Cisco IOS Commands
Cisco IOS for Catalyst switches and ISR routers. Any unique abbreviation works (conf t, sh ip int br), and ? lists what can come next.
Practice these in Terminal Practice
Modes
-
enable -
Turn on privileged commands
Mode:
> -
disable -
Turn off privileged commands
Mode:
# -
configure terminal -
Enter configuration mode
Mode:
# -
exit -
Exit from the EXEC
Mode:
> # (config)# or any sub-mode -
end -
Exit to privileged EXEC mode
Mode:
(config)# or any sub-mode -
logout -
Exit from the EXEC
Mode:
> #
Looking around
-
show running-config -
Current operating configuration
Mode:
# -
show startup-config -
Contents of startup configuration
Mode:
# -
show version -
System hardware and software status
Mode:
> # -
show ip interface brief -
Brief summary of IP status and configuration
Mode:
> # -
show interfaces status -
Show interface line status (switches only)
Mode:
> # -
show interfaces INTERFACE -
Interface status and configuration
Mode:
> # -
show cdp neighbors -
CDP neighbor entries
Mode:
> # -
show mac address-table -
MAC forwarding table (switches only)
Mode:
> # -
show clock -
Display the system clock
Mode:
> # -
show history -
Display the session command history
Mode:
> # -
terminal length <number> -
Set number of lines on a screen
Mode:
> #
Saving and reloading
-
copy running-config startup-config -
Save the running configuration
Mode:
# -
write memory -
Write running configuration to memory (save)
Mode:
# -
write -
Write running configuration to memory (save)
Mode:
# -
erase startup-config -
Erase the saved configuration
Mode:
# -
reload -
Restart the device (loads the startup-config)
Mode:
#
Interfaces
-
interface INTERFACE -
Select an interface to configure
Mode:
(config)# or any sub-mode -
interface range TEXT -
Configure several interfaces at once, e.g. interface range fa0/1 - 10
Mode:
(config)# or any sub-mode -
description TEXT -
Interface specific description
Mode:
(config-if)# -
ip address A.B.C.D A.B.C.D -
Set the IP address and subnet mask
Mode:
(config-if)# -
no ip address -
Remove the IP address
Mode:
(config-if)# -
shutdown -
Shut down the interface
Mode:
(config-if)# -
no shutdown -
Turn the interface on
Mode:
(config-if)#
VLANs and trunks
-
vlan <number> -
Create a VLAN and enter VLAN config mode (switches only)
Mode:
(config)# or any sub-mode -
name WORD -
Name the VLAN
Mode:
(config-vlan)# -
no vlan <number> -
Delete a VLAN (switches only)
Mode:
(config)# -
show vlan brief -
VTP all VLAN status in brief (switches only)
Mode:
> # -
show vlan -
VTP VLAN status (switches only)
Mode:
> # -
switchport mode {access|trunk} -
Set the port to access (one VLAN) or trunk (many VLANs) (switches only)
Mode:
(config-if)# -
switchport access vlan <number> -
Put the port in a VLAN (switches only)
Mode:
(config-if)# -
no switchport access vlan -
Put the port back in VLAN 1 (switches only)
Mode:
(config-if)# -
switchport trunk allowed vlan TEXT -
Which VLANs a trunk carries (switches only)
Mode:
(config-if)#
Routing and reachability
-
ip route A.B.C.D A.B.C.D A.B.C.D -
Add a static route: ip route <network> <mask> <next-hop>
Mode:
(config)# -
no ip route A.B.C.D A.B.C.D A.B.C.D -
Remove a static route
Mode:
(config)# -
show ip route -
IP routing table
Mode:
> # -
ip default-gateway A.B.C.D -
Default router for the switch itself (for management) (switches only)
Mode:
(config)# -
ping WORD -
Send echo messages
Mode:
> #
Passwords and access
-
hostname WORD -
Set system's network name
Mode:
(config)# -
enable secret WORD -
Set the (hashed) privileged mode password
Mode:
(config)# -
no enable secret -
Remove the enable secret
Mode:
(config)# -
enable password WORD -
Set the (unhashed) privileged mode password
Mode:
(config)# -
service password-encryption -
Encrypt plain-text passwords in the config
Mode:
(config)# -
no service password-encryption -
Stop encrypting passwords
Mode:
(config)# -
username WORD secret WORD -
Create a local user with a hashed password
Mode:
(config)# -
username WORD password WORD -
Create a local user
Mode:
(config)# -
banner motd TEXT -
Set Message of the Day banner
Mode:
(config)#
Console and remote lines
-
line console <number> -
Configure the console port
Mode:
(config)# or any sub-mode -
line vty <number> <number> -
Configure remote (Telnet/SSH) lines
Mode:
(config)# or any sub-mode -
password WORD -
Set the line password
Mode:
(config-line)# -
login -
Ask for the line password
Mode:
(config-line)# -
login local -
Ask for a local username and password
Mode:
(config-line)# -
no login -
Do not ask for a password
Mode:
(config-line)# -
transport input {ssh|telnet|all|none} -
Which protocols may connect (ssh is the secure choice)
Mode:
(config-line)#
SSH
-
ip domain-name WORD -
Define the default domain name
Mode:
(config)# -
ip domain name WORD -
Define the default domain name
Mode:
(config)# -
crypto key generate rsa modulus <number> -
Generate RSA keys (needed for SSH)
Mode:
(config)# -
ip ssh version <number> -
Specify the SSH protocol version
Mode:
(config)#
From localhostmonkey.com/learn/cheat-sheets/cisco/