Home › Guides › Essential CCNA commands

Essential CCNA Commands

The Cisco IOS commands that show up again and again on the CCNA — grouped by what you're actually doing, with the show commands that save you in troubleshooting questions.

Updated October 2026 · ~8 min read

Moving between modes

Router> enable                 ! user EXEC -> privileged EXEC
Router# configure terminal     ! -> global config  (short: conf t)
Router(config)# interface g0/0 ! -> interface config
Router(config-if)# exit        ! back up one level
Router(config-if)# end         ! jump straight to privileged EXEC (or Ctrl+Z)

Basic device setup

Router(config)# hostname R1
R1(config)# enable secret Cisco123       ! encrypted privileged password
R1(config)# service password-encryption  ! obscure plaintext passwords
R1(config)# banner motd # Authorized access only #
R1# show running-config                   ! the live config  (short: show run)
R1# copy running-config startup-config    ! save it  (or: write memory)
R1# show version                          ! IOS version, uptime, model

Interfaces

R1(config)# interface g0/0
R1(config-if)# description Link to SW1
R1(config-if)# ip address 192.168.1.1 255.255.255.0
R1(config-if)# no shutdown                ! bring the interface up
R1# show ip interface brief               ! quick up/down + IP table (show ip int br)
R1# show interfaces status                ! switch port status/VLAN/speed

"Administratively down" means someone needs to type no shutdown. "Down/down" usually means a cabling or far-end problem.

VLANs and switchports

SW1(config)# vlan 10
SW1(config-vlan)# name SALES
SW1(config)# interface g0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport access vlan 10
SW1(config)# interface g0/24
SW1(config-if)# switchport mode trunk
SW1# show vlan brief                       ! which ports are in which VLAN
SW1# show interfaces trunk                 ! trunk links and allowed VLANs

Routing

! Static route
R1(config)# ip route 10.2.2.0 255.255.255.0 192.168.1.2

! Default route
R1(config)# ip route 0.0.0.0 0.0.0.0 192.168.1.2

! OSPF
R1(config)# router ospf 1
R1(config-router)# network 192.168.1.0 0.0.0.255 area 0

R1# show ip route            ! the routing table
R1# show ip ospf neighbor    ! OSPF adjacencies (Full = good)
R1# show ip protocols        ! which routing protocols are running

SSH and remote access

R1(config)# ip domain-name example.com
R1(config)# crypto key generate rsa        ! choose 1024+ modulus
R1(config)# username admin secret StrongPass
R1(config)# line vty 0 4
R1(config-line)# transport input ssh
R1(config-line)# login local
R1# show ssh

The troubleshooting show commands

A huge share of exam questions are "here's the output — what's wrong?" Know what each of these tells you:

CommandTells you
show ip interface briefWhich interfaces are up and their IPs
show ip routeHow the router reaches each network
show vlan briefPort-to-VLAN assignments
show mac address-tableWhich MAC is on which switch port
show cdp neighborsDirectly connected Cisco devices
show ip ospf neighborOSPF adjacency state
ping / tracerouteReachability and the path taken

Don't just read commands — type them

Recognizing a command isn't the same as producing it under pressure. CLI Recall drills you until the syntax is muscle memory, and accepts valid abbreviations like the real CLI.

Start drilling free

Related guides