list>] port-priority <priority>(config-if)#Changes the port priority, used as a tie-breaker when costs and bridge IDs are equal.
spanning-tree vlan 10 port-priority 64
💡 Multiples of 16 from 0 to 240; default 128.
show spanning-tree [vlan <vlan-id>]#Shows the root bridge, this switch's bridge ID and each port's role, state and cost.
show spanning-tree vlan 10
show spanning-tree summary#Shows the STP mode, which features are on (PortFast default, BPDU Guard) and port counts per state.
show spanning-tree summary
show spanning-tree interface <interface> detail#Shows the STP details of one port, including BPDUs sent and received.
show spanning-tree interface GigabitEthernet1/0/1 detail
Discover directly connected neighbors with Cisco's CDP or the standard LLDP.
show cdp neighbors#Lists directly connected Cisco devices: name, local port, platform and remote port.
show cdp neighbors
show cdp neighbors detail#Adds each neighbor's IP address, IOS version and native VLAN.
show cdp neighbors detail
show cdp entry <device-name>#Shows the detailed CDP information for one neighbor.
show cdp entry SW2
show cdp#Shows whether CDP is running and its timers.
show cdp
no cdp run(config)#Turns CDP off on the whole device. cdp run turns it back on.
no cdp run
💡 CDP is on by default.
no cdp enable(config-if)#Stops CDP on one interface, for example a port facing the internet.
no cdp enable
cdp timer <seconds>(config)#Sets how often CDP messages are sent.
cdp timer 30
💡 Default 60 seconds.
cdp holdtime <seconds>(config)#Sets how long a neighbor's information is kept without a new message.
cdp holdtime 120
💡 Default 180 seconds.
lldp run(config)#Turns LLDP on for the whole device.
lldp run
💡 LLDP is off by default on most Cisco devices.
[no] lldp transmit(config-if)#Controls whether the interface sends LLDP messages.
no lldp transmit
[no] lldp receive(config-if)#Controls whether the interface listens for LLDP messages.
no lldp receive
lldp timer <seconds>(config)#Sets how often LLDP messages are sent.
lldp timer 30
💡 Default 30 seconds.
lldp holdtime <seconds>(config)#Sets how long a neighbor's LLDP information is kept.
lldp holdtime 120
💡 Default 120 seconds.
show lldp neighbors [detail]#Lists LLDP neighbors; detail adds addresses and system descriptions.
show lldp neighbors detail
Add IPv4 and IPv6 static, default and floating routes, and read the routing table.
ip route <network> <mask> <next-hop>(config)#Adds a static route that sends traffic for a network to a next-hop address.
ip route 192.168.20.0 255.255.255.0 10.0.0.2
ip route <network> <mask> <exit-interface>(config)#Adds a static route that points out an interface instead of at a next hop.
ip route 192.168.20.0 255.255.255.0 Serial0/0/0
💡 Fine on point-to-point links. On Ethernet, add the next hop too (a fully specified route) to avoid ARP for every destination.
ip route <network> <mask> <exit-interface> <next-hop>(config)#A fully specified static route that names both the exit interface and the next hop.
ip route 192.168.20.0 255.255.255.0 GigabitEthernet0/1 10.0.0.2
ip route 0.0.0.0 0.0.0.0 <next-hop>(config)#Adds a default route, used for any destination with no more specific match.
ip route 0.0.0.0 0.0.0.0 203.0.113.1
💡 Shown as S* and sets the gateway of last resort.
ip route <network> <mask> <next-hop> <distance>(config)#Adds a floating static route: a backup with a higher administrative distance that is only used when the main route disappears.
ip route 0.0.0.0 0.0.0.0 198.51.100.1 5
💡 Static routes default to AD 1. To back up an OSPF route (AD 110), use a value above 110.
ip route <host-address> 255.255.255.255 <next-hop>(config)#Adds a host route that matches a single IPv4 address.
ip route 192.168.50.10 255.255.255.255 10.0.0.6
show ip route [static | connected | ospf]#Shows the IPv4 routing table, optionally only one route source.
show ip route static
💡 Codes: C connected, L local, S static, O OSPF, * candidate default.
show ip route <address>#Shows which route the router would use for one destination address.
show ip route 192.168.20.5
ipv6 route <prefix>/<length> <next-hop>(config)#Adds an IPv6 static route through a global unicast next hop.
ipv6 route 2001:db8:20::/64 2001:db8:0:1::2
💡 Needs ipv6 unicast-routing to forward traffic.
ipv6 route <prefix>/<length> <exit-interface> <link-local-next-hop>(config)#Adds an IPv6 static route through a link-local next hop. The exit interface is required because link-local addresses repeat on every link.
ipv6 route 2001:db8:20::/64 GigabitEthernet0/1 fe80::2
ipv6 route ::/0 <next-hop>(config)#Adds an IPv6 default route.
ipv6 route ::/0 2001:db8:0:ff::1
show ipv6 route [static]#Shows the IPv6 routing table.
show ipv6 route static
Configure single-area OSPF, tune it and check neighbors and routes.
router ospf <process-id>(config)#Starts an OSPF process and enters router configuration mode.
router ospf 1
💡 The process ID is only locally significant; neighbors do not need the same number.
router-id <a.b.c.d>(config-router)#Sets the router ID by hand, the 32-bit value that names this router in OSPF.
router-id 1.1.1.1
💡 Without it, OSPF uses the highest loopback IP, then the highest active interface IP. A change needs clear ip ospf process.
network <address> <wildcard> area <area-id>(config-router)#Enables OSPF on every interface whose IP falls in the range, and puts it in the area.
network 10.0.12.0 0.0.0.3 area 0
💡 Uses a wildcard mask, not a subnet mask. network 10.0.12.1 0.0.0.0 area 0 matches one exact interface.
ip ospf <process-id> area <area-id>(config-if)#Enables OSPF directly on the interface, an alternative to the network command.
ip ospf 1 area 0
passive-interface <interface>(config-router)#Keeps advertising the interface's network but stops sending hellos on it, so no neighbors form there.
passive-interface GigabitEthernet0/1
💡 Use it on LAN ports facing only hosts.
passive-interface default(config-router)#Makes every interface passive; then re-enable the links to neighbors with no passive-interface <interface>.
passive-interface default
default-information originate [always](config-router)#Advertises this router's default route into OSPF.
default-information originate
💡 The router needs a default route in its own table unless you add always.
auto-cost reference-bandwidth <mbps>(config-router)#Changes the reference bandwidth used to calculate interface costs, so fast links get different costs.
auto-cost reference-bandwidth 10000
💡 Default is 100 Mbps, so FastEthernet, Gigabit and 10-Gigabit links all get cost 1. Set the same value on every router.
maximum-paths <number>(config-router)#Sets how many equal-cost paths OSPF can install for one destination.
maximum-paths 4
💡 The default is 4 on most platforms.
ip ospf cost <cost>(config-if)#Sets the interface's OSPF cost directly, overriding the bandwidth calculation.
ip ospf cost 50
ip ospf priority <0-255>(config-if)#Sets the priority for DR/BDR election on the segment. Highest wins; 0 means never become DR or BDR.
ip ospf priority 255
💡 The default is 1. The election is not preemptive: a new higher priority only wins after the current DR goes away.
ip ospf network point-to-point(config-if)#Treats an Ethernet link between two routers as point-to-point, so no DR/BDR election takes place.
ip ospf network point-to-point
ip ospf hello-interval <seconds>(config-if)#Changes how often hellos are sent on the interface.
ip ospf hello-interval 5
💡 Defaults are 10 s hello and 40 s dead on Ethernet. Both timers must match for neighbors to form.
ip ospf dead-interval <seconds>(config-if)#Changes how long the router waits without hellos before it declares the neighbor down.
ip ospf dead-interval 20
show ip ospf neighbor#Lists OSPF neighbors with their router ID, priority, state (FULL, 2WAY...) and interface.
show ip ospf neighbor
show ip ospf interface brief#One line per OSPF interface showing area, cost, state (DR, BDR, DROTH, P2P) and neighbor count.
show ip ospf interface brief
show ip ospf interface [interface]#Shows the OSPF details of an interface: network type, cost, timers, DR and BDR.
show ip ospf interface GigabitEthernet0/0
show ip ospf#Shows the OSPF process, its router ID, reference bandwidth and areas.
show ip ospf
show ip ospf database#Shows the link-state database (the LSAs this router knows).
show ip ospf database
show ip protocols#Summarizes the running routing protocols: router ID, networks, passive interfaces, sources and AD.
show ip protocols
clear ip ospf process#Restarts OSPF, which drops and rebuilds all adjacencies. Needed for a new router ID to take effect.
clear ip ospf process
💡 Disruptive: routes are lost until neighbors come back.
Share a virtual default gateway between two routers with HSRP.
standby <group> ip <virtual-ip>(config-if)#Joins an HSRP group and sets the virtual IP that hosts use as their default gateway.
standby 10 ip 192.168.10.254
💡 The virtual IP must be in the interface's subnet but not used by any device.
standby <group> priority <0-255>(config-if)#Sets the router's HSRP priority. The highest priority becomes active.
standby 10 priority 110
💡 The default is 100; on a tie the highest interface IP wins.
standby <group> preempt(config-if)#Lets a router with higher priority take back the active role when it comes online.
standby 10 preempt
💡 Preemption is off by default.
standby version 2(config-if)#Switches the interface to HSRPv2, which supports IPv6 and more group numbers.
standby version 2
💡 Version 1 is the default. Both routers must use the same version.
standby <group> timers <hello> <hold>(config-if)#Changes the HSRP hello and hold times in seconds.
standby 10 timers 1 3
💡 Defaults: 3 s hello, 10 s hold.
show standby brief#One line per HSRP group: priority, preempt, state (Active, Standby), active and standby routers and the virtual IP.
show standby brief
show standby#Shows full HSRP details including the virtual MAC address and timers.
show standby
Enable IPv6 routing and give interfaces global, EUI-64 and link-local addresses.
ipv6 unicast-routing(config)#Lets the router forward IPv6 packets and send Router Advertisements.
ipv6 unicast-routing
💡 Off by default. Without it the router still has IPv6 addresses but acts like a host.
ipv6 address <prefix>/<length>(config-if)#Assigns a full IPv6 address to the interface.
ipv6 address 2001:db8:acad:1::1/64
💡 Also creates a link-local address automatically. An interface can hold several IPv6 addresses.
ipv6 address <prefix>/64 eui-64(config-if)#Builds the interface ID from the MAC address (EUI-64) and adds it to the given prefix.
ipv6 address 2001:db8:acad:2::/64 eui-64
ipv6 address <fe80-address> link-local(config-if)#Sets the link-local address by hand so it is short and easy to recognize.
ipv6 address fe80::1 link-local
ipv6 enable(config-if)#Turns on IPv6 with only a link-local address, no global address.
ipv6 enable
ipv6 address autoconfig(config-if)#Makes the interface create its own address with SLAAC from Router Advertisements.
ipv6 address autoconfig
ipv6 address dhcp(config-if)#Gets an IPv6 address from a DHCPv6 server.
ipv6 address dhcp
show ipv6 interface brief#Lists interfaces with their status and IPv6 addresses (link-local and global).
show ipv6 interface brief
show ipv6 interface [interface]#Shows the IPv6 details of an interface, including joined multicast groups such as ff02::1.
show ipv6 interface GigabitEthernet0/0
show ipv6 neighbors#Shows the IPv6 neighbor table (NDP), the IPv6 version of the ARP table.
show ipv6 neighbors
Translate private inside addresses to public ones with static NAT, dynamic NAT and PAT.
ip nat inside(config-if)#Marks the interface as facing the inside (private) network.
ip nat inside
ip nat outside(config-if)#Marks the interface as facing the outside (public) network.
ip nat outside
💡 Forgetting inside or outside on one interface is the most common NAT mistake.
ip nat inside source static <inside-local> <inside-global>(config)#Creates a permanent one-to-one mapping, so an inside server is always reachable at the same public address.
ip nat inside source static 192.168.10.20 203.0.113.20
ip nat inside source static {tcp | udp} <inside-local> <port> <inside-global> <port>(config)#Forwards one public port to a port on an inside host (port forwarding).
ip nat inside source static tcp 192.168.10.20 443 203.0.113.5 443
ip nat pool <name> <first-ip> <last-ip> netmask <mask>(config)#Defines a range of public addresses for dynamic NAT.
ip nat pool PUBLIC 203.0.113.10 203.0.113.20 netmask 255.255.255.0
ip nat inside source list <acl> pool <name> [overload](config)#Translates inside addresses that match the ACL to addresses from the pool. With overload it also uses ports (PAT).
ip nat inside source list 1 pool PUBLIC
ip nat inside source list <acl> interface <interface> overload(config)#PAT: translates every matching inside host to the outside interface's single address, keeping them apart by port number.
ip nat inside source list 1 interface GigabitEthernet0/1 overload
💡 The ACL (for example access-list 1 permit 192.168.0.0 0.0.255.255) only chooses which traffic is translated.
show ip nat translations#Lists the current NAT table with inside local, inside global, outside local and outside global addresses.
show ip nat translations
show ip nat statistics#Shows the inside and outside interfaces, hits and misses, and pool usage.
show ip nat statistics
clear ip nat translation *#Removes all dynamic NAT entries from the table.
clear ip nat translation *
💡 Static entries stay. Useful after changing the NAT configuration.
debug ip nat#Shows each address translation as it happens.
debug ip nat
💡 Turn it off with undebug all.
Run a DHCP server on IOS, relay requests to another server and get an address as a client.
ip dhcp excluded-address <first-ip> [last-ip](config)#Keeps an address or range out of every pool, for gateways, servers and printers.
ip dhcp excluded-address 192.168.10.1 192.168.10.10
ip dhcp pool <name>(config)#Creates a DHCP pool and enters DHCP pool configuration mode.
ip dhcp pool VLAN10
network <network> <mask>(dhcp-config)#Sets the subnet the pool hands out addresses from.
network 192.168.10.0 255.255.255.0
💡 A /prefix-length form (network 192.168.10.0 /24) also works.
default-router <address>(dhcp-config)#Sets the default gateway given to clients.
default-router 192.168.10.1
dns-server <address> [address2](dhcp-config)#Sets the DNS servers given to clients.
dns-server 192.168.1.53 192.168.1.54
domain-name <domain>(dhcp-config)#Sets the DNS domain name given to clients.
domain-name corp.example.com
lease {<days> [hours] [minutes] | infinite}(dhcp-config)#Sets how long clients may keep their address.
lease 7
💡 The default is 1 day.
ip helper-address <server-ip>(config-if)#Makes the router relay DHCP broadcasts on this interface to a DHCP server on another subnet.
ip helper-address 192.168.1.10
💡 Configure it on the interface facing the clients, not the server.
ip address dhcp(config-if)#Makes the interface a DHCP client that gets its address from a server, common on internet-facing ports.
ip address dhcp
show ip dhcp binding#Lists the addresses the server has leased, with each client's ID and lease expiry.
show ip dhcp binding
show ip dhcp pool [name]#Shows each pool's range, how many addresses are leased and the next address to hand out.
show ip dhcp pool VLAN10
show ip dhcp conflict#Lists addresses the server found already in use when it tried to lease them.
show ip dhcp conflict
Keep device clocks in sync so logs and certificates have the right time.
ntp server <address> [prefer](config)#Makes the device sync its clock from an NTP server.
ntp server 192.168.1.123
ntp master [stratum](config)#Makes the device an authoritative NTP server using its own clock.
ntp master 3
💡 Default stratum is 8. Mostly used in labs without an external time source.
ntp source <interface>(config)#Sends NTP packets from a fixed interface address, usually a loopback.
ntp source loopback 0
ntp authenticate(config)#Turns on NTP authentication so the device only trusts servers that know a shared key.
ntp authenticate
ntp authentication-key <key-id> md5 <key>(config)#Defines an NTP authentication key.
ntp authentication-key 1 md5 NtpKey123
ntp trusted-key <key-id>(config)#Marks a key as trusted. Then reference it with ntp server <address> key <key-id>.
ntp trusted-key 1
ntp update-calendar(config)#Copies the NTP time to the hardware clock so it is close to correct after a reboot.
ntp update-calendar
show ntp associations#Lists the NTP servers the device talks to; * marks the one it is synced to.
show ntp associations
show ntp status#Shows whether the clock is synchronized, the stratum and the reference server.
show ntp status
Let monitoring systems poll the device and send log messages to a syslog server.
snmp-server community <string> {ro | rw} [acl](config)#Creates an SNMPv1/v2c community (a shared password) with read-only or read-write access.
snmp-server community M0nitor-RO ro 10
💡 Communities travel in clear text; the optional ACL limits which managers may use it.
snmp-server location <text>(config)#Records where the device is, readable by the NMS.
snmp-server location Building A, Floor 2, Rack 4
snmp-server contact <text>(config)#Records who is responsible for the device.
snmp-server contact noc@example.com
snmp-server host <address> version 2c <community>(config)#Sends SNMP notifications (traps) to a management station.
snmp-server host 192.168.1.50 version 2c M0nitor-RO
snmp-server enable traps(config)#Turns on sending of SNMP traps.
snmp-server enable traps
snmp-server group <group> v3 priv(config)#Creates an SNMPv3 group that requires both authentication and encryption.
snmp-server group NMS v3 priv
snmp-server user <user> <group> v3 auth sha <auth-password> priv aes 128 <priv-password>(config)#Creates an SNMPv3 user with SHA authentication and AES encryption.
snmp-server user nmsadmin NMS v3 auth sha AuthPass123 priv aes 128 PrivPass123
💡 SNMPv3 users do not appear in the running configuration.
logging host <address>(config)#Sends log messages to a syslog server.
logging host 192.168.1.60
logging trap <level>(config)#Sets the lowest severity sent to the syslog server, as a name or number 0-7.
logging trap warnings
💡 Includes the chosen level and everything more severe (lower number). Default is informational (6).
logging buffered [size] [level](config)#Keeps log messages in a RAM buffer that you read with show logging.
logging buffered 16384 informational
logging console [level](config)#Sets the lowest severity shown on the console. no logging console turns console messages off.
logging console warnings
service timestamps log datetime msec(config)#Adds the date and time, to the millisecond, to each log message.
service timestamps log datetime msec
terminal monitor#Shows log and debug messages in your SSH or Telnet session; by default they only appear on the console.
terminal monitor
show logging#Shows the logging settings and the messages in the local buffer.
show logging
Local user accounts, SSH instead of Telnet and other login protections.
username <name> [privilege <level>] secret <password>(config)#Creates a local user account with a hashed password.
username admin privilege 15 secret Str0ng-Pass!
💡 Prefer secret over password, which is stored in clear text or type 7.
login local(config-line)#Makes the line ask for a username and password from the local user database.
login local
ip domain-name <domain>(config)#Sets the device's domain name, which is needed to generate RSA keys for SSH.
ip domain-name example.com
💡 Newer IOS XE releases also accept ip domain name.
crypto key generate rsa [modulus <bits>](config)#Creates the RSA key pair that SSH uses. Requires a hostname and domain name first.
crypto key generate rsa modulus 2048
💡 SSH version 2 needs a modulus of at least 768 bits; use 2048.
ip ssh version 2(config)#Allows only SSH version 2, the secure version.
ip ssh version 2
transport input ssh(config-line)#Allows only SSH on the VTY lines, blocking Telnet.
transport input ssh
💡 transport input none blocks all remote access on those lines.
show ip ssh#Shows whether SSH is enabled, its version and timeouts.
show ip ssh
show ssh#Lists the SSH sessions currently connected to the device.
show ssh
ssh -l <username> <address>#Opens an SSH session from this device to another one.
ssh -l admin 192.168.99.12
security passwords min-length <length>(config)#Rejects new passwords shorter than the given length.
security passwords min-length 10
login block-for <seconds> attempts <tries> within <seconds>(config)#Blocks all logins for a while after too many failed attempts, which slows down password guessing.
login block-for 120 attempts 3 within 60
aaa new-model(config)#Turns on the AAA framework so login can use RADIUS or TACACS+ servers and method lists.
aaa new-model
💡 Once enabled, VTY lines use the default AAA login method (local users if nothing else is set). Create a local user first so you are not locked out.
Limit which and how many MAC addresses can use a switch port.
switchport port-security(config-if)#Turns on port security for the port.
switchport port-security
💡 The port must be a static access (or trunk) port; it fails on a dynamic port. The default allows one MAC with violation mode shutdown.
switchport port-security maximum <number>(config-if)#Sets how many MAC addresses the port may learn.
switchport port-security maximum 2
switchport port-security violation {protect | restrict | shutdown}(config-if)#Chooses what happens on a violation: protect drops silently, restrict drops and logs, shutdown err-disables the port.
switchport port-security violation restrict
💡 shutdown is the default.
switchport port-security mac-address <mac>(config-if)#Allows a specific MAC address on the port.
switchport port-security mac-address 0050.7966.6801
switchport port-security mac-address sticky(config-if)#Learns MAC addresses automatically and writes them into the running configuration.
switchport port-security mac-address sticky
💡 Save the config, or the sticky addresses are lost on reload.
show port-security#Summarizes secured ports with their maximum, current count, violation count and action.
show port-security
show port-security interface <interface>#Shows the port security settings and status of one port, including the last MAC that caused a violation.
show port-security interface FastEthernet0/5
show port-security address#Lists the secure MAC addresses on all ports.
show port-security address
errdisable recovery cause psecure-violation(config)#Brings ports shut down by port security back up automatically after a timer.
errdisable recovery cause psecure-violation
errdisable recovery interval <seconds>(config)#Sets how long to wait before re-enabling err-disabled ports.
errdisable recovery interval 300
💡 The default is 300 seconds.
Block rogue DHCP servers and forged ARP messages on access switches.
ip dhcp snooping(config)#Turns on DHCP snooping globally.
ip dhcp snooping
💡 It does nothing until you also enable it for VLANs.
ip dhcp snooping vlan <vlan-list>(config)#Enables DHCP snooping on the listed VLANs.
ip dhcp snooping vlan 10,20
ip dhcp snooping trust(config-if)#Marks a port as trusted, so DHCP server messages are allowed in. Use it on uplinks toward the real DHCP server.
ip dhcp snooping trust
💡 All ports are untrusted by default.
ip dhcp snooping limit rate <packets-per-second>(config-if)#Err-disables the port if it receives more DHCP messages per second than the limit, stopping starvation attacks.
ip dhcp snooping limit rate 10
no ip dhcp snooping information option(config)#Stops the switch adding Option 82 to DHCP requests, which some DHCP servers reject.
no ip dhcp snooping information option
show ip dhcp snooping#Shows the snooping status, enabled VLANs and trusted ports with their rate limits.
show ip dhcp snooping
show ip dhcp snooping binding#Lists the binding table of MAC address, IP address, VLAN and port learned from DHCP.
show ip dhcp snooping binding
💡 Dynamic ARP Inspection checks ARP messages against this table.
ip arp inspection vlan <vlan-list>(config)#Enables Dynamic ARP Inspection on the VLANs, checking ARP messages on untrusted ports against the DHCP snooping table.
ip arp inspection vlan 10,20
ip arp inspection trust(config-if)#Marks a port as trusted for DAI so its ARP messages are not checked. Use it on uplinks to other switches and routers.
ip arp inspection trust
ip arp inspection validate {[src-mac] [dst-mac] [ip]}(config)#Adds extra checks that the MAC and IP addresses inside ARP messages are consistent.
ip arp inspection validate src-mac dst-mac ip
💡 Each new validate command replaces the previous one, so list every check in one line.
ip arp inspection limit rate <packets-per-second>(config-if)#Err-disables the port if ARP messages arrive faster than the limit.
ip arp inspection limit rate 25
💡 Untrusted ports default to 15 packets per second.
show ip arp inspection#Shows the DAI settings and counts of forwarded and dropped ARP packets per VLAN.
show ip arp inspection
Filter traffic by source address only, with numbered or named standard ACLs.
access-list <1-99> {permit | deny} <source> [wildcard](config)#Adds a line to a numbered standard ACL that matches packets by source address.
access-list 10 permit 192.168.10.0 0.0.0.255
💡 Every ACL ends with an invisible deny any. Use host 192.168.10.5 for one address and any for all.
access-list <number> remark <text>(config)#Adds a comment to a numbered ACL to explain its purpose.
access-list 10 remark Allow the admin subnet
ip access-list standard <name>(config)#Creates or edits a named standard ACL and enters ACL configuration mode.
ip access-list standard MGMT-ONLY
[sequence] {permit | deny} <source> [wildcard](config-std/ext-nacl)#Adds a line inside a named standard ACL, optionally at a given sequence number.
20 deny host 192.168.10.66
💡 Lines are numbered in tens by default, so you can insert a line between existing ones.
no <sequence>(config-std/ext-nacl)#Deletes one line from the ACL by its sequence number.
no 20
remark <text>(config-std/ext-nacl)#Adds a comment inside a named ACL.
remark Block the guest printer
ip access-group <acl> {in | out}(config-if)#Applies an ACL to an interface in one direction.
ip access-group 10 out
💡 One ACL per interface, per direction, per protocol. Place standard ACLs close to the destination.
access-class <acl> in(config-line)#Applies an ACL to the VTY lines so only permitted sources can open SSH or Telnet sessions.
access-class MGMT-ONLY in
show access-lists [acl]#Shows every ACL with its lines and how many packets each line has matched.
show access-lists 10
show ip interface <interface>#Shows the IP settings of an interface, including which ACLs are applied inbound and outbound.
show ip interface GigabitEthernet0/1
Filter by protocol, source, destination and port with numbered or named extended ACLs.
access-list <100-199> {permit | deny} <protocol> <source> <wildcard> <destination> <wildcard> [eq <port>](config)#Adds a line to a numbered extended ACL that can match protocol, source, destination and port.
access-list 110 permit tcp 192.168.10.0 0.0.0.255 host 203.0.113.10 eq 443
💡 Protocol is ip, tcp, udp, icmp and so on. Ports only work with tcp or udp.
access-list <100-199> deny ip any any log(config)#Ends an ACL with an explicit deny that also logs every match, so you can see what was dropped.
access-list 110 deny ip any any log
ip access-list extended <name>(config)#Creates or edits a named extended ACL and enters ACL configuration mode.
ip access-list extended WEB-IN
[sequence] {permit | deny} <protocol> <source> <destination> [eq <port>](config-std/ext-nacl)#Adds a line inside a named extended ACL. Source and destination take an address with wildcard, host <ip> or any.
permit tcp any host 192.168.20.5 eq 22
permit tcp <source> <destination> established(config-std/ext-nacl)#Matches TCP packets that have the ACK or RST bit set, letting return traffic of sessions started from inside come back in.
permit tcp any 192.168.10.0 0.0.0.255 established
permit icmp <source> <destination> [echo | echo-reply](config-std/ext-nacl)#Allows ICMP, optionally only one message type such as ping requests or replies.
permit icmp any 192.168.10.0 0.0.0.255 echo-reply
ip access-list resequence <acl> <start> <increment>(config)#Renumbers the lines of an ACL to make room for new ones.
ip access-list resequence WEB-IN 10 10
ip access-group <acl> {in | out}(config-if)#Applies the extended ACL to an interface in one direction.
ip access-group WEB-IN in
💡 Place extended ACLs close to the source so unwanted traffic is dropped early.
show ip access-lists [acl]#Shows the IPv4 ACLs with their lines and match counts.
show ip access-lists WEB-IN
Test reachability, inspect ARP and MAC tables, and debug carefully.
ping <address>#Sends ICMP echo requests to test reachability. ! means a reply, . means a timeout.
ping 192.168.20.10
💡 The first ping often loses a packet while ARP resolves the next hop. U means destination unreachable.
ping <address> source <interface>#Pings from a specific interface address, useful for testing the return route to a LAN.
ping 192.168.20.10 source GigabitEthernet0/1
ping#Typed alone, starts an extended ping that asks for count, size, source and other options.
ping
traceroute <address>#Lists each router hop on the path to a destination.
traceroute 203.0.113.50
💡 Press Ctrl+Shift+6 to stop a long traceroute or ping.
show ip arp#Shows the ARP table that maps IPv4 addresses to MAC addresses.
show ip arp
clear arp-cache#Empties the dynamic entries in the ARP table.
clear arp-cache
show mac address-table [dynamic] [interface <interface>] [vlan <vlan-id>]#Shows the switch's MAC address table: which MAC was learned on which port and VLAN.
show mac address-table interface GigabitEthernet1/0/5
clear mac address-table dynamic#Removes the learned MAC addresses so the switch relearns them.
clear mac address-table dynamic
show interfaces counters errors#On a switch, lists error counters (FCS, alignment, collisions) for every port.
show interfaces counters errors
debug ip icmp#Shows a message for each ICMP packet the device sends or receives.
debug ip icmp
💡 Debugs can overload a busy device's CPU. Use them with care in production.
debug ip ospf adj#Shows OSPF adjacency events, useful when neighbors will not form.
debug ip ospf adj
undebug all#Turns off every running debug.
undebug all
💡 no debug all does the same thing.
show debugging#Lists the debugs that are currently running.
show debugging
show processes cpu [sorted]#Shows CPU usage over the last 5 seconds, 1 minute and 5 minutes, and per process.
show processes cpu sorted