Cisco IOS Commands

Cisco IOS for Catalyst switches and ISR routers. Any unique abbreviation works (conf t, sh ip int br), and ? lists what can come next.

Practice these in Terminal Practice

Modes

enable
Turn on privileged commands Mode: >
disable
Turn off privileged commands Mode: #
configure terminal
Enter configuration mode Mode: #
exit
Exit from the EXEC Mode: > # (config)# or any sub-mode
end
Exit to privileged EXEC mode Mode: (config)# or any sub-mode
logout
Exit from the EXEC Mode: > #

Looking around

show running-config
Current operating configuration Mode: #
show startup-config
Contents of startup configuration Mode: #
show version
System hardware and software status Mode: > #
show ip interface brief
Brief summary of IP status and configuration Mode: > #
show interfaces status
Show interface line status (switches only) Mode: > #
show interfaces INTERFACE
Interface status and configuration Mode: > #
show cdp neighbors
CDP neighbor entries Mode: > #
show mac address-table
MAC forwarding table (switches only) Mode: > #
show clock
Display the system clock Mode: > #
show history
Display the session command history Mode: > #
terminal length <number>
Set number of lines on a screen Mode: > #

Saving and reloading

copy running-config startup-config
Save the running configuration Mode: #
write memory
Write running configuration to memory (save) Mode: #
write
Write running configuration to memory (save) Mode: #
erase startup-config
Erase the saved configuration Mode: #
reload
Restart the device (loads the startup-config) Mode: #

Interfaces

interface INTERFACE
Select an interface to configure Mode: (config)# or any sub-mode
interface range TEXT
Configure several interfaces at once, e.g. interface range fa0/1 - 10 Mode: (config)# or any sub-mode
description TEXT
Interface specific description Mode: (config-if)#
ip address A.B.C.D A.B.C.D
Set the IP address and subnet mask Mode: (config-if)#
no ip address
Remove the IP address Mode: (config-if)#
shutdown
Shut down the interface Mode: (config-if)#
no shutdown
Turn the interface on Mode: (config-if)#

VLANs and trunks

vlan <number>
Create a VLAN and enter VLAN config mode (switches only) Mode: (config)# or any sub-mode
name WORD
Name the VLAN Mode: (config-vlan)#
no vlan <number>
Delete a VLAN (switches only) Mode: (config)#
show vlan brief
VTP all VLAN status in brief (switches only) Mode: > #
show vlan
VTP VLAN status (switches only) Mode: > #
switchport mode {access|trunk}
Set the port to access (one VLAN) or trunk (many VLANs) (switches only) Mode: (config-if)#
switchport access vlan <number>
Put the port in a VLAN (switches only) Mode: (config-if)#
no switchport access vlan
Put the port back in VLAN 1 (switches only) Mode: (config-if)#
switchport trunk allowed vlan TEXT
Which VLANs a trunk carries (switches only) Mode: (config-if)#

Routing and reachability

ip route A.B.C.D A.B.C.D A.B.C.D
Add a static route: ip route <network> <mask> <next-hop> Mode: (config)#
no ip route A.B.C.D A.B.C.D A.B.C.D
Remove a static route Mode: (config)#
show ip route
IP routing table Mode: > #
ip default-gateway A.B.C.D
Default router for the switch itself (for management) (switches only) Mode: (config)#
ping WORD
Send echo messages Mode: > #

Passwords and access

hostname WORD
Set system's network name Mode: (config)#
enable secret WORD
Set the (hashed) privileged mode password Mode: (config)#
no enable secret
Remove the enable secret Mode: (config)#
enable password WORD
Set the (unhashed) privileged mode password Mode: (config)#
service password-encryption
Encrypt plain-text passwords in the config Mode: (config)#
no service password-encryption
Stop encrypting passwords Mode: (config)#
username WORD secret WORD
Create a local user with a hashed password Mode: (config)#
username WORD password WORD
Create a local user Mode: (config)#
banner motd TEXT
Set Message of the Day banner Mode: (config)#

Console and remote lines

line console <number>
Configure the console port Mode: (config)# or any sub-mode
line vty <number> <number>
Configure remote (Telnet/SSH) lines Mode: (config)# or any sub-mode
password WORD
Set the line password Mode: (config-line)#
login
Ask for the line password Mode: (config-line)#
login local
Ask for a local username and password Mode: (config-line)#
no login
Do not ask for a password Mode: (config-line)#
transport input {ssh|telnet|all|none}
Which protocols may connect (ssh is the secure choice) Mode: (config-line)#

SSH

ip domain-name WORD
Define the default domain name Mode: (config)#
ip domain name WORD
Define the default domain name Mode: (config)#
crypto key generate rsa modulus <number>
Generate RSA keys (needed for SSH) Mode: (config)#
ip ssh version <number>
Specify the SSH protocol version Mode: (config)#

From localhostmonkey.com/learn/cheat-sheets/cisco/