Top 20 Cisco IOS Show Commands Every CCNA Student Should Know by Muscle Memory
A short, exam oriented reference for the 20 Cisco IOS show commands that come up most often on CCNA 200-301 labs, interviews, and real US network engineering jobs. Real output, when to run each one, and the one line it is checking for.
If you can only memorize twenty Cisco IOS show commands before your CCNA, make it these. They cover the four layers you will be asked about on the exam (physical, Layer 2, Layer 3, services), and they are what a US network engineer actually runs on day one of a new job.
Every command below has three things: when to use it, the real output you will see, and the single line you should be scanning for. No fluff.
Section 1: cabling and physical interfaces
1. show ip interface brief
The first command you run on any device. Full stop. One line per interface, three columns that matter: IP address, admin status, line protocol.
R1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 10.0.0.1 YES NVRAM up up
GigabitEthernet0/1 unassigned YES NVRAM administratively down down
GigabitEthernet0/2 192.168.1.1 YES NVRAM up down
Scan for anything other than up/up in the right two columns. administratively down means shutdown is applied. up/down means the cable or the far end is wrong.
2. show interfaces status
Same idea, switch flavor. One line per switchport, access or trunk mode, native VLAN, duplex, speed.
Switch# show interfaces status
Port Name Status Vlan Duplex Speed Type
Gi0/1 connected 10 a-full a-1000 10/100/1000BaseTX
Gi0/2 notconnect 1 auto auto 10/100/1000BaseTX
Gi0/23 connected trunk a-full a-1000 10/100/1000BaseTX
Scan for connected vs notconnect vs err-disabled. err-disabled means a port security or BPDU Guard violation; investigate before you re-enable.
3. show interfaces GigabitEthernet0/0
The full dump for one interface. You want three numbers from the bottom: input errors, CRC, and output drops.
R1# show interfaces GigabitEthernet0/0
GigabitEthernet0/0 is up, line protocol is up
Hardware is iGbE, address is 0012.3456.7890
MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec
...
5 minute input rate 4000 bits/sec, 3 packets/sec
10 input errors, 10 CRC, 0 frame, 0 overrun, 0 ignored
Any non zero CRC is a cabling problem. Replace the cable or the SFP before you touch anything else.
4. show interfaces counters errors
Platform wide view of the same thing, no scrolling. Clean columns, one line per switchport. Great for a quick sweep.
Section 2: Layer 2 switching
5. show vlan brief
Which VLANs exist on this switch and which access ports are assigned to each. Memorize this one. Most VLAN questions on the exam resolve here.
Switch# show vlan brief
VLAN Name Status Ports
---- ------------- --------- -------------------------------
1 default active Gi0/5, Gi0/6
10 USERS active Gi0/1, Gi0/2
20 VOICE active Gi0/3
If an access port is in VLAN 1 and you did not put it there, nobody did; that is the default. If the VLAN itself is missing from this list, trunking cannot carry it either.
6. show interfaces trunk
The single most useful trunk command. Shows allowed VLANs per side, native VLAN, encapsulation.
Switch# show interfaces trunk
Port Mode Encapsulation Status Native vlan
Gi0/23 on 802.1q trunking 1
Port Vlans allowed on trunk
Gi0/23 1-10,30
Port Vlans allowed and active in management domain
Gi0/23 1,10
The “Vlans allowed on trunk” column is per side. If a VLAN is in the list on one side and not on the other, Layer 2 frames in that VLAN drop silently.
7. show mac address-table
The switch’s forwarding table. Each row is a MAC on a port in a VLAN.
Switch# show mac address-table
Vlan Mac Address Type Ports
10 aabb.cc01.0001 DYNAMIC Gi0/1
10 aabb.cc01.0002 DYNAMIC Gi0/2
If you expect a device to be in VLAN 10 and its MAC is sitting in VLAN 1, your access VLAN assignment is wrong on that port. Pair this with show interfaces status for a two command port diagnosis.
8. show spanning-tree
Which switch is root, which ports are forwarding or blocked, what the port cost is. You will see this on the exam dozens of times across the labs.
Switch# show spanning-tree vlan 10
VLAN0010
Spanning tree enabled protocol rstp
Root ID Priority 32778
Address aabb.cc00.0100
This bridge is the root
...
If you expect this switch to be root and it says “This bridge is the root”, great. If not, check port priorities and bridge IDs on both ends.
9. show spanning-tree inconsistentports
The command that saves your Saturday. Shows every port that STP has put into a special state (BPDU inconsistent, root inconsistent, loop inconsistent). If a port keeps going err-disabled after a user plugs in, this tells you which Guard feature fired.
10. show etherchannel summary
Which port channels exist, which protocol (LACP or PAgP), which physical links are bundled, what each link’s state is.
Switch# show etherchannel summary
Group Port-channel Protocol Ports
------+-------------+-----------+-----------------------------
1 Po1(SU) LACP Gi0/1(P) Gi0/2(P)
Flags: SU is the port channel up and in use; (P) on each physical port means it is bundled. (I) means independent, meaning the port is up but not bundled, almost always a config mismatch on one side.
Section 3: Layer 3 routing
11. show ip route
The routing table. Read the legend at the top, then look for the specific prefix you expect. The route source (O for OSPF, S for static, C for connected, L for local) tells you where it was learned.
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
...
Gateway of last resort is 10.0.0.254 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 10.0.0.254
C 10.0.0.0/24 is directly connected, GigabitEthernet0/0
O 192.168.1.0/24 [110/2] via 10.0.0.2, 00:05:13, GigabitEthernet0/0
If a destination is unreachable, the first question is: is there a route for it? If yes, is the next hop reachable? That is the first forty seconds of every routing ticket.
12. show ip route 192.168.1.5
The longest match for one specific IP. Use this when you want to know which route the router would actually use to reach that address.
13. show ip ospf neighbor
Who OSPF thinks its neighbors are and what state the adjacency is in. FULL is the only state that means routes are exchanging.
R1# show ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
2.2.2.2 1 FULL/BDR 00:00:35 10.0.0.2 GigabitEthernet0/0
INIT means hello timers, auth, or area ID mismatch. EXSTART almost always means MTU mismatch. 2-WAY on a broadcast network means both are DROTHERs; that is normal.
14. show ip ospf interface
Per interface OSPF state. Network type, cost, priority, hello and dead timers, MTU, area. The MTU line is where you confirm the EXSTART diagnosis above.
15. show ip arp
The router’s ARP table. Pair with show ip interface brief when the far side is on the same subnet and you cannot ping it. No ARP entry means the ARP broadcast is not reaching back.
Section 4: services and management
16. show running-config
The current config. Combine with | section or | include to find the one thing you care about.
R1# show running-config | section line vty
line vty 0 4
login local
transport input ssh
17. show running-config interface GigabitEthernet0/0
The config of one interface. Faster than scrolling.
18. show cdp neighbors detail
Who is connected on each port, their platform, their IOS version, which of their ports connects back. Powerful for drawing a topology map on a device you did not install.
R1# show cdp neighbors detail
Device ID: Switch1
Entry address(es):
IP address: 10.0.0.10
Platform: cisco WS-C2960, Capabilities: Switch
Interface: GigabitEthernet0/0, Port ID (outbound port): FastEthernet0/24
If CDP is off on the neighbor, try show lldp neighbors detail instead; it is on by default on more modern Catalysts and Nexus.
19. show ip nat translations
The active NAT table. The four columns are the four exam terms: inside global, inside local, outside local, outside global. If a flow is not working through NAT, verify the translation exists here first.
R1# show ip nat translations
Pro Inside global Inside local Outside local Outside global
tcp 198.51.100.2:1024 10.0.0.5:52314 203.0.113.9:443 203.0.113.9:443
20. show logging
The syslog buffer. Where you look when the device knows something went wrong but has not told you yet. Look for %LINK, %LINEPROTO, %SPANTREE, %OSPF, %SEC.
R1# show logging | last 10
*Oct 10 14:03:21.123: %LINEPROTO-5-UPDOWN: Line protocol on Interface Gi0/0, changed state to down
*Oct 10 14:03:22.456: %LINK-3-UPDOWN: Interface Gi0/0, changed state to down
The one minute workflow
A user says “I can’t reach the server.” You have one minute to look busy and competent.
show ip interface briefon the user’s gateway. Interface up?show ip arpon the gateway. ARP for the user populated?show mac address-tableon the access switch. User’s MAC on the expected port and VLAN?show vlan briefon the same switch. VLAN exists, port assigned to it?show interfaces trunkon the uplink. VLAN allowed on both sides?show ip routeon the gateway. Route to the server’s subnet exists?show ip nat translationson the perimeter router. Translation present?
If you can run those seven commands and say what each tells you, you are already more useful than most Tier 1s.
Where to practice these
If you want to run every one of these on a working, broken, or half broken topology without installing anything, open any lab on /exam/labs/ (fix the broken network, in your browser, free). The topology, the console, and the Cisco IOS behavior are the same you will see at a US employer on a Catalyst 9300 or an ISR 4321.
Memorize these 20. Interview panels in the US routinely open with “what is the first show command you run when you log in to a strange device?” Four of the twenty above answer that one way or another.
Get posts like this by email.
One short, opinionated tutorial per week. Unsubscribe in one click.
Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.
