Cisco IOS Cheatsheet
Operational modes
| Mode | Prompt | Access |
|---|---|---|
| User EXEC | Router> | Default at startup. Basic monitoring. |
| Privileged EXEC | Router# | enable from user mode. |
| Global Configuration | Router(config)# | configure terminal from privileged mode. |
| Interface Configuration | Router(config-if)# | interface [type][number] from global config. |
Basic commands
Navigation and help
? ! Show available commands
Tab ! Auto-complete a partial command
Ctrl+Z ! Return to privileged mode from anywhere
exit ! Exit the current mode
end ! Return directly to privileged mode
Monitoring
show running-config ! Current configuration in RAM
show startup-config ! Saved configuration in NVRAM
show interfaces ! Interface status and statistics
show ip interface brief ! Interface summary with IP and status
show ip route ! Routing table
show version ! Device and IOS information
Basic interface configuration
Router(config)# interface GigabitEthernet0/0
Router(config-if)# ip address 192.168.1.1 255.255.255.0
Router(config-if)# no shutdown
Router(config-if)# description Main LAN
Router(config-if)# exit
Passwords and security
Router(config)# enable secret MyPassword ! Encrypted password for privileged mode
Router(config)# line console 0
Router(config-line)# password ConsolePwd
Router(config-line)# login
Router(config)# line vty 0 4
Router(config-line)# password TelnetPwd
Router(config-line)# login
Saving configuration
Router# copy running-config startup-config ! Save current config
Router# write memory ! Equivalent (short form)
Router# reload ! Restart the device
Dynamic routing
RIP v2
Router> enable
Router# configure terminal
Router(config)# router rip
Router(config-router)# version 2
Router(config-router)# no auto-summary
Router(config-router)# network 192.168.1.0
Router(config-router)# network 10.0.0.0
Router(config-router)# exit
Router# write memory
OSPF Single-Area
In a single-area configuration all routers belong to Area 0 (Backbone).
Router1> enable
Router1# configure terminal
Router1(config)# router ospf 1
Router1(config-router)# router-id 1.1.1.1
Router1(config-router)# network 192.168.10.0 0.0.0.255 area 0
Router1(config-router)# network 10.1.1.0 0.0.0.3 area 0
! Prevent OSPF hello packets toward the LAN (recommended)
Router1(config-router)# passive-interface GigabitEthernet0/0
Router1(config-router)# end
Router1# write memory
OSPF Multi-Area
Peripheral areas always connect to Area 0. The router bridging two areas is the ABR (Area Border Router).
Router-ABR> enable
Router-ABR# configure terminal
Router-ABR(config)# router ospf 1
Router-ABR(config-router)# router-id 2.2.2.2
! Interconnect network → Area 0 (Backbone)
Router-ABR(config-router)# network 10.1.1.0 0.0.0.3 area 0
! Remote-site network → Area 1
Router-ABR(config-router)# network 172.16.0.0 0.0.255.255 area 1
Router-ABR(config-router)# end
Router-ABR# write memory
OSPF verification
show ip ospf neighbor ! OSPF adjacencies
show ip ospf ! Process info (router-id, areas)
show ip route ospf ! Routes learned via OSPF (O = intra-area, O IA = inter-area)
show ip ospf interface brief ! OSPF status per interface
debug ip ospf events ! Real-time debug (use with caution)
| Concept | Detail |
|---|---|
| Process ID | Local to the router; does not need to match between routers |
| Router-ID | Must be unique; if not configured, uses the highest IP |
| Area 0 | Mandatory in multi-area; all areas must connect to it |
| ABR | Router with interfaces in at least two different areas |
| Wildcard mask | Inverse of the subnet mask (e.g. /24 → 0.0.0.255) |
passive-interface | Blocks OSPF hello packets on LAN/end-user interfaces |
DHCP
Router# configure terminal
Router(config)# ip dhcp pool MyPool
Router(dhcp-config)# network 192.168.1.0 255.255.255.0
Router(dhcp-config)# default-router 192.168.1.1
Router(dhcp-config)# dns-server 8.8.8.8 8.8.4.4
Router(dhcp-config)# lease 1 12 30 ! 1 day, 12 hours, 30 min
Router(dhcp-config)# exit
! Exclude static addresses from automatic assignment
Router(config)# ip dhcp excluded-address 192.168.1.1 192.168.1.10
Router(config)# exit
Router# write memory
DHCP Relay (ip helper-address)
When the DHCP server is on a different subnet:
Router(config)# interface GigabitEthernet0/1
Router(config-if)# ip helper-address 10.0.0.1 ! IP of the DHCP server
VLAN
Create a VLAN
Switch# configure terminal
Switch(config)# vlan 10
Switch(config-vlan)# name Office
Switch(config-vlan)# exit
Switch(config)# write memory
Assign a port to a VLAN (access port)
Switch(config)# interface FastEthernet0/1
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# exit
Configure multiple interfaces at once
! Contiguous range
Switch(config)# interface range FastEthernet0/1 - 5
! Non-contiguous interfaces
Switch(config)# interface range FastEthernet0/1, FastEthernet0/3, FastEthernet0/5
Switch(config-if-range)# switchport mode access
Switch(config-if-range)# switchport access vlan 10
Switch(config-if-range)# exit
Trunk port
Switch(config)# interface GigabitEthernet0/1
Switch(config-if)# switchport mode trunk
Switch(config-if)# switchport trunk allowed vlan 10,20,30
Switch(config-if)# exit
VLAN verification
show vlan brief
show interfaces trunk
VTP (VLAN Trunking Protocol)
SERVER switch
sw0(config)# vtp mode server
sw0(config)# vtp domain company
sw0(config)# vtp password 123456
sw0(config)# vtp version 2
sw0(config)# end
sw0# write memory
CLIENT switch
sw1(config)# vtp mode client
sw1(config)# vtp domain company
sw1(config)# vtp password 123456
sw1(config)# end
sw1# write memory
show vtp status ! Verify VTP configuration
Virtual sub-interfaces (Router-on-a-Stick)
Allows a single router to route traffic between multiple VLANs via sub-interfaces:
Router# configure terminal
Router(config)# interface GigabitEthernet0/1.10
Router(config-subif)# encapsulation dot1Q 10
Router(config-subif)# ip address 192.168.10.254 255.255.255.0
Router(config-subif)# exit
Router(config)# interface GigabitEthernet0/1.20
Router(config-subif)# encapsulation dot1Q 20
Router(config-subif)# ip address 192.168.20.254 255.255.255.0
Router(config-subif)# exit
NAT, PAT and Port Forwarding
0. Prerequisites — Define interfaces
Router(config)# interface GigabitEthernet0/1
Router(config-if)# ip nat inside ! LAN interface
Router(config-if)# exit
Router(config)# interface GigabitEthernet0/0
Router(config-if)# ip nat outside ! WAN/Internet interface
Router(config-if)# exit
1. Static NAT (1 private IP → 1 fixed public IP)
Router(config)# ip nat inside source static 192.168.1.10 209.165.200.225
2. Dynamic NAT (pool of public IPs)
! Step A: define the pool of public IPs
Router(config)# ip nat pool MyPool 209.165.200.226 209.165.200.230 netmask 255.255.255.248
! Step B: ACL for authorised internal traffic
Router(config)# access-list 1 permit 192.168.1.0 0.0.0.255
! Step C: associate ACL with the pool
Router(config)# ip nat inside source list 1 pool MyPool
3. PAT / NAT Overload (many private IPs → 1 public IP)
! Step A: ACL
Router(config)# access-list 1 permit 192.168.1.0 0.0.0.255
! Step B: overload on the WAN interface
Router(config)# ip nat inside source list 1 interface GigabitEthernet0/0 overload
The keyword
overloadis essential: without it, the router would perform Dynamic NAT and support only one user at a time.
4. Port Forwarding (Static PAT)
! Internal web server 192.168.1.50:80 exposed on public port 80
Router(config)# ip nat inside source static tcp 192.168.1.50 80 209.165.200.225 80
! Internal SSH port 22, exposed on port 2222 (more secure)
Router(config)# ip nat inside source static tcp 192.168.1.50 22 209.165.200.225 2222
NAT verification and debug
show ip nat translations ! Active translation table
show ip nat statistics ! General statistics
clear ip nat translation * ! Clear all translations
debug ip nat ! Real-time debug (lab use only!)
| Type | Key command | When to use |
|---|---|---|
| Static NAT | static <local_ip> <global_ip> | Public servers (Web, Mail) |
| Dynamic NAT | pool <name> + list <acl> | Multiple public IPs available |
| PAT (Overload) | list <acl> interface <int> overload | Standard Internet access |
| Port Forwarding | static tcp <local_ip> <port> ... | Open specific ports |
EC