This is the Cisco IOS command reference we wish we had as CCNA candidates: the commands you actually run every day, grouped by job, with real output captured on IOS XE 17.18 in our CML lab (a router, a switch, and a Linux host - no synthetic output anywhere). Bookmark it, then drill the ones you don't know.
Quick Reference: Most-Used Cisco Commands
enable · configure terminal · hostname · endshow ip interface brief · show version · show running-configinterface Gi1/0/1 · ip address · no shutdown · descriptionip route · router ospf 1 · show ip route · show ip ospf neighborshow vlan brief · show mac address-table · show interfaces statusping · traceroute · debug · copy run startModes and Navigation
enable ! user EXEC (>) to privileged EXEC (#)
configure terminal ! enter global configuration mode
exit ! back one mode level
end ! straight back to privileged EXEC from any depth
do show ip int br ! run an EXEC command from inside config modeThe do prefix is the one beginners miss: it saves you bouncing out of config mode every time you want to check something.
Device Identity and Saving
hostname R1 ! set the device name
banner motd #Authorized only# ! login banner
copy running-config startup-config ! save (write memory does the same)
show running-config ! full current config
show running-config | section ospf ! just one section of itNothing survives a reload until you copy running-config to startup-config. Make saving a reflex after every change window.
The Status-Check Trio
Three commands answer "what is this box and what state is it in". First, show version - platform, software version, uptime, and the reload reason:
R1# show version
Cisco IOS Software [IOSXE], Linux Software (X86_64BI_LINUX-ADVENTERPRISEK9-M),
Version 17.18.2, RELEASE SOFTWARE (fc3)
...
R1 uptime is 9 minutes
Configuration register is 0x0Second, show ip interface brief - every interface, its address, and its up/down state in one screen. This is the first command to run on any unfamiliar device:
R1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
Ethernet0/0 10.78.0.1 YES TFTP up up
Ethernet0/1 10.78.10.1 YES TFTP up up
Ethernet0/2 10.78.12.1 YES TFTP up up
Ethernet0/3 unassigned YES unset administratively down down
Loopback0 1.1.1.1 YES TFTP up upStatus is layer 1, Protocol is layer 2. "administratively down" means someone typed shutdown - the fix is no shutdown, not a cable swap.
Third, show cdp neighbors - what is physically attached (Cisco devices announce themselves via CDP):
R1# show cdp neighbors
Device ID Local Intrfce Holdtme Capability Platform Port ID
SW1 Eth 0/1 135 R S I Linux Uni Eth 0/0
R2 Eth 0/2 146 R Linux Uni Eth 0/0Interface Configuration
R1(config)# interface Ethernet0/1
R1(config-if)# description LINK-TO-SW1-VLAN10
R1(config-if)# ip address 10.78.10.1 255.255.255.0
R1(config-if)# no shutdownAlways set a description - it shows up in show interfaces status and show interfaces description, and future-you will be grateful. To inspect one interface in depth (errors, drops, rates):
R1# show interfaces Ethernet0/1
Ethernet0/1 is up, line protocol is up
Hardware is AmdP2, address is aabb.cc00.1010 (bia aabb.cc00.1010)
Description: LINK-TO-SW1-VLAN10
Internet address is 10.78.10.1/24
MTU 1500 bytes, BW 10000 Kbit/sec, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
...
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignoredThe lines you care about when troubleshooting: reliability/load, input errors, CRC, and collisions. Non-zero CRC on a fiber or copper link usually means physical-layer trouble.
Routing Commands
A static route needs a destination network, a mask, and a next hop (or exit interface):
R1(config)# ip route 192.168.50.0 255.255.255.0 10.78.12.2R1# show ip route static
S 192.168.50.0/24 [1/0] via 10.78.12.2Basic OSPF - one process, one network statement per range you want to advertise:
R1(config)# router ospf 1
R1(config-router)# network 10.78.0.0 0.0.255.255 area 0
R1(config-router)# network 1.1.1.1 0.0.0.0 area 0Verify with the neighbor table and the routing table:
R1# show ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
2.2.2.2 1 FULL/DR 00:00:38 10.78.12.2 Ethernet0/2
R1# show ip route ospf
O 2.2.2.2 [110/11] via 10.78.12.2, 00:13:48, Ethernet0/2FULL means the adjacency is complete. A neighbor stuck in EXSTART/EXCHANGE is classically an MTU mismatch (not a priority problem).
Switching Commands
On a switch, the MAC address table is the ground truth for "where is this device plugged in":
SW1# show mac address-table dynamic
Vlan Mac Address Type Ports
---- ----------- -------- -----
10 5254.006d.dcda DYNAMIC Et0/1
10 aabb.cc00.1010 DYNAMIC Et0/0SW1# show vlan brief
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active
10 Users active Et0/0, Et0/1, Et0/2
999 Parking active Et0/3And the spanning-tree state per VLAN (root bridge, port roles):
SW1# show spanning-tree vlan 10
VLAN0010
Spanning tree enabled protocol rstp
Root ID Priority 32778
Address aabb.cc00.1100
This bridge is the rootFor port state at a glance, show interfaces status is the fastest view on a switch - we cover reading every column of it in the show interfaces status guide.
Connectivity Testing
R1# ping 2.2.2.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
R1# traceroute 2.2.2.2 probe 1
Type escape sequence to abort.
Tracing the route to 2.2.2.2
1 10.78.12.2 1 msecEach ! is a reply; a . is a timeout; U means destination unreachable came back. For source-interface, size, and repeat-count control, type ping with no arguments to enter the extended ping dialog.
Debugging, Done Right
Debugs print live protocol events to the console. Scope them tightly (never debug all on production gear), and turn them off when done. A safe, useful example - watching ICMP while a host pings us:
R1# debug ip icmp
ICMP packet debugging is on
*Aug 23 23:42:31.928: ICMP: echo reply sent, src 10.78.10.1, dst 10.78.10.50,
topology BASE, dscp 0 topoid 0
*Aug 23 23:42:32.928: ICMP: echo reply sent, src 10.78.10.1, dst 10.78.10.50,
topology BASE, dscp 0 topoid 0
R1# undebug all
All possible debugging has been turned offundebug all (or u all) is the command to burn into muscle memory before you start any debug session.
Filtering Output
Every show command accepts an output filter on IOS - this is how you stay sane on devices with hundreds of interfaces:
show run | section router ospf ! one config section
show ip int brief | exclude unassigned
show vlan brief | include Users
show run | begin line vty ! everything from the first match on(On IOS the filter keyword is include, not grep - grep is NX-OS syntax.)
Security Quick Hits
username admin privilege 15 secret Pinglabz123 ! secret = hashed, use it
service password-encryption ! obscures line passwords
access-list 10 permit 10.78.0.0 0.0.0.255
line vty 0 4
access-class 10 in ! restrict remote access
transport input ssh ! SSH only, no telnet
login localThe full SSH setup (keys, users, verification) is in How to Enable SSH on Cisco Routers and Switches.
Efficiency Tips
- Tab completes any partial command;
?lists what can come next. - Commands can be abbreviated to uniqueness:
sh ip int br,conf t,wr. - Ctrl+A / Ctrl+E jump to start/end of line; Ctrl+Shift+6 aborts a stuck ping, traceroute, or DNS lookup.
terminal length 0disables paging when you are capturing output.
Frequently Asked Questions
What are the most essential Cisco commands for beginners?
Start with enable, configure terminal, show ip interface brief, show running-config, and copy running-config startup-config. Those five get you into the box, show you its state, and make your changes stick.
How do I save the configuration?
copy running-config startup-config (or the shorter write memory). Until you do, everything you configured disappears on reload.
Which commands are used for basic troubleshooting?
ping and traceroute for reachability, show ip interface brief for interface state, show ip route for path selection, and show interfaces for errors and drops. On switches, add show mac address-table and show interfaces status.
Key Takeaways
show ip interface brief,show version, andshow cdp neighborsprofile any unfamiliar device in under a minute.- Static routes need a next hop or exit interface -
ip route network mask next-hop. - Debug narrowly, and know
undebug allbefore you start. - Output filters (
| include,| section,| begin) are the difference between scrolling and finding. - Nothing is saved until
copy running-config startup-config.