Command cheat sheet
Command notes based primarily on Jeremy’s IT Lab CCNA learning videos, with examples, configuration modes, and day references.
Download original cheat sheet293 commands
No matching commands. Try another search.
CLI basics, interfaces & routing
?
Example:Router# ? —Displays available commands/options
command ?
Example:Router# show ? —Shows available options for a specific command
TAB
Example:Router# conf + TAB → configure —Auto-completes a partially typed command
enable
Example:Router> enable → Router# —Moves from User EXEC to Privileged EXEC
disable
Example:Router# disable → Router> —Moves from Privileged EXEC to User EXEC
configure terminal / conf t
Example:Router# conf t → Router(config)# —Enters Global Configuration Mode
exit
Example:Router(config)# exit → Router# —Moves back one CLI level
end
Example:Router(config-if)# end → Router# —Immediately returns to Privileged EXEC Mode
do
Example:Router(config)# do show ip interface brief —Runs a Privileged EXEC command while in configuration mode
enable password [pw]
Example:Router(config)# enable password cisco —Sets a password for entering Privileged EXEC mode
enable secret [pw]
Example:Router(config)# enable secret cisco —Sets an encrypted password for Privileged EXEC; preferred over enable password
service password-encryption
Example:Router(config)# service password-encryption —Encrypts plaintext passwords using weak Type 7 encryption
no service password-encryption
Example:Router(config)# no service password-encryption —Stops future automatic encryption of plaintext passwords
show running-config
Example:Router# show running-config —Displays the current active configuration
show startup-config
Example:Router# show startup-config —Displays the configuration saved in NVRAM for the next reboot
write / write memory
Example:Router# write memory —Saves running-config to startup-config
copy running-config startup-config
Example:Router# copy running-config startup-config —Copies the active configuration into startup configuration
no [command]
Example:Router(config)# no shutdown —Removes or disables a configuration command
show arp
Example:Router# show arp —Shows the device's ARP table
show mac address-table
Example:Switch# show mac address-table —Shows a switch's learned MAC address table
clear mac address-table dynamic
Example:Switch# clear mac address-table dynamic —Clears dynamically learned MAC- table entries
ping [ip]
Example:Router# ping 192.168.1.1 —Tests IP reachability using ICMP Echo messages
interface g0/0
Example:Router(config)# interface g0/0 → Router(config-if)# —Enters configuration mode for GigabitEthernet 0/0
ip address [ip] [mask]
Example:Router(config-if)# ip address 192.168.1.1 255.255.255.0 —Assigns an IPv4 address and subnet mask to an interface
show ip interface brief
Example:Router# show ip interface brief —Lists interfaces, IP addresses, assignment method, status, and protocol
show interfaces
Example:Router# show interfaces g0/0 —Shows detailed interface information, including Layer 1, Layer 2, and some Layer 3 details
show interfaces description
Example:Router# show interfaces description —Shows each interface's description
description [text]
Example:Router(config-if)# description WAN to ISP —Adds a label/note to an interface
show interfaces status
Example:Switch# show interfaces status —Shows port status, VLAN, duplex, speed, and interface type
no shutdown
Example:Router(config-if)# no shutdown —Administratively enables an interface
shutdown
Example:Router(config-if)# shutdown —Administratively disables an interface
interface range f0/5 -12
Example:Switch(config)# interface range f0/5 -12 —Enters configuration mode for FastEthernet 0/5 through 0/12 simultaneously
show ip route
Example:Router# show ip route —Displays the router's IPv4 routing table
ip route [network] [mask] [next-hop]
Example:Router(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2 —Creates a static route to a network using a next-hop IP address
ip route [network] [mask] [exit-interface]
Example:Router(config)# ip route 192.168.2.0 255.255.255.0 g0/1 —Creates a static route using an exit interface
ip route 0.0.0.0 0.0.0.0 [next-hop]
Example:Router(config)# ip route 0.0.0.0 0.0.0.0 10.0.0.2 —Configures an IPv4 default route
ip route 0.0.0.0 0.0.0.0 [exit-interface]
Example:Router(config)# ip route 0.0.0.0 0.0.0.0 g0/1 —Configures a default route using an exit interface
ip route [network] [mask] [next-hop] [exit- interface]
Example:Router(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2 g0/1 —Configures a static route using both a next-hop IP and exit interface
no ip route [network] [mask] ...
Example:Router(config)# no ip route 192.168.2.0 255.255.255.0 10.0.0.2 —Removes a configured static route
show ip route static
Example:Router# show ip route static —Displays only static routes in the routing table
show ip route connected
Example:Router# show ip route connected —Displays directly connected routes
show ip route 0.0.0.0
Example:Router# show ip route 0.0.0.0 —Checks routing information for the default route
show vlan brief
Example:Switch# show vlan brief —Displays VLANs configured on the switch and shows which access ports belong to each VLAN
vlan [vlan-id]
Example:Switch(config)# vlan 10 —Creates VLAN 10 if it does not already exist and enters VLAN configuration mode
name [name]
Example:Switch(config-vlan)# name SALES —Assigns a descriptive name to the VLAN
interface range [interfaces]
Example:Switch(config)# interface range f0/1 -10 —Selects multiple interfaces so they can be configured at the same time
switchport mode access
Example:Switch(config-if)# switchport mode access —Forces the switch interface to operate as an access port
switchport access vlan [vlan-id]
Example:Switch(config-if)# switchport access vlan 10 —Assigns an access port to VLAN 10
switchport trunk encapsulation dot1q
Example:Switch(config-if)# switchport trunk encapsulation dot1q —Sets the trunk encapsulation protocol to IEEE 802.1Q on switches that support multiple trunk encapsulation types
switchport mode trunk
Example:Switch(config-if)# switchport mode trunk —Manually configures the interface as a trunk port
show interfaces trunk
Example:Switch# show interfaces trunk —Displays interfaces currently operating as trunks, native VLANs, encapsulation, and allowed VLANs
switchport trunk allowed vlan [list]
Example:Switch(config-if)# switchport trunk allowed vlan 10,20,30 —Restricts the trunk so only the specified VLANs are allowed across it
switchport trunk allowed vlan add [list]
Example:Switch(config-if)# switchport trunk allowed vlan add 40 —Adds VLANs to the current allowed VLAN list without replacing the existing list
switchport trunk allowed vlan remove [list]
Example:Switch(config-if)# switchport trunk allowed vlan remove 20 —Removes VLANs from the trunk's allowed list
switchport trunk allowed vlan except [list]
Example:Switch(config-if)# switchport trunk allowed vlan except 30 —Allows all VLANs except the VLANs specified
switchport trunk allowed vlan none
Example:Switch(config-if)# switchport trunk allowed vlan none —Removes all VLANs from the trunk's allowed list
switchport trunk allowed vlan all
Example:Switch(config-if)# switchport trunk allowed vlan all —Allows all VLANs across the trunk
switchport trunk native vlan [vlan-id]
Example:Switch(config-if)# switchport trunk native vlan 99 —Changes the native VLAN used for untagged traffic on an 802.1Q trunk
interface g0/0.[subinterface]
Example:Router(config)# interface g0/0.10 —Creates/enters a router subinterface, commonly used for router-on-a-stick inter-VLAN routing
encapsulation dot1q [vlan-id]
Example:Router(config-subif)# encapsulation dot1q 10 —Associates the router subinterface with VLAN 10 using 802.1Q tagging
encapsulation dot1q [vlan-id] native
Example:Router(config-subif)# encapsulation dot1q 99 native —Associates the subinterface with the trunk's native VLAN
ip address [ip] [mask]
Example:Router(config-subif)# ip address 192.168.10.1 255.255.255.0 —Assigns the VLAN's default-gateway IP address to the router subinterface
Layer 3 Switching Commands
ip routing
Example:SW1(config)# ip routing —Enables Layer 3 IP routing on a multilayer switch, allowing it to route between networks/VLANs.
no switchport
Example:SW1(config-if)# no switchport —Converts a switch interface from a Layer 2 switchport into a Layer 3 routed port, allowing an IP address to be assigned directly to it.
Spanning Tree Verification Commands
show spanning-tree
Example:SW1# show spanning-tree —Displays STP information including root bridge, root ports, designated ports, costs, and port states.
show spanning-tree summary
Example:SW1# show spanning-tree summary —Displays a summarized overview of STP configuration and status.
show spanning-tree detail
Example:SW1# show spanning-tree detail —Displays detailed STP information, including topology changes and BPDU activity.
PortFast Commands
spanning-tree portfast
Example:SW1(config-if)# spanning-tree portfast —Enables PortFast on an interface. The port can transition to forwarding immediately instead of waiting through normal STP convergence. Typically used on end-device/access ports.
spanning-tree portfast default
Example:SW1(config)# spanning-tree portfast default —Enables PortFast by default on eligible access ports.
spanning-tree portfast disable
Example:SW1(config-if)# spanning-tree portfast disable —Explicitly disables PortFast on the interface.
spanning-tree portfast trunk
Example:SW1(config-if)# spanning-tree portfast trunk —Enables PortFast on a trunk interface. Use only when the trunk connects to an appropriate endpoint, not another switch.
BPDU Guard Commands
spanning-tree bpduguard enable
Example:SW1(config-if)# spanning-tree bpduguard enable —Enables BPDU Guard directly on an interface. If a BPDU is received, the port is typically placed into an err-disabledstate.
spanning-tree portfast bpduguard default
Example:SW1(config)# spanning-tree portfast bpduguard default —Globally enables BPDU Guard on PortFast-enabled ports.
show errdisable recovery
Example:SW1# show errdisable recovery —Displays err-disable recovery settings and reasons/interfaces associated with err-disable conditions.
Rapid PVST+ Command
spanning-tree mode rapid-pvst
Example:SW1(config)# spanning-tree mode rapid-pvst —Configures the switch to use Rapid PVST+, Cisco's per-VLAN implementation of Rapid Spanning Tree.
Root Bridge & STP Path Selection
spanning-tree vlan 1 root primary
Example:SW1(config)# spanning-tree vlan 1 root primary —Adjusts bridge priority to make the switch the preferred root bridgefor VLAN 1.
spanning-tree vlan 1 root secondary
Example:SW2(config)# spanning-tree vlan 1 root secondary —Adjusts bridge priority so the switch is preferred as the backup root bridge.
spanning-tree vlan 1 cost [cost]
Example:SW1(config-if)# spanning-tree vlan 1 cost 10 —Manually changes an interface's STP cost for VLAN 1, influencing STP's path selection.
spanning-tree vlan 1 port-priority [priority]
Example:SW1(config-if)# spanning-tree vlan 1 port-priority 64 —Changes STP port priority for VLAN 1, which can influence which port is selected when other criteria tie.
BPDU Filter
spanning-tree bpdufilter enable
Example:SW1(config-if)# spanning-tree bpdufilter enable —Enables BPDU filtering on an interface, preventing normal sending/processing of BPDUs. Use carefully because it can defeat STP's loop protection.
Root Guard
spanning-tree guard root
Example:SW1(config-if)# spanning-tree guard root —Enables Root Guard, preventing a neighboring switch from becoming the STP root through that interface.
Loop Guard
spanning-tree guard loop
Example:SW1(config-if)# spanning-tree guard loop —Enables Loop Guard on an interface. Helps prevent STP loops if expected BPDUs suddenly stop being received.
spanning-tree loopguard default
Example:SW1(config)# spanning-tree loopguard default —Globally enables Loop Guard on applicable point-to-point interfaces.
Rapid PVST
spanning-tree mode rapid-pvst
Example:SW1(config)# spanning-tree mode rapid-pvst —Enables Rapid PVST+, Cisco's per-VLAN implementation of Rapid Spanning Tree Protocol (RSTP).
spanning-tree portfast
Example:SW1(config-if)# spanning-tree portfast —Enables PortFast on an interface, allowing an edge/access port to transition to forwarding immediately. Typically used on ports connected to end devices.
spanning-tree link-type point-to-point
Example:SW1(config-if)# spanning-tree link-type point-to-point —Manually configures an RSTP interface as a point-to-point link, typically used for full-duplex switch-to-switch connections.
spanning-tree link-type shared
Example:SW1(config-if)# spanning-tree link-type shared —Manually configures an RSTP interface as a shared link, typically associated with half-duplex/shared Ethernet.
etherchannel -General
show etherchannel load-balance
Example:SW1# show etherchannel load-balance —Displays the load-balancing method currently being used by EtherChannel.
show etherchannel summary
Example:SW1# show etherchannel summary —Displays a summary of EtherChannels, including port-channel numbers, protocols, member interfaces, and their states.
show etherchannel port-channel
Example:SW1# show etherchannel port-channel —Displays detailed information about configured EtherChannel port-channel interfaces.
show etherhannel load-balance
port-channel load-balance src-dst-mac
Example:SW1(config)# port-channel load-balance src-dst-mac —Configures EtherChannel load balancing based on source and destination MAC addresses.
Layer 2 EtherChannel —Switch-to-Switch
interface range [interfaces]
Example:SW1(config)# interface range g0/1 -2 —Selects the physical interfaces that will become members of the EtherChannel.
channel-group 1 mode desirable
Example:SW1(config-if-range)# channel-group 1 mode desirable —Adds the selected interfaces to Port-Channel 1 using PAgP desirable mode.
channel-protocol pagp
Example:SW1(config-if-range)# channel-protocol pagp —Explicitly selects PAgP. Usually unnecessary because desirable/auto already indicates PAgP.
channel-protocol lacp
Example:SW1(config-if-range)# channel-protocol lacp —Explicitly selects LACP. Usually unnecessary because active/passive already indicates LACP.
interface port-channel 1
Example:SW1(config)# interface port-channel 1 —Enters configuration mode for the logical EtherChannel interface.
switchport trunk encapsulation dot1q
Example:SW1(config-if)# switchport trunk encapsulation dot1q —Configures the Port- Channel to use 802.1Q trunk encapsulation. Only required on switches that support multiple encapsulation types.
switchport mode trunk
Example:SW1(config-if)# switchport mode trunk —Makes the logical Port-Channel a Layer 2 trunk capable of carrying multiple VLANs.
Layer 3 EtherChannel —Multilayer Switch / Routed Connection
interface range [interfaces]
Example:SW1(config)# interface range g0/1 -2 —Selects the physical interfaces that will become members of the Layer 3 EtherChannel.
no switchport
Example:SW1(config-if-range)# no switchport —Converts the selected physical interfaces into Layer 3 routed interfaces.
channel-group 1 mode active
Example:SW1(config-if-range)# channel-group 1 mode active —Adds the interfaces to Port-Channel 1 using LACP.
interface port-channel 1
Example:SW1(config)# interface port-channel 1 —Enters configuration mode for the logical Layer 3 Port-Channel.
no switchport
Example:SW1(config-if)# no switchport —Configures the Port-Channel as a Layer 3 routed interface.
ip address [IP] [mask]
Example:SW1(config-if)# ip address 10.0.0.1 255.255.255.252 —Assigns an IPv4 address to the logical Layer 3 Port-Channel.
OSPF
router ospf [process-id]
Example:R1(config)# router ospf 1 —Enables OSPF and enters OSPF configuration mode. The process ID is locally significantand does nothave to match neighboring routers.
network [IP] [wildcard-mask] area [area-id] doing 0.0.0.0 255.255.255.255 works or just IP like 10.10.4.2 0.0.0.0
Example:R1(config-router)# network 10.0.0.0 0.0.0.255 area 0 —Identifies router interfaces whose IP addresses match the network/wildcard combination and enables OSPF on those interfaces. Also places those interfaces into the specified OSPF area.
passive-interface [interface] passive-interface default (will make all interfaces passive)
Example:R1(config-router)# passive-interface g0/1 —Stops OSPF Hello messages from being sent out the interface, preventing neighbor relationships from forming there. The connected network can still be advertised by OSPF. Typically used on interfaces connected to end-user LANs rather than other OSPF routers.
default-information originate After running this setup a default route on that router (i.g. if router 1 accesses the internet, setup 0.0.0.0 0.0.0.0 to the next hop
Example:R1(config-router)# default-information originate —Advertises a default route (0.0.0.0/0)into OSPF so neighboring OSPF routers can learn it. By default, the router must already have a default route in its routing table.
router-id [router-id]
Example:R1(config-router)# router-id 1.1.1.1 —Manually configures the router's OSPF Router ID, a 32-bit value written like an IPv4 address that uniquely identifies the OSPF router.
maximum-paths [number]
Example:R1(config-router)# maximum-paths 4 —Configures the maximum number of equal-cost OSPF routesthat can be installed in the routing table for load balancing.
distance [number]
Example:R1(config-router)# distance 100 —Changes the administrative distanceof OSPF routes. OSPF's default administrative distance is 110.
show ip protocols
Example:R1# show ip protocols —Displays information about the routing protocols currently running, including OSPF process ID, Router ID, advertised networks, passive interfaces, and administrative distance.
show ip ospf interface brief
clear ip ospf process
Example:R1# clear ip ospf process —Restarts the OSPF process. Useful after changing certain OSPF settings such as the Router ID. This temporarily tears down OSPF neighbor relationships.
OSPF Cost & Interface Commands — Day 27
auto-cost reference-bandwidth [Mbps]
Example:R1(config-router)# auto-cost reference-bandwidth 10000 —Changes the reference bandwidth OSPF uses to automatically calculate interface cost. Cost = Reference Bandwidth ÷ Interface Bandwidth.Configure the same reference bandwidth on all OSPF routers.
ip ospf cost [number]
Example:R1(config-if)# ip ospf cost 10 —Manually sets the OSPF cost of an interface, overriding the automatically calculated cost. Preferred method when you specifically want to change OSPF cost.
bandwidth [Kbps]
Example:R1(config-if)# bandwidth 100000 —Changes the interface's logical bandwidth value, which can affect OSPF's automatic cost calculation. It does notchange the interface's actual physical speed.
show ip ospf neighbor
Example:R1# show ip ospf neighbor —Displays OSPF neighbors, including Router ID, priority, neighbor state, dead timer, neighbor IP address, and local interface.
ip ospf [process-id] area [area-id]
Example:R1(config-if)# ip ospf 1 area 0 —Enables OSPF directly on an interface and places it in the specified area. This is an alternative to using the OSPF network command.
OSPF DR/BDR & Network Commands — Day 28
ip ospf priority [number]
Example:R1(config-if)# ip ospf priority 200 —Changes an interface's OSPF priority for DR/BDR elections. Higher priority is preferred. 0 makes the router ineligible to become DR or BDR on that interface.
show ip ospf database
Example:R1# show ip ospf database —Displays the OSPF Link-State Database (LSDB)and the LSAs known by the router.
ip ospf network [type]
Example:R1(config-if)# ip ospf network point-to-point —Changes the OSPF network type used on an interface, affecting neighbor behavior and whether DR/BDR elections occur.
OSPF Authentication Commands — Day 28
ip ospf authentication
Example:R1(config-if)# ip ospf authentication —Enables simple/plain-text OSPF authenticationon the interface. Neighboring routers must use compatible authentication settings.
ip ospf authentication-key [password]
Example:R1(config-if)# ip ospf authentication-key cisco —Configures the password used for simple OSPF authentication on the interface.
Serial Interface Commands —Day 28
clock rate [bps]
Example:R1(config-if)# clock rate 128000 —Configures the clock rate on the DCE sideof a serial connection. The DCE device provides clocking to the link.
encapsulation ppp
Example:R1(config-if)# encapsulation ppp —Changes the serial interface's Layer 2 encapsulation to PPP. Cisco serial interfaces traditionally default to HDLC.
show controllers [interface]
Example:R1# show controllers serial 0/0/0 —Displays hardware/controller information about an interface. On serial links, it can be used to determine which side is DCE or DTE.
MTU Commands —Day 28
ip mtu [bytes]
Example:R1(config-if)# ip mtu 1400 —Changes the maximum size of an IP packet that can be sent without fragmentation on the interface. OSPF neighbors need compatible MTU settings to successfully form a full adjacency.
IPv6 Commands —Day 31–32
ipv6 unicast-routing
Example:R1(config)# ipv6 unicast-routing —Enables the router to forward IPv6 packets between interfaces. Required for IPv6 routing.
ipv6 address [address/prefix]
Example:R1(config-if)# ipv6 address 2001:db8:1::1/64 —Manually assigns an IPv6 address and prefix length to an interface.
show ipv6 interface brief
Example:R1# show ipv6 interface brief —Displays a summary of interfaces, their status, and assigned IPv6 addresses.
ipv6 address [prefix] eui-64
Example:R1(config-if)# ipv6 address 2001:db8:1::/64 eui-64 —Automatically generates the interface ID portion of the IPv6 address using modified EUI-64.
Standard Numbered ACLs —Day 34
access-list [number] permit [source] [wildcard]
Example:R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255 —Creates a numbered standard ACLentry permitting traffic based only on the source IPv4 address. Standard ACL numbers are commonly 1–99 or 1300–1999.
access-list [number] deny [source] [wildcard]
Example:R1(config)# access-list 1 deny 192.168.1.0 0.0.0.255 —Creates a standard ACL entry denying traffic from the specified source network.
access-list [number] permit any
Example:R1(config)# access-list 1 permit any —Permits traffic from any source IPv4 address. any is shorthand for 0.0.0.0 255.255.255.255.
access-list [number] remark [text]
Example:R1(config)# access-list 1 remark ALLOW-SALES-LAN —Adds a description/comment to an ACL to document its purpose.
show access-lists
Example:R1# show access-lists —Displays configured ACLs, their entries, sequence numbers, and match counters.
show ip access-lists
Example:R1# show ip access-lists —Displays configured IPv4 ACLsand their entries.
ip access-group [ACL] in
Example:R1(config-if)# ip access-group 1 in —Applies an IPv4 ACL to traffic enteringan interface.
ip access-group [ACL] out
Example:R1(config-if)# ip access-group 1 out —Applies an IPv4 ACL to traffic leavingan interface.
Named Standard ACLs —Day 35
ip access-list standard [name]
Example:R1(config)# ip access-list standard BLOCK-SALES —Creates a named standard IPv4 ACLand enters Standard Named ACL configuration mode.
[sequence] permit [source] [wildcard]
Example:R1(config-std-nacl)# 10 permit 192.168.1.0 0.0.0.255 —Creates a permit ACE with a specific sequence number.
[sequence] deny [source] [wildcard]
Example:R1(config-std-nacl)# 20 deny 192.168.2.0 0.0.0.255 —Creates a deny ACE with a specific sequence number.
no [sequence]
Example:R1(config-std-nacl)# no 10 —Removes the ACL entry with that sequence number without deleting the entire ACL.
ip access-list resequence [ACL] [starting-sequence] [increment]
Example:R1(config)# ip access-list resequence BLOCK-SALES 10 10 —Renumbers ACL entries beginning at sequence 10 and increasing by 10.
Extended ACLs —Day 35
access-list [number] permit [protocol] [source] [destination]
Example:R1(config)# access-list 100 permit ip 192.168.1.0 0.0.0.255 any —Creates a numbered extended ACLpermitting traffic based on protocol, source, and destination.
access-list [number] deny [protocol] [source] [destination]
Example:R1(config)# access-list 100 deny tcp 192.168.1.0 0.0.0.255 any —Creates an extended ACL denying matching traffic based on protocol, source, and destination.
ip access-list extended [name]
Example:R1(config)# ip access-list extended WEB-FILTER —Creates a named extended IPv4 ACLand enters Extended Named ACL configuration mode.
eq [port]
Example:R1(config-ext-nacl)# permit tcp any any eq 443 —Matches traffic with a port equal tothe specified value.
gt [port]
Example:R1(config-ext-nacl)# permit tcp any any gt 1023 —Matches ports greater than the specified value.
lt [port]
Example:R1(config-ext-nacl)# permit tcp any any lt 1024 —Matches ports less thanthe specified value.
neq [port]
Example:R1(config-ext-nacl)# permit tcp any any neq 22 —Matches ports not equal to the specified value.
range [start] [end]
Example:R1(config-ext-nacl)# permit tcp any any range 20 21 —Matches a range of TCP or UDP port numbers.
CDP Verification Commands —Day 36
show cdp
Example:SW1# show cdp —Displays global CDP information including timers, holdtime, and CDP version.
show cdp traffic
Example:SW1# show cdp traffic —Displays statistics for CDP packets sent and received.
show cdp interface
Example:SW1# show cdp interface —Displays CDP information and status for CDP- enabled interfaces.
show cdp neighbors
Example:SW1# show cdp neighbors —Displays directly connected Cisco neighbors including Device ID, local interface, capabilities, platform, and remote Port ID.
show cdp neighbors detail
Example:SW1# show cdp neighbors detail —Displays detailed information about CDP neighbors, including IP addresses, software/platform information, interfaces, and other advertised information.
show cdp entry [device-id]
Example:SW1# show cdp entry R1 —Displays detailed CDP information about a specific neighbor.
CDP Configuration Commands —Day 36
cdp run
Example:SW1(config)# cdp run —Enables CDP globallyon the device.
no cdp run
Example:SW1(config)# no cdp run —Disables CDP globally on the device.
cdp enable
Example:SW1(config-if)# cdp enable —Enables CDP on a specific interface.
no cdp enable
Example:SW1(config-if)# no cdp enable —Disables CDP on a specific interface.
cdp timer [seconds]
Example:SW1(config)# cdp timer 30 —Changes how frequently the device sends CDP advertisements.
cdp holdtime [seconds]
Example:SW1(config)# cdp holdtime 90 —Changes how long received CDP information is retained before being discarded.
cdp advertise-v2
Example:SW1(config)# cdp advertise-v2 —Enables CDP Version 2 advertisements.
LLDP Verification Commands —Day 36
show lldp
Example:SW1# show lldp —Displays global LLDP information including timers and status.
show lldp traffic
Example:SW1# show lldp traffic —Displays statistics for LLDP frames sent and received.
show lldp interface
Example:SW1# show lldp interface —Displays LLDP transmit/receive status and information for interfaces.
show lldp neighbors
Example:SW1# show lldp neighbors —Displays directly connected LLDP neighbors including Device ID, local interface, capabilities, and remote Port ID.
show lldp neighbors detail
Example:SW1# show lldp neighbors detail —Displays detailed information learned about all LLDP neighbors.
show lldp entry [device-id]
Example:SW1# show lldp entry R1 —Displays detailed LLDP information about a specific neighbor.
LLDP Configuration Commands —Day 36
lldp run
Example:SW1(config)# lldp run —Enables LLDP globallyon the device.
no lldp run
Example:SW1(config)# no lldp run —Disables LLDP globally.
lldp transmit
Example:SW1(config-if)# lldp transmit —Enables transmission of LLDP advertisements on the interface.
lldp receive
Example:SW1(config-if)# lldp receive —Enables receiving LLDP advertisements on the interface.
lldp timer [seconds]
Example:SW1(config)# lldp timer 30 —Configures how frequently LLDP advertisements are sent.
lldp holdtime [seconds]
Example:SW1(config)# lldp holdtime 120 —Configures the LLDP holdtime advertised to neighboring devices.
lldp reinit [seconds]
Example:SW1(config)# lldp reinit 2 —Configures the delay before LLDP is reinitialized on an interface.
NTP Verification Commands
show clock
Example:R1# show clock —Displays the device's current software clock time and date.
show clock detail
Example:R1# show clock detail —Displays detailed software clock information, including the configured time source and timezone information.
show ntp status
Example:R1# show ntp status —Displays general NTP status, including whether the device is synchronized, its stratum, reference clock, and timing information.
show ntp associations
Example:R1# show ntp associations —Displays configured NTP peers/servers and their synchronization status.
Manual Clock & Calendar Commands
clock set [hh:mm:ss] [day] [month] [year]
Example:R1# clock set 12:30:00 14 September 2026 —Manually sets the device's software clock.
calendar set [hh:mm:ss] [day] [month] [year]
Example:R1# calendar set 12:30:00 14 September 2026 —Manually sets the device's hardware calendaron devices that support one.
clock update-calendar
Example:R1# clock update-calendar —Copies the current software clock → hardware calendar.
clock read-calendar
Example:R1# clock read-calendar —Copies the hardware calendar → software clock.
Timezone & Daylight Saving Commands
clock timezone [name] [hours-offset] [minutes- offset]
Example:R1(config)# clock timezone EST -5 —Configures the device's timezone and its offset from UTC.
clock summer-time [name] recurring [start] [end] [offset]
Example:R1(config)# clock summer-time EDT recurring —Configures recurring daylight saving/summer time. Additional arguments can specify exactly when DST starts and ends.
NTP Client Commands
ntp server [ip-address]
Example:R2(config)# ntp server 10.0.0.1 —Configures an NTP server that this device will use to synchronize its clock.
ntp server [ip-address] prefer
Example:R2(config)# ntp server 10.0.0.1 prefer —Configures an NTP server and marks it as the preferredserver when multiple NTP servers are available.
ntp source [interface]
Example:R2(config)# ntp source loopback0 —Configures the specified interface's address as the source address for NTP packets.
ntp update-calendar
Example:R2(config)# ntp update-calendar —Configures the device to periodically update its hardware calendar using the NTP-synchronized software clock.
NTP Server & Peer Commands
ntp master [stratum]
Example:R1(config)# ntp master 5 —Configures the Cisco device to act as an NTP master/server. The optional value specifies the stratum advertised by the device.
ntp peer [ip-address]
Example:R1(config)# ntp peer 10.0.0.2 —Configures a symmetric NTP peer relationship with another device.
ntp peer [ip-address] key [number]
Example:R1(config)# ntp peer 10.0.0.2 key 1 —Configures an NTP peer and specifies the authentication key to use.
NTP Authentication Commands
ntp authenticate
Example:R1(config)# ntp authenticate —Globally enables NTP authentication.
ntp authentication-key [number] md5 [key]
Example:R1(config)# ntp authentication-key 1 md5 CCNA —Creates an NTP authentication key using the specified key number and password.
ntp trusted-key [number]
Example:R1(config)# ntp trusted-key 1 —Marks the specified NTP authentication key as trusted.
ntp server [ip-address] key [number]
Example:R2(config)# ntp server 10.0.0.1 key 1 —Configures an NTP server and specifies the authentication key used when communicating with it.
DNS Verification Commands
show hosts
Example:R1# show hosts —Displays configured hostname-to-IP mappings as well as hostnames learned and cached through DNS.
DNS Configuration Commands
ip dns server
Example:R1(config)# ip dns server —Configures the Cisco device to act as a DNS server and answer DNS queries.
ip domain lookup
Example:R1(config)# ip domain lookup —Enables the device to perform DNS hostname lookups. DNS lookup is normally enabled by default.
no ip domain lookup
Example:R1(config)# no ip domain lookup —Disables DNS hostname lookups. Useful in labs to prevent IOS from trying to resolve mistyped commands as hostnames.
ip host [hostname] [IP]
Example:R1(config)# ip host SERVER1 192.168.1.10 —Creates a static hostname-to-IP address mappingin the local host table.
ip name-server [IP]
Example:R1(config)# ip name-server 8.8.8.8 —Configures the IP address of a DNS server the device can query to resolve hostnames.
ip domain name [domain]
Example:R1(config)# ip domain name example.com —Configures the device's default domain name. Also commonly used when configuring SSH.
DHCP Show Commands
show ip dhcp binding
Example:R1# show ip dhcp binding —Displays DHCP clients that currently have IP addresses assigned by the router's DHCP server.
DHCP Global Config Commands
ip dhcp excluded-address [low-address] [high- address]
Example:R1(config)# ip dhcp excluded-address 192.168.1.1 192.168.1.10 —Excludes a range of addresses from being assigned to DHCP clients.
ip dhcp pool [pool-name]
Example:R1(config)# ip dhcp pool LAN —Creates a DHCP pool and enters DHCP Pool Configuration mode. If the pool already exists, enters its configuration.
network [network] [subnet-mask]
Example:R1(dhcp-config)# network 192.168.1.0 255.255.255.0 —Specifies the subnet from which DHCP addresses will be assigned. Excluded addresses will not be given to clients.
lease [days] [hours] [minutes]
Example:R1(dhcp-config)# lease 7 —Configures how long DHCP clients can keep their assigned addresses.
lease infinite
Example:R1(dhcp-config)# lease infinite —Configures DHCP leases so they do not expire.
default-router [IP]
Example:R1(dhcp-config)# default-router 192.168.1.1 —Specifies the default gateway provided to DHCP clients.
dns-server [IP]
Example:R1(dhcp-config)# dns-server 8.8.8.8 —Specifies the DNS server address provided to DHCP clients.
domain-name [domain]
Example:R1(dhcp-config)# domain-name example.com —Specifies the domain name provided to DHCP clients.
option 43 ip [IP]
Example:R1(dhcp-config)# option 43 ip 10.0.0.10 —Configures DHCP Option 43. Cisco APs can use this option to learn the IP address of their Wireless LAN Controller (WLC).
DHCP Interface Commands
ip helper-address [IP]
Example:R1(config-if)# ip helper-address 10.0.0.10 —Configures the interface to act as a DHCP relay, forwarding client DHCP broadcasts toward a DHCP server on another network. Configure it on the interface facing the DHCP clients.
ip address dhcp
Example:R1(config-if)# ip address dhcp —Configures the router interface to act as a DHCP clientand obtain its own IPv4 address automatically from a DHCP server.
SNMP Configuration Commands
snmp-server contact [contact-info]
Example:R1(config)# snmp-server contact Network-Admin —Configures contact information for the person responsible for the SNMP-managed device.
snmp-server location [location-info]
Example:R1(config)# snmp-server location Server-Room —Configures a description of the physical location of the SNMP-managed device.
snmp-server community [string] ro
Example:R1(config)# snmp-server community CCNA ro —Configures an SNMP community string with read-only (RO)access. The NMS can read information but cannot modify it.
snmp-server community [string] rw
Example:R1(config)# snmp-server community CCNA rw —Configures an SNMP community string with read-write (RW)access. The NMS can read and modify information.
snmp-server host [IP] version 2c [community- string]
Example:R1(config)# snmp-server host 192.168.1.100 version 2c CCNA —Specifies the NMSthat will receive SNMP notifications, using SNMPv2c and the specified community string.
snmp-server enable traps [trap-types]
Example:R1(config)# snmp-server enable traps link —Enables specified SNMP trap/notification typesto be sent to the configured NMS.
Syslog Privileged Commands
terminal monitor
Example:R1# terminal monitor —Displays Syslog messages in the current VTY session (SSH/Telnet). Must be enabled again when a new remote session is established.
Syslog Configuration Commands
logging console [level]
Example:R1(config)# logging console warnings —Sets the minimum Syslog severity level displayed on the console connection.
logging monitor [level]
Example:R1(config)# logging monitor warnings —Sets the Syslog severity level that can be displayed on VTY (SSH/Telnet) sessionswhen terminal monitor is enabled.
logging buffered [size] [level]
Example:R1(config)# logging buffered 16384 warnings —Stores Syslog messages in the device's RAM logging buffer. Optional size is specified in bytes.
logging trap [level]
Example:R1(config)# logging trap warnings —Sets the Syslog severity level sent to configured external Syslog servers.
logging [IP]
Example:R1(config)# logging 192.168.1.100 —Configures an external Syslog server to receive logging messages.
logging synchronous
Example:R1(config-line)# logging synchronous —Prevents Syslog messages from disrupting commands you are typing by redisplaying the prompt/input on a new line.
service sequence-numbers
Example:R1(config)# service sequence-numbers —Adds sequence numbers to Syslog messages, making it easier to determine their order.
service timestamps log datetime
Example:R1(config)# service timestamps log datetime —Adds the current date and time to Syslog messages.
service timestamps log uptime
Example:R1(config)# service timestamps log uptime —Adds the amount of time since the device booted to Syslog messages.
SSH —Day 42
hostname [name] ip domain name [domain]
Example:R1(config)# hostname R1 / R1(config)# ip domain name example.com — Configures the device hostname and domain name. Both are needed before generating the RSA keys used by SSH.
username [username] secret [password]
Example:R1(config)# username admin secret CCNA123 —Creates a local username and encrypted secret for authentication. Used with login local.
crypto key generate rsa
Example:R1(config)# crypto key generate rsa —Generates the RSA key pair used by SSH. Requires a hostname and domain name to be configured first.
ip ssh version [1|2]
Example:R1(config)# ip ssh version 2 —Configures the SSH version. SSHv2 is preferred because SSHv1 is obsolete and insecure.
line vty [line] line vty [start] [end]
Example:R1(config)# line vty 0 15 —Enters VTY line configuration mode. VTY lines are used for remote CLI connections such as SSH and Telnet.
login login local
Example:R1(config-line)# login local —login authenticates using the password configured directly on the VTY line. login local authenticates using the device's local username/password databaseand is commonly used for SSH.
transport input [protocols]
Examples:R1(config-line)# transport input ssh / transport input ssh telnet / transport input none —Controls which remote-access protocols are permitted on the VTY lines. transport input ssh is preferredbecause it prevents insecure Telnet access.
exec-timeout [minutes] [seconds]
Example:R1(config-line)# exec-timeout 5 0 —Automatically disconnects the remote session after the specified period of inactivity.
access-class [ACL] in
Example:R1(config-line)# access-class 10 in —Applies an ACL to incoming VTY connections to control which source IP addresses are allowed to remotely access the device.
ip default-gateway [IP]
Example:SW1(config)# ip default-gateway 192.168.1.1 —Configures a default gateway on a Layer 2 switchso the switch's management IP can communicate with SSH clients on other networks. Not normally needed on a router or multilayer switch performing IP routing.
show ip ssh show version
Example:R1# show ip ssh / R1# show version —show ip ssh verifies the SSH configuration, version, timeout, and retries. show version displays IOS/device information.
FTP / TFTP —Day 43
show file systems
Example:R1# show file systems —Displays available file systems and storage locations on the device. Useful first to identify locations such as flash:.
show flash
Example:R1# show flash —Displays the contents of Flash memory. Use this to verify the IOS image/file you want to copy or check available storage.
show version
Example:R1# show version —Displays the currently running IOS version and image along with device, uptime, memory, and boot information.
ip ftp username [username] ip ftp password [password]
Example:R1(config)# ip ftp username admin / R1(config)# ip ftp password CCNA123 — Configures the credentials the Cisco device will use when connecting to an FTP server. FTP only; TFTP does not use authentication.
copy [source] [destination]
Examples:R1# copy tftp: flash: / R1# copy ftp: flash: / R1# copy flash: tftp: / R1# copy flash: ftp: / R1# copy running-config tftp: / R1# copy tftp: running-config —Copies files or configurations between the Cisco device and another location. Source comes first, destination second.
delete [file-path]
Example:R1# delete flash:old-ios.bin —Deletes a specified file. Commonly used to remove an old IOS image or unwanted file from Flash.
boot system [file-path]
Example:R1(config)# boot system flash:cisco-ios.bin —Configures which IOS image the device should attempt to load during its next boot.
NAT —Day 44
ip nat inside ip nat outside
Example:R1(config-if)# ip nat inside / R1(config-if)# ip nat outside —Identifies which router interfaces connect to the inside/private networkand which connect to the outside/public network.
ip nat inside source static [inside-local] [inside- global]
Example:R1(config)# ip nat inside source static 192.168.1.10 203.0.113.10 —Configures Static NAT, creating a permanent one-to-one mapping between an inside local (private) address and an inside global (public) address.
show ip nat translations show ip nat statistics
Example:R1# show ip nat translations / R1# show ip nat statistics —translations displays the NAT translation table. statistics displays NAT activity, configured interfaces, pools, and translation statistics.
clear ip nat translation *
Example:R1# clear ip nat translation * —Clears all dynamic NAT/PAT translationsfrom the NAT translation table.
NAT Part 2 —Day 45
ip nat inside ip nat outside
Example:R1(config-if)# ip nat inside / R1(config-if)# ip nat outside —Identifies interfaces as inside(private/internal network) or outside(public/external network) for NAT.
ip nat inside source static [inside-local] [inside- global]
Example:R1(config)# ip nat inside source static 192.168.1.10 203.0.113.10 —Configures Static NAT, permanently mapping one inside local/private address to one inside global/public address.
access-list [ACL] permit [source] [wildcard]
Example:R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255 —Identifies the inside/local addresses that are eligible to be translated by Dynamic NAT or PAT.
ip nat pool [name] [start-IP] [end-IP] netmask [mask] ip nat pool [name] [start-IP] [end-IP] prefix- length [prefix]
Example:R1(config)# ip nat pool PUBLIC 203.0.113.10 203.0.113.20 netmask 255.255.255.0 —Creates a pool of inside global/public addressesfor Dynamic NAT or PAT.
ip nat inside source list [ACL] pool [pool] ip nat inside source list [ACL] pool [pool] overload
Example:R1(config)# ip nat inside source list 1 pool PUBLIC / R1(config)# ip nat inside source list 1 pool PUBLIC overload —Connects the ACL to the NAT pool. Without overload = Dynamic NAT. With overload = PAT, allowing multiple inside hosts to share addresses using port numbers.
ip nat inside source list [ACL] interface [interface] overload
Example:R1(config)# ip nat inside source list 1 interface g0/1 overload —Configures PAT using the outside interface's IP address. Multiple inside devices can share a single public IPv4 address using different port numbers.
PoE / Power Policing —Day 46
power inline police power inline police action err- disable power inline police action log
Example:SW1(config-if)# power inline police —Enables PoE power policing on the interface. Default/err-disable action places the port into err-disabled stateif the powered device (PD) exceeds its allowed power. action log instead generates a Syslog message and restarts power to the device rather than err-disabling the port.
show power inline police [interface]
Example:SW1# show power inline police g0/1 —Displays PoE power-policing information for the specified interface, including power usage and policing status.
Voice VLAN / VoIP —Day 46
switchport mode access switchport access vlan [data-vlan]
Example:SW1(config-if)# switchport mode access / SW1(config-if)# switchport access vlan 10 —Configures the switchport as an access port and assigns normal data trafficto the specified access VLAN.
switchport voice vlan [voice-vlan]
Example:SW1(config-if)# switchport voice vlan 20 —Assigns traffic from an attached IP phoneto the specified voice VLAN. Voice traffic is tagged with the voice VLAN ID while a connected PC can use the regular access/data VLAN.
Port Security —Day 49
switchport mode access switchport mode trunk
Example:SW1(config-if)# switchport mode access —Statically configures the switchport's mode. Port security requires the port to be statically configured as an access or trunk port rather than a dynamic port. Most CCNA examples use access ports.
switchport port-security
Example:SW1(config-if)# switchport port-security —Enables port security on the interface.
switchport port-security maximum [number]
Example:SW1(config-if)# switchport port-security maximum 2 —Sets the maximum number of secure MAC addresses allowed on the interface. Default = 1.
switchport port-security mac-address [MAC] switchport port-security mac-address sticky switchport port-security mac-address sticky [MAC]
Example:SW1(config-if)# switchport port-security mac-address sticky —Controls which MAC addresses are considered secure. A MAC can be manually configured, or sticky can dynamically learn MAC addresses and add them to the running configuration as sticky secure MACs.
switchport port-security violation shutdown switchport port-security violation restrict switchport port-security violation protect
Example:SW1(config-if)# switchport port-security violation restrict —Configures what happens when an unauthorized MAC causes a violation. Shutdownerr-disables the port, restrictdrops offending traffic while counting/logging violations, and protectdrops offending traffic with less notification. Shutdown is the default.
switchport port-security aging time [minutes] switchport port-security aging type absolute switchport port-security aging type inactivity switchport port-security aging static
Example:SW1(config-if)# switchport port-security aging time 60 / switchport port-security aging type inactivity —Configures secure MAC aging. absolute ages entries after the configured time regardless of activity; inactivity ages them after being inactive. aging static allows statically configured secure MAC addresses to age.
errdisable recovery cause psecure-violation errdisable recovery cause dhcp-rate-limit errdisable recovery cause arp-inspection
Example:SW1(config)# errdisable recovery cause psecure-violation —Allows the switch to automatically recover ports that were err-disabled by the specified cause. These causes correspond to Port Security, DHCP Snooping, and Dynamic ARP Inspection.
errdisable recovery interval [seconds]
Example:SW1(config)# errdisable recovery interval 300 —Configures how long an interface remains err-disabled before the switch attempts automatic recovery for enabled recovery causes.
show port-security show port-security interface [interface]
Example:SW1# show port-security / SW1# show port-security interface f0/1 —Displays overall port-security information or detailed information for a specific interface, including status, violation mode, maximum MACs, secure MACs, and violation count.
show mac address-table secure
Example:SW1# show mac address-table secure —Displays secure MAC addresses learned or configured through port security.
show errdisable recovery
Example:SW1# show errdisable recovery —Displays configured err-disable recovery causes, timers, and interfaces currently waiting for recovery.
DHCP Snooping —Day 50
ip dhcp snooping ip dhcp snooping vlan [vlan-id]
Example:SW1(config)# ip dhcp snooping / SW1(config)# ip dhcp snooping vlan 10 — Enables DHCP Snooping globally and then for the specified VLAN. Both are required.
no ip dhcp snooping information option
Example:SW1(config)# no ip dhcp snooping information option —Disables insertion of DHCP Option 82information into DHCP messages.
ip dhcp snooping trust
Example:SW1(config-if)# ip dhcp snooping trust —Marks the interface as trusted, allowing DHCP server messages such as Offer and ACK through it. Typically configured toward the legitimate DHCP server/uplink. Ports are untrusted by default.
ip dhcp snooping limit rate [pps]
Example:SW1(config-if)# ip dhcp snooping limit rate 15 —Limits the number of DHCP messages allowed per second on the interface. Exceeding the configured rate can cause the interface to become err-disabled. Commonly configured on untrusted/client-facing ports.
errdisable recovery cause dhcp-rate-limit errdisable recovery interval [seconds]
Example:SW1(config)# errdisable recovery cause dhcp-rate-limit / SW1(config)# errdisable recovery interval 300 —Allows a port err-disabled because of a DHCP rate-limit violation to automatically recover after the configured interval.
show ip dhcp snooping binding
Example:SW1# show ip dhcp snooping binding —Displays the DHCP Snooping binding table, which maps learned client MAC addresses to IP addresses, VLANs, interfaces, and lease information.
Dynamic ARP Inspection (DAI) —Day 51
ip arp inspection vlan [vlan-id]
Example:SW1(config)# ip arp inspection vlan 10 —Enables Dynamic ARP Inspection (DAI) for the specified VLAN. DAI normally uses the DHCP Snooping binding tableto determine whether ARP messages are legitimate.
ip arp inspection validate src-mac ip arp inspection validate dst-mac ip arp inspection validate ip ip arp inspection validate src-mac dst-mac ip
Example:SW1(config)# ip arp inspection validate src-mac dst-mac ip —Enables additional ARP validation. src-mac checks the Ethernet source MAC against the ARP sender MAC, dst- mac checks the Ethernet destination MAC against the ARP target MAC where applicable, and ip checks for invalid/unacceptable IP addresses in ARP packets. Multiple checks can be enabled in one command.
arp access-list [name] permit ip host [IP] mac host [MAC] deny ip host [IP] mac host [MAC]
Example:SW1(config)# arp access-list STATIC-HOSTS → SW1(config-arp-nacl)# permit ip host 192.168.1.10 mac host 0011.2233.4455 —Creates an ARP ACLand permits/denies specific IP-to-MAC mappings. Useful for hosts with static IP addresses that aren't represented in the DHCP Snooping binding table.
ip arp inspection filter [arp-acl] vlan [vlan-id]
Example:SW1(config)# ip arp inspection filter STATIC-HOSTS vlan 10 —Applies an ARP ACL to DAI for the specified VLAN.
ip arp inspection trust
Example:SW1(config-if)# ip arp inspection trust —Marks an interface as trustedfor DAI. ARP messages received on trusted interfaces bypass normal DAI inspection. Interfaces are untrusted by default. Typically used on appropriate infrastructure/uplink ports.
ip arp inspection limit rate [pps] burst interval [seconds]
Example:SW1(config-if)# ip arp inspection limit rate 15 burst interval 1 —Limits the number of ARP packets allowed on the interface during the specified interval. Exceeding the limit can place the interface into err-disabledstate.
errdisable recovery cause arp-inspection errdisable recovery interval [seconds]
Example:SW1(config)# errdisable recovery cause arp-inspection / SW1(config)# errdisable recovery interval 300 —Enables automatic recovery for ports err-disabled by an ARP inspection rate violation and specifies how long the switch waits before attempting recovery.
show ip arp inspection show ip arp inspection interfaces
Example:SW1# show ip arp inspection / SW1# show ip arp inspection interfaces — Displays DAI configuration/statistics and the DAI status, trust state, and rate information for interfaces.
