Skip to main content
PacketMentor logo
Open menu
← All posts
ccnaciscoiosshow-commandstroubleshooting

Top 20 Cisco IOS Show Commands Every CCNA Student Should Know by Muscle Memory

A short, exam oriented reference for the 20 Cisco IOS show commands that come up most often on CCNA 200-301 labs, interviews, and real US network engineering jobs. Real output, when to run each one, and the one line it is checking for.

If you can only memorize twenty Cisco IOS show commands before your CCNA, make it these. They cover the four layers you will be asked about on the exam (physical, Layer 2, Layer 3, services), and they are what a US network engineer actually runs on day one of a new job.

Every command below has three things: when to use it, the real output you will see, and the single line you should be scanning for. No fluff.

Section 1: cabling and physical interfaces

1. show ip interface brief

The first command you run on any device. Full stop. One line per interface, three columns that matter: IP address, admin status, line protocol.

R1# show ip interface brief
Interface            IP-Address      OK? Method Status                Protocol
GigabitEthernet0/0   10.0.0.1        YES NVRAM  up                    up
GigabitEthernet0/1   unassigned      YES NVRAM  administratively down down
GigabitEthernet0/2   192.168.1.1     YES NVRAM  up                    down

Scan for anything other than up/up in the right two columns. administratively down means shutdown is applied. up/down means the cable or the far end is wrong.

2. show interfaces status

Same idea, switch flavor. One line per switchport, access or trunk mode, native VLAN, duplex, speed.

Switch# show interfaces status
Port      Name             Status       Vlan       Duplex  Speed Type
Gi0/1                      connected    10         a-full  a-1000 10/100/1000BaseTX
Gi0/2                      notconnect   1          auto    auto 10/100/1000BaseTX
Gi0/23                     connected    trunk      a-full  a-1000 10/100/1000BaseTX

Scan for connected vs notconnect vs err-disabled. err-disabled means a port security or BPDU Guard violation; investigate before you re-enable.

3. show interfaces GigabitEthernet0/0

The full dump for one interface. You want three numbers from the bottom: input errors, CRC, and output drops.

R1# show interfaces GigabitEthernet0/0
GigabitEthernet0/0 is up, line protocol is up
  Hardware is iGbE, address is 0012.3456.7890
  MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec
  ...
  5 minute input rate 4000 bits/sec, 3 packets/sec
  10 input errors, 10 CRC, 0 frame, 0 overrun, 0 ignored

Any non zero CRC is a cabling problem. Replace the cable or the SFP before you touch anything else.

4. show interfaces counters errors

Platform wide view of the same thing, no scrolling. Clean columns, one line per switchport. Great for a quick sweep.

Section 2: Layer 2 switching

5. show vlan brief

Which VLANs exist on this switch and which access ports are assigned to each. Memorize this one. Most VLAN questions on the exam resolve here.

Switch# show vlan brief
VLAN Name          Status    Ports
---- ------------- --------- -------------------------------
1    default       active    Gi0/5, Gi0/6
10   USERS         active    Gi0/1, Gi0/2
20   VOICE         active    Gi0/3

If an access port is in VLAN 1 and you did not put it there, nobody did; that is the default. If the VLAN itself is missing from this list, trunking cannot carry it either.

6. show interfaces trunk

The single most useful trunk command. Shows allowed VLANs per side, native VLAN, encapsulation.

Switch# show interfaces trunk
Port        Mode             Encapsulation  Status    Native vlan
Gi0/23      on               802.1q         trunking  1

Port        Vlans allowed on trunk
Gi0/23      1-10,30

Port        Vlans allowed and active in management domain
Gi0/23      1,10

The “Vlans allowed on trunk” column is per side. If a VLAN is in the list on one side and not on the other, Layer 2 frames in that VLAN drop silently.

7. show mac address-table

The switch’s forwarding table. Each row is a MAC on a port in a VLAN.

Switch# show mac address-table
Vlan    Mac Address       Type        Ports
10      aabb.cc01.0001    DYNAMIC     Gi0/1
10      aabb.cc01.0002    DYNAMIC     Gi0/2

If you expect a device to be in VLAN 10 and its MAC is sitting in VLAN 1, your access VLAN assignment is wrong on that port. Pair this with show interfaces status for a two command port diagnosis.

8. show spanning-tree

Which switch is root, which ports are forwarding or blocked, what the port cost is. You will see this on the exam dozens of times across the labs.

Switch# show spanning-tree vlan 10
VLAN0010
  Spanning tree enabled protocol rstp
  Root ID    Priority    32778
             Address     aabb.cc00.0100
             This bridge is the root
...

If you expect this switch to be root and it says “This bridge is the root”, great. If not, check port priorities and bridge IDs on both ends.

9. show spanning-tree inconsistentports

The command that saves your Saturday. Shows every port that STP has put into a special state (BPDU inconsistent, root inconsistent, loop inconsistent). If a port keeps going err-disabled after a user plugs in, this tells you which Guard feature fired.

10. show etherchannel summary

Which port channels exist, which protocol (LACP or PAgP), which physical links are bundled, what each link’s state is.

Switch# show etherchannel summary
Group  Port-channel  Protocol    Ports
------+-------------+-----------+-----------------------------
1      Po1(SU)         LACP      Gi0/1(P)    Gi0/2(P)

Flags: SU is the port channel up and in use; (P) on each physical port means it is bundled. (I) means independent, meaning the port is up but not bundled, almost always a config mismatch on one side.

Section 3: Layer 3 routing

11. show ip route

The routing table. Read the legend at the top, then look for the specific prefix you expect. The route source (O for OSPF, S for static, C for connected, L for local) tells you where it was learned.

R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
...
Gateway of last resort is 10.0.0.254 to network 0.0.0.0

S*    0.0.0.0/0 [1/0] via 10.0.0.254
C     10.0.0.0/24 is directly connected, GigabitEthernet0/0
O     192.168.1.0/24 [110/2] via 10.0.0.2, 00:05:13, GigabitEthernet0/0

If a destination is unreachable, the first question is: is there a route for it? If yes, is the next hop reachable? That is the first forty seconds of every routing ticket.

12. show ip route 192.168.1.5

The longest match for one specific IP. Use this when you want to know which route the router would actually use to reach that address.

13. show ip ospf neighbor

Who OSPF thinks its neighbors are and what state the adjacency is in. FULL is the only state that means routes are exchanging.

R1# show ip ospf neighbor
Neighbor ID     Pri   State           Dead Time   Address         Interface
2.2.2.2           1   FULL/BDR        00:00:35    10.0.0.2        GigabitEthernet0/0

INIT means hello timers, auth, or area ID mismatch. EXSTART almost always means MTU mismatch. 2-WAY on a broadcast network means both are DROTHERs; that is normal.

14. show ip ospf interface

Per interface OSPF state. Network type, cost, priority, hello and dead timers, MTU, area. The MTU line is where you confirm the EXSTART diagnosis above.

15. show ip arp

The router’s ARP table. Pair with show ip interface brief when the far side is on the same subnet and you cannot ping it. No ARP entry means the ARP broadcast is not reaching back.

Section 4: services and management

16. show running-config

The current config. Combine with | section or | include to find the one thing you care about.

R1# show running-config | section line vty
line vty 0 4
 login local
 transport input ssh

17. show running-config interface GigabitEthernet0/0

The config of one interface. Faster than scrolling.

18. show cdp neighbors detail

Who is connected on each port, their platform, their IOS version, which of their ports connects back. Powerful for drawing a topology map on a device you did not install.

R1# show cdp neighbors detail
Device ID: Switch1
Entry address(es):
  IP address: 10.0.0.10
Platform: cisco WS-C2960, Capabilities: Switch
Interface: GigabitEthernet0/0, Port ID (outbound port): FastEthernet0/24

If CDP is off on the neighbor, try show lldp neighbors detail instead; it is on by default on more modern Catalysts and Nexus.

19. show ip nat translations

The active NAT table. The four columns are the four exam terms: inside global, inside local, outside local, outside global. If a flow is not working through NAT, verify the translation exists here first.

R1# show ip nat translations
Pro Inside global     Inside local     Outside local     Outside global
tcp 198.51.100.2:1024 10.0.0.5:52314   203.0.113.9:443   203.0.113.9:443

20. show logging

The syslog buffer. Where you look when the device knows something went wrong but has not told you yet. Look for %LINK, %LINEPROTO, %SPANTREE, %OSPF, %SEC.

R1# show logging | last 10
*Oct 10 14:03:21.123: %LINEPROTO-5-UPDOWN: Line protocol on Interface Gi0/0, changed state to down
*Oct 10 14:03:22.456: %LINK-3-UPDOWN: Interface Gi0/0, changed state to down

The one minute workflow

A user says “I can’t reach the server.” You have one minute to look busy and competent.

  1. show ip interface brief on the user’s gateway. Interface up?
  2. show ip arp on the gateway. ARP for the user populated?
  3. show mac address-table on the access switch. User’s MAC on the expected port and VLAN?
  4. show vlan brief on the same switch. VLAN exists, port assigned to it?
  5. show interfaces trunk on the uplink. VLAN allowed on both sides?
  6. show ip route on the gateway. Route to the server’s subnet exists?
  7. show ip nat translations on the perimeter router. Translation present?

If you can run those seven commands and say what each tells you, you are already more useful than most Tier 1s.

Where to practice these

If you want to run every one of these on a working, broken, or half broken topology without installing anything, open any lab on /exam/labs/ (fix the broken network, in your browser, free). The topology, the console, and the Cisco IOS behavior are the same you will see at a US employer on a Catalyst 9300 or an ISR 4321.

Memorize these 20. Interview panels in the US routinely open with “what is the first show command you run when you log in to a strange device?” Four of the twenty above answer that one way or another.

Get posts like this by email.

One short, opinionated tutorial per week. Unsubscribe in one click.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.