CCNA study notes / Commands
CCNA QUICK REFERENCE

Command cheat sheet

Command notes based primarily on Jeremy’s IT Lab CCNA learning videos, with examples, configuration modes, and day references.

Download original cheat sheet

293 commands

CLI basics, interfaces & routing

?

Example:Router# ? —Displays available commands/options

User EXEC > or Privileged EXEC #Day 4

command ?

Example:Router# show ? —Shows available options for a specific command

Any modeDay 4

TAB

Example:Router# conf + TAB → configure —Auto-completes a partially typed command

Any modeDay 4

enable

Example:Router> enable → Router# —Moves from User EXEC to Privileged EXEC

User EXEC >Day 4

disable

Example:Router# disable → Router> —Moves from Privileged EXEC to User EXEC

Privileged EXEC #Day 4

configure terminal / conf t

Example:Router# conf t → Router(config)# —Enters Global Configuration Mode

Privileged EXEC #Day 4

exit

Example:Router(config)# exit → Router# —Moves back one CLI level

Any configuration modeDay 4

end

Example:Router(config-if)# end → Router# —Immediately returns to Privileged EXEC Mode

Any configuration modeDay 4

do

Example:Router(config)# do show ip interface brief —Runs a Privileged EXEC command while in configuration mode

Global Config or lowerDay 4

enable password [pw]

Example:Router(config)# enable password cisco —Sets a password for entering Privileged EXEC mode

Global ConfigDay 4

enable secret [pw]

Example:Router(config)# enable secret cisco —Sets an encrypted password for Privileged EXEC; preferred over enable password

Global ConfigDay 4

service password-encryption

Example:Router(config)# service password-encryption —Encrypts plaintext passwords using weak Type 7 encryption

Global ConfigDay 4

no service password-encryption

Example:Router(config)# no service password-encryption —Stops future automatic encryption of plaintext passwords

Global ConfigDay 4

show running-config

Example:Router# show running-config —Displays the current active configuration

Privileged EXEC #Day 4

show startup-config

Example:Router# show startup-config —Displays the configuration saved in NVRAM for the next reboot

Privileged EXEC #Day 4

write / write memory

Example:Router# write memory —Saves running-config to startup-config

Privileged EXEC #Day 4

copy running-config startup-config

Example:Router# copy running-config startup-config —Copies the active configuration into startup configuration

Privileged EXEC #Day 4

no [command]

Example:Router(config)# no shutdown —Removes or disables a configuration command

Appropriate configuration modeDay 4

show arp

Example:Router# show arp —Shows the device's ARP table

Privileged EXEC #Day 6

show mac address-table

Example:Switch# show mac address-table —Shows a switch's learned MAC address table

Privileged EXEC #Day 6

clear mac address-table dynamic

Example:Switch# clear mac address-table dynamic —Clears dynamically learned MAC- table entries

Privileged EXEC #Day 6

ping [ip]

Example:Router# ping 192.168.1.1 —Tests IP reachability using ICMP Echo messages

User EXEC > or Privileged EXEC #Day 6

interface g0/0

Example:Router(config)# interface g0/0 → Router(config-if)# —Enters configuration mode for GigabitEthernet 0/0

Global ConfigDay 8

ip address [ip] [mask]

Example:Router(config-if)# ip address 192.168.1.1 255.255.255.0 —Assigns an IPv4 address and subnet mask to an interface

Interface ConfigDay 8

show ip interface brief

Example:Router# show ip interface brief —Lists interfaces, IP addresses, assignment method, status, and protocol

Privileged EXEC #Day 8

show interfaces

Example:Router# show interfaces g0/0 —Shows detailed interface information, including Layer 1, Layer 2, and some Layer 3 details

Privileged EXEC #Day 8

show interfaces description

Example:Router# show interfaces description —Shows each interface's description

Privileged EXEC #Day 8

description [text]

Example:Router(config-if)# description WAN to ISP —Adds a label/note to an interface

Interface ConfigDay 8

show interfaces status

Example:Switch# show interfaces status —Shows port status, VLAN, duplex, speed, and interface type

Privileged EXEC #Day 8

no shutdown

Example:Router(config-if)# no shutdown —Administratively enables an interface

Interface ConfigDay 9

shutdown

Example:Router(config-if)# shutdown —Administratively disables an interface

Interface ConfigDay 9

interface range f0/5 -12

Example:Switch(config)# interface range f0/5 -12 —Enters configuration mode for FastEthernet 0/5 through 0/12 simultaneously

Global ConfigDay 9

show ip route

Example:Router# show ip route —Displays the router's IPv4 routing table

Privileged EXEC #Day 11

ip route [network] [mask] [next-hop]

Example:Router(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2 —Creates a static route to a network using a next-hop IP address

Global ConfigDay 11

ip route [network] [mask] [exit-interface]

Example:Router(config)# ip route 192.168.2.0 255.255.255.0 g0/1 —Creates a static route using an exit interface

Global ConfigDay 11

ip route 0.0.0.0 0.0.0.0 [next-hop]

Example:Router(config)# ip route 0.0.0.0 0.0.0.0 10.0.0.2 —Configures an IPv4 default route

Global ConfigDay 11

ip route 0.0.0.0 0.0.0.0 [exit-interface]

Example:Router(config)# ip route 0.0.0.0 0.0.0.0 g0/1 —Configures a default route using an exit interface

Global ConfigDay 11

ip route [network] [mask] [next-hop] [exit- interface]

Example:Router(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2 g0/1 —Configures a static route using both a next-hop IP and exit interface

Global ConfigDay 11

no ip route [network] [mask] ...

Example:Router(config)# no ip route 192.168.2.0 255.255.255.0 10.0.0.2 —Removes a configured static route

Global ConfigDay 11

show ip route static

Example:Router# show ip route static —Displays only static routes in the routing table

Privileged EXEC #Day 11

show ip route connected

Example:Router# show ip route connected —Displays directly connected routes

Privileged EXEC #Day 11

show ip route 0.0.0.0

Example:Router# show ip route 0.0.0.0 —Checks routing information for the default route

Privileged EXEC #Day 16

show vlan brief

Example:Switch# show vlan brief —Displays VLANs configured on the switch and shows which access ports belong to each VLAN

Privileged EXEC #Day 16

vlan [vlan-id]

Example:Switch(config)# vlan 10 —Creates VLAN 10 if it does not already exist and enters VLAN configuration mode

Global ConfigDay 16

name [name]

Example:Switch(config-vlan)# name SALES —Assigns a descriptive name to the VLAN

VLAN Config (config-vlan)Day 16

interface range [interfaces]

Example:Switch(config)# interface range f0/1 -10 —Selects multiple interfaces so they can be configured at the same time

Global ConfigDay 16

switchport mode access

Example:Switch(config-if)# switchport mode access —Forces the switch interface to operate as an access port

Interface ConfigDay 16

switchport access vlan [vlan-id]

Example:Switch(config-if)# switchport access vlan 10 —Assigns an access port to VLAN 10

Interface ConfigDay 16

switchport trunk encapsulation dot1q

Example:Switch(config-if)# switchport trunk encapsulation dot1q —Sets the trunk encapsulation protocol to IEEE 802.1Q on switches that support multiple trunk encapsulation types

Interface ConfigDay 17

switchport mode trunk

Example:Switch(config-if)# switchport mode trunk —Manually configures the interface as a trunk port

Interface ConfigDay 17

show interfaces trunk

Example:Switch# show interfaces trunk —Displays interfaces currently operating as trunks, native VLANs, encapsulation, and allowed VLANs

Privileged EXEC #Day 17

switchport trunk allowed vlan [list]

Example:Switch(config-if)# switchport trunk allowed vlan 10,20,30 —Restricts the trunk so only the specified VLANs are allowed across it

Interface ConfigDay 17

switchport trunk allowed vlan add [list]

Example:Switch(config-if)# switchport trunk allowed vlan add 40 —Adds VLANs to the current allowed VLAN list without replacing the existing list

Interface ConfigDay 17

switchport trunk allowed vlan remove [list]

Example:Switch(config-if)# switchport trunk allowed vlan remove 20 —Removes VLANs from the trunk's allowed list

Interface ConfigDay 17

switchport trunk allowed vlan except [list]

Example:Switch(config-if)# switchport trunk allowed vlan except 30 —Allows all VLANs except the VLANs specified

Interface ConfigDay 17

switchport trunk allowed vlan none

Example:Switch(config-if)# switchport trunk allowed vlan none —Removes all VLANs from the trunk's allowed list

Interface ConfigDay 17

switchport trunk allowed vlan all

Example:Switch(config-if)# switchport trunk allowed vlan all —Allows all VLANs across the trunk

Interface ConfigDay 17

switchport trunk native vlan [vlan-id]

Example:Switch(config-if)# switchport trunk native vlan 99 —Changes the native VLAN used for untagged traffic on an 802.1Q trunk

Interface ConfigDay 17

interface g0/0.[subinterface]

Example:Router(config)# interface g0/0.10 —Creates/enters a router subinterface, commonly used for router-on-a-stick inter-VLAN routing

Global ConfigDay 17

encapsulation dot1q [vlan-id]

Example:Router(config-subif)# encapsulation dot1q 10 —Associates the router subinterface with VLAN 10 using 802.1Q tagging

Subinterface Config (config- subif)Day 17

encapsulation dot1q [vlan-id] native

Example:Router(config-subif)# encapsulation dot1q 99 native —Associates the subinterface with the trunk's native VLAN

Subinterface ConfigDay 17

ip address [ip] [mask]

Example:Router(config-subif)# ip address 192.168.10.1 255.255.255.0 —Assigns the VLAN's default-gateway IP address to the router subinterface

Subinterface ConfigDay 17

Layer 3 Switching Commands

ip routing

Example:SW1(config)# ip routing —Enables Layer 3 IP routing on a multilayer switch, allowing it to route between networks/VLANs.

Global ConfigDay 20

no switchport

Example:SW1(config-if)# no switchport —Converts a switch interface from a Layer 2 switchport into a Layer 3 routed port, allowing an IP address to be assigned directly to it.

Interface ConfigDay 20

Spanning Tree Verification Commands

show spanning-tree

Example:SW1# show spanning-tree —Displays STP information including root bridge, root ports, designated ports, costs, and port states.

Privileged EXECDay 20

show spanning-tree summary

Example:SW1# show spanning-tree summary —Displays a summarized overview of STP configuration and status.

Privileged EXECDay 20

show spanning-tree detail

Example:SW1# show spanning-tree detail —Displays detailed STP information, including topology changes and BPDU activity.

Privileged EXECDay 20

PortFast Commands

spanning-tree portfast

Example:SW1(config-if)# spanning-tree portfast —Enables PortFast on an interface. The port can transition to forwarding immediately instead of waiting through normal STP convergence. Typically used on end-device/access ports.

Interface ConfigDay 20

spanning-tree portfast default

Example:SW1(config)# spanning-tree portfast default —Enables PortFast by default on eligible access ports.

Global ConfigDay 21

spanning-tree portfast disable

Example:SW1(config-if)# spanning-tree portfast disable —Explicitly disables PortFast on the interface.

Interface ConfigDay 21

spanning-tree portfast trunk

Example:SW1(config-if)# spanning-tree portfast trunk —Enables PortFast on a trunk interface. Use only when the trunk connects to an appropriate endpoint, not another switch.

Interface ConfigDay 21

BPDU Guard Commands

spanning-tree bpduguard enable

Example:SW1(config-if)# spanning-tree bpduguard enable —Enables BPDU Guard directly on an interface. If a BPDU is received, the port is typically placed into an err-disabledstate.

Interface ConfigDay 21

spanning-tree portfast bpduguard default

Example:SW1(config)# spanning-tree portfast bpduguard default —Globally enables BPDU Guard on PortFast-enabled ports.

Global ConfigDay 21

show errdisable recovery

Example:SW1# show errdisable recovery —Displays err-disable recovery settings and reasons/interfaces associated with err-disable conditions.

Privileged EXECDay 21

Rapid PVST+ Command

spanning-tree mode rapid-pvst

Example:SW1(config)# spanning-tree mode rapid-pvst —Configures the switch to use Rapid PVST+, Cisco's per-VLAN implementation of Rapid Spanning Tree.

Global ConfigDay 21

Root Bridge & STP Path Selection

spanning-tree vlan 1 root primary

Example:SW1(config)# spanning-tree vlan 1 root primary —Adjusts bridge priority to make the switch the preferred root bridgefor VLAN 1.

Global ConfigDay 21

spanning-tree vlan 1 root secondary

Example:SW2(config)# spanning-tree vlan 1 root secondary —Adjusts bridge priority so the switch is preferred as the backup root bridge.

Global ConfigDay 21

spanning-tree vlan 1 cost [cost]

Example:SW1(config-if)# spanning-tree vlan 1 cost 10 —Manually changes an interface's STP cost for VLAN 1, influencing STP's path selection.

Interface ConfigDay 21

spanning-tree vlan 1 port-priority [priority]

Example:SW1(config-if)# spanning-tree vlan 1 port-priority 64 —Changes STP port priority for VLAN 1, which can influence which port is selected when other criteria tie.

Interface ConfigDay 21

BPDU Filter

spanning-tree bpdufilter enable

Example:SW1(config-if)# spanning-tree bpdufilter enable —Enables BPDU filtering on an interface, preventing normal sending/processing of BPDUs. Use carefully because it can defeat STP's loop protection.

Interface ConfigDay 21

Root Guard

spanning-tree guard root

Example:SW1(config-if)# spanning-tree guard root —Enables Root Guard, preventing a neighboring switch from becoming the STP root through that interface.

Interface ConfigDay 21

Loop Guard

spanning-tree guard loop

Example:SW1(config-if)# spanning-tree guard loop —Enables Loop Guard on an interface. Helps prevent STP loops if expected BPDUs suddenly stop being received.

Interface ConfigDay 21

spanning-tree loopguard default

Example:SW1(config)# spanning-tree loopguard default —Globally enables Loop Guard on applicable point-to-point interfaces.

Global ConfigDay 21

Rapid PVST

spanning-tree mode rapid-pvst

Example:SW1(config)# spanning-tree mode rapid-pvst —Enables Rapid PVST+, Cisco's per-VLAN implementation of Rapid Spanning Tree Protocol (RSTP).

Global ConfigDay 22

spanning-tree portfast

Example:SW1(config-if)# spanning-tree portfast —Enables PortFast on an interface, allowing an edge/access port to transition to forwarding immediately. Typically used on ports connected to end devices.

Interface ConfigDay 22

spanning-tree link-type point-to-point

Example:SW1(config-if)# spanning-tree link-type point-to-point —Manually configures an RSTP interface as a point-to-point link, typically used for full-duplex switch-to-switch connections.

Interface ConfigDay 22

spanning-tree link-type shared

Example:SW1(config-if)# spanning-tree link-type shared —Manually configures an RSTP interface as a shared link, typically associated with half-duplex/shared Ethernet.

Interface ConfigDay 22

etherchannel -General

show etherchannel load-balance

Example:SW1# show etherchannel load-balance —Displays the load-balancing method currently being used by EtherChannel.

Privileged EXECDay 23

show etherchannel summary

Example:SW1# show etherchannel summary —Displays a summary of EtherChannels, including port-channel numbers, protocols, member interfaces, and their states.

Privileged EXECDay 23

show etherchannel port-channel

Example:SW1# show etherchannel port-channel —Displays detailed information about configured EtherChannel port-channel interfaces.

Privileged EXECDay 23

show etherhannel load-balance

port-channel load-balance src-dst-mac

Example:SW1(config)# port-channel load-balance src-dst-mac —Configures EtherChannel load balancing based on source and destination MAC addresses.

Global ConfigDay 23

Layer 2 EtherChannel —Switch-to-Switch

interface range [interfaces]

Example:SW1(config)# interface range g0/1 -2 —Selects the physical interfaces that will become members of the EtherChannel.

Global ConfigDay 23

channel-group 1 mode desirable

Example:SW1(config-if-range)# channel-group 1 mode desirable —Adds the selected interfaces to Port-Channel 1 using PAgP desirable mode.

Interface ConfigDay 23

channel-protocol pagp

Example:SW1(config-if-range)# channel-protocol pagp —Explicitly selects PAgP. Usually unnecessary because desirable/auto already indicates PAgP.

Interface ConfigDay 23

channel-protocol lacp

Example:SW1(config-if-range)# channel-protocol lacp —Explicitly selects LACP. Usually unnecessary because active/passive already indicates LACP.

Interface ConfigDay 23

interface port-channel 1

Example:SW1(config)# interface port-channel 1 —Enters configuration mode for the logical EtherChannel interface.

Global ConfigDay 23

switchport trunk encapsulation dot1q

Example:SW1(config-if)# switchport trunk encapsulation dot1q —Configures the Port- Channel to use 802.1Q trunk encapsulation. Only required on switches that support multiple encapsulation types.

Interface ConfigDay 23

switchport mode trunk

Example:SW1(config-if)# switchport mode trunk —Makes the logical Port-Channel a Layer 2 trunk capable of carrying multiple VLANs.

Interface ConfigDay 23

Layer 3 EtherChannel —Multilayer Switch / Routed Connection

interface range [interfaces]

Example:SW1(config)# interface range g0/1 -2 —Selects the physical interfaces that will become members of the Layer 3 EtherChannel.

Global ConfigDay 23

no switchport

Example:SW1(config-if-range)# no switchport —Converts the selected physical interfaces into Layer 3 routed interfaces.

Interface ConfigDay 23

channel-group 1 mode active

Example:SW1(config-if-range)# channel-group 1 mode active —Adds the interfaces to Port-Channel 1 using LACP.

Interface ConfigDay 23

interface port-channel 1

Example:SW1(config)# interface port-channel 1 —Enters configuration mode for the logical Layer 3 Port-Channel.

Global ConfigDay 23

no switchport

Example:SW1(config-if)# no switchport —Configures the Port-Channel as a Layer 3 routed interface.

Interface ConfigDay 23

ip address [IP] [mask]

Example:SW1(config-if)# ip address 10.0.0.1 255.255.255.252 —Assigns an IPv4 address to the logical Layer 3 Port-Channel.

Interface ConfigDay 23

OSPF

router ospf [process-id]

Example:R1(config)# router ospf 1 —Enables OSPF and enters OSPF configuration mode. The process ID is locally significantand does nothave to match neighboring routers.

Global ConfigDay 26

network [IP] [wildcard-mask] area [area-id] doing 0.0.0.0 255.255.255.255 works or just IP like 10.10.4.2 0.0.0.0

Example:R1(config-router)# network 10.0.0.0 0.0.0.255 area 0 —Identifies router interfaces whose IP addresses match the network/wildcard combination and enables OSPF on those interfaces. Also places those interfaces into the specified OSPF area.

Router ConfigDay 26

passive-interface [interface] passive-interface default (will make all interfaces passive)

Example:R1(config-router)# passive-interface g0/1 —Stops OSPF Hello messages from being sent out the interface, preventing neighbor relationships from forming there. The connected network can still be advertised by OSPF. Typically used on interfaces connected to end-user LANs rather than other OSPF routers.

Router ConfigDay 26

default-information originate After running this setup a default route on that router (i.g. if router 1 accesses the internet, setup 0.0.0.0 0.0.0.0 to the next hop

Example:R1(config-router)# default-information originate —Advertises a default route (0.0.0.0/0)into OSPF so neighboring OSPF routers can learn it. By default, the router must already have a default route in its routing table.

Router ConfigDay 26

router-id [router-id]

Example:R1(config-router)# router-id 1.1.1.1 —Manually configures the router's OSPF Router ID, a 32-bit value written like an IPv4 address that uniquely identifies the OSPF router.

Router ConfigDay 26

maximum-paths [number]

Example:R1(config-router)# maximum-paths 4 —Configures the maximum number of equal-cost OSPF routesthat can be installed in the routing table for load balancing.

Router ConfigDay 26

distance [number]

Example:R1(config-router)# distance 100 —Changes the administrative distanceof OSPF routes. OSPF's default administrative distance is 110.

Router ConfigDay 26

show ip protocols

Example:R1# show ip protocols —Displays information about the routing protocols currently running, including OSPF process ID, Router ID, advertised networks, passive interfaces, and administrative distance.

Privileged EXECDay 26

show ip ospf interface brief

clear ip ospf process

Example:R1# clear ip ospf process —Restarts the OSPF process. Useful after changing certain OSPF settings such as the Router ID. This temporarily tears down OSPF neighbor relationships.

Privileged EXECDay 26

OSPF Cost & Interface Commands — Day 27

auto-cost reference-bandwidth [Mbps]

Example:R1(config-router)# auto-cost reference-bandwidth 10000 —Changes the reference bandwidth OSPF uses to automatically calculate interface cost. Cost = Reference Bandwidth ÷ Interface Bandwidth.Configure the same reference bandwidth on all OSPF routers.

Router ConfigDay 27

ip ospf cost [number]

Example:R1(config-if)# ip ospf cost 10 —Manually sets the OSPF cost of an interface, overriding the automatically calculated cost. Preferred method when you specifically want to change OSPF cost.

Interface ConfigDay 27

bandwidth [Kbps]

Example:R1(config-if)# bandwidth 100000 —Changes the interface's logical bandwidth value, which can affect OSPF's automatic cost calculation. It does notchange the interface's actual physical speed.

Interface ConfigDay 27

show ip ospf neighbor

Example:R1# show ip ospf neighbor —Displays OSPF neighbors, including Router ID, priority, neighbor state, dead timer, neighbor IP address, and local interface.

Privileged EXECDay 27

ip ospf [process-id] area [area-id]

Example:R1(config-if)# ip ospf 1 area 0 —Enables OSPF directly on an interface and places it in the specified area. This is an alternative to using the OSPF network command.

Interface ConfigDay 27

OSPF DR/BDR & Network Commands — Day 28

ip ospf priority [number]

Example:R1(config-if)# ip ospf priority 200 —Changes an interface's OSPF priority for DR/BDR elections. Higher priority is preferred. 0 makes the router ineligible to become DR or BDR on that interface.

Interface ConfigDay 28

show ip ospf database

Example:R1# show ip ospf database —Displays the OSPF Link-State Database (LSDB)and the LSAs known by the router.

Privileged EXECDay 28

ip ospf network [type]

Example:R1(config-if)# ip ospf network point-to-point —Changes the OSPF network type used on an interface, affecting neighbor behavior and whether DR/BDR elections occur.

Interface ConfigDay 28

OSPF Authentication Commands — Day 28

ip ospf authentication

Example:R1(config-if)# ip ospf authentication —Enables simple/plain-text OSPF authenticationon the interface. Neighboring routers must use compatible authentication settings.

Interface ConfigDay 28

ip ospf authentication-key [password]

Example:R1(config-if)# ip ospf authentication-key cisco —Configures the password used for simple OSPF authentication on the interface.

Interface ConfigDay 28

Serial Interface Commands —Day 28

clock rate [bps]

Example:R1(config-if)# clock rate 128000 —Configures the clock rate on the DCE sideof a serial connection. The DCE device provides clocking to the link.

Serial Interface ConfigDay 28

encapsulation ppp

Example:R1(config-if)# encapsulation ppp —Changes the serial interface's Layer 2 encapsulation to PPP. Cisco serial interfaces traditionally default to HDLC.

Serial Interface ConfigDay 28

show controllers [interface]

Example:R1# show controllers serial 0/0/0 —Displays hardware/controller information about an interface. On serial links, it can be used to determine which side is DCE or DTE.

Privileged EXECDay 28

MTU Commands —Day 28

ip mtu [bytes]

Example:R1(config-if)# ip mtu 1400 —Changes the maximum size of an IP packet that can be sent without fragmentation on the interface. OSPF neighbors need compatible MTU settings to successfully form a full adjacency.

Interface ConfigDay 28

IPv6 Commands —Day 31–32

ipv6 unicast-routing

Example:R1(config)# ipv6 unicast-routing —Enables the router to forward IPv6 packets between interfaces. Required for IPv6 routing.

Global ConfigDay 31

ipv6 address [address/prefix]

Example:R1(config-if)# ipv6 address 2001:db8:1::1/64 —Manually assigns an IPv6 address and prefix length to an interface.

Interface ConfigDay 31

show ipv6 interface brief

Example:R1# show ipv6 interface brief —Displays a summary of interfaces, their status, and assigned IPv6 addresses.

Privileged EXECDay 31

ipv6 address [prefix] eui-64

Example:R1(config-if)# ipv6 address 2001:db8:1::/64 eui-64 —Automatically generates the interface ID portion of the IPv6 address using modified EUI-64.

Interface ConfigDay 32

Standard Numbered ACLs —Day 34

access-list [number] permit [source] [wildcard]

Example:R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255 —Creates a numbered standard ACLentry permitting traffic based only on the source IPv4 address. Standard ACL numbers are commonly 1–99 or 1300–1999.

Global ConfigDay 34

access-list [number] deny [source] [wildcard]

Example:R1(config)# access-list 1 deny 192.168.1.0 0.0.0.255 —Creates a standard ACL entry denying traffic from the specified source network.

Global ConfigDay 34

access-list [number] permit any

Example:R1(config)# access-list 1 permit any —Permits traffic from any source IPv4 address. any is shorthand for 0.0.0.0 255.255.255.255.

Global ConfigDay 34

access-list [number] remark [text]

Example:R1(config)# access-list 1 remark ALLOW-SALES-LAN —Adds a description/comment to an ACL to document its purpose.

Global ConfigDay 34

show access-lists

Example:R1# show access-lists —Displays configured ACLs, their entries, sequence numbers, and match counters.

Privileged EXECDay 34

show ip access-lists

Example:R1# show ip access-lists —Displays configured IPv4 ACLsand their entries.

Privileged EXECDay 34

ip access-group [ACL] in

Example:R1(config-if)# ip access-group 1 in —Applies an IPv4 ACL to traffic enteringan interface.

Interface ConfigDay 34

ip access-group [ACL] out

Example:R1(config-if)# ip access-group 1 out —Applies an IPv4 ACL to traffic leavingan interface.

Interface ConfigDay 34

Named Standard ACLs —Day 35

ip access-list standard [name]

Example:R1(config)# ip access-list standard BLOCK-SALES —Creates a named standard IPv4 ACLand enters Standard Named ACL configuration mode.

Global ConfigDay 35

[sequence] permit [source] [wildcard]

Example:R1(config-std-nacl)# 10 permit 192.168.1.0 0.0.0.255 —Creates a permit ACE with a specific sequence number.

Standard Named ACL ConfigDay 35

[sequence] deny [source] [wildcard]

Example:R1(config-std-nacl)# 20 deny 192.168.2.0 0.0.0.255 —Creates a deny ACE with a specific sequence number.

Standard Named ACL ConfigDay 35

no [sequence]

Example:R1(config-std-nacl)# no 10 —Removes the ACL entry with that sequence number without deleting the entire ACL.

Named ACL ConfigDay 35

ip access-list resequence [ACL] [starting-sequence] [increment]

Example:R1(config)# ip access-list resequence BLOCK-SALES 10 10 —Renumbers ACL entries beginning at sequence 10 and increasing by 10.

Global ConfigDay 35

Extended ACLs —Day 35

access-list [number] permit [protocol] [source] [destination]

Example:R1(config)# access-list 100 permit ip 192.168.1.0 0.0.0.255 any —Creates a numbered extended ACLpermitting traffic based on protocol, source, and destination.

Global ConfigDay 35

access-list [number] deny [protocol] [source] [destination]

Example:R1(config)# access-list 100 deny tcp 192.168.1.0 0.0.0.255 any —Creates an extended ACL denying matching traffic based on protocol, source, and destination.

Global ConfigDay 35

ip access-list extended [name]

Example:R1(config)# ip access-list extended WEB-FILTER —Creates a named extended IPv4 ACLand enters Extended Named ACL configuration mode.

Global ConfigDay 35

eq [port]

Example:R1(config-ext-nacl)# permit tcp any any eq 443 —Matches traffic with a port equal tothe specified value.

Extended Named ACL ConfigDay 35

gt [port]

Example:R1(config-ext-nacl)# permit tcp any any gt 1023 —Matches ports greater than the specified value.

Extended Named ACL ConfigDay 35

lt [port]

Example:R1(config-ext-nacl)# permit tcp any any lt 1024 —Matches ports less thanthe specified value.

Extended Named ACL ConfigDay 35

neq [port]

Example:R1(config-ext-nacl)# permit tcp any any neq 22 —Matches ports not equal to the specified value.

Extended Named ACL ConfigDay 35

range [start] [end]

Example:R1(config-ext-nacl)# permit tcp any any range 20 21 —Matches a range of TCP or UDP port numbers.

Extended Named ACL ConfigDay 35

CDP Verification Commands —Day 36

show cdp

Example:SW1# show cdp —Displays global CDP information including timers, holdtime, and CDP version.

Privileged EXECDay 36

show cdp traffic

Example:SW1# show cdp traffic —Displays statistics for CDP packets sent and received.

Privileged EXECDay 36

show cdp interface

Example:SW1# show cdp interface —Displays CDP information and status for CDP- enabled interfaces.

Privileged EXECDay 36

show cdp neighbors

Example:SW1# show cdp neighbors —Displays directly connected Cisco neighbors including Device ID, local interface, capabilities, platform, and remote Port ID.

Privileged EXECDay 36

show cdp neighbors detail

Example:SW1# show cdp neighbors detail —Displays detailed information about CDP neighbors, including IP addresses, software/platform information, interfaces, and other advertised information.

Privileged EXECDay 36

show cdp entry [device-id]

Example:SW1# show cdp entry R1 —Displays detailed CDP information about a specific neighbor.

Privileged EXECDay 36

CDP Configuration Commands —Day 36

cdp run

Example:SW1(config)# cdp run —Enables CDP globallyon the device.

Global ConfigDay 36

no cdp run

Example:SW1(config)# no cdp run —Disables CDP globally on the device.

Global ConfigDay 36

cdp enable

Example:SW1(config-if)# cdp enable —Enables CDP on a specific interface.

Interface ConfigDay 36

no cdp enable

Example:SW1(config-if)# no cdp enable —Disables CDP on a specific interface.

Interface ConfigDay 36

cdp timer [seconds]

Example:SW1(config)# cdp timer 30 —Changes how frequently the device sends CDP advertisements.

Global ConfigDay 36

cdp holdtime [seconds]

Example:SW1(config)# cdp holdtime 90 —Changes how long received CDP information is retained before being discarded.

Global ConfigDay 36

cdp advertise-v2

Example:SW1(config)# cdp advertise-v2 —Enables CDP Version 2 advertisements.

Global ConfigDay 36

LLDP Verification Commands —Day 36

show lldp

Example:SW1# show lldp —Displays global LLDP information including timers and status.

Privileged EXECDay 36

show lldp traffic

Example:SW1# show lldp traffic —Displays statistics for LLDP frames sent and received.

Privileged EXECDay 36

show lldp interface

Example:SW1# show lldp interface —Displays LLDP transmit/receive status and information for interfaces.

Privileged EXECDay 36

show lldp neighbors

Example:SW1# show lldp neighbors —Displays directly connected LLDP neighbors including Device ID, local interface, capabilities, and remote Port ID.

Privileged EXECDay 36

show lldp neighbors detail

Example:SW1# show lldp neighbors detail —Displays detailed information learned about all LLDP neighbors.

Privileged EXECDay 36

show lldp entry [device-id]

Example:SW1# show lldp entry R1 —Displays detailed LLDP information about a specific neighbor.

Privileged EXECDay 36

LLDP Configuration Commands —Day 36

lldp run

Example:SW1(config)# lldp run —Enables LLDP globallyon the device.

Global ConfigDay 36

no lldp run

Example:SW1(config)# no lldp run —Disables LLDP globally.

Global ConfigDay 36

lldp transmit

Example:SW1(config-if)# lldp transmit —Enables transmission of LLDP advertisements on the interface.

Interface ConfigDay 36

lldp receive

Example:SW1(config-if)# lldp receive —Enables receiving LLDP advertisements on the interface.

Interface ConfigDay 36

lldp timer [seconds]

Example:SW1(config)# lldp timer 30 —Configures how frequently LLDP advertisements are sent.

Global ConfigDay 36

lldp holdtime [seconds]

Example:SW1(config)# lldp holdtime 120 —Configures the LLDP holdtime advertised to neighboring devices.

Global ConfigDay 36

lldp reinit [seconds]

Example:SW1(config)# lldp reinit 2 —Configures the delay before LLDP is reinitialized on an interface.

Global ConfigDay 36

NTP Verification Commands

show clock

Example:R1# show clock —Displays the device's current software clock time and date.

Privileged EXECDay 37

show clock detail

Example:R1# show clock detail —Displays detailed software clock information, including the configured time source and timezone information.

Privileged EXECDay 37

show ntp status

Example:R1# show ntp status —Displays general NTP status, including whether the device is synchronized, its stratum, reference clock, and timing information.

Privileged EXECDay 37

show ntp associations

Example:R1# show ntp associations —Displays configured NTP peers/servers and their synchronization status.

Privileged EXECDay 37

Manual Clock & Calendar Commands

clock set [hh:mm:ss] [day] [month] [year]

Example:R1# clock set 12:30:00 14 September 2026 —Manually sets the device's software clock.

Privileged EXECDay 37

calendar set [hh:mm:ss] [day] [month] [year]

Example:R1# calendar set 12:30:00 14 September 2026 —Manually sets the device's hardware calendaron devices that support one.

Privileged EXECDay 37

clock update-calendar

Example:R1# clock update-calendar —Copies the current software clock → hardware calendar.

Privileged EXECDay 37

clock read-calendar

Example:R1# clock read-calendar —Copies the hardware calendar → software clock.

Privileged EXECDay 37

Timezone & Daylight Saving Commands

clock timezone [name] [hours-offset] [minutes- offset]

Example:R1(config)# clock timezone EST -5 —Configures the device's timezone and its offset from UTC.

Global ConfigDay 37

clock summer-time [name] recurring [start] [end] [offset]

Example:R1(config)# clock summer-time EDT recurring —Configures recurring daylight saving/summer time. Additional arguments can specify exactly when DST starts and ends.

Global ConfigDay 37

NTP Client Commands

ntp server [ip-address]

Example:R2(config)# ntp server 10.0.0.1 —Configures an NTP server that this device will use to synchronize its clock.

Global ConfigDay 37

ntp server [ip-address] prefer

Example:R2(config)# ntp server 10.0.0.1 prefer —Configures an NTP server and marks it as the preferredserver when multiple NTP servers are available.

Global ConfigDay 37

ntp source [interface]

Example:R2(config)# ntp source loopback0 —Configures the specified interface's address as the source address for NTP packets.

Global ConfigDay 37

ntp update-calendar

Example:R2(config)# ntp update-calendar —Configures the device to periodically update its hardware calendar using the NTP-synchronized software clock.

Global ConfigDay 37

NTP Server & Peer Commands

ntp master [stratum]

Example:R1(config)# ntp master 5 —Configures the Cisco device to act as an NTP master/server. The optional value specifies the stratum advertised by the device.

Global ConfigDay 37

ntp peer [ip-address]

Example:R1(config)# ntp peer 10.0.0.2 —Configures a symmetric NTP peer relationship with another device.

Global ConfigDay 37

ntp peer [ip-address] key [number]

Example:R1(config)# ntp peer 10.0.0.2 key 1 —Configures an NTP peer and specifies the authentication key to use.

Global ConfigDay 37

NTP Authentication Commands

ntp authenticate

Example:R1(config)# ntp authenticate —Globally enables NTP authentication.

Global ConfigDay 37

ntp authentication-key [number] md5 [key]

Example:R1(config)# ntp authentication-key 1 md5 CCNA —Creates an NTP authentication key using the specified key number and password.

Global ConfigDay 37

ntp trusted-key [number]

Example:R1(config)# ntp trusted-key 1 —Marks the specified NTP authentication key as trusted.

Global ConfigDay 37

ntp server [ip-address] key [number]

Example:R2(config)# ntp server 10.0.0.1 key 1 —Configures an NTP server and specifies the authentication key used when communicating with it.

Global ConfigDay 37

DNS Verification Commands

show hosts

Example:R1# show hosts —Displays configured hostname-to-IP mappings as well as hostnames learned and cached through DNS.

Privileged EXECDay 38

DNS Configuration Commands

ip dns server

Example:R1(config)# ip dns server —Configures the Cisco device to act as a DNS server and answer DNS queries.

Global ConfigDay 38

ip domain lookup

Example:R1(config)# ip domain lookup —Enables the device to perform DNS hostname lookups. DNS lookup is normally enabled by default.

Global ConfigDay 38

no ip domain lookup

Example:R1(config)# no ip domain lookup —Disables DNS hostname lookups. Useful in labs to prevent IOS from trying to resolve mistyped commands as hostnames.

Global ConfigDay 38

ip host [hostname] [IP]

Example:R1(config)# ip host SERVER1 192.168.1.10 —Creates a static hostname-to-IP address mappingin the local host table.

Global ConfigDay 38

ip name-server [IP]

Example:R1(config)# ip name-server 8.8.8.8 —Configures the IP address of a DNS server the device can query to resolve hostnames.

Global ConfigDay 38

ip domain name [domain]

Example:R1(config)# ip domain name example.com —Configures the device's default domain name. Also commonly used when configuring SSH.

Global ConfigDay 38

DHCP Show Commands

show ip dhcp binding

Example:R1# show ip dhcp binding —Displays DHCP clients that currently have IP addresses assigned by the router's DHCP server.

Privileged EXECDay 39

DHCP Global Config Commands

ip dhcp excluded-address [low-address] [high- address]

Example:R1(config)# ip dhcp excluded-address 192.168.1.1 192.168.1.10 —Excludes a range of addresses from being assigned to DHCP clients.

Global ConfigDay 39

ip dhcp pool [pool-name]

Example:R1(config)# ip dhcp pool LAN —Creates a DHCP pool and enters DHCP Pool Configuration mode. If the pool already exists, enters its configuration.

Global ConfigDay 39

network [network] [subnet-mask]

Example:R1(dhcp-config)# network 192.168.1.0 255.255.255.0 —Specifies the subnet from which DHCP addresses will be assigned. Excluded addresses will not be given to clients.

DHCP Pool ConfigDay 39

lease [days] [hours] [minutes]

Example:R1(dhcp-config)# lease 7 —Configures how long DHCP clients can keep their assigned addresses.

DHCP Pool ConfigDay 39

lease infinite

Example:R1(dhcp-config)# lease infinite —Configures DHCP leases so they do not expire.

DHCP Pool ConfigDay 39

default-router [IP]

Example:R1(dhcp-config)# default-router 192.168.1.1 —Specifies the default gateway provided to DHCP clients.

DHCP Pool ConfigDay 39

dns-server [IP]

Example:R1(dhcp-config)# dns-server 8.8.8.8 —Specifies the DNS server address provided to DHCP clients.

DHCP Pool ConfigDay 39

domain-name [domain]

Example:R1(dhcp-config)# domain-name example.com —Specifies the domain name provided to DHCP clients.

DHCP Pool ConfigDay 39

option 43 ip [IP]

Example:R1(dhcp-config)# option 43 ip 10.0.0.10 —Configures DHCP Option 43. Cisco APs can use this option to learn the IP address of their Wireless LAN Controller (WLC).

DHCP Pool ConfigDay 39

DHCP Interface Commands

ip helper-address [IP]

Example:R1(config-if)# ip helper-address 10.0.0.10 —Configures the interface to act as a DHCP relay, forwarding client DHCP broadcasts toward a DHCP server on another network. Configure it on the interface facing the DHCP clients.

Interface ConfigDay 39

ip address dhcp

Example:R1(config-if)# ip address dhcp —Configures the router interface to act as a DHCP clientand obtain its own IPv4 address automatically from a DHCP server.

Interface ConfigDay 39

SNMP Configuration Commands

snmp-server contact [contact-info]

Example:R1(config)# snmp-server contact Network-Admin —Configures contact information for the person responsible for the SNMP-managed device.

Global ConfigDay 40

snmp-server location [location-info]

Example:R1(config)# snmp-server location Server-Room —Configures a description of the physical location of the SNMP-managed device.

Global ConfigDay 40

snmp-server community [string] ro

Example:R1(config)# snmp-server community CCNA ro —Configures an SNMP community string with read-only (RO)access. The NMS can read information but cannot modify it.

Global ConfigDay 40

snmp-server community [string] rw

Example:R1(config)# snmp-server community CCNA rw —Configures an SNMP community string with read-write (RW)access. The NMS can read and modify information.

Global ConfigDay 40

snmp-server host [IP] version 2c [community- string]

Example:R1(config)# snmp-server host 192.168.1.100 version 2c CCNA —Specifies the NMSthat will receive SNMP notifications, using SNMPv2c and the specified community string.

Global ConfigDay 40

snmp-server enable traps [trap-types]

Example:R1(config)# snmp-server enable traps link —Enables specified SNMP trap/notification typesto be sent to the configured NMS.

Global ConfigDay 40

Syslog Privileged Commands

terminal monitor

Example:R1# terminal monitor —Displays Syslog messages in the current VTY session (SSH/Telnet). Must be enabled again when a new remote session is established.

Privileged EXECDay 41

Syslog Configuration Commands

logging console [level]

Example:R1(config)# logging console warnings —Sets the minimum Syslog severity level displayed on the console connection.

Global ConfigDay 41

logging monitor [level]

Example:R1(config)# logging monitor warnings —Sets the Syslog severity level that can be displayed on VTY (SSH/Telnet) sessionswhen terminal monitor is enabled.

Global ConfigDay 41

logging buffered [size] [level]

Example:R1(config)# logging buffered 16384 warnings —Stores Syslog messages in the device's RAM logging buffer. Optional size is specified in bytes.

Global ConfigDay 41

logging trap [level]

Example:R1(config)# logging trap warnings —Sets the Syslog severity level sent to configured external Syslog servers.

Global ConfigDay 41

logging [IP]

Example:R1(config)# logging 192.168.1.100 —Configures an external Syslog server to receive logging messages.

Global ConfigDay 41

logging synchronous

Example:R1(config-line)# logging synchronous —Prevents Syslog messages from disrupting commands you are typing by redisplaying the prompt/input on a new line.

Line ConfigDay 41

service sequence-numbers

Example:R1(config)# service sequence-numbers —Adds sequence numbers to Syslog messages, making it easier to determine their order.

Global ConfigDay 41

service timestamps log datetime

Example:R1(config)# service timestamps log datetime —Adds the current date and time to Syslog messages.

Global ConfigDay 41

service timestamps log uptime

Example:R1(config)# service timestamps log uptime —Adds the amount of time since the device booted to Syslog messages.

Global ConfigDay 41

SSH —Day 42

hostname [name] ip domain name [domain]

Example:R1(config)# hostname R1 / R1(config)# ip domain name example.com — Configures the device hostname and domain name. Both are needed before generating the RSA keys used by SSH.

Global ConfigDay 42

username [username] secret [password]

Example:R1(config)# username admin secret CCNA123 —Creates a local username and encrypted secret for authentication. Used with login local.

Global ConfigDay 42

crypto key generate rsa

Example:R1(config)# crypto key generate rsa —Generates the RSA key pair used by SSH. Requires a hostname and domain name to be configured first.

Global ConfigDay 42

ip ssh version [1|2]

Example:R1(config)# ip ssh version 2 —Configures the SSH version. SSHv2 is preferred because SSHv1 is obsolete and insecure.

Global ConfigDay 42

line vty [line] line vty [start] [end]

Example:R1(config)# line vty 0 15 —Enters VTY line configuration mode. VTY lines are used for remote CLI connections such as SSH and Telnet.

Global ConfigDay 42

login login local

Example:R1(config-line)# login local —login authenticates using the password configured directly on the VTY line. login local authenticates using the device's local username/password databaseand is commonly used for SSH.

Line ConfigDay 42

transport input [protocols]

Examples:R1(config-line)# transport input ssh / transport input ssh telnet / transport input none —Controls which remote-access protocols are permitted on the VTY lines. transport input ssh is preferredbecause it prevents insecure Telnet access.

Line ConfigDay 42

exec-timeout [minutes] [seconds]

Example:R1(config-line)# exec-timeout 5 0 —Automatically disconnects the remote session after the specified period of inactivity.

Line ConfigDay 42

access-class [ACL] in

Example:R1(config-line)# access-class 10 in —Applies an ACL to incoming VTY connections to control which source IP addresses are allowed to remotely access the device.

Line ConfigDay 42

ip default-gateway [IP]

Example:SW1(config)# ip default-gateway 192.168.1.1 —Configures a default gateway on a Layer 2 switchso the switch's management IP can communicate with SSH clients on other networks. Not normally needed on a router or multilayer switch performing IP routing.

Global ConfigDay 42

show ip ssh show version

Example:R1# show ip ssh / R1# show version —show ip ssh verifies the SSH configuration, version, timeout, and retries. show version displays IOS/device information.

Privileged EXECDay 42

FTP / TFTP —Day 43

show file systems

Example:R1# show file systems —Displays available file systems and storage locations on the device. Useful first to identify locations such as flash:.

Privileged EXECDay 43

show flash

Example:R1# show flash —Displays the contents of Flash memory. Use this to verify the IOS image/file you want to copy or check available storage.

Privileged EXECDay 43

show version

Example:R1# show version —Displays the currently running IOS version and image along with device, uptime, memory, and boot information.

Privileged EXECDay 43

ip ftp username [username] ip ftp password [password]

Example:R1(config)# ip ftp username admin / R1(config)# ip ftp password CCNA123 — Configures the credentials the Cisco device will use when connecting to an FTP server. FTP only; TFTP does not use authentication.

Global ConfigDay 43

copy [source] [destination]

Examples:R1# copy tftp: flash: / R1# copy ftp: flash: / R1# copy flash: tftp: / R1# copy flash: ftp: / R1# copy running-config tftp: / R1# copy tftp: running-config —Copies files or configurations between the Cisco device and another location. Source comes first, destination second.

Privileged EXECDay 43

delete [file-path]

Example:R1# delete flash:old-ios.bin —Deletes a specified file. Commonly used to remove an old IOS image or unwanted file from Flash.

Privileged EXECDay 43

boot system [file-path]

Example:R1(config)# boot system flash:cisco-ios.bin —Configures which IOS image the device should attempt to load during its next boot.

Global ConfigDay 43

NAT —Day 44

ip nat inside ip nat outside

Example:R1(config-if)# ip nat inside / R1(config-if)# ip nat outside —Identifies which router interfaces connect to the inside/private networkand which connect to the outside/public network.

Interface ConfigDay 44

ip nat inside source static [inside-local] [inside- global]

Example:R1(config)# ip nat inside source static 192.168.1.10 203.0.113.10 —Configures Static NAT, creating a permanent one-to-one mapping between an inside local (private) address and an inside global (public) address.

Global ConfigDay 44

show ip nat translations show ip nat statistics

Example:R1# show ip nat translations / R1# show ip nat statistics —translations displays the NAT translation table. statistics displays NAT activity, configured interfaces, pools, and translation statistics.

Privileged EXECDay 44

clear ip nat translation *

Example:R1# clear ip nat translation * —Clears all dynamic NAT/PAT translationsfrom the NAT translation table.

Privileged EXECDay 44

NAT Part 2 —Day 45

ip nat inside ip nat outside

Example:R1(config-if)# ip nat inside / R1(config-if)# ip nat outside —Identifies interfaces as inside(private/internal network) or outside(public/external network) for NAT.

Interface ConfigDay 45

ip nat inside source static [inside-local] [inside- global]

Example:R1(config)# ip nat inside source static 192.168.1.10 203.0.113.10 —Configures Static NAT, permanently mapping one inside local/private address to one inside global/public address.

Global ConfigDay 45

access-list [ACL] permit [source] [wildcard]

Example:R1(config)# access-list 1 permit 192.168.1.0 0.0.0.255 —Identifies the inside/local addresses that are eligible to be translated by Dynamic NAT or PAT.

Global ConfigDay 45

ip nat pool [name] [start-IP] [end-IP] netmask [mask] ip nat pool [name] [start-IP] [end-IP] prefix- length [prefix]

Example:R1(config)# ip nat pool PUBLIC 203.0.113.10 203.0.113.20 netmask 255.255.255.0 —Creates a pool of inside global/public addressesfor Dynamic NAT or PAT.

Global ConfigDay 45

ip nat inside source list [ACL] pool [pool] ip nat inside source list [ACL] pool [pool] overload

Example:R1(config)# ip nat inside source list 1 pool PUBLIC / R1(config)# ip nat inside source list 1 pool PUBLIC overload —Connects the ACL to the NAT pool. Without overload = Dynamic NAT. With overload = PAT, allowing multiple inside hosts to share addresses using port numbers.

Global ConfigDay 45

ip nat inside source list [ACL] interface [interface] overload

Example:R1(config)# ip nat inside source list 1 interface g0/1 overload —Configures PAT using the outside interface's IP address. Multiple inside devices can share a single public IPv4 address using different port numbers.

Global ConfigDay 45

PoE / Power Policing —Day 46

power inline police power inline police action err- disable power inline police action log

Example:SW1(config-if)# power inline police —Enables PoE power policing on the interface. Default/err-disable action places the port into err-disabled stateif the powered device (PD) exceeds its allowed power. action log instead generates a Syslog message and restarts power to the device rather than err-disabling the port.

Interface ConfigDay 46

show power inline police [interface]

Example:SW1# show power inline police g0/1 —Displays PoE power-policing information for the specified interface, including power usage and policing status.

Privileged EXECDay 46

Voice VLAN / VoIP —Day 46

switchport mode access switchport access vlan [data-vlan]

Example:SW1(config-if)# switchport mode access / SW1(config-if)# switchport access vlan 10 —Configures the switchport as an access port and assigns normal data trafficto the specified access VLAN.

Interface ConfigDay 46

switchport voice vlan [voice-vlan]

Example:SW1(config-if)# switchport voice vlan 20 —Assigns traffic from an attached IP phoneto the specified voice VLAN. Voice traffic is tagged with the voice VLAN ID while a connected PC can use the regular access/data VLAN.

Interface ConfigDay 46

Port Security —Day 49

switchport mode access switchport mode trunk

Example:SW1(config-if)# switchport mode access —Statically configures the switchport's mode. Port security requires the port to be statically configured as an access or trunk port rather than a dynamic port. Most CCNA examples use access ports.

Interface ConfigDay 49

switchport port-security

Example:SW1(config-if)# switchport port-security —Enables port security on the interface.

Interface ConfigDay 49

switchport port-security maximum [number]

Example:SW1(config-if)# switchport port-security maximum 2 —Sets the maximum number of secure MAC addresses allowed on the interface. Default = 1.

Interface ConfigDay 49

switchport port-security mac-address [MAC] switchport port-security mac-address sticky switchport port-security mac-address sticky [MAC]

Example:SW1(config-if)# switchport port-security mac-address sticky —Controls which MAC addresses are considered secure. A MAC can be manually configured, or sticky can dynamically learn MAC addresses and add them to the running configuration as sticky secure MACs.

Interface ConfigDay 49

switchport port-security violation shutdown switchport port-security violation restrict switchport port-security violation protect

Example:SW1(config-if)# switchport port-security violation restrict —Configures what happens when an unauthorized MAC causes a violation. Shutdownerr-disables the port, restrictdrops offending traffic while counting/logging violations, and protectdrops offending traffic with less notification. Shutdown is the default.

Interface ConfigDay 49

switchport port-security aging time [minutes] switchport port-security aging type absolute switchport port-security aging type inactivity switchport port-security aging static

Example:SW1(config-if)# switchport port-security aging time 60 / switchport port-security aging type inactivity —Configures secure MAC aging. absolute ages entries after the configured time regardless of activity; inactivity ages them after being inactive. aging static allows statically configured secure MAC addresses to age.

Interface ConfigDay 49

errdisable recovery cause psecure-violation errdisable recovery cause dhcp-rate-limit errdisable recovery cause arp-inspection

Example:SW1(config)# errdisable recovery cause psecure-violation —Allows the switch to automatically recover ports that were err-disabled by the specified cause. These causes correspond to Port Security, DHCP Snooping, and Dynamic ARP Inspection.

Global ConfigDay 49

errdisable recovery interval [seconds]

Example:SW1(config)# errdisable recovery interval 300 —Configures how long an interface remains err-disabled before the switch attempts automatic recovery for enabled recovery causes.

Global ConfigDay 49

show port-security show port-security interface [interface]

Example:SW1# show port-security / SW1# show port-security interface f0/1 —Displays overall port-security information or detailed information for a specific interface, including status, violation mode, maximum MACs, secure MACs, and violation count.

Privileged EXECDay 49

show mac address-table secure

Example:SW1# show mac address-table secure —Displays secure MAC addresses learned or configured through port security.

Privileged EXECDay 49

show errdisable recovery

Example:SW1# show errdisable recovery —Displays configured err-disable recovery causes, timers, and interfaces currently waiting for recovery.

Privileged EXECDay 49

DHCP Snooping —Day 50

ip dhcp snooping ip dhcp snooping vlan [vlan-id]

Example:SW1(config)# ip dhcp snooping / SW1(config)# ip dhcp snooping vlan 10 — Enables DHCP Snooping globally and then for the specified VLAN. Both are required.

Global ConfigDay 50

no ip dhcp snooping information option

Example:SW1(config)# no ip dhcp snooping information option —Disables insertion of DHCP Option 82information into DHCP messages.

Global ConfigDay 50

ip dhcp snooping trust

Example:SW1(config-if)# ip dhcp snooping trust —Marks the interface as trusted, allowing DHCP server messages such as Offer and ACK through it. Typically configured toward the legitimate DHCP server/uplink. Ports are untrusted by default.

Interface ConfigDay 50

ip dhcp snooping limit rate [pps]

Example:SW1(config-if)# ip dhcp snooping limit rate 15 —Limits the number of DHCP messages allowed per second on the interface. Exceeding the configured rate can cause the interface to become err-disabled. Commonly configured on untrusted/client-facing ports.

Interface ConfigDay 50

errdisable recovery cause dhcp-rate-limit errdisable recovery interval [seconds]

Example:SW1(config)# errdisable recovery cause dhcp-rate-limit / SW1(config)# errdisable recovery interval 300 —Allows a port err-disabled because of a DHCP rate-limit violation to automatically recover after the configured interval.

Global ConfigDay 50

show ip dhcp snooping binding

Example:SW1# show ip dhcp snooping binding —Displays the DHCP Snooping binding table, which maps learned client MAC addresses to IP addresses, VLANs, interfaces, and lease information.

Privileged EXECDay 50

Dynamic ARP Inspection (DAI) —Day 51

ip arp inspection vlan [vlan-id]

Example:SW1(config)# ip arp inspection vlan 10 —Enables Dynamic ARP Inspection (DAI) for the specified VLAN. DAI normally uses the DHCP Snooping binding tableto determine whether ARP messages are legitimate.

Global ConfigDay 50

ip arp inspection validate src-mac ip arp inspection validate dst-mac ip arp inspection validate ip ip arp inspection validate src-mac dst-mac ip

Example:SW1(config)# ip arp inspection validate src-mac dst-mac ip —Enables additional ARP validation. src-mac checks the Ethernet source MAC against the ARP sender MAC, dst- mac checks the Ethernet destination MAC against the ARP target MAC where applicable, and ip checks for invalid/unacceptable IP addresses in ARP packets. Multiple checks can be enabled in one command.

Global ConfigDay 50

arp access-list [name] permit ip host [IP] mac host [MAC] deny ip host [IP] mac host [MAC]

Example:SW1(config)# arp access-list STATIC-HOSTS → SW1(config-arp-nacl)# permit ip host 192.168.1.10 mac host 0011.2233.4455 —Creates an ARP ACLand permits/denies specific IP-to-MAC mappings. Useful for hosts with static IP addresses that aren't represented in the DHCP Snooping binding table.

Global Config / ARP ACL ConfigDay 50

ip arp inspection filter [arp-acl] vlan [vlan-id]

Example:SW1(config)# ip arp inspection filter STATIC-HOSTS vlan 10 —Applies an ARP ACL to DAI for the specified VLAN.

Global ConfigDay 50

ip arp inspection trust

Example:SW1(config-if)# ip arp inspection trust —Marks an interface as trustedfor DAI. ARP messages received on trusted interfaces bypass normal DAI inspection. Interfaces are untrusted by default. Typically used on appropriate infrastructure/uplink ports.

Interface ConfigDay 50

ip arp inspection limit rate [pps] burst interval [seconds]

Example:SW1(config-if)# ip arp inspection limit rate 15 burst interval 1 —Limits the number of ARP packets allowed on the interface during the specified interval. Exceeding the limit can place the interface into err-disabledstate.

Interface ConfigDay 50

errdisable recovery cause arp-inspection errdisable recovery interval [seconds]

Example:SW1(config)# errdisable recovery cause arp-inspection / SW1(config)# errdisable recovery interval 300 —Enables automatic recovery for ports err-disabled by an ARP inspection rate violation and specifies how long the switch waits before attempting recovery.

Global ConfigDay 50

show ip arp inspection show ip arp inspection interfaces

Example:SW1# show ip arp inspection / SW1# show ip arp inspection interfaces — Displays DAI configuration/statistics and the DAI status, trust state, and rate information for interfaces.

Privileged EXECDay 50

Get in Touch